Market Conduct: The Behaviours the Rules Prohibit
Market conduct regulation prohibits behaviours that damage the fairness of a market rather than any single counterparty: trading on information others do not have, moving a price by artificial means, misleading people about a product, and failing the duties owed to a client. The prohibitions sit in the regulations of the Securities and Exchange Board of India (SEBI), published at sebi.gov.in. A firm implements them through two documents that do different work: a code of conduct and a compliance policy.
A vegetable stall in a district town is worth a minute's attention. The whole exchange runs on two quiet assumptions that nobody ever checks. The scale is telling the truth, and the price called out to one buyer is the price called out to the person standing behind them. Now suppose the scale is set to read a little heavy. Every buyer that morning pays for something they did not receive, in amounts too small for any one of them to notice, let alone to argue about. Nobody feels robbed. Nobody walks back to complain. And the stall has taken a real amount of money, in total, from a hundred people who each lost almost nothing.
Every behaviour set out below has the same shape as the heavy scale: a private gain produced by degrading something everybody else was relying on. Market conductThe behaviours regulation prohibits because they damage the fairness of a market rather than the position of one identified party. regulation is the set of prohibitions written around that shape. The prohibitions are not mainly about one party cheating another party in a way the second party can see and dispute. Each one covers behaviour that takes a thin slice from everybody at once. The harm is therefore hard to point at, and there is usually nobody who turns up to complain about it.
The behaviours below are prohibited because Indian securities law and the regulations made under it prohibit them, and a prohibition does not float free of the country whose law creates it. The regulations are named below, with the body that issues them and the date they were read. Penalty amounts, reporting thresholds and periods of every kind live in the text of those regulations and are amended there. A figure carried in from memory fails somebody at exactly the moment they lean on it.
Bhadra Securities Private Limited, an invented broker and depository participant, employs Yashodhan Pai as its compliance officer, the person who has to answer when anybody asks what the firm actually does about anything. Vindhya Ceramics Private Limited is a listed company whose shares trade, and Prerna Wadekar is its compliance officer. The difference between the two documents is invisible in the abstract and completely obvious the moment somebody at a real desk is offered something by a client.
Why anybody breaches a conduct rule is a separate subject. Behavioural finance takes up what tempts a person, how somebody talks themselves into a decision, and what pressure a desk was under. A rule states what is prohibited. An explanation of motive is a theory about people, and swapping the theory in for the rule quietly replaces something that can be checked with something that can only be argued about. What follows states what is prohibited, how it surfaces, and what a firm is expected to hold.
What does market conduct regulation actually prohibit?
The honest first answer is that there is no single list to memorise. The prohibitions sit across several regulations, they are written in the language of law rather than the language of a checklist, and they get amended. The prohibitions do fall into four recognisable groups, and a group transfers where a list does not.
The first group is about information. Trading on information that other people do not have, or passing that information to somebody who then trades on it, is prohibited. The second group is about price. Moving a price by artificial means, rather than letting it move because somebody genuinely wanted to buy or sell at that level, is prohibited, and creating the appearance of trading that is not real trading belongs in the same group. The third group is about what is said. Misleading people about a product, about what it does, about what it costs or about who is offering it, is prohibited. The fourth group is about the duties a firm takes on the moment it agrees to act for somebody. Failing those duties, by putting the firm's own interest ahead of the client's or by falling short of what is called fair dealingThe duty to treat the interests of a client properly, including handling their business on the terms and in the order the client is entitled to expect., is prohibited.
Taken together, these four are often gathered under the shorthand market abuseThe broad category covering behaviours that distort a price or the flow of information in a market. A useful label rather than a legal category by itself., which is convenient and slightly misleading, because it makes the behaviour sound theatrical. Most of what falls inside these groups is not theatrical at all. The behaviour is small and procedural, and a flat sentence describes it exactly.
A list of prohibited acts goes out of date and a group does not, so grouping the prohibitions beats listing them. A new instrument arrives, a new venue arrives, a new way of getting hold of information arrives, and the specific act that gets written into a regulation changes with it. The condition each group protects does not change. Once it is clear that the first group exists to keep information reaching people on the same terms, anything new can be put to that same question directly, instead of waiting for somebody to add a line to a list.
Four groups, four different acts, four different regulations. What do the prohibited behaviours actually have in common?
Why are these particular behaviours singled out?
Why these four, and not being rude to a client, or running a chaotically organised back office? Both of those are bad. Neither is a conduct prohibition in this sense, and the reason is worth having.
A market works because two things hold. A price means something, in the sense that it reflects what people were actually willing to pay. And information reaches people on the same terms, in the sense that nobody on one side of a trade is looking at something the other side cannot see. Everything else in a market sits on top of those two conditions, and neither of them is enforced by physics. Both conditions hold because enough participants behave as though they hold.
Each prohibited behaviour takes a slice of that shared reliability and converts it into an advantage for one participant. Trading on information others do not have converts the second condition into a private gain. Moving a price by artificial means converts the first. Misleading somebody about a product converts the reliability of what is said. Failing a duty owed to a client converts the reliability of the agent that everybody has to use in order to reach the market at all. Four conversions, one shape.
The harm is therefore diffuseSpread thinly across everybody in a market rather than falling on one identifiable party, so that no single person can measure what they lost. rather than concentrated. The stall with the heavy scale did not take a large amount from one customer. The stall took a very small amount from every customer, and the total is real even though no individual total is large enough to be felt. Diffuse harm is harm nobody notices at the time. The response to it therefore cannot wait for somebody to notice.
Code of Conduct: what is it, and what does it govern?
A code of conductThe document in which a firm states what behaviour it expects of the people who work in it. is the document in which a firm states what behaviour it expects of the people who work in it. The definition is worth keeping that thin. A code of conduct is often described as though it were the firm's conscience, and a conscience is not a document.
A single paragraph is enough to place the register. A code is written in the language of expectation. A person acts in the interests of the client they agreed to act for, ahead of their own interest. A person does not deal on the basis of information the market does not have. A person does not accept anything from a client that could reasonably be taken to affect their judgement. Sentences of that shape, addressed to a person, about what that person does.
None of this is optional decoration in the Indian setting. A registered intermediary is subject to conduct requirements set out in the regulations under which it is registered, and a firm's own code is how those requirements are put in front of the people who have to follow them. Bhadra Securities Private Limited holds one. Everybody at the firm has signed it. Yashodhan Pai can produce a copy of it in under a minute, and being able to produce it is exactly as far as that document goes.
A code of conduct sets a standard, and setting a standard is a genuinely useful act that is nonetheless not the same as implementing it. Nothing in a code says who a situation is reported to. Nothing in it says where anything is written down. Nothing in it says who decides, or by when, or what happens to the decision afterwards. The work of saying who, where and by when belongs to a different document entirely.
Compliance Policy: what is it, and what does it govern?
A compliance policyThe document in which a firm states the processes by which its obligations are met: who acts, in what order, on what record. is the document in which a firm states the processes by which its obligations are met. Same thinness of definition, entirely different subject. A code governs what a person does. A policy governs the firm's response to it.
Its register is procedural and just as recognisable. A situation of this kind is declared to the compliance officer before anything else happens. The declaration is entered in a register kept for the purpose. The compliance officer decides, records the decision, and records the reason for the decision. The register is available for inspection. Nobody in a policy is being told what to believe. Everybody is being told what to do, in what order, to whom, and on what record.
The procedural register gives a compliance policy a property a code of conduct simply does not have. A policy produces evidence as a by-product of being followed. If the policy says a thing is recorded in a register, and the register exists with entries in it, then somebody outside the firm can read the register and see what actually happened. If the policy says a decision is taken by a named role, and the record shows who took it, that can be checked too. A code of conduct, followed perfectly by everybody for years, leaves behind nothing at all.
A compliance policy is what turns an obligation into a route somebody can walk, and what turns a decision into something a third party can examine afterwards. That is why an inspection asks for the policy and the records first, and reads the code afterwards, if at all.
The firm's code of conduct has been read end to end. What does the compliance policy state that the code does not?
Code of Conduct vs Compliance Policy: which one answers what?
Put the two side by side and the difference is one line long. A code of conduct governs behaviour and a compliance policy governs process, and everything else about the pair follows from that single split.
The code answers the question is this acceptable. The policy answers the question what must happen about it. The two questions have different answers, and neither answer contains the other. Knowing that accepting a substantial gift from a client is not acceptable behaviour says nothing whatever about who it is declared to. Knowing that it is declared to the compliance officer before acceptance says nothing about whether accepting it was ever alright in the first place.
The two documents also leave different things behind, and the practical difference bites there. A code leaves a stated standardWhat is expected, as distinct from what is done about it. A standard can be stated without any process existing to give effect to it.: the firm has said what it expects. A policy leaves a route and a record: the firm can show what was done. When somebody inspects the firm, the code tells them what the firm said it expects, and the policy together with its records tells them what the firm actually did. A stated standard and a record of what was done are two different kinds of evidence, and neither substitutes for the other.
A firm can hold both documents in one binder, and plenty do. Combining them physically is fine and often sensible. Combining them in the mind is not. The moment a firm believes it has one document doing one job, it stops asking which of the two questions it has actually answered.
Somebody at Bhadra Securities Private Limited is offered a gift by a client of the firm. Which document governs the situation?
Why does a firm need both, and what fails when it has only one?
The two failure cases fail in opposite directions, and only one of them is famous. Take them separately.
A firm with a code and no policy has values and no evidence. The firm has said what it expects and cannot show what happened. Every situation that arose was handled by somebody using their judgement. The judgement may well have been excellent, and there is no record of any of it. No document said who anything was declared to, so nothing was declared to anybody in particular. No document said where anything was written down, so nothing was written down anywhere in particular. When the question eventually comes, the firm can produce one thoughtful document, and nothing else.
A firm with a policy and no code has records of decisions nobody set a standard for. The declarations are all there in the register, dated and initialled and complete. The line the decisions were being measured against is missing. Ask why a particular declaration was allowed and the honest answer is that somebody at the time decided it was fine, and the fact that the decision is recorded does not turn it into a decision against anything.
Neither document is a weaker version of the other, and a firm holding one of them has not half solved the problem: it has solved one problem completely and the other one not at all. The argument for both is stronger than the usual argument. The usual argument is that regulators expect to see both. Regulators do expect to see both. The reason they do is the paragraph above.
Here is the less familiar direction. A firm has a detailed compliance policy setting out exactly who a gift is declared to, where it is entered and who decides, and it has no code of conduct at all. What is missing?
What happens when somebody at Bhadra Securities is offered a gift by a client?
Here is the single situation that makes all of this concrete, and it is deliberately small. Nothing dramatic happens in it.
Somebody at Bhadra Securities Private Limited is offered a gift by a client of the firm. Not a bribe. Just a gift, of the kind that arrives at a wedding, or at the end of a year that went well for both sides. The person receiving it is genuinely unsure what to do, so they walk over to Yashodhan Pai and ask which document governs this.
The honest answer is both, and each one answers a different half of the question.
The code of conduct answers whether accepting it is acceptable behaviour. The code states what the firm expects of a person who is offered something by somebody whose business that person handles. The wording is about the person and their judgement, and it applies whether or not anybody happens to be watching.
The compliance policy answers what must happen about it. To whom it is declared. By when. Where the declaration is entered. Who decides whether it may be accepted. Where that decision and the reason for it are recorded. Whether the record is available if somebody asks for it a year later.
Ask which document governs the gift and the answer is both, doing different halves of one job, and that single small situation is the clearest demonstration available that the two are not alternatives. Remove the code and the policy still records a declaration, decided against nothing in particular. Remove the policy and the standard still exists, applied by somebody, evidenced nowhere. Yashodhan Pai needs both open on the desk to close the question, and closing the question takes about four minutes when both exist and is not really possible when one is missing.
Somebody trades on information that nobody else in the market has, and makes a gain doing it. Who complains?
Who do conduct rules protect, and why is the answer not the client?
The instinctive answer is the client, and it is wrong in a way worth understanding rather than simply correcting.
Conduct rules do protect clients, and one of the four groups is entirely about duties owed to a client. But the thing being protected across all four groups is the market itself: the condition that makes it usable by anybody at all. Suppose a customer contract at Vindhya Ceramics Private Limited comes to an end, and 9 people inside the company know before the market does. If somebody trades on that, the person on the other side of the trade is nobody's client, has no relationship with anybody involved, and was simply trading that day. The person on the other side is worse off and will never know it. How many of those 9 people are connected persons in the sense the regulations use is a legal characterisation, set out under insider trading.
The absence of an identified victim is what makes the protection impersonal. Conduct rules protect a group nobody can name. There is usually no complainant, and enforcement therefore has to be public rather than responsive. A dispute over a bill has somebody who calls. A product missold to one identified client has somebody who complains, in writing, with a date. A price moved by artificial means has nobody at all. The loss landed in slices across everybody who traded at the wrong price, and no slice was large enough to be felt by the person carrying it.
If nobody complains, nothing is reported, and if nothing is reported then the response has to be built rather than triggered. A regulator therefore runs surveillance rather than waiting for post. An order at the end of an enforcement process is published for the same reason, rather than sent quietly to the person concerned. At Vindhya Ceramics Private Limited, Prerna Wadekar administers the trading window, a mechanism whose period, opening and closing dates and notice interval are set in the regulations and read there.
How is a breach usually discovered?
Not by somebody noticing. The finding runs directly against the intuition almost everybody arrives with.
DetectionHow a breach comes to be known. In this setting it is a property of standing mechanisms rather than of anybody paying attention. in this setting is a property of mechanisms that run whether or not anybody is paying attention, and there are four that matter. Exchange and regulator surveillance watches trading data for patterns that do not fit, continuously, without anybody having decided to look at a particular firm today. Inspection arrives at a registered firm and examines stated areas of its activity, again without anybody having flagged that firm first. A report from inside the firm, from somebody who saw something and said so through a route the firm was required to provide, arrives without any external process at all. And a pattern across accounts or across time is visible to somebody looking at the aggregate and completely invisible to everybody looking at any single piece of it.
Not one of those four depends on anybody being vigilant. The four are the controls for exactly that reason, and vigilance is not one of them. Vigilance is a hope about people. A mechanism is a thing that runs on a schedule whether people are having a good week or a bad one.
A compliance policy quietly earns its place here too. When a mechanism produces a question, the firm's answer is its records. Bhadra Securities Private Limited can answer a question about a declared gift because a register exists with the declaration in it, dated, with the decision and the reason beside it. A firm without the register answers the same question with somebody's recollection, and recollection is not an answer that survives being written down and read back six months later.
A conduct breach at a registered firm comes to light. Statistically, how did it most likely surface?
What does a conduct rule not do?
Three things, and each of them gets assumed regularly enough to be worth naming.
A conduct rule does not explain why anybody would breach it. The rule states what is prohibited. The rule carries none of the rest: what tempts a person, how somebody talks themselves round to a decision, what pressure a desk was under that quarter. Why people do what they do is a real subject with real research behind it, and behavioural finance is where it is taught. Reading a motive into a prohibition swaps a rule that can be checked for a theory that can only be argued about, and the two do not do the same work.
A conduct rule does not decide any particular case either. The rule states what is prohibited. Whether a particular thing that actually happened falls inside that prohibition is a determination somebody has to make on the facts, through a process, and that determination is what an enforcement outcome contains. A rule and a finding are different objects and get confused constantly.
And a conduct rule does not establish that a person sanctioned under it is a bad actor. Many conduct failures are procedural. Several are contested, sometimes for years. Some matters close on agreed terms without anybody determining that the conduct occurred at all. Reading a sanction as a verdict on a person is a reading the document itself does not support, and the flattest available language is the right language for this entire subject.
The prohibition has been read end to end, and somebody's motive remains unexplained. Does a conduct rule explain why a person would breach it?
Where are the prohibitions actually read?
At the source, on the day, with the date written down. There is no shorter honest version of that answer.
The Securities and Exchange Board of India issues the regulations prohibiting fraudulent and unfair trade practices in the securities market, the regulations prohibiting insider trading, and the conduct requirements that apply to a registered intermediary. All of them are published at sebi.gov.in. Each is a live document, each is amended from time to time, and each carries a version date at the source where it is read.
A summary of a regulation is a description of what that regulation said on some day the writer did not necessarily record. Summaries are not thereby useless. A summary is where reading starts and never where it finishes. The current text is the thing to open, with the date of reading noted and checked against any secondary description before that description is relied on for anything that matters.
The one thing worth being strict about is figures. Penalty amounts, reporting thresholds and periods are exactly the kind of item that gets amended quietly, and exactly the kind of item a reader repeats with complete confidence a year later without remembering where it came from, so each is read in the live text rather than carried.
The question is what is prohibited today, precisely rather than roughly, and not as of whenever somebody last wrote about it. Where does that search end?
What the regulations are, and where their figures are read
The prohibitions described above are Indian ones. The Securities and Exchange Board of India issues the regulations prohibiting fraudulent and unfair trade practices in the securities market, the regulations prohibiting insider trading, and the conduct requirements applying to a registered intermediary. All of them are published at sebi.gov.in and were read on 19 August. Where a firm is also regulated by the Reserve Bank of India, obligations issued at rbi.org.in reach it as well.
Four items in this subject move with amendment: any penalty amount, any period of prohibition, any reporting threshold and any settlement figure. Each sits in a text that is amended, and each is the kind of number that does its damage on the day somebody leans on it. Read the current text yourself at the site named, compare the version date printed there against the date recorded here, and treat any question about a particular firm or a particular situation as a matter for the document itself and for advice on the facts.
The firm that writes a code of conduct and believes it has addressed conduct risk
The document is genuinely good. Somebody thought hard about it, it was circulated, everybody signed it, and it sits where it can be produced within a minute. Nothing else changed. No document says who anything is declared to, so there is no route. No document says where anything is written down, so there is no record. The wrong reading is that stating a standard implements it.
The cost arrives later and it arrives in an unpleasant shape. When something goes wrong, the firm can produce a document showing that the behaviour was not permitted and that the firm had said so, in writing, to the person concerned, who signed for it. The signed document establishes exactly one thing: the firm knew. Nothing in it establishes that the firm did anything about it.
A code alone, at precisely the moment it is needed, is evidence of knowledge rather than evidence of diligence, and the two point in opposite directions.
A firm has a thoughtful code of conduct, signed by everybody, and no compliance policy at all. Something goes wrong. What does the firm have?
How does somebody outside the firm actually use any of this?
Three readers use it differently, and all three make the same move.
Somebody choosing a broker or a depository participant, for a household account or for a small business, can ask the firm for its conduct documents. Most registered firms publish them or will provide them on request. The move is not to read the code and be reassured by how it sounds. A code is written to sound reassuring, and succeeding at that establishes nothing. The move is to look for the policy behind it and put two questions to the policy: does it name a role that decides, and does it name a record. A document that says the firm is committed to the highest standards of integrity, and never names a person or a register anywhere in it, has described a hope rather than a practice.
An analyst or a lender looking at a regulated firm makes the same move for a different reason. A firm whose obligations are met by named routes and standing records behaves predictably when an inspection arrives. The answers already exist in a drawer. A firm whose obligations are met by good people exercising judgement also behaves predictably, right up until the good people change jobs, and people change jobs constantly.
The split changes the question somebody inside a firm asks when something unusual lands on the desk, and that is the most direct use of the pair. The instinct is to ask what should be done, and that question invites a judgement and produces an answer nobody can check. The better question is which document governs this, and that question usually returns two answers and a route. Holding the two documents apart has exactly that practical value, even when they are stapled together on the shelf.
Penalty amounts, reporting thresholds, settlement figures and periods of every kind, including the length of any trading window, are read in the live text of the regulations named above. Why anybody breaches a conduct rule belongs to behavioural finance. Who counts as a connected person, what unpublished price sensitive information is, and how a trading window works are set out under insider trading. The anti-money laundering obligations on a financial intermediary are set out separately. Inspection and investigation are set out under supervisory actions, and what an enforcement order contains under enforcement orders and adjudication.
References
| Source | Document | Where |
|---|---|---|
| Securities and Exchange Board of India | The regulations prohibiting fraudulent and unfair trade practices in the securities market. The source of the price group of prohibitions and of the misleading-statement group | sebi.gov.in |
| Securities and Exchange Board of India | The conduct requirements applying to a registered intermediary. The source of the conduct obligations a registered firm carries by virtue of its registration | sebi.gov.in |
| Securities and Exchange Board of India | The regulations prohibiting insider trading. The source of the information group of prohibitions, and of the trading window as a mechanism | sebi.gov.in |
| International Organization of Securities Commissions | The published principles addressing conduct in securities markets. The source of the four-group sorting of these behaviours used above | iosco.org |
Bhadra Securities Private Limited, Yashodhan Pai, Vindhya Ceramics Private Limited and Prerna Wadekar are invented.
Educational material. Not advice on any investment, tax, budget or market position.
