Skip to main content

InsightPublished

FY 2026–27 Compliance Planning for Market Intermediaries: Why the Old Compliance Calendar Is No Longer Enough

Compliance Planning, FY 2026-27, SEBI, Stock Brokers, Depository Participants, AIF, Mutual Funds, Research Analysts, Investment Advisers, Regulatory Change Management, Compliance Calendar, Cybersecurity, Governance

  • compliance planning
  • fy 2026-27
  • sebi
  • stock brokers
  • depository participants
  • mutual funds
FY 2026–27 Compliance Planning for Market Intermediaries: Why the Old Compliance Calendar Is No Longer Enough | CompliSense

FY 2026–27 needs more than another compliance calendar. SEBI’s recent changes show why firms must now plan around implementation, systems, evidence, events and regulatory change—not only due dates.

1. A New Financial Year Should Not Begin by Copying Last Year’s Compliance Calendar

For many Compliance teams, 1 April still begins with a familiar exercise: take last year’s compliance calendar, roll the dates forward, add a few new circulars and circulate the updated tracker. That approach was manageable when a large part of compliance consisted of periodic filings, certifications, audits and fixed regulatory dates. It is becoming increasingly inadequate.

The developments leading into FY 2026–27 demonstrate why. SEBI is simultaneously removing redundant reporting, introducing controls directly into digital platforms, prescribing system-level investor protections, strengthening evidence around operational processes and creating obligations that arise when an event occurs rather than on a pre-determined calendar date.

A compliance plan for FY 2026–27 therefore cannot simply answer, “What is due and when?” It also needs to answer: what has changed, which process must change with it, who owns that process, what system dependency exists, and how will the organisation prove implementation?

That is a fundamentally different exercise.

2. Some Obligations Are Disappearing—and That Also Requires Compliance Work

One of the most useful signals came from SEBI’s 23 March 2026 stock-broker circular. From 17 April, brokers no longer separately report their demat accounts to stock exchanges; depositories will provide the relevant account-opening and closure information directly. At the same time, account nomenclature and other underlying controls continue to apply.

This is an important example of what FY 2026–27 planning should look like. Regulatory change management is not only about adding obligations. Compliance teams also need a formal process for retiring them.

Otherwise, firms accumulate what could be called zombie compliance: discontinued filings remain in trackers, employees continue producing unnecessary reports, SOPs cite superseded provisions and automated reminders continue triggering because nobody formally decommissioned the old obligation.

Every annual planning exercise should therefore ask not only “What is new?”, but also “What should we stop doing?”

3. Other Changes Cannot Be Managed by a Calendar at All

Consider SEBI’s revised framework for creation and invocation of pledges through depositories. Depositories were required to implement the revised requirements by 6 April 2026, including standardised Pledge Request Forms, prescribed undertakings and notifications upon invocation.

A calendar can remind Compliance that 6 April exists. It cannot ensure that physical forms have been replaced, digital workflows capture the new undertakings, notification systems work correctly or the complete transaction trail can later be produced.

The same problem arises with the social-media disclosure framework effective 1 May 2026. SEBI-regulated entities and their agents must display relevant registration details on their social-media presence and at the beginning of securities-market-related content.

That requirement belongs partly to Compliance, but implementation sits across Marketing, Digital, Legal, agencies and potentially agents or distributors. There is no meaningful way to manage it through a line item saying “Social-media disclosure – 1 May.”

The compliance plan needs to contain the implementation project behind the date.

4. The New Compliance Calendar Needs an “Evidence Layer”

Cybersecurity makes this shift particularly visible. Under the CSCRF-driven VAPT process, identifying a vulnerability is only the beginning. The institution must remediate findings, support closure with evidence, obtain revalidation where required and move the result through the relevant governance process.

CDSL’s March 2026 operating framework also illustrates the consequences of treating cyber closure casually: its DP Operating Instructions prescribe penalties for non-submission of VAPT/compliance reports and for vulnerabilities remaining open beyond stipulated timelines, with stronger consequences possible for unresolved High or Medium vulnerabilities.

The compliance tracker of the past might contain:

VAPT Report – Completed

The FY 2026–27 control should instead be capable of showing:

Finding → Risk → Owner → Remediation → Evidence → Revalidation → Approval → Closure

The distinction matters because regulators increasingly care not only whether an activity was performed, but whether the institution can demonstrate the control actually worked.

5. Annual Compliance Is Also Becoming More Structured

The start of FY 2026–27 creates another opportunity: plan annual assurance work now rather than assembling evidence near the deadline.

For Research Analysts and Investment Advisers, SEBI’s framework requires annual compliance audits to be completed within six months from the end of the financial year, followed by submission of the audit report within the prescribed period. SEBI’s 25 March clarifications also expanded the eligible professional pool by expressly recognising members of the Institute of Cost Accountants of India for these audits.

For AIFs, March brought an important restructuring of regulatory reporting. AIFs are now required to submit a comprehensive Annual Activity Report within 30 calendar days from the end of March, while a limited Quarterly Activity Report operates for the other quarters, with the first such quarterly report for the quarter ending June 2026.

These are not just dates to add to April and September. The better question at the start of the year is: what evidence will the auditor or regulator require, and are we generating it continuously?

If Compliance spends September reconstructing records from six months of emails, the annual planning process has already failed.

6. FY 2026–27 Also Needs an Implementation Watchlist

Not every regulatory development should immediately become a compliance task. Some should become watchlist items.

SEBI’s March Board meeting approved several significant changes that require further regulatory or operational steps, including changes to the fit-and-proper framework, AIF winding-up arrangements and FPI settlement architecture. Mutual-fund borrowing provides another useful example: SEBI issued the framework on 13 March but subsequently deferred applicability of the intraday-borrowing provisions after industry representations regarding operational challenges.

This is where many compliance calendars become noisy. A Board decision, consultation paper, circular, effective requirement and exchange operating instruction are treated as though they were the same thing.

They are not.

The FY 2026–27 plan should distinguish between Regulatory Watch → Implementation Preparation → Active Obligation. That prevents premature tasks while ensuring major changes are not forgotten until the implementation circular arrives.

26-27

7. Build the FY 2026–27 Plan Around Five Questions

Rather than beginning with dates, Compliance Officers should challenge every material requirement through five questions:

  • What changed? New obligation, relaxation, clarification or replacement?
  • Who actually owns it? Compliance, Operations, Technology, Finance, Marketing, HR, Legal or a combination?
  • What must change operationally? Filing, SOP, system rule, client communication, contract, data field or approval process?
  • What proves completion? Filing acknowledgement, screenshot, configuration evidence, audit report, approval, log or published record?
  • What could trigger it again? Calendar date, transaction, incident, personnel change, threshold breach, new account or regulatory event?

That final question is increasingly important. A modern compliance framework needs both recurring obligations and event-based controls.

8. The Real FY 2026–27 Reset

The strongest Compliance teams will not start this year by producing a bigger spreadsheet.

They will begin by reconciling the regulatory universe, retiring superseded obligations, separating watchlist items from active requirements, identifying system changes, allocating cross-functional ownership and defining the evidence expected at closure.

The new planning model is closer to:

Regulatory Change → Applicability → Owner → Implementation → Evidence → Monitoring → Reassessment

The calendar still matters. Due dates still matter.

But they are now only one part of the compliance architecture.

For FY 2026–27, the real objective should be to ensure that by the time a deadline appears on the calendar, most of the compliance work has already happened.

Related compliance hubs

Continue from this explainer into topic hubs that connect analysis with regulator updates and workflow context.

Related regulator archives

Continue into source-linked archives for regulators connected to this topic area.

Related articles

Continue with related analysis selected by the editorial team or sharing the same topics.

Related legal updates

Source-linked updates that place this article in the current regulatory workflow.

Content accountability

Prepared by CompliSense Editorial Desk (Regulatory Content Team) and reviewed by CompliSense Regulatory Review Desk (Compliance Review Team).

This attribution reflects the preparation and review roles used for CompliSense regulatory publishing.

Continue evaluation