F-61, Basement, Bali Nagar, New Delhi-110015. +91 9810910051 mohit@camvm.in

 
     
   
 
 
     
   
 

OTHER > Auditing

DP Concurrent Audit: From Account Opening to Transaction Processing — Understanding the Complete Audit Trail
Category: Auditing, Posted on: 14/08/2026 , Posted By: Geetika Rathore
Visitor Count:24

A practical perspective on key risk-prone areas in CDSL DP operations

A Demat account may appear to be a straightforward way of holding securities electronically. From a compliance and operational perspective, however, a Depository Participant (DP) handles a much wider range of activities—from KYC and account opening to client modifications, issuance and execution of Delivery Instruction Slips (DIS), transaction statements, dematerialisation, pledge, freeze/unfreeze and account closure.

This is why concurrent audit of DP operations plays an important role. Rather than looking only at transactions after the event, concurrent audit provides timely review of specified risk-prone areas and helps identify documentation gaps, processing errors, reconciliation issues and control weaknesses.

In practical terms, the review is not limited to asking whether a transaction was processed. It also considers whether the transaction was properly authorised, supported by appropriate records, correctly processed and traceable across the relevant systems.

Client Instruction → Supporting Documents → Authorisation → System Processing → Depository Records → Reconciliation → Exception Resolution

1. Account Opening: Building the Foundation

The audit trail begins with the opening of the Beneficial Owner (BO) account. This is an important control point because the information captured at account opening forms the basis for the client’s future transactions and servicing.

·        Proof of identity and address

·        KYC documentation and self-attestation

·        Verification of original documents, where applicable

·        PAN verification and correct capture in CDSL

·        In-person verification

·        Photograph and signature verification

·        KRA and CKYCR-related requirements

·        KYC requirements applicable to the category of BO

·        Bank details and other relevant client information

·        FATCA/CRS requirements, where applicable

·        Rights & Obligations document

·        Client Master Report

·        Tariff Sheet

·        POA/DDPI-related controls, where applicable

·        Maker-checker controls

The audit does not stop at checking whether KYC documents are available. It also considers whether the relevant documents and client information have been appropriately verified and whether the information captured in the system agrees with the underlying records.

BSDA and nomination-related controls also form part of the account-opening review. For eligible accounts, the applicable BSDA requirements and the client’s consent, where relevant, need to be considered. Similarly, nomination or the applicable declaration/option relating to nomination should be checked in accordance with the requirements applicable to the account.

2. KYC Validation: Controls Continue After Account Opening

KYC is not simply a one-time account-opening exercise. The audit also considers controls relating to KYC validation and deficiencies identified through the applicable KRA/CKYCR process.

Where KYC records require validation or correction, the DP needs to follow the applicable process before permitting transactions in circumstances where restrictions are required. The review may therefore cover communication of deficiencies, follow-up and relevant freeze/unfreeze controls.

The audit may also cover issues such as disconnected mobile numbers and updation of client details based on valid modification requests. The broader point is that client-data controls continue throughout the life of the BO account.

3. Client Master Modification: Every Change Leaves a Trail

Client information can change during the life of a Demat account. Changes may relate to address, name, signature, bank details, PAN, mobile number, email ID, nomination and other client-master particulars.

From an audit perspective, a modification is more than a system update. The relevant trail should establish what was changed, who requested it, what supporting document or authorisation was available, how it was processed and when the system was updated.

The review therefore considers whether modifications are supported by the appropriate request and whether the updated information is reflected consistently in CDAS and the back-office system, with the applicable communication to the BO. Address changes, bank-detail changes, nomination-related changes, PAN changes and contact-detail changes deserve particular attention.

4. DIS Issuance: Controlling the Instruction Trail

Delivery Instruction Slips (DIS) are an important control point in DP operations. The audit therefore looks beyond the mere availability of DIS booklets and examines the controls around their issuance and inventory.

·        Standardised DIS format

·        Recording of DIS issuance in CDAS

·        Serial-number tracking and account-wise mapping

·        Inventory control and physical verification

·        First DIS booklet issuance

·        Requisition slips

·        Loose DIS, where applicable

·        Undelivered DIS

·        DIS issued to dormant/inactive accounts, where applicable

A strong DIS-control framework helps establish that the instruction instrument issued to the client can be traced from issuance through subsequent use or cancellation/blocking, as applicable.

5. Execution of DIS: From Client Instruction to Securities Transfer

Once a DIS is received, the next stage is execution. The audit considers whether the DIS used for a transaction corresponds with the issuance records and whether the instruction has passed the applicable verification and authorisation controls.

Risk-based checks are particularly important for high-value or sensitive transactions. The audit framework may include additional verification for DIS transactions above the applicable threshold and independent verification of transactions originating from dormant or inactive accounts, where required.

The audit also considers whether executed DIS are scanned/uploaded within the applicable timeline and whether pending scanning or uploading is monitored.

The resulting audit trail can be viewed as:

·        DIS Issued → DIS Received → Instruction Verified → Transaction Executed → DIS Scanned/Uploaded → Records Reconciled

This sequence helps demonstrate that a securities transfer is not treated as an isolated system entry but as a transaction supported by an identifiable instruction trail.

6. E-DIS: Technology Changes the Process, Not the Need for Controls

Electronic instructions change the mode through which clients authorise transactions, but they do not remove the need for proper controls.

Where E-DIS is operational, the review should consider the applicable authorisation, authentication, mandate, transaction records, system logs and reporting controls.

Importantly, audit procedures should be based on the facilities actually operated by the DP. If a particular facility is not offered or was not applicable during the audit period, the relevant section should be treated accordingly rather than assuming that every DP uses the same mechanism.

7. Transaction Statements: Is the Client Receiving Accurate Information?

Transaction and holding statements are another important part of the audit trail. The review considers whether statements generated from the back-office system agree with the corresponding records generated from CDAS and whether the DP maintains adequate evidence of statements sent to BOs.

Where the relevant records differ, the difference should be investigated. The objective is to ensure that the information ultimately communicated to the client is supported by consistent underlying records.

8. Account Closure and Transmission: Completing the Lifecycle

The audit trail does not end with the last transaction. Account closure is also subject to specific controls.

The review may cover the closure request, client authentication, holdings and outstanding items, processing in the system, applicable authorisation and maintenance of supporting records. Where online closure or transfer-cum-shifting processes apply, the relevant procedure should also be considered.

Transmission is a separate and important area, particularly in cases involving the demise of a BO. The audit considers the applicable documentation, processing requirements and relevant reporting mechanisms.

The overall objective is to ensure that an account is not merely marked as closed in one system, but that the closure or transmission process is complete and appropriately reflected across the relevant records.

9. Dematerialisation and Rematerialisation: Tracking Securities Movement

Dematerialisation and rematerialisation involve movement between physical and electronic form and therefore require proper tracking.

The review may cover request forms, securities details, processing status, accepted/rejected requests, pending cases, dispatch and rejection records and compliance with applicable processing timelines.

Pending and rejected requests deserve particular attention because they may point to documentation issues, processing delays or other exceptions. The audit trail should make it possible to understand the status of each request and the action taken on it.

10. Freeze/Unfreeze and Pledge/Unpledge

Freeze and unfreeze activities can directly affect a client’s ability to transact. The audit therefore considers the basis for the freeze, the authority or source of the instruction, the type and scope of freeze, system status and the relevant unfreeze process, where applicable.

Similarly, pledge, unpledge and hypothecation transactions require appropriate controls over creation, release and invocation, as applicable. The relevant client/party details, securities, quantity, authorisation and depository records should be consistent with the transaction processed.

These areas demonstrate why a small system status change can have a significant operational impact and therefore requires an adequate audit trail.

11. Grievances: Another Source of Control Information

Grievance redressal is also relevant to the DP control environment. The review may cover whether BO grievances received through the applicable channels are recorded, monitored and resolved within the prescribed timelines.

Pending grievances and recurring complaints can be particularly useful from an audit perspective because they may highlight operational problems that are not immediately visible through transaction testing alone.

In this sense, grievance records can provide another source of information about the effectiveness of the DP’s processes and client-servicing controls.

12. Back-Office Controls: Keeping Systems in Sync

The back-office system supports many stages of DP operations. The audit therefore considers whether transactions are appropriately uploaded into CDAS, whether the back office is updated for transactions processed in CDAS and whether relevant records remain consistent.

This is important because a mismatch between the back-office system and depository records can create an incomplete or unreliable audit trail.

The key principle is simple: information should not merely exist somewhere in the system. The relevant records should be complete, consistent and capable of reconciliation.

What Does a Good DP Concurrent Audit Actually Achieve?

A DP concurrent audit brings together multiple layers of control:

·        Client Documents

·        Authorisation / Instruction

·        DP Processing

·        CDAS / Back-Office Entry

·        Depository Record

·        Statement / Communication to BO

·        Reconciliation and Exception Handling

At each stage, the objective is to establish a reliable and traceable audit trail.

Where an exception is identified, the focus should not always stop at correcting the individual entry. Repeated observations may indicate a weakness in the underlying process and may require stronger preventive or detective controls.

Conclusion

A Demat account has a much longer operational journey than what a client sees on the screen.

From KYC and account opening to client modifications, DIS issuance, transaction execution, statements, dematerialisation, freeze/unfreeze, pledge, transmission and account closure, every stage creates records that need to work together.

This is the real value of DP concurrent audit. It provides timely review of risk-prone areas and helps ensure that client instructions are properly supported, transactions are processed through appropriate controls, records across systems remain consistent and exceptions are identified and addressed.

Ultimately, DP concurrent audit is not just about finding mistakes. It is about making sure that important client activities are properly authorised, accurately processed, traceable and supported by an adequate audit trail.

That is what turns concurrent audit from a routine compliance exercise into a meaningful risk and control mechanism for protecting client interests and strengthening DP operations.


To Activate comments you need to provide details for google authentication and facebook authentication
 
     
201290 Times Visited