When Other Companies’ UPSI Enters Your Business

September 1, 2026

Why boards should treat third-party UPSI as an information-governance issue — not merely an insider-trading control.

1. The blind spot

Listed companies have made considerable progress in managing unpublished price-sensitive information (UPSI) relating to their own securities. Codes of conduct, designated persons, trading windows and structured digital databases are now established governance features for most. But there is a second information-governance question that deserves the board’s attention, and it is less consistently examined:

What market-sensitive information about other listed companies enters your organisation through ordinary business activity — and how does your existing framework address it?

Consider a few unremarkable situations. A procurement team negotiates a large contract with a listed EPC company and learns, in the course of that discussion, material information about its order pipeline. A business development team evaluating a joint venture receives commercially sensitive information about a potential listed partner’s financial position. A key-account manager is told by a listed customer about a significant change in its strategic plans.

For the people in those conversations, this is the ordinary texture of business. Some of the information exchanged may, in certain circumstances, be price-sensitive in the regulatory sense. The people receiving it may not recognise it as such.

The question for governance is not whether any breach has occurred. It is whether the organisation has thought clearly about where this kind of information enters, who encounters it, and whether its existing frameworks account for that reality.

2. Why leadership should care:

This is not a question for the secretarial function alone. It arises through the business — procurement, sales, strategy, project management, key relationships — and the people best positioned to understand it are often in functions that sit at some distance from the traditional PIT compliance framework.

Confidential information also does not move only through formal documents. It moves through meetings, conversations, emails, presentations, shared platforms and informal exchanges. A policy response alone is therefore unlikely to be sufficient. The question is whether governance has kept pace with how businesses actually operate.

There is a useful way to frame this for the board. The traditional PIT framework has understandably focused on protecting the company’s own UPSI. The next governance question is how sensitive information moves across the wider business ecosystem — and what responsibilities flow from operating in that ecosystem.

This is not a new category of regulatory risk created by recent enforcement. It is an existing governance question that has not always been examined in the context of third-party information.

Good governance is not about being the most restrictive. It is about the right control around the right information at the right time.

3. What the regulatory architecture tells us:

The legal and regulatory framework provides context for this governance question, though the precise application in specific circumstances requires expert advice.

SEBI’s enforcement has established a foundational principle in one relevant decision: the source of UPSI and the company whose securities are traded need not be the same as the insider’s own organisation. In V.K. Kaul v. SEBI (Appeal No. 55 of 2012, SAT, October 2012), the matter involved a person who had access to UPSI concerning one listed company and traded in that company’s securities, though his primary association was with another company.1 This establishes, as a matter of principle, that information sensitivity is not determined by organisational affiliation.

SEBI’s proceedings involving ICSA (India) Limited’s transactions with state electricity boards, and the SAT’s subsequent consideration of the matter in G. Bala Reddy & Others v. SEBI (July 2019), illustrated that commercial and contractual processes can generate price-sensitive information before any formal corporate announcement.2 This is relevant context for understanding how UPSI can arise through ordinary business activity.

Regulation 9(2) of the SEBI (Prohibition of Insider Trading) Regulations, 2015 covers “every other person who is required to handle UPSI in the course of business operations.” Whether and how this provision applies to a listed company’s situation when it receives third-party UPSI through ordinary commercial activity is a question that has not been definitively settled, and specific legal advice is recommended in context.

Regulation 9A requires the CEO or managing director to put adequate and effective internal controls in place and requires the audit committee to review and verify that those controls are adequate and operating effectively. The scope of this obligation in relation to third-party UPSI should similarly be reviewed in context.

From a governance standpoint, the more important question is whether existing frameworks reflect the way information actually moves through the business. Boards need not wait for regulatory clarity before examining whether their information flows are well-governed.

We note, based on our current research, that we have not identified a SEBI enforcement order specifically holding a non-intermediary commercial company liable for failing to establish a framework for third-party UPSI received in the ordinary course of business. This does not constitute legal advice, and the regulatory position continues to evolve.

A recent SEBI enforcement matter – SEBI interim order in the matter of IEX dt: October 15, 2025 – illustrates the regulator’s attention to information-based cases arising from commercial and regulatory activity. The governance-minded organisation treats this not as an enforcement alert but as a prompt to examine its own information architecture.

4. Five questions for the board:

1. Do the people closest to our customers and suppliers recognise information sensitivity?

The individuals most likely to encounter third-party UPSI through ordinary business activity are often outside the traditional compliance framework — in procurement, sales, business development, strategy, operations and key-account management. They need not become securities-law experts, but they should be able to recognise when a commercial conversation has moved into potentially sensitive territory, and understand what the organisation expects of them in that circumstance. The governance function is well placed to facilitate this awareness — as a bridge to management, not as a gatekeeper.

    BOARD QUESTION: Which people in our business are closest to sensitive information about our listed customers, suppliers and strategic partners — and do they understand their responsibilities?

    2. Is our framework built for how information actually moves?

    Information does not travel only through formal channels. It moves through informal conversations, messaging platforms, shared documents and verbal briefings. A framework that addresses policy language alone is unlikely to account for these flows. The question for the board is whether confidentiality is a feature of the operating model — in how workflows are designed, how systems are configured, how data rooms and access controls operate — rather than only a clause in an agreement.

    BOARD QUESTION: Does the way our business actually handles information reflect the sensitivity of what it receives?

    3. Are we prepared to enforce our framework consistently?

    A governance framework has value only if the organisation is willing to apply it consistently — including in situations where the person involved is commercially important. This is not merely a legal or compliance question; it is a question of institutional culture. It is also a practical question: management should consider the enforcement implications of the framework before, not after, the first difficult situation arises.

    BOARD QUESTION: If our framework were tested against a senior or high-performing member of the team, would we apply it?

    4.  Are we proportionate rather than performative?

    The objective is governance that enables confident business activity, not governance that creates friction for its own sake. Proportionality requires calibrating the level of control to the realistic sensitivity of the information — a routine supplier discussion and a transaction involving a listed counterparty are not the same. Frameworks that are formally comprehensive but practically unwieldy tend not to function as intended.

    BOARD QUESTION: Does our framework actually work in the way business is conducted — or would it break down under normal operating pressure?

    5. Does our responsibility extend to our business partners?

    The information chain does not end at the boundary of the listed company. A smaller supplier, contractor or JV partner may receive commercially sensitive information in the course of a business relationship yet have no established framework for handling it. There is a governance dimension to consider here: not imposing compliance requirements on every counterparty, but ensuring that sensitive information shared with third parties is accompanied by appropriate confidentiality discipline

    BOARD QUESTION: Do our business partners understand the sensitivity of information they receive from us — and do our agreements and practices reflect that?

    5. What good information governance looks like: Proportionate governance in this area does not require a separate compliance programme or a new category of designated persons. It requires an institution to examine how information moves through its business and whether its architecture reflects that reality. A high-level framework might proceed as follows:

    • IDENTIFY  Where can third-party UPSI enter the organisation?

    Map the business relationships, workflows and processes through which sensitive information about other listed entities could realistically enter — customer relationships, supplier contracts, strategy discussions, M&A, project negotiations, JV conversations. Avoid limiting this exercise to job titles or existing designated-person categories.

    • MAP  Which roles and processes are realistically exposed?

    Identify the functions, teams and individual roles that are most likely to encounter this information in the ordinary course of their work. This is a business question as much as a governance question, and it benefits from involving the relevant business heads rather than only the governance function.

    • CLASSIFY AND ESCALATE  What happens when potentially sensitive information enters?

    Establish a clear pathway for individuals who encounter information that may be sensitive: how to recognise it, who to inform, and what restricted treatment, if any, should follow. This need not be complex, but it must be practical and understood.

    • CONTROL  What proportionate people, process and technology controls apply?

    Controls may include information classification, access management, restricted data rooms, confidentiality protocols, audit trails and, where legally relevant, trading restrictions. The appropriate level of control should be calibrated to the realistic sensitivity of the information and the nature of the relationship.

    • ASSURE  Who checks that the framework actually functions?

    Periodic review by management and oversight by the audit committee or board committee creates institutional accountability. The question is not only whether the framework exists, but whether it operates as intended.

    6. Three actions for management:

    1. Map where third-party UPSI can realistically enter: Commission a structured conversation with key business heads — in procurement, sales, strategy, projects and key-account management — about the listed entities they interact with and the nature of the information they receive. This does not require a legal exercise; it requires business self-awareness.
    2. Identify the functions most likely to encounter it: Work beyond the existing designated-persons framework to understand which people in the organisation are regularly in a position to receive sensitive information about other listed entities. These individuals may not have been included in standard PIT training or awareness.
    3. Test whether existing controls address the real information flow: Review the organisation’s current policies, access controls, workflows and training programmes and assess whether they account for information received from, or about, listed counterparties. Where gaps exist, design proportionate responses.

    7. From PIT compliance to information governance:

    The issue raised in this note ultimately reflects a broader evolution in how listed companies should think about information. The traditional insider-trading conversation has been framed around protecting the company’s own UPSI from misuse. That remains important.

    But businesses do not operate in isolation. They operate through ecosystems of customers, suppliers, contractors, JV partners and counterparties. Information moves across those relationships in both directions. Some of that information will, in certain circumstances, meet the definition of UPSI with respect to other listed entities. The governance question is whether the organisation has considered those flows and whether its architecture is proportionate to them.

    This is also an opportunity to elevate the Company Secretary’s role. Historically, PIT governance has been largely a secretarial function. A mature information-governance framework requires the Company Secretary to facilitate a conversation that draws in management, sales, procurement, legal, technology and risk — as the architect of a broader governance agenda, not only as the administrator of a compliance requirement.

    8. The institutional question:

    A governance framework that addresses only the company’s own UPSI is necessary, but not sufficient for a listed company operating through the full complexity of a modern business ecosystem.

    The deeper question is one of institutional trust: can we be trusted with sensitive information that comes to us simply because of the business we conduct with others? This is a question of business culture and leadership discipline — not primarily a regulatory one.

    The organisations that examine this question calmly and early — that have designed proportionate systems, built appropriate awareness, and developed the discipline to apply them — are the ones whose governance is genuinely fit for how business operates. For a listed company, that is governance, not compliance.

    NOTES

    1  V.K. Kaul v. SEBI, Appeal No. 55 of 2012, SAT, order dated 8 October 2012. The case involved trading in Orchid Chemicals & Pharmaceuticals Ltd shares on information about a proposed acquisition by a Ranbaxy subsidiary. The principle is relevant because the UPSI related to the traded company’s securities, though the individual’s association was with another listed company.

    2  ICSA (India) Ltd / G. Bala Reddy & Others v. SEBI, SAT, decided 12 July 2019. SEBI’s original proceedings concerned UPSI arising from work orders involving state electricity boards, examining when information from a tender process became price-sensitive.