The Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) on April 30, 2026, issued the Standard Operating Procedure (S.O.P) Reporting mechanism by REs on the Cyber-Incidents reported/identified pertaining to Unauthorized Access to KYC Information on CKYCRR.
The following has been stated:-
•This SOP by CERSAI defines how Regulated Entities (REs) must report cyber incidents involving unauthorized access to CKYCRR under the Prevention of Money Laundering Act, 2002 framework.
•REs must report specified cyber incidents (like data breaches, malware, credential compromise, or suspicious access) within 6 hours of detection.
•Initial reporting involves incident verification, impact assessment, evidence preservation, and emailing details; CERSAI may temporarily disconnect affected REs.
•REs must submit detailed reports to CERT-In, regulators, and CERSAI, and handle containment, coordination, and communication.
•Post-incident, REs must conduct root cause analysis, implement corrective actions, and non-compliance can lead to system blocking and regulatory reporting.
The detailed notification is given in the document below.