For Practising Company Secretaries

The NSE and BSE circulars of 18 October 2024 set six points a Practising Company Secretary certifies on an entity’s Structured Digital Database. This page maps each point to where the evidence sits in InsiderQ and lists the checks a PCS can perform without relying on the vendor.

Version 1.0Effective 3rd May 2025Naapbooks Limited · BSE SME 543351

Since the exchanges’ circulars of 18 October 2024 — NSE/CML/2024/31 and BSE notice 20241018-44 — the annual confirmation of structured digital database maintenance is issued by a Practising Company Secretary. This page maps each certification statement to where the evidence is found, so that a certification visit is an afternoon rather than a project.

Nothing on this page is conditional on the entity using InsiderQ, and nothing is offered in return for it. Naapbooks does not offer, and will not offer, any commission, referral fee or other consideration in connection with a certification. A certifying professional with the evidence to hand is better for everyone, including the entity being certified.

The six certification points, and where the evidence sits

#What is certifiedWhere to find it in InsiderQWhat to look at
1The company has a structured digital database in placeThe application itself; UPSI Statement reportConfirm the instance is live and that records exist for the period. Note the version and installation date from the post-installation letter.
2Control exists as to who can access the SDDUser list; role configurationRoles are Compliance Officer, Designated Person, Connected Person and PCS. Review for leavers, dormant accounts and role appropriateness. Accounts can be disabled rather than deleted, which preserves the trail.
3All UPSI disseminated in the period has been capturedUPSI Statement, filtered to the periodReconcile against the entity’s own record of price-sensitive events — board meetings, results, ratings, fund raising, litigation outcomes. Exportable to PDF or Excel.
4The system captures the nature of UPSI with date and timeUPSI Statement; individual UPSI recordsEach record carries the nature of the information, the sender, the recipients and a system-applied timestamp. Entries are recorded through the application rather than edited into it.
5The database is maintained internally and an audit trail is maintainedAudit Logs report; Credential Handover Record; Data Custody and AccessAudit Logs record activity in the application. For the internal-maintenance limb, the handover record evidences that the vendor holds no credential — and the custody page lists checks you can run yourself.
6The database is non-tamperable and can retain records for eight yearsAudit Logs; retention configuration; the entity’s backup arrangementsConfirm the retention configuration and, importantly, that the entity’s own backup regime supports the Regulation 3(6) horizon.

The internal-maintenance question, asked properly

The limb of point 5 that causes most difficulty is “maintained internally”. Regulation 3(5) requires that the database “shall not be outsourced and shall be maintained internally”. SEBI’s Comprehensive FAQs dated 31 December 2024 draw the line at access rather than at hosting: FAQ 7 permits cloud hosting where the board and compliance officer retain accountability for confidentiality, integrity and security; FAQ 8 states that where a third-party vendor maintains the server on a login basis, the vendor “may have access to such records which would be contrary to the regulations”.

The question to put to any SDD vendor is not “is it cloud or on-premise” but “who holds root on that server, and can any of your employees read the data?”Ask for the answer in writing

Checks you can perform independently

CheckHow
Who holds server credentialsAsk to see the credential handover record. Then audit the server’s user accounts and authorised keys with the entity’s IT team.
Whether the vendor retains accessHave the entity rotate the root password and confirm support still functions. If it does not, the vendor was relying on retained access.
Whether data leaves the instanceReview outbound network configuration. The only outbound requirement should be SMTP to the entity’s own mail service.
Who can see the data inside the applicationReview the user list and roles; every account is visible to the Compliance Officer.
Whether entries can be alteredReview the Audit Logs report for the period and reconcile a sample of entries against it.

Reports available for the certification file

ReportWhat it showsFormat
UPSI StatementAll UPSI recorded in the period, with nature, parties and timestampsPDF, Excel
Audit LogsActivity recorded in the applicationPDF, Excel
Designated PersonHoldings and transactions of designated personsPDF, Excel
Connected PersonHoldings and transactions of connected personsPDF, Excel
Deviation ReportContra trade, pre-clearance violation and variationPDF, Excel
Holding StatementConsolidated holdings of designated and connected personsPDF, Excel

A PCS login already exists in the product and has visibility of all reports. Ask the Compliance Officer to create one for you rather than working from their account — a separate login leaves a cleaner trail on both sides.

Matters worth raising with your client

These arise repeatedly and are worth a conversation whatever software is in use.

  • The expanded UPSI definition. Regulation 2(1)(n) was amended by SEBI/LAD-NRO/GN/2025/235, notified 11 March 2025 and in force from the ninetieth day after gazette publication, expanding the categories of deemed UPSI substantially and aligning them with LODR Schedule III materiality. Entities whose classification practice predates that amendment are likely to be under-capturing.
  • Externally sourced UPSI. The same amendment provides that information not emanating from within the organisation may be entered into the database not later than two calendar days from receipt. A hard, dated obligation, and worth sampling specifically.
  • Timeliness generally. SEBI has issued an administrative warning where entries were accurate but late, rejecting remote working as an explanation. Delay alone is a finding.
  • Retention arithmetic. Eight years runs from completion of the relevant transactions, not from the date of entry. A transaction that takes two years to complete carries ten years of records from first entry.
  • The consequence is public. The exchanges display non-compliance on the entity’s quote page and withhold further listing approvals other than bonus and split.

Your own firm’s obligation

ICSI issued an advisory to members on 28 February 2024 reminding Practising Company Secretaries that a fiduciary handling unpublished price sensitive information is itself required to maintain a structured digital database internally. SEBI’s Comprehensive FAQs of 31 December 2024 confirm at FAQs 5 and 6 that intermediaries and fiduciaries must maintain their own database, by reference to Regulation 9A(2)(d) and Schedule C.

InsiderQ I&F is the edition built for that, and firm-level licensing is available for PCS practices. The same custody position applies: the database is maintained by your firm, on infrastructure your firm controls, with no vendor credential. We are glad to discuss it entirely separately from any client engagement.

Questions about any of this? We answer them from the compliance officer’s side of the table, not the sales side.

Talk to us

Version 1.0 · effective 3rd May 2025. Regulatory references were current at the date of issue and should be verified against the current SEBI and exchange texts.

This page is informational and is not professional advice.