Third-Party UPSI and Information Governance

September 1, 2026

Third-Party UPSI: Why Insider-Trading Compliance Is Becoming an Information-Governance Question

For most listed companies in India, managing unpublished price-sensitive information (UPSI) about their own securities has become part of standard governance practice. Codes of conduct, designated persons, trading windows and digital databases are now established features of the compliance framework.

A related question, which deserves greater board attention, is less consistently addressed: what happens when the business receives commercially sensitive information about other listed companies through its ordinary customer, supplier and partner relationships?

How this information enters:

Consider how a business operates. A procurement team negotiates a significant contract with a listed EPC company, and in the course of that discussion, the other party’s representatives share information about its order book, capacity or financial position. A strategy team evaluating a joint venture receives detailed commercial information about a potential listed partner. A senior relationship manager is told by a listed customer about a material change in its business plans.

To the people in these conversations, this is normal business activity. Some of the information exchanged may, in certain circumstances, be price-sensitive in the regulatory sense. The employees involved may not recognise it as such. The organisation’s existing PIT framework may not have been designed with this type of information in mind.

Why this is a leadership issue, not only a secretarial one:

The traditional PIT framework has understandably focused on protecting the company’s own UPSI from misuse. The next governance question is how sensitive information moves across the wider business ecosystem. This is not a question that begins and ends with the secretarial function.

The Company Secretary is well placed to bring this issue onto the governance agenda — as the bridge between management and the board, and as the facilitator of a broader conversation. But effective governance around third-party information flows will involve management, sales, procurement, strategy, legal, technology and risk functions working together.

This reflects a broader principle in how information governance is evolving: good governance is not about being the most restrictive. It is about ensuring that the right controls apply to the right information at the right time.

What the regulatory architecture suggests:

The legal framework provides useful context, though precise application requires expert advice in specific circumstances. A decision of the Securities Appellate Tribunal has established, as a matter of principle, that information sensitivity is not determined by organisational affiliation — the source of UPSI and the company whose securities are traded need not be the same entity as the insider’s employer. Regulation 9(2) of the SEBI (Prohibition of Insider Trading) Regulations, 2015 covers persons required to handle UPSI in the course of business operations. Regulation 9A addresses internal controls under the PIT framework, with oversight obligations on the CEO/MD and audit committee. The application of these provisions to third-party UPSI received through ordinary commercial activity has not been definitively settled, and specific legal advice is recommended.

From a governance standpoint, boards need not wait for regulatory certainty before examining whether their existing frameworks reflect how information actually moves through the business.

What proportionate governance looks like:

Proportionate information governance starts with understanding where the exposure actually sits — not with a new compliance layer. The question is where third-party UPSI can realistically enter the organisation, which functions are most likely to encounter it, and whether existing controls account for those flows.

A useful starting point is to map exposure rather than to assume it is covered by existing frameworks. Business relationships that involve listed counterparties — as customers, suppliers, project partners or strategic targets — may be more extensive than the existing PIT framework was designed to address.

Three actions for management are worth prioritising: mapping realistically where third-party UPSI can enter; identifying the functions most likely to encounter it; and testing whether existing controls address those flows.

The institutional question:

The deeper question is one of institutional trust. Can a listed company be trusted with sensitive information that comes to it through the normal conduct of business? That is increasingly a governance, culture and business-discipline question — and it belongs on the board’s agenda.

Beyond the highlights — explore the complete article at the link → Click here