{"id":1793,"date":"2026-09-17T10:09:30","date_gmt":"2026-09-17T10:09:30","guid":{"rendered":"https:\/\/trackwizz.com\/knowledge-hub\/?p=1793"},"modified":"2026-09-22T10:31:51","modified_gmt":"2026-09-22T10:31:51","slug":"aml-for-stockbrokers-and-depository-participants","status":"publish","type":"post","link":"https:\/\/trackwizz.com\/knowledge-hub\/aml-for-stockbrokers-and-depository-participants\/","title":{"rendered":"AML for Stockbrokers and Depository Participants"},"content":{"rendered":"<h2><strong>Guarding the Two Gates Every Market Abuser Must Pass Through<\/strong><\/h2>\n<p><em>What SEBI actually requires, what three years of enforcement reveal about how the system gets abused, and what brokers and DPs should be doing about risk assessment, internal controls, governance, and technology<\/em><\/p>\n<h3>1. Why Brokers and DPs Are the Two Gates Everyone Must Pass Through<\/h3>\n<p>Every other AML article in this series has looked at a regulated entity that sits at one end of a transaction, such as a bank clearing a payment or an NBFC disbursing a loan. The securities market is structurally different, and that difference is what makes stockbrokers and Depository Participants (<strong>DP<\/strong>s) worth a dedicated conversation rather than a subsection of a broader one.<\/p>\n<p>No one can transact in Indian securities without passing through a stockbroker, the only route to order execution on an exchange. And no one can hold or transfer dematerialised securities without a demat account maintained by a DP. Between them, these two intermediary types sit at the only two chokepoints the entire securities market has: access to trade, and custody of what was traded. A criminal seeking to launder proceeds, corner an IPO, manipulate a price, or trade on inside information has no way around either gate. That is exactly why the modus operandi documented in SEBI&#8217;s own orders over the past two decades returns, again and again, to the same two failure points: a broker&#8217;s dealer-level access being abused, or a DP&#8217;s account-opening and monitoring controls being exploited.<\/p>\n<p>This piece works through what <strong>SEBI&#8217;s AML\/CFT <\/strong>framework actually requires of these two intermediary types, what a wide sweep of SEBI enforcement orders, spanning market manipulation, front-running, pump-and-dump schemes, and the market&#8217;s own history of large-scale abuse, reveals about how the ecosystem gets exploited, and what a defensible risk assessment, control environment, and governance structure should look like in response. Individuals and entities named in the underlying orders are not identified here; each case study refers only to \u201cone stockbroker,\u201d \u201cone DP,\u201d or \u201ca family group,\u201d consistent with the analytical, pattern-focused purpose of this piece.<\/p>\n<h3>2. The Regulatory Architecture: What SEBI Actually Requires<\/h3>\n<p>Stockbrokers and DPs are \u201cintermediaries\u201d under Section 12 of the SEBI Act, 1992, and \u201cfinancial institutions\u201d in the wider PMLA sense. Both are reporting entities in their own right, obligated to maintain records, conduct client due diligence, and file Suspicious Transaction Reports with FIU-IND. The consolidated obligation is set out in SEBI&#8217;s Master Circular on AML\/CFT standards for securities market intermediaries, currently SEBI\/HO\/MIRSD\/MIRSDSECFATF\/P\/CIR\/2024\/78 dated June 6, 2024, which supersedes an earlier version issued on February 3, 2023, and traces back through a lineage of circulars issued since 2006, following India&#8217;s implementation of the PMLA and FATF&#8217;s recommendations.<\/p>\n<p><strong>2.1 What the Master Circular Requires of Every Intermediary<\/strong><\/p>\n<ul>\n<li>A board-approved AML\/CFT policy and a Customer Acceptance Policy naming prohibited client categories, not just generic risk language.<\/li>\n<li>A Principal Officer responsible for AML\/CFT compliance and STR filing, and a Designated Director carrying board-level accountability, mirroring the structure covered in this series&#8217; pieces on <strong>PEP <\/strong>and sanctions screening.<\/li>\n<li>Client Due Diligence (<strong>CDD<\/strong>) at onboarding and on an ongoing basis, risk categorisation of every client into low, medium, or high risk, and a defined \u201cClients of Special Category\u201d (CSC) list covering PEPs, NRIs, HNIs, trusts and NGOs, and clients from high-risk jurisdictions, all requiring enhanced due diligence, discussed at length in this series&#8217; earlier pieces on PEP screening.<\/li>\n<li>A periodic, documented ML\/TF risk assessment at the institutional level, and sanctions screening against <strong>UNSC <\/strong>and <strong>MHA<\/strong>-designated lists under <strong>UAPA <\/strong>Section 51A, the same freeze-without-delay obligation covered in this series&#8217; sanctions screening piece.<\/li>\n<\/ul>\n<p><strong>2.2 What Is Distinctly a Stockbroker&#8217;s Obligation<\/strong><\/p>\n<ul>\n<li>Verifying the identity of every client before assigning a Unique Client Code (UCC). No order can be placed on an exchange without one, making UCC assignment the broker&#8217;s equivalent of a bank&#8217;s account-opening gate.<\/li>\n<li>Segregating client funds and securities from the broker&#8217;s own proprietary accounts, and never using client collateral for the broker&#8217;s own trading or borrowing. This is the specific control whose breakdown produced some of the securities market&#8217;s largest intermediary failures historically.<\/li>\n<li>Real-time and post-trade surveillance of order and trade patterns for manipulative behaviour, including spoofing, layering, circular trading, and front-running, under exchange-mandated surveillance obligations that sit alongside, and feed into, the broker&#8217;s own AML monitoring. These obligations are now consolidated in SEBI&#8217;s Master Circular on Surveillance of Securities Market, dated May 15, 2026, which brought together the prior surveillance circulars into a single reference document and, notably, also governs the monitoring of unauthenticated news and stock recommendations circulated by intermediaries through social media and messaging platforms, the exact vector at the centre of the case study in Section 3.4.<\/li>\n<li>Reporting on algorithmic trading systems used by the broker or its clients, including AI\/ML-based systems, to the exchange and to SEBI, a distinct and often under-appreciated obligation discussed further in Section 9.<\/li>\n<\/ul>\n<p><strong>2.3 What Is Distinctly a DP&#8217;s Obligation<\/strong><\/p>\n<ul>\n<li>KYC and beneficial-ownership verification at demat account opening. The DP is the only intermediary that ever independently verifies who actually owns a given block of dematerialised securities.<\/li>\n<li>Monitoring off-market transfers, meaning transfers between demat accounts outside an exchange trade, for patterns inconsistent with the account holder&#8217;s profile. This has historically been one of the least-monitored corners of the securities market, as Section 3 illustrates.<\/li>\n<li>Monitoring pledge creation and invocation, since securities pledged as collateral and then quietly transferred or sold can be used to disguise the true ownership chain of an asset.<\/li>\n<li>Flagging patterns in account-opening activity itself, such as large numbers of accounts opened on the same day, through the same branch, with overlapping addresses, contact details, or introducers. This is a control point whose absence is central to the case study in Section 3.5.<\/li>\n<\/ul>\n<p>The practical point worth holding onto through the rest of this piece is this: a broker&#8217;s obligations are concentrated at the point of trade, and a DP&#8217;s obligations are concentrated at the point of custody and transfer. Criminals who understand this distinction target whichever gate is weakly monitored, which is precisely why the most damaging historical failures in the Indian securities market trace back to DP-side account-opening gaps more often than to broker-side trade surveillance gaps.<\/p>\n<h3>3. Learning from the Market&#8217;s Own History: Typologies and Modus Operandi<\/h3>\n<p>The typologies below are drawn from SEBI orders spanning roughly the last three years, supplemented by two landmark historical cases, clearly dated as such, that remain foundational to understanding why today&#8217;s DP and broker controls exist in their current form. No individual or entity is named; each is referred to generically.<\/p>\n<p><strong>3.1 Insider Trading Through a Broker-Held Relationship<\/strong><\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"601\"><strong>Case Study: Family Trading Ahead of Price-Sensitive Information<\/strong><\/p>\n<p>A designated employee of a listed public sector company became privy to unpublished quarterly financial results and dividend information. His in-laws, both long-standing traders in the same <em>scrip <\/em>through their own broking accounts, executed derivative trades during the narrow window between the information&#8217;s creation and its public disclosure, generating profits in the tens of lakhs. The adjudicating authority ultimately found the trading pattern consistent with the family&#8217;s fifteen-year trading history in the same scrip, including years of losses, and held that proximity and relationship alone, without a documented communication trail, did not meet the evidentiary bar. The broker holding these accounts had no visibility into the insider relationship or the UPSI itself. The case illustrates the limit of what broker-side surveillance can catch on its own, and why cross-referencing beneficial ownership and family relationships, discussed in Section 8, matters even when no single account looks abnormal in isolation.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>3.2 Dealer-Level Front-Running of a Broker&#8217;s Own Proprietary Book<\/strong><\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"601\"><strong>Case Study: A Dealer Trading Ahead of His Own Employer<\/strong><\/p>\n<p>A dealer at a registered stockbroker, also holding Depository Participant and Research Analyst registrations, was found to have used his discretion over the timing and volume of his employer&#8217;s proprietary trades to place his own orders, through his own account, his spouse&#8217;s account, and a family HUF account, ahead of the firm&#8217;s own large trades, then square off once the firm&#8217;s order moved the price. Over 70 confirmed instances across more than three years generated profits exceeding five lakh rupees, identified through exchange-level Buy-Buy-Sell pattern surveillance rather than any internal escalation. The dealer&#8217;s own recorded statement admitted the sequencing. This case is a direct illustration of why segregation between dealer-level trading discretion and family-account oversight is not optional: the broker was, in effect, front-run by its own staff, using accounts it itself held as DP.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>3.3 Cross-Segment Price Manipulation Using a Broker&#8217;s Own Infrastructure<\/strong><\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"601\"><strong>Case Study: Manipulating Futures to Profit in Options<\/strong><\/p>\n<p>A registered stockbroker, also a Depository Participant and Research Analyst, was found to be running a scheme in which he placed large, resting options orders away from the prevailing market price, then aggressively traded stock futures of the same underlying to artificially move the futures price. Because futures and options prices are economically linked through put-call parity, this manufactured price movement fed through into options premiums, executing the resting orders at artificially favourable prices. When exchange scrutiny prompted the broker to stop the activity in its own proprietary account, an identical pattern reappeared almost immediately in a closely related family entity, sharing common directors, a common residential address, and common contact details, trading through the same broker&#8217;s own infrastructure. SEBI&#8217;s interim order impounded over twenty-eight crore rupees in prima facie wrongful gains. The case is a clear illustration of self-dealing risk unique to entities that are simultaneously broker, trading member, and proprietary trader, and of how quickly a manipulative pattern migrates to a connected entity once the primary vehicle is flagged.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>3.4 Social-Media-Driven Pump-and-Dump Across a Broker&#8217;s Retail Book<\/strong><\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"601\"><strong>Case Study: A Family Network Promoting SME Stocks<\/strong><\/p>\n<p>A group of related individuals, described in press reports as acting as operators and account holders within the same family, was found to have systematically accumulated shares in small and medium enterprise (SME)-listed companies, then promoted those stocks through bullish messaging on X, WhatsApp, and Telegram, at times with explicit target prices, framed as stock recommendations. As retail interest and prices rose on the back of this promotion, the group allegedly sold into the resulting demand. In a 234-page interim order dated May 22, 2026, SEBI barred seven individuals from the securities market and alleged unlawful gains of approximately twenty crore rupees. As with the other recent cases in this section, the findings are prima facie and interim in nature, pending further process. Every trade in this scheme passed through ordinary broking accounts that, viewed in isolation, showed nothing more than a family group actively trading small-cap stocks. The manipulation was visible only once trading activity was correlated against the group&#8217;s own social media promotional activity, a data source outside a broker&#8217;s traditional transaction-monitoring scope but one now explicitly within the scope of SEBI&#8217;s May 2026 surveillance framework referenced in Section 2.2.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>3.5 The Landmark Case: Cornering IPO Allotments Through Fictitious Demat Accounts<\/strong><\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"601\"><strong>Landmark Case, 2005 to 2007: The Demat Scam<\/strong><\/p>\n<p>This is a historical case, not drawn from the last three years, but it remains the foundational precedent for why DP account-opening controls exist in their current form. Between 2003 and 2005, SEBI found that certain key operators had opened tens of thousands of demat accounts in fictitious or benami names. In one IPO alone, over 45,000 such accounts were identified, with one DP responsible for opening more than 42,000 multiple accounts for a single operator. Each account made a small-value IPO application, sized to qualify for the retail investor quota, which historically enjoys better allotment odds than larger categories. Once allotted, the fictitious accounts transferred their shares off-market to the key operators, who in turn transferred them to financiers who sold immediately on listing, pocketing the gap between issue price and listing price. SEBI&#8217;s investigation covered 21 IPOs, including several major listings of that period, and found that thousands of demat accounts had been opened on the same day, through the same branch, without the account-opening irregularities being flagged. SEBI ultimately barred 24 entities, including a leading stockbroker and a major retail brokerage, from the market, barred twelve DPs from opening fresh demat accounts pending inspection, and separately fined both central depositories for lapses that allowed the scheme to operate at this scale. This case is the direct ancestor of today&#8217;s KYC Registration Agency (KRA) system and of the account-opening red flags, same-day, same-branch, same-introducer account clusters, that a modern DP control environment is expected to catch automatically.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>3.6 The Other Landmark Case: Algorithmic Trading and Preferential Market Access<\/strong><\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"601\"><strong>Landmark Case, 2015 Onward: Preferential Co-Location Access<\/strong><\/p>\n<p>Also, a historical case, but structurally important for understanding technology-enabled manipulation risk. A whistle-blower alleged that certain trading members obtained preferential, earlier access to price and order data through the exchange&#8217;s co-location and algorithmic trading infrastructure, allowing them to systematically trade ahead of the rest of the market. The matter has involved years of investigation and regulatory and criminal proceedings. Its relevance to a broker&#8217;s own AML\/CFT control environment is direct: any broker offering algorithmic trading facilities to clients, or co-locating its own systems, has an obligation to ensure that technology access itself does not become a vector for market abuse, which is exactly the concern behind SEBI&#8217;s AI\/ML and algorithmic trading reporting requirements discussed in Section 9.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>3.7 Circular and Synchronised Trading: A Recurring Structural Typology<\/strong><\/p>\n<p>Beyond the specific cases above, circular and synchronised trading remains a persistent typology across SEBI&#8217;s enforcement history. A group of connected entities, often sharing directors, addresses, or funding sources, repeatedly trades the same security among themselves at pre-arranged prices and volumes, creating an artificial impression of trading interest and volume without any genuine change in beneficial ownership. This is explicitly captured within Regulations 3 and 4 of the <strong>PFUTP <\/strong>Regulations, 2003 (as amended), which prohibit dealing in securities in a manner that creates a false or misleading appearance of trading activity. The typology is structurally similar to the cross-segment case in Section 3.3 in one key respect: it depends entirely on connected-entity relationships that are invisible to a broker or DP looking at any single account in isolation, and visible only once accounts are mapped against each other for shared directors, addresses, contact details, or funding patterns, precisely the analytical task Section 9 argues technology is now essential for.<\/p>\n<h3>4. What This Reveals About Internal Control Weaknesses<\/h3>\n<p>Read together, these cases point to a small, recurring set of control gaps, not novel failures unique to any one case, but the same handful of weaknesses appearing across a fifteen-year span:<\/p>\n<ul>\n<li>Dealer-level discretion without independent oversight: a single individual holding both the information advantage of knowing about an impending large order and the execution authority over its timing and volume is a control failure waiting to happen, as Section 3.2 shows directly.<\/li>\n<li>Account-opening controls that check individual applications but not clustering &#8211; verifying that a single demat account&#8217;s KYC documents are valid, does not catch 40,000 valid-looking accounts opened by the same operator on the same day, the precise gap Section 3.5 exposed at scale.<\/li>\n<li>Family and related-party blindness: in four of the six cases above, the connecting thread was a family or closely related entity structure, such as a spouse, in-laws, an HUF, or commonly directed companies, that was only established after the fact, through director databases, KYC cross-references, and shared contact details, not caught proactively by either broker or DP at onboarding.<\/li>\n<li>Segment-siloed surveillance: the cross-segment manipulation case in Section 3.3 was only detectable by watching futures and options activity together. A surveillance system that monitors each segment independently, as many still effectively do, would have seen nothing wrong in either segment on its own.<\/li>\n<li>Data sources outside the transaction record: the pump-and-dump case in Section 3.4 required correlating trading activity against social media promotional content, a data source no traditional AML transaction-monitoring system ingests by default.<\/li>\n<li>Self-dealing conflicts in multiply-registered entities: an entity holding stockbroker, DP, and Research Analyst registrations simultaneously, as in Section 3.3, creates layered self-dealing opportunities that a single-registration entity would not have, and correspondingly needs a control environment calibrated to that layered risk, not a generic one.<\/li>\n<\/ul>\n<h3>5. Risk Assessment: What Brokers and DPs Should Actually Do<\/h3>\n<p>The discipline this series has previously described for NBFCs under RBI&#8217;s October 2024 Internal Risk Assessment Guidance, a dual-level assessment covering both the institution&#8217;s own business model and each individual customer relationship, moving from inherent risk through control effectiveness to a documented residual risk, translates directly to the securities market context, even though that specific guidance is not itself addressed to SEBI-regulated entities.<\/p>\n<p><strong>5.1 Business-Level Risk Factors Specific to Broking and DP Operations<\/strong><\/p>\n<table width=\"601\">\n<thead>\n<tr>\n<td width=\"233\"><strong>Risk Factor<\/strong><\/td>\n<td width=\"368\"><strong>Why It Matters Here<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"233\">Dual or multiple registration (broker plus DP plus RA, or broker plus proprietary trading desk)<\/td>\n<td width=\"368\">Creates self-dealing and information-advantage risk not present in single-registration entities, as Section 3.3 illustrates directly<\/td>\n<\/tr>\n<tr>\n<td width=\"233\">Algorithmic trading and colocation facilities offered to clients<\/td>\n<td width=\"368\">Technology access itself can become a manipulation vector, per Section 3.6, and requires its own governance layer, not just KYC on the client behind it<\/td>\n<\/tr>\n<tr>\n<td width=\"233\">Volume of off-market transfers relative to on-exchange trades<\/td>\n<td width=\"368\">Off-market transfers bypass exchange-level surveillance entirely and are a DP-specific blind spot<\/td>\n<\/tr>\n<tr>\n<td width=\"233\">Retail concentration in illiquid, low-market-capitalisation, and SME scrips<\/td>\n<td width=\"368\">Both the cross-segment manipulation and pump-and-dump cases specifically targeted lower-liquidity, easier-to-move securities<\/td>\n<\/tr>\n<tr>\n<td width=\"233\">Family, promoter, and connected-entity concentration in the client base<\/td>\n<td width=\"368\">The single most recurring thread across every case study above<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>5.2 Customer-Level Risk Factors<\/strong><\/p>\n<ul>\n<li>Beneficial ownership complexity and family or relationship mapping at onboarding, not just at the individual account level, but cross-referenced against other accounts held with the same broker or DP.<\/li>\n<li>Dealer or employee-linked accounts. Any account held by, or demonstrably operated by, an employee of the broker itself, as in Section 3.2, warrants automatic elevation to a higher-scrutiny category, with restrictions on the employee&#8217;s own trading discretion over client or proprietary flow.<\/li>\n<li>Account-opening clustering. Same-day, same-branch, same-introducer, or same-contact-detail account openings should trigger review before, not after, the accounts become active.<\/li>\n<li>Trading pattern deviation from an account&#8217;s own history. Both the insider trading and cross-segment cases turned on whether trading activity was consistent with, or a sharp departure from, the account&#8217;s own multi-year pattern.<\/li>\n<li>External promotional activity linked to an account holder. This is increasingly relevant given the pump-and-dump typology, though it sits at the edge of what a broker can practically monitor without additional data sources.<\/li>\n<\/ul>\n<h3>6. Internal Controls Brokers and DPs Should Have in Place<\/h3>\n<ul>\n<li>Segregation of duties between dealers or relationship managers and the compliance or surveillance function, with no dealer holding both trade-timing discretion over a large client or proprietary order and unsupervised access to related-party trading accounts.<\/li>\n<li>Mandatory clustering checks at demat account opening: automated flags for shared addresses, mobile numbers, email IDs, bank account details, or introducers across multiple new applications, particularly when volumes spike around a specific corporate action such as an IPO.<\/li>\n<li>Director and beneficial-ownership cross-referencing against the MCA database and existing client records, refreshed periodically rather than only at onboarding. This is the specific step that established the family connection in the cross-segment manipulation case.<\/li>\n<li>Cross-segment surveillance that watches a client&#8217;s activity across cash, futures, and options together, not as three independently monitored silos, given that the cross-segment manipulation typology is specifically designed to defeat segment-by-segment monitoring.<\/li>\n<li>Off-market transfer and pledge monitoring calibrated to the account&#8217;s own profile. Large or unusual off-market transfers, or pledge creation followed swiftly by invocation and sale, should generate a review, not just a record.<\/li>\n<li>Dormant account reactivation triggers. An account with no activity for an extended period suddenly transacting at volume is a pattern flagged repeatedly across AML typologies in this series and applies equally to demat accounts as to bank accounts.<\/li>\n<li>Algorithmic trading and technology governance: a live inventory of algo strategies and AI\/ML systems in use, whether offered to clients or used internally, tested for abnormal behaviour, and reported per SEBI&#8217;s current disclosure and accountability requirements, discussed in Section 9.<\/li>\n<li>A disciplined STR filing workflow with a documented escalation path from surveillance alert to Principal Officer review to filing decision, and clear record-keeping of the rationale for both filed and closed alerts, the same disposition discipline covered in this series&#8217; piece on alert triage dashboards.<\/li>\n<\/ul>\n<h3>7. Managing Residual Risk<\/h3>\n<p>No control environment eliminates risk. The honest question is what remains after controls are applied, and how that residual risk is actively managed rather than passively accepted:<\/p>\n<ul>\n<li>Independent testing of the surveillance and CDD function, distinct from routine internal audit, given how directly the case studies above trace back to gaps that looked adequate on paper but had drifted or were never tested against a real clustering or cross-segment scenario.<\/li>\n<li>Periodic re-assessment of residual risk as products and client mix change. A broker adding algorithmic trading facilities, or a DP seeing a spike in account openings ahead of an IPO, should trigger an interim residual-risk review rather than waiting for the next scheduled cycle.<\/li>\n<li>A genuine whistleblower and escalation channel, since several of the historical failures above were ultimately surfaced through external whistle-blowers or exchange-level surveillance rather than the intermediary&#8217;s own internal detection.<\/li>\n<li>Explicit acceptance, at senior management and Board level, of which residual risks are being knowingly carried. For instance, the residual risk of a family-connected account structure that has been reviewed and found benign should be documented as a decision, not left as an unstated assumption.<\/li>\n<\/ul>\n<h3>8. Governance<\/h3>\n<p>A control environment built on paper policy alone does not survive contact with the typologies above. Governance is what keeps it operating in practice:<\/p>\n<ul>\n<li>Board-approved AML\/CFT and surveillance policy, reviewed at least annually and whenever SEBI&#8217;s Master Circular or the PFUTP Regulations are amended.<\/li>\n<li>A Principal Officer and Designated Director with real authority to escalate, freeze, and report, not titles layered onto an existing compliance role without the corresponding mandate.<\/li>\n<li>Board or Risk Committee level MIS covering surveillance alert volumes, STR filings, account-opening clustering flags, and any escalations, with enough granularity that the Board can ask why a dealer&#8217;s trading pattern looked unusual for three years before it was caught and receive a real answer.<\/li>\n<li>Explicit governance of dual-registration conflicts. Where a single entity holds broker, DP, or Research Analyst registrations, the Board should require a documented Chinese wall arrangement between proprietary trading, client dealing, and research functions, tested periodically rather than assumed.<\/li>\n<li>A culture in which surveillance flags on senior dealers or promoter-linked accounts receive the same rigour as flags on ordinary retail clients, since several of the case studies above involved individuals or entities with long-standing, trusted relationships with the intermediary itself.<\/li>\n<\/ul>\n<h3>9. The Role of AI\/ML, Clustering, and Graph Analysis, and Why It Matters Here Specifically<\/h3>\n<p>SEBI&#8217;s oversight of AI\/ML usage among market intermediaries has moved well past the reporting-only regime it started with in 2019, and the regulatory picture is worth setting out accurately before turning to what these technologies can do for the control gaps identified in Section 4.<\/p>\n<p><strong>9.1 From Disclosure to Liability: How the Framework Has Evolved<\/strong><\/p>\n<p>The foundation was laid on January 4, 2019, through a pair of circulars: SEBI\/HO\/MIRSD\/DOS2\/CIR\/P\/2019\/10 for stockbrokers and DPs, and a companion circular, SEBI\/HO\/MRD\/DOP1\/CIR\/P\/2019\/24, for market infrastructure institutions. Both required periodic disclosure of AI\/ML systems in use. At the time, this was purely a reporting obligation. SEBI wanted visibility into adoption, not yet a governance regime. Reporting cadence and scope were revised from December 2023 through exchange circulars, moving to half-yearly reporting for algorithmic trading members and annual reporting for others, and broadening the definition of an AI\/ML system to cover predictive, analytical, and pattern-recognition algorithms used across front, mid, and back-office functions, not just client-facing trading tools. Through 2025, exchanges further harmonised their reporting templates into a single cross-exchange mechanism.<\/p>\n<p>That reporting layer is no longer the whole story. On February 6, 2025, SEBI notified actual amendments to the Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) Regulations, 2018 and the SEBI (Intermediaries) Regulations, 2008, introducing binding liability provisions for AI\/ML tool usage. Regulated entities, including stock exchanges, clearing corporations, depositories, and SEBI-registered intermediaries such as brokers and DPs, are now squarely responsible for the privacy, security, and integrity of investor data processed by such tools, and for the output the tools produce. This shifts the framework from telling the regulator what is being used to owning the consequences of what is being used, a materially different governance posture than the 2019 disclosure obligation alone.<\/p>\n<p>SEBI followed this in June 2025 with a Consultation Paper on responsible AI\/ML usage, proposing a governance framework built around six pillars: ethics, accountability, transparency, auditability, data privacy, and fairness. The paper also proposes a requirement that firms maintain a board-approved AI Governance Framework, echoing the board-level accountability this series has previously discussed in the context of RBI&#8217;s FREE-AI framework for banks and NBFCs. The proposal also floats a regulatory-lite distinction between AI\/ML systems that directly affect clients, such as trading recommendations or algorithmic execution, and those used purely for internal operations, suggesting the compliance burden is intended to scale with client-facing risk rather than apply uniformly. Most recently, in May 2026, SEBI issued a specific advisory on the use of emerging, advanced AI tools for vulnerability detection, a signal that the regulator&#8217;s own posture is shifting from passive reporting toward active expectations of how AI should be used defensively, not merely how its use should be disclosed.<\/p>\n<p>For a stockbroker or DP, the practical upshot is that AI\/ML governance is no longer a box-ticking quarterly or half-yearly form. Any deployment of the clustering, graph-analysis, or anomaly-detection capabilities described below now sits within a framework where the firm bears direct responsibility for the tool&#8217;s output and the integrity of the data it processes. The same technologies that answer the control gaps in Section 4 need their own board-approved governance layer before deployment, not as an afterthought.<\/p>\n<p><strong>9.2 Why These Specific Technologies Answer the Gaps Identified Earlier<\/strong><\/p>\n<ul>\n<li>Clustering algorithms are the direct technological answer to the account-opening blind spot in Section 3.5. Identifying accounts that share an address, mobile number, email domain, bank account, or introducer across thousands of applications is a task no manual KYC review can perform at scale but is exactly what unsupervised clustering models are built for. Had this capability existed and been applied in real time in the mid-2000s, the demat scam&#8217;s tens of thousands of fictitious accounts would have been flagged as a cluster within days of opening, not years into an investigation.<\/li>\n<li>Graph and network analysis is the direct answer to the family and related-party blindness described in Section 4. Mapping directors, beneficial owners, shared contact details, and account relationships as a graph, rather than as isolated rows in a KYC database, is precisely how the connection between the two related entities in the cross-segment manipulation case in Section 3.3 was ultimately established, and precisely the kind of analysis that should run continuously and automatically, not only once a regulator&#8217;s own investigation has already begun.<\/li>\n<li>Cross-segment and cross-product anomaly detection, trained across a client&#8217;s full trading footprint rather than one product silo at a time, is the direct answer to the segment-siloed surveillance gap in Section 4. The cross-segment manipulation typology exists specifically because it is invisible to surveillance that watches futures and options independently.<\/li>\n<li>Behavioural and profitability-pattern anomaly detection at the dealer level, flagging when a specific dealer&#8217;s own or family accounts show a statistically abnormal win rate or timing correlation against the firm&#8217;s proprietary book, is the direct answer to the dealer-level front-running typology in Section 3.2, and is a materially harder pattern for a human compliance reviewer to catch through periodic manual sampling alone.<\/li>\n<\/ul>\n<p>The benefits of adopting these technologies, taken together, are speed, scale, and pattern visibility that manual review genuinely cannot match. A clustering model can compare every new demat account against every existing account in seconds. A graph model can surface a four-hop family or corporate connection that a compliance analyst would need hours to trace manually, if they thought to look at all. A well-tuned anomaly detection model reduces the dependence on any single alert threshold being set correctly by a human in advance. None of this replaces human judgment. Consistent with the explainability and human-override principles this series has discussed elsewhere, every model output should remain a prioritised lead for a compliance analyst to investigate, not an automated verdict. And given SEBI&#8217;s shift from disclosure to liability, every model&#8217;s logic and data handling now needs to be documented well enough to satisfy not just the 2019 circular&#8217;s reporting obligation, but the direct responsibility for tool output SEBI&#8217;s February 2025 amendments impose, and the board-approved AI Governance Framework its 2025 consultation paper expects firms to maintain. Given how directly the case studies in this piece trace back to exactly the kind of clustering and cross-referencing these technologies are built to do, the argument for adopting them is not a technology argument. It is the same argument as every case study in Section 3, made in the negative: this is what happens when the analysis these tools perform does not happen at all.<\/p>\n<h3>10. In Summary<\/h3>\n<p>Stockbrokers and DPs sit at the only two chokepoints the Indian securities market has: access to trade, and custody of what was traded. The typologies documented across three years of SEBI enforcement, read alongside the market&#8217;s own foundational history, point back to the same handful of control gaps with striking consistency: unsupervised dealer discretion, account-opening controls that check individuals but not clusters, blindness to family and related-party structures, surveillance that watches one segment at a time, and self-dealing risk in multiple registered entities. None of these gaps require a novel control philosophy to close. They require the risk assessment, internal controls, and governance discipline this piece has set out, applied with the same rigour to a trusted senior dealer&#8217;s account as to an unknown retail client&#8217;s, and increasingly supported by the clustering, graph, and anomaly-detection technologies that can see the connections a manual review, however careful, is structurally unlikely to catch in time.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>References<\/strong><\/p>\n<p>AZB and Partners (2025) &#8216;SEBI Introduces Provisions in Relation to Usage of Artificial Intelligence and Machine Learning Tools by Market Infrastructure Institutions and Registered Intermediaries&#8217;. Available at: https:\/\/www.azbpartners.com\/bank\/sebi-introduces-provisions-in-relation-to-usage-of-artificial-intelligence-and-machine-learning-tools-by-market-infrastructure-institutions-and-registered-intermediaries\/<\/p>\n<p>Bar and Bench (n.d.) &#8216;Supreme Court overrules Securities Appellate Tribunal in IPO scam&#8217;. Available at: https:\/\/www.barandbench.com\/columns\/supreme-court-overrules-securities-tribunal-ipo-scam<\/p>\n<p>Business Standard (2019) &#8216;Sebi asks brokers, depositories using AI tools to make security disclosures&#8217;. Available at: https:\/\/www.business-standard.com\/amp\/article\/markets\/sebi-asks-brokers-depositories-using-ai-tools-to-make-security-disclosures-119010401096_1.html<\/p>\n<p>Chambers and Partners (2025) &#8216;SEBI&#8217;s Framework on Artificial Intelligence (AI) Tools: A Push Towards Accountable AI&#8217;. Available at: https:\/\/chambers.com\/articles\/sebi-s-framework-on-artificial-intelligence-ai-tools-a-push-towards-accountable-ai<\/p>\n<p>Free Press Journal (2026) &#8216;SEBI Bans 7 Individuals In Rs 20 Crore Stock Manipulation Case Linked To Social Media Pump-and-Dump Scheme&#8217;, May 25, 2026. Available at: https:\/\/www.freepressjournal.in\/business\/sebi-bans-7-individuals-in-20-crore-stock-manipulation-case-linked-to-social-media-pump-and-dump-scheme<\/p>\n<p>IIIT Hyderabad JPMC Archive (n.d.) &#8216;IPO scam: Sebi unearths more bogus demat accounts&#8217;. Available at: https:\/\/jpmc.iiit.ac.in\/static\/news_pages\/4289.html<\/p>\n<p>IIIT Hyderabad JPMC Archive (n.d.) &#8216;Sebi cracks the whip, bars 24 players&#8217;. Available at: https:\/\/jpmc.iiit.ac.in\/static\/news_pages\/4283.html<\/p>\n<p>IIIT Hyderabad JPMC Archive (n.d.) &#8216;Sebi fines CDSL, NSDL for lapses in IPO allotment&#8217;. Available at: https:\/\/jpmc.iiit.ac.in\/static\/news_pages\/1958.html<\/p>\n<p>Indian Kanoon (2007) &#8216;Sebi vs Karvy Stock Broking Ltd. on 22 June, 2007&#8217;, Securities Appellate Tribunal. Available at: https:\/\/future.indiankanoon.org\/doc\/127298\/<\/p>\n<p>IndiaCorpLaw (2025) &#8216;From Algorithms to Accountability: Analysing SEBI&#8217;s AI\/ML Governance Framework&#8217;. Available at: https:\/\/indiacorplaw.in\/2025\/07\/16\/from-algorithms-to-accountability-analysing-sebis-ai-ml-governance-framework\/<\/p>\n<p>Moneylife (n.d.) &#8216;SEBI imposes Rs 20 lakh fine on Biren Shah in IPO fraud case&#8217;. Available at: https:\/\/www.moneylife.in\/article\/sebi-imposes-rs20-lakh-fine-on-biren-shah-in-ipo-fraud-case\/30325.html<\/p>\n<p>Moneylife (n.d.) &#8216;SEBI slaps Rs 1.5 crore fine on an individual in IPO fraud case&#8217;. Available at: https:\/\/www.moneylife.in\/article\/sebi-slaps-rs15-crore-fine-on-an-individual-in-ipo-fraud-case\/30474.html<\/p>\n<p>NSDL (2024) Circular No. NSDL\/POLICY\/2024\/0077, June 7, 2024, on SEBI&#8217;s Master Circular on AML\/CFT Standards. Available at: https:\/\/nsdl.co.in\/downloadables\/pdf\/2024-0077-_Policy-SEBI_Master_Circular_on_Guidelines_on_AML_Standards_and_CFT_Obligations_of_Securities_Market_Intermediaries_under_the_PMLA_2002_and_Rules_frame.pdf<\/p>\n<p>NSE (2023) Circular Ref. No. 106\/2023, December 12, 2023, on Change in Submission Timeline for Reporting of AI\/ML Applications and Systems. Available at: https:\/\/nsearchives.nseindia.com\/<\/p>\n<p>SEBI (2019) Circular SEBI\/HO\/MIRSD\/DOS2\/CIR\/P\/2019\/10, January 4, 2019, on Reporting for Artificial Intelligence (AI) and Machine Learning (ML) Applications and Systems Offered and Used by Market Intermediaries. Available at: https:\/\/www.sebi.gov.in\/legal\/circulars\/jan-2019\/reporting-for-artificial-intelligence-ai-and-machine-learning-ml-applications-and-systems-offered-and-used-by-market-intermediaries_41546.html<\/p>\n<p>SEBI (2024) Master Circular SEBI\/HO\/MIRSD\/MIRSDSECFATF\/P\/CIR\/2024\/78, June 6, 2024, on Guidelines on AML\/CFT Standards and Obligations of Securities Market Intermediaries.<\/p>\n<p>SEBI (2025) Notifications dated February 6, 2025, amending the Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) Regulations, 2018 and the SEBI (Intermediaries) Regulations, 2008.<\/p>\n<p>SEBI (2025) Consultation Paper on Responsible Usage of Artificial Intelligence (AI) and Machine Learning (ML) in Indian Securities Markets, June 2025.<\/p>\n<p>SEBI (2026) Master Circular on Surveillance of Securities Market, No. HO\/43\/15\/12(3)2025-ISD-POD2\/I\/11734\/2026, May 15, 2026.<\/p>\n<p>SEBI (2026) &#8216;Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection&#8217;, May 2026. Available at: https:\/\/www.sebi.gov.in\/legal\/circulars\/may-2026\/advisory-on-emerging-advanced-artificial-intelligence-ai-tools-for-vulnerability-detection_101270.html<\/p>\n<p>SEBI (2007) &#8216;Order against Ms. Himani Patel&#8217;, WTM\/GA\/ISD\/42\/11\/07. Available at: https:\/\/www.sebi.gov.in\/enforcement\/orders\/nov-2007\/order-against-ms-himani-patel_8333.html<\/p>\n<p>SEBI (2006) &#8216;Directions under Sections 11 read with 11B of SEBI Act, 1992 in the matter of investigations in respect of Initial Public Offerings against India Bulls Securities Ltd.&#8217;, WTM\/GA\/105\/IVD\/11\/06. Available at: https:\/\/www.sebi.gov.in\/sebi_data\/docfiles\/15671_t.html<\/p>\n<p>Wikipedia (n.d.) &#8216;NSE co-location scam&#8217;. Available at: https:\/\/en.wikipedia.org\/wiki\/NSE_co-location_scam<\/p>\n<p>Wikipedia (n.d.) &#8216;Circular trading&#8217;. Available at: https:\/\/en.wikipedia.org\/wiki\/Circular_trading<\/p>\n<p>Prevention of Money-Laundering Act, 2002 and Rules framed thereunder.<\/p>\n<p>SEBI (Prohibition of Fraudulent and Unfair Trade Practices Relating to Securities Market) Regulations, 2003, as amended.<\/p>\n<p>SEBI Act, 1992, Section 12.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Guarding the Two Gates Every Market Abuser Must Pass Through What SEBI actually requires, what three years of enforcement reveal about how the system gets abused, and what brokers and DPs should be doing about risk assessment, internal controls, governance, and technology 1. Why Brokers and DPs Are the Two Gates Everyone Must Pass Through [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[8],"tags":[],"class_list":["post-1793","post","type-post","status-publish","format-standard","hentry","category-anti-money-laundering"],"_links":{"self":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts\/1793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/comments?post=1793"}],"version-history":[{"count":2,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts\/1793\/revisions"}],"predecessor-version":[{"id":1795,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts\/1793\/revisions\/1795"}],"wp:attachment":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/media?parent=1793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/categories?post=1793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/tags?post=1793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}