Advanced Search Options : ❯
Regulation 29 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Third-party inspection authorises the Authority to appoint a professional to inspect a KYC Registration Agency's books of account, records, documents, infrastructure, systems, procedures or affairs. The professional has the powers of an Inspecting Authority, while the KRA and its employees have equivalent inspection-related obligations. The Authority may recover all inspection expenses, including the professional's fees, from the KRA.
Regulation 28 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Regulation 28 requires a KYC Registration Agency and its Principal Officer, directors, chairperson, CEO, key managerial personnel, officers, employees and agents to cooperate with inspections. They must provide assistance, books of account, records, documents, statements and activity-related information within the required time. The KRA must allow reasonable premises access, facilitate examination of relevant material, provide copies, and enable examination or recording of statements.
Regulation 27 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
KYC Registration Agencies may be inspected to verify record maintenance, regulatory compliance, internal controls, safeguards, and continuing fitness or eligibility. Inspection may also examine complaints concerning KRA activities and matters considered necessary for investor or IFSC financial market interests. Prior notice is ordinarily required, but may be dispensed with for recorded reasons where investor interests warrant immediate inspection.
Regulation 26 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
A KRA may allow Authority-specified entities regulated by other financial sector regulators to access its systems for undertaking client KYC. It may also connect with a central KYC registry authorised by the Central Government for collating and sharing KYC information within the financial sector.
Regulation 25 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Regulated Entities must conduct initial client KYC and due diligence, authenticate and upload KYC information and scanned records, and retain physical KYC documents. Changes in KYC particulars or status require updated uploads and retention of supporting documents. KYC data may be used only for its intended purpose and cannot be shared for commercial gain. Each Regulated Entity retains ultimate responsibility for client KYC, must apply risk-proportionate enhanced measures, and integrate systems for seamless KYC document exchange.
Regulation 24 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
KYC Registration Agencies must maintain interoperable and secure systems for KYC records, including electronic connectivity, secure data transmission, independent validation, record storage and retrieval, and dissemination of client updates to relevant intermediaries. They must protect records against loss, tampering and unauthorised access, maintain separate backups, conduct periodic control and system audits, rectify deficiencies, and comply with data protection requirements. Access by regulated entities must be limited to their own clients' records and require client consent, while all KYC record uploads, modifications and downloads must be auditable.
Regulation 23 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
KYC Registration Agencies must receive a Client's KYC documents from the Regulated Entity in accordance with the Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer Guidelines, related circulars and directions, and other relevant prevention-of-money-laundering legislation. The duty links KRA document receipt to the applicable KYC and anti-money-laundering regulatory framework.
Regulation 22 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
KYC Registration Agencies must undergo an annual compliance audit conducted by specified qualified professionals or a person authorised to audit in a foreign jurisdiction. The audit report for each financial year must be furnished to the Authority by 30 September of the following year. Additional audits and reports must be undertaken where specified by the Authority.
Regulation 21 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
KYC Registration Agencies operating within International Financial Services Centres must pay fees specified by the Authority. Every KRA is subject to this payment obligation, and the Authority determines the applicable fees through its specifications. Payment is required in accordance with those fee requirements, which identify the fees payable by KYC Registration Agencies within the regulatory framework.
Regulation 20 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Regulation 20 requires a KYC Registration Agency established as a company in an IFSC to obtain the Authority's prior approval for any direct or indirect change in control. A KRA operating through an IFSC branch must intimate the Authority of any direct or indirect change in control within fifteen days.
Regulation 19 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Every KYC Registration Agency must maintain a sound system for comprehensively managing risks arising from its operations. Adequate internal procedures and controls must be appropriate to the types of business it undertakes, including outsourced activities, to protect clients and their assets and ensure proper and effective management of risks throughout those business activities.
Inter-Commissioner Agreement Supports Valid Inter-City Income-Tax Case Transfer for Coordinated Assessment Despite Objections and Hearing Claims
Inter-city transfer of income-tax jurisdiction requires concurrence of the competent jurisdictional authorities where the transfer crosses Commissioner jurisdictions. Centralisation following search proceedings may be justified by a recorded nexus with the searched group and the need for coordinated investigation and assessment. The receiving Principal Commissioner's independent consent after applying mind satisfies the concurrence requirement. Transfer is an administrative power reviewable only for arbitrariness or mala fides. Notice must disclose the grounds for centralisation and address objections, but relied-upon investigation material need not be supplied at the transfer stage; disclosure may be sought during assessment. These requirements supported the transfer's validity.
Regulation 18 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Cyber security and cyber resilience obligations require every KYC Registration Agency (KRA) to maintain a robust framework aligned with requirements specified by the Authority from time to time. Compliance remains dependent on applicable Authority requirements, which may be updated periodically, and covers cyber security safeguards and operational resilience within the KRA framework.
Regulation 17 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Each KYC Registration Agency must maintain a business continuity plan containing procedures for emergencies or significant business disruptions. It must update the plan following material changes to operations, structure, business, or location, and conduct an annual review. The requirements establish continuing preparedness, change-management, and periodic review for operational continuity.
Regulation 16 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Disputes arising out of or relating to activities of a KYC Registration Agency in an International Financial Services Centre must be resolved in accordance with the dispute-resolution mechanism specified by the Authority. The Authority-specified mechanism governs the resolution of disputes connected with the KYC Registration Agency's activities within that International Financial Services Centre.
Regulation 15 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
KYC Registration Agencies must take adequate measures for consumer grievance redressal according to requirements specified by the Authority. They must also maintain records of investor grievances received and the redress provided. The obligations combine complaint-handling measures with documented tracking of grievance receipt and resulting redress as an ongoing recordkeeping duty in connection with consumer complaints.
Regulation 14 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
A KYC Registration Agency must immediately furnish any material change in previously supplied application information or particulars where the change bears on its registration certificate. Changes in the Principal Officer, Compliance Officer, or key managerial personnel must be intimated within 15 days. It must also provide reports, returns, statements, and other particulars in the prescribed form, manner, and intervals.
Regulation 13 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
KYC Registration Agencies must preserve financial statements, audit reports, quarterly net-worth statements, compliance records, client account-opening documents, authority forms and activity records in electronic retrieval form for at least eight years. Client KYC documents must be retained electronically for the period prescribed under the Prevention of Money Laundering Act and its rules, with retrieval of KYC information facilitated within the stipulated time period.
Regulation 12 of the International Financial Services Centres Authority (Kyc Registration Agency) Re...
Regulation 12 requires every KRA to comply with the Code of Conduct set out in Schedule I. Adherence to those scheduled standards is mandatory for KRA regulatory compliance and conduct within the applicable registration framework.
Notification No. S.O. 3608(E) Dated:- 5-8-2025 Information Technology
Airport operational critical information infrastructure, including airfield lighting, operational control, access control, baggage handling, passenger-processing, surveillance and clock systems, is declared a protected system under the Information Technology Act, 2000. Access is confined to persons authorised in writing by Delhi International Airport Ltd, including designated employees, need-based service-provider or vendor personnel, and case-specific consultants, regulators, officials, auditors and stakeholders. The designation takes effect upon publication in the Official Gazette.