Inadvertent Disclosure is Still Disclosure

Alphy Staff
Morgan Stanley Building for HarmCheck Blog on Inadvertent Disclosure

Was it a mistake, or was it intentional? From a compliance-control standpoint, the first priority is the same: stop sensitive information before it leaves the firm. That’s the point of HarmCheck Restricted List™: identifying references to restricted securities and potential MNPI in outbound email while there is still time to stop the message.

In a recent incident at Morgan Stanley, according to Bloomberg, the answer appears to have been “mistake.” A banker reportedly intended to send a client-facing document but instead emailed an internal version containing information on more than 100 investment-banking deals, including some price-sensitive information.

Once information like that has been sent, the task changes quickly from prevention to containment.

According to the report, the bank told Bloomberg in a statement that it “took steps to this inadvertent sharing of information” but did not provide further details.

The stakes can rise sharply if the information concerns a publicly traded company. In that situation, the firm may be dealing with material non-public information, potential market-abuse issues and questions about whether anyone could trade on what was disclosed.

For example:

  • Morgan Stanley — Paid more than $249 million in 2024 after employees disclosed confidential information about upcoming block trades to select investors.

  • Deutsche Bank — Paid $9.5 million in 2016 for inadequate controls around potentially market-moving information shared by research analysts.

  • Goldman Sachs — Paid $22 million in 2012 after regulators found weak controls around selective sharing of research ideas with favored clients.

This is exactly the kind of risk HarmCheck’s Restricted List™ classifier is designed to help address.

Most compliance controls are designed to detect a problem after information has already been sent. HarmCheck Restricted List intervenes earlier — while the email is still being written.

As an employee types, HarmCheck checks the message in real time against the firm’s restricted securities list and can flag references to restricted tickers, issuers and other potential MNPI before the user hits Send. The risky content may already be in the draft, but the disclosure hasn’t happened yet.

HarmCheck is unique in providing this kind of proactive, preventive control at the point of communication. Once the message leaves the firm, compliance is managing an incident. HarmCheck is designed to intervene while there is still time to stop one.