Level III Core · Guidance for Standard II: Integrity of Capital Markets
Firewalls and Information Barriers for CFA Level III
Updated 8 October 2026 · Fact-checked
A firewall (information barrier) is a set of firm policies that stops material nonpublic information from moving between departments. It works with restricted lists, watch lists, and monitoring. To answer exam questions, identify the MNPI risk, then choose the control that blocks the flow and supports compliance under Standard II(A).
Understand Firewalls and Information Barriers
Standard II(A) says you must not act or cause others to act on material nonpublic information (MNPI). Large firms create this risk by design. An investment banking unit may learn about a merger. The research or asset management unit of the same firm trades securities. If the information crosses over, the firm and its people can breach the Standard.
A firewall, also called an information barrier, is the firm's answer. It separates the people who hold MNPI from the people who trade or advise. Typical features are physical separation of departments, restricted access to files and systems, limits on who can attend meetings, and a compliance function that controls any crossing of the barrier.
Two lists support the barrier. The watch list holds securities the firm is monitoring for possible MNPI. It is usually confidential and used by compliance to review trading, communications and research activity. The restricted list holds securities the firm will not trade, and may bar research and recommendations on. The restricted list is often shared more widely so employees know the stop rule. Remember the difference: watch means monitor, restricted means stop.
The barrier must be backed by compliance. Compliance reviews employee and proprietary trading, logs information requests, and decides when a name moves onto or off a list. Written policies, training and consistent enforcement matter. A firewall that exists on paper but is ignored does not satisfy the Standard.
A firewall is the preferred approach over simply stopping all communication or just halting trading. It is also better than relying on an employee's own judgement. The Standard's guidance favours information barriers because they let the firm keep operating while still preventing misuse. Ideally, a firm should not just rely on a firewall alone. It should also have a compliance review of trading and a clear way to handle anyone who has to cross the wall.
Key rules to remember
- Firewall purpose
- MNPI stays on one side of the barrier; trading and advice stay on the other
- Applies between departments such as investment banking, research and asset management.
- Watch list
- Watch list = monitor trading and activity in names that may involve MNPI
- Usually confidential and used by compliance. Does not by itself stop trading.
- Restricted list
- Restricted list = no trading and often no research or recommendations in the named securities
- Typically circulated to relevant staff so they know to stop.
- Core elements of a compliance procedure
- Written policy + compliance review + access controls + lists + training + enforcement
- A barrier is effective only when these work together.
How to solve Firewalls and Information Barriers questions
Use this method for any scenario on MNPI controls, lists or information barriers.
- 1Read the facts and identify what information the person holds and whether it is material and nonpublic.
- 2Identify the departments involved and whether information could cross from one to another.
- 3Decide which control fits: firewall, watch list, restricted list, or compliance review of trading.
- 4Check the command word. If asked to identify, name the control. If asked to justify, link the control to the risk.
- 5Check whether the firm's policy is adequate: written, enforced, monitored, and led by compliance.
- 6State the conclusion in one sentence tied to Standard II(A), and add the action the firm or member should take.
Quickest way: Watch means monitor, restricted means stop
When to use it: Use when an item set asks which list or control applies, or what a firm should do about MNPI risk.
- Ask: is the firm only aware of possible MNPI, or does it hold MNPI? Possible means watch list; confirmed involvement means restricted list.
- Ask: should staff be told? The restricted list is circulated; the watch list stays confidential.
- Ask: who controls the crossing? Compliance, not the individual.
- Pick the answer that blocks the information flow without relying on one person's judgement.
Common mistakes in Firewalls and Information Barriers
Treating the watch list and restricted list as the same thing.
Both relate to MNPI and both sound like warning lists.
Fix: Link watch to monitoring and confidentiality, and restricted to a trading and often research ban that staff can see.
Saying a firewall is enough on its own.
Students remember the barrier but forget the supporting procedures.
Fix: Add compliance review, trading monitoring, training and enforcement to the answer.
Recommending that the firm stop all communication between departments.
It feels like the safest option.
Fix: The guidance favours targeted barriers that let the firm operate. Block MNPI flow, not all contact.
Letting an employee decide alone whether information is material.
Students focus on personal ethical duty.
Fix: Route the question to compliance. The firm's procedure should control the decision.
Assuming a barrier on paper satisfies the Standard.
Policies look complete when written down.
Fix: Look for evidence of enforcement, monitoring and training. A barrier that is not applied is a weakness.
Worked examples
Example 1
A firm's investment banking division is advising on a confidential acquisition of a listed company. The firm's asset management division holds shares of the target. Which procedure best prevents misuse of the information while letting both divisions continue to operate?
Show the solution
- The information is likely material and nonpublic, since it concerns an unannounced acquisition.
- The risk is that it passes from investment banking to asset management.
- The best control is an information barrier controlled by compliance.
- Compliance should also add the target to the restricted list so the firm does not trade or issue recommendations on it.
Answer: Maintain an information barrier between the divisions, controlled by compliance, and place the target company on the restricted list. This blocks the flow of MNPI without stopping normal business.
Example 2
A compliance officer hears that a client of the firm may be planning a takeover, but nothing has been confirmed and the firm has not been engaged. What should the officer do with the security, and should the list be shared with all staff?
Show the solution
- The firm has only a possible involvement, with no confirmed MNPI held.
- The suitable tool is the watch list, so compliance can monitor trading and communications in the security.
- The watch list is usually kept confidential, so it should not be sent to all staff.
- If the firm is later engaged and holds MNPI, compliance can move the name to the restricted list.
Answer: Put the security on the confidential watch list and monitor activity. Do not circulate it widely. Move it to the restricted list if the firm comes to hold MNPI.
Exam tips
- Know the one-line difference: watch list monitors and stays confidential; restricted list stops activity and is shared.
- When asked what a firm should do, name the firewall and then add compliance oversight. One extra supporting control often earns the point.
- Use the command word. Identify means name it; justify means link it to the MNPI risk in one sentence.
- Avoid extreme answers such as halting all communication unless the facts force it.
- Link the answer to Standard II(A) in your last line.
Firewalls and Information Barriers in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Firewalls and Information Barriers: frequently asked questions
What is the difference between a restricted list and a watch list?
A watch list is a confidential list of securities compliance monitors for possible MNPI. A restricted list names securities the firm will not trade, and often will not research or recommend. The restricted list is usually shared with staff.
What is a firewall in the CFA Standards?
It is an information barrier that stops MNPI passing between departments of a firm. It is meant to let the firm keep operating while preventing misuse of information. It relies on compliance procedures to work.
Is a firewall enough to comply with Standard II(A)?
No. It is the core control, but it needs compliance review, monitoring of trading, training and enforcement. A barrier that is not applied does not protect the firm.
Who decides when a security goes on a list?
Compliance decides, not the individual employee. This keeps decisions consistent and removes reliance on personal judgement.