- within Corporate/Commercial Law topic(s)
- with Senior Company Executives, HR and Finance and Tax Executives
- in India
- with readers working within the Accounting & Consultancy, Banking & Credit and Law Firm industries
“Does the company’s control system work when it matters?”
A trading window email is missed. A designated person trades through a family account. A contra transaction is noticed only when the exchange asks for trade details. A pre-clearance approval form is signed without testing past trades. An SDD entry is incomplete. A senior executive is involved, and the compliance team is unsure who should inquire. The company has a code, but no real process to identify the breach, examine it fairly, decide the consequence and close the record.
This is where many listed companies face difficulty. The issue is not limited to proving or disproving insider trading. General Counsels, Company Secretaries, Legal Heads, CFOs, Compliance Officers, Independent Directors and Audit Committee members may have to answer a more uncomfortable set of questions. Was the person correctly identified as a designated person? Were immediate relatives mapped? Was the pre-clearance system working, or was it a formality? If a relaxation was granted, what made it defensible? If different employees were treated differently, what was the intelligible basis? If the matter reached SEBI or the stock exchange, would the company’s action-taken record inspire confidence?
This Article addresses those grey-zone situations where there may be no clear finding of UPSI-based trading, but the company may still face a code, control, reporting or governance problem. Readers dealing with practical concerns around designated person trades, immediate relative transactions, trading-window controls, SDD discipline, internal inquiry, consequence-setting or stock exchange queries may write to litigation@indiacp.com or info@indiacp.com for clarifications on this article or suggestions on issues to be examined in future pieces.
The First Question: What Exactly Was Breached?
The SEBI (Prohibition of Insider Trading) Regulations, 2015 require listed companies to frame and enforce a code of conduct to regulate, monitor and report trading by designated persons and their immediate relatives.1 That framework sits alongside broader obligations relating to UPSI identification, SDD maintenance, disclosures, trading plans, pre-clearance, contra trade restrictions and reporting of code violations.2
The first classification, therefore, matters. Was there insider trading? Was there a trading window breach? Was there a failure to pre-clear? Was there a delayed disclosure? Was the issue an immediate-relative trade, a pledge event, a contra transaction, an SDD lapse, or a failure of internal escalation? The answer may change the legal risk, the internal process and the consequence.
A company should not mechanically describe every lapse as insider trading. But it should also not close the matter merely because no UPSI was present. In inquiry and investigation proceedings, a recurring problem is not only the trade by the designated person or immediate relative, but the company’s failure to identify it in time, inquire into it properly, apply the code consistently and preserve a defensible action-taken trail.
Pre-Clearance Is a Control Point, Not a Signature Line
Pre-clearance is often treated as a procedural approval. In substance, it is a live checkpoint. Before a trade is permitted, the company should be able to test whether the person is a designated person, whether the relevant immediate relatives are covered, whether the trading window is open, whether the person had access to UPSI, whether any event-sensitive information was in circulation, whether past trades create contra-trade risk and whether the proposed trade is consistent with the code.
This raises practical questions. How does the company decide who a designated person is? How often is that list refreshed? Are finance, strategy, legal, secretarial, investor relations, treasury, promoter-office and business teams mapped properly? Does the company test access to information, or only designation? When pre-clearance is sought, does the compliance officer have enough visibility into SDD, trading history and pending corporate events?
A pre-clearance form cannot answer these questions by itself. The form is only the visible end of the control system. If the underlying mapping is weak, approval may give false comfort.
Contra Trade and Relaxation: How Much Comfort Is Enough?
Contra-trade restrictions remain one of the more difficult areas in practice. The concern is not merely whether two transactions fall within a six-month period. The harder issue is whether the company understands why the second transaction occurred, whether it was voluntary or compelled, whether the person had access to UPSI, whether any relaxation was sought, and whether the reasons for relaxation are strong enough to survive later scrutiny.
SEBI’s FAQ guidance indicates that contra-trade restrictions are to be applied to each trade and that relaxation from strict application may be granted by the compliance officer for reasons recorded in writing, provided the relaxation does not violate the Regulations.3 That phrase - “reasons recorded in writing” - should not be allowed to become a rubber stamp.
How deep should the company go before accepting a contra-trade explanation? What would be a defensible reason for relaxation? Would the answer change if the person is a CFO, a business head, a promoter-group employee or a junior executive with no relevant information access? What if the same factual pattern arises again? These are the questions each company should be able to answer through its own code, records and governance design.
Pledge, Invocation and Revocation: The Quiet Risk
Pledge-related events also require careful treatment. A pledge is not a conventional market buy or sell, but for PIT analysis, creation, revocation and invocation of a pledge are treated as trading.4 This makes pledge monitoring relevant for disclosure, pre-clearance and contra-trade assessment.
At the same time, the company should not treat every pledge event as if it were a deliberate market transaction. Invocation may be broker-driven, lender-driven, margin-triggered or automatic. Revocation may occur without a conscious trading decision at the relevant moment. The real governance question is whether the company had a way to identify the event, understand the trigger, obtain supporting records, assess preventability and decide whether the breach was technical, negligent, repeated or deliberate.
An ill-managed pledge trail can become difficult to explain when it coincides with trading-window closure, a sensitive corporate event or an exchange query.
SDD and Control Systems: The Ticking Time-Bomb
The Structured Digital Database is often discovered as a problem only when a Stock Exchange or SEBI query arrives. That is too late. A delayed or incomplete SDD entry may appear clerical, but it may point to a deeper control issue: Who identified UPSI? When did the information become sensitive? Who had access? Was access captured in real time? Did trading-window closure follow the same assessment?
An ill-managed SDD, weak access mapping and casual trading approval process may remain hidden for months. Then one trade, one announcement, one complaint or one exchange email exposes the gap. The question for boards and audit committees is whether SDD is being maintained as a live control system or as a retrospective compliance artefact.
Internal Inquiry: Fairness Is in the Process
Once a breach or possible breach is identified, the company’s response should not be informal, selective or personality-driven. An internal inquiry does not require the company to conduct a courtroom trial. But it should be fair enough to be credible.
Fairness lies in the process: notice of the issue, opportunity to explain, collection of relevant trade and communication records, review of UPSI access, conflict check, escalation where required, and reasoned closure. The company should not brush a matter under the carpet. Equally, it should not impose a disproportionate consequence only to show seriousness.
This is especially important where the person involved is senior. Does the compliance officer have practical authority to examine the conduct of a CFO, MD, promoter-office employee or business head? What happens if the breach involves the compliance officer or a person to whom the compliance officer reports? Is there an escalation route to the Audit Committee, Board, Chairperson, Independent Director or external adviser? A policy that gives power without a conflict mechanism may look strong on paper but weak in practice.
The point is simple: when power to inquire is given, responsibility to inquire fairly and effectively follows.
Policies Must Be Implementable, Not Merely Impressive
A PIT code, penalty framework, conflict policy or inquiry SOP should not be drafted only for completeness. It should work on the ground. Can the compliance team actually verify past trades? Can it access SDD information? Can it identify immediate relatives? Can it obtain broker statements? Can it pause a decision where conflict exists? Can it consult external experts where the issue is legally or factually sensitive?
The need is for a guided process, not a one-off reaction. Regulators have their own procedures for inquiry and adjudication. Companies should not conduct internal compliance inquiries as if they are improvising every time. A compliance investigation SOP, conflict-of-interest protocol and consequence matrix can create structure without making the process rigid.
Poorly designed policies may also create risks outside securities law. Consequences involving monetary penalties, wage deductions, bonus impact, ESOP eligibility, suspension, termination or employment-record consequences should be tested against employment contracts, HR policies, standing orders, and applicable labour law. A securities compliance policy cannot assume that every internal penalty is automatically enforceable merely because it is written into a code.
Consequence Matrix: Baseline, Not Blind Formula
The phrase “penalty matrix” may suggest punishment. A better expression may be “consequence matrix”. Its purpose is not to replace the application of the mind. It is to make the decision effective, less time-consuming, non-arbitrary and recordable.
A good consequence matrix sets baselines, aggravating as well as mitigating factors. It distinguishes administrative lapses, trading-related breaches without UPSI, serious UPSI-linked misconduct, repeated conduct, concealment, non-cooperation and senior-management involvement. It allows exceptions. It recognises that different classes may be treated differently where role, designation, information access, function, trade value, intent, repeat conduct or cooperation differs.
But different treatment needs intelligible criteria. If two similar breaches lead to different outcomes, can the company explain why? Was one person a designated person by function? Did one person have access to the relevant information? Was one breach self-reported, while another was discovered only after an exchange query? Was one trade automatic while another was deliberate? Without recorded criteria, discretion can look like arbitrariness.
Consequence-setting should not become a memory exercise, a mood exercise or a trial by fire. It should be guided by policy, facts, proportionality and law.
The Wider Risk: Not Only the Trader
A code breach may begin with one employee or an immediate relative. It may not end there. If the company had no effective DP or IR mapping, no functioning pre-clearance process, no SDD discipline, no inquiry SOP, no reporting framework, no consequence matrix or no escalation for senior-person breaches, scrutiny may move from the trader to the company’s control environment.
The conduct of the compliance officer, key managerial personnel, managing director, board or committee may come into focus where the record suggests knowledge, neglect, inadequate systems, selective treatment or failure to report. The SEBI Act contains investigation powers, penalties for insider trading, penalties for failure to furnish information or maintain records, residuary penalty provisions, and provisions dealing with offences by companies and persons in charge in specified circumstances.5 Liability is increasingly being extended to compliance officers and senior management for systemic failures, even where insider trading is not independently established.6
This means the company should not assume that “no UPSI” ends the matter. Sometimes, the more difficult issue is whether the company had a workable system at all.
Conclusion: The Trade May Be Small. The Internal Control Question May Not Be.
For listed companies, trades by designated persons and immediate relatives should be seen as part of a larger compliance-control ecosystem. The trade is only one data point. Around it sit DP identification, information access, SDD entries, pre-clearance, trading-window closure, contra-trade review, pledge monitoring, internal inquiry, conflict management, employment-law sensitivity and consequence-setting.
The questions worth asking are not always simple. Who should inquire when the person involved is a senior? How should the company treat an automatic pledge invocation? When does a technical lapse become repeated indiscipline? How should different treatments be justified? Does the Audit Committee see only the result, or also the process? Are the Company’s policies practical and workable?
The absence of UPSI should refine the inquiry, not close it. A listed company does not need a harsh system. It needs a system that is workable, fair, legally grounded, and explainable when the next query arrives.
Footnotes
1 Securities and Exchange Board of India (Prohibition of Insider Trading) Regulations, 2015, reg. 9 & sched. B, https://www.sebi.gov.in/legal/regulations/mar-2025/securities-and-exchange-board-of-india-prohibition-of-insider-trading-regulations-2015-last-amended-on-march-12-2025-_92672.html.
2 Id. regs. 2(1)(e), 2(1)(g), 2(1)(n), 3-5, 7-9A & sched. B; SEBI Circular No. SEBI/HO/ISD/ISD/CIR/P/2019/82, Standardizing Reporting of Violations Related to Code of Conduct under SEBI (Prohibition of Insider Trading) Regulations, 2015 (July 19, 2019), https://www.sebi.gov.in/legal/circulars/jul-2019/standardizing-reporting-of-violations-related-to-code-of-conduct-under-sebi-prohibition-of-insider-trading-regulations-2015_43618.html; SEBI Circular No. SEBI/HO/ISD/ISD/CIR/P/2020/135, Reporting to Stock Exchanges regarding Violations under SEBI (Prohibition of Insider Trading) Regulations, 2015 relating to the Code of Conduct (July 23, 2020), https://www.sebi.gov.in/legal/circulars/jul-2020/reporting-to-stock-exchanges-regarding-violations-under-securities-and-exchange-board-of-india-prohibition-of-insider-trading-regulations-2015-relating-to-the-code-of-conduct-coc-_47121.html.
3 SEBI, Comprehensive FAQs on SEBI (Prohibition of Insider Trading) Regulations, 2015, FAQs 36, 42-43, 46-47 (Dec. 31, 2024), https://www.sebi.gov.in/enforcement/clarifications-on-insider-trading/dec-2024/comprehensive-faqs-on-sebi-pit-regulations-2015_90403.html.
4 Id. FAQs 1, 13-15.
5 Securities and Exchange Board of India Act, 1992, §§ 11C, 15A, 15G, 15HB, 27, https://www.sebi.gov.in/acts/act15ac.pdf.
6 Securities and Exchange Board of India, Adjudication Order in the matter of insider trading activity by certain entities in the scrip of Shalimar Paints Limited (Jul. 25, 2024), https://www.sebi.gov.in/enforcement/orders/jul-2024/adjudication-order-in-the-matter-of-insider-trading-activity-by-certain-entities-in-the-scrip-of-shalimar-paints-limited-_85110.html
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.