Corporate & Compliance Digest September 21, 2026
We are delighted to share this week's AKP Corporate & Compliance Weekly Digest. Please feel free to write to us with your feedback at info@akandpartners.in.
1. Labour Law & Employment Law
1.1. Cabinet approves increase in EPFO wage ceiling to expand social security coverage
The Union Cabinet has approved an increase in the wage ceiling for mandatory coverage under the Employees’ Provident Fund Organisation (EPFO) from INR 15,000 (Indian Rupees Fifteen Thousand only) to INR 25,000 (Indian Rupees Twenty-Five Thousand only) per month, effective from 17 September 2026. The enhancement is expected to bring a larger number of employees within the ambit of mandatory social security coverage, extending access to benefits under the Employees’ Provident Fund (EPF), Employees’ Pension Scheme (EPS) and Employees’ Deposit Linked Insurance Scheme (EDLI). The Ministry of Labour and Employment stated that the revision will strengthen retirement savings, pension and insurance protection, promote formalisation of employment and support workforce stability. The estimated annual Government expenditure on account of the enhancement is approximately INR 11,339 crore (Indian Rupees Eleven Thousand Three Hundred Thirty-Nine Crore only), with a projected outlay of INR 56,696 crore (Indian Rupees Fifty-Six Thousand Six Hundred Ninety-Six Crore only) over five years.
2. Securities & Capital Markets
2.1. CDSL introduces OTP-Based authentication for critical physical BO Modification Requests
Central Depository Services (India) Limited ("CDSL") has introduced an OTP-based authentication mechanism for specified critical physical Beneficial Owner (BO) modification requests, including changes to e-mail ID, mobile number, bank details, signature, Power of Attorney, nomination details, mode of operation and address. Under the revised process, once a Depository Participant ("DP") completes the maker-checker process, CDSL will send an OTP authentication link to the registered mobile number and e-mail ID of the first holder. The link will remain valid for seven calendar days, while the OTP generated through the link will remain valid for 15 minutes. Modification requests will be processed only upon successful OTP authentication, failing which they will be automatically cancelled after expiry of the validity period. The functionality is scheduled to be deployed by 1 October 2026, and DPs have been advised to make the necessary back-office system changes to comply with the revised process.
2.2. CDSL issues update on Simplified and Standardised Transmission Framework
CDSL has reiterated to DPs the implementation of the simplified and standardised framework for transmission of securities, pursuant to its earlier communiqué dated 25 August 2026 issued under the ease of doing investment and ease of doing business initiative. CDSL has informed DPs that the necessary amendments to the DP Operating Instructions in relation to the revised transmission framework will be communicated separately. DPs have been advised to take note of the forthcoming changes and ensure readiness for compliance with the updated operational requirements.
2.3. CDSL enhances online facility for submission of Net Worth Certificates and Audited Financial Statements
CDSL has enhanced its online audit portal for the submission of Net Worth Certificates and Audited Financial Statements ("AFS") by DPs. DPs are required to submit the Net Worth Certificate, together with the AFS and auditor’s report for the financial year ended 31 March 2026, on or before 31 October 2026 through the Audit Web Application. The enhanced facility introduces additional validation fields, mandatory disclosure requirements, automated variance tracking for net worth and profit and loss figures, and a structured online mechanism for submission of clarifications and supporting documents sought by CDSL during the verification process. CDSL has clarified that incorrect or incomplete submissions will be treated as non-submission and will attract penalties in accordance with the applicable Operating Instructions.
2.4. BSE explores launch of MSCI-Linked Derivatives in India
Bombay Stock Exchange (“BSE”) has entered into an agreement with MSCI to explore the launch of futures and options contracts in India linked to selected MSCI indices, subject to regulatory approvals. The initiative is aimed at expanding investment and hedging opportunities for market participants and enhancing accessibility to the Indian capital market. BSE noted that the growing volume of capital benchmarked to indices and increased adoption of Exchange Traded Funds ("ETFs") have driven demand for index-based derivatives to facilitate fund flows and manage market exposure. MSCI indices are among the world’s most widely tracked benchmarks, with over USD 21 trillion in assets under management linked to them as of 31 December 2025.
2.5. BSE Clearing introduces Shorter-Tenor SLB Contracts
BSE Clearing Limited (BSECL) has introduced three-working-day contracts in the Securities Lending and Borrowing (SLB) segment with effect from 17 August 2026. The new contracts feature a T+1 first leg and T+3 reverse leg and will initially be available for eligible securities in the Futures and Options (F&O) segment under the “D” series. The initiative, introduced under the Securities and Exchange Board of India (SEBI) SLB framework, is intended to provide greater flexibility for short-term securities borrowing and delivery requirements, facilitate inter-exchange arbitrage and improve price alignment across trading venues. BSECL has clarified that the contracts will operate through the existing automated order-matching mechanism and will not permit foreclosure, repay, recall or rollover facilities.
2.6. NSE launches India’s first Tokenised Corporate Bond issuances through EBP Platform
The National Stock Exchange of India Limited ("NSE") has successfully implemented tokenisation technology for corporate bonds on its Electronic Bidding Platform (EBP) under the Securities and Exchange Board of India (“SEBI”) Regulatory Sandbox Framework. The platform facilitated India’s first tokenised bond issuances by REC Limited and Larsen & Toubro Limited, raising a cumulative INR 1,000 crore (Indian Rupees One Thousand Crore only). REC Limited raised INR 500 crore (Indian Rupees Five Hundred Crore only) at a coupon rate of 7.30 percent (seven point three zero per cent), while Larsen & Toubro Limited raised an additional INR 500 crore (Indian Rupees Five Hundred Crore only). Tokenisation, enabled through Distributed Ledger Technology (DLT), is designed to facilitate atomic settlement, enhance transparency and improve operational efficiency across the securities lifecycle. The initiative marks a significant milestone in the development of digital bond market infrastructure in India and supports broader adoption of tokenised securities in regulated capital markets.
2.7. NSE advises Trading Members to comply with TRAI Directions on Customer Communications
NSE, pursuant to a communication received from the SEBI, has advised Trading Members to ensure compliance with directions and guidelines issued by the Telecom Regulatory Authority of India ("TRAI"). Trading Members have been directed to integrate with the Department of Telecommunications’ (DoT) Mobile Number Revocation List (MNRL), incorporate MNRL checks into customer authentication and communication processes, use the 1600 series exclusively for service and transactional calls, and comply with TRAI requirements on pre-tagging variable fields in SMS content templates. NSE has also advised members to undertake consumer awareness initiatives regarding the 1600 and 140 numbering series to enhance customer recognition and trust while ensuring uninterrupted delivery of legitimate communications.
3. Information Technology & Data Protection
3.1. CERT-In issues critical advisory on multiple vulnerabilities in Cisco Secure Firewall Products
The Indian Computer Emergency Response Team ("CERT-In") has issued Vulnerability Note CIVN-2026-0464 highlighting multiple critical vulnerabilities in Cisco Secure Firewall products, including Adaptive Security Appliance ("ASA"), Threat Defense ("FTD") and Firewall Management Center ("FMC") software. CERT-In has warned that the vulnerabilities could enable remote attackers to execute arbitrary commands, gain elevated privileges, bypass authentication and session controls, access sensitive information and cause denial-of-service ("DoS") conditions. Notably, two of the vulnerabilities are reportedly being actively exploited in the wild. Organisations using affected Cisco products have been advised to immediately apply vendor-recommended security updates and mitigations.
3.2. CERT-In issues critical advisory on Remote Code Execution Vulnerability in Check Point Security Management
CERT-In has issued Vulnerability Note CIVN-2026-0465 regarding a critical remote code execution vulnerability affecting Check Point Security Management and Log Server products. The vulnerability could allow a remote attacker to execute arbitrary code and elevate privileges on targeted systems by exploiting weaknesses in the login process. CERT-In has advised organisations using affected versions of Check Point Security Management Server and Multi-Domain Security Management Server to urgently implement the vendor’s security updates and remediation measures.
3.3. CERT-In issues high-severity advisory on Acronis Backup Plugin Vulnerability
CERT-In has issued Vulnerability Note CIVN-2026-0466 highlighting a high-severity privilege escalation vulnerability in Acronis Backup plugins for cPanel, Web Host Manager ("WHM") and Plesk environments. The vulnerability could enable an attacker with access to the affected system to gain elevated privileges and perform unauthorised actions, including potential execution of arbitrary code. CERT-In has advised system administrators to upgrade to the latest vendor-supported versions and apply the recommended security patches without delay.
3.4. Copyright Office rejects AI Authorship Claim in landmark DABUS Copyright Application
The Registrar of Copyrights, India, has rejected an application seeking copyright registration for the artistic work “A Recent Entrance to Paradise”, where the artificial intelligence system Device for the Autonomous Bootstrapping of Unified Sentience ("DABUS") was named as the author. While the Copyright Office held that the work satisfied the originality requirement under Section 13 of the Copyright Act, 1957, it concluded that DABUS is neither a natural nor a juristic person and therefore cannot be recognised as an author under Section 2(d)(vi) of the Act. The Registrar further held that, based on the applicant’s own submissions, Dr. Stephen L. Thaler was the person who caused the work to be created and could potentially qualify as the statutory author. However, since the applicant persisted in identifying DABUS as the author and declined to amend the application, the copyright registration request was rejected. The order clarifies that any recognition of artificial intelligence systems as authors would require legislative intervention and cannot be achieved through administrative interpretation of the existing law.
3.5. Principal Scientific Adviser’s Office releases Discussion Paper on Cross-Border Data Interoperability for AI Systems
The Office of the Principal Scientific Adviser to the Government of India has released a discussion paper titled “Enabling Cross-Border Data Interoperability for AI Systems”, proposing a risk-based framework to facilitate secure and trusted international data flows for Artificial Intelligence (AI) development while preserving data sovereignty. The paper advocates a balanced approach between strict data localisation and unrestricted data transfers through mechanisms such as controlled access, trusted data corridors, federated processing and interoperability frameworks. It proposes a three-pillar model comprising compatibility, accountability and coordination, supported by a risk-based classification system for AI-related data. The paper also examines global approaches adopted by India, the European Union (EU), the United States (US), China, the Association of Southeast Asian Nations (ASEAN), the African Union (AU) and the Asia-Pacific Economic Cooperation (APEC), and recommends the development of common technical standards, certification mechanisms, interoperable agreements and institutional coordination frameworks to support responsible cross-border AI data exchange.
3.6. TRAI strengthens UCC Framework through AI-Driven enforcement and enhanced consumer protection measures
The Telecom Regulatory Authority of India ("TRAI") has notified the Telecom Commercial Communication Customer Preference (Third Amendment) Regulations, 2026, introducing a strengthened framework to curb Unsolicited Commercial Communications ("UCC"). Key measures include mandatory use of Artificial Intelligence and Machine Learning (AI/ML) systems by Telecom Service Providers (TSPs) to identify suspected spam senders, stricter enforcement where multiple customer complaints are corroborated by AI-based detection, regulation of Application-to-Person (A2P) calls through mandatory pre-declaration requirements, and a new consumer appeal mechanism for UCC complaints. The amendments also expand the scope of valid consent to include verifiable legacy consents, strengthen safeguards against misuse of headers and content templates, introduce stricter accountability for senders and telemarketers, prohibit blanket spam-tagging of regulated communication series such as 140xx, 1600xx and 1601xx, and enable TRAI to prescribe mandatory contractual conditions between access providers and telemarketers. The revised framework is aimed at enhancing consumer protection, improving spam detection and strengthening accountability across the commercial communications ecosystem.
4. Taxation (Indirect & Direct)
4.1. CBDT notifies fourth amendment to Income-tax Rules, 2026
The Central Board of Direct Taxes ("CBDT") has notified the Income-tax (Fourth Amendment) Rules, 2026, introducing procedural and compliance-related amendments under the Income-tax Act, 2025. Key changes include extending the deadline for applications for registration as a valuer and authorised income-tax practitioner from 30 September 2026 to 31 March 2027, revising electronic communication provisions, and replacing Form No. 169 and Form No. 171 with updated application formats for registration of valuers and authorised income-tax practitioners, respectively. The amended forms introduce enhanced disclosure requirements, standardised personal information fields, eligibility declarations and digital filing features. Certain amendments have been made effective retrospectively from 1 April 2026, while others take effect from the date of publication of the notification.
5. Regulatory Enforcement (SEBI)
Authority | Name of the Entity | Amount | Contravention |
SEBI | Mirae Asset Venture Opportunity Trust, Mirae Asset Venture Investments (India) Private Limited
| INR 1,275,000 (Indian Rupees Twelve Lakh Seventy-Five Thousand only)
| Violation of Regulation 15(1)(c) of the SEBI (Alternative Investment Funds) Regulations, 2012 (AIF Regulations), by investing INR 128.18 crore (Indian Rupees One Hundred Twenty-Eight Crore Eighteen Lakh only) in a single investee company, Supermarket Grocery Supplies Private Limited, resulting in exposure of 38.35 per cent (thirty-eight point three five per cent) of the scheme’s investable funds against the prescribed limit of 25 per cent (twenty-five per cent). The matter was settled under SEBI’s summary settlement mechanism without admission or denial of the findings.
|
Disclaimer
The note is prepared for knowledge dissemination and does not constitute legal, financial or commercial advice. AK & Partners or its associates are not responsible for any action taken based on its contents.
For further queries or details, you may contact:
Mr Anuroop Omkar
Founding Partner, AK & Partners





Comments