← Back to Knowledge Hub

Your company secretary runs the filings. Regulation 9A puts the internal controls on the CEO or MD by name. That is not a distinction the compliance team can fix for you.

Regulation 9A: the Chief Executive Officer, Managing Director or analogous person must put in place adequate and effective internal controls to prevent insider trading. The Audit Committee must verify, at least annually, that they are operating effectively.

Most founders meet the PIT Regulations through a policy document circulated after listing and a quarterly email telling them the trading window is shut. That framing is dangerously incomplete. The regulations impose obligations at three levels β€” on the company, on the CEO/MD personally, and on you as a designated person β€” and they fail in different ways.

The company-level failures are usually procedural and survivable. The personal ones are not. When SEBI examines a leak, it asks who was responsible for the system that failed, and Regulation 9A answers that question in advance with a job title. Meanwhile every promoter, director and KMP is separately exposed under Regulation 4 for their own trades, and under the Code of Conduct for their immediate relatives' trades.

This is a build guide, not a summary of the law. Nine systems, what each must actually do, and where they break.

BOTTOM LINE

  • You personally own the controls. Regulation 9A names the CEO/MD/analogous person β€” not the compliance officer β€” as responsible for internal controls.
  • The Audit Committee must verify annually that those controls are adequate and operating effectively, and that verification is minuted.
  • The SDD cannot be outsourced. It must be maintained internally, time-stamped, non-tamperable, audit-trailed, preserved 8 years.
  • Certification is now external. Since the October 2024 exchange circulars, SDD compliance is confirmed in the Annual Secretarial Compliance Report or via a PCS-certified SDD certificate within 60 days of financial year end.
  • Your relatives are your exposure. Immediate relatives' trades run through the same window, pre-clearance and disclosure rules.

System 1 β€” The UPSI identification matrix

Governs this section: Regulation 2(1)(n), PIT Regulations, 2015 (as amended, effective 10 June 2025)

Everything downstream depends on correctly answering "is this UPSI?" β€” and since the 2025 amendment expanded the illustrative list from five categories to sixteen, the old instinct is unreliable.

What to build: a written matrix mapping each of the sixteen categories to (a) the internal function that first learns of it, (b) the trigger point at which it becomes UPSI, and (c) the named person who must notify the compliance officer. Fund-raising decisions sit with the CFO. Forensic audit initiation sits with the Audit Committee chair. Licence suspensions sit with the plant or regulatory head. Third-party guarantees sit with treasury.

Where it breaks: the events that feel operational. A licence suspension notice lands with a factory manager who has never read the PIT Code and files it as a regulatory matter. Nobody tells the compliance officer for eleven days. The window stayed open, three designated persons traded, and the company now has a reportable violation plus a SEBI file.

CAUTION β€” the "not UPSI" decision needs a paper trail

Deciding that something is not UPSI is a judgment call that SEBI will review with hindsight and a share-price chart. Record the reasoning at the time, dated, with who decided. A contemporaneous note explaining why a contract loss was immaterial is a defence. The same explanation constructed after a SEBI summons is not.

System 2 β€” The Structured Digital Database

Governs this section: Regulations 3(5) & 3(6), PIT Regulations, 2015; BSE/NSE circulars dated 18 October 2024

The SDD is the first document SEBI requests in any investigation, and it is where most listed companies are quietly non-compliant.

Hard requirements: maintained internally β€” it cannot be outsourced; capturing the nature of the UPSI and the name, PAN or other legally authorised identifier of every person who shared it and every person who received it; with time-stamping, audit trails and non-tamperable architecture; preserved at least 8 years after completion of the relevant transactions, and until proceedings conclude if SEBI has notified an investigation. Since the 2025 amendment, UPSI received from outside the company must be entered within 2 calendar days of receipt.

What this rules out: spreadsheets. An editable Excel file has no audit trail and no non-tamperable property, and SEBI inspections specifically test whether audit logs can be produced. If your SDD is a shared workbook, you do not have an SDD.

The certification layer: following the BSE and NSE circulars of 18 October 2024, entities to which Regulation 24A of the LODR applies confirm SDD compliance within the Annual Secretarial Compliance Report. Entities outside Regulation 24A β€” including SME-platform companies, REITs, InvITs and exclusively debt-listed entities β€” must file an SDD Compliance Certificate from a Practising Company Secretary within 60 days of the financial year end. Non-compliant entities file quarterly PCS certificates until they comply, and the exchanges publish non-compliance status.

Where it breaks: retro-fitting. Entries made in a batch three weeks later are visible in the audit trail as exactly that, and a back-dated SDD is materially worse than an incomplete one β€” it converts a control failure into a credibility failure.

System 3 β€” The designated persons register

Governs this section: Regulations 9 & 9A(2), PIT Regulations, 2015

Regulation 9A requires that all employees with access to UPSI are identified as designated persons. This is a live register, not an annexure drafted at listing.

What to build: a register covering promoters, directors, KMP, and every employee whose functional role gives UPSI access β€” plus their immediate relatives, since the Code's trading restrictions extend to them. It must update on every appointment, resignation, role change and relative-status change (marriage, a spouse taking a broking account), and it should carry PAN details, because the SDD and Regulation 7 disclosures need them.

Where it breaks: the register drifts. A finance manager promoted into the results-preparation team eighteen months ago was never added. She trades in a closed window in perfect good faith. The company's defence β€” that she wasn't on the list β€” is the admission, not the answer: Regulation 9A required her to be identified.

System 4 β€” Trading window governance

Governs this section: Regulation 9 read with Schedule B, PIT Regulations, 2015

The mandatory closure: from the end of every quarter until 48 hours after the declaration of financial results. Note both ends β€” the window shuts at quarter-end, not at the board meeting, and reopens 48 hours after dissemination, not at announcement.

Event-driven closures: any other UPSI crystallising mid-quarter closes the window for those who can reasonably be expected to possess it. The 2025 amendment gave compliance officers flexibility where UPSI originates externally and designated persons are unlikely to hold it β€” useful, but exercise it in writing with reasons.

What to build: automated notifications at closure and reopening, an acknowledgement trail, and a standing calendar entry so nobody relies on someone remembering to send the email.

Where it breaks: the reopening. Teams reliably shut the window and unreliably wait the full 48 hours. Counting from the wrong event β€” board approval rather than exchange dissemination β€” is the most common technical breach in the whole regime.

System 5 β€” Pre-clearance

Governs this section: Schedule B, PIT Regulations, 2015

Trades above a company-set threshold require prior approval, supported by an undertaking that the person possesses no UPSI, and typically executed within 7 days of approval or the approval lapses.

What to build: a request form capturing quantity, expected value and the no-UPSI declaration; a compliance officer approval log; execution confirmation; and an automatic check against the contra-trade history before approval is granted.

Where it breaks: the undertaking is treated as a formality. It is signed evidence. A designated person who signs "I possess no UPSI" and then trades on information they did hold has converted a regulatory contravention into a documented false declaration.

System 6 β€” Contra-trade monitoring

Governs this section: Schedule B, PIT Regulations, 2015

No opposite transaction within 6 months of an earlier trade by a designated person. Profits from violative contra-trades are disgorged to SEBI's Investor Protection and Education Fund.

What to build: a rolling six-month ledger per designated person, checked automatically at the pre-clearance stage rather than discovered afterwards.

Where it breaks: ESOPs. A KMP exercises options and sells the resulting shares four months after buying shares in the open market. The exercise may be exempt; the sale is a contra-trade against the earlier purchase. This single fact pattern accounts for a large share of code violations reported to the exchanges.

System 7 β€” Disclosure discipline

Governs this section: Regulations 6 & 7, PIT Regulations, 2015

  • Initial disclosure: holdings disclosed within 7 days of appointment as director/KMP or of becoming a promoter.
  • Continual disclosure (Reg 7(2)): every trade β€” or series of trades in a calendar quarter β€” exceeding β‚Ή10 lakh in value must be disclosed by the designated person to the company within 2 trading days, and by the company to the exchanges within 2 trading days of receipt.

Where it breaks: aggregation. The threshold is cumulative across the quarter, not per transaction. Four purchases of β‚Ή3 lakh each cross β‚Ή10 lakh, and the clock ran from the trade that crossed it. Founders who trade in tranches miss this routinely.

System 8 β€” Trading plans, for those who are always inside

Governs this section: Regulation 5, PIT Regulations, 2015 (as amended 2024)

If you are a promoter or CXO with near-permanent UPSI access, the practical reality is that you can rarely trade cleanly. The trading plan is the designed solution: pre-commit to trades, have the plan approved by the compliance officer and disclosed to the exchanges, then let it execute regardless of what you subsequently learn.

Following SEBI's 2024 rationalisation, the cool-off between disclosure and implementation is 120 days (reduced from six months), the blanket black-out around results was removed, and planners may set optional price limits within a Β±20% band.

The trade-off: once set, the plan must be implemented. You cannot suspend it because the price moved against you. That irrevocability is precisely what makes it a defence.

Where it breaks: treating it as optional timing. A plan abandoned mid-course invites the inference that the abandonment itself was informed.

System 9 β€” Institutional mechanism, whistle-blower policy and the annual review

Governs this section: Regulation 9A, PIT Regulations, 2015

This is the system that names you.

Regulation 9A(1)–(2): the CEO, MD or analogous person must put in place adequate and effective internal controls β€” identifying all UPSI-access employees as designated persons, defining what constitutes UPSI, restricting its communication, and serving notice on or obtaining confidentiality agreements from recipients.

Regulation 9A(4): the Audit Committee (or analogous body) must review compliance at least once every financial year and verify that internal controls are adequate and operating effectively.

Regulation 9A(5): written policies and procedures for inquiry into any leak or suspected leak of UPSI, with findings informing SEBI promptly.

Regulation 9A(6): a whistle-blower policy, with employees made aware of it, enabling them to report UPSI leaks.

Where it breaks: the annual review becomes a tabled agenda item with no testing behind it. If the Audit Committee minute records "reviewed and found adequate" with no evidence of sample testing β€” no SDD entries examined, no window closures traced, no pre-clearance files pulled β€” then the verification required by 9A(4) did not meaningfully happen. Build the review as an actual audit: sample five UPSI events, trace each through identification, SDD entry, window closure and pre-clearance refusals, and minute the findings including exceptions.

PRACTITIONER'S NOTE β€” what SEBI actually asks for

In an investigation the sequence is predictable: the SDD extract, the designated persons register as it stood on the relevant date, the trading window closure notices with acknowledgements, the pre-clearance file, and the Audit Committee minutes evidencing the 9A(4) review. If those five documents are complete, contemporaneous and consistent with each other, most matters resolve at the explanation stage. If they contradict each other, the inconsistency becomes the case.

Worked example

Mini-case β€” the founder who did everything right and still nearly failed

A listed SaaS company's founder-MD learns on 8 September that a strategic investor is exploring a stake purchase that would impact control. Under the post-2025 list, "agreements which may impact management or control" is a named UPSI category.

What the systems do: the founder notifies the compliance officer the same day (System 1 matrix β€” control-impacting agreements sit with the MD). The SDD entry goes in that day with the names and PANs of the four people aware, and the investor's banker is logged as an external recipient (System 2). The compliance officer closes the trading window for those four (System 4) and issues a confidentiality notice to the banker (System 9).

Where it nearly failed: the founder's brother β€” an immediate relative on the designated persons register (System 3) β€” had a pre-clearance request pending from 5 September to sell β‚Ή18 lakh of shares. It was approved on 6 September, valid for 7 days. He had not yet executed. The compliance officer, checking the register against the new window closure, revoked the approval on 8 September before execution.

Had that revocation not happened, the sale would have completed on 9 September, crossed the β‚Ή10 lakh Reg 7(2) threshold, occurred inside a window closed for UPSI the relative was presumed to share, and left the company reporting a code violation while both brothers explained a suspiciously well-timed exit to SEBI. The system that saved them was not the policy document β€” it was one person checking a live register against a live closure.

Common mistakes

  1. Believing the compliance officer owns the controls. Regulation 9A names the CEO/MD.
  2. Running the SDD on a spreadsheet. No audit trail, no non-tamperable property, no compliance.
  3. Outsourcing the SDD. Expressly not permitted β€” it must be maintained internally.
  4. A designated persons register that never updates after role changes or changes in relatives' circumstances.
  5. Reopening the window at announcement rather than 48 hours after dissemination.
  6. Missing ESOP contra-trades against open-market purchases in the preceding six months.
  7. Treating the β‚Ή10 lakh disclosure threshold as per-trade rather than aggregated across the calendar quarter.
  8. An Audit Committee "review" with no testing behind the minute.
  9. No contemporaneous record of "not UPSI" decisions.
  10. Assuming relatives are outside the perimeter. They are inside it, and their trades are attributed to you in practice.

Checklist

  1. Map all sixteen UPSI categories to owning functions and named notifiers; publish the matrix internally.
  2. Deploy an SDD with time-stamping, audit trails and non-tamperable architecture, maintained internally; log external UPSI within 2 calendar days.
  3. Confirm the correct certification route β€” ASCR (Reg 24A entities) or PCS certificate within 60 days of year-end.
  4. Maintain the designated persons register live, with PANs and immediate relatives; reconcile quarterly against HR records.
  5. Automate window closure and reopening notices; count the 48 hours from exchange dissemination.
  6. Enforce pre-clearance with a no-UPSI undertaking, 7-day validity and an automatic contra-trade check.
  7. Run a rolling six-month contra-trade ledger per designated person, including ESOP activity.
  8. Calendar Reg 7(2) disclosures on a cumulative quarterly basis, not per trade.
  9. Use trading plans for perpetual insiders; honour them once set.
  10. Conduct the Regulation 9A(4) Audit Committee review as a tested audit, minuting samples and exceptions.
  11. Maintain and publicise the whistle-blower policy; document any leak inquiry.
  12. Preserve the SDD for 8 years, longer if SEBI notifies proceedings.

FAQ

Who is personally responsible for PIT internal controls? Regulation 9A places this on the Chief Executive Officer, Managing Director or analogous person β€” not the compliance officer, who administers the Code under Regulation 9.

Can we outsource the SDD to our RTA or a vendor? No. It must be maintained internally with adequate internal controls, though software may be used to maintain it internally.

Is an Excel-based SDD acceptable? In practice, no. The regulation requires time-stamping, audit trails and non-tamperable capability, and SEBI inspections test whether audit logs can be produced.

How do we certify SDD compliance? Entities covered by Regulation 24A of the LODR confirm it in the Annual Secretarial Compliance Report; others file a PCS-certified SDD Compliance Certificate within 60 days of the financial year end, and quarterly if non-compliant.

Do my spouse's trades count as mine? Immediate relatives are deemed connected persons and are covered by the Code's window, pre-clearance and disclosure rules. Practically, yes β€” treat them as your exposure.

Can I trade if I'm always in possession of UPSI? Through an approved and disclosed trading plan under Regulation 5, with a 120-day cool-off β€” which must then be implemented as committed.

How often must the Audit Committee review PIT compliance? At least once every financial year, verifying that internal controls are adequate and operating effectively.

What if we discover a leak? Regulation 9A(5) requires written policies for inquiry; conduct it, document it, inform SEBI promptly of findings, and report code violations to the exchanges.

Primary sources

  • Regulations 3(5), 3(6), 4, 5, 6, 7, 9, 9A & Schedules B–C, SEBI (Prohibition of Insider Trading) Regulations, 2015
  • SEBI (Prohibition of Insider Trading) (Amendment) Regulations, 2025 β€” Notification SEBI/LAD-NRO/GN/2025/235 dated 11 March 2025, effective 10 June 2025
  • SEBI (Prohibition of Insider Trading) (Amendment) Regulations, 2024 β€” trading plan rationalisation
  • BSE and NSE circulars dated 18 October 2024 β€” Standard Operating Process for SDD compliance certification
  • Regulation 24A, SEBI (LODR) Regulations, 2015 β€” Annual Secretarial Compliance Report
  • SEBI FAQs on the PIT Regulations

Disclaimer: This article is general information on a fast-changing area of securities law, current at the time of writing. It is not legal or professional advice for any specific company or individual. Verify the position against the live SEBI regulations, exchange circulars and FAQs, and consult your compliance officer or a practising company secretary before acting or trading.