⚠️ Critical Compliance Guide

Regulatory Compliance for Finance NDAs

SEC, FINRA, OCC, SOX, and Dodd-Frank considerations for financial services NDAs. Interactive checklist to ensure your NDA meets all requirements.

🚨 Dodd-Frank Whistleblower Carve-out is Mandatory

SEC Rule 21F-17 prohibits any person from taking action to impede an individual from communicating directly with SEC staff about a possible securities law violation. The SEC has brought enforcement actions against companies with NDAs that lacked proper whistleblower carve-outs, resulting in significant penalties.

Every finance NDA must include an explicit carve-out. Attempting to waive these rights is void as a matter of law and may subject your organization to SEC enforcement.

Sample Carve-out Language:

"Nothing in this Agreement shall prohibit or restrict the Receiving Party or its Representatives from: (i) reporting possible violations of federal law or regulation to any governmental agency or entity, including but not limited to the Department of Justice, the Securities and Exchange Commission, the Congress, and any agency Inspector General, or making other disclosures that are protected under the whistleblower provisions of federal law or regulation; (ii) cooperating with any government investigation; or (iii) receiving any individual monetary award or other individual relief by reason of participation in any government whistleblower program."

Compliance Checklist

Review each item to ensure your finance NDA meets regulatory requirements

0 of 0 items reviewed

⚖️ SEC Requirements

Whistleblower Carve-out (Rule 21F-17)

NDA explicitly permits reporting potential securities violations to SEC without prior approval or notice to the company.

SEC Examination Cooperation

Carve-out allows disclosure to SEC staff during examinations and investigations without triggering NDA breach.

Rule 10b-5 Considerations

If MNPI will be shared, NDA addresses trading restrictions and information barrier requirements.

Form ADV Disclosure Carve-out

For investment advisers: permits disclosure of information required on Form ADV public filings.

📊 FINRA Requirements (Broker-Dealers)

FINRA Examination Cooperation

Carve-out permits disclosure during FINRA examinations without breaching NDA.

Rule 2010 Compliance

NDA terms do not conflict with standards of commercial honor and just principles of trade.

Arbitration Filing Carve-out

NDA permits disclosure of information necessary for FINRA arbitration proceedings.

Form U4/U5 Disclosure

Permits disclosure required on registration and termination forms.

🏢 Banking Regulatory Requirements

OCC Examination Access

For national banks: permits full disclosure to OCC examiners during safety and soundness examinations.

FDIC Examination Access

For insured institutions: permits disclosure during FDIC examinations.

BSA/AML Compliance

NDA does not restrict SAR filing, CTR reporting, or FinCEN cooperation.

State Banking Regulator Access

Permits disclosure to state banking regulators during examinations.

OCC Third-Party Risk Management

Vendor NDAs align with OCC Bulletin 2013-29 requirements for right-to-audit and oversight.

📋 SOX and Corporate Requirements

SOX Section 806 Whistleblower Protection

For public companies: NDA permits reporting of fraud without retaliation.

Record Retention Compliance

Return/destroy provisions do not conflict with SOX record retention requirements.

Audit Committee Access

NDA does not restrict disclosure to board audit committees.

🏛️ State Securities Law Considerations

State Regulator Examination Access

Carve-out permits disclosure to state securities regulators during examinations.

Blue Sky Law Filing Requirements

NDA permits disclosures required for state securities registrations and exemptions.

NASAA Model Rules Compliance

Verify NDA does not conflict with state-specific requirements under NASAA guidelines.

🔒 Privacy and Data Protection

GLBA Compliance

NDA aligns with Gramm-Leach-Bliley customer privacy requirements.

State Privacy Law Compliance

NDA accounts for state-specific privacy requirements (CCPA, etc.).

PCI-DSS Requirements (if applicable)

For payment data: NDA addresses PCI compliance and breach notification.

Key Regulatory Rules

Understanding the legal framework for finance NDA compliance

SEC Rule 21F-17 (Whistleblower Protection)

17 CFR 240.21F-17

Prohibits any action to impede communication with SEC about potential violations. SEC has assessed millions in penalties for NDAs without proper carve-outs.

SEC Rule 10b-5 (Insider Trading)

17 CFR 240.10b-5

Prohibits trading on material non-public information. NDAs involving MNPI should address trading restrictions and information barriers.

OCC Bulletin 2013-29 (Third-Party Risk)

OCC 2013-29

Establishes risk management requirements for bank vendor relationships including audit rights and oversight provisions that must align with NDA terms.

Sarbanes-Oxley Section 806

18 U.S.C. 1514A

Protects employees of public companies who report securities fraud. NDAs cannot restrict these disclosures.

FINRA Rule 2010 (Standards of Commercial Honor)

FINRA Rule 2010

Requires members to observe high standards of commercial honor. NDA provisions must not conflict with these obligations.

Bank Secrecy Act / AML Requirements

31 U.S.C. 5311 et seq.

Requires financial institutions to report suspicious activity. NDAs cannot restrict SAR filing or FinCEN cooperation.

⚠️ Important: Consult a Securities Attorney

This compliance guide provides general information about regulatory requirements affecting finance industry NDAs. It is not a substitute for legal advice. Regulatory requirements vary by entity type, registration status, and specific business activities. The checklist above addresses common requirements but may not cover all situations. Always consult with a securities attorney familiar with your specific regulatory environment before executing finance NDAs.