PASS Securities Operations and Risk Management Examination Difficulty: Beginner 2 Questions   5 min read
📌 Chapter 2.5 — REGULATORS

Picture a scenario where a high-net-worth client approaches your firm to open a trading and demat account, providing a set of identity documents in the morning. Your back-office team processes these documents, and by the end of the day, the data is uploaded to a KYC Registration Agency (KRA) portal. This process is not merely a box-ticking exercise for your firm; it is the vital point where your client’s identity is centralized and verified within the Indian securities ecosystem.

By utilizing a KRA, you ensure that the client’s KYC status is standardized and accessible across different intermediaries, preventing the need for the investor to repeat the document submission process every time they sign up with a new broker or depository participant.

KRAs act as the primary repository for KYC data, serving as the connective tissue between intermediaries and regulatory authorities like SEBI. When you perform an ‘in-person verification’ or validate an e-KYC pull via Aadhaar, you are effectively initializing a record that the KRA must then validate. If the KRA flags a discrepancy—perhaps a mismatch in the address proof or an expired document—your firm receives a notice that the record is ‘on hold’.

In a practical sense, this means your trading system must immediately restrict the client’s ability to place orders, as they are effectively locked out of the market until the records are synchronized and rectified.

For a professional in securities operations, understanding the KRA process is essential for effective risk management. If you fail to ensure that your client’s information is uploaded and successfully registered with the KRA, you are essentially operating with a ‘blind spot’ in your risk architecture. This creates a significant vulnerability during audit trails or when the Financial Intelligence Unit requests data regarding suspicious transactions. If you ignore a ‘rejected’ status from a KRA and continue to facilitate trades, you are inviting direct regulatory scrutiny and penalties for violating PMLA guidelines.

Think of the KRA as the ‘single source of truth’ for investor identity. Whether you are handling settlement issues, reconciling client codes, or responding to an exchange audit, the KRA status provides the foundation for the client’s legal existence in the market. By ensuring your internal systems are perfectly synced with the KRA, you provide the security and trust that define a compliant and efficient brokerage house.

Always remember that a KRA is not just a digital filing cabinet, but the gatekeeper that keeps the market ecosystem clean of illicit participants.


Nuance

⚠️ Nuance
A common pitfall is the belief that completing the physical document collection fulfills the legal requirement. Candidates often confuse the act of collecting documents with the mandatory regulatory act of ‘KRA registration confirmation’. The KRA is responsible for verifying the data against original sources; until the status shows ‘Verified’ or ‘Registered’ on the KRA portal, the intermediary remains technically non-compliant even if the files are sitting in their own local database.

Check Your Understanding

Practice Question 1

An intermediary submits a new client’s KYC data to a KRA on Tuesday. Under current SEBI norms, the KRA must complete the verification of the records and update the status in its system within how many days of receipt of the data?

Practice Question 2

If a KRA notifies an intermediary that a client’s KYC record has been ‘rejected’ due to a mismatch, what is the most appropriate course of action the intermediary must take?


This is a companion read for Section 2.5 — REGULATORS from PASS Securities Operations and Risk Management Examination by Akhilesh Gururani, available on Amazon Kindle.

Copyright © 2026 `Akhilesh Gururani. All rights reserved.