Board Meetings
Managing confidentiality and information flow during M&A

In an M&A process, information is both the raw material and the largest single source of risk. The same documents that let a board evaluate a deal can, in the wrong hands or released at the wrong moment, collapse it. A leaked approach moves the target's share price and hands leverage to the other side. A poorly managed insider list becomes a regulatory problem. A confidential document that reaches a party it should not becomes a liability that outlives the transaction.
For a board that acquires only occasionally, this can be treated as an exceptional situation, managed with heightened care for the duration of one deal. For a board running an ongoing acquisition programme, that approach does not hold. Confidentiality cannot be reinvented each time a deal appears, because the point of greatest exposure is precisely the early, informal phase before bespoke controls are in place. The acquirer on its eighth deal should have a standing information-governance model that switches on the moment a target is identified. Most rebuild it deal by deal, and the gaps between deals are where leaks happen.
This makes information management a board-level concern, not a purely administrative one. The board and the Company Secretary are responsible for the integrity of the process and for meeting the legal obligations that attach to inside information. This article sets out the key risks and the governance practices that contain them, as a repeatable capability rather than a one-off effort.
The broader question of how a board oversees a deal, and where its leverage sits across the whole process, is covered in our article on the board's role in M&A. This piece focuses specifically on information and confidentiality.
In this article:
- The three information risks that most often compromise a deal: premature disclosure, insider information, and document security across parties
- Three practices that turn confidentiality into a repeatable governance capability rather than a scramble
- Why the early, informal phase of a deal carries the most risk, and how to close it
- What the board and Company Secretary each own in managing information flow

The key risks around confidentiality in deal processes
Three risks account for most of the damage: premature disclosure, insider-information failures, and weak document control across parties. They compound the more parties a deal involves and the longer it runs, which is why they are harder to manage in an active programme than in a single transaction.
Premature disclosure and market sensitivity
Where a party to the deal is publicly listed, the existence of a live approach is usually price-sensitive, and premature disclosure has direct consequences: a moved share price, a strengthened counterparty, an emboldened competitor, or a regulator asking questions.
The regulatory framework here is also shifting, which is worth the board's attention. Under a reform to the EU Market Abuse Regulation taking effect in June 2026, issuers in a protracted process such as a merger will generally need to disclose only the final event rather than each intermediate step, which changes the timing calculus around a deal. What does not change is the obligation to control the information in the meantime and to maintain an insider list while it remains confidential. The board's practical job is to ensure a clear, agreed position on what is disclosed, when, and by whom, decided in advance rather than under pressure when a leak forces the question.
Insider information and trading restrictions
Once a deal constitutes inside information, everyone who holds it carries legal obligations, and the company carries the obligation to know who they are. This is where informal information flow becomes a compliance exposure rather than merely a risk to the deal.
The board and Company Secretary need confidence on three points:
- Who is on the insider list, that it is accurate, and that it is updated as people are added or removed
- That everyone with access understands their obligations, including the restrictions on trading in the relevant securities
- That the company can demonstrate, after the fact, who had access to what and when, because that audit trail is what a regulator will ask for
The third point is the one that quietly fails when deal information moves by email and informal conversation. A board cannot reconstruct an accurate access record from an inbox, and in an active programme, where the same people move between deals, the record has to be maintained per deal rather than in general.
Document security across multiple parties
A deal pulls in advisers, legal counsel, the counterparty, and internal teams who were not previously in scope, and the volume of sensitive material moving between them is high. Every one of those handoffs is a point where a document can reach someone it should not, and the risk is rarely a dramatic breach. It is the mundane failure: a reply-all, a forwarded attachment, a document left accessible after someone's role in the deal has ended.
The deal profession itself now ranks security at the top of what it demands. In Datasite's 2026 survey of 1,000 dealmakers, conducted with FT Longitude, security and accuracy were the two most important attributes dealmakers wanted when completing tasks across the deal lifecycle, ahead of speed. That order of priorities is the right one for a board to adopt: in information management, a fast process that leaks is worse than a controlled one that takes an extra day.
3 ways to set up effective information governance for M&A
The three practices below turn confidentiality from something a board hopes goes well into something it has designed. Set up once, they apply to every deal in a programme.
1. Define who has access to what, and when
The default in many organisations is that the board, as a body, sees board material. In a deal, that default is wrong. Access should be scoped to the specific individuals who need a given document for their role in the transaction, and it should change as the deal moves.
In practice this means:
- Access granted at the level of the individual director or a subcommittee, not the board as a standing group, so that a director recused for a conflict does not receive material they should not see
- Access that can be adjusted and revoked as roles change, without reissuing documents or hoping an email is not forwarded
- A clear, current record of who can see what, which doubles as the audit trail the insider-information obligations require
Defining this once, as a standing model that applies whenever a deal begins, is what closes the early-phase gap. The alternative, configuring access afresh under time pressure each time, is how the wrong person ends up on a distribution list.
2. Establish clear protocols for board communications
Most confidentiality failures are not sophisticated. They are ordinary communication habits applied to information that cannot tolerate them. A protocol agreed in advance removes the improvisation.
The protocol should establish where deal discussion happens and where it does not, that sensitive material is never circulated by personal email or consumer messaging, how decisions are taken between formal meetings when a deal moves faster than the board calendar, and who is authorised to speak for the board externally. None of this is complex. Its value is that it exists before the deal, so that under pressure people follow a defined process rather than reaching for whatever is convenient.
3. Only use secure, auditable platforms for document sharing
The single most consequential decision in deal-information management is where the information lives. Email is the default and the worst option: it cannot enforce access controls, cannot be revoked, cannot track who has seen what, and cannot produce the audit trail that inside-information obligations require. A confidential deal run over email is a process the organisation cannot actually account for.
A secure, purpose-built platform changes the picture, and it is worth noting that the governance stage of the deal is where controlled tools are least embedded. The same Datasite research found that board reporting and governance is the least digitised stage of the deal lifecycle, with a substantial share of dealmakers using no structured tooling there at all. That is precisely the gap a board should close, because it is the stage where the record has to be strongest and where an audit will look first.
The requirements are specific: document-level controls over who can view, download, print, or forward; the ability to revoke access instantly; watermarking for the most sensitive material; and a complete, tamper-evident record of every action. These are not luxuries in a deal context. They are what allows a board to say, with confidence and evidence, that it controlled its information.
How board meetings carry the information-governance load
Information governance is enforced, or lost, in how board meetings themselves are run.
Route deal material through the secure channel, never around it. The moment one document goes out by email because it was quicker, the controls are gone and the audit trail has a hole. The discipline only works if it is absolute.
Check preparation before a deal meeting. Where key documents have not been read, decision quality suffers, and a deal decision taken by an underprepared board is both a governance risk and, if challenged later, a hard one to defend. If preparation is inadequate, postponing is the stronger choice. As Mark Williams, Chief Revenue Officer at Datasite Group, emphasized on Boardroom Confidential podcast: “You don’t always know what question you’re going to get, so you may get four or five questions, but you need to be prepared to answer over a hundred.”
Capture confidentiality decisions, not just deal decisions. Decisions about disclosure timing, communication restrictions, and who may speak externally are decisions in their own right. They should be recorded with named owners, so the protocol is documented rather than assumed.
Finalise and sign the minutes promptly. M&A minutes are legally significant. They should be finalised, approved, and signed without delay, producing a fixed record of what was decided that cannot be quietly revised afterwards.
Control the distribution of the minutes themselves. The record of a confidential deal is itself confidential. Its circulation should be restricted to authorised recipients, through the same controlled channel as the underlying material.
The test of good deal-information governance
Ask whether the board could produce, today, an accurate record of who has had access to a live deal's documents and when. Ask whether a document could be revoked from someone whose role in the deal has ended, in minutes rather than not at all. Ask whether the confidentiality protocol was agreed before the deal or is being worked out as it goes. If the honest answers involve an inbox and a hope, the board is exposed in exactly the way a regulator, or a leak, will find.
How Sherpany supports secure M&A information management
Everything above depends on the board holding its deal information somewhere it can actually control, rather than in the scattered channels a deal tends to spread across.
Sherpany consolidates M&A materials in one secure environment with granular, document-level access controls, so material can be restricted to specific directors or a subcommittee and adjusted as the deal moves, preventing the accidental exposure that email invites. The library's security settings govern who can download, print, or forward a document, with watermarking available for the most sensitive material, and every action leaves an auditable record, which is the trail that inside-information obligations require and that an inbox can never provide.
Because deals rarely wait for the board calendar, resolutions can be passed between meetings through a fully auditable digital approval process, so an urgent decision does not force the board into an insecure workaround. And board minutes, the legally significant record of what was decided, can be finalised and digitally signed to producehttps://sherpany.com/en/resources/board-role-in-m-and-a-oversight a fixed, tamper-evident record, then distributed only to authorised recipients through the same controlled channel.
For boards that want to understand the security standards a board platform should meet, Sherpany's Trust Center sets out its approach in detail. M&A oversight and board composition are two of the three areas examined in Sherpany's guide to strategic decision-making at mid-year.
Confidentiality is a capability, not a precaution
A board that treats each deal's confidentiality as a fresh exercise in care will, sooner or later, have the deal that leaks, because care does not scale and improvisation fails under pressure. The board that has designed its information governance once, as a standing capability that engages the moment a target is identified, has removed most of the risk before the deal begins.
That is the difference the programme view makes. For an occasional acquirer, information management is a precaution taken for the duration of a transaction. For an acquirer that runs a programme, it is a capability that either exists or does not, and the deals expose which it is. The practices are not difficult. What is difficult is deciding to build them before the deal that needs them, rather than after the one that exposed their absence.
If you would like to strengthen how your board manages confidentiality and information flow across its deals, book a free consultation today and find out how Sherpany can help.