4.5 Maintenance of Compliance Records & Regulatory Inspection

Key Takeaways

  • Regulation 25(1) of the SEBI (Research Analysts) Regulations, 2014 requires signed reports, recommendations and rationale, public appearance records, KYC, a client register with PAN, client communication records and client consent.

  • Regulation 25(2) requires records to be kept in physical or electronic form for at least five years, and electronically kept records that must be signed must be digitally signed.

  • SEBI can inspect research analysts under Chapter IV (Regulations 27 to 31), normally with seven days' notice, and PARS must cooperate and produce records.

  • Regulation 26 requires a non-individual research analyst to appoint a compliance officer or an independent professional who is a member of ICAI, ICSI or the Institute of Cost Accountants of India.

  • The annual compliance audit under Regulation 25(3) must be done by an ICAI, ICSI or ICMAI member within six months of the financial year end, with the report filed within one month.

Last updated: October 2026

4.5 Maintenance of Compliance Records & Regulatory Inspection

Quick Answer: Regulation 25 of the SEBI (Research Analysts) Regulations, 2014 lists the records a research analyst must keep, from signed research reports and the rationale for each recommendation to client KYC, a client register with PAN, records of all client communication, and the client's consent to the terms and conditions. Records may be physical or electronic but must be preserved for at least five years. SEBI can inspect them under Chapter IV of the regulations, a non-individual RA must have a compliance officer under Regulation 26, and every RA must complete an annual compliance audit by a member of ICAI, ICSI or the Institute of Cost Accountants of India.


Statutory Record-Keeping Mandate: Regulation 25 of SEBI RA Regulations

In securities markets, regulatory accountability depends on an unbroken documentary trail. Records let SEBI and the firm check what was recommended, why, to whom, and when, and they protect both clients and staff when disputes arise.

Records Required by Regulation 25(1)

Every research analyst and research entity must maintain:

  1. Research reports, duly signed and dated;
  2. Research recommendations provided;
  3. Rationale for arriving at each research recommendation;
  4. Record of public appearances;
  5. Know Your Client (KYC) records of fee-paying clients;
  6. A client register listing each client with PAN, the date and nature of the research service, the products or securities covered, and the fee or consideration charged or received;
  7. Records of communication with all clients, including prospective clients, such as emails and call recordings; and
  8. The terms and conditions of research services disclosed to clients and the clients' consent on them.

SEBI's master circular explains item 7 in detail. Interaction records begin with the first interaction with a client (even before onboarding) and continue until the research service ends. They may be a physical record signed by the client, telephone recordings, email from the registered email ID, SMS records, or any other legally verifiable record. A call recording is not needed when the interaction already has a digital footprint, such as email. The requirement covers fee-paying and non-fee-paying clients, including institutional investors.


The 5-Year Retention Rule & Electronic Data Governance

Regulation 25(2) sets the retention period: all records must be maintained in physical or electronic form and preserved for a minimum period of five (5) years. Where a dispute has been raised, the master circular requires the records to be kept until the dispute is resolved, and records that SEBI asks to be preserved must be kept until SEBI says otherwise.

REGULATION 25 RECORD-KEEPING: MINIMUM 5 YEARS
- Signed research reports        - Recommendations and rationale
- Public appearance records      - KYC of fee-paying clients
- Client register with PAN       - Client communication records
- Terms and conditions and the client's consent

Electronic Record Governance

Regulation 25(2) adds one technical rule: records that must be signed and are kept electronically must be digitally signed. Beyond that, good practice, and SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for regulated entities, points firms toward:

  • Tamper-Evident Storage: Write-once or versioned archives, so archived files cannot be silently altered or deleted;
  • Audit Trails: Logs showing who created, accessed or changed each record;
  • Backups: Regular backups held away from the primary site to survive fire, cyber incidents or hardware loss;
  • Business Continuity: A tested plan for restoring archives and client communication systems.
Record CategorySpecific Contents to PreserveWhy It Matters in an Audit or Inspection
Rationale and WorkpapersModel spreadsheets, assumptions, notes supporting each recommendationShows the documentary basis that Regulations 18(7) and 20(4) require
Published ResearchFinal signed reports, publication date and time, recipient listsShows simultaneous release with no selective advance access (Regulation 22(1))
Employee Trade RecordsApproval requests, trade confirmations, restricted listsShows compliance with the personal trading restrictions in Regulation 16
Client InteractionsCRM notes, emails, recorded calls, webinar recordingsShows that sales and non-core staff stayed within their role and gave no unauthorised tips
Loading diagram...
Five-Year Record Retention and Compliance Governance Cycle under SEBI RA Regulations

SEBI's Inspection Powers (Chapter IV of RA Regulations)

SEBI actively supervises research analysts. Its inspection powers sit in Chapter IV (Regulations 27 to 31) of the RA Regulations, read with Sections 11 and 11C of the SEBI Act, 1992.

Grounds for Inspection (Regulation 27)

SEBI may, on its own or on receiving information or a complaint, appoint inspecting authorities to inspect the books of accounts, records and documents of a research analyst or research entity in order to:

  • Ensure that books, records and documents are being maintained in the manner the regulations specify;
  • Inspect complaints received from any person on any matter bearing on the research analyst's activities;
  • Ascertain whether the SEBI Act and the RA Regulations are being complied with; and
  • Inspect the affairs of the research analyst in the interest of the securities market or of investors.

Notice, Cooperation and Powers (Regulations 28 to 31)

  1. Notice: SEBI gives at least seven days' notice before an inspection, but it may order an inspection without notice if it is satisfied that this is in the interest of investors.
  2. Duty to Cooperate: The research analyst and every associated person with relevant information, expressly including partners, directors, the principal officer and persons associated with research services, must produce books, accounts and documents and furnish the statements and information the inspecting authority requires.
  3. Statements on Oath: The inspecting authority may examine on oath and record the statement of any employee, director, partner, principal officer or person associated with research services, and may obtain authenticated copies of documents.
  4. Action: After considering the inspection report and giving a hearing, SEBI may issue directions under Regulation 31, such as barring the RA (including its PARS) from providing research recommendations for a period, ordering refunds of fees with interest, or prohibiting access to the capital market for a specified period.

Warning

Under Section 11C(6) of the SEBI Act, 1992, a person who without reasonable cause fails to produce books, accounts or records, or refuses to answer questions during an investigation, is punishable with imprisonment of up to one year, a fine of up to ₹1 crore, or both, plus a further fine of up to ₹5 lakh for every day the failure continues.

PARS Obligations During Regulatory Inspections

Persons Associated with Research Services (PARS) frequently manage client relationship desks and CRM software. During an inspection, PARS personnel must:

  • Cooperate fully and transparently with inspecting officers;
  • Provide unredacted communication logs, customer interaction tickets, and broadcast distribution lists;
  • Never alter, backdate, delete, or conceal emails, instant messaging chats, or complaint files;
  • Answer all factual inquiries truthfully, without attempting to deflect regulatory scrutiny or fabricate explanations.

The Compliance Officer: Role, Authority & Responsibilities

Under Regulation 26 of the SEBI RA Regulations, a non-individual research analyst or research entity must appoint either a compliance officer or an independent professional who is a member of ICAI, ICSI or the Institute of Cost Accountants of India and holds the NISM certification SEBI specifies, to monitor compliance with the SEBI Act, the RA Regulations and SEBI circulars. If an independent professional is appointed, the principal officer must give SEBI or the RAASB an undertaking that the principal officer remains responsible for monitoring compliance.

Independence and Reporting Lines

The compliance officer is the firm's internal regulatory conscience and needs authority to act without commercial pressure. Firms therefore give the role direct access to senior management or the board and do not tie its pay to sales or brokerage targets.

Primary Responsibilities of the Compliance Officer

  • Administering Internal Policies: Maintaining the firm's Regulation 15 policies on dealing and trading, information barriers, and insider trading controls;
  • Information Barrier Monitoring: Overseeing separation between research and sales, trading or investment banking teams, and logging any authorised wall-crossings;
  • Personal Trading Approvals: Reviewing staff trading requests and enforcing Regulation 16 (no dealing in securities the analyst recommends or follows within 30 days before or 5 days after a report);
  • Pre-Publication Checks: Verifying that reports carry complete Regulation 19 disclosures (financial interests, 1% shareholding, compensation from the issuer);
  • Supervising Client Onboarding: Ensuring KYC, CKYC/KRA and PMLA procedures are followed, including enhanced due diligence for high-risk clients;
  • Grievance Redressal Oversight: Maintaining the complaint register, ensuring Action Taken Reports are filed on SEBI SCORES 2.0 within 21 calendar days, and representing the entity in SMART ODR proceedings.

Mandatory Annual Compliance Audit

Regulation 25(3) of the SEBI RA Regulations requires every research analyst and research entity to conduct an annual audit of compliance with the regulations.

Qualified Auditors

The audit must be conducted by a member of:

  1. The Institute of Chartered Accountants of India (ICAI);
  2. The Institute of Company Secretaries of India (ICSI); or
  3. The Institute of Cost Accountants of India (ICMAI).

Scope and Reporting Timeline (SEBI Master Circular)

  • The audit report must list each provision of the RA Regulations and of SEBI's circulars on which compliance is reported.
  • The audit must be completed within six months from the end of each financial year (by September 30 for a year ending March 31), and the report submitted to the RAASB/SEBI within one month of its date.
  • Adverse findings, with the action taken and approved by the RA or its management, must be submitted within one month of the audit report and no later than October 31 for the previous financial year.
  • The RA must publish the status of the audit report, and any adverse findings with action taken, on its website, and must provide the compliance audit report to its clients.
  • The annual certificate confirming client-level segregation of research and distribution forms part of the audit.

Auditors typically test whether reports carry adequate rationale, whether records meet the five-year rule, whether staff trading complies with Regulation 16, how complaints were handled, and whether every PARS holds a valid NISM certificate (Series XXV-A for sales and non-core staff, Series XV for others).

Test Your Knowledge

Under Regulation 25 of the SEBI (Research Analysts) Regulations, 2014, what is the minimum period for which a research analyst must preserve records such as research reports, the rationale for recommendations, client KYC and records of client communication?

A

A minimum period of two (2) years from the date of initial publication or client interaction.

B

A minimum period of three (3) years, coinciding with the validity term of NISM certifications.

C

A minimum period of five (5) years, in physical or electronic form.

D

A minimum period of eight (8) years, mirroring the financial record retention rules under the Income Tax Act.

Test Your Knowledge

Regulation 25(3) of the SEBI (Research Analysts) Regulations, 2014 requires an annual compliance audit. Who may conduct it, and by when must it be completed?

A

An empanelled financial journalist with ten years of market reporting experience, within three months of the financial year end.

B

A member of ICAI, ICSI or the Institute of Cost Accountants of India, within six months from the end of the financial year.

C

The firm's own compliance officer, provided they have passed NISM Series XXV-A, by December 31 each year.

D

A mutual fund distributor registered with AMFI, at any time before the RA's registration fee falls due.

Test Your Knowledge

During a SEBI inspection under Chapter IV of the SEBI (Research Analysts) Regulations, 2014, the inspecting authority asks for the complete communication logs between sales staff (PARS) and high-net-worth clients for the past two years and wants to record a PARS employee's statement. How must the research entity and its staff respond?

A

Withhold communications deemed commercially sensitive to preserve business confidentiality.

B

Provide only summaries prepared by the compliance officer instead of the raw logs.

C

Demand a High Court search warrant before releasing any electronic messages.

D

Produce the complete records and cooperate fully, because Regulation 29 places the duty on the RA and its associated persons, including PARS, and allows statements on oath.

Sections you finish are checked off in the contents.