Research Analysts ("RAs") occupy a unique and sensitive position in India's securities market, they issue buy/sell/hold recommendations, publish research reports, and influence the investment decisions of retail and institutional investors alike. Recognising the trust reposed in this function, the Securities and Exchange Board of India (SEBI) regulates RAs under the SEBI (Research Analysts) Regulations, 2014, and through a continuously evolving set of circulars issued directly by SEBI or through the Research Analyst Administration and Supervisory Body (RAASB), presently administered by BSE Limited.
Over the last two years, SEBI has significantly tightened the compliance architecture applicable to Ras, partly in response to investor grievances around unregistered/unauthorised advice, and partly as part of a broader push towards digital governance, accessibility, and accountability in the securities market ecosystem. Two audits, in particular, now sit at the centre of an RA's annual compliance calendar: the Digital Accessibility Audit (a relatively recent addition, tied to disability-rights legislation) and the Annual Compliance Audit (a long-standing, comprehensive review of regulatory adherence). This article discusses both in some detail, including the latest extended timelines and the substantive content that these audits typically cover.
Who Is a "Research Analyst" under SEBI Regulations?
Before turning to the audits, it is useful to recall who qualifies as an RA. Under the SEBI (Research Analysts) Regulations, 2014, a "research analyst" is a person who is primarily responsible for preparation and/or publication of research reports, or who makes buy/sell/hold recommendations, or gives price targets, or offers an opinion concerning public offers, in respect of securities listed or proposed to be listed on a stock exchange. This can include individuals, partnership firms, LLPs, and companies, and covers both full-fledged and part-time research analysts (subject to specified client-count caps for the latter). Every RA is required to obtain a certificate of registration from SEBI, appoint a compliance officer, maintain a functional website, and comply with a wide-ranging set of conduct, disclosure, and reporting obligations, the two audits discussed below being central to demonstrating this compliance.
Audit One: The Digital Accessibility Audit
Background and Legal Basis:
The Digital Accessibility Audit finds its origin not in securities law directly, but in the Rights of Persons with Disabilities Act, 2016 ("RPwD Act") and the rules made thereunder, which require that digital platforms including websites and mobile applications that used by entities providing services to the public be accessible to persons with disabilities. SEBI, recognising that Research Analysts, Investment Advisers, and other regulated entities routinely operate client-facing websites and applications, extended this accessibility mandate to its regulated universe through SEBI Circular No. SEBI/HO/ITD-1/ITD_VIAP/P/CIR/2025/131 dated September 25, 2025. This circular made it mandatory for all Regulated Entities, including Research Analysts, to conduct an accessibility audit of their digital platforms and remediate the findings of such audit, so that persons with visual, hearing, cognitive, or motor disabilities can access and navigate these platforms without undue barriers.
Following this, exchanges such as BSE (functioning as RAASB for research analysts) issued implementing notices for instance, BSE Notice No. 20260708-12 dated July 8, 2026 reiterating the applicability of this mandate and its timelines to Research Analysts registered with SEBI.
Extension: July 31, 2026
Compliance with an accessibility audit is not a trivial, one-click exercise, it typically involves engaging a specialised accessibility auditor to test the RA's website (and any mobile application) against recognised standards such as WCAG (Web Content Accessibility Guidelines), followed by a remediation phase in which identified gaps (missing alt-text, poor colour contrast, absence of screen-reader compatibility, inaccessible forms, etc.) are fixed. Given the scale of this exercise across the securities market ecosystem, SEBI recognised that many regulated entities particularly smaller RAs and solo practitioners needed additional time.
Accordingly, SEBI Circular No. HO/(411)2026-ITD-5_DIV2/I/17922/2026 dated July 31, 2026 granted an extension for the "Conduct of Accessibility Audit for the digital platforms and Remediation of findings from the audit," pushing the compliance deadline to October 31, 2026. This extension was communicated to Research Analysts by BSE (in its capacity as RAASB) through BSE Notice No. 20260731-17 dated July 31, 2026, which annexed the SEBI circular and directed all Research Analysts to take note and ensure compliance within the revised timeline.
In practical terms, this means Research Analysts now have until October 31, 2026, to:
-
Get their digital platform(s) principally their website, and any mobile application audited for accessibility by a competent auditor; and
-
Remediate the findings/gaps identified in that audit within the same extended window.
RAs should treat this extension as a final buffer rather than an invitation to delay given the audit-and-remediation cycle typically spans several weeks (initial audit, findings report, remediation by the development team, and a closure/re-verification round), engaging an accessibility auditor well in advance of the October 31 deadline is advisable, rather than waiting until the final weeks.
Audit Two: The Annual Compliance Audit
Statutory Basis and Timelines
Distinct from the accessibility audit, the Annual Compliance Audit is a long-standing, substantive review of an RA's adherence to the full body of SEBI (Research Analysts) Regulations, 2014, and the various circulars issued thereunder. Every Research Analyst is required to have this audit conducted annually by a member of the Institute of Chartered Accountants of India (ICAI), the Institute of Company Secretaries of India (ICSI), or the Institute of Cost Accountants of India (ICMAI) i.e., a practising CA, CS, or CMA.
The key timelines, as mandated by SEBI and reiterated through RAASB/BSE circulars, are:
-
The audit must be completed within six months from the end of the relevant financial year (i.e., for a financial year ending March 31, the audit should ordinarily be completed by around September 30 of the same calendar year).
-
The compliance audit report must be submitted to RAASB/SEBI within one month of the date the audit is completed.
-
If the audit throws up adverse findings, the RA must submit an Action Taken Report (ATR) detailing the corrective steps taken, duly approved by the individual RA (or by the management, in the case of a non-individual RA) to RAASB/SEBI within one month of the audit report, but in no case later than October 31 of each year, in respect of the previous financial year.
-
RAs are additionally required to obtain and maintain an annual certificate confirming compliance with client-level segregation requirements (i.e., ensuring that advisory and distribution-related activities, where applicable, are kept appropriately segregated), and this certificate forms part of the compliance audit.
-
The status of the compliance audit report, together with any adverse findings and the action taken thereon, must be published on the RA's website, ensuring transparency for existing and prospective clients.
So, put simply: for the financial year ending March 31, 2026, the audit should be completed by around September 30, 2026, the report filed with RAASB/SEBI within a month thereafter, and critically October 31, 2026 operates as the outer, non-negotiable deadline for filing the Action Taken Report on any adverse findings.
Major Content Areas Covered in the Annual Compliance Audit Report
While the precise format may be periodically updated by SEBI/RAASB, the Annual Compliance Audit Report typically works through the RA's compliance across a structured checklist, cross-referencing each regulation or circular clause against a status of "Complied / Not Complied / Not Applicable," along with reasons for non-compliance (if any) and management's comments on adverse findings. The major thematic areas typically covered include:
-
Entity and Registration Particulars: name of the RA, SEBI registration number, BSE enlistment number, entity type, financial year under audit, and details of the Principal Officer and Compliance Officer.
-
Registration and Eligibility: whether the RA holds a valid certificate of registration, and continues to satisfy the eligibility criteria (including qualification and NISM certification requirements) on an ongoing basis.
-
Net Worth / Deposit Requirements: verification that the RA maintains the prescribed net worth or net tangible assets (for individuals), and complies with the deposit requirements linked to the number of clients serviced.
-
Conditions of Certificate: compliance with naming conventions (use of the term "research analyst" in correspondence), intimation of material changes to SEBI, and related conditions attached to the certificate of registration.
-
General Responsibilities and Conduct: adherence to the general obligations cast on RAs, including restrictions such as the prohibition on free trials and on accepting part-payments of fees.
-
Risk Profiling and Suitability (where applicable to the RA's service model): whether appropriate profiling has been undertaken and client consent obtained.
-
Disclosures to Clients: whether all prescribed disclosures (conflicts of interest, terms of service, fee structure, etc.) have been made to clients.
-
Maintenance of Records: whether records of client interactions, research reports, recommendations, and related communications have been maintained and preserved as required, including call recordings where implementation/execution-related consent is involved.
-
Client Agreements: whether a proper agreement, including Most Important Terms and Conditions (MITC), has been executed with clients before rendering advice or charging fees.
-
Functional Website Compliance: whether the RA maintains a functional website containing the details prescribed by SEBI (including, increasingly, accessibility compliance).
-
Compliance Officer Appointment: verification that a qualified compliance officer has been appointed and holds the requisite NISM certifications.
-
Investor Grievance Redressal: compliance with the SEBI Complaints Redress System (SCORES) framework, including display of grievance redressal information and timely resolution of investor complaints.
-
Client-Level Segregation: where the RA or its group also undertakes distribution activities, whether appropriate segregation has been maintained and certified.
-
Investor Charter and Complaint Disclosures: publication of the Investor Charter and monthly disclosure of investor complaint data on the website/app.
-
Advertisement Code Compliance: adherence to SEBI's advertisement code, including prior approval requirements for advertisements, where applicable.
-
Outsourcing, Data Access, and Technology-Related Guidelines: compliance with SEBI's guidelines on outsourcing of activities, use of Software-as-a-Service (SaaS) solutions, and terms of usage of market data.
-
AML/CFT and KYC Norms: adherence to Anti-Money Laundering/Combating the Financing of Terrorism obligations and Know-Your-Client norms applicable to securities market intermediaries.
-
Periodic and Other Reporting Requirements: timely submission of half-yearly periodic reports, complaint data disclosures, and SaaS-related undertakings, as prescribed under the applicable master circular.
-
Findings of Previous SEBI/RAASB Inspections: whether observations from the last SEBI or RAASB inspection, if any, have been duly complied with.
Each of these line items is examined by the auditor, marked as complied, not complied, or not applicable, with reasons recorded for any non-compliance, and management's response/action taken captured against adverse findings, the resulting document forming the Annual Compliance Audit Report that is filed with RAASB/SEBI and published on the RA's website.
Why These Two Audits Matter Together
Though structurally very different, one being a technical, accessibility-focused audit rooted in disability-rights law, and the other a comprehensive regulatory compliance review, both audits share a common thread: they are now mandatory, time-bound obligations that form part of an RA's annual governance calendar, with public disclosure (via website publication) built into the framework. Missing either deadline is no longer a purely internal lapse; it becomes visible to regulators, and in the case of the compliance audit, to clients as well.
For Research Analysts many of whom operate as small or solo practices the practical takeaway is to build both audits into a fixed annual compliance calendar: engaging an accessibility auditor well ahead of the (now extended) October 31, 2026 deadline for the digital accessibility audit, and engaging a CA/CS/CMA for the Annual Compliance Audit soon after the financial year closes, so that the audit is completed within six months, the report filed within a month thereafter, and any Action Taken Report submitted comfortably ahead of the October 31 outer deadline.
Conclusion
SEBI's regulatory expectations from Research Analysts have grown considerably more granular and technology-conscious in recent years from the depth of the Annual Compliance Audit, which tests adherence across registration, conduct, disclosure, record-keeping and reporting obligations, to the newer Digital Accessibility Audit, which brings disability-inclusive design squarely into securities market compliance. With the accessibility audit deadline now extended to October 31, 2026, and the compliance audit cycle continuing to run on its six-month-plus-one-month-plus-ATR-by-October-31 timeline, Research Analysts would do well to treat these not as year-end scrambles, but as structured, forward-planned exercises engaging the right professionals early, documenting compliance contemporaneously, and using the audit process itself as an opportunity to strengthen investor trust rather than merely satisfy a regulatory checkbox.
