NSDL revised the requirements relating to the Annual System Audit Report for Depository Participants

Jun 07, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Secretarial ComplianceThe National Securities Depository Limited (NSDL), on June 04, 2026, revised the requirements relating to the Annual System Audit Report for Depository Participants (DPs) to align with SEBI’s Cyber Security and Cyber Resilience Framework (CSCRF). The circular updates the eligibility criteria for appointment of system auditors and the Terms of Reference (TOR) for conducting annual system audits, replacing the corresponding provisions issued through the September 18, 2024 circular.

Under the revised framework, Depository Participants are required to submit the Annual System Audit Report annually by June 30 (within three months from the end of the financial year). Where the auditor identifies any non-compliance, the participant must submit a Corrective Action Taken Report (ATR) by September 30, which must be validated by the same auditor who conducted the audit. Auditors are also required to classify each TOR item as Compliant, Non-Compliant, or Not Applicable, with justification for any non-applicable items.

The circular further emphasizes that failure to submit the Annual System Audit Report within the prescribed timeline will be treated as a regulatory non-compliance and may attract penalties or other actions under NSDL Business Rules. Participants are advised to strengthen their systems and compliance processes and ensure auditors are informed of the revised audit requirements.

[Circular No. NSDL/POLICY/2026/0087]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT