Skip to main content
Category: Conflicts of Interest

Outside Business Activities

Also known as: OBA, Outside Business Activities of Registered Persons
Simply put

An Outside Business Activity (OBA) is any business or work a financial professional does outside of their main firm, typically where they receive compensation. In the U.S. securities industry, registered persons are generally required to disclose these activities to their firm and, in some cases, on regulatory forms. This concept is specific to financial services regulation and is a matter of adherence to defined rules rather than voluntary ethical judgment.

Formal definition

Outside Business Activity (OBA) refers, under FINRA Rule 3270, to activity in which a registered person serves as an employee, independent contractor, sole proprietor, officer, director, or partner of another person, or is compensated or has the reasonable expectation of compensation, outside the scope of the relationship with their member firm. Firms are expected to require disclosure and evaluate such activities, and per SOURCE 4 investment advisers may also need to disclose OBAs on required regulatory forms. Per SOURCE 1, FINRA has proposed to replace Rules 3270 and 3280 (Private Securities Transactions), so practitioners should confirm the current rule status against primary sources. This entry addresses U.S. securities-industry obligations under FINRA and applicable adviser regulation and is jurisdiction-specific; the precise scope, disclosure timing, and any effective dates of proposed rule changes should be verified against the source rulebook, as exact requirements vary and may change. This glossary entry is educational and not a substitute for qualified legal or compliance counsel. OBA is distinct from Private Securities Transactions (historically addressed separately under Rule 3280) and from a firm's broader compliance program elements such as its code of conduct, training modules, and monitoring functions.

Why it matters

Outside Business Activities sit at the intersection of employee conduct and regulatory obligation in the U.S. securities industry. A registered person's activity outside their firm can create conflicts of interest, obscure the source of compensation, or expose customers to risks the firm has not evaluated. Because FINRA Rule 3270 generally requires disclosure of such activities, unreported OBAs are a recurring focus of regulatory scrutiny and firm supervision. This is a compliance matter, adherence to a defined rule with defined disclosure expectations, rather than a purely values-based ethical judgment, though undisclosed outside activity can also raise ethical concerns about candor.

For firms, the significance lies in supervisory responsibility. When a registered person engages in outside work, the firm is expected to require disclosure and evaluate the activity, which supports its ability to identify conflicts and protect customers. Failing to capture and assess OBAs can leave a firm unable to demonstrate adequate supervision. Investment advisers face a parallel obligation: per the NASAA source, advisers engaged in an OBA must disclose information about those activities on several required regulatory forms, making accurate disclosure a matter of regulatory recordkeeping as well as internal policy.

The regulatory landscape here is also in flux. As of the Armstrong Teasdale source, FINRA has proposed to replace Rules 3270 and 3280 (Private Securities Transactions). Because scope, disclosure timing, and any effective dates may change, practitioners should confirm current rule status against the primary rulebook rather than relying on a fixed description. Exact requirements vary by circumstance and should be verified against FINRA's rules and applicable adviser regulation; this entry is educational and not a substitute for qualified legal or compliance counsel.

Who it's relevant to

Compliance Officers and Supervisors
Those responsible for supervision at member firms need to establish processes for capturing OBA disclosures from registered persons and for evaluating the disclosed activities. Because FINRA has proposed to replace Rules 3270 and 3280, compliance staff should track the current rule status against the primary rulebook so their procedures reflect prevailing requirements.
Registered Persons
Employees who are registered persons are the parties whose outside activities the rule addresses. They are generally required to disclose to their firm any qualifying outside work, including roles as employee, independent contractor, sole proprietor, officer, director, or partner, or activity for which they are or reasonably expect to be compensated, so the firm can evaluate it.
Investment Adviser Personnel
Per the NASAA source, advisers engaged in an OBA must disclose information about those activities on several required regulatory forms. Adviser compliance teams should ensure OBA information is accurately captured and reflected on applicable regulatory filings, recognizing that specific requirements should be confirmed against primary sources.
Legal and Regulatory Affairs Teams
Because the OBA framework is jurisdiction-specific to U.S. securities regulation and is subject to a pending FINRA proposal to replace Rules 3270 and 3280, legal teams play a role in interpreting scope, disclosure timing, and effective dates. Questions touching these matters may require qualified legal counsel and verification against the current rulebook.
Learning and Development Staff
Those who build training for registered persons can use OBA as a focused topic within a broader compliance curriculum, clarifying disclosure obligations. Training on OBA is one module and does not by itself satisfy a firm's supervisory or disclosure obligations under the applicable rules.

Inside OBA

Definition and Scope
Outside Business Activities (OBAs) refer to employment, financial, advisory, board, or entrepreneurial engagements an individual undertakes beyond their role with the organization. The concept typically covers paid and unpaid activities that could intersect with the employer's interests, though the precise scope depends on how each organization defines it in policy.
Conflict of Interest Nexus
OBAs are primarily a compliance and ethics concern because they can create actual, potential, or perceived conflicts of interest. Compliance addresses whether the activity violates policy or applicable law, while ethics addresses whether the activity, even if permitted, undermines the individual's objectivity or the organization's trust.
Disclosure Mechanism
Most OBA frameworks rely on a disclosure and approval process through which employees report outside activities so the organization can assess and, where necessary, manage or prohibit them. Disclosure is one control within a broader conflicts-of-interest program and does not by itself resolve a conflict.
Review and Determination
Following disclosure, a designated function (such as compliance, legal, or a manager) evaluates whether the activity is permissible, permissible with conditions, or prohibited. Determinations depend on the facts, the individual's role, and applicable internal policy or external requirements.
Regulatory and Sector Considerations
In certain regulated sectors, external requirements may impose specific obligations regarding outside activities of employees. Such requirements are jurisdiction- and sector-specific and should be confirmed against the applicable primary sources and qualified legal counsel rather than assumed to apply universally.
Record-Keeping
Maintaining documentation of disclosures, reviews, and decisions supports program consistency and demonstrates that the organization assesses OBAs. Record-keeping is part of a monitoring and program-governance function, distinct from the training that communicates OBA expectations to employees.

Common questions

Answers to the questions practitioners most commonly ask about OBA.

Is disclosing an outside business activity the same as getting it approved?
No. Disclosure and approval are distinct steps. Disclosure is the employee's act of reporting the activity through the required channel, while approval is a separate determination by the organization that the activity does not create an unmanageable conflict or policy violation. An employee who has disclosed but not received approval should not assume the activity is permitted. Organizations typically define which activities require only notification and which require affirmative sign-off; employees should confirm the specific requirement under their own policy. This entry is educational and not a substitute for reviewing your organization's applicable policy or seeking guidance from your compliance function.
Does an outside business activity policy only concern legal compliance, or does it also involve ethics?
It involves both, and the two dimensions should not be conflated. Some outside business activities implicate compliance in the strict sense, adherence to laws, regulations, or binding internal policies with defined consequences, such as securities rules or sector-specific restrictions. Others raise ethics questions of values-based judgment, such as whether an activity creates the appearance of a conflict or divided loyalty even where no rule is technically breached. A given activity may sit anywhere on that spectrum, and a disclosure regime is generally intended to surface both types of concern for review rather than to address only one.
What information should an outside business activity disclosure typically capture?
Disclosure forms are generally designed to capture enough detail for the organization to assess potential conflicts, though the specific fields vary by policy. Commonly requested information includes the nature of the activity, the outside entity or client involved, the employee's role and any compensation, the anticipated time commitment, and any overlap with the employer's business, customers, or suppliers. The disclosure is one input into a review process; it does not by itself resolve whether a conflict exists. Consult your organization's form and instructions for the exact requirements that apply to you.
How should outside business activity disclosures be integrated with the broader compliance program?
An outside business activity disclosure mechanism is one component of a larger system and does not substitute for other program elements such as a code of conduct, risk assessment, training, or monitoring and auditing functions. In practice, disclosures are commonly linked to conflict-of-interest processes, recorded so they can be reviewed and, where relevant, monitored over time, and referenced in training so employees understand when and how to report. Integration is intended to support consistent handling; the effectiveness of any such arrangement depends on implementation and context.
How often should outside business activities be disclosed or re-confirmed?
Timing depends on how the organization designs its policy. Many programs combine event-driven disclosure, required when a new activity begins or a material change occurs, with periodic re-confirmation, such as an annual attestation. Because circumstances that create conflicts can arise after an initial approval, ongoing or refreshed disclosure is generally regarded as more responsive than a one-time filing. The appropriate cadence is a policy design choice; employees should follow the specific intervals and triggers set out in their own organization's rules.
Who typically reviews and decides on outside business activity disclosures?
Review responsibility varies by organization and is usually defined in the applicable policy. Depending on the structure, decisions may involve the compliance function, human resources, the employee's management chain, legal, or a combination of these, sometimes with escalation for higher-risk activities. Because some determinations touch on matters that vary by local law or that may require qualified legal counsel, organizations often route certain cases accordingly. This entry is educational and not legal advice; consult your compliance and legal teams on how review authority is assigned in your setting.

Common misconceptions

Disclosing an outside business activity automatically means it is approved.
Disclosure is only the first step. It triggers a review under which the organization determines whether the activity is permitted, permitted with conditions, or prohibited. Disclosure alone does not constitute approval or resolve any underlying conflict.
Only paid outside activities need to be disclosed.
Depending on how an organization defines OBAs, unpaid roles such as board memberships or advisory positions can also create conflicts of interest and may fall within disclosure requirements. What must be disclosed depends on the organization's specific policy rather than compensation alone.
Having an OBA policy or completing OBA training prevents conflicts of interest from occurring.
A policy and associated training are intended to help identify and manage outside activities, but they cannot guarantee prevention of conflicts or misconduct. Effectiveness depends on disclosure practices, review quality, and ongoing implementation, and outcomes vary by context.

Best practices

Define the scope of covered activities clearly in policy, specifying whether paid and unpaid roles, board positions, and advisory engagements are included, so employees understand what must be disclosed.
Establish a structured disclosure-and-review workflow that assigns responsibility for evaluating each disclosure and distinguishes between permitted, conditional, and prohibited outcomes.
Treat disclosure as the beginning of a review process rather than automatic approval, and communicate this distinction explicitly in training and policy language.
Maintain documentation of disclosures, reviews, and determinations to support consistency and to demonstrate that OBAs are actively assessed.
Confirm any sector- or jurisdiction-specific requirements against primary sources and qualified legal counsel, rather than assuming universal application, since OBA obligations can vary by regulatory context.
Coordinate OBA training with the broader conflicts-of-interest program so employees understand that training communicates expectations but does not itself resolve conflicts or replace the disclosure and review controls.