Outsourcing Policy for SEBI-Registered Research Analyst
1. Objective
The purpose of this policy is to:
- Establish a structured approach for outsourcing by a SEBI-registered Research Analyst.
- Ensure that outsourced activities do not compromise regulatory obligations, data integrity, or business continuity.
- Outline controls to manage associated risks and ensure adherence to SEBI guidelines.
2. Applicability
This policy applies to:
- All outsourcing arrangements entered into by the Research Analyst, including past and future engagements.
- All departments and business functions engaging or proposing to engage third-party vendors for services related to RA operations.
3. Definition of Outsourcing
Outsourcing refers to the use of a third party (whether affiliated or independent, within India or abroad) to perform activities associated with services offered by the Research Analyst, which the RA may otherwise perform internally. Examples include:
- Data processing
- Back-office operations
- Client query handling (non-research)
- IT support or infrastructure
- Document digitization and storage
4. Prohibited Outsourcing Activities
- Preparation and dissemination of research reports
- Execution of client service agreements
- Compliance monitoring and reporting
- Internal audit and regulatory reporting
- KYC compliance
5. Guiding Principles for Outsourcing
5.1 Due Diligence
Prior to outsourcing any activity, a comprehensive due diligence process must be conducted to assess:
- Financial and operational capability of the service provider
- Technical expertise, infrastructure, and staffing
- Legal and regulatory compliance history
- Data protection and cybersecurity measures
- Business continuity and disaster recovery preparedness
5.2 Risk Management
Outsourcing arrangements must consider and mitigate the following risks:
- Operational Risk โ service disruption or errors in execution
- Reputational Risk โ vendor misconduct affecting the RA’s credibility
- Legal Risk โ breach of regulatory laws, litigation, or penalties
- Country Risk โ political, regulatory or legal instability in the vendor’s jurisdiction (in case of offshore outsourcing)
- Strategic Risk โ misalignment of the vendor’s business model with the RA’s strategic goals
- Concentration Risk โ excessive reliance on a single vendor or geography
- Exit Strategy Risk โ inability to transition services or exit the relationship smoothly
6. Responsibilities and Governance
6.1 Role of the Board / Partners
- Approve the outsourcing policy and material outsourcing arrangements.
- Monitor the effectiveness of risk mitigation controls periodically.
- Ensure that the RA retains ultimate accountability for all outsourced functions.
6.2 Internal Controls
- A centralized record of all outsourcing arrangements shall be maintained.
- All outsourced services shall be regularly monitored and reviewed.
- Responsibility for compliance and quality of service shall remain with the RA.
7. Outsourcing Agreement
Every outsourcing arrangement must be documented via a legally binding contract that includes the following clauses:
| Clause | Description |
|---|---|
| Scope of Services | Clearly define outsourced functions and performance standards. |
| Data Security | Vendor must implement adequate security measures to protect RA and client data. |
| Confidentiality | No disclosure of any data or information to unauthorized persons. |
| Regulatory Access | Allow SEBI or RAASB to access the vendor’s records relevant to outsourced services. |
| Termination | Terms for exit, including notice period and transfer of data/assets. |
| Business Continuity | Provision for alternate arrangements and disaster recovery. |
| Compliance | Obligation to comply with applicable Indian laws, SEBI regulations and this policy. |
| Audit Rights | RA reserves the right to conduct audits, either internally or via external professionals. |
8. Monitoring and Review of Vendor Performance
- Periodic performance reviews shall be conducted against agreed SLAs (Service Level Agreements).
- Key Risk Indicators (KRIs) and audit findings shall be tracked.
- Any deviation from agreed standards must trigger immediate corrective action.
9. Data Privacy and Information Security
- Data shared with vendors must be limited to what is essential for service performance.
- Vendors must comply with the Information Technology Act, 2000, SEBI’s cybersecurity circulars, and other applicable laws.
- No client-sensitive information shall be processed outside India unless permitted under law and adequately protected.
10. Reporting of Suspicious Activities
RAs remain solely responsible for reporting suspicious transactions to:
- Financial Intelligence Unit (FIU-IND)
- SEBI or any competent authority, even if such activity is detected through outsourced channels.
11. Business Continuity and Exit Strategy
- The outsourcing agreement must include an exit strategy with minimal business disruption.
- A detailed Business Continuity Plan (BCP) shall be in place for each material outsourcing arrangement, reviewed annually.
12. Review of the Outsourcing Policy
- This policy shall be reviewed at least once every year, or whenever there is a material change in SEBI guidelines.
- The review shall be conducted by the Compliance Officer and approved by the Board / Partners.
13. Documentation and Record Retention
- All outsourcing-related documents (agreements, evaluations, performance reports, etc.) shall be retained for a minimum of five years.
- In case of ongoing investigations or legal issues, records shall be retained until the matter is resolved.
14. Policy Disclosure
A summary of this policy may be disclosed on the website of the Research Analyst as part of regulatory transparency, if deemed appropriate.
Regards,
Trade Nova Technologies Private Limited
SEBI Registered Research Analyst
SEBI Registration No.: INH000026789
Need help with this?
Our Principal Officer, Harinder Singh, and Compliance Officer, Pardeep Kumar, are available MonโFri ยท 9:00 AM to 5:00 PM.