Building the Audit Trail: The Operational Reality of SEBI's Structured Digital Database (SDD)

Building the Audit Trail: The Operational Reality of SEBI's Structured Digital Database (SDD)
Implementing the Structured Digital Database. Source: Bloomberg / Bloomberg via Getty Images

Here is a blog article breaking down the deep-dive panel discussion on the operational realities of the Structured Digital Database (SDD).

To effectively combat insider trading, regulators need to follow the footprint of information. In 2018, the Committee on Fair Market Conduct identified a critical vulnerability: once a company shares Unpublished Price Sensitive Information (UPSI) internally or with external partners, it loses visibility over how that information travels [20:03].

The solution was the Structured Digital Database (SDD). In a dedicated ICSI masterclass, representatives from SEBI, the BSE, and leading Practicing Company Secretaries (PCS) explored the strict technological and operational expectations regulators now have for the SDD.

If you are a Compliance Officer or a PCS issuing compliance certificates, here are the non-negotiable standards you need to meet.

1. Excel is Not a Database

The panel made one rule abundantly clear: tracking UPSI on a password-protected Excel spreadsheet is a direct violation of the regulation [39:24].

An acceptable SDD must possess three mandatory characteristics [53:30]:

  • Non-tamperable: The system must not allow the silent deletion or overriding of records. If an entry is edited (e.g., correcting a typo in a PAN number), the system must preserve both the original entry and the correction.
  • Time-stamped: Entries must be logged with an automated, system-generated time stamp that cannot be manipulated by the user.
  • Audit Trail: The software must generate printable or exportable reports tracing the complete journey of a piece of UPSI from creation to closure (or public disclosure).

2. Strict Internal Hosting Requirements

Cloud-based conveniences often clash with data sovereignty. Regulators explicitly require that the SDD be maintained internally [50:48].

Companies cannot outsource the database to third-party vendors' external servers. Furthermore, for conglomerates and group companies, commingling data on a single "group server" is strictly prohibited. Each listed entity must maintain its own logically partitioned and internally controlled database to prevent unauthorized access across group companies [51:04].

3. The Burden of Proof on Certification

A significant shift in the PIT framework is the requirement for independent certification. While compliance officers initially self-certified their SDD operations, the burden now extends to Practicing Company Secretaries (PCS) [55:17].

For a PCS, accepting a simple declaration from a vendor or an IT head is no longer sufficient [01:13:04]. They are expected to:

  • Perform user acceptance testing (UAT) or dummy entries to verify time-stamping and audit trail integrity.
  • Cross-verify the PANs entered into the system against public databases to ensure identities haven't been falsified [49:59].
  • Compare the SDD entries against the company's Regulation 30 disclosures to ensure all finalized material events were properly tracked during their "unpublished" phase [01:51:08].

4. No Exceptions for Debt or Size

A frequent question among smaller entities or companies with only debt securities listed is whether they can claim exemptions due to the prohibitive cost of enterprise software. The regulatory stance is a firm "no" [01:56:43].

If your securities are listed on a recognized exchange—be it equity or debt, regardless of your paid-up capital—you must maintain a fully functional SDD. Suspended companies are also required to comply, as their listing status remains active even if trading is halted [02:05:28].

5. "When in Doubt, Include"

How quickly must an entry be made? SEBI expects entries to be practically real-time. If you share UPSI today, it should be logged today—not 15 days later when a quarterly compliance report is due [01:59:52].

Furthermore, companies shouldn't just log the obvious events like quarterly financial results. M&A discussions, new product patents, or regulatory notices must be tracked the moment they become material [01:08:56]. As the panel succinctly advised compliance officers: When in doubt, include it.

For the complete masterclass on SDD compliance, watch the full ICSI session here:https://www.youtube.com/live/Yzjvz9Mf81Q