Just a moment...

Top
Help
×

By creating an account you can:

Logo TaxTMI
>
Call Us / Help / Feedback

Contact Us At :

E-mail: [email protected]

Call / WhatsApp at: +91 99117 96707

For more information, Check Contact Us

FAQs :

To know Frequently Asked Questions, Check FAQs

Most Asked Video Tutorials :

For more tutorials, Check Video Tutorials

Submit Feedback/Suggestion :

Email :
Please provide your email address so we can follow up on your feedback.
Category :
Description :
Min 15 characters0/2000
TMI Blog
Home / RSS

Master Circular on Know Your Client (KYC) norms for the securities market

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... captioned subject and includes certain modifications to align such circulars/directions with the provisions of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005 and the Securities and Exchange Board of India [KYC (Know Your Client) Registration Agency] Regulations, 2011. The provisions of this Master Circular shall come into force from the date of its issue. 3. Any modifications/updation in existing KYC records, shall be effected in line with the provisions of this Circular by December 31, 2023. 4. On and from the date of issue of this Circular, all circulars for the purpose of KYC as listed in Appendix shall stand rescinded/modified as indicated therein. 5. Notwithstanding such rescission, a) Anything done or any action taken or purported to have been done or taken under the rescinded circulars, prior to such rescission, shall be deemed to have been done or taken under the corresponding provisions of this Master Circular; b) Any application made to the Board under the rescinded circulars, prior to such rescission, and pending before it shall be deemed to have been made under the corresponding provisions of this Master Circular; ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....undering (Maintenance of Records) Rules, 2005. f. "Client" shall have the same meaning as assigned to it under Section 2(ha) of the Prevention of Money Laundering Act, 2002. g. "Client Due Diligence" shall have the same meaning as assigned to it under Rule 2 (1) (b) of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005. h. "Designated Director" shall have the same meaning as assigned to it under Rule 2 (1) (ba) of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005. i. "Digital KYC" shall have the same meaning as assigned to it under Rule 2 (1) (bba) of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005. j. "Digital Signature" shall have the same meaning as assigned to it under clause (p) of subsection (1) of section (2) of the Information Technology Act, 2000 (21 of 2000). k. "e-KYC authentication facility" shall have the same meaning as assigned to it under clause (j) of sub section (1) of section (2) of Aadhaar (Authentication and Offline Verification) Regulations, 2021. l. "Electronic Signature" shall have the same meaning assigned to it under clause (ta)....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ortfolio Investors and Eligible Foreign Investors shall be guided as per provisions of SEBI Circular SEBI/HO/AFD-2/CIR/P/2022/175 December 19, 2022 and amendments thereto. 5. The account opening form (AOF) for client shall be divided into two parts. Part I of the AOF shall be the KYC form which shall capture the basic details about the client. For this purpose, all registered intermediaries shall use the KYC templates provided by Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) for individuals and for legal entities for capturing the KYC information. The CKYCR templates - Individual and Legal Entity provided by CERSAI is available at https://www.ckycindia.in/ckyc/?r=download. 6. Part II of the form shall obtain the additional information specific to the area of activity of the intermediary, as considered appropriate by them. The instant Master Circular deals with the provisions of Part I -KYC form. Requirement of Permanent Account Number (PAN) 7. In order to strengthen the KYC norms and identify every participant in the securities market with their respective PAN thereby ensuring sound audit trail of all the transactions, P....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....defined as per Rule 2 (d) of Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (PML Rules): i. the passport; ii. the driving licence; iii. proof of possession of Aadhaar number; iv. the Voter's Identity Card issued by Election Commission of India; v. job card issued by NREGA duly signed by an officer of the State Government; vi. the letter issued by the National Population Register containing details of name address; or vii. any other document as notified by the Central Government in consultation with the Regulator. b. Further, in terms of proviso to the above Rule, where simplified measures are applied for verifying the identity of the clients, the following documents shall also be deemed to be officially valid document: i. Identity card/ document with applicant's photo, issued by the Central/State Government Departments, Statutory/Regulatory Authorities, Public Sector Undertakings, Scheduled Commercial Banks and Public Financial Institutions; ii. Letter issued by a gazetted officer, with a duly attested photograph of the person. 15. The registered intermediaries shal....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... listed companies and leave and licence agreements with such employers allotting official accommodation. 18. In terms of the PML Rules, cases where the client submits his proof of possession of Aadhaar number as an officially valid document, he may submit it in such form as is issued by the UIDAI. 19. A document shall be deemed to an officially valid document even if there is a change in the name subsequent to its issuance provided it is supported by a Marriage Certificate issued by the State Government or a gazette notification, indicating such change of name. 20. For non-residents and foreign nationals, (allowed to trade subject to RBI and FEMA guidelines), copy of passport/Persons of Indian Origin (PIO) Card/Overseas Citizenship of India (OCI) Card and overseas address proof is mandatory. 21. In case the officially valid document presented by a foreign national does not contain the details of address, the documents issued by the Government departments of foreign jurisdictions and letter issued by the Foreign Embassy or Mission in India shall be accepted as proof of address. 22. If any proof of address is in a foreign language, then translation into English shall b....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....under the CDD process. 30. The stock exchanges and depositories shall monitor the compliance of the aforementioned provision on identification of beneficial ownership through half yearly internal audits. In case of mutual funds, compliance of the same shall be monitored by the Boards of the Asset Management Companies and the Trustees and in case of other registered intermediaries, by their Board of Directors. Requirement of additional documents for non-individuals (Legal Entities)^5 31. In case of non-individuals, additional documents (certified copies of equivalent e-documents) to be obtained are mentioned below: i. Corporate body: a. Certificate of incorporation. b. Memorandum and Articles of Association. c. Board Resolution for investment in securities market. d. Power of Attorney granted to its managers, officers or employees, as the case may be, to transact on its behalf. e. Authorised signatories list with specimen signatures. f. Copy of the balance sheet for the last financial year (initially for the last two financial years and subsequently for every last financial year). g. Latest share holdin....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... c. Committee resolution for persons authorised to act as authorised signatories with specimen signatures. d. True copy of Society Rules and Bye Laws certified by the Chairman/Secretary. Requirement of Mobile Number and Email ID 32. The registered intermediaries shall upload the details of mobile number and email address on the KRA system. It shall be ensured that the mobile number/email addresses of their employees/authorized persons, distributors etc. are not uploaded on behalf of clients. Digital KYC 33. In order to enable the online KYC process for establishing account based relationship with the registered intermediary, client's KYC shall be completed through digital (online / Application (App) based) KYC, in- person verification through video, online submission of officially valid document / other documents, using electronic/digital signature, including Aadhaar e-Sign. 34. The client shall visit the website/App/digital platform of the registered intermediary and fill up the online KYC form and submit requisite documents. 35. SEBI registered intermediaries shall obtain the express consent of the client before undertaking online KYC. 36. The PA....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ils of the client shall be captured online and signed cancelled cheque shall be provided as a photo/scan of the original under electronic/digital signature including Aadhaar e-Sign. Bank account details shall be verified by Penny Drop mechanism or any other mechanism using API of the Bank. The name and bank details as obtained shall be verified with the information provided by client. 48. Once all the required information as per the online KYC form is filled up by the investor, KYC process shall be completed as under: a. The client shall take a print out of the completed KYC form and after affixing their wet signature, send the scanned copy / photograph of the same to the registered intermediary under electronic/digital signature including Aadhaar e-Sign or b. Affix online the cropped signature on the filled KYC form and submit the same to the registered intermediary under electronic/digital signature including Aadhaar e-Sign. c. The "original seen and verified" requirement for officially valid document would be met where the investor provides the officially valid document in the following manner: i. As a clear photograph or scanned copy of th....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....rmediary. 57. In case of Stock brokers, their Authorised Persons (appointed by the stock brokers after getting approval from the concerned Stock Exchanges) can perform the IPV. 58. In case of Mutual Funds, their Asset Management Companies (AMCs) and the distributors who comply with the certification process of National Institute of Securities Market (NISM) or Association of Mutual Funds (AMFI) and have undergone the process of 'Know Your Distributor (KYD)', can perform the IPV. Additionally, entities registered as Category 1 Execution Only Platform (EOP) can perform the IPV. 59. In case of applications received by the mutual funds directly from the clients (i.e. not through any distributor), they may also rely upon the IPV performed by the scheduled commercial banks. 60. To enable ease of completing IPV of an investor, intermediary may undertake the Video in Person Verification (VIPV) of an individual investor through their App. The following process shall be adopted in this regard: a) Intermediary through their authorised official, specifically trained for this purpose, may undertake live VIPV of an individual client, after obtaining his/her informed consent. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....on of their clients for the purpose of KYC. 66. The following entities shall get registered with UIDAI as KYC user agency ("KUA") and shall allow SEBI registered intermediaries to undertake Aadhaar Authentication in respect of their clients for the purpose of KYC. (i) Bombay Stock Exchange Limited (ii) National Securities Depository Limited (iii) Central Depository Services (India) Limited (iv) CDSL Ventures Limited (v) NSDL Database Management Limited (vi) NSE Data and Analytics Limited (vii) CAMS Investor Services Private Limited (viii) Computer Age Management Services Private Limited (ix) National Stock Exchange of India Limited (NSE). 67. SEBI registered intermediaries who want to undertake Aadhaar authentication services through KUAs, shall enter into an agreement with any one KUA and get themselves registered with UIDAI as Sub-KUAs. The agreement in this regard shall be as prescribed by UIDAI. Entities permitted to undertake e-KYC Aadhaar Authentication service of UIDAI in Securities Market as sub-KUA 68. Department of Revenue (DoR), Ministry of Finance (MoF), Government of India, vid....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....d to the client on portal. v. Sharing of e-KYC data by the KUA with Sub-KUA shall be allowed under Regulation 16(2) of Aadhaar (Authentication) Regulations, 2016. Sub-KUA shall clearly specify the name of the KUA and Sub-KUA, and details of sharing of data among KUA and Sub-KUA while capturing client consent. vi. Client shall fill the additional detail as required under KYC format. B. Assisted Investor (Resident) e-KYC process (Aadhaar as an officially valid document): i. Client approaches any of the SEBI Registered Entity/Sub-KUAs for e-KYC through Aadhaar. ii. SEBI registered entities (Sub-KUAs) shall perform e-KYC using registered / whitelisted devices with KUAs. iii. KUA shall ensure that all devices and device operators of Sub-KUA are registered / whitelisted devices with KUA. iv. Client shall enter Aadhaar No. or Virtual Id and provide consent on the registered device. v. Client provides biometric on the registered device. vi. SEBI registered intermediary (Sub-KUA) fetches the e-KYC details through the KUA from UIDAI which shall be displayed to the client on the registered device. vii. Client ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... 77. For non-compliances if any observed on the part of the reporting entities (KUAs/Sub KUAs), SEBI shall take necessary action under the applicable laws and also bring the same to the notice of DoR/FIU/UIDAI for further necessary action, if any. 78. The registered intermediary (KUAs/Sub-KUAs) shall also adhere to the continuing compliances and standards of privacy and security prescribed by UIDAI to carry out Aadhaar Authentication Services under section 11A of PMLA. 79. Based on a report from SEBI/UIDAI or otherwise, if it is found that the reporting entity no longer fulfils the requirements for performing authentication under clause (a) of section 11A(1) of PMLA, the Central Government may withdraw the notification after giving an opportunity to the reporting entity. KYC for SARAL Account Opening Form for resident individuals 80. For individual clients participating in the cash segment without obtaining various other facilities such as internet trading, margin trading, derivative trading and use of power of attorney, the requirement of submission of 'proof of address' shall be as follows: a. Individual client may submit only one documentary proof of address....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....m of the KRA within 3 working days from the date of completion of KYC process. 85. In case a client's KYC documents sent by the intermediary to KRA are not complete, the KRA shall inform the same to the intermediary who shall forward the required information/documents promptly to KRA. 86. For existing clients, the KYC data shall be uploaded by the intermediary provided they are in conformity with details sought in the uniform KYC format. While uploading these clients' data the intermediary shall ensure that there is no duplication of data in the KRA system. 87. The intermediaries shall maintain electronic records of KYCs of clients and keeping physical records would not be necessary. 88. The intermediary shall promptly provide KYC related information to KRA, as and when required. 89. The intermediary shall have adequate internal controls to ensure the security/authenticity of data uploaded by it. Guidelines for KRAs: 90. KRA system shall provide KYC information in data and image form to the intermediary. 91. KRA shall send a letter to the client within 2 working days of the receipt of the initial/updated KYC documents from intermediary, confirming the detail....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....hall follow uniform internal guidelines/standards detailing aspects of identification of attributes and procedures for verification/ validation, in consultation with SEBI. 103. The systems of intermediaries and the KRAs shall be integrated to facilitate seamless movement of documents/information to and from the intermediary to the KRAs for verification/validation of attributes under risk management framework. 104. The records of all existing clients whose KYC has been completed based on OVDs other than Aadhaar, shall be verified by December 31, 2023. Processing of Investor complaints against KRA {KYC (Know Your Client) Registration Agency} in SEBI Complaints Redress System (SCORES) 105. All complaints pertaining to KRAs will be electronically sent through SCORES at http://scores.gov.in/Admin. KRAs are directed to view the pending complaints and submit the ATR along with supporting documents electronically in SCORES. Updation of action taken would not be possible with physical ATRs. Hence, submission of physical ATR will not be accepted for complaints lodged in SCORES. 106. KRAs shall take adequate steps for redressal of grievances within one month from the date of re....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ng, safeguarding and retrieving the KYC records in digital form of a "client", as defined in clause (ha) sub-section (1) of Section 2 of the PMLA, 2002. 114. As required under the PML Rules, registered intermediaries shall capture the KYC information for sharing with the Central KYC Records Registry in the manner mentioned in the PML Rules, as per the KYC template finalised by CERSAI. 115. Registered intermediaries shall within ten days after the commencement of an account-based relationship with a client, file the electronic copy of the client's KYC records with the CKYCR. 116. Registered intermediaries shall ensure that all existing KYC records of legal entities and of individual clients are uploaded on to CKYCR when the updated information is obtained/received from the client. 117. The Central KYC Records Registry User Manual for uploading KYC records on CKYCR finalised by CERSAI is available at https://www.ckycindia.in/ckyc/assets/doc/User_Manual_1.12.1.pdf. 118. Registered intermediaries shall ensure compliance with requirements contained in the PML Rules in this regard. 119. For addressing any difficulty in uploading KYC records to CKYCR, CERSAI has operatio....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... Protection Centre (NCIIPC) of National Technical Research Organisation (NTRO), Government of India, in the report titled 'Guidelines for Protection of National Critical Information Infrastructure' and subsequent revisions, if any, from time to time. 5. KRAs shall also incorporate best practices from standards such as ISO 27001, ISO 27002, COBIT 5, etc., or their subsequent revisions, if any, from time to time. 6. KRAs shall designate a senior official as Chief Information Security Officer (CISO) whose function would be to assess, identify and reduce cyber security risks, respond to incidents, establish appropriate standards and controls, and direct the establishment and implementation of processes and procedures as per the cyber security and resilience policy approved by the Board of the KRAs. 7. The Board of the KRAs shall constitute a Technology Committee comprising experts proficient in technology. This Technology Committee shall on a quarterly basis review the implementation of the Cyber Security and Cyber Resilience policy approved by their Board, and such review shall include review of their current IT and Cyber Security and Cyber Resilience capabilities, set goals ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....eriod. KRAs shall grant access to IT systems, applications, databases and networks on a need-to-use basis and based on the principle of least privilege. Such access shall be for the period when the access is required and shall be authorized using strong authentication mechanisms. 16. KRAs shall implement strong password controls for users' access to systems, applications, networks and databases. Password controls shall include a change of password upon first log-on, minimum password length and history, password complexity as well as maximum validity period. The user credential data shall be stored using strong and latest hashing algorithms. 17. KRAs shall ensure that records of user access are uniquely identified and logged for audit and review purposes. Such logs shall be maintained and stored in encrypted form for a time period not less than two (2) years. 18. KRAs shall deploy additional controls and security measures to supervise staff with elevated system access entitlements (such as admin or privileged users). Such controls and measures shall inter-alia include restricting the number of privileged users, periodic review of privileged users' activities, disallow privi....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....es and automatic anti-virus scanning shall be done on a regular basis. Security of Data 30. Data-in-motion and Data-at-rest shall be in encrypted form by using strong encryption methods such as Advanced Encryption Standard (AES), RSA, SHA- 2, etc. 31. KRAs shall implement measures to prevent unauthorised access or copying or transmission of data/information held in contractual or fiduciary capacity. It shall be ensured that confidentiality of information is not compromised during the process of exchanging and transferring information with external parties. 32. The information security policy shall also cover use of devices such as mobile phone, faxes, photocopiers, scanners, etc. that can be used for capturing and transmission of data. 33. KRAs shall allow only authorized data storage devices through appropriate validation processes. Hardening of Hardware and Software 34. Only a hardened and vetted hardware/software shall be deployed by the KRAs. During the hardening process, KRAs shall inter-alia ensure that default passwords are replaced with strong passwords and all unnecessary services are removed or disabled in equipment/software. 35. All open ports whi....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ll be remedied on immediate basis and compliance of closure of findings identified during VAPT shall be submitted to SEBI within 3 months post the submission of final VAPT report. 42. In addition, KRAs shall perform vulnerability scanning and conduct penetration testing prior to the commissioning of a new system which is a critical system or part of an existing critical system. Monitoring and Detection 43. KRAs shall establish appropriate security monitoring systems and processes to facilitate continuous monitoring of security events and timely detection of unauthorised or malicious activities, unauthorised changes, unauthorised access and unauthorized copying or transmission of data/information held in contractual or fiduciary capacity, by internal and external parties. The security logs of systems, applications and network devices shall also be monitored for anomalies. 44. Further, to ensure high resilience, high availability and timely detection of attacks on systems and networks, KRAs shall implement suitable mechanism to monitor capacity utilization of its critical systems and networks. 45. Suitable alerts shall be generated in the event of detection of unauthor....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....formation shall be shared through the dedicated e-mail id: [email protected]. The format for submitting the quarterly reports is attached as Annexure C. 52. Such details as are felt useful for sharing with other KRAs in masked and anonymous manner shall be shared using mechanism to be specified by SEBI from time to time. Training 53. KRAs shall conduct periodic training programs to enhance awareness level among the employees and outsourced staff, vendors, etc. on IT/Cyber security policy and standards. Special focus shall be given to build awareness levels and skills of staff from non-technical disciplines. 54. The training program shall be reviewed and updated to ensure that the contents of the program remain current and relevant. Periodic Audit 55. KRAs shall arrange to have its systems audited on an annual basis by an CERT-IN empanelled auditor, an independent DISA (ICAI) Qualification, CISA (Certified Information System Auditor) from ISACA, CISM (Certified Information Securities Manager) from ISACA, CISSP (Certified Information Systems Security Professional) from International Information Systems Security Certification Consortium (commonly known as (ISC)2), to c....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....rformance Unaccounted for changes in the DNS tables, router rules, or firewall rules Unexplained elevation or use of privileges Operation of a program or sniffer device to capture network traffic; An indicated last time of usage of a user account that does not correspond to the actual last time of usage for that user A system alarm or similar indication from an intrusion detection tool Altered home pages, which are usually the intentional target for visibility, or other pages on the Web serve  Anomalies Suspicious probes Suspicious browsing New files Changes in file lengths or dates Attempts to write to system Data modification or deletion Denial of service Door knob rattling Unusual time of usage Unusual usage patterns Unusual log file entries Presence of new setuid or setgid files Changes in system directories and files Activity during non-working hours or holidays Other (Please specify)   7. Details of unusual behaviour/symptoms -       8. Has this problem been experienced earlier? If yes, details -     9. Agencies notified - Law Enforcement....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....CR) 16. CIR/MIRSD/120/2016 dated 10-Nov-16 Uploading of The Existing Clients' KYC Details With Central KYC Records Registry (CKYCR) System by The Registered Intermediaries 17. SEBI/HO/MIRSD/DOP/CIR/P/2019/111 dated 15-Oct-19 Cyber Security &Cyber Resilience framework for KYC Registration Agencies 18. SEBI/HO/MIRSD/DOP/CIR/P/2019/123 dated 05-Nov-19 E-KYC Authentication Facility Under Section 11A of The Prevention of Money Laundering Act, 2002 by Entities In The Securities Market For Residents Investor 19. SEBI/HO/MIRSD/DOP/CIR/P/2020/73 dated 24-Apr-20 Clarification On Know Your Client (KYC) Process And Use of Technology For KYC 20. SEBI/HO/MIRSD/DOP/CIR/P/2020/80 dated 12-May-20 Entities Permitted To Undertake E-KYC Aadhaar Authentication Service of UIDAI In Securities Market 21. SEBI/HO/MIRSD/DOP/CIR/P/2020/167 dated 08-Sep-20 Entities Permitted To Undertake E-KYC Aadhaar Authentication Service of UIDAI In Securities Market -Addition of NSE To The List 22. SEBI/HO/MIRSD/DOP/CIR/P/2021/31 dated 10-Mar-21 Rollout of Legal Entity Template 23. SEBI/HO/MIRSD/DoP/P/CIR/2022/74 dated 30-May-22 Modification in Cy....