The Securities and Exchange Commission's settlement with Benjamin Tesfaye highlights the consequences when confidentiality controls fail. Tesfaye agreed to pay $20,836 in disgorgement and interest, plus $18,668 in civil penalties, after allegedly trading on information shared by his girlfriend, a senior director of ethics and compliance, about an impending acquisition.
This case is significant not for its monetary penalties but for exposing weaknesses in control environments. A compliance professional disclosed material nonpublic information to someone outside the organization, who then traded on it before a public announcement. This enforcement action highlights gaps in many compliance programs.
Key Findings
Personal relationships create unmonitored disclosure channels. The SEC complaint describes a couple who lived together and had arrangements to protect confidential information. Despite these precautions, the girlfriend hinted at "big things" happening, which led Tesfaye to deduce the target company by asking a family member about recent interviews. Organizations monitor email and document access, but not personal conversations.
Compliance roles don't prevent judgment failures. The girlfriend, in a senior ethics and compliance role at a U.S. subsidiary of Asahi Kasei Corp, was responsible for handling sensitive information. Her sharing of acquisition details, even indirectly, shows that knowing insider trading rules doesn't prevent lapses when personal excitement or trust override professional discipline. Those tasked with preventing violations may be uniquely positioned to commit them.
Circumstantial evidence builds enforcement cases. The SEC didn't need a direct recording of the girlfriend naming Calliditas Therapeutics. The complaint shows Tesfaye texted a family member about job interviews while on the phone with his girlfriend, then bought Calliditas shares the same day. Five days later, Asahi announced the acquisition, and shares jumped 70 percent. This timeline, along with their pattern of sharing career information, provided enough basis for enforcement. Your controls should account for what investigators can reconstruct, not just what you can prove internally.
Reputational damage exceeds financial penalties. Tesfaye paid $39,504 in total. The girlfriend's employment status is unclear, but the SEC complaint identifies her employer as based in Cary, North Carolina, where Veloxis Pharmaceuticals, an Asahi subsidiary, recently settled fraud charges. Whether Veloxis is involved or not, the optics are damaging: a compliance function that couldn't prevent information leakage from within its own ranks.
What This Means for Your Team
You can't firewall personal relationships, but you can acknowledge they exist. Most compliance programs treat confidentiality as a training topic and a signed acknowledgment, assuming professionals understand and follow the rules. This case shows that understanding rules and consistently applying them under social pressure are different skills.
The girlfriend knew insider trading law and handled sensitive information daily. Yet, she shared enough for Tesfaye to act on. This suggests your confidentiality controls need behavioral reinforcement, not just policy documentation.
Action Items by Priority
Revise confidentiality training to address social engineering and relationship dynamics. Standard insider trading training focuses on material nonpublic information and legal consequences. Add scenarios where employees face pressure from trusted individuals: a partner asking about work stress, a family member seeking career advice, a friend discussing industry news. Make it clear that even vague statements like "big things are happening" can create liability. Run these scenarios annually for anyone with access to M&A activity, financial results, or strategic initiatives.
Implement pre-clearance requirements for securities trading by compliance staff. If your compliance team has access to material nonpublic information, require them to submit trading requests through your legal or HR function before executing. This creates a documented approval trail and forces a pause between intent and action. The pause is crucial for reconsidering whether they possess information that should prevent the trade.
Conduct periodic reviews of trading activity for employees in sensitive roles. You likely monitor executive trading under Section 16 of the Securities Exchange Act. Extend that monitoring to compliance officers, internal auditors, legal staff, and anyone involved in M&A due diligence. Flag trades in companies your organization is evaluating, negotiating with, or preparing to announce. Investigate timing patterns where trades occur shortly before public announcements. This won't prevent all violations, but it creates deterrence and demonstrates oversight to regulators.
Document confidentiality expectations in employment agreements for compliance roles. Include specific language about handling material nonpublic information and the duty to maintain confidentiality even in personal relationships. Reference the potential for SEC enforcement and the fact that settlements require disgorgement plus penalties. Make it clear that compliance roles carry heightened obligations and that violations will result in termination and referral to authorities. This documentation supports both internal discipline and external enforcement.
Review your whistleblower hotline procedures for reporting suspected insider trading. Employees who observe colleagues making unusual trades or discussing confidential information in inappropriate settings need a clear path to report concerns. Your Whistleblower Hotline should explicitly cover securities violations and provide Retaliation Protection. Train managers to escalate trading-related reports immediately to legal counsel, not to investigate them internally.





