๐ข FINAL CIRCULAR โ IN FORCE
Issued by: SEBI ย |ย Date: August 20, 2026 ย |ย Effective: Immediately, from August 20, 2026
SEBI Enables KYC Data Sharing Between KRAs and IFSCA-Regulated Entities (2026)
Entities operating out of India's International Financial Services Centres โ GIFT City being the obvious example โ have historically sat in a KYC silo of their own, regulated by IFSCA rather than SEBI. SEBI's circular dated August 20, 2026 changes that in one narrow but useful way: it opens up the KYC Registration Agency (KRA) system to entities regulated by the International Financial Services Centres Authority (IFSCA), letting them tap into the same centralised KYC records that SEBI-regulated intermediaries already rely on.
The mechanism SEBI uses is a specific one. Regulation 16A(1) of the SEBI {KYC (Know Your Client) Registration Agency} Regulations, 2011 already permits entities regulated by "other regulators in the financial sector" to access the KRA system โ but only once SEBI formally specifies which regulators qualify. This circular is that specification, naming IFSCA for the first time.
For KRAs, the change is operational: a new category of institution can now legitimately request access to the KRA system, and KRAs need to know exactly what rules govern that access before granting it.
What Is Regulation 16A(1), and Why Does It Matter Here?
The SEBI KRA Regulations, 2011 govern how KYC Registration Agencies collect, store, and share client KYC data within the securities market ecosystem. Regulation 16A(1) is the specific gateway provision that allows this data to be shared outside SEBI's own regulatory perimeter โ but only with entities regulated by other financial-sector regulators that SEBI has expressly named.
๐ In Plain English โ What Is a KRA, and What Does Regulation 16A(1) Do?
A KRA is a SEBI-registered agency that holds and verifies KYC records for investors in the securities market, so an investor doesn't have to repeat KYC every time they open an account with a new intermediary. Regulation 16A(1) works like a permission list โ an outside regulator's entities can only tap into this shared KYC pool once SEBI puts that regulator's name on the list. Before this circular, IFSCA wasn't on that list; now it is.
Regulation 16A(1), SEBI KRA Regulations, 2011: entities regulated by other financial-sector regulators that SEBI specifies from time to time may access the KRA system to carry out KYC of clients who engage them for financial services.
๐ In Plain English โ Who Is IFSCA?
The International Financial Services Centres Authority is the unified regulator for banking, capital markets, insurance, and fund management activity within India's International Financial Services Centres (IFSCs), such as GIFT City in Gujarat. It functions somewhat like SEBI, RBI, and IRDAI combined โ but only for entities operating within an IFSC.
What Exactly Has SEBI Specified in This Circular?
The operative decision is narrow and precise: SEBI has specified IFSCA for the purpose of Regulation 16A(1), "in order to enable interoperability and to facilitate sharing of information between SEBI registered KRAs and entities regulated by IFSCA." In effect, IFSCA-regulated entities โ think banking units, fund managers, and other financial intermediaries operating in GIFT City โ can now approach KRAs to access existing KYC records for clients who also engage them for financial services, rather than collecting KYC documentation from scratch.
โ ๏ธ What This Circular Does Not Do
This is a specification of IFSCA as an eligible regulator under Regulation 16A(1) โ it does not create a new KYC framework, does not amend the SEBI KRA Regulations themselves, and does not grant IFSCA-regulated entities any exemption from KYC compliance. Access comes bundled with obligations, covered next.
What Rules Must IFSCA-Regulated Entities Follow When Accessing the KRA System?
Access to the KRA system is not unconditional. Under Regulation 16A(2) of the SEBI KRA Regulations, any entity accessing the KRA system โ IFSCA-regulated or otherwise โ becomes fully subject to the SEBI KRA Regulations for that purpose. The circular layers three specific compliance requirements on top of that:
1๏ธโฃ Full applicability of SEBI KRA Regulations
Per Regulation 16A(2), IFSCA-regulated entities accessing the KRA system are bound by the SEBI KRA Regulations, 2011 in full โ the same framework that governs any other entity using the KRA system.
2๏ธโฃ General KYC Master Circular
All such entities must follow SEBI's Master Circular on KYC norms for the securities market dated October 12, 2023, as amended from time to time.
3๏ธโฃ FPI-specific Data Security norms
Where the client is registered as a
Foreign Portfolio Investor, these entities must additionally follow the Data Security guidelines in SEBI's FPI Master Circular dated May 30, 2024.
๐ In Plain English โ Why the Extra FPI Layer?
FPI KYC data is treated as more sensitive than standard domestic investor KYC, partly because it often includes cross-border ownership and beneficial-owner information. SEBI is making sure that even though IFSCA-regulated entities are getting a new door into the KRA system, that door doesn't become a weaker point for FPI data specifically โ the same Data Security standards that apply to DDPs and Custodians handling FPI KYC apply here too.
Legal Basis and Effective Date of the SEBI-IFSCA KRA Circular
The circular is issued under Section 11(1) of the SEBI Act, 1992, read with Regulation 16A(1) of the SEBI KRA Regulations, 2011 โ SEBI's standing powers to protect investors and regulate the securities market. It was issued with the approval of the Competent Authority and takes effect immediately, with no phased rollout or transition window.
Compliance Checklist
โ Update access protocols โ KRAs should update onboarding and access-control processes to recognize IFSCA-regulated entities as a permitted user category under Regulation 16A(1).
โ Apply the standard KYC framework โ Ensure IFSCA-regulated entities accessing the system are held to SEBI's Master Circular on KYC norms dated October 12, 2023, exactly as any other accessing entity would be.
โ Flag FPI clients for extra data security checks โ Build a process check for cases where the underlying client is an FPI, triggering the Data Security requirements of the FPI Master Circular dated May 30, 2024.
โ Confirm entity is genuinely IFSCA-regulated โ Verify the requesting entity's regulatory status with IFSCA before granting KRA system access, since the circular's permission is scoped specifically to IFSCA-regulated entities.
โ Update internal compliance manuals โ Record this specification against Regulation 16A(1) of the SEBI KRA Regulations, 2011, for audit and inspection purposes.
โ No transition period to track โ The circular is effective immediately from August 20, 2026; there is no staggered timeline to build into a compliance calendar.
Frequently Asked Questions
What does SEBI's August 20, 2026 circular on KRAs and IFSCA do?
It specifies the International Financial Services Centres Authority (IFSCA) under Regulation 16A(1) of the SEBI KRA Regulations, 2011, permitting entities regulated by IFSCA to access the KRA system and enabling SEBI-registered KRAs to share client KYC information with them.
What is Regulation 16A(1) of the SEBI KRA Regulations?
It is a provision that allows entities regulated by other financial sector regulators, once specified by SEBI, to access the KRA system to undertake KYC of clients who engage them for financial services.
Which regulator has been newly specified under this provision?
The International Financial Services Centres Authority (IFSCA), the regulator for financial services and products in India's International Financial Services Centres such as GIFT City.
Do IFSCA-regulated entities have to follow SEBI's KYC rules when accessing the KRA system?
Yes. Under Regulation 16A(2) of the SEBI KRA Regulations, all such entities are fully subject to the SEBI KRA Regulations and must follow SEBI's Master Circular on KYC norms for the securities market dated October 12, 2023.
Are there additional requirements for FPI clients?
Yes. Where the client is registered as a Foreign Portfolio Investor, IFSCA-regulated entities accessing the KRA system must also follow the Data Security guidelines specified in SEBI's FPI Master Circular dated May 30, 2024.
When does this circular take effect?
The circular takes effect immediately, from August 20, 2026, the date of issue, and was issued with the approval of the Competent Authority.
Under what legal authority was this circular issued?
It was issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992, read with Regulation 16A(1) of the SEBI KRA Regulations, 2011.
What should KRAs do now?
KRAs should update their access-control and data-sharing protocols to recognize IFSCA-regulated entities as permitted users of the KRA system, subject to the same KYC and data security safeguards that apply to other regulated entities.
CorpLawUpdates Analysis
This circular is small in text but meaningful in intent. Regulation 16A(1) has existed since 2011 as an interoperability provision that only takes effect once SEBI names a qualifying regulator โ and this circular is the specification we're currently aware of that does so, naming IFSCA. It signals SEBI's willingness to treat India's IFSC ecosystem as a genuine extension of the domestic securities market for KYC purposes, rather than a walled-off jurisdiction.
The practical upside is duplication avoidance. An investor who already has KYC on file with a KRA โ because they deal with a SEBI-regulated intermediary โ won't need to be KYC'd from scratch again if they also engage an IFSCA-regulated entity in GIFT City. That's a genuine efficiency gain for investors operating across both ecosystems, and for the IFSCA-regulated entities themselves, who can now onboard faster.
The compliance challenge sits with the KRAs. They now need a reliable way to verify that a requesting entity is genuinely IFSCA-regulated before granting access โ the circular doesn't specify a verification mechanism, which suggests KRAs will need to build or adapt one, likely in coordination with IFSCA's own entity registers. The layered obligation for FPI clients also means KRAs can't treat this as a blanket "grant access and done" exercise; access has to be conditioned on the nature of the underlying client.
Looking ahead, this specification is unlikely to be the last of its kind. Regulation 16A(1) was written broadly enough to accommodate multiple regulators, and as India's regulatory perimeter around fintech, insurance, and pension intermediaries continues to interact more closely with SEBI's securities market ecosystem, similar specification circulars for other regulators would not be surprising.
Source: SEBI Circular "Enabling sharing of information by KYC Registration Agencies (KRAs) with entities regulated by International Financial Services Centres Authority," Ref. No. HO/38/15/(7)2026-MIRSD-POD/I/19255/2026, dated August 20, 2026. Signed by Vishal Mahadev Padole, General Manager, SEBI. Available at www.sebi.gov.in under "Legal โ Circulars." Contact: Tel 022-26449247, Email
[email protected].
This article is for informational and educational purposes only and does not constitute legal or regulatory advice. Verify with primary regulatory sources before acting.