Market Abuse Regulation

What Is the Difference Between a Permanent and Event-Based Insider List?

Under Article 18 of the Market Abuse Regulation (MAR), you must maintain insider lists that record everyone with access to inside information. There are two main types of insider list: permanent and event-based. Although both help you demonstrate compliance with MAR, they serve different purposes. Choosing correctly between permanent vs event-based insider lists is essential to maintaining accurate records and responding effectively if your national competent authority investigates potential market abuse.

What is an insider list?

An insider list is a record of everyone who has access to inside information within your organisation or through external parties, such as legal advisors, auditors or financial advisers.

The list helps you:

You must keep insider lists up to date and retain them in accordance with MAR.

What is a permanent insider list?

A permanent insider list contains individuals who have access to all inside information because of the nature of their role.

This might include certain senior executives or members of your legal or compliance function who are involved in all significant corporate events.

A permanent insider list should remain relatively small. It is not intended to include everyone who regularly works on confidential projects. If someone only has access to inside information relating to specific transactions, they should appear on an event-based insider list instead.

There is a risk that some companies might include people on the permanent list who do not have access to absolutely all inside information in order to reduce the administrative work involved in creating new event-based lists each time. However, it is important to be strict in this discipline and not inflate the list, as regulators need to understand exactly who had access to the information at any time, if an investigation is necessary.

If a company fails to manage its insider lists correctly, it could lead to increased regulatory scrutiny and sanctions under Article 18 of MAR. The article requires issuers to update the list promptly. It must provide an accurate representation of who knew what and when.

What is an event-based insider list?

An event-based insider list relates to a specific piece of inside information or a particular corporate event. You should create a new list whenever a project gives rise to inside information. Add individuals as they gain access to the information and remove them when they no longer need it. Examples include:

  • Preparing annual or interim financial results
  • A merger or acquisition
  • Capital raising
  • A significant contract
  • A major restructuring.

An individual may appear on several event-based insider lists at the same time if they are involved in multiple confidential projects.

Permanent vs event-based insider lists

Permanent insider list

Event-based insider list

Covers all inside information within the organisation

Covers one specific piece of inside information

Used for individuals with permanent access because of their role

Used for anyone given access during a particular project or event

Entries remain until the individual’s role changes

Individuals are added and removed as access changes

Usually small and consistent

Changes throughout the lifecycle of the project

Common compliance mistakes

Managing insider lists becomes more difficult if you do not clearly distinguish between the two types. Common mistakes include:

  • Adding too many people to the permanent insider list so it includes people who do not always have access to all inside information. This means that the organisation no longer has a defensible record of who knew about the inside information at any particular time. Overinflating the permanent list can delay or complicate investigations, leading to potential measures being issued by the regulator.
  • Leaving individuals on an event-based list after they no longer have access
  • Failing to record when access to inside information began or ended, thus slowing down any potential investigation
  • Not retaining previous versions of insider lists, as is required under MAR
  • Using a permanent insider list instead of creating event-based lists for new projects.

How can you manage insider lists effectively?

You should have a clear process for deciding which type of insider list to use. Good practice includes:

  • Creating an event-based insider list as soon as inside information arises

  • Reviewing your permanent insider list regularly to ensure only eligible individuals remain on it

  • Recording when people gain and lose access to inside information

  • Notifying individuals when they are added to an insider list and reminding them of their obligations

  • Ensuring that you meet the specified formatting requirements

  • Retaining previous versions of your insider lists to provide a complete audit trail.