How SEBI’s New Fraud Detection Mandate Changes Broker Compliance

How SEBI’s New Fraud Detection Mandate Changes Broker Compliance

Table of Contents

    Somewhere between January and April 2026, a requirement that had been rolling out in stages since mid-2024 quietly crossed its finish line. The smallest stock brokers in India — firms with up to 2,000 active client codes became legally bound on 1 April 2026 to run a working fraud-detection system of their own. What began as a SEBI circular has since been folded into the SEBI (Stock Brokers) Regulations, 2026 notified on 7 January 2026 — as a standalone statutory obligation: Regulation 21. In plain terms, every registered stock broker in India, regardless of size, must now keep an active institutional mechanism in place to catch fraud before it reaches investors.

    That single word “required” is what has really changed. Fraud detection has moved from an operational best practice that well-run firms adopted on their own to a codified condition of holding a broking licence in India at all.

    What Regulation 21 Actually Requires

    Regulation 21 places a direct duty on every stockbroker to build and run a working system that prevents, detects, and reports fraud or market abuse. What lifts this above a paperwork exercise is the breadth of who it covers. The obligation doesn’t stop at the broker’s own payroll — it extends to conduct by clients, directors, senior management, key managerial personnel, and “authorised persons,” a category that takes in sub-brokers and algorithmic trading providers operating under the broker’s own registration.

    Regulation 23(2) then closes an obvious escape route. Responsibility for keeping this mechanism running cannot be quietly pushed down to a compliance executive several levels below the top floor. The rule fixes accountability on the designated director and senior management by name. If the system misses something it should have caught, that failure now has clearly identified owners at the top of the firm.

    From Circular Guidance to Codified Law

    To see why this counts as a genuine shift rather than a rebranding exercise, it helps to trace where the obligation came from. SEBI first introduced the idea through a circular dated 4 July 2024 (Circular No. SEBI/HO/MIRSD/MIRSD-PoD-1/P/CIR/2024/96), directing brokers to build systems for trading surveillance, internal controls, escalation and reporting, and a formal whistleblower policy. Because a national brokerage and a small regional one don’t operate at the same scale, SEBI staggered the rollout by client base. Qualified Stock Brokers had to comply first, by 1 August 2024. Brokers with more than 50,000 active unique client codes followed on 1 January 2025, those in the 2,001 to 50,000 band on 1 April 2025, and the smallest firms — up to 2,000 active client codes — on 1 April 2026.

    That phased, circular-led approach made sense as a transition tool. But a circular is operational guidance issued under an existing regulation — it does not carry the same standing as the regulation itself. By writing the same obligation directly into Chapter IV of the 2026 Regulations as Regulation 21, SEBI has given fraud detection the weight of primary subordinate legislation rather than an add-on instruction sitting in a compliance officer’s inbox.

    Chapter IV is an entirely new addition to the rulebook, not a renamed version of something that existed in 1992, which tells you SEBI intended fraud prevention to stand as its own institutional pillar rather than a clause buried inside general conduct rules. For a firm being inspected, a gap against a named regulation is a materially different conversation from a gap against circular guidance. The requirement hasn’t merely continued into 2026 — it has been hardened.

    What the Institutional Mechanism Has to Include

    Read the regulation alongside the circular that preceded it, and the “institutional mechanism” SEBI expects is clearly not a single tool or a policy sitting unread in a shared drive. It is an operating system with several connected parts, and brokers need to be able to demonstrate each one on request.

    The detection side comes first. Firms are expected to run surveillance systems capable of flagging unusual trading patterns — price manipulation, front-running, wash trades, pump-and-dump activity — as they happen, not weeks later during an audit. Sitting alongside that are internal controls covering the conduct of employees and authorised persons, including the sub-brokers and algo-trading partners who trade under the firm’s own registration. Together these two elements decide whether suspicious activity is caught at all.

    The response side matters just as much. A written escalation and reporting process has to route flagged activity to the right internal committee and, where warranted, on to the stock exchange and SEBI without unnecessary delay. A whistleblower policy has to give employees and insiders a genuinely confidential channel, so anyone who spots wrongdoing has a safe, formal route to report it. Half-yearly reporting to the exchanges then documents flagged incidents and the remedial action taken, building an ongoing trail of vigilance rather than a one-time compliance certificate. And underneath all of it sits the accountability that Regulation 23(2) demands — named, senior-level ownership, so the mechanism has an accountable owner instead of being everyone’s job and, in practice, no one’s.

    A Wider Net: Mule Accounts, Clearing Members, and Authorised Persons

    Two further pieces of the same reform deserve attention, because they quietly widen what “fraud or market abuse” actually covers.

    Mule Accounts Now Named in the Rulebook

    The regulations updated the definition of market abuse to explicitly name trading conducted through mule accounts — demat and trading accounts opened in one person’s name but controlled and used by someone else, typically to disguise the source of manipulated trades or to launder illicit gains. Mule accounts have become one of the more persistent fraud patterns in Indian markets precisely because they are hard to trace back to a real beneficial owner. Naming them directly in the regulation gives a broker’s surveillance team a specific, defined pattern to watch for, rather than a vague instruction to monitor for fraud in the abstract.

    Clearing Members Brought Into the Same Perimeter

    The 2026 framework also closes an old regulatory gap between brokers and clearing members. Under Regulation 3(4), the same governance and fraud-prevention chapters that bind brokers now apply, with necessary modification, to clearing members too. Combined with Regulation 21’s coverage of authorised persons, the practical effect is that a broker’s fraud-detection perimeter now reaches well beyond its own employees — into its sub-broker network, its algo partners, and the clearing function sitting behind its trades.

    What Brokers Should Be Doing Right Now

    For any firm that has not yet treated this as a settled, closed business, a handful of checks are worth prioritising, and most of them are about proving the mechanism works rather than proving it exists on paper.

    Start by confirming, in writing, that your surveillance systems and internal controls are actually running day to day and not simply documented in a policy no one has stress-tested. From there, map every authorised person, sub-broker, and algo-trading partner connected to your registration, and satisfy yourself that each one sits inside your monitoring perimeter rather than quietly outside it. Check, too, that your whistleblower channel is genuinely confidential and that staff actually know it exists — a policy nobody has heard of protects no one. Half-yearly reporting to your exchange should be scheduled and owned by a named person, not left to whoever remembers as the deadline approaches.

    It is also worth reviewing your firm’s social media presence against SEBI’s separate circular dated 26 February 2026, which requires every registered intermediary to display its registered name and SEBI registration number on social platforms and at the start of securities-related content, effective from 1 May 2026. That obligation runs in parallel with Regulation 21, and it is easy to overlook because it lives outside the fraud-detection chapter.

    Where Internal Compliance Runs Out of Road

    Here is the part that even well-prepared brokers can overlook. Regulation 21 asks a firm to police fraud happening under its own roof — but it has no reach over fraud happening under its name outside that roof. A cloned website harvesting client credentials, a fake trading app sitting in an app store, or an unregistered “advisor” running a guaranteed-returns scheme while dropping a real brokerage’s name to sound credible — none of that shows up on an internal surveillance dashboard. Yet all of it can mislead the same investors SEBI is trying to protect, and all of it lands on the real firm’s reputation regardless of whose fault it actually is.

    That gap is why the internal fraud-detection mandate pairs so naturally with an external identification one. The same period that hardened Regulation 21 into law also produced the February 2026 social media disclosure circular, and both push in the same direction: they ask regulated entities to make their genuine, compliant identity easier to verify online. A broker that has done all the internal work but has no visibility into how it is being impersonated, discussed, or misrepresented in search results and on social platforms is still exposed — just in a place its own compliance team was never built to watch.

    This is the layer that search perception management is meant to cover, and it is where a service like AiPlex ORM’s Search Perception Management sits alongside the internal mechanism rather than replacing it — monitoring how a brokerage appears across search engines, surfacing impersonators and fraudulent look-alikes early, and helping ensure that what investors find when they search for a firm is the genuine, compliant business behind the name rather than an imitation of it. If Regulation 21 is about proving you are watching internally, keeping an eye on your external footprint is how you show the same discipline where the regulation’s own reach ends. You can see how that approach works at Aiplexorm.

    The Takeaway

    Regulation 21 has turned fraud detection from a best practice into a standing legal duty, backed by named accountability, a wider definition of abuse, and a compliance perimeter that now reaches sub-brokers and algo partners as well as employees. For brokers, the honest response is not a one-time audit before an inspection — it is treating surveillance, escalation, and reporting as permanent, living parts of how the firm runs.

    But the internal mechanism is only half the job. The other half is making sure your firm’s search results, social profiles, and app store listings actually reflect who you are, and are not quietly being hijacked by the same fraud SEBI is asking you to fight. If the regulation is about proving you are watching from the inside, protecting your identity in search and on social platforms is how you prove it from the outside too.

    This article is intended for general information and does not constitute legal, regulatory, or compliance advice. Brokers and intermediaries should refer to the original SEBI regulations and circulars and consult a qualified professional for guidance specific to their firm.

    Share this Article
    FacebookTwitterLinkedIn

    OUR RECENT POSTS

    SEBI Stock Brokers Regulations 2026 Explained

    SEBI Stock Brokers Regulations 2026 Explained

    For more than thirty years, the way stock brokers were registered, governed, and held accountable in India rested on a single rulebook drafted in a very different market. That era has now ended. On 7 January 2026, the Securities and Exchange Board of India notified a completely new framework, and if you run, work at,

    AI Admin

    |

    10/09/2026

    |

    1 min read

    Legal Guide to Court-Ordered Removal of Defamatory Content

    Legal Guide to Court-Ordered Removal of Defamatory Content

    Securing a court order to remove defamatory content online is often the only step that forces a platform to act. Grievance forms get ignored. Anonymous accounts keep posting. A judicial order changes that, because it converts a request into a binding obligation. This guide explains how the process works in India, what evidence you need,

    AI Admin

    |

    24/08/2026

    |

    1 min read

    SERP Reputation Repair: How to Manage Negative Search Results

    SERP Reputation Repair: How to Manage Negative Search Results

    Type your own name or your company name into Google. Whatever appears in those first ten results is, for most people, the truth about you. It does not matter what your website says, how good your product is, or how many happy customers you have served quietly over the years. If a complaint page, a

    AI Admin

    |

    22/08/2026

    |

    1 min read

    Top Reputation Management Tools for Tracking Brand Mentions

    Top Reputation Management Tools for Tracking Brand Mentions

    Every day, somewhere on the internet, someone is talking about your brand. It might be a satisfied customer leaving a five star review, a frustrated buyer venting on Reddit, a journalist referencing your company in an industry roundup, or a competitor’s fan questioning your pricing in a niche forum. None of these people will send

    AI Admin

    |

    21/08/2026

    |

    1 min read

    Crisis Communication Management Service | AiPlex ORM

    Crisis Communication Management Service | AiPlex ORM

    A single screenshot can travel further than a decade of careful work. One angry review, one leaked email, one video clip taken out of context, and a brand that spent years earning trust suddenly finds itself defending its own name in public. This is the reality of operating in an always connected market where opinions

    AI Admin

    |

    20/08/2026

    |

    1 min read

    ORM Logo
    Get Started

    GET STARTED TODAY...

    Speak to a strategist today and see why brands rate AiPlex among the best online reputation management company options for India and global markets.