← Back to Knowledge Hub

Your company secretary runs the filings. Regulation 9A puts the internal controls on the CEO or MD by name. That is not a distinction the compliance team can fix for you.

Regulation 9A: the Chief Executive Officer, Managing Director or analogous person must put in place adequate and effective internal controls to prevent insider trading. The Audit Committee must verify, at least annually, that they are operating effectively.

Most founders meet the PIT Regulations through a policy document circulated after listing and a quarterly email saying the trading window is shut. That framing is incomplete in a way that matters. The regulations impose obligations at three levels β€” on the company, on the CEO or MD personally, and on you as a designated person β€” and each fails differently.

Company-level failures are usually procedural and survivable. The personal ones are not. When SEBI examines a leak it asks who was responsible for the system that failed, and Regulation 9A has already answered with a job title. Separately, every promoter, director and KMP is exposed under Regulation 4 for their own trades, and under the Code of Conduct for their immediate relatives' trades.

What follows is a build guide rather than a summary of the law. Nine systems, what each has to do, and where each one breaks.

The bottom line

You personally own the controls. Regulation 9A names the CEO, MD or analogous person, not the compliance officer.

The Audit Committee must verify annually that those controls are adequate and operating effectively, and the verification has to be minuted.

The SDD cannot be outsourced. Maintained internally, time-stamped, non-tamperable, audit-trailed, preserved 8 years.

Certification is external now. Since the October 2024 exchange circulars, SDD compliance is confirmed in the Annual Secretarial Compliance Report, or through a PCS-certified SDD certificate within 60 days of financial year end.

Your relatives are your exposure. Immediate relatives' trades run through the same window, pre-clearance and disclosure rules.

System 1 β€” the UPSI identification matrix

Everything downstream depends on correctly answering one question: is this UPSI? Regulation 2(1)(n) of the PIT Regulations, 2015, as amended with effect from 10 June 2025, expanded the illustrative list from five categories to sixteen, which means the instinct built up over the previous decade is no longer reliable.

What to build: a written matrix mapping each of the sixteen categories to the internal function that first learns of it, the trigger point at which it becomes UPSI, and the named person who must notify the compliance officer. Fund-raising decisions sit with the CFO. Forensic audit initiation sits with the Audit Committee chair. Licence suspensions sit with the plant or regulatory head. Third-party guarantees sit with treasury.

Where it breaks: on the events that feel operational rather than market-sensitive. A licence suspension notice reaches a factory manager who has never read the PIT Code, and who files it as a regulatory matter. Nobody tells the compliance officer for eleven days. The window stayed open, three designated persons traded, and the company now has a reportable violation and a SEBI file.

One related discipline is worth building at the same time. Deciding that something is not UPSI is a judgment SEBI will review later, with hindsight and a share-price chart in front of it. Record the reasoning at the time, dated, with the name of whoever decided. A contemporaneous note explaining why a contract loss was immaterial is a defence. The same explanation written after a summons arrives is not.

System 2 β€” the structured digital database

Regulations 3(5) and 3(6) govern the SDD. It is the first document SEBI asks for in any investigation, and it is where most listed companies are quietly non-compliant.

Hard requirements: maintained internally, since it cannot be outsourced; capturing the nature of the UPSI and the name, PAN or other legally authorised identifier of everyone who shared it and everyone who received it; with time-stamping, audit trails and non-tamperable architecture; preserved at least 8 years after the relevant transactions complete, and until proceedings conclude where SEBI has notified an investigation. Since the 2025 amendment, UPSI received from outside the company must be entered within 2 calendar days of receipt.

What that rules out: spreadsheets. An editable workbook has no audit trail and no non-tamperable property, and SEBI inspections specifically test whether audit logs can be produced. If your SDD is a shared Excel file, you do not have an SDD.

The certification layer: following the BSE and NSE circulars dated 18 October 2024, entities to which Regulation 24A of the LODR applies confirm SDD compliance inside the Annual Secretarial Compliance Report. Entities outside Regulation 24A β€” SME-platform companies, REITs, InvITs and exclusively debt-listed entities β€” file an SDD Compliance Certificate from a Practising Company Secretary within 60 days of the financial year end. Non-compliant entities file quarterly PCS certificates until they comply, and the exchanges publish the non-compliance status.

Where it breaks: retro-fitting. Entries made in a batch three weeks later are visible in the audit trail as exactly that. A back-dated SDD is materially worse than an incomplete one, because it turns a control failure into a credibility failure.

System 3 β€” the designated persons register

Regulations 9 and 9A(2) require that all employees with access to UPSI are identified as designated persons. This is a live register, not an annexure drafted at listing and left alone.

What to build: a register covering promoters, directors, KMP and every employee whose functional role gives UPSI access, plus their immediate relatives, since the Code's trading restrictions extend to them. It updates on every appointment, resignation, role change and change in a relative's circumstances β€” a marriage, a spouse opening a broking account. Carry PAN details, because the SDD and the Regulation 7 disclosures both need them.

Where it breaks: drift. A finance manager promoted into the results-preparation team eighteen months ago was never added. She trades in a closed window in complete good faith. The company's defence, that she was not on the list, is the admission rather than the answer, because Regulation 9A required her to be on it.

System 4 β€” trading window governance

Regulation 9, read with Schedule B, sets the mandatory closure: from the end of every quarter until 48 hours after the declaration of financial results. Both ends matter. The window shuts at quarter-end, not at the board meeting, and it reopens 48 hours after dissemination, not at announcement.

Beyond that, any UPSI crystallising mid-quarter closes the window for those who can reasonably be expected to possess it. The 2025 amendment gave compliance officers flexibility where UPSI originates externally and designated persons are unlikely to hold it. Useful, but exercise it in writing, with reasons.

What to build: automated notifications at closure and reopening, an acknowledgement trail, and a standing calendar entry so the process does not depend on someone remembering to send an email.

Where it breaks: the reopening. Teams reliably shut the window and unreliably wait the full 48 hours. Counting from the wrong event β€” board approval rather than exchange dissemination β€” is the most common technical breach in the entire regime.

System 5 β€” pre-clearance

Under Schedule B, trades above a company-set threshold need prior approval, supported by an undertaking that the person possesses no UPSI, and typically executed within 7 days of approval or the approval lapses.

What to build: a request form capturing quantity, expected value and the no-UPSI declaration; an approval log kept by the compliance officer; execution confirmation; and an automatic check against contra-trade history before approval is granted.

Where it breaks: when the undertaking is treated as a formality. It is signed evidence. A designated person who declares "I possess no UPSI" and then trades on information they did hold has converted a regulatory contravention into a documented false declaration, which is a considerably worse position.

System 6 β€” contra-trade monitoring

Schedule B bars any opposite transaction within 6 months of an earlier trade by a designated person. Profits from a violative contra-trade are disgorged to SEBI's Investor Protection and Education Fund.

What to build: a rolling six-month ledger per designated person, checked automatically at the pre-clearance stage rather than discovered afterwards.

Where it breaks: ESOPs. A KMP exercises options and sells the resulting shares four months after buying shares on the open market. The exercise may be exempt. The sale is a contra-trade against the earlier purchase, and this single fact pattern accounts for a large share of the code violations reported to the exchanges.

System 7 β€” disclosure discipline

Regulations 6 and 7 carry two duties.

  • Initial disclosure: holdings disclosed within 7 days of appointment as a director or KMP, or of becoming a promoter.
  • Continual disclosure under Regulation 7(2): every trade, or series of trades in a calendar quarter, exceeding β‚Ή10 lakh in value must be disclosed by the designated person to the company within 2 trading days, and by the company to the exchanges within 2 trading days of receipt.

Where it breaks: aggregation. The threshold is cumulative across the quarter, not per transaction. Four purchases of β‚Ή3 lakh each cross β‚Ή10 lakh, and the clock ran from the trade that crossed it. Founders who buy in tranches miss this routinely.

System 8 β€” trading plans, for those who are always inside

A promoter or CXO with near-permanent UPSI access can rarely trade cleanly, and Regulation 5 exists for exactly that position. Pre-commit to the trades, have the plan approved by the compliance officer and disclosed to the exchanges, then let it execute regardless of what you subsequently learn.

After SEBI's 2024 rationalisation the cool-off between disclosure and implementation is 120 days, down from six months, the blanket black-out around results was removed, and planners may set optional price limits within a Β±20% band.

The trade-off: once set, the plan must be implemented. You cannot suspend it because the price moved against you, and that irrevocability is precisely what makes it a defence.

Where it breaks: treating a plan as optional timing. Abandoning one mid-course invites the inference that the abandonment was itself informed.

System 9 β€” institutional mechanism, whistle-blower policy and the annual review

This is the system that names you. Regulation 9A breaks into four duties.

  • 9A(1) and (2): the CEO, MD or analogous person must put in place adequate and effective internal controls β€” identifying all UPSI-access employees as designated persons, defining what constitutes UPSI, restricting its communication, and serving notice on or obtaining confidentiality agreements from recipients.
  • 9A(4): the Audit Committee, or an analogous body, must review compliance at least once every financial year and verify that the internal controls are adequate and operating effectively.
  • 9A(5): written policies and procedures for inquiry into any leak or suspected leak of UPSI, with the findings informing SEBI promptly.
  • 9A(6): a whistle-blower policy that employees are made aware of, enabling them to report UPSI leaks.

Where it breaks: the annual review turns into a tabled agenda item with nothing behind it. A minute recording "reviewed and found adequate" with no evidence of sample testing β€” no SDD entries examined, no window closures traced, no pre-clearance files pulled β€” means the verification 9A(4) requires did not meaningfully take place. Run it as an actual audit: sample five UPSI events, trace each one through identification, SDD entry, window closure and pre-clearance refusals, and minute the findings including the exceptions.

It helps to know what an investigation asks for, because the sequence is predictable. The SDD extract. The designated persons register as it stood on the relevant date. The trading window closure notices with acknowledgements. The pre-clearance file. The Audit Committee minutes evidencing the 9A(4) review. Where those five are complete, contemporaneous and consistent with one another, most matters resolve at the explanation stage. Where they contradict each other, the inconsistency becomes the case.

A worked example

A listed SaaS company's founder-MD learns on 8 September that a strategic investor is exploring a stake purchase that would affect control. Under the post-2025 list, agreements which may impact management or control is a named UPSI category.

What the systems do. The founder notifies the compliance officer the same day, because the System 1 matrix puts control-impacting agreements with the MD. The SDD entry goes in that day with the names and PANs of the four people aware, and the investor's banker is logged as an external recipient. The compliance officer closes the trading window for those four and issues a confidentiality notice to the banker.

Where it nearly failed. The founder's brother, an immediate relative on the designated persons register, had a pre-clearance request pending from 5 September to sell β‚Ή18 lakh of shares. It was approved on 6 September, valid for 7 days, and he had not yet executed. The compliance officer, checking the register against the new window closure, revoked the approval on 8 September before execution.

Without that revocation the sale would have completed on 9 September. It would have crossed the β‚Ή10 lakh Regulation 7(2) threshold, occurred inside a window closed for UPSI the relative was presumed to share, and left the company reporting a code violation while both brothers explained a well-timed exit to SEBI. What saved them was not the policy document. It was one person checking a live register against a live closure.

Common mistakes

  1. Believing the compliance officer owns the controls. Regulation 9A names the CEO or MD.
  2. Running the SDD on a spreadsheet. No audit trail, no non-tamperable property, no compliance.
  3. Outsourcing the SDD. It has to be maintained internally.
  4. A designated persons register that never updates after role changes or changes in relatives' circumstances.
  5. Reopening the window at announcement rather than 48 hours after dissemination.
  6. Missing ESOP contra-trades against open-market purchases in the preceding six months.
  7. Reading the β‚Ή10 lakh disclosure threshold as per-trade rather than aggregated across the calendar quarter.
  8. An Audit Committee review with no testing behind the minute.
  9. Keeping no contemporaneous record of the decisions that something was not UPSI.
  10. Assuming relatives sit outside the perimeter. They are inside it, and in practice their trades are attributed to you.

Frequently asked questions

Who is personally responsible for PIT internal controls? Regulation 9A places this on the Chief Executive Officer, Managing Director or analogous person, not on the compliance officer, who administers the Code under Regulation 9.

Can we outsource the SDD to our RTA or a vendor? No. It must be maintained internally with adequate internal controls, though software may be used to maintain it internally.

Is an Excel-based SDD acceptable? In practice, no. The regulation requires time-stamping, audit trails and non-tamperable capability, and SEBI inspections test whether audit logs can be produced.

How do we certify SDD compliance? Entities covered by Regulation 24A of the LODR confirm it in the Annual Secretarial Compliance Report. Others file a PCS-certified SDD Compliance Certificate within 60 days of the financial year end, and quarterly while non-compliant.

Do my spouse's trades count as mine? Immediate relatives are deemed connected persons and are covered by the Code's window, pre-clearance and disclosure rules. Treat them as your exposure.

Can I trade if I am always in possession of UPSI? Through an approved and disclosed trading plan under Regulation 5, with a 120-day cool-off, which must then be implemented as committed.

How often must the Audit Committee review PIT compliance? At least once every financial year, verifying that the internal controls are adequate and operating effectively.

What if we discover a leak? Regulation 9A(5) requires written policies for inquiry. Conduct it, document it, inform SEBI promptly of the findings, and report code violations to the exchanges.

Primary sources

  • Regulations 3(5), 3(6), 4, 5, 6, 7, 9, 9A and Schedules B–C, SEBI (Prohibition of Insider Trading) Regulations, 2015
  • SEBI (Prohibition of Insider Trading) (Amendment) Regulations, 2025 β€” Notification SEBI/LAD-NRO/GN/2025/235 dated 11 March 2025, effective 10 June 2025
  • SEBI (Prohibition of Insider Trading) (Amendment) Regulations, 2024 β€” trading plan rationalisation
  • BSE and NSE circulars dated 18 October 2024 β€” Standard Operating Process for SDD compliance certification
  • Regulation 24A, SEBI (LODR) Regulations, 2015 β€” Annual Secretarial Compliance Report
  • SEBI FAQs on the PIT Regulations