Atlas
  • All-in-one
  • Solutions
  • Compare
  • Pricing
PricingGet started
  1. Atlas
  2. Guides
  3. Information Barriers: How a Firm Acts for Both Sides Lawfully
August 30, 2026·11 min read·information barriers, conflicts of interest, compliance, professional services

Information Barriers: How a Firm Acts for Both Sides Lawfully

An information barrier is a promise that two teams in the same firm cannot learn what the other knows. It is only worth as much as its weakest practical control.

Firms grow into conflicts. A practice that advises one party in a sector will eventually be asked to advise another, and the question becomes whether the firm can act for both without compromising either. An information barrier, sometimes called an ethical wall, is the mechanism that makes this possible where it is permitted at all.

The concept is simple and the implementation is where firms fail. A barrier described in a memorandum and contradicted by a shared folder is not a barrier; it is a document that will be produced in evidence to demonstrate that the firm knew what was required and did not do it.

When a barrier is sufficient, and when it is not

Not every conflict can be managed. Where the same team would have to act against its own advice, or where the professional rules of the relevant jurisdiction prohibit acting for both parties in the matter, the answer is to decline rather than to build a wall. Barriers manage the risk of information flowing where it should not; they do not cure a fundamental conflict of duty.

Where a barrier is appropriate, informed consent from both clients is usually required or advisable, and it should be genuine: a client who is told the firm also acts for the other party, and what protections exist, is in a position to consent. A consent buried in standard terms is unlikely to be worth much if it is ever tested.

What a barrier that holds actually requires

  • Separate teams, with a documented list of who is inside each and a rule about who may join. People move between engagements, and a barrier is breached most often by a transfer nobody flagged.
  • Access controls in the systems where the work lives, applied at the level of the matter rather than the department, and defaulting to deny. If the control is that people are asked not to look, there is no control.
  • Physical and logical separation of documents, including drafts, working papers, correspondence and any shared drive that predates the barrier.
  • Supervision arrangements that do not require a single individual to oversee both sides, which is the failure mode most often discovered after the fact.
  • A record of the barrier: when it was raised, who authorised it, who is inside, and what the clients were told.
  • Training for the people inside it, because a barrier maintained by people who do not understand its boundaries fails at the first casual conversation.

The failure modes

The most common breach is not deliberate. It is a person added to a distribution list, a document filed in a shared location out of habit, a search facility that indexes both matters, or a colleague asked an informal question at lunch. Each is unremarkable in isolation and each destroys the barrier.

The second is temporal. Barriers are raised when the conflict is noticed, which may be after material has already been shared. The remedy is to check what already exists before declaring a barrier effective, and to record the position honestly if some crossover has already occurred.

The third is the audit trail. A firm that cannot demonstrate who accessed what is unable to prove the barrier held, which in a dispute is close to being unable to prove anything. Access logging is therefore part of the control rather than an optional refinement.

Testing it rather than assuming it

A barrier should be tested the way any other control is tested. Take a person from one side and confirm that they cannot reach a document from the other, through every route the firm's systems provide: direct navigation, search, a shared link, a report, an export, and any integration that moves data elsewhere.

Search and reporting are the routes most often missed, because access is usually configured on the primary interface and inherited imperfectly by everything else. A barrier that holds in the document library and leaks through a search index is not a barrier, and the only way to know is to try it.

Keep reading

  • Building a Delivery Playbook Your Firm Will Actually Use
  • Building a Rate Card That Holds Up in Negotiation
  • Client Onboarding for Advisory Firms: The First Two Weeks
  • Engagement Acceptance: What to Check Before the First Billable Hour
  • How to Close an Engagement Properly
  • Managing Subcontractors and Flow Down Obligations
  • Free PDF tools
  • The all-in-one work OS

FAQ

Questions, answered.

What is an information barrier in a professional services firm?
An information barrier, also called an ethical wall, is a set of controls preventing confidential information held by one team from reaching another team in the same firm acting for a party with opposing interests. It combines separate teams, deny-by-default access controls at the matter level, document separation, independent supervision, a documented record and access logging.
When is an information barrier not enough to manage a conflict?
Where the same team would have to act against its own advice, or where the professional rules of the relevant jurisdiction prohibit acting for both parties in that matter. Barriers manage information flow; they do not cure a fundamental conflict of duty, and in those cases the correct answer is to decline the work.
How do information barriers usually fail?
Rarely by deliberate breach. Typically through a person added to a distribution list, a document filed in a shared location out of habit, a search index that spans both matters, an informal conversation, or a barrier raised only after material had already been shared. Without access logging, a firm also cannot demonstrate that the barrier held.
How do you test that an information barrier works?
Take a person on one side and attempt to reach the other side's material through every available route: direct navigation, search, shared links, reports, exports and any integration that moves data outside the system. Search and reporting are the routes most often overlooked, because permissions configured on the main interface are frequently inherited imperfectly elsewhere.

Ready when you are

One workspace, not ten.

Atlas replaces the stack with one platform for tasks, projects, CRM, contracts, e-signature, PDF tools, and analytics. Start free.

Get started freeSee pricing
AtlasWork, planned itself.

The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

All systems operational
  • SOC 2 II
  • ISO 27001
  • HIPAA
  • GDPR

Product

  • Overview
  • PDF tools
  • Diagram tools
  • People & HR
  • Integrations
  • Marketplace
  • Pricing

Resources

  • Guides
  • Glossary
  • Compare
  • Docs
  • API reference
  • Support
  • Changelog
  • Status

Company

  • About
  • Careers
  • Press
  • Contact

Legal & trust

  • Trust center
  • Security
  • Privacy
  • Terms
  • DPA
  • GDPR
  • SLA
  • Refunds
  • Google API data
Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
PrivacyTermsSecurityStatus