SEBI Insider Trading Compliance For Indian Companies in 2025
InsiderQ • Trading Compliance For Indian Companies • 5 min read
Quick Answer
SEBI insider trading compliance in 2025 means Indian listed companies must maintain a
Structured Digital Database (SDD) of everyone who accesses unpublished price-sensitive information (UPSI), enforce trading window closures and pre-clearance for designated persons, and follow SEBI's March 2025 amendment, which expanded the definition of UPSI to 16 categories of material events and tightened SDD entry timelines. Non-compliance can trigger penalties, trading bans, and reputational damage.
Why Insider Trading Compliance Matters
Insider trading isn't a new problem in Indian markets. But 2025 has been a turning point.
High-profile cases from the IndusInd Bank derivatives disclosure controversy to SEBI's final order against former Infosys-linked traders have pushed insider trading compliance from a back-office checklist to a boardroom priority.
For company secretaries and compliance officers, the message is simple: SEBI is no longer just punishing violations after they happen. It's building systems to catch them faster, and it expects companies to do the same.
This guide breaks down what changed, what SEBI now expects, and how listed companies can build a compliance program that actually holds up.
What Is Insider Trading Under SEBI Rules?
Insider trading is the buying, selling, or dealing in a listed company's securities by a person who has access to unpublished price-sensitive information (UPSI) material, non-public information that could affect the share price if disclosed. It is prohibited under the SEBI (Prohibition of Insider Trading) Regulations, 2015 ("PIT Regulations").
Insider trading in India is regulated primarily through:
- SEBI (Prohibition of Insider Trading) Regulations, 2015 the core framework
- SEBI (LODR) Regulations, 2015 disclosure obligations for listed companies
- Periodic amendments and circulars issued by SEBI and the stock exchanges (NSE/BSE)
What Changed: The SEBI PIT Amendment, 2025
SEBI notified significant amendments to the PIT Regulations on March 11, 2025 (published March 12, 2025), following consultation papers issued in May 2023 and November 2024. Two changes stand out for compliance teams:
1. A broader definition of UPSI. The list of events treated as UPSI was expanded to 16 categories of material information, aligned with Schedule III of the SEBI LODR Regulations. New inclusions cover events such as the award or termination of contracts outside the ordinary course of business, and changes in credit ratings (excluding ESG-linked ratings).
2. A clearer timeline for the Structured Digital Database (SDD). Where UPSI originates outside the listed entity for example, from an external advisor or counterparty companies must now record it in the SDD within two calendar days of receiving it. Information from within the organization must still be logged as soon as a designated person receives or shares it.
Separately, a December 2024 amendment widened the definition of "connected person," replacing the narrower term "immediate relative" with "relative" a change that pulls more individuals into the compliance net, including certain former employees whose prior access to UPSI can still make them connected persons.
Key takeaway: If your insider trading policy still uses the pre-2025 definitions of UPSI or connected persons, it's out of date. Update it before your next disclosure cycle.
What Recent Enforcement Cases Teach Us
Two cases illustrate why compliance infrastructure matters more than policy documents alone.
The IndusInd Bank case. Concerns around undisclosed discrepancies in the bank's derivatives portfolio drew SEBI scrutiny into whether executives traded or exercised stock options while in possession of information that had not yet been made public.
The Infosys-linked case. In a final order dated January 31, 2025, SEBI directed an individual to disgorge over ₹2.6 crore in gains linked to trading ahead of the public announcement of a strategic Infosys partnership, along with monetary penalties and a one-year market ban for both the trader and the person alleged to have passed on the information.
Both cases share a common thread: the trail of evidence came from communication records, trading patterns, and database logs exactly the kind of data an SDD and surveillance system are designed to capture. Companies with weak record-keeping struggle to demonstrate they weren't part of the leak; companies with strong systems can show, quickly, who knew what and when.
Note on verification: Some figures related to insider trading enforcement volumes for 2024–25 are reported inconsistently across secondary sources. Only data points independently confirmed via SEBI orders or established financial media have been included. Where a statistic could not be verified against a primary source, it has been omitted rather than estimated.
Building a Compliance-First Culture
Ticking regulatory boxes isn't the same as building a culture where insider trading doesn't happen in the first place. Strong programs combine three layers: controls, oversight, and culture.
1. Information Barriers ("Chinese Walls")
- Separate sensitive functions (deal teams, finance, investor relations) from general staff access
- Restrict document and system access based on role, not seniority
- Audit information-flow logs periodically, not just annually
2. Training That Actually Sticks
- Run structured, role-specific training a board director and a mid-level finance analyst don't need the same session
- Use real (anonymized) case studies, including recent SEBI orders, rather than generic slides
- Make consequences concrete: fines, bans, and reputational fallout, not just "this is against policy"
3. Surveillance and Monitoring
- Monitor designated persons' trading activity, ideally in near real time
- Set automated alerts for trades that coincide with trading window closures
- Link surveillance output directly into your pre-clearance workflow, so red flags stop a trade before it happens, not after
Governance: What the Board Should Be Doing
| Governance Area | What It Looks Like in Practice |
|---|---|
| Board oversight | Insider trading policy reviewed at least annually; deviations reported to the audit committee |
| Compliance certification | Designated persons and their relatives certify compliance periodically |
| Technology integration | Digital pre-clearance requests, automated SDD entries, exchange surveillance integration |
| Culture | Compliance tied to performance reviews; zero-tolerance enforced consistently, not selectively |
Building Blocks of a Modern Compliance Program
Step-by-step: setting up (or upgrading) your insider trading compliance framework.
- Update your policy to reflect the 2025 UPSI and connected-person definitions
- Identify designated persons across the organization, including relevant vendors and consultants with UPSI access
- Set up the SDD with clear ownership who logs entries, and within what timeline
- Digitize pre-clearance so trading requests are checked against trading window status automatically
- Train designated persons on the updated rules, with a documented sign-off
- Monitor trades against disclosed holdings and flag anomalies
- Report to the board on compliance status, exceptions, and any investigations, at defined intervals
- Review annually, and immediately after any SEBI amendment
Pros and Cons of Technology-Enabled Compliance
| Pros | Cons |
|---|---|
| Faster detection of suspicious trades | Requires upfront investment in software/training |
| Reduces manual SDD errors | Needs ongoing data governance to stay accurate |
| Creates an audit-ready trail for regulators | Can create false positives if poorly configured |
| Scales as the organization and connected-person list grow | Still requires human judgment for edge cases |
Common Mistakes Companies Make
- Treating the SDD as a formality instead of a live, continuously updated record
- Using outdated definitions of UPSI or connected persons after a SEBI amendment
- Manual, spreadsheet-based pre-clearance that can't scale or produce a clean audit trail
- Training once, at onboarding, and never again
- No clear owner for compliance data leaving gaps that surface only during an investigation
Expert Tips for Staying Ahead of SEBI
- Review your policy within 30 days of any SEBI amendment don't wait for the annual cycle
- Extend training to relatives and connected entities, not just employees, given the broadened definition of "connected person"
- Log SDD entries the same day wherever possible, even though the regulation allows two calendar days for externally originating UPSI faster logging reduces dispute risk
- Run a mock SEBI audit internally once a year to find gaps before a regulator does
Where SEBI Is Headed Next
A few directional trends are worth watching, based on SEBI's public statements and recent regulatory activity:
- Greater use of data analytics and AI-assisted surveillance by SEBI and the exchanges to flag unusual trading patterns
- Tighter timelines for disclosure and database entries, continuing the direction set by the 2025 amendment
- Broader definitions of who counts as a connected or designated person, closing loopholes exposed by recent cases
These are reasonable extrapolations from SEBI's recent regulatory pattern rather than confirmed future rules treat them as trends to monitor, not settled law.
Compliance Checklist for Listed Companies
- Insider trading policy updated to reflect 2025 UPSI and connected-person definitions
- Designated persons list current and reviewed quarterly
- SDD maintained with defined entry-timeline ownership
- Pre-clearance process digitized and linked to trading window status
- Annual + event-triggered training completed and documented
- Whistleblower mechanism active and communicated
- Board-level review scheduled at least annually
- Escalation and reporting procedure documented
Conclusion
SEBI's 2025 amendments aren't a one-time update to file away they're a signal of where enforcement is heading: broader definitions, faster documentation, and heavier reliance on data trails. The IndusInd Bank and Infosys-linked cases both show that regulators increasingly rely on the same records companies are required to keep communication logs, trading data, and SDD entries.
For Indian listed companies, the practical takeaway is straightforward: treat insider trading compliance as a live system, not a static policy document. Companies that invest in clear governance, real training, and reliable technology won't just avoid penalties they'll build the kind of trust that matters to investors, regulators, and employees alike.
Key Takeaways
- SEBI's PIT amendment (notified March 11, 2025) expanded UPSI to 16 categories of material events and set a 2-calendar-day SDD entry window for externally originating information
- A December 2024 amendment broadened the definition of "connected person," including certain former employees
- Recent enforcement cases (IndusInd Bank, Infosys-linked matter) show SEBI relies heavily on communication records and trading data trails
- Strong compliance requires three layers: information barriers, board-level governance, and technology-enabled monitoring
- Outdated policies referencing pre-2025 definitions create real compliance risk