Flock

Can a debenture trustee outsource its work?

By Flock Research · Filings research desk

Debenture trustee outsourcing is allowed, but SEBI draws two hard lines around it. The trustee cannot outsource the work that makes it a trustee, and it cannot outsource the liability for anything it does outsource. Everything else is a risk management exercise governed by a board approved policy. This guide covers what cannot be outsourced, who carries the loss when a vendor fails, and the group company rule. It is not investment advice.

Definition

Outsourcing by a debenture trustee

is the use of one or more third parties, within or outside its group, to perform activities associated with the services it offers. Chapter XIV of SEBI's Master Circular for Debenture Trustees governs it and bars outsourcing of core business activities and compliance functions. Source: SEBI.

What can a debenture trustee not outsource?

Two categories, stated flatly. Paragraph 4 of Chapter XIV of SEBI's Master Circular for Debenture Trustees, SEBI/HO/DDHS-PoD-1/P/CIR/2025/117 dated August 13, 2025, provides that a debenture trustee desirous of outsourcing its activities shall not outsource its core business activities and compliance functions.

Chapter XIV also opens by naming the reason the rule exists. SEBI notes that intermediaries often resort to outsourcing to reduce costs and at times for strategic reasons, while the DT Regulations require debenture trustees to render high standards of service and exercise due diligence and proper care in their operations.

Two obligations stay with the trustee regardless of any arrangement. It must comply with the SEBI (KYC Registration Agency) Regulations, 2011 and guidelines issued under them. And it is responsible for reporting any suspicious transactions or reports to the Financial Intelligence Unit or other competent authority in respect of activities carried out by third parties.

Who bears the loss if a vendor fails?

The trustee, entirely. Paragraph 3 of Annex-XIVA requires that outsourcing arrangements neither diminish the trustee's ability to fulfil its obligations to customers and regulators, nor impede effective supervision by the regulators. Four sub-paragraphs give that effect.

ProvisionEffect
3.1The trustee is fully liable and accountable for outsourced activities to the same extent as if the service were provided in-house
3.2Arrangements do not affect investor rights against the trustee. It is liable for losses caused by third party failure and responsible for redressing grievances arising from third party activity
3.3Facilities, premises and data used for the outsourced activity are deemed to be the trustee's. The trustee and the regulator, or persons authorised by it, may access them at any point of time
3.4Arrangements must not impair SEBI, SRO or auditor supervision or inspection of the trustee

Fully liable

The debenture trustee's accountability for an outsourced activity, being the same as if the service were provided in-house

Source: SEBI Master Circular for Debenture Trustees, SEBI/HO/DDHS-PoD-1/P/CIR/2025/117, Annex-XIVA paragraph 3.1, dated August 13, 2025

For a bondholder, that is the practically useful part. A complaint about something a vendor did is still a complaint against the trustee, and the trustee has to redress it.

What must the board approve before anything is outsourced?

A policy, and the responsibility for it sits at board level. Paragraph 1 of Annex-XIVA requires a comprehensive policy guiding the assessment of whether and how activities can appropriately be outsourced. The board of the intermediary holds responsibility for the policy and overall responsibility for activities undertaken under it.

Paragraph 1.1 sets what the policy must cover: the activities or nature of activities that can be outsourced, the authorities who can approve outsourcing of them, and the selection of the third party. It gives one worked example of an activity that must not be outsourced, being anything that would impair the supervisory authority's right to assess, or its ability to supervise the business of the debenture trustee. The policy must be based on an evaluation of risk concentrations, limits on the acceptable overall level of outsourced activities, and risks arising from outsourcing multiple activities to the same entity.

Paragraph 1.2 requires the board to mandate a regular review of the policy as the business environment changes, and to ensure ongoing outsourcing decisions and third party activities stay within it.

What does the risk assessment have to consider?

Materiality, judged on four factors under paragraph 2.1: the impact of a third party's failure to perform on the trustee's financial, reputational and operational performance and on investors and clients; the trustee's ability to cope through suitable back-up arrangements if the third party fails; the regulatory status of the third party including its fitness and probity status; and situations involving conflict of interest between the trustee and the third party, with the measures put in place to address them.

Paragraph 2.3 requires records of all outsourced activities to be preserved centrally so they are readily accessible for review by the board or senior management, regularly updated, and available to form part of the corporate governance review. Paragraph 2.4 requires the board to mandate regular reviews by internal or external auditors of the outsourcing policies and risk management system where felt necessary, and requires the trustee to review the third party's financial and operational capabilities to assess whether it can continue to meet its obligations.

Can the vendor be a group company?

Yes, with conditions that remove the advantage of it being one. Paragraph 2.2 states there shall not be any prohibition on a group entity or associate of the debenture trustee acting as the third party. It then requires systems to keep an arm's length distance between the trustee and the third party in terms of infrastructure, manpower, decision-making and record keeping, for avoidance of potential conflicts of interest, with necessary disclosures made as part of the contractual agreement.

The closing sentence is the one to read twice. The risk management practices expected while outsourcing to a related party or associate are identical to those followed while outsourcing to an unrelated party. There is no lighter regime for keeping work inside the group.

Selection is governed by due diligence under paragraph 4.2, covering the third party's resources and capabilities including financial soundness, compatibility of its practices and systems with the trustee's requirements, market feedback on its reputation and track record, the level of concentration of outsourced arrangements with a single third party, and the environment of the foreign country where the third party is located.

Paragraph 5 requires every outsourcing relationship to be governed by a clearly defined and legally binding written contract with each third party, describing all material aspects including rights, responsibilities and expectations of the parties, client confidentiality issues, and termination procedures.

The other structural separation rule, covering businesses the trustee runs itself, is in what activities can a debenture trustee undertake, and the conduct rules that sit behind both are in debenture trustee conflict of interest rules. The obligations that cannot be delegated are listed in duties of a debenture trustee, the grievance route that survives outsourcing is in how to complain to a debenture trustee, and the diligence work itself is described in how does a debenture trustee do due diligence.

A debenture trustee can outsource support work but not its core business or compliance functions, and it carries the liability either way. Flock reports what issuers and trustees disclose, with the source and the date attached. It is not investment advice.

Frequently asked questions

Can a debenture trustee outsource its work?

Partly. Paragraph 4 of Chapter XIV of SEBI's Master Circular for Debenture Trustees dated August 13, 2025 provides that a debenture trustee shall not outsource its core business activities and compliance functions. Other activities may be outsourced under the principles at Annex-XIVA of the same circular. Source: SEBI.

Who is liable if an outsourced provider fails?

The debenture trustee. Under paragraph 3.1 of Annex-XIVA, the trustee is fully liable and accountable for outsourced activities to the same extent as if the service were provided in-house, and under paragraph 3.2 it is liable to investors for losses caused by the third party's failure and responsible for redressing grievances arising from it. Source: SEBI.

Can a debenture trustee outsource to a group company?

Yes. Paragraph 2.2 of Annex-XIVA states there shall not be any prohibition on a group entity or associate acting as the third party, but requires systems for an arm's length distance in infrastructure, manpower, decision-making and record keeping, disclosure in the contract, and risk management practices identical to those used for an unrelated party. Source: SEBI.

Can outsourcing limit a regulator's access?

No. Under paragraph 3.3 of Annex-XIVA, facilities, premises and data involved in an outsourced activity are deemed to be those of the registered debenture trustee, and the trustee and the regulator or persons authorised by it have the right to access them at any point of time. Paragraph 3.4 bars arrangements that impair SEBI, SRO or auditor supervision. Source: SEBI.

Flock tracks these filings, sourced, dated, and linked back to the original. See what smart-money entities disclosed, without the guesswork about what it means.

Disclosures shown are public regulatory filings. Data may be delayed or incomplete. Smart-money entities may no longer hold positions shown. Not investment advice.

The Smart Money Digest

A free weekly email of notable disclosure activity — every line with its filing date and source link. No advice, just filings. Unsubscribe anytime.