General
7 min read

Operational Compliance Checklist: Client Records and System Integrity for Stock Brokers

Though the fundamental regulatory statute governing stockbrokers is the SCRA and SEBI, the day-to-day reality of compliance involves strict adherence to extensive operational processes.

Operational Compliance Checklist: Client Records and System Integrity for Stock Brokers

Foreword

Though the fundamental regulatory statute governing stockbrokers is the SCRA and SEBI, the day-to-day reality of compliance involves strict adherence to extensive operational processes. This Compliance Audit Checklist is not merely a legislative report; these processes are about the effective working of the brokerage covering the entire scope of operations from client registration to trading terminal security. A broker must have internal processes that can stand up to scrutiny in three core areas of risk: i) Client Documentation, ii) Transaction Control, and iii) Systems Integrity, in order to maintain the broker's license and earn client trust. This paper applies the complex law in compliance checklist format to implementable compliance objectives for brokers' management and auditors.


Operational Compliance Checklist: Client Records and System Integrity for Stock Brokers

The checklist below summarizes the areas that were assessed during a compliance audit, which ensures a stock broker is in compliance with SEBI and the Stock Exchanges.

1. Books of Account and Financial Integrity

The first step in any audit is verifying whether all records are being properly retained, both at the head office and at all of its extended operational locations.

  • Legally Required Records: Verifying that all mandatory Books of Account required by the SCRA and SEBI are being properly maintained, including specialized Books of Account, such as the Securities Register, Margin Deposit Book, and Grievance Register.

  • Record Retention Disciplines: Verifying that separate, proper Books of Account are maintained for each branch, sub-broker, and by exchange segments, where applicable.

  • Financial Review: A thorough review of financial reports/statements must be made to verify accuracy and compliance with regulatory requirements.

2. Client Registration and Documentation Control

Compliance in this area aims for legal viability of client relationships, proper disclosure of risks and meeting regulatory requirements for due diligence (KYC/AML).

Registration and Disclosure

  • Mandatory Documents: Verification that the account opening kit includes only the mandatory sections: Client Registration Form, Rights and Obligations document, Risk Disclosure Document (RDD), Policies and Procedure, Do’s and Don’ts Guidance Note, Tariff Sheet.

  • Required Proofs: Obtaining and verification of all mandatory client proofs (ID, Address, PAN, Bank, Demat Proofs), both Individual Clients and Non-Individual Clients (with updated shareholding patterns in corporates).

  • Client Consent: Authorization sought in the non-mandatory documents should not be bundled and if authorizations are sought must have separate instruction and combined with appropriate client consent.

  • Legibility and Indexing: All documents should be determined legible (minimum font size 11), indexed and included in a clearly segmented docket (Mandatory and non-mandatory parts).

KYC, AML, and Monitoring

  • In-Person Verification (IPV): Verification that the IPV has been carried out by either the employee of the broker, sub-broker or person authorized by the broker.

  • Data Uploads: Verification that the client KYC data is being uploaded consistently and timely to the SEBI-registered KRAs and CKYCR.

  • Beneficial Ownership: Verification that the broker has appropriately verified the identity of the beneficial owners in line with SEBI AML/KYC expectations.

  • Monitoring Trades: Monitoring trades made by clients against financial information provided by the client; especially in relation to the equity derivatives segment.

Running Account and Third-Party Risk

  • Running Account Authorization: The authorization must unambiguously permit the client to terminate authority at any time, and it can only be signed by the client (not a Power of Attorney).

  • UCC and Communication: Ensuring the UCC is properly assigned, registered, and mapped against the client's PAN/Passport. The email ID and mobile number must be current in the UCC and match what is listed in the broker’s back-office.

  • Tripartite Agreements: Validation that the broker has not signed any tripartite agreement with the clients/participants and any third party/group company to circumvent direct control over client funds or client securities.

3. Transaction Control: Contract Notes and Sub-Brokers

This section checks that the execution of trades and communication of the details of trades are done in compliance with regulatory obligations to ensure transparency and control.

Contract Note Integrity

  • Issuance and Format - Contract notes should be issued within 24 hours of the execution of the trade, have a unique running serial number which must reset each year and where necessary, be in the Common Contract Note format prescribed by the Exchange (i.e. NSE/BSE Circulars).

  • ECN (Electronic Contract Notes) - Digital contract notes should have an associated digital signature, be encrypted, and non-tamperable (IT Act, 2000 compliant) and all ECN’s sent must have a log maintained.

  • Display Requirements - Contract Notes must display the broker's name (as registered with SEBI), registration number, full address and details of the Compliance Officer.

  • Brokerage Limits - Check that the brokerages charged are within limits, particularly for option contracts where the fee does not exceed 2.5% of the premium amount or $1.05 per lot (whichever is higher).

Sub-Broker and Branch Oversight

  • Registration Verification: Confirming that the broker only maintains relationships with registered sub-brokers, authorized persons, and remisiers.

  • Brokerage Sharing: Thorough verification that there is no sharing of brokerage with another trading member, an employee of another broker, or with anyone suspended/denied access.

  • Monitoring and Surveillance: Performing regular inspections and monitoring of sub-brokers and branch offices while also maintaining a system to monitor sudden fluctuations in customer turnover through specific branches.

4. Terminal Operations and System Audits

The Final check considers the technology foundation, ensuring that the trading systems are secure, accessed by individuals authorized to use the systems, and that audits of the systems are conducted on a regular basis.

  •  User Certification: Confirmation that all approved users and all person personnel representing the seller have current and valid NISM certifications (e.g., Series IV, VII, III-A for Compliance Officers).

  •  System Integrity: Confirmation that only current software versions are used and that appropriate systems to secure the data and backed up in the manner appropriate.

  •  System Audits: Confirmation that all required System Audits (Half-Yearly/Yearly) have been conducted for CTCL, IBT, and IML facilities and their reports issued to the Exchanges (NSE/BSE) where required.

  •  Risk Controls: There are checks in place related to value and/or quantity that are appropriate given the client risk profile and a limit in place to limit the cumulative value of all unexecuted orders which are not above a certain level.


Final Point

This checklist of operations is an authentic indicator of a brokerage's commitment to the Indian regulatory environment. The important takeaway for management is that compliance is a function of process and not documentation. From the pre-account opening verification of a client's PAN to ensuring each ECN is digitally signed and tamper-proof, the process of achieving compliance with these micro-level requirements is what protects the firm from regulatory action. Commitment to this operational structure creates the foundation for a respected and viable brokerage business.