Corporate & Compliance Digest August 31, 2026

We are delighted to share this week's AKP Corporate & Compliance Weekly Digest. Please feel free to write to us with your feedback at info@akandpartners.in.
1. Labour Law & Employment Law
1.1. Karnataka passes S&E Amendment Bill to streamline compliance and decriminalise procedural offences
The Karnataka Legislature has passed the Karnataka Shops and Commercial Establishments (Amendment) Bill, 2026, introducing significant reforms to the Karnataka Shops and Commercial Establishments Act, 1961 ("S&E Act"). The Bill exempts establishments employing 10 or more workers that are already registered under the Occupational Safety, Health and Working Conditions Code, 2020 (“OSH&WC Code”) from obtaining separate registration under the S&E Act, thereby eliminating duplicate registration requirements. It also enables electronic registration and communication, provides for perpetual registration validity until closure of the establishment, mandates issuance of service certificates to employees within seven days of request, and prohibits employers from retaining employees’ original documents. Additionally, the Bill decriminalises certain procedural non-compliances by replacing imprisonment with enhanced monetary penalties, introduces a revised compounding framework, and creates a statutory appeal mechanism against compounding orders, with the objective of improving ease of doing business and strengthening trust-based governance.
1.2. Gujarat mandates online registration under OSH&WC Code through Shram Setu Portal
The Government of Gujarat has issued a notification mandating online registration of eligible establishments under the OSH&WC Code through the Shram Setu Portal. Establishments employing 10 or more workers are required to obtain registration under the Code. New establishments must apply for registration within 60 days of the Code becoming applicable, while establishments already registered under earlier labour laws are required to update their registration details online within 180 days. The notification also requires registration certificates to be prominently displayed at the principal place of business, either physically or digitally, as part of the State’s efforts to promote digital labour law compliance and streamlined regulatory administration.
1.3. Tripura issues Draft OSH&WC Rules, 2026
The Government of Tripura has issued the Draft Tripura Occupational Safety, Health and Working Conditions Rules, 2026 (Draft OSH&WC Rules), proposing a comprehensive framework for implementation of the OSH&WC Code in the State. The draft rules seek to replace multiple existing labour law rules relating to factories, contract labour, building and construction workers, inter-state migrant workers, plantations and motor transport workers with a unified compliance regime. The proposed framework mandates electronic registration of establishments through a government portal, prescribes registration fees based on workforce size, requires issuance of appointment letters to employees, introduces periodic medical examinations for workers, and lays down detailed reporting requirements for workplace accidents, dangerous occurrences and occupational diseases. The draft rules also provide for online appeals, digital compliance processes and enhanced obligations relating to worker health, safety and welfare.
2. Securities & Capital Markets
2.1. CDSL notifies SEBI’s IT Resilience Index Framework for MIIs
Central Depository Services (India) Limited ("CDSL") has informed Depository Participants ("DPs") about the Securities and Exchange Board of India ("SEBI") framework introducing an Information Technology Resilience Index (ITRI) for Market Infrastructure Institutions (MIIs). The framework seeks to strengthen monitoring of the resilience, reliability and cyber security of critical IT systems through a system-driven index based on parameters such as availability, security, integrity, governance, business continuity and scalability. MIIs are required to operationalise the framework, including early warning mechanisms and continuous service delivery monitoring, by 28 February 2027, with the first ITRI reporting cycle covering the half-year ending 31 March 2027.
2.2. CDSL clarifies nomination requirements for minor nominees in Demat Accounts
CDSL has clarified the operational requirements for nomination in demat accounts where the nominee is a minor. CDSL has specified that the nominee’s date of birth and minor status indicator will be mandatory fields. While guardian details for a minor nominee remain optional in line with SEBI requirements, where such details are provided, the relationship between the guardian and the nominee must also be disclosed. The revised functionality will be made available in the live environment from 28 August 2026.
2.3. NSDL notifies SEBI Alignment of Cyber Incident Reporting Portal with FIRE Format
National Securities Depository Limited ("NSDL") has notified DPs of the SEBI circular aligning SEBI’s Cyber Incident Reporting Portal with the Forum of Incident Response and Evidence Sharing (FIRE) reporting format. The alignment is intended to standardise cyber incident reporting across regulated entities, improve the quality and consistency of incident disclosures, and facilitate more effective monitoring, analysis and response to cybersecurity incidents. DPs have been advised to take note of the revised reporting requirements and ensure compliance with the updated cyber incident reporting framework.
2.4. NSDL notifies SEBI Circular on acceptance of digitally signed PoAs from FPIs
NSDL has notified Designated Depository Participants (DDPs) regarding the SEBI circular permitting Foreign Portfolio Investors (“FPIs”) to submit digitally signed Powers of Attorney ("PoAs") in accordance with the Information Technology Act, 2000. Under the revised framework, digitally signed PoAs may be accepted as valid proof-of-address documents for FPI onboarding, eliminating the need for notarisation, apostillisation or consularisation. The measure forms part of SEBI’s broader initiative to digitalise and streamline the FPI registration process, reduce onboarding timelines and enhance ease of doing business for foreign investors. The circular came into effect on 20 August 2026.
2.5. NSDL revises deadline for submission of Pay-in instructions on SPEED-e
NSDL has informed participants of revised deadline timings for submission of pay-in instructions on SPEED-e following changes in pay-in and pay-out schedules for stock exchange settlements. The revised timelines apply to various settlement categories, including National Stock Exchange of India Limited (NSE) and BSE Limited (BSE) market settlements, and require participants to ensure that client and clearing member instructions submitted through SPEED-e are executed within the updated cut-off periods. NSDL has advised participants to make necessary operational arrangements to ensure timely settlement compliance and minimise the risk of settlement failures.
2.6. NSDL issues operational guidelines on Modified Nomination Norms for Demat Accounts and MF Folios
NSDL has issued operational guidelines for implementation of the SEBI framework on modified nomination norms for demat accounts and mutual fund folios. Under the revised framework, nomination will be mandatory for all new single-holder accounts and folios unless the investor expressly opts out, while nomination will remain optional for jointly held accounts. Investors may appoint up to three nominees and submit, modify or cancel nominations through online or offline channels using simplified documentation and authentication procedures. The guidelines also streamline nomination requirements by removing the witness requirement for physically signed nomination forms and mandate periodic reminders to investors without registered nominations, with the objective of reducing unclaimed assets and improving ease of doing investments. The revised norms are effective from 1 September 2026.
2.7. NSDL enhances BSDA modification process in Local DPM System
NSDL has introduced enhancements to the Basic Services Demat Account ("BSDA") modification process in the Local Depository Participant Module (DPM) system. The enhancement is intended to facilitate more efficient processing of BSDA-related modifications and support implementation of the revised regulatory framework governing BSDA eligibility and opt-out requirements. DPs are required to capture and maintain prescribed consent details and other relevant information through the enhanced system functionalities to ensure compliance with the updated BSDA framework and improve operational efficiency in account management.
3. Information Technology & Data Protection
3.1. CERT-In issues Advisory on Critical Remote Code Execution Vulnerability in Gitea
The Indian Computer Emergency Response Team ("CERT-In") has issued a critical vulnerability advisory concerning Gitea versions 1.17 to 1.27.0. The vulnerability (CVE-2026-60004) exists in the diffpatch endpoint and could allow an attacker with repository access to execute arbitrary shell commands as the Gitea service account. Successful exploitation may lead to unauthorised access to source code repositories, sensitive information disclosure, unauthorised modification of repositories and potential system compromise. CERT-In has advised users to apply the vendor-recommended security updates immediately.
3.2. CERT-In warns of High-Severity Hardcoded Credentials Vulnerability in CP Plus Router
CERT-In has reported a high-severity vulnerability (CVE-2026-19412) affecting CP Plus CP-XR-DE21-S routers running firmware version 1.057.043_0027 or below. The vulnerability arises from hardcoded credentials embedded in the firmware, which could enable attackers to gain unauthorised administrative access and full control over affected devices. CERT-In has advised users and administrators to upgrade to the latest patched firmware released by the vendor to mitigate the risk.
3.3. CERT-In alerts users to Multiple High-Severity Vulnerabilities in Google Chrome
CERT-In has issued a high-severity advisory regarding multiple vulnerabilities in Google Chrome for Desktop versions prior to 152.0.7977.64/.65 for Windows and Mac, and prior to 152.0.7977.64 for Linux. The vulnerabilities stem from issues including use-after-free errors, out-of-bounds reads, improper input validation and race conditions, which could allow remote attackers to execute arbitrary code, elevate privileges, bypass security restrictions or cause denial-of-service conditions. CERT-In has recommended that users update Google Chrome to the latest version provided by the vendor.
3.4. CERT-In issues Advisory on Multiple Vulnerabilities in Oracle Products
CERT-In has issued a high-severity advisory regarding multiple vulnerabilities affecting various Oracle Corporation products, including Oracle MySQL, Oracle Database Server, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Analytics, Oracle Communications, Oracle Commerce and Oracle Financial Services Applications. The vulnerabilities could enable attackers to gain unauthorised access, execute arbitrary code, disclose sensitive information, bypass security controls or cause denial-of-service conditions. Certain vulnerabilities may be exploitable remotely without requiring valid user credentials, posing significant risks to affected systems. CERT-In has advised organisations and information technology administrators to promptly apply the security updates released by Oracle to mitigate potential exploitation.
4. Corporate Law & MCA
4.1. MCA publishes FAQs on Registration and Compliance Requirements for Foreign Companies and Indian Subsidiaries
The Ministry of Corporate Affairs ("MCA") has issued a comprehensive Frequently Asked Questions (“FAQs”) document clarifying the regulatory framework applicable to foreign companies and Indian subsidiaries of foreign entities. The FAQs provide guidance on registration requirements, filing obligations, permissible activities for liaison, branch and project offices, naming conventions for subsidiaries, documentation and apostille requirements, and approvals from regulators such as the Reserve Bank of India ("RBI") and the International Financial Services Centres Authority ("IFSCA"). The MCA has clarified that a subsidiary incorporated in India, even if wholly owned by a foreign company, remains an Indian company and is not required to register as a foreign company. The FAQs also address annual filing obligations, Corporate Social Responsibility ("CSR") compliance, foreign director documentation, registration timelines and sector-specific approvals, providing greater regulatory clarity for foreign investors and multinational groups establishing or operating businesses in India.
5. Regulatory Enforcement SEBI
Authority | Name of the Entity | Amount | Contravention |
SEBI | Vedic Ayurveda Limited
| INR 3,00,000 (Indian Rupees Three Lakh only)
| Failure to comply with promoter reclassification requirements and filing incorrect shareholding pattern disclosures for multiple quarters, in violation of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015. |
Disclaimer
The note is prepared for knowledge dissemination and does not constitute legal, financial or commercial advice. AK & Partners or its associates are not responsible for any action taken based on its contents.
For further queries or details, you may contact:
Mr Anuroop Omkar
Founding Partner, AK & Partners





Comments