Since the exchanges’ circulars of 18 October 2024 — NSE/CML/2024/31 and BSE notice 20241018-44 — the annual confirmation of structured digital database maintenance is issued by a Practising Company Secretary. This page maps each certification statement to where the evidence is found, so that a certification visit is an afternoon rather than a project.
Nothing on this page is conditional on the entity using InsiderQ, and nothing is offered in return for it. Naapbooks does not offer, and will not offer, any commission, referral fee or other consideration in connection with a certification. A certifying professional with the evidence to hand is better for everyone, including the entity being certified.
The six certification points, and where the evidence sits
| # | What is certified | Where to find it in InsiderQ | What to look at |
|---|---|---|---|
| 1 | The company has a structured digital database in place | The application itself; UPSI Statement report | Confirm the instance is live and that records exist for the period. Note the version and installation date from the post-installation letter. |
| 2 | Control exists as to who can access the SDD | User list; role configuration | Roles are Compliance Officer, Designated Person, Connected Person and PCS. Review for leavers, dormant accounts and role appropriateness. Accounts can be disabled rather than deleted, which preserves the trail. |
| 3 | All UPSI disseminated in the period has been captured | UPSI Statement, filtered to the period | Reconcile against the entity’s own record of price-sensitive events — board meetings, results, ratings, fund raising, litigation outcomes. Exportable to PDF or Excel. |
| 4 | The system captures the nature of UPSI with date and time | UPSI Statement; individual UPSI records | Each record carries the nature of the information, the sender, the recipients and a system-applied timestamp. Entries are recorded through the application rather than edited into it. |
| 5 | The database is maintained internally and an audit trail is maintained | Audit Logs report; Credential Handover Record; Data Custody and Access | Audit Logs record activity in the application. For the internal-maintenance limb, the handover record evidences that the vendor holds no credential — and the custody page lists checks you can run yourself. |
| 6 | The database is non-tamperable and can retain records for eight years | Audit Logs; retention configuration; the entity’s backup arrangements | Confirm the retention configuration and, importantly, that the entity’s own backup regime supports the Regulation 3(6) horizon. |
The internal-maintenance question, asked properly
The limb of point 5 that causes most difficulty is “maintained internally”. Regulation 3(5) requires that the database “shall not be outsourced and shall be maintained internally”. SEBI’s Comprehensive FAQs dated 31 December 2024 draw the line at access rather than at hosting: FAQ 7 permits cloud hosting where the board and compliance officer retain accountability for confidentiality, integrity and security; FAQ 8 states that where a third-party vendor maintains the server on a login basis, the vendor “may have access to such records which would be contrary to the regulations”.
The question to put to any SDD vendor is not “is it cloud or on-premise” but “who holds root on that server, and can any of your employees read the data?”Ask for the answer in writing
Checks you can perform independently
| Check | How |
|---|---|
| Who holds server credentials | Ask to see the credential handover record. Then audit the server’s user accounts and authorised keys with the entity’s IT team. |
| Whether the vendor retains access | Have the entity rotate the root password and confirm support still functions. If it does not, the vendor was relying on retained access. |
| Whether data leaves the instance | Review outbound network configuration. The only outbound requirement should be SMTP to the entity’s own mail service. |
| Who can see the data inside the application | Review the user list and roles; every account is visible to the Compliance Officer. |
| Whether entries can be altered | Review the Audit Logs report for the period and reconcile a sample of entries against it. |
Reports available for the certification file
| Report | What it shows | Format |
|---|---|---|
| UPSI Statement | All UPSI recorded in the period, with nature, parties and timestamps | PDF, Excel |
| Audit Logs | Activity recorded in the application | PDF, Excel |
| Designated Person | Holdings and transactions of designated persons | PDF, Excel |
| Connected Person | Holdings and transactions of connected persons | PDF, Excel |
| Deviation Report | Contra trade, pre-clearance violation and variation | PDF, Excel |
| Holding Statement | Consolidated holdings of designated and connected persons | PDF, Excel |
A PCS login already exists in the product and has visibility of all reports. Ask the Compliance Officer to create one for you rather than working from their account — a separate login leaves a cleaner trail on both sides.
Matters worth raising with your client
These arise repeatedly and are worth a conversation whatever software is in use.
- The expanded UPSI definition. Regulation 2(1)(n) was amended by SEBI/LAD-NRO/GN/2025/235, notified 11 March 2025 and in force from the ninetieth day after gazette publication, expanding the categories of deemed UPSI substantially and aligning them with LODR Schedule III materiality. Entities whose classification practice predates that amendment are likely to be under-capturing.
- Externally sourced UPSI. The same amendment provides that information not emanating from within the organisation may be entered into the database not later than two calendar days from receipt. A hard, dated obligation, and worth sampling specifically.
- Timeliness generally. SEBI has issued an administrative warning where entries were accurate but late, rejecting remote working as an explanation. Delay alone is a finding.
- Retention arithmetic. Eight years runs from completion of the relevant transactions, not from the date of entry. A transaction that takes two years to complete carries ten years of records from first entry.
- The consequence is public. The exchanges display non-compliance on the entity’s quote page and withhold further listing approvals other than bonus and split.
Your own firm’s obligation
ICSI issued an advisory to members on 28 February 2024 reminding Practising Company Secretaries that a fiduciary handling unpublished price sensitive information is itself required to maintain a structured digital database internally. SEBI’s Comprehensive FAQs of 31 December 2024 confirm at FAQs 5 and 6 that intermediaries and fiduciaries must maintain their own database, by reference to Regulation 9A(2)(d) and Schedule C.
InsiderQ I&F is the edition built for that, and firm-level licensing is available for PCS practices. The same custody position applies: the database is maintained by your firm, on infrastructure your firm controls, with no vendor credential. We are glad to discuss it entirely separately from any client engagement.
Questions about any of this? We answer them from the compliance officer’s side of the table, not the sales side.
Talk to usVersion 1.0 · effective 3rd May 2025. Regulatory references were current at the date of issue and should be verified against the current SEBI and exchange texts.
This page is informational and is not professional advice.