Standard III(E) protects client confidential information. The default is simple: keep it private. The exam difficulty sits in three narrow exceptions and in the way local law can override your instinct to either stay silent or speak up. Most CFA® Level I scenarios ask you to decide whether disclosure is permitted, required, or forbidden, and to whom.
Quick Answer
Standard III(E) requires you to keep information about current, former, and prospective clients confidential. Three exceptions apply: the information concerns illegal activity by the client, disclosure is required by law, or the client permits it. Applicable law controls and may still require confidentiality even when a client's conduct appears illegal, so check the legal authority before disclosing anything.
Key Takeaways
Confidentiality is the default for current, former, and prospective clients alike.
Only three exceptions release you: client illegal activity, a legal requirement to disclose, or the client's permission.
Applicable law decides the outcome. It can require disclosure, permit it, or prohibit it, even where conduct looks illegal.
An exception permits only the relevant disclosure. It is never a license to share freely.
The duty does not end when the client leaves, and a common trap is assuming it does.
Cooperating with a CFA Institute investigation usually does not breach this duty.
What You Need to Know for CFA Level I
The duty covers information you receive through your professional relationship with a client that relates to the client's business or personal affairs.
Confidentiality continues after the relationship ends. There is no automatic expiry under the Standard.
Client permission has to be specific enough to define what may be shared and with whom.
If law requires disclosure, disclose only what is required. If law requires confidentiality, do not disclose just because conduct looks illegal.
Colleagues authorized and working for the client may receive necessary information, but casual internal sharing is not allowed.
Follow your firm's secure communication, storage, and device policies.
What Client Information Must Remain Confidential?
The Standard protects information you learn through the special relationship you have with a client. That includes personal and financial details, account and transaction data, identity, strategy, and information about prospective clients gathered during the relationship. The test is the source and the relationship, not whether the topic feels sensitive. Information that is already public does not become confidential just because a client happened to mention it to you.
What Are the Exceptions to Client Confidentiality?
Three exceptions, and only three, can release the duty.
Exception | What it means | What it allows |
|---|---|---|
Client illegal activity | The information concerns illegal activities by the client or prospective client | May permit disclosure, but applicable law still controls whether you may, must, or must not |
Legal compulsion | Disclosure is required by law, regulation, or valid legal process | Disclose only what the law requires, to the authority entitled to receive it |
Client permission | The client or prospective client authorizes the disclosure | Disclose only what the permission covers, to whom it names |
Even when an exception applies, it opens a door to the relevant disclosure, not to unrestricted sharing. When the application of law is uncertain, consult compliance or legal counsel before acting.

How Does Applicable Law Affect Disclosure?
This is where the analysis connects to Standard I(A): Knowledge of the Law. Law can require reporting, permit reporting, or prohibit disclosure outright. Suspected illegal activity does not, by itself, create a duty to tell an outside party. In some jurisdictions, voluntary disclosure would itself break the law. So the order matters: identify the protected information first, then find the legal authority, then limit any disclosure to the scope and recipient the law allows.
How Long Does the Duty of Confidentiality Last?
It continues for former clients and has no automatic end date under the Standard. A client who has moved on is still owed confidentiality for what you learned during the relationship. A former client can authorize disclosure, which releases the specific information covered by that permission. Separate rules on retaining or destroying records may come from law, regulation, or firm policy, but those are record-retention obligations rather than an expiry of the confidentiality duty.
How Should Confidential Information Be Shared Inside a Firm?
Only employees who are authorized and actually need the information to work for the client should receive it. Share the minimum necessary, through secure channels. A supervisor, a trusted colleague, a relative, a spouse, or an outside vendor does not get access just because you trust them. Where third-party service providers handle client information, confidentiality agreements and access controls should be in place so the duty travels with the data.
Vulnerable Investors and Secondary Contacts
Sometimes confidentiality runs into client protection. If you suspect diminished capacity or financial exploitation, staying silent and speaking up can both feel wrong. The cleaner path starts at account opening: establish a client-authorized secondary contact in advance. If a concern later appears, follow applicable law and firm procedures before making any limited disclosure, and document the concern, the consultation, the authorization, the recipient, and exactly what you shared.
Electronic Information and CFA Institute Investigations
Most accidental breaches are electronic, not deliberate. Email, personal devices, cloud storage, removable media, remote work, and a message sent to the wrong recipient all create exposure. The Standard does not require you to be an information-security specialist, but it does require you to understand and follow your firm's controls. Separately, members and candidates must cooperate with CFA Institute Professional Conduct investigations, unless applicable law prevents the disclosure.
Recommended Procedures for Compliance
These are recommended practices that support the Standard.
Use access controls and minimum-necessary permissions for client data.
Agree approved communication and storage methods with each client.
Train both investment and noninvestment staff who handle client information.
Set escalation procedures for legal requests, suspected illegal activity, vulnerable clients, and accidental disclosures.
Document every authorized or legally required disclosure.
Compliant Scenario
Situation. At account opening, a client named a trusted relative as an authorized secondary contact. Two years later, the adviser notices possible signs of financial exploitation.
Relevant issue. The adviser wants to protect the client without breaching confidentiality.
Correct action. The adviser follows firm procedure, consults compliance, confirms what local law permits, then makes a limited disclosure to the pre-authorized secondary contact covering only the relevant concern.
Why it complies. The prior authorization and the narrow scope keep the disclosure inside what the client allowed and what the law permits. Nothing beyond the specific concern is shared.
Violation Scenario
Situation. An adviser leaves a firm and, to impress a new employer, describes a former client's account history and strategy, believing the duty ended when the relationship did. The adviser leaves out the client's name but includes enough detail that the client is easily identifiable.
Violation. The duty did not end with the relationship, so former-client information is still protected. Removing the name does not help when the remaining detail identifies the person.
Required alternative. Describe general experience and skills without disclosing identifiable client information, or obtain the former client's specific permission first.
Why the original action fails. Confidentiality continues for former clients, and "anonymized" detail that still points to one person is not anonymous. The disclosure had no qualifying exception.
Common Exam Traps
Assuming confidentiality ends when the client leaves. It continues for former clients with no automatic expiry.
Treating suspected illegal activity as automatic permission or an automatic duty to report. You still have to check applicable law before disclosing.
Sharing with a trusted person who is not authorized. A spouse, relative, colleague, or supervisor needs authorization or a genuine business need.
Over-disclosing. Even with an exception, share only what the law, the authorization, or the protective purpose requires.
Believing cooperation with a CFA Institute investigation breaches the duty. It generally does not, unless applicable law prevents disclosure.
Ignoring electronic risk. Personal devices, cloud tools, and misaddressed messages cause accidental disclosures that the Standard expects you to guard against.
Practice Question
A former client is under investigation by a government agency. Local law prohibits the adviser from voluntarily disclosing client records without valid legal process. A regulator phones the adviser and informally asks to see the former client's file. What is the most appropriate action?
Provide the file, because the request comes from a regulator
Confirm the legal authority for the request and keep the information confidential unless disclosure is legally required
Refuse to engage with the regulator in any way and destroy the file
Correct Answer: B
The duty of confidentiality continues for former clients, and local law here prohibits voluntary disclosure. The correct step is to verify whether the request carries legal authority that requires disclosure. If it does, disclose only what is required. If it does not, the information stays confidential.
Option A is wrong because a regulator's informal request is not the same as a legal requirement to disclose, and applicable law here forbids voluntary disclosure.
Option C is wrong because refusing all cooperation and destroying records could obstruct a lawful process and breach record-retention obligations. The Standard asks for a measured legal check, not silence and shredding.
Continue Your CFA Level I Prep With KeyPoint
Use structured lessons, practice questions, mock exams, and progress tracking to focus on the time you have left
FAQs About Standard III(E): Preservation of Confidentiality
How long does the duty of confidentiality last?
It continues after the client relationship ends and has no automatic expiry under the Standard. Former clients are still owed confidentiality, although a former client can authorize disclosure of specific information.
Can a financial adviser disclose suspected client illegal activity?
Not automatically. Suspected illegal activity is one exception, but applicable law controls whether you may, must, or must not disclose. Check the legal authority and limit any disclosure to what the law requires.
Can client information be shared with colleagues inside the same firm?
Only with colleagues who are authorized and need the information to work for that client, and only the minimum necessary. Being trusted or senior is not the same as being authorized.