Capital Market • Information Systems Audit ICAI Journal Ref: June 2021 • Vol. 69 • No. 12 • pp. 20–24 (1432–1436) SEBI KRA Regulations • Cyber Resilience • VAPT • DISA / CISA

Information System (IS) Audit of KRAs – Capital Market

SP
Dr. P. Siva Rama Prasad
Expert in Finance • cma.psrprasad@gmail.com • eboard@icai.in

“KYC Registration Agency (KRA) is an agency Registered with Securities Exchange Board of India under the SEBI-KYC (Know Your Client) Registration Agency Regulations, 2011. KRAs have to maintain KYC documents of all investors in a Centralized IT System, on behalf of Capital Market in India through different Intermediaries that are Registered with SEBI. KYC Registration Agencies (KRAs) play a vital role in maintaining KYC documents of various clients of Securities Market, verify and store documents submitted by the clients through various Intermediaries of Securities Market in India. Read on…”

1 Cyber Security System, Cyber Resilience Structure & CIA Triad

It is required that KRAs should have the High-Quality Cyber Security System and Cyber Resilience Structure in order to provide indispensable IT facilities and execute the process of systemically risky functions relating to Capital or Securities Market.

Cyber-attacks and threats attempt to conciliation of confidentiality, integrity and availability i.e., CIA of the information technology systems, network systems and data stored in databases in servers:

Confidentiality:

Means to prevent the access of computer systems by unauthorised persons and the information to be available only to the authorized users of the organization.

Integrity:

The guarantee that the information is dependable and correct in all respects that is stored in the computer system.

Availability:

Refers to the assurance of reliable access of computer systems and information by authorized users of the IT systems of the organization timely, i.e., as and when they require.

Cyber security framework includes procedures, tools and processes that are identified to prevent the access of cyber-attacks by unscrupulous persons and to improve the cyber pliability of the organization’s IT systems. Cyber resilience is an organisation’s ability to prepare or develop the various IT tools and to respond to a cyber-attack on IT systems instantly with less human intervention, automatic and to continue action during, and improve and recover of IT systems from the cyber-attacks.

2 SEBI Regulatory Mandate & Registered KRAs in India

Section 11 (1) of the Securities and Exchange Board of India Act, 1992 defines to protect the interests of all types of investors of securities market and to promote the healthy development of, and to regulate the securities market and to maintain good governance.

Earlier investors have to complete the KYC procedures as and when they approach each type of SEBI intermediary and submit the relevant KYC documents and procedures of each intermediary may vary from one to another due to lack of non-adherence of the standard and common guidelines that are issued by SEBI to all the intermediaries. This creates a lot of inconvenience to investors and they face many problems like missing of unique system not adopted by the intermediaries uniformly, sometimes it leads to duplication, additional cost and time to the prospective investors.

In view of these challenges and also to eliminate such problems of KYC process to be executed by the investors and to have a uniform KYC process across SEBI registered intermediaries, SEBI has introduced the concept of KYC Registration Agency (KRA). As on date the following are registered with SEBI as KRAs:

  • DotEx International Ltd: A unit of the National Stock Exchange of India Ltd (NSE).
  • Karvy Data Management Services Ltd. (KDMS): Registered KRA.
  • NSDL Database Management Limited: A fully owned subsidiary of National Securities Depository Ltd. (NSDL).
  • CAMS KRA: Set up by Computer Age Management Services (CAMS).
  • CDSL Ventures Limited (CVL): A division of Central Depository Services (India) Limited.

This enables an investor to invest / trade through various intermediaries, after undergoing onetime KYC process through any intermediary at initial stage. Additionally, if there are any subsequent changes in investor’s KYC information, i.e., static or dynamic or demographic, the investor can approach any one of SEBI Registered intermediary and request change which can be made by intermediary after verification with changes made in the IT system. The originals (subsequent change documents) are submitted to the KRAs by any one of the registered intermediaries of SEBI.

3 Roles and Obligations: KRAs vs. Intermediaries

Role of KRAs

  • KRAs are responsible for storing, safeguarding and retrieving the KYC documents submitted by the clients through various intermediaries.
  • KRAs have to retain the original KYC documents submitted by the clients both in physical and electronic form like cheque truncation system of the banks. These KYC documents are preserved for a period as per the guidelines issued by SEBI.
  • Clients common KYC information to be shared or disseminated to all the intermediaries by the KRA through the IT system.
  • Establish inter-operability among KRAs through electronic connectivity.
  • Have a system to send acknowledgement to the clients of various Intermediaries after receipt and verification of the KYC documents.

Roles and Obligations of Intermediaries

  • Intermediaries shall perform the initial KYC / due diligence of the client and upload the KYC information / documents in IT System of KRA and arrange to send the original KYC documents to KRA within the prescribed time.
  • When client approaches different intermediary later on, intermediaries need to verify the client’s details from the system of KRAs or if warrants obtain fresh KYC from the clients.
  • On receipt of information on change in KYC details from the clients by intermediary, he is responsible for uploading the revised KYC information on the system of KRA and send the physical KYC documents to KRA.
  • Intermediary have the ultimate responsibility for the KYC documents of its clients with the risk profile of its clients.

4 IS Audit Mandate and Auditor Empanelment Qualifications

On annual basis the IS auditors are to audit the KRAs as Registered with SEBI. As per the Guidelines issued by SEBI, qualifications that are required for empanelled IS Auditors are CERT-In empanelment, independent auditor status, and any of the following qualifications:

DISA (ICAI): Diploma of Information Systems Auditor from The Institute of Chartered Accountants of India.
CISA (ISACA): Certified Information System Auditor from Information Systems Audit and Control Association.
CISM (ISACA): Certified Information Securities Manager from ISACA.
CISSP (ISC-2): Certified Information Systems Security Professional from International Information Systems Security Certification Consortium.

Reporting Timeline: IS Auditors have to verify compliance and submit the IS Audit Report to the Securities and Exchange Board of India (SEBI) along with audit remarks of the Board of KYC Registration Agencies within three months from the end of each financial year.

5 Checklist for IS Auditors to Audit KRAs

The objective of IS Audit is to check the Cyber Security and Cyber Resilience Policy of the KRAs across five core functional domains:

Identify
Protect
Detect
Respond
Recover

a) Identify: Critical Assets and Threat Modeling

  • Identify critical assets based on sensitivity and criticality of business operations, services and data management of KRAs.
  • Identify threats and vulnerabilities of cyber risks and control measures taken by KRAs.
  • If third-party service providers are providing various services to KRAs, check whether they are following similar Standards of Information Security.

b) Protect: Detailed Security Controls

i. Access Controls

  • Check any person other than authorised officials has access to confidential data, applications, system resources or facilities.
  • Check whether KRAs are granted access to IT Systems on need-based approach and defined period with strong authentication mechanisms.
  • Check whether KRA implements strong password controls to access IT systems by authorised users.
  • Check whether KRAs maintain access logs of IT systems preserved for not less than two years.
  • Check whether access lock policy after failed attempts is implemented.
  • Check whether outsourced staff/vendors accessing the system are subject to stringent supervision, monitoring and access restrictions.
  • Check whether two-factor authentication (2FA) at log-in is implemented by KRAs.
  • Check whether IDs of employees who worked earlier or retired are withdrawn from the IT System i.e., “End of Life” Mechanism.

ii. Physical Security

  • Check whether KRAs allow access to critical systems by outsourced staff / visitors, etc.
  • Check whether access to physical systems is revoked if there is no need.
  • Check whether KRAs implemented CCTVs, CARD access systems, security guards, mantraps, bollards wherever required to enter system rooms.

iii. Network System Management

  • Check whether KRAs conduct regular enforcement checks to ensure baseline standards uniformly.
  • Check whether KRAs introduced firewalls as well as intrusion detection systems to prevent viruses and threats.
  • Check whether anti-virus scanning happens on regular basis and updated versions are available.

iv. Data Security

  • Check whether KRAs use strong encryption methods like Advanced Encryption Standard (AES), RSA, SHA-2, etc.
  • Check whether IT systems prevent unauthorised persons from copying and transmitting stored data/information.
  • Check whether information security policy covers mobile phones, photocopiers, scanners to capture and transmit data.
  • Check whether KRAs allow authorized data storage devices to capture data with appropriate validation process.

v. Hardware and Software

  • Check whether hardened and vetted hardware/software is used by KRAs.
  • Check whether default passwords are replaced with strong passwords during hardening process.
  • Check whether all open ports are blocked to avoid exploitation of data from IT systems.

vi. Application Programmes Security and Testing

  • Check whether KRAs are using regression testing before new or modified systems are implemented.

vii. Patches Management of Software

  • Check whether KRAs implement security patches in time, with verification (identification, categorisation, and prioritisation).
  • Check whether rigorous testing is conducted before deployment in the production environment.

viii. Disposal of Storage Devices and IT Systems

  • Check whether KRAs use methods like wiping, cleaning, overwriting, degaussing, and physical destruction for disposal.

ix. Vulnerability Assessment and Penetration Testing (VAPT)

  • Check whether KRAs conduct VAPT tests in the IT environment at least once in a year.
  • Check whether KRAs take prompt remedial measures for identified vulnerabilities.
  • Check whether KRAs perform vulnerability scanning and penetration tests prior to installation of new IT systems and providing internet access.

c) Detection and Monitoring

  • Check whether appropriate security monitoring systems detect unauthorised/malicious activities, changes, access, or copying.
  • Check whether KRAs implement suitable mechanisms to monitor capacity utilization of networks and critical systems.
  • Check whether suitable alerts are generated upon detection of unauthorised or abnormal system activities.

d) Recovery and Response

  • Check whether alerts are generated in case of cyber-attack or breach, and suitable eradication systems are in place.
  • Check whether timely restoration of systems is achieved, adhering to SEBI-defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
  • Check whether a response plan defines employee and outsourced staff responsibilities during attacks.
  • Check whether any loss or destruction of data happened and if preventive action plans are prepared.
  • Check whether KRAs conduct periodic drills to test the adequacy and effectiveness of the recovery plan.

e) Information Sharing & f) Staff Training

Information Sharing: Check whether KRAs submit quarterly reports on cyber-attacks and mitigation measures to SEBI regularly (enabling SEBI to share incident alerts with other KRAs).
Staff Training: Check whether periodic training programmes cover SEBI IT/cyber security policies for staff, vendors, and outsourced personnel; whether special focus is provided to non-technical staff; and whether training modules are reviewed and updated regularly.

6 Conclusion

“Technology is a key game changer in financial services as it cannot only provide fast and better services to the consumer, it can also be a catalyst in improving the ease of doing business.” – Shri Ajay Tyagi, Chairman, SEBI

KYC registration agencies (KRAs) play a vital role in maintaining KYC documents of various clients of securities market. Through annual Information Systems Audit (IS Audit), it is not only possible to strengthen the good governance of access controls, network controls and data security of IT systems of KRAs, but also it is also possible to prevent cyber-attacks on IT systems.

About the Author

Dr. P. Siva Rama Prasad
Expert in Finance & Capital Market Systems
Email: cma.psrprasad@gmail.com • eboard@icai.in