MNPI Controls in Research
Research desks now buy satellite images, app-usage data, and expert-network calls as routinely as they buy price history — and any of these can carry material non-public information without a vendor ever saying so. MNPI controls are the checks a research process runs before that data reaches a model.
Prerequisites: What Makes Information Material and Non-Public, The Research Standards Document
A junior researcher at a mid-sized fund is building a signal from a new alternative-data feed: anonymised, aggregated foot-traffic counts at big-box retailers, bought from a data vendor to forecast quarterly same-store sales ahead of earnings. Two weeks before a retailer's earnings date, the feed shows a sharp, unambiguous drop in visits at a specific chain — a signal so strong the desk is ready to short the stock heavily into the print. What nobody on the research desk checked is where the vendor actually sourced the counts: for that one chain, in that one quarter, the vendor's sample happened to include devices from a marketing contractor who had early access to the retailer's own internal sales dashboards, and the "foot traffic" numbers for the final two weeks of the quarter had been quietly supplemented with the contractor's leaked estimate of actual register receipts. The data was not traffic. It was material non-public information about the company's actual results, laundered through a data vendor's methodology page that nobody on the research desk had read past the summary paragraph.
This is the risk MNPI controls exist to catch: the boundary between "a clever alternative-data signal" and "trading on someone's leaked corporate information" has moved from being an obvious, personal choice — take the tip or don't — to something that can arrive hidden inside a vendor contract, an expert-network call, or a dataset's fine print. See What Makes Information Material and Non-Public for what makes information material and non-public in the first place; this page is about the process a research desk runs to keep that information from ever reaching a model.
Where MNPI actually enters a research pipeline
Four entry points account for most real cases:
| Entry point | The risk |
|---|---|
| Expert-network calls | An "industry expert" who is a current employee describes internal, unreleased numbers rather than public industry knowledge — see Expert Networks and the Mosaic Theory |
| Alternative-data vendors | A dataset's methodology quietly incorporates a non-public source, or a small sample size means the data is really about one identifiable insider's behaviour |
| Employee tips and personal networks | A researcher's contact at a company mentions something in confidence that turns out to be inside information |
| Deal and issuance work | Contact with a bank on a pending financing or M&A deal, requiring the researcher to be "wall-crossed" — see Wall Crossing and Restricted Lists |
The alternative-data case is the one growing fastest and the one researchers are least trained to spot, because it doesn't feel like a tip — it feels like a spreadsheet.
What the controls actually check
A research desk with functioning MNPI controls runs three checks, roughly in this order, before a new data source or contact ever informs a live signal:
- Source diligence before purchase. Legal or compliance reviews any new vendor's methodology, sample construction, and where their raw data physically comes from — not just the marketing description — before a contract is signed, and re-reviews it if the vendor changes methodology.
- A compliance-approved script for expert-network calls, with a compliance monitor present or a recording kept, and an explicit instruction to the expert at the start of every call not to disclose material non-public information, plus a hard stop the moment a call drifts toward specific unreleased figures.
- A named person a researcher must escalate to the moment anything in a call or a dataset feels like it could be non-public and material — and a firm norm that escalating is the safe, expected action, not an admission of having done something wrong.
None of these checks require the researcher to be a lawyer. They require the process to make "stop and ask" the path of least resistance, because the researcher in the moment — mid-call, mid-backtest, excited about a signal that finally works — is the person least likely to want to slow down.
MNPI risk in modern research rarely looks like a tip from a friend at a bar. It looks like a dataset that works unusually well, from a vendor whose methodology nobody on the desk actually read. The control that catches it is diligence on the data's origin, done before the signal is trusted, not after it has already made money.
Worked example, continued: what should have happened
Back to the foot-traffic feed. A functioning control would have caught this at the first check, not the third: before the vendor contract was signed, compliance would have requested the vendor's full sourcing methodology, including how the sample was constructed for each covered retailer, and would have flagged the marketing-contractor supplement as an unacceptable, undisclosed non-public source — killing the vendor relationship, or at minimum that one chain's coverage, before any researcher ever saw the resulting numbers. The failure in the story was not that a researcher did something reckless with a signal. It was that no one's job was to check where the signal came from before it reached the desk at all.
"The vendor says it's aggregated and anonymised" is not a defence. Regulators and courts look at what the data actually reveals about a specific company's results, not at how the vendor labels it. A small enough sample, or a single well-placed source folded into an aggregate, can make "anonymised" data functionally equivalent to an inside tip — see What Counts as Market Abuse for how that line gets drawn.
As a rule of thumb for any new alternative-data source: if you cannot explain, in one sentence, exactly which real-world devices, people, or transactions the data is counting and how the vendor got access to count them, you do not yet know enough to trust the signal — regardless of how well it backtests.
Related concepts
Practice in interviews
Further reading
- SEC, Regulation FD and enforcement actions on expert-network use
- López de Prado, Advances in Financial Machine Learning (Ch. 1, on data sourcing risk)