Compliance & Quality

Compliance proven through 20+ years serving the most demanding asset managers.

Every engagement adheres to these institutional standards when appropriate. Research is scoped, sourced, reviewed, and documented before it reaches a client.

01
Detection and avoidance of MNPI
02
Compliance with FCRA and with global privacy standards (GDPR)
03
Multi-layer QA on every project
MNPI Protection

Layers of protection against inadvertent MNPI.

Protecting clients from the inadvertent receipt of material non-public information is the purpose the research process is built around.

01
Sourcing is the first line of defense — appropriate Sources only, and compliant outreach
02
Researchers and AI interviewers are trained on how interviews are to be conducted
03
Pre-call confirmations are made with every Source and documented
04
Post-interview risk-based review, assisted by AI, covering MNPI, anonymization and defamation
05
A compliance read, with a formal internal escalation path for anything sensitive. Content is delivered only once the review is satisfied
Before Every Interview

What every Source confirms before the call.

01
Heron introduces itself and the scope of the research. A client is never identified
02
The Source is told that Heron does not want MNPI and will not knowingly accept it
03
The tenure rule is confirmed. Heron’s standard is six months since departure from a subject company
04
The Source confirms that nothing will be shared in violation of an NDA or any other duty
05
Consent to record is requested, and the confirmations are documented in our project system
Source Anonymity

What we protect, and what we do not promise.

01
The Sources of all interviews are anonymized
02
Personally identifiable information about secondary individuals mentioned in an interview is redacted
03
Client contracts prohibit clients from reverse-engineering or contacting our Sources
04
Anonymity is protected by best efforts. Heron does not guarantee it and does not conduct off-the-record interviews
Artificial Intelligence

How AI is used, and how it is governed.

01
Whether a call is researcher-led or AI-led is disclosed to the Source in the outreach
02
AI interviewers work from human-reviewed question sets within defined guardrails, and are not directed to ask about future performance
03
Transcription, editing and review are AI-assisted; responsibility for the accuracy and compliance of the output stays with people
04
Only enterprise-licensed models are used, and client data, prompts and outputs are not used to train third-party models
05
A formal Artificial Intelligence Use Policy applies to employees, contractors and third parties acting for the firm
Firmwide Programs

The programs behind the process.

01
Compliance training at onboarding and approximately quarterly thereafter, with annual MNPI training
02
FCRA: US pre-employment work is a consumer report, and consent and disclosure rules are applied accordingly
03
Privacy: GDPR “Legitimate Business Purpose” standards applied universally, and requests not to be contacted are honored
04
Cybersecurity: single sign-on and multi-factor across platforms, encrypted company-issued devices, quarterly training
05
Insurance: directors and officers, professional liability and errors and omissions, cyber and privacy, umbrella
06
External counsel retained across SEC and regulatory, employment and FCRA, privacy and data protection, and cybersecurity

Two compliance overviews — the firmwide Compliance Policies & Operating Procedures, and an abbreviated overview specific to Heron Events — are available to clients and prospective clients on request.

Make capital decisions with clarity.

Whether you need a due diligence project, access to transcripts, or a platform demonstration, our team will respond quickly.

Talk to our team

Media inquiries, please email media@heron-intelligence.com.