Wednesday, 2 September 2026

Enabling sharing of information by KYC KRA with entities regulated by IFSC

SEBI Circular No. HO/38/15/(7)2026-MIRSD-POD/I/19255/2026 dated August 20, 2026, concerning the sharing of KYC information by SEBI-registered KYC Registration Agencies (KRAs) with entities regulated by the International Financial Services Centres Authority (IFSCA).

1. Background and objective

The Circular has been issued to facilitate interoperability and information sharing between SEBI-registered KRAs and entities regulated by IFSCA. The regulatory mechanism is enabled through Regulation 16A of the SEBI (KYC Registration Agency) Regulations, 2011.

Regulation 16A(1) permits entities regulated by other financial-sector regulators, when specified by SEBI, to access the KRA system for undertaking KYC of their clients. SEBI has now formally specified IFSCA for this purpose.

This represents an important step towards creating greater integration between the KYC infrastructure of India's securities market and the financial ecosystem operating within the International Financial Services Centre (IFSC).

2. What has changed?

The principal regulatory change is that IFSCA-regulated entities are now enabled to access the KRA system maintained by SEBI-registered KRAs for undertaking KYC of their clients.

In practical terms, this means that eligible entities regulated by IFSCA can leverage the existing KRA infrastructure rather than having to operate an entirely independent KYC information-gathering mechanism.

The Circular therefore establishes a regulatory bridge between:

SEBI/KRAs → IFSCA-regulated entities → KYC information

This is particularly relevant to the expanding financial-services ecosystem in the IFSC.

3. Applicability of SEBI KRA Regulations

The Circular makes it clear that once an IFSCA-regulated entity accesses the KRA system, the provisions of the SEBI KRA Regulations, 2011 become applicable to such entity.

This is an important compliance consideration.

Access to the KRA database is therefore not merely a facility or technological integration. The accessing entity must comply with the applicable regulatory framework governing the KRA system.

Accordingly, IFSCA-regulated entities intending to use the KRA infrastructure should ensure that their internal KYC processes, systems, controls and personnel are aligned with the applicable requirements.

4. Compliance with SEBI's KYC framework

The Circular specifically requires all entities accessing the KRA system to follow the guidelines contained in SEBI's Master Circular dated October 12, 2023 on KYC norms for the securities market, as amended from time to time.

Therefore, IFSCA-regulated entities cannot treat KRA access as an isolated technical arrangement. Their use of KRA information must be integrated with the applicable KYC compliance framework.

From a compliance perspective, entities should therefore review:

  • KYC onboarding procedures;
  • KYC verification and validation processes;
  • access controls;
  • record-keeping arrangements;
  • data handling and confidentiality;
  • internal controls governing KRA access; and
  • compliance monitoring and audit mechanisms.

5. Special requirement for Foreign Portfolio Investors

The Circular contains an additional requirement where the client is registered as a Foreign Portfolio Investor (FPI).

In such cases, entities accessing the KRA system must also comply with the Data Security guidelines contained in SEBI's Master Circular dated May 30, 2024 relating to Foreign Portfolio Investors, Designated Depository Participants and Eligible Foreign Investors, as amended from time to time.

This is particularly significant because FPI-related KYC information can involve sensitive financial and identification data.

IFSCA-regulated entities dealing with FPIs should therefore pay particular attention to:

  • information-security controls;
  • authorised access;
  • data protection;
  • secure transmission and storage;
  • prevention of unauthorised disclosure; and
  • monitoring of access to KRA information.

6. Immediate effectiveness

The Circular is effective immediately from August 20, 2026.

Consequently, IFSCA-regulated entities that intend to utilise the KRA system should assess their readiness without waiting for a separate implementation date.

7. Regulatory significance

The Circular is significant beyond its immediate KYC implications.

The IFSC ecosystem is intended to provide a globally oriented financial-services platform, and efficient KYC interoperability is an important component of such an ecosystem. Enabling IFSCA-regulated entities to access the established KRA infrastructure should potentially:

  • reduce duplication in KYC processes;
  • improve operational efficiency;
  • facilitate smoother client onboarding;
  • improve consistency of KYC information;
  • reduce compliance friction for financial-sector participants; and
  • strengthen regulatory coordination between SEBI and IFSCA.

It also reflects a broader movement towards inter-regulatory cooperation and standardisation of financial-sector KYC infrastructure.

8. Impact on IFSCA-regulated entities

From the perspective of an IFSCA-regulated entity, the Circular should be viewed as both an opportunity and a compliance responsibility.

The opportunity lies in being able to access an established KYC repository and potentially streamline client onboarding.

The corresponding responsibility is that such access brings with it the requirement to comply with the relevant SEBI KRA framework and, where applicable, the enhanced data-security requirements for FPIs.

Entities should therefore consider conducting an internal gap assessment covering:

AreaSuggested compliance action
KRA accessEstablish appropriate authorised access
KYC processesAlign procedures with SEBI KRA requirements
Internal controlsDefine responsibility and approval mechanisms
Data securityReview controls over KRA information
FPI clientsImplement applicable additional data-security requirements
Record keepingEnsure appropriate maintenance of KYC records
Employee accessRestrict access to authorised personnel
Compliance monitoringInclude KRA usage within periodic compliance reviews

9. Impact on KRAs

For SEBI-registered KRAs, the Circular effectively expands the universe of entities that may access their systems.

KRAs will therefore need to facilitate access by eligible IFSCA-regulated entities in accordance with the regulatory framework, while ensuring appropriate controls around authentication, access, information sharing and data security.

The Circular does not, however, appear from the uploaded document to prescribe a separate operational implementation mechanism or specific technical timeline for KRAs. Such operational requirements may therefore need to be read along with the applicable KRA regulations, master circulars and subsequent directions.

10. Key takeaway for compliance professionals

The most important takeaway is that IFSCA has now been specifically recognised by SEBI under Regulation 16A(1) as a regulator whose regulated entities may access the SEBI KRA system.

However, such access comes with corresponding obligations. The accessing entities must comply with the SEBI KRA Regulations and the applicable SEBI KYC framework, with additional data-security requirements applying in relation to FPI clients.

Conclusion

The August 20, 2026 Circular is a relatively concise regulatory intervention, but its practical significance is considerable. By permitting IFSCA-regulated entities to access SEBI's KRA infrastructure, SEBI has taken a concrete step towards greater harmonisation of KYC processes across India's financial regulatory architecture.

For IFSCA-regulated entities, the immediate priority should be to determine whether they intend to utilise the KRA facility and, if so, ensure that their KYC policies, systems, access controls and data-security framework are capable of meeting the requirements incorporated through the Circular.

In essence, the Circular facilitates interoperability, but interoperability comes with regulatory accountability.

No comments:

Post a Comment

Digitisation of FPI Onboarding

  The recent SEBI Circular dated 20 August 2026 permitting the submission of a digitally signed Power of Attorney (PoA) as part of the reg...