PASS Securities Operations and Risk Management Examination Difficulty: Beginner 2 Questions   5 min read
📌 Chapter 8.8 — INTERNET BASED TRADING (IBT) & SECURITIES TRADING USING WIRELESS TECHNOLOGY (STWT)

Consider a Monday morning in the risk department where you notice a series of high-frequency login attempts from a static IP address in a different state. If your firm’s mobile app relied only on a static password, this could quickly escalate into an unauthorized trade entry incident, forcing you to freeze client accounts and initiate an expensive forensic audit.

By mandating Two-Factor Authentication (2FA) for Internet-Based Trading (IBT) and Securities Trading using Wireless Technology (STWT), you create a necessary layer of verification that ensures the person placing the trade is actually the client registered with your records.

In the Indian context, SEBI mandates that this second factor of authentication must be something beyond just a password, typically utilizing an OTP sent to the registered mobile number or a dynamic time-based token. When a client attempts to trade via their smartphone while commuting, the system validates their identity via these layers before the risk management module checks their available margin.

If your system were to bypass this step for the sake of speed, you would be in violation of circulars designed to prevent market manipulation and protect the integrity of the client’s capital.

This process is not merely a technical checkbox but a foundational element of your firm’s operational risk framework. Think of it as a digital handshake that happens in milliseconds, ensuring that the source of the order is verified before the order reaches the exchange server. Without this, your middle office would be vulnerable to account takeovers, which often lead to complex client grievances, disputes over unauthorized transactions, and potential regulatory sanctions against the broker.

Ultimately, robust authentication ensures that your firm’s audit trail remains beyond reproach during a SEBI or exchange-led inspection. When you insist on 2FA as a non-negotiable prerequisite, you effectively safeguard the entire lifecycle of the trade, from the moment the user clicks buy to the eventual settlement at the clearing corporation. Your role as an operations professional is to be the guardian of this digital barrier, ensuring that the convenience of STWT never comes at the expense of market safety.


Nuance

⚠️ Nuance
Candidates often mistakenly believe that a biometric login (like a fingerprint or face ID) on a smartphone completely satisfies the 2FA requirement. While convenient for the user, true 2FA must involve a second independent element—usually a dynamic, time-sensitive code or a separate secure token—rather than just a local device-based lock. If your firm relies solely on biometric authentication, you may be failing to meet the regulatory requirement for a secondary, external verification factor.

Check Your Understanding

Practice Question 1

Which of the following describes the primary objective of implementing a 2FA framework for a broker offering STWT services under SEBI guidelines?

Practice Question 2

A broker’s IT department proposes a new login process where a client enters a password and then a static PIN that never changes. Why would this fail to meet standard regulatory expectations for 2FA in STWT?


This is a companion read for Section 8.8 — INTERNET BASED TRADING (IBT) & SECURITIES TRADING USING WIRELESS TECHNOLOGY (STWT) from PASS Securities Operations and Risk Management Examination by Akhilesh Gururani, available on Amazon Kindle.

Copyright © 2026 `Akhilesh Gururani. All rights reserved.