What are SEBI Research Analyst Annual Audit Checklist 2026
September 14, 2026 12 mins read

What are SEBI Research Analyst Annual Audit Checklist 2026

Author: taxationconsultancy997@gmail.com
Sebi Registrations and Legal Support - Taxation Counsultancy

A SEBI Research Analyst annual audit is not limited to checking your registration certificate or a few basic documents. The auditor may review client records, research reports, personal trading, website disclosures, advertising material, complaints, cyber-security controls, outsourcing arrangements and evidence of ongoing compliance.

Research Analysts and research entities should maintain these records throughout the year rather than preparing them only when the audit is due. This approach helps identify gaps early and keeps the entity ready for a SEBI or RAASB inspection.

In this guide, we explain the key documents and compliance areas that a SEBI-registered Research Analyst should review before the annual compliance audit.

Important: This article is for general educational information. The exact requirements may vary according to the nature, structure and activities of the Research Analyst or research entity. Obtain professional advice for your specific circumstances.

What is a SEBI RA annual audit?

A SEBI Research Analyst annual audit is a compliance review of the Research Analyst’s activities against the applicable SEBI Research Analysts Regulations, circulars and related requirements.

The audit generally examines whether the RA:

  • Maintained required records.
  • Followed personal trading and conflict-of-interest controls.
  • Issued research reports with appropriate disclosures.
  • Maintained compliant client onboarding and communication records.
  • Displayed required information on its website and mobile application.
  • Followed advertising and promotional communication requirements.
  • Maintained complaint and grievance records.
  • Completed periodic regulatory submissions.
  • Protected client and business data.
  • Documented outsourced activities and technology controls.

Complete SEBI RA audit checklist

1. Client communication records

Maintain samples of emails, letters, WhatsApp communications and other correspondence in which you identified yourself as a Research Analyst.

The records should demonstrate that applicable details were communicated correctly, including:

  • Registered name.
  • SEBI registration number.
  • Registration status.
  • Contact details.
  • Relevant disclosures and disclaimers.
  • Details required in research recommendations or reports.

Your communication records should be consistent with the information published on your website and in your research reports.

2. Personal trading records

The auditor may review personal trading and investment records to identify conflicts between your recommendations and your own transactions.

Prepare:

  • Demat account statements.
  • Contract notes.
  • Trading ledgers.
  • Records from every applicable broker.
  • Details of securities bought and sold during the audit period.
  • Records for applicable associates, employees and family members.
  • Internal approvals for permitted or exceptional trades.
  • A copy of the internal policy governing personal trading.

The auditor may compare trading records with published recommendations to check whether applicable trading restrictions and cooling-off requirements were followed.

Do not assume that maintaining one demat account is sufficient. If you or applicable connected persons use multiple broking accounts, keep records for all relevant accounts.

3. Conflict-of-interest disclosures

A Research Analyst should identify and document financial interests in securities or companies covered in its research.

Prepare declarations relating to:

  • Shareholding in companies covered by research.
  • Financial interests in recommended securities.
  • Securities purchased before an IPO or other restricted event.
  • Personal or related-party transactions.
  • Potential conflicts involving employees or family members.
  • The process used to disclose conflicts to clients.

Where a recommendation concerns a security in which the RA has a financial interest, the research report and client communication should contain the disclosures required under the applicable framework.

4. Research records and source verification

Keep a complete record of the research process behind every report or recommendation.

This may include:

  • Final research reports.
  • Draft versions and approval records.
  • Research notes.
  • Data sources.
  • Financial models.
  • Analyst workings.
  • Date of publication.
  • Date of revisions.
  • Review and approval evidence.
  • Supporting documents for assumptions and conclusions.

You should also maintain controls against the use of unauthenticated news, rumours or misleading information. The audit may examine whether recommendations were based on reliable and verifiable sources rather than unverified social media content or market rumours.

5. Client-level segregation

Individual Research Analysts must carefully document the separation between research services and financial product distribution activities.

Review whether:

  • The RA directly provides distribution services.
  • Family members are involved in distribution activities.
  • There is a common client between research and distribution businesses.
  • Clients were given a clear choice between services.
  • Client lists were checked for overlap.
  • Agreements clearly define the service being provided.
  • Fees were collected separately and transparently.

Where relevant, maintain:

  • A PAN-wise Research Analyst client list.
  • A PAN-wise distribution client list of connected family members or entities.
  • Onboarding records.
  • Service-selection records.
  • Agreements and fee records.
  • Declarations regarding non-provision of prohibited distribution services.

The purpose of this review is to identify possible cases where one client received, or was charged for, overlapping services through connected persons.

6. Website and mobile application compliance

Your website is one of the first areas an auditor may examine. Maintain screenshots and records showing that required disclosures are live and accessible.

Review whether your website or app displays:

  • Registered name.
  • SEBI registration number.
  • Registration validity, where applicable.
  • Complete address.
  • Telephone number.
  • Email address.
  • Grievance officer’s name and contact details.
  • Grievance redressal mechanism.
  • Investor Charter.
  • Required disclaimers.
  • Compliance audit status.
  • Adverse findings and action taken, where applicable.
  • Links and information required for investor grievance escalation.

SEBI’s framework requires Research Analysts to publish the status of the compliance audit report and any adverse findings with action taken on their website

Do not use the SEBI logo unless its use is specifically permitted. A registration number should not be presented in a manner that implies SEBI endorsement, guaranteed returns or approval of investment performance.

7. Investor Charter and grievance redressal

The Investor Charter should be prominently available to clients and website visitors. It should not be hidden in an inaccessible footer or provided only after a complaint arises.

Maintain evidence showing:

  • Investor Charter published on the website.
  • Investor Charter available in the mobile application, if applicable.
  • Investor Charter shared during onboarding.
  • Investor Charter included in relevant client communications.
  • Grievance officer details are current.
  • Escalation contacts are displayed.
  • Working hours and response channels are clear.

SEBI’s Research Analyst master circular identifies the Investor Charter and grievance process as important investor-facing disclosures.

8. Monthly complaint reporting

Maintain a month-wise complaint register in the prescribed format.

Your records should include:

  • Complaint reference number.
  • Date received.
  • Client details.
  • Nature of complaint.
  • Person responsible for handling it.
  • Date of resolution.
  • Resolution provided.
  • Pending status, if any.
  • Escalation details.
  • Supporting correspondence.

If complaints were received through SCORES or another applicable grievance platform, retain login, access and resolution evidence. Also document the action taken for complaints involving impersonation or fraudulent use of the RA’s name and registration details.

The SEBI master circular provides for investor grievance escalation through SCORES where a complaint is not satisfactorily resolved.[sebi.gov]

9. Advertising and public appearances

Maintain a complete register of all advertising and public-awareness activity during the audit period.

Include:

  • Meta and Facebook advertisements.
  • Google or search advertisements.
  • Website banners.
  • YouTube videos.
  • Instagram content.
  • Podcasts.
  • Webinars.
  • Television appearances.
  • Seminars.
  • Influencer promotions.
  • Referral arrangements.
  • Public interviews.

For each activity, retain:

  • Final creative or recording.
  • Date of publication.
  • Approval evidence.
  • Applicable RAASB or exchange approval.
  • Disclosure and disclaimer shown.
  • Name and registration details used.
  • Financial interest disclosure, where relevant.

Avoid marketing language that suggests:

  • Guaranteed returns.
  • Assured profits.
  • Risk-free investments.
  • Fixed performance.
  • “Sure-shot” recommendations.
  • Winning schemes or contests.
  • Prize-based client acquisition.
  • Misleading discounts or inducements.

A compliance review should also confirm that no advertisement was issued while the RA registration was suspended or subject to a restriction that prevented the activity.

10. Influencers, referral partners and distribution associations

If you work with an influencer, referral partner, channel partner or digital platform, document the arrangement carefully.

Maintain:

  • Name of the partner.
  • Nature of the relationship.
  • Agreement copy.
  • Compensation terms.
  • Content approval process.
  • Disclosure requirements.
  • Evidence of registration and eligibility.
  • Published communications.
  • Monitoring records.

Do not rely on informal commission arrangements or verbal promises. The auditor may ask whether an influencer or referral arrangement improperly promotes the RA’s service or creates a prohibited incentive structure.

11. Periodic regulatory reporting

Prepare evidence of all applicable regulatory submissions, including:

  • Half-yearly periodic reports.
  • Reports submitted by the applicable due dates.
  • Submission acknowledgements.
  • Emails or portal receipts.
  • Clarifications submitted to SEBI or RAASB.
  • Responses to regulatory requests.
  • Previous-year compliance audit report.
  • Adverse findings from the previous year.
  • Action Taken Report.
  • Proof of corrective submissions.

Organise the evidence by financial year and submission date. A simple compliance calendar can help prevent missed deadlines.

12. Model portfolios

If you offer model portfolios, maintain separate documentation for every model.

The records should cover:

  • Model portfolio name.
  • Launch date.
  • Investment theme.
  • Objective.
  • Risk level.
  • Investment horizon.
  • Security-selection methodology.
  • Underlying research report for each security.
  • Fact sheet and disclosures.
  • Benchmark.
  • Rebalancing frequency.
  • Rebalancing communication.
  • Reasons for additions, removals or changes.
  • Performance information, where communicated.

The model portfolio name should accurately describe its objective and theme. For example, a portfolio described as a “long-term dividend strategy” should have a documented methodology consistent with that description.

Also verify that your public view on a constituent security is not inconsistent with your internal or client-facing recommendations.

13. IT systems and data security

Prepare a list of all systems used to deliver services and store business or client data.

Include:

  • Research and portfolio software.
  • CRM systems.
  • Cloud storage.
  • Email systems.
  • Client onboarding platforms.
  • Payment systems.
  • Website hosting.
  • Mobile applications.
  • Backup systems.
  • Data-storage locations.
  • Access-control procedures.

Maintain:

  • Cybersecurity policy.
  • Vulnerability assessment or penetration-testing records, where applicable.
  • User-access records.
  • Backup policy.
  • Incident-response process.
  • Vendor security assessments.
  • Data-processing agreements.
  • Evidence of remediation.

If technology is outsourced, document the vendor relationship and retain monitoring records. Outsourcing technology does not automatically eliminate the RA’s responsibility to supervise compliance and protect client information.

14. Outsourcing arrangements

For each outsourced function, maintain:

  • Written agreement.
  • Scope of work.
  • Vendor due-diligence record.
  • Risk assessment.
  • Service-level expectations.
  • Data-security terms.
  • Monitoring reports.
  • Review and renewal records.
  • Evidence that core responsibilities remain controlled by the RA.

Do not outsource the core regulatory responsibility in a manner that leaves the RA unable to explain its own research, client records or compliance process.

15. AML and CFT policies

Maintain updated Anti-Money Laundering and Countering the Financing of Terrorism policies where applicable.

Your records may include:

  • AML policy.
  • CFT policy.
  • Client identification procedures.
  • Risk classification process.
  • Suspicious transaction escalation process.
  • Record-retention procedure.
  • Employee training evidence.
  • FIU-IND registration and related records, where applicable.

The auditor may verify whether the written policies are actually implemented in onboarding and client-monitoring procedures.

Common mistakes before an RA audit

Research Analysts frequently focus on registration documents and overlook operational evidence. Common gaps include:

  • Website disclosures not updated.
  • Investor Charter missing or difficult to find.
  • Old grievance officer details.
  • Incomplete personal trading records.
  • Missing records from a second broker.
  • No evidence of advertisement approval.
  • Unverified social media promotions.
  • Inconsistent registration details across platforms.
  • No client-segregation declaration.
  • Missing periodic-reporting acknowledgements.
  • No record of action taken on previous findings.
  • Incomplete research files.
  • Undocumented outsourcing arrangements.
  • Unclear model portfolio methodology.
  • Marketing language implying guaranteed returns.
  • Failure to document impersonation complaints.

How to prepare efficiently

Use a year-round compliance system instead of creating documents immediately before the audit.

Recommended process

  1. Create a master compliance checklist mapped to every applicable requirement.
  2. Assign an owner and review frequency for each item.
  3. Save evidence in folders organised by financial year and compliance category.
  4. Take dated screenshots of website and app disclosures.
  5. Maintain an advertisement and public-appearance register.
  6. Reconcile research recommendations with personal and connected-person trading records.
  7. Review client overlap and segregation every quarter.
  8. Update the complaint register every month.
  9. Test website disclosures, forms and grievance links regularly.
  10. Conduct an internal pre-audit review before the external annual audit.

A practical folder structure could include:

  • 01 Registration and Certificates
  • 02 Client Onboarding
  • 03 Research Reports
  • 04 Personal Trading
  • 05 Website and Investor Charter
  • 06 Advertisements
  • 07 Complaints and SCORES
  • 08 Periodic Reporting
  • 09 Model Portfolios
  • 10 IT and Cybersecurity
  • 11 Outsourcing
  • 12 AML and CFT
  • 13 Previous Audit Findings

Frequently asked questions

Q1. Is an annual audit mandatory for a SEBI Research Analyst?

Ans. The applicable SEBI framework requires Research Analysts and research entities to conduct an annual compliance audit covering the relevant regulations and circulars. The audit should be completed and reported within the prescribed timeline.

Q2. What documents are required for a SEBI RA audit?

Ans. The exact list depends on your structure and activities, but commonly reviewed records include client files, research reports, trading records, disclosures, advertisements, website screenshots, complaint registers, periodic reports, policies, technology records and previous audit documents.

Q3. Does the auditor check the Research Analyst’s website?

Ans. Yes. Website and app disclosures may be reviewed, including registration details, grievance information, Investor Charter, disclaimers and compliance audit status.

Q4. Does an individual Research Analyst need to maintain personal trading records?

Ans. A Research Analyst should maintain applicable records of personal and connected-person trading so the auditor can evaluate conflicts of interest and compliance with trading restrictions.

Q5. What happens if the audit identifies adverse findings?

Ans. Adverse findings should be documented, addressed and reported according to the applicable SEBI and RAASB requirements. The status and action taken may also need to be published on the website.

Q6. Can a Research Analyst use influencers for promotion?

Ans. Any influencer, referral or public-promotion arrangement should be reviewed against applicable regulatory requirements and documented with written agreements, approvals and disclosures. Avoid informal arrangements and promotional claims about assured returns.

Q7. Can Taxation Consultancy help with a SEBI RA audit?

Ans. Taxation Consultancy provides SEBI registration, post-registration compliance, audit and regulatory-support services for Research Analysts and other regulated entities. Visit the relevant SEBI compliance service page or contact the team to discuss your requirements.

Get audit-ready before the deadline

A SEBI Research Analyst annual audit should be treated as a year-round compliance process, not a last-minute document exercise. Review your client records, research files, trading statements, website disclosures, advertising activity, complaints, reporting evidence and technology controls well before the audit begins.

Taxation Consultancy supports SEBI Research Analysts with registration, post-registration compliance, audit preparation and regulatory assistance. Contact the team at +91-8928321757 or taxationconsultancy997@gmail.com to discuss your audit requirements. The business website identifies support for SEBI Research Analyst registration, post-registration compliance, audit reports and SEBI legal support.[taxationconsultancy]