top of page

Corporate & Compliance Digest July 20, 2026

  • Writer: AK & Partners
    AK & Partners
  • Jul 20
  • 6 min read

We are delighted to share this week's AKP Corporate & Compliance Weekly Digest. Please feel free to write to us with your feedback at info@akandpartners.in.


1.            Labour Law & Employment Law


1.1.      Ministry of Finance issues instructions on Timely Payment of Wages to Outsourced and Contractual Workers

The Ministry of Finance ("MoF"), Department of Expenditure, has issued instructions requiring all procuring entities to ensure timely payment of wages and salaries to manpower engaged directly or through contractors in compliance with the Code on Wages, 2019 and other labour codes. Employers must ensure wages are paid within prescribed timelines, including within seven days of the succeeding month for monthly-paid employees. The Office Memorandum also places responsibility on principal employers to verify wage payments, earmark sufficient funds for manpower contracts, incorporate penalty clauses for delayed payments, and monitor compliance through Government e-Marketplace ("GeM") and Public Financial Management System ("PFMS") reports. Contractors that repeatedly default on wage payments may face blacklisting under the General Financial Rules, 2017 (GFR 2017).

 

2.            Securities & Capital Markets 


2.1.         CDSL modifies nomination norms for Demat Accounts

Central Depository Services (India) Limited ("CDSL") has introduced revised norms to simplify the nomination process for demat accounts. Sole individual account holders will now be required to either register a nominee or formally opt out of nomination, while nomination will remain optional for jointly held demat accounts. Any addition, modification or updation of nomination in joint accounts will require consent from all joint holders. The revised framework also simplifies offline nominations by removing the witness requirement for wet signatures, except where a thumb impression is used. Depository Participants ("DPs") must ensure mandatory capture of key nominee details, issue acknowledgements for nomination requests, and periodically encourage investors without nomination registrations to comply. The changes will be implemented in the live environment from 28 August 2026. 

 

2.2.        CDSL introduces LAS Module on Easiest Platform for Digital Pledge Processing

CDSL has introduced a Loan Against Securities ("LAS") module on its Easiest platform. The new facility enables investors to digitally initiate pledge requests through participating banks and Non-Banking Financial Companies (NBFCs) to avail loans against securities held in their demat accounts. DPs will be required to approve or reject LAS pledge requests through the Easiest portal on the same day of request generation, with an option to enable auto-approval for future transactions. The initiative is aimed at streamlining and digitising the pledge creation process for securities-backed lending.

 

2.3.          CDSL directs freezing of Demat Accounts with Non-Validated KYC Records

CDSL has notified DPs that demat accounts linked to Permanent Account Numbers (PAN) whose Know Your Customer (KYC) records remain unvalidated by KYC Registration Agencies (KRAs) will be frozen for both debit and credit transactions from 1 August 2026. CDSL has provided DPs with account-wise details of affected investors for necessary follow-up and compliance. Frozen accounts will be marked as KYC non-compliant and may be reactivated only upon successful completion of the prescribed KYC validation and unfreezing process.  

 

2.4.        NSE Clearing issues clarification on submission of action taken reports for Internal Audit Non-Compliances

NSE Clearing Limited ("NSE Clearing") has reiterated the framework for submission of Action Taken Reports ("ATRs") in respect of non-compliances identified in Internal Audit Reports by Clearing Members. Under the revised compliance framework, all non-compliances must be rectified within two months from the due date for submission of the Internal Audit Report, and the ATR must be certified by the empanelled internal auditor, including sample verification covering at least one month. The requirement applies to all Internal Audit Reports for the half-year ended 31 March 2026 and onwards, with the due date for submission of ATRs for the half-year ended 31 March 2026 being 31 July 2026. NSE Clearing has advised Clearing Members to ensure timely compliance with the revised reporting requirements.

 

3.           Information Technology & Data Protection


3.1.        CERT-In flags multiple high-severity vulnerabilities in GitLab CE and EE

The Indian Computer Emergency Response Team ("CERT-In") has issued a high-severity vulnerability note regarding multiple security vulnerabilities affecting GitLab Community Edition (CE) and Enterprise Edition (EE) versions prior to 18.11.7, 19.0.4 and 19.1.2. The vulnerabilities may enable attackers to execute arbitrary scripts, carry out Cross-Site Scripting (“XSS”) attacks, gain unauthorised access to protected resources, expose sensitive information and credentials, manipulate repository content, and make unauthorised changes to system settings or records. Organisations and individuals using self-managed GitLab installations have been advised to promptly apply the latest security patches released by GitLab to mitigate the identified risks.

 

3.2.        CERT-In issues high-severity advisory on multiple vulnerabilities in SAP Products

CERT-In has issued a high-severity advisory highlighting multiple vulnerabilities affecting several SAP products, including SAP S/4HANA, SAP NetWeaver, SAP Commerce Cloud, SAP Fiori and SAP Integration Suite. The identified vulnerabilities could enable threat actors to execute arbitrary code, conduct Structured Query Language (“SQL”) injection and XSS attacks, bypass authentication and authorisation controls, disclose sensitive information, exploit security misconfigurations, and cause denial-of-service conditions. CERT-In has warned that successful exploitation may lead to unauthorised access, data compromise, system disruption and remote code execution. Organisations using affected SAP products have been advised to promptly implement the security fixes released by SAP.

 

3.3.        CERT-In issues high-severity advisory on multiple vulnerabilities in Microsoft Products

CERT-In has issued a high-severity advisory regarding multiple vulnerabilities affecting various Microsoft products, including Microsoft Windows, Microsoft Office, Microsoft Azure, Microsoft Dynamics, SQL Server and other Microsoft applications. The vulnerabilities could enable threat actors to gain elevated privileges, execute arbitrary code remotely, access sensitive information, bypass security controls, conduct spoofing attacks, tamper with systems and cause denial-of-service (DoS) incidents. CERT-In has specifically highlighted vulnerabilities in Microsoft Active Directory Federation Services (AD FS) and Microsoft Office SharePoint, certain of which are reportedly being actively exploited. Organisations and individuals using affected Microsoft products have been advised to apply the latest security updates released by Microsoft without delay.

 

3.4.        CERT-In flags multiple high-severity vulnerabilities in Drupal

CERT-In has issued a high-severity vulnerability note regarding multiple vulnerabilities in Drupal Core. The vulnerabilities may allow threat actors to disclose sensitive information and conduct XSS attacks due to insufficient access controls and improper sanitisation mechanisms. Successful exploitation could result in unauthorised access to sensitive information and potential system compromise. CERT-In has advised organisations and individuals using affected Drupal versions to upgrade to the latest supported releases, noting that several older versions, including Drupal 8, Drupal 9, Drupal 10.5.x and Drupal 11.2.x, have reached end-of-life and no longer receive security support.

 

4.           Taxation (Direct & Indirect)


4.1.        CBDT notifies TDS Exemption for specified payments to IFSC Units

The Central Board of Direct Taxes (CBDT) has notified that no tax deduction at source (TDS) shall apply on specified payments made to eligible units operating in an International Financial Services Centre ("IFSC") and claiming deductions under Section 147 of the Income-tax Act, 2025. The exemption covers various income streams, including interest on external commercial borrowings, dividends, professional fees, advisory fees, brokerage, referral fees, commission and distribution fees received by eligible IFSC entities such as banking units, finance companies, fund management entities, investment advisers and insurance intermediaries. To avail the benefit, the IFSC unit must furnish a prescribed declaration to the payer, and the relaxation will be available for the selected period of twenty consecutive tax years. The notification is deemed effective from 1 April 2026.

 

5.               Regulatory Enforcement MCA

 

Authority

Name of the Entity

Amount

Contravention

ROC, Delhi

Varindera Constructions Limited

 

INR 10,39,706 (Indian Rupees Ten Lakh Thirty-Nine Thousand Seven Hundred and Six only)

 

Failure to transfer unspent Corporate Social Responsibility (CSR) to the specified fund within the prescribed period, resulting in violation of Section 135(7) of the Companies Act, 2013.

 

ROC, Delhi

Narains Infrastructure Private Limited

 

INR 2,50,000 (Indian Rupees Two Lakh Fifty Thousand only)

 

Delay of 826 days in filing Form BEN-2 relating to Significant Beneficial Ownership (SBO), in violation of Section 90(4) read with Section 90(11) of the Companies Act, 2013.

 

ROC, Delhi

Sharp Agricom Limited

 

INR 3,00,000 (Indian Rupees Three Lakh only)

 

Failure to appoint the requisite number of Independent Directors for 2,623 days, in violation of Section 149(4) read with Section 172 of the Companies Act, 2013.

 

ROC, Ahmadabad

Soleos Energy Limited

 

INR 31,000 (Indian Rupees Thirty-One Thousand only)

 

Issued the private placement offer-cum-application letter (Form PAS-4) before filing the special resolution with the Registrar of Companies in Form MGT-14, in violation of Rule 14(8) of the Companies (Prospectus and Allotment of Securities) Rules, 2014.

ROC, Coimbatore

Veejay Lakshmi Engineering Works Limited

 

INR 88,000 (Indian Rupees Eighty-Eight Thousand only)

 

Delay of 78 days in filing Form MR-1 for the re-appointment of a Whole-Time Director, resulting in contravention of Section 196 of the Companies Act, 2013.  

 

ROC, Kolkata

Bengal & Assam Company Limited

 

INR 10,000 (Indian Rupees Ten Thousand only)

 

Failure to include the prescribed CSR disclosure in the Board's Report by not annexing the CSR report as required under Rule 8(1) of the Companies (Corporate Social Responsibility Policy) Rules, 2014.

 

Disclaimer


The note is prepared for knowledge dissemination and does not constitute legal, financial or commercial advice. AK & Partners or its associates are not responsible for any action taken based on its contents.


For further queries or details, you may contact:


Mr Anuroop Omkar

Founding Partner, AK & Partners


Comments


Subscribe to our newsletter 
AK and Partners Logo

27A, Ground Floor & Upper Ground Floor,

HKV, New Delhi - 110016

Office: +91 11 41727676

info@akandpartners.in

  • LinkedIn
  • Facebook

Thanks for submitting!

© 2025 I AK & Partners

bottom of page