Inside a SEBI Investigation: How Your SDD Records Become Evidence Against You
InsiderQ • Evidence Against You • 7 min read
Quick Answer
When SEBI investigates suspected insider trading, one of the first documents it pulls is the company's Structured Digital Database (SDD). Investigators don't read it as a form that was filled in correctly they read it as a timeline. They compare who had access to unpublished price sensitive information (UPSI), when they got it, and whether their trades line up. Gaps, late entries, or missing names don't just look sloppy. They can turn a routine compliance check into a personal liability problem for the Compliance Officer.
That distinction filing versus timeline is the whole article in one sentence. Everything below explains why it matters and what to do about it.
What the SDD Is Actually For
The Structured Digital Database is a mandatory, tamper-evident record that every listed company and market intermediary must maintain under Regulation 3(5) of the SEBI (Prohibition of Insider Trading) Regulations, as amended in 2018. It became compulsory from April 1, 2019.
Every time UPSI is shared inside or outside the company, the SDD is supposed to capture:
- The nature of the UPSI (what the information was)
- The names of the people who shared it and who received it
- The date and time it was shared
- The purpose of sharing it due diligence, a board meeting, an advisory mandate, and so on
- The PAN of every recipient
Think of it less as a filing cabinet and more as a flight recorder. It exists so that if something goes wrong later, regulators can reconstruct exactly who knew what, and when they knew it. That's what makes large-scale insider trading investigations possible at all without it, SEBI would be relying on guesswork and voluntary disclosure.
How SEBI Actually Investigates Using SDD Records
SEBI doesn't open a file, read the SDD top to bottom, and move on. Investigators follow a fairly consistent sequence once something looks off.
- Spot the trading anomaly. SEBI's surveillance systems track pre-announcement trading volume, price swings, and options activity across exchanges. A spike like unusual call-option buying a few days before good earnings news is often the trigger that opens a case.
- Reconstruct the UPSI timeline. Investigators pin down exactly when the price-sensitive information first existed. For quarterly results, that might be the date the CFO saw the draft P&L. For a deal, it might be the day the term sheet was signed. The SDD is supposed to already reflect this.
- Cross-check the SDD against trading activity. Everyone named in the SDD as having had access to the UPSI gets compared against everyone who traded the stock during that window. Overlap alone isn't proof of wrongdoing but it puts people on a list that now requires an explanation.
- Flag people who traded but aren't in the SDD. This step tends to produce the first real finding. If someone traded during the UPSI window and their name is nowhere in the SDD, investigators need an explanation. Sometimes it's a genuine gap, which is still a compliance failure. Sometimes it points to something worse: records that were inaccurate or edited after the fact.
- Check when entries were actually made. Since the 2025 PIT Amendment (effective June 9, 2025), UPSI must be logged into the SDD within two calendar days of coming into existence. Investigators look closely at entry timestamps. A cluster of entries all dated the same day, weeks after the events they describe, is exactly the pattern that draws scrutiny.
Checkpoint SDD vs. Forensic-Grade SDD
Not all SDDs are built the same, and the gap between "technically compliant" and "would survive an investigation" is bigger than most companies assume.
| Feature | Checkpoint SDD | Forensic-Grade SDD |
|---|---|---|
| Format | Excel sheet or basic shared database | Purpose-built system with controlled access |
| Update frequency | Monthly or quarterly batches | Within the 2-day statutory window |
| Timestamps | Manually typed, editable | Immutable, server-generated at entry |
| Audit trail | None | Full log of who entered, edited, or deleted each record |
| Coverage | Formal board paper recipients only | Advisors, bankers, consultants, informal disclosures under NDA |
| Link to trading window | Not connected | UPSI event, window closure, disclosure, and reopening all documented |
| Retention readiness | Ad hoc, single location | Backed up, structured for the 8-year mandate |
Key takeaway: If a company hands SEBI a checkpoint-style SDD, investigators register a finding before they've even looked at the trading data that the company failed to maintain records it was legally required to keep.
Red Flags Investigators Look For
Based on SEBI's published enforcement orders, certain patterns in SDD records consistently draw extra attention:
- Bulk retroactive entries. A company generating UPSI continuously through board meetings, fundraising, management discussions should show entries spread over time, not bunched together.
- Missing PAN numbers. The PIT Regulations require a PAN for every recipient. Blank or placeholder fields suggest the database wasn't maintained carefully.
- Mismatched trading window dates. If the SDD shows UPSI first logged on a certain date, but the trading window closed five days earlier, investigators will ask what triggered that early closure.
- Suspiciously short UPSI windows. If information seems to enter and exit UPSI status very fast every time, investigators may question whether events were classified narrowly to minimise compliance obligations.
- Entries added after an enforcement notice arrives. This is the most serious red flag on the list. It can shift the case from a civil compliance penalty into an allegation of obstruction or record falsification.
Common mistake: Treating the SDD as something to "clean up" once a quarter, rather than something updated in real time. By the time a company realizes gaps exist, the two-day entry window has usually already been missed for months of activity.
Who's Personally on the Hook
This is the part many Compliance Officers underestimate: the SDD isn't an anonymous corporate document. Regulation 3(5) places the maintenance obligation on the listed entity, but SEBI's enforcement history including the Edelweiss Financial Services case, where the Compliance Officer was personally penalised shows that the CO is treated as the accountable individual in practice.
Penalty Exposure at a Glance
| Provision | Penalty | Applies To |
|---|---|---|
| Section 15G, SEBI Act, 1992 | ₹25 crore or 3× profits, whichever is higher | Insider trading-related violations |
| Section 15A(b), SEBI Act, 1992 | ₹1 lakh per day, up to ₹1 crore total | Record-keeping failures, in addition to any underlying penalty |
The 8-Year Retention Rule: Why It's Harder Than It Sounds
The 2025 PIT Amendment introduced a mandatory 8-year retention period for SDD records. On paper that's a storage requirement. In practice, it's an operational one.
- Any company listed since April 2019 needs to retain records across every technology change, office move, staff turnover, and data migration that happens in between.
- An SDD kept in an Excel file today raises a hard question: where will that exact file be in 2031, who will still have access to it, and can anyone prove it wasn't edited afterward?
- Companies that weren't rigorous about SDD maintenance in the early years now have a documented, multi-year gap that SEBI could still investigate.
Expert tip: Retention isn't just "don't delete the file." It's maintaining a chain of custody strong enough that a record can be authenticated as having been made at the time it claims to have been made. A record nobody can vouch for is worth far less than one with a verifiable audit trail even if the underlying data is identical.
Why SME-Listed Companies Can't Assume They're Lower Risk
Companies on the BSE SME and Startup Platform sometimes assume lighter compliance obligations across the board, and for some LODR Regulation 46 disclosure requirements, that's partly true.
It is not true for the PIT Regulations. There is no SME carve-out. Every listed company regardless of size, trading volume, or market cap must maintain a compliant SDD, enforce trading window restrictions, monitor designated persons, and retain records for 8 years.
If anything, the practical risk is higher at smaller companies:
- Larger companies typically run a dedicated, full-time compliance function with purpose-built systems.
- At smaller companies, the Compliance Officer role is often part-time, systems are basic, and processes set up at IPO haven't kept pace with SEBI's evolving requirements.
When SEBI requests an SDD, it doesn't scale its expectations to the size of the company.
SDD Compliance Checklist
Use this as a quick self-audit not a substitute for a full compliance review:
- UPSI events are logged within 2 calendar days of occurring
- Timestamps are system-generated, not manually entered
- Every recipient's PAN is captured and complete
- Advisors, bankers, and consultants under NDA are included, not just internal staff
- There's a visible link between each UPSI event and the related trading window closure
- Edit and access logs exist and are reviewable
- Records are backed up in a way that would survive an 8-year retention period
- Entries happen continuously, not in monthly or quarterly batches
Key Takeaways
- SEBI reads the SDD as a chronological record of who knew what and when not a compliance form to be checked off.
- Investigations follow a set pattern: spot the anomaly, map the UPSI timeline, cross-check against trades, flag unexplained overlaps, and scrutinise entry timestamps.
- A "checkpoint" SDD creates an automatic compliance finding before trading data is even reviewed.
- The 2025 PIT Amendment requires UPSI entries within 2 calendar days and record retention for 8 years.
- Compliance Officers face personal liability, with penalties reaching ₹25 crore or 3× profits under Section 15G, plus up to ₹1 crore under Section 15A(b) for record-keeping failures.
- SME-listed companies have no carve-out under the PIT Regulations, despite lighter obligations elsewhere.
When SEBI requests your SDD, the regulator does not apply a size discount on what it expects to find.