Skip to main content Skip to footer

Beyond the obvious: Why information barriers are important

Madeleine Porter

Legal Industry Expert (APAC), iManage

When most lawyers hear "information barrier" or "ethical wall," their minds jump straight to the textbook scenario: a sensitive IP dispute, a hostile takeover, a conflict between two current clients. And it's true: The duty of confidentiality that sits at the heart of legal practice, codified in instruments like Section 9 of the Australian Solicitors' Conduct Rules, Rule 6.3 of the Solicitors Regulation Authority, and Rule 1.6 of the American Bar Association's Model Rules, makes safeguarding client information a fundamental professional obligation.

But that's only the beginning of the story. In practice, information barriers are one of the most versatile and widely used risk management tools available to a modern law firm. The use cases extend far beyond the classic conflict scenario, touching everything from market abuse regulation to workplace psychological safety. Firms that treat information barriers as a narrow compliance checkbox are missing a much bigger opportunity to manage risk holistically.

The classic case: confidentiality and conflicts

The most familiar trigger for an information barrier is a straightforward confidentiality risk, such as a highly classified patent matter or advice on a hostile bid for a publicly listed company. From there, conflicts of interest form the next major category, and they are more nuanced than they first appear:

  • Confidential information conflicts. This is where one matter team holds information materially relevant to another client's matter, even without direct adversity between the two.

  • Former-client conflicts. This involves rules such as Rule 10 of the Australian Solicitors' Conduct Rules (and its SRA equivalent), which permit a firm to act despite holding confidential former-client information, provided consent is obtained and an effective barrier is in place.

  • Perceived conflicts. This is a client relationship issue (also known as a commercial conflict) in which no real conflict exists, but client optics demand a barrier as reassurance. This is surprisingly common in practice, and some clients will refuse to brief and open matters with lawyers unless a wall is in place.

  • Current-client conflicts. This is the most common type of conflict and is managed differently across jurisdictions; Australia's so-called "Aussie exemption" allows a firm to act for two clients with adverse interests where both consent is given and an effective wall is maintained, a concept mirrored in the UK for common-interest and competing-objective scenarios.

Because of the doctrine of imputed conflicts, in which one lawyer's conflict can be attributed to the entire firm, a properly maintained information barrier is often the mechanism that allows a firm to keep acting at all, rather than losing the matter entirely.

The regulatory and market-sensitive layer

Some of the highest-stakes use cases sit at the intersection of legal ethics and financial regulation. Matters that are price-sensitive or fall under the Market Abuse Regulation or The Corporations Act 2001 (Cth) need airtight barriers, as a leak here isn't just a confidentiality breach; it's a potential insider-trading violation carrying civil or criminal exposure for both the firm and individual lawyers. A firm advising a listed company on CEO succession or a corporate demerger is a textbook example, and ties directly into insider list obligations under UK MAR.

Jurisdictional and regulatory structuring adds another layer. International firms operating across multiple jurisdictions often need to segregate matters to comply with local rules on reserved legal work. Singapore and South Korea are common examples, requiring only locally qualified practitioners to handle certain matters. The same logic applies to firms operating through joint ventures overseas, where barriers prevent cross-contamination between the JV and the wider firm.

Multidisciplinary practices face a related challenge: As firms expand into consulting and advisory arms alongside traditional legal services, barriers become essential to preserving privilege and, in some regulatory environments such as the UK, to satisfying requirements that legal and non-legal arms operate as genuinely separate entities.

The people-driven risks

Several of the most operationally important use cases have nothing to do with the matter itself and everything to do with the people involved:

  • New starters awaiting completion of background checks may need restricted access to client information until clearance is finalised, a surprisingly common scenario that firms often under-manage.

  • Secondees retaining access to firm systems while on client placement need barriers around matters that could create a conflict with their secondment.

  • Reverse secondees — a rarer scenario in which client staff embedded within the firm for training — present a heightened risk. A firm hosting a secondee from one beverage company, for instance, would need to wall off all work for that company's direct competitors to prevent inadvertent access.

Governance, investigations, and compliance obligations

Information barriers also play a quiet but critical role in a firm's internal governance machinery:

  • AML tipping-off risk arises where a lawyer suspects a client of money laundering and must report to the firm's MLRO; both the underlying suspicion and the MLRO's resulting investigation file need to sit behind a barrier.

  • Whistleblower matters require the same isolation and sensitivity around internal access and monitoring.

  • Data loss prevention investigations — as firms increasingly monitor for unauthorised access or removal of client material, any resulting investigation needs to be handled confidentially and separately from business as usual.

  • Probity plans, common in government and public procurement work, formalise barriers as a condition of a firm acting for multiple parties in a process, often requiring signed confidentiality deeds, mandatory training, and strict rules against staff moving between "sides" of a matter. Breach of these barriers can constitute a material breach of the probity arrangement itself, with real revenue consequences if a client withdraws instructions.

The human dimension: psychological safety and vulnerable clients

Two use cases stand out because they protect people rather than information alone.

Matters involving children demand heightened barriers given the vulnerabilities involved, the obligation to act in a child's best interests, and the web of child welfare, juvenile justice, and family law statutes that govern how their information is handled.

Psychologically distressing matters — a sexual abuse case, for example — increasingly require barriers not just to protect confidentiality, but to meet employers' statutory obligations to protect staff from psychological hazards at work, an obligation now explicit in jurisdictions like Australia. Here, the barrier controls not just who can see the file, but who is trained and prepared to view it.

Why this matters for risk management

Taken together, these use cases reveal something important: information barriers are not a single-purpose conflicts tool. They are a flexible risk control that sits at the intersection of:

  • Professional and ethical obligations (confidentiality, conflicts, privilege)

  • Financial and market regulation (MAR, listing rules, insider trading)

  • Data governance and cybersecurity (DLP, access controls, regulatory expectations)

  • People risk (new starters, secondees, background checks)

  • Client relationship management (client-requested walls, commercial conflicts)

  • Workplace safety and wellbeing (psychological hazards, vulnerable client matters)

  • Formal governance arrangements (probity plans, AML reporting, whistleblowing)

For firms, the risk management implication is clear: Information barrier capability shouldn't be treated as a niche conflicts-clearance function bolted onto a matter opening process. It needs to be embedded as core infrastructure, technically enforced, properly resourced, and understood across the firm as a tool that manages far more than the obvious conflict scenario. Firms that only reach for information barriers in the classic cases leave significant categories of risk, including regulatory, reputational, and human, unmanaged, and the firm is exposed to reputational, professional, and financial exposure.

Madeleine Porter

Legal Industry Expert (APAC)

Madeleine Porter, Legal Industry Expert (APAC) at iManage, combines her background as a practicing lawyer with deep expertise in legal technology to guide firms across the Asia-Pacific region through the evolving landscape of AI adoption and operational transformation. Known for her candid insights and global perspective, Madeleine leads thought leadership initiatives that explore the lawyer’s experience with AI—its practical applications, ethical considerations, and strategic impact.