top of page

Corporate & Compliance Digest September 14, 2026

Writer: AK & Partners
AK & Partners
13 hours ago
9 min read

We are delighted to share this week's AKP Corporate & Compliance Weekly Digest. Please feel free to write to us with your feedback at info@akandpartners.in.


1.          Labour Law & Employment Law


1.1.       Ministry of Labour and Employment amends EPF investment norms for rupee bonds

The Ministry of Labour and Employment has amended the investment pattern applicable under the Employees’ Provident Fund (EPF) framework by revising the category of eligible debt instruments and related investments. The amendment permits investment in Rupee Bonds with a minimum outstanding maturity of three years issued by the International Bank for Reconstruction and Development, International Finance Corporation, Asian Development Bank and New Development Bank. The change updates the investment guidelines notified under Section 17 of the Employees’ Provident Funds and Miscellaneous Provisions Act, 1952 and is aimed at expanding the universe of permissible high-quality debt investments for exempted provident fund trusts. 

 

2.              Securities & Capital Markets 


2.1.          CDSL amends DP Operating Instructions for Re-KYC of NRI clients

Central Depository Services (India) Limited ("CDSL") has amended Chapter 2 of its Depository Participant ("DP") Operating Instructions relating to account opening, pursuant to a circular issued by the Securities and Exchange Board of India ("SEBI") on relaxation of geo-tagging requirements for Non-Resident Indians ("NRIs") undertaking re-KYC. Under the revised framework, DPs offering online account opening facilities must continue to incorporate safeguards such as random action-based verification, time stamping, geo-location tagging and spoofed Internet Protocol (IP) address prevention. However, the requirement that clients be physically located in India during onboarding has been relaxed for re-KYC of existing NRI clients. Additionally, DPs must ensure that the Global Positioning System (GPS) location captured through the application or website corresponds with the country mentioned in the proof of address furnished by the NRI client. The amendments take immediate effect and are intended to facilitate smoother digital re-KYC processes for NRIs while maintaining necessary security controls.  

 

2.2.        CDSL amends DP Operating Instructions for Pledge and Invocation of Securities

CDSL has amended Chapter 8 of its DP Operating Instructions governing pledge, un-pledge and invocation of securities. The amendments require pledgors and pledgees to provide undertakings confirming compliance with the Indian Contract Act, 1872, including the pledgee’s obligation to provide reasonable notice and comply with Sections 176 and 177 relating to invocation of pledged securities. CDSL has also introduced new formats and procedures for margin pledge, margin re-pledge and auto-pledge arrangements, including one-time undertakings from Trading Members (TMs), Clearing Members (CMs) and pledgees. Further, CDSL has clarified that depository participants may continue processing margin pledge and invocation transactions based on such undertakings, while depository notifications will be sent to both pledgors and pledgees upon invocation of pledged securities. The changes are aimed at strengthening legal compliance, transparency and operational safeguards in pledge-related transactions.

 

2.3.          CDSL issues user guide for DP and Auditor Registration on audit web portal

CDSL has issued a detailed user guide for registration and login of DPs and auditors on its Audit Web Portal. CDSL has reiterated that submission of prescribed audit reports through the Audit Web Portal is mandatory, and reports submitted through any other mode will be treated as non-submission. The guide provides step-by-step procedures for registration, login, password reset, auditor addition and deletion, and report submission activities for both DPs and auditors. CDSL has advised stakeholders to adhere to the prescribed processes to ensure timely access to the portal and smooth execution of audit-related reporting and compliance requirements.

 

2.4.         CDSL notifies SEBI circular easing compliance requirements for FPIs investing in Government Securities

CDSL has notified DPs regarding the SEBI circular easing regulatory compliance requirements for Foreign Portfolio Investors ("FPIs") investing exclusively in Government Securities. Pursuant to the withdrawal by the Reserve Bank of India (RBI) of concentration limit requirements for FPIs investing in Government Securities through the General Route, SEBI has removed the requirement for such FPIs to provide investor group details. Previously, this relaxation was available only to FPIs investing under the Fully Accessible Route (FAR). Depositories, custodians and Designated Depository Participants (DDPs) have been advised to implement the necessary system changes, with the revised framework taking immediate effect.

 

2.5.          CDSL introduces new transaction status in DP89 report

CDSL has enhanced the transaction-status reporting mechanism in the DP89 Report for Invocation (Confiscation) for Early Pay-in and Pledge Release (Unpledged) for Early Pay-in transactions. Previously, such transactions were reflected with the status “F - Failed” while pending the obligation-matching process. Under the revised framework, these transactions will now be reported as “U - Under Process” until the matching process is completed, following which the final status will be updated as per the existing system logic. CDSL has advised DPs and Clearing Members (CMs) to make the necessary changes in their back-office systems. The enhancement will be effective from 18 September 2026.

 

2.6.          NSE launches Nifty AI Catalysts Index

National Stock Exchange of India Limited ("NSE"), through its subsidiary NSE Indices Limited ("NSE Indices"), has launched the Nifty AI Catalysts Index, a thematic index designed to track companies supporting the growth of India’s Artificial Intelligence (AI) ecosystem. The index provides exposure to businesses involved in computing and information technology infrastructure, connectivity, power and electrification, cooling systems, engineering and construction, and digital infrastructure materials. The index follows a free-float market capitalisation-based methodology with a maximum stock weight of 3 per cent (three per cent), has a base date of 28 June 2024 and a base value of 1,000. It will be reconstituted semi-annually and rebalanced quarterly. NSE stated that the index is expected to serve as a benchmark for asset managers and as a reference index for passive investment products, including Exchange Traded Funds (ETFs), index funds and structured products.

 

2.7.          NSE announces changes to Nifty Fixed Income Indices

NSE, through its subsidiary NSE Indices, has announced revisions to select Nifty fixed income indices, effective from 11 September 2026. The changes include the inclusion of specified State Development Loan ("SDL") securities issued by Rajasthan, Madhya Pradesh, Uttarakhand, Maharashtra and Uttar Pradesh in the Nifty SDL Plus PSU Bond Sep 2026 60:40 Index, Nifty SDL Sep 2026 Index, Nifty SDL Sep 2026 V1 Index and Nifty SDL Oct 2026 Index. The periodic reconstitution is intended to ensure that the indices continue to accurately reflect the underlying fixed income market and maintain their relevance as benchmarks for fixed income investment products.

 

2.8.          BSE announces reconstitution of multiple equity and factor indices

BSE Index Services Private Limited (BSE Index Services) has announced the reconstitution of several sectoral, thematic and factor-based indices, with the changes becoming effective from 21 September 2026. The review covers a wide range of indices, including the BSE Information Technology, BSE Healthcare, BSE Financial Services, BSE Industrials, BSE Consumer Discretionary, BSE Momentum, BSE Quality, BSE Low Volatility and various BSE 500 factor indices. Significant constituent additions and deletions have been carried out across these indices as part of the periodic review process to ensure continued representation of the underlying market segments and investment themes. BSE Index Services has clarified that there are no changes to the BSE REITs and InvITs Index and the BSE REITs Index.

 

3.            Information Technology & Data Protection


3.1.        CERT-In issues high-severity alert on privilege escalation vulnerability in Microsoft Defender

The Indian Computer Emergency Response Team ("CERT-In") has issued a high-severity advisory concerning a privilege escalation vulnerability (CVE-2026-69414) in the Microsoft Malware Protection Engine, a core component of Microsoft Defender Antivirus. The vulnerability arises from improper access control and privilege management and could allow an attacker with limited access to elevate privileges and gain unauthorised access to protected resources, potentially compromising affected systems. CERT-In has advised organisations and users to apply the security updates issued by Microsoft without delay.

 

3.2.         CERT-In warns of critical SQL injection vulnerability in All-in-One WP Migration and Backup Plugin

CERT-In has reported a high-severity SQL Injection vulnerability (CVE-2026-19949) in All-in-One WP Migration and Backup versions 7.109 and earlier. The vulnerability could allow an unauthenticated remote attacker to execute malicious SQL queries, access sensitive database information, obtain the plugin’s secret key and potentially achieve arbitrary code execution, resulting in complete compromise of affected WordPress installations. CERT-In has advised users to immediately apply the security updates and mitigations recommended by the vendor.

 

3.3.         CERT-In issues high-severity advisory on multiple vulnerabilities in Google Chrome

CERT-In has issued a high-severity advisory regarding multiple vulnerabilities affecting Google Chrome for Desktop versions prior to 152.0.7977.82/.83 for Windows and Mac, and prior to 152.0.7977.82 for Linux. The vulnerabilities could enable remote code execution, disclosure of sensitive information, security bypass and denial-of-service ("DoS") attacks. CERT-In has noted that one of the vulnerabilities (CVE-2026-85046) is being actively exploited in the wild and has advised users to update Google Chrome to the latest available version immediately.

 

3.4.      CERT-In issues high-severity advisory on multiple vulnerabilities in Microsoft products

CERT-In has issued a high-severity advisory regarding multiple vulnerabilities affecting various Microsoft products, including Microsoft Windows, Microsoft Office, Microsoft Dynamics, SQL Server, Azure applications, developer tools and server software. The vulnerabilities could enable attackers to execute arbitrary code remotely, elevate privileges, disclose sensitive information, bypass security controls, tamper with systems or cause DoS conditions. CERT-In has specifically highlighted privilege escalation vulnerabilities, including CVE-2026-81963 and CVE-2026-85880, which are reportedly being actively exploited in the wild. Users and organisations have been advised to apply the latest security updates released by Microsoft without delay.

 

3.5.          CERT-In issues high-severity advisory on multiple vulnerabilities in SAP products

CERT-In has issued a high-severity advisory concerning multiple vulnerabilities across several SAP products, including SAP NetWeaver, SAP Integration Suite, SAP S/4HANA, SAP Commerce Cloud and SAP Manufacturing Integration and Intelligence. The vulnerabilities arise from issues such as memory corruption, improper access controls, information disclosure, XML External Entity (XXE) flaws, security misconfigurations and missing authorisation checks. Successful exploitation could allow attackers to execute arbitrary code, elevate privileges, access sensitive information, bypass security restrictions, cause DoS conditions, manipulate application data and perform Server-Side Request Forgery (SSRF) attacks. CERT-In has advised users to promptly implement the security fixes recommended by SAP.

 

3.6.          Government amends E-Commerce Rules to enhance consumer protection and platform transparency

The Ministry of Consumer Affairs, Food and Public Distribution has notified the Consumer Protection (E-Commerce) (Amendment) Rules, 2026, introducing enhanced transparency, disclosure and consumer protection requirements for e-commerce entities and marketplace platforms, effective from 1 January 2027. E-commerce entities will be required to prominently disclose key business and grievance redressal details, acknowledge consumer complaints within 48 hours and resolve them within one month. Platforms must clearly identify sponsored listings, disclose the “prior price” (lowest price in the preceding 30 days) when announcing discounts, prominently display seller details on invoices, and undertake annual self-audits to ensure compliance with the Guidelines for Prevention and Regulation of Dark Patterns, 2023. The amendments also prohibit manipulation of search rankings, restrict the use of consumer data without explicit consent, mandate disclosure of country of origin and seller identification details, and require marketplace entities to explain key parameters influencing product and seller rankings.

 

4.           Taxation (Indirect & Direct)


4.1.        CBDT notifies SFT reporting framework for Depository Transactions

The Central Board of Direct Taxes ("CBDT") has issued a notification prescribing the format, procedure and reporting guidelines for furnishing Statement of Financial Transactions (SFT-2517) relating to depository transactions under the Income-tax Act, 2025. Depositories will be required to report information relating to capital gains arising from transfers of listed securities and mutual fund units on a half-yearly basis for pre-filling of income-tax returns. The framework prescribes detailed data formats, valuation methodologies, First-In-First-Out (FIFO) based asset identification, classification of short-term and long-term capital assets, reporting of off-market transactions and correction mechanisms for defective filings. The first-half and second-half SFTs are required to be furnished by 31 October and 30 April respectively.

 

4.2.        CBDT prescribes SFT reporting norms for Mutual Fund Transactions

CBDT has notified the format, procedure and guidelines for filing Statement of Financial Transactions (SFT-2518) relating to mutual fund transactions by Registrars and Share Transfer Agents (RTAs). The framework requires reporting of capital gains-related information from mutual fund unit transfers and redemptions for pre-filling taxpayers’ income-tax returns. The notification sets out asset classification rules, valuation methodologies, FIFO-based computation of holding periods and cost of acquisition, reporting of off-market transfers, and submission of correction statements where inaccuracies are identified. RTAs must furnish the information on a half-yearly basis, with reporting deadlines of 31 October and 30 April for the respective reporting periods.

 

5.               Regulatory Enforcement (SEBI)

 

Authority

Name of the Entity

Amount

Contravention

SEBI

PMC Projects (India) Private Limited

 

INR 13,65,000 (Indian Rupees Thirteen Lakh Sixty-Five Thousand only)

 

 

Alleged violation of Regulation 17(8) read with Paragraph B of Part B of Schedule II of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 (LODR Regulations) read with Section 21 of the Securities Contracts (Regulation) Act, 1956 (SCRA), in relation to banking transactions and inter-corporate security deposits involving PMC Projects (India) Private Limited, Adani Ports and Special Economic Zone Limited (APSEZL) and its subsidiaries. The matter was settled without admission or denial of the findings.

 

SEBI

Emami Realty Limited

 

INR 2,00,000 (Indian Rupees Two Lakh only)

 

 Violation of Regulation 23(2) and Regulations 4(1)(a), (b), (c), (d), (e), (g), (h), (i), (j), 4(2)(e)(i), 33(1)(c), 34(3) read with Clause B(2) of Schedule V and Regulation 48 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 ("LODR Regulations"). The company failed to obtain prior Audit Committee approval for a related party transaction with Lohitka Property LLP and incorrectly classified investments in subsidiaries and convertible debentures as inventories instead of investments in its standalone financial statements for FY 2021-22 and FY 2022-23.

 

SEBI

Investowryght Research Analytics Private Limited

 

INR 10,00,000 (Indian Rupees Ten Lakh only)

 

Multiple violations of the SEBI (Research Analysts) Regulations, 2014 ("RA Regulations") and SEBI (Prohibition of Fraudulent and Unfair Trade Practices relating to Securities Market) Regulations, 2003 ("PFUTP Regulations"), including providing assurances of returns and recovery of losses, inducing clients to trade, failure to maintain Know Your Client ("KYC") records in the prescribed format, charging fees beyond the permitted limit of INR 151,000 (Indian Rupees One Lakh Fifty-One Thousand only) per annum, failure to publish complaint redressal data within prescribed timelines, and failure to submit periodic reports to the Research Analyst Administration and Supervisory Body ("RAASB"). SEBI imposed a penalty of INR 500,000 (Indian Rupees Five Lakh only) under Section 15HA and INR 500,000 (Indian Rupees Five Lakh only) under Section 15EB of the SEBI Act, 1992.

 

 

Disclaimer


The note is prepared for knowledge dissemination and does not constitute legal, financial or commercial advice. AK & Partners or its associates are not responsible for any action taken based on its contents.


For further queries or details, you may contact:


Mr Anuroop Omkar

Founding Partner, AK & Partners


Comments


Subscribe to our newsletter 
AK and Partners Logo

27A, Ground Floor & Upper Ground Floor,

HKV, New Delhi - 110016

Office: +91 11 41727676

info@akandpartners.in

  • LinkedIn
  • Facebook

Thanks for submitting!

© 2025 I AK & Partners

bottom of page