Navigating the Grey Areas of UPSI: Insights from the ICSI Masterclass on SDD
The mandate is clear: SEBI’s Prohibition of Insider Trading (PIT) Regulations require listed companies to maintain a Structured Digital Database (SDD) to track the flow of Unpublished Price Sensitive Information (UPSI). Yet, years after its introduction, many companies are still grappling with a fundamental question: When exactly does a piece of information become UPSI?
In a recent ICSI masterclass, experts from SEBI, the BSE, and leading corporate compliance officers tackled this complex issue, emphasizing that identifying the "germination point" of UPSI requires a documented, analytical approach.
If you are a compliance officer managing an SDD, here are the critical takeaways on classifying and tracking UPSI.
The Danger of Delayed Compliance
Varsha Agarwal from SEBI opened the session with a stark warning: the regulator's patience is wearing thin. Following pilot inspections, SEBI found the state of SDD compliance to be "very poor" [19:17].
A recurring defense from companies is that they are waiting for perfect clarity before implementing the SDD. The panel universally rejected this stance. As one expert noted, "delayed compliance is better than no compliance" [01:22:38]. If a company realizes it failed to log a past UPSI event, it should enter it into the SDD immediately. While regulators may still flag the delay, attempting to hide the omission is viewed as a far more severe infraction [01:25:45].
SEBI has also introduced a "name and shame" policy. Companies found non-compliant with SDD regulations (specifically regulations 3(5) and 3(6)) will have their names, along with their compliance officer's name, displayed on the stock exchange's quote page until the exchange verifies compliance has been achieved [01:01:02].
Identifying the "Germination Point"
The most significant challenge for compliance officers is determining when to log an event. As Narayan Shankar (EVP & Company Secretary at Mahindra & Mahindra) explained, UPSI is not limited to financial results—it is an inclusive definition covering mergers, acquisitions, significant capacity expansions, and even major impairments [52:17].
When does an acquisition discussion transform from casual exploration into UPSI? Shankar outlined SEBI's "Three Bucket Theory" [56:49]:
- Bucket 1 (Exploratory): Discussions are imprecise. There is no reasonable probability of the transaction going through. (Usually not UPSI).
- Bucket 2 (High Degree of Crystallization): The probability of the transaction proceeding is higher than the probability of it failing. Unresolved issues are being ironed out, and there is a structured negotiation process. This is the germination point of UPSI.
- Bucket 3 (Finality): The deal is signed and announced.
The critical takeaway: UPSI exists long before a deal is 100% certain. If PR teams are drafting press releases, or if the "Father of the Bride" (the controlling shareholder) has agreed to timelines, the information is price-sensitive and must be in the SDD [54:20].
The Regulation 30 Fallacy
A common misconception is that every disclosure made under Regulation 30 of the LODR (Listing Obligations and Disclosure Requirements) must automatically be an SDD entry.
This is false. Regulation 30 covers material events, while the PIT regulations govern price-sensitive information. Many LODR disclosures (like notices of AGMs or standard changes in directors) do not trigger a trading window closure and are not UPSI [49:30]. Conversely, not every SDD entry will result in a Regulation 30 disclosure—a major M&A deal might reach Bucket 2 (triggering an SDD entry) but ultimately collapse before reaching Bucket 3 (meaning no public disclosure is made) [01:10:18].
Companies must have a documented, internal policy that uses both quantitative metrics (e.g., impact on 2% of turnover) and qualitative analysis to determine what constitutes UPSI [50:51].
The Cloud Conundrum
The physical location of the SDD remains a point of contention. BSE's Gopal Krishnan Iyer noted that many companies are currently non-compliant because they host their SDD on external cloud servers [27:26].
The regulations demand the database be maintained internally to ensure absolute control over access and audit trails. While SEBI is reviewing representations from the industry regarding the use of dedicated, partitioned cloud servers, the current stance requires the database to reside firmly within the company's IT infrastructure [01:46:50].
For the full discussion and Q&A on SDD implementation, watch the complete ICSI masterclass here:https://www.youtube.com/live/KOLWngenSCw