Audit committee review of insider trading controls
The audit committee's yearly review of the company's compliance with the PIT Regulations and of the effectiveness of its internal controls.
Audit committee review, at least once a financial year
- SEBI
- Insider trading and takeovers
- Not specified
- 2026-09-01
Once every financial year, with no fixed date. PIT Reg 9A(4) requires the audit committee of a listed company to review compliance with the PIT Regulations at least once a financial year and to verify that the systems for internal control are adequate and operating effectively. There is no filing and no certificate, so the obligation is met by the review happening and being minuted before the financial year closes.
This obligation is widely listed as a Reg 9A certification by the chief executive or managing director. No such certification exists. The only dated item in Reg 9A is the audit committee's once-a-year review, and the internal control duty around it carries no filing.
Deadlines counted from an event
The audit committee reviews compliance with the PIT Regulations at least once a financial year and verifies that the internal controls are adequate and operating effectively. Reg 9A(4) sets a minimum frequency, not a date, so the calendar shows the cadence rather than a deadline.
The rule
The audit committee reviews compliance with the PIT Regulations at least once a financial year and verifies that the internal controls are adequate and operating effectively. Reg 9A(4) sets a minimum frequency, not a date, so the calendar shows the cadence rather than a deadline.
Who must comply
- The audit committee of every listed company
- The board of directors, where a company has no audit committee, since Reg 9A places the duty on other analogous body in that case
Statutory basis
Before you file
- Get the compliance officer's report for the year.
- Get the structured digital database access log for the year.
- Get the list of trading window closures and pre-clearances for the year.
- Get the list of code of conduct breaches and the action taken.
- Put the review on an audit committee agenda before the financial year closes.
How to file
- Table the compliance material at an audit committee meeting.
- Review compliance with the PIT Regulations for the year.
- Verify that the internal controls are adequate.
- Verify that the internal controls operate effectively.
- Record the review and the committee's conclusions in the minutes.
- Do not file anything with SEBI or an exchange. The minutes are the record.
If you miss it
There is no fee and no filing, so the head is section 15HB of the SEBI Act, which allows a penalty of up to ₹1 crore for a contravention with no separate penalty prescribed. In practice the failure surfaces during an inspection or an insider trading investigation, where the absence of a minuted review undercuts the company's case that its controls were adequate.
- Reg 9A(1) to 9A(3) put the internal controls on the chief executive or managing director and make the board responsible for ensuring they do it, so a missing review reflects on both
- A company with no minuted review has no documentary answer to a question about control effectiveness, which is the question SEBI asks first after a leak
Recent changes affecting this
Common questions
Is there a CEO or managing director certification under Reg 9A?
No. Reg 9A(1) and 9A(2) require the chief executive or managing director to put internal controls in place, Reg 9A(3) makes the board responsible for ensuring that happens, and Reg 9A(4) requires the audit committee review. None of that is a certificate and none of it is filed.
When in the year does the review have to happen?
Reg 9A(4) sets a minimum of once a financial year and names no date, so any audit committee meeting in the year will do. Most companies take it with the year-end compliance report.