9.2 Crisis Management, Service Continuity & CRM Technology
Key Takeaways
- In any crisis the PAIA's sequence is fixed: acknowledge fast, state only verified facts, escalate the same day, log everything, then close the loop once the RIA decides.
- Reassuring a client that a fallen investment 'will recover' is a forward-looking view on a security and therefore advice — outside the non-core boundary.
- The IA Regulations require KYC, risk-profiling, suitability, agreement and interaction records to be kept for five years, and until resolution where a dispute exists.
- Every client should have a documented named backup contact; single-threaded relationships are an operational continuity risk.
- CRM discipline is evidential: log the same day, record facts rather than conclusions, and never edit, delete or backdate a complaint record.
9.2 Crisis Management, Service Continuity & CRM Technology
Quick Answer: A crisis in an advisory firm is any event that breaks the client's confidence or the firm's ability to serve — a market crash, a credit event in a held product, a key-person exit, a data breach, or an outage. The PAIA's job in all of them is the same: communicate early, communicate accurately, escalate, and document. Service continuity is the planning that makes that possible, and the CRM is the system of record that proves it happened.
What counts as a crisis
| Crisis type | Trigger | First client question | PAIA's first action |
|---|---|---|---|
| Market event | Index falls sharply; a held fund drops | "Should I exit?" | Acknowledge, do not advise, book a review with the RIA |
| Product / credit event | A debt issuer defaults; a scheme is side-pocketed or gated | "Is my money safe?" | State only what the AMC/issuer has published; route the rest |
| Operational failure | Missed SIP, wrong statement, delayed redemption | "What happened to my money?" | Reconcile, confirm facts, give a dated commitment |
| Key-person exit | The client's RIA or relationship manager leaves | "Who handles me now?" | Named handover, in writing, before the client notices |
| Data / cyber incident | Unauthorised access to client data or systems | "Is my data exposed?" | Escalate to compliance immediately; say nothing unverified |
| Regulatory action | SEBI direction or adverse order against the firm | "Should I move my money?" | Only the firm's approved statement; never a personal view |
The crisis communication playbook
The order matters more than the wording.
- Acknowledge within hours, not days. Silence is read as concealment. A holding message that says "we know, we are checking, we will revert by 5 pm tomorrow" is better than a perfect message sent late.
- Say only what is verified. In a market or credit event, quote the AMC's or issuer's published disclosure and nothing beyond it. Speculating about recovery percentages is both unwise and a boundary breach.
- Do not give the reassurance the client is asking for. "Don't worry, it will bounce back" is a forward-looking view on a security — that is advice, and the PAIA may not give it.
- Escalate the same day. The RIA, the compliance officer and the grievance officer must hear it from the PAIA, not from SCORES.
- Log everything. Date, channel, what the client said, what was said back, who it was escalated to. The record is what protects the PAIA if the event becomes a complaint.
- Close the loop. Once the RIA decides the response, go back to the client with the decision and the reasoning — even if the answer is "no action".
The behavioural point: clients rarely leave because of a loss. They leave because nobody called. A proactive call during a drawdown costs ten minutes and is the single highest-return activity in a bad month.
Service continuity
Continuity planning is what turns the playbook above from a good intention into an operating capability.
- Business continuity and disaster recovery. Where do statements, KYC files and advice records live if the office is unavailable? Cloud-hosted records with access controls, plus tested restores, are the practical answer.
- Records that outlive people. The IA Regulations require KYC, risk-profiling, suitability, agreement and interaction records to be maintained for five years — and until resolution where a dispute exists. Continuity means those records are findable by someone other than the person who created them.
- Named backup coverage. Every client should have a documented second point of contact. A single-threaded relationship is an operational risk.
- Succession and handover. When a relationship manager exits, the handover note — goals, profile, open items, communication preferences, last review date — is a deliverable, not a courtesy.
- Cyber resilience. SEBI's cybersecurity and cyber-resilience framework applies to regulated intermediaries, and India's Digital Personal Data Protection Act, 2023 governs the personal data an advisory firm holds. For a PAIA the practical rules are unchanged from Section 8.2: least-privilege access, no client data on personal devices or personal messaging, no unencrypted transfers, and immediate escalation of any suspected exposure.
CRM and technology across the client lifecycle
The curriculum expects a PAIA to know what technology is used at each stage, not to configure it.
| Lifecycle stage | Typical system | What it produces |
|---|---|---|
| Prospecting | CRM pipeline / lead board | Qualified prospect record, next action, owner |
| Onboarding | e-KYC, video-KYC, CKYC pull, KRA upload, e-sign | 14-digit CKYC identifier, signed agreement, IPV record |
| Profiling | Digital risk-profiling questionnaire | Scored profile, category, timestamp |
| Advice & execution | Advisory platform, order routing | Suitability note (RIA-signed), executed transaction |
| Reporting | Portfolio reporting / consolidated statement tool | Periodic statement, performance report |
| Servicing | CRM task queue, ticketing, call recording | Interaction log, SLA clock, complaint ID |
| Compliance | Records archive, complaint register, conflict register | Five-year audit trail |
Three habits make the CRM useful rather than decorative:
- Same-day logging. A note written the next morning is already an approximation.
- Facts, not conclusions. Record what the client said and what was sent, not "client seems happy".
- One record per interaction. Merged or backdated entries destroy the evidential value of the whole file.
What a PAIA must never do with the CRM: delete or edit a complaint record, backdate an interaction, or export client data to a personal device. Each of these converts an ordinary service failure into a confidentiality and record-keeping breach that the RIA answers for.
A debt fund held by several clients side-pockets a defaulted issuer. Clients start calling the PAIA. Which response is correct?
Six weeks after a service complaint was resolved, a PAIA notices the CRM entry describes the issue less clearly than it should. What is the appropriate action?