Governance of unpublished price-sensitive information is becoming a business imperative

/ 3 min read
AI Hub

As the scale of India’s listed markets reaches new highs, companies must be able to demonstrate how sensitive information moves through their organisations.

Representational image
Representational image

The combined market capitalisation of companies listed on the BSE stands at about ₹494 lakh crore. As the scale, participation and breadth of India’s listed market grow, so does the responsibility to protect the information on which investment decisions are made.

ADVERTISEMENT

The markets landscape is evolving rapidly, more companies are preparing to go public, retail participation has widened, and institutional investors are becoming more selective. Governance, transparency, earnings visibility, and realistic valuations now carry as much weight as the ability to complete an IPO. At the same time, companies work with a wider network of bankers, lawyers, auditors, consultants and other advisors, each of whom may encounter sensitive information at different stages.

This is where the prevention of insider trading becomes a business issue. Companies preparing to list, as well as established listed entities, need an insider-trading framework that works when tested. That means protecting sensitive information, assigning clear responsibility and maintaining a reliable record of who knew what, when and why. Investor trust depends on this discipline.

ADVERTISEMENT

Listed entities have been advised, by the exchanges, to maintain complete structured digital database records, periodically review policies intended to prevent UPSI leakage, train employees and fiduciaries, and ensure that their codes of conduct work in practice. When unpublished price-sensitive information, or UPSI, is shared, the individuals handling it must also be recorded.

A company may have a comprehensive insider-trading policy, a structured digital database, or SDD, and a process for closing trading windows. These are essential foundations. Their value depends on what happens when information first becomes price-sensitive. Was it identified at the right time? Who received it? Why was it shared? Was

access limited? Can the company demonstrate how it remained protected until disclosure?

Recommended Stories

Weak controls can result in regulatory action and reputational damage; they can also expose a deeper governance weakness. Delayed or retrospective SDD entries, differences between project records and the database, unclear reasons for sharing information, and incomplete records of project team changes can leave a company unable to establish who knew what and when.

The risk is especially acute outside financial-result periods. A potential acquisition, a large contract, a financing arrangement, a leadership change or an unexpected movement in business performance may become price-sensitive while the standard trading window remains open. Calendar-based controls cannot capture every such event; the framework must respond when the information takes shape.

ADVERTISEMENT

Companies need clear triggers for identifying UPSI and clear ownership of that judgement. The assessment should begin when information becomes specific enough to materially affect the price of securities, even if the underlying proposal is still evolving. Once identified, the entire lifecycle should be captured: where the information originated, who created, accessed, shared and received it, why access was required, and when it entered the public domain.

The SDD should become the spine of this evidence trail; its entries should be reconciled with emails, data-room access, board papers, confidentiality undertakings, legitimate-purpose approvals, pre-clearance records, trading restrictions and stock exchange disclosures. Exceptions should be investigated, escalated and closed through a documented process. Regular testing tells boards whether the control environment works during real events.

Most Powerful Women In Business 2026
View Full List >

Technology can make this trail easier to maintain, though judgement and accountability remain central. Training should reflect the situations faced by Boards, CXOs, transaction teams, designated persons and external advisers. Role-based sessions built around real business scenarios can help each group recognise UPSI early and follow the appropriate safeguards when sensitive developments arise.

For companies preparing for an IPO, UPSI governance should form part of the transition to public-company readiness. The listing process places valuations, financial performance, capital structures, business plans, and investor feedback before a large advisory network. Building information discipline during this period prepares the organisation for the scrutiny that follows listing.

For listed companies, the direction is clear. Policies and systems must be supported by timely evidence, defined accountability and regular testing. As India’s public markets grow in value and participation, investor trust will depend on what companies can demonstrate. Strong UPSI governance protects that trust through controls that can withstand regulator scrutiny.

(The author is partner, Grant Thornton Bharat. Views are personal.)

NEXT STORY