Corporate & Compliance Digest August 17, 2026
- AK & Partners

- Aug 17
- 8 min read
We are delighted to share this week's AKP Corporate & Compliance Weekly Digest. Please feel free to write to us with your feedback at info@akandpartners.in.
1. Labour Law & Employment Law
1.1. UT of Ladakh notifies Social Security Rules, 2026
The Administration of the Union Territory of Ladakh has notified the Code on Social Security (Ladakh) Rules, 2026 under the Code on Social Security, 2020, consolidating and replacing various erstwhile Jammu and Kashmir labour and social security rules. The Rules establish the Ladakh Unorganised Workers’ Social Security Board and the Ladakh Building and Other Construction Workers’ Welfare Board, prescribe procedures relating to gratuity, maternity benefits, employee compensation, Employees’ Insurance Court proceedings, welfare schemes for building and construction workers, cess collection, employment information reporting, compliance, offences and compounding. Key provisions include mandatory registration of establishments, filing of annual returns, maintenance of employment records, reporting of vacancies to Career Centres, and administration of the Ladakh Social Security Fund. The Rules also prescribe detailed timelines, forms and procedures for gratuity claims, appeals, maternity benefit complaints, compensation matters and social security governance in the Union Territory.
2. Securities & Capital Markets
2.1. CDSL advises DPs to comply with SEBI’s “@valid” UPI ID requirements
Central Depository Services (India) Limited ("CDSL"), pursuant to a clarification issued by the Securities and Exchange Board of India ("SEBI"), has advised Depository Participants ("DPs") to ensure that all investor-facing collection bank accounts are linked with validated “@valid” Unified Payments Interface ("UPI") IDs. The clarification extends beyond UPI transactions and requires all bank accounts through which DPs receive funds, fees or other monies from individual and non-institutional investors to be verifiable through the SEBI Check facility before investors transfer funds. Each investor-facing account must have a separate “@valid” UPI ID, although such IDs need not necessarily be enabled for inward UPI payments. DPs are required to implement the necessary changes within the timeline prescribed by SEBI to enhance investor protection and reduce the risk of fraudulent fund transfers.
2.2. CDSL communicates SEBI amendments to Municipal Debt Securities Framework
CDSL has informed DPs of amendments notified by the SEBI to the SEBI (Issue and Listing of Municipal Debt Securities) Regulations, 2015 (ILMDS Regulations). The revised framework permits privately placed municipal debt securities with a face value of either INR 100,000 (Indian Rupees One Lakh only) or INR 10,000 (Indian Rupees Ten Thousand only), subject to specified conditions. SEBI has also introduced a two-step escrow account mechanism for pooled finance vehicles and Special Purpose Vehicles ("SPVs") to strengthen repayment security and investor protection. In addition, disclosure timelines for municipalities have been relaxed, with half-yearly unaudited financial results now due within 60 days and annual audited financial results within 90 days from the end of the relevant period. DPs have been advised to take note of the amendments, which are effective immediately.
2.3. NSDL communicates SEBI’s Streamlined Inspection Framework for market intermediaries
National Securities Depository Limited ("NSDL") has informed Participants of the SEBI revised inspection framework for market intermediaries, effective from Financial Year (FY) 2026-27. Under the new approach, stock exchanges and depositories will conduct joint inspections of Stock Brokers and DPs, while SEBI will rationalise its inspection activity to approximately one-third of the inspections conducted in the previous financial year. SEBI has also discontinued repetitive annual comprehensive inspections of compliant entities, particularly Qualified Stock Brokers (QSBs), and will instead adopt a risk-based supervisory approach focusing on entities with elevated risk indicators, recurring compliance concerns and regulatory alerts. The framework further provides for joint inspections of entities holding multiple intermediary registrations and increased reliance on exchange-generated alerts, complaints, social media inputs, cyber incidents and market intelligence to strengthen regulatory oversight while improving ease of doing business.
2.4. NSE restricts trading for clients with non-validated KYC records
The National Stock Exchange of India Limited ("NSE") has advised Trading Members to ensure that all client Know Your Client ("KYC") records are uploaded to KYC Registration Agencies ("KRAs") and that only clients with a status of “KYC Registered” or “KYC Validated” are permitted to trade. Clients whose KYC records uploaded to KRAs between 1 July 2026 and 31 July 2026 remain “On Hold” for any reason will be classified as “Not Permitted to Trade” from 29 August 2026. Such clients will neither be allowed to undertake fresh trades nor square off existing positions until KRA validation requirements are fulfilled, although open positions will expire as per the relevant contract terms. NSE has further clarified that clients becoming KRA-compliant subsequently will be permitted to trade on a T+1 basis based on information received from KRAs.
2.5. NSE introduces dedicated 1600-Series Number for investor outreach
NSE has announced that, with effect from 15 August 2026, its Investor Services Centre and Defaulter Department will use a dedicated 1600 series number, 1600322410, for outbound calls to investors. The number is intended solely for outgoing communications and cannot be used by investors to call or send messages to NSE. Market participants should continue using NSE’s toll-free number for inbound enquiries. NSE has also cautioned investors against sharing sensitive personal information, including Permanent Account Number (PAN), Aadhaar, bank account details, card details, login credentials or One-Time Passwords (OTPs), over telephone calls. The initiative is aimed at helping investors identify genuine NSE communications and enhancing protection against fraudulent and impersonation calls.
3. Information Technology & Data Protection
3.1. CERT-In issues High-Severity Advisory on multiple Microsoft Product Vulnerabilities
The Indian Computer Emergency Response Team ("CERT-In") has issued a high-severity advisory highlighting multiple vulnerabilities across various Microsoft products, including Microsoft Windows, Microsoft Office, Microsoft Azure, Microsoft SQL Server, Microsoft Dynamics, Server Software and Developer Tools. The vulnerabilities could enable attackers to execute remote code, escalate privileges, access sensitive information, bypass security controls, conduct spoofing attacks, tamper with systems or cause denial-of-service (DoS) conditions. Notably, CERT-In has flagged CVE-2026-68820, a privilege escalation vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock, which is reportedly being actively exploited in the wild. Organisations and users are advised to apply the latest Microsoft security updates immediately to mitigate the risk of system compromise, data exfiltration, ransomware attacks and operational disruption.
3.2. CERT-In issues advisory on Apple Threat Notifications and Spyware Risks
CERT-In has issued an advisory following threat notifications released by Apple regarding sophisticated spyware attacks targeting Apple devices, including users in India. According to Apple, the attacks are linked to highly resourced or state-sponsored adversaries and may compromise device security and sensitive data. CERT-In has advised users to immediately update iPhones to iOS 26.6 and ensure all other Apple devices, messaging applications and cloud-based applications are updated to their latest versions. Users are also encouraged to enable Lockdown Mode for enhanced protection against spyware threats. Individuals who have received an Apple threat notification may seek technical assistance from CERT-In; however, they are advised not to reset, restart or modify affected devices to preserve potential forensic evidence.
3.3. CERT-In issues critical advisory on Langflow OSS Remote Code Execution Vulnerability
CERT-In has issued a critical severity advisory regarding a Remote Code Execution (RCE) vulnerability in Langflow Open Source Software (“Langflow OSS”) versions 1.0.0 to 1.10.0. The vulnerability could allow an unauthenticated attacker to obtain a superuser token and execute arbitrary Python code on affected servers, potentially leading to complete compromise of the application and underlying system. According to CERT-In, the risk is particularly significant in default deployments where the auto-login feature is enabled and the code validation endpoint is accessible over a network. Organisations and individuals using Langflow OSS are advised to immediately apply vendor-recommended security updates and mitigations to safeguard the confidentiality, integrity and availability of affected systems.
3.4. CERT-In issues High-Severity Advisory on WordPress XSS Vulnerability
CERT-In has issued a high-severity advisory regarding a Cross-Site Scripting (XSS) vulnerability affecting WordPress versions prior to 7.0.3. The vulnerability arises from improper input handling and sanitisation on the login screen and could allow an unauthenticated attacker to execute arbitrary JavaScript on an affected system. In certain circumstances, successful exploitation may also lead to execution of PHP code and further compromise of the website or underlying system. CERT-In has advised organisations and individuals using WordPress to immediately upgrade to WordPress version 7.0.3 or later to mitigate the risk of unauthorised access, remote compromise and system exploitation.
3.5. CERT-In Issues Critical Advisory on SQL Injection Vulnerability in Metabase
CERT-In has issued a critical severity advisory regarding a SQL Injection vulnerability affecting multiple versions of Metabase, a business intelligence and data analytics platform. The vulnerability could allow an unauthenticated remote attacker to inject malicious SQL commands through the password reset endpoint, potentially leading to unauthorised administrator access, modification of application configurations, and access to or export of sensitive data. CERT-In has warned that the vulnerability poses a significant risk to the confidentiality, integrity and availability of affected systems and has advised organisations and individuals using Metabase to immediately apply the vendor-recommended security updates.
4. Taxation (Direct & Indirect)
4.1. CBDT Releases FAQs on Key Tax Relief and Ease of Doing Business Measures Proposed Under the Taxation and Other Laws (Amendment) Bill, 2026
The Central Board of Direct Taxes ("CBDT"), through a set of Frequently Asked Questions (FAQs), has clarified key amendments proposed under the Taxation and Other Laws (Amendment) Bill, 2026. The proposed changes include extending tax exemptions for foreign companies supporting electronic goods manufacturing until tax year 2040-41, introducing new tax exemptions for foreign mining companies selling rough diamonds in Special Notified Zones (SNZs), and providing relief for foreign companies storing components in customs bonded warehouses for contract manufacturing. The FAQs also clarify proposed simplification of the data centre tax regime through removal of certain notification requirements and recognition of leased data centre models. Additionally, the proposed amendments seek to exempt dividends received by business trust unit holders from SPVs operating under the new tax regime and significantly relax eligibility conditions for investment funds to facilitate the relocation of fund managers to India and promote ease of doing business.
5. Regulatory Enforcement MCA
Authority | Name of the Entity | Amount | Contravention |
ROC - Delhi | AVTAR STEEL LIMITED and its officers in default
| INR 300,000 (Indian Rupees Three Lakh only)
| Failure to appoint the requisite number of eligible Independent Directors as required under Section 149(4) of the Companies Act, 2013 read with Rule 4 of the Companies (Appointment and Qualification of Directors) Rules, 2014, attracting penalty under Section 172 of the Companies Act, 2013. The company remained non-compliant from 1 April 2016 to 10 June 2025.
|
ROC- Mumbai | Arihant Trip Private Limited
| INR 5,000 (Indian Rupees Five Thousand only)
| Incorrect disclosure in e-Form MGT-7A for FY 2022-23 by erroneously reporting ‘Nil’ debentures despite the company having outstanding 13.5 percent (thirteen point five percent) Compulsorily Convertible Debentures ("CCDs").
|
ROC- Kolkata | Shekhavati Investment Corporation Limited
| INR 200,000 (Indian Rupees Two Lakh only)
| Failure to file Form CSR-2 for FY 2020-21 within the prescribed timeline under Rule 12(1B) of the Companies (Accounts) Rules, 2014, attracting penalty under Section 450 of the Companies Act, 2013.
|
ROC- Kolkata | Sollfege Smart Electronics Limited
| INR 10,000 (Indian Rupees Ten Thousand only)
| Filing an incorrect e-Form AOC-4 CFS for FY 2018-19 by incorrectly stating the Annual General Meeting ("AGM") date as 30 September 2019 instead of 11 October 2019, resulting in violation of Rule 8(3) of the Companies (Registration Offices and Fees) Rules, 2014 and attracting penalty under Section 450 of the Companies Act, 2013.
|
ROC- Kanpur | J. K. Cement Limited
| INR 500,000 (Indian Rupees Five Lakh only)
| Delayed filing of Form BEN-2 relating to Significant Beneficial Ownership ("SBO"). The company failed to file Form BEN-2 within 30 days of receipt of Form BEN-1 dated 20 January 2021 and filed the form on 18 May 2026, resulting in a delay of approximately 1,914 days, in violation of Section 90(4) of the Companies Act, 2013 read with Rule 4 of the Companies (Significant Beneficial Owners) Rules, 2018, attracting penalty under Section 90(11) of the Companies Act, 2013. |
Disclaimer
The note is prepared for knowledge dissemination and does not constitute legal, financial or commercial advice. AK & Partners or its associates are not responsible for any action taken based on its contents.
For further queries or details, you may contact:
Mr Anuroop Omkar
Founding Partner, AK & Partners





Comments