A practical perspective on key risk-prone areas in
CDSL DP operations
A Demat account may appear to be a
straightforward way of holding securities electronically. From a compliance and
operational perspective, however, a Depository Participant (DP) handles a much
wider range of activities—from KYC and account opening to client modifications,
issuance and execution of Delivery Instruction Slips (DIS), transaction
statements, dematerialisation, pledge, freeze/unfreeze and account closure.
This is why concurrent audit of DP
operations plays an important role. Rather than looking only at transactions
after the event, concurrent audit provides timely review of specified
risk-prone areas and helps identify documentation gaps, processing errors,
reconciliation issues and control weaknesses.
In practical terms, the review is not
limited to asking whether a transaction was processed. It also considers
whether the transaction was properly authorised, supported by appropriate
records, correctly processed and traceable across the relevant systems.
Client Instruction → Supporting Documents →
Authorisation → System Processing → Depository Records → Reconciliation →
Exception Resolution
1. Account Opening: Building the Foundation
The audit trail begins with the opening of
the Beneficial Owner (BO) account. This is an important control point because
the information captured at account opening forms the basis for the client’s
future transactions and servicing.
·
Proof of identity and address
·
KYC documentation and
self-attestation
·
Verification of original
documents, where applicable
·
PAN verification and correct
capture in CDSL
·
In-person verification
·
Photograph and signature
verification
·
KRA and CKYCR-related
requirements
·
KYC requirements applicable to
the category of BO
·
Bank details and other relevant
client information
·
FATCA/CRS requirements, where
applicable
·
Rights & Obligations
document
·
Client Master Report
·
Tariff Sheet
·
POA/DDPI-related controls,
where applicable
·
Maker-checker controls
The audit does not stop at checking whether
KYC documents are available. It also considers whether the relevant documents
and client information have been appropriately verified and whether the
information captured in the system agrees with the underlying records.
BSDA and nomination-related controls also form part of the account-opening
review. For eligible accounts, the applicable BSDA requirements and the
client’s consent, where relevant, need to be considered. Similarly, nomination
or the applicable declaration/option relating to nomination should be checked
in accordance with the requirements applicable to the account.
2. KYC Validation: Controls Continue After Account Opening
KYC is not simply a one-time
account-opening exercise. The audit also considers controls relating to KYC
validation and deficiencies identified through the applicable KRA/CKYCR
process.
Where KYC records require validation or correction, the DP needs to follow the
applicable process before permitting transactions in circumstances where
restrictions are required. The review may therefore cover communication of
deficiencies, follow-up and relevant freeze/unfreeze controls.
The audit may also cover issues such as disconnected mobile numbers and
updation of client details based on valid modification requests. The broader
point is that client-data controls continue throughout the life of the BO
account.
3. Client Master Modification: Every Change Leaves a Trail
Client information can change during the
life of a Demat account. Changes may relate to address, name, signature, bank
details, PAN, mobile number, email ID, nomination and other client-master
particulars.
From an audit perspective, a modification is more than a system update. The
relevant trail should establish what was changed, who requested it, what
supporting document or authorisation was available, how it was processed and
when the system was updated.
The review therefore considers whether
modifications are supported by the appropriate request and whether the updated
information is reflected consistently in CDAS and the back-office system, with
the applicable communication to the BO. Address changes, bank-detail changes,
nomination-related changes, PAN changes and contact-detail changes deserve
particular attention.
4. DIS Issuance: Controlling the Instruction Trail
Delivery Instruction Slips (DIS) are an
important control point in DP operations. The audit therefore looks beyond the
mere availability of DIS booklets and examines the controls around their
issuance and inventory.
·
Standardised DIS format
·
Recording of DIS issuance in
CDAS
·
Serial-number tracking and
account-wise mapping
·
Inventory control and physical
verification
·
First DIS booklet issuance
·
Requisition slips
·
Loose DIS, where applicable
·
Undelivered DIS
·
DIS issued to dormant/inactive
accounts, where applicable
A strong DIS-control framework helps
establish that the instruction instrument issued to the client can be traced
from issuance through subsequent use or cancellation/blocking, as applicable.
5. Execution of DIS: From Client Instruction to Securities
Transfer
Once a DIS is received, the next stage is
execution. The audit considers whether the DIS used for a transaction
corresponds with the issuance records and whether the instruction has passed
the applicable verification and authorisation controls.
Risk-based checks are particularly important for high-value or sensitive
transactions. The audit framework may include additional verification for DIS
transactions above the applicable threshold and independent verification of
transactions originating from dormant or inactive accounts, where required.
The audit also considers whether executed DIS are scanned/uploaded within the
applicable timeline and whether pending scanning or uploading is monitored.
The resulting audit trail can be viewed as:
·
DIS Issued → DIS Received →
Instruction Verified → Transaction Executed → DIS Scanned/Uploaded → Records
Reconciled
This sequence helps demonstrate that a
securities transfer is not treated as an isolated system entry but as a
transaction supported by an identifiable instruction trail.
6. E-DIS: Technology Changes the Process, Not the Need for
Controls
Electronic instructions change the mode
through which clients authorise transactions, but they do not remove the need
for proper controls.
Where E-DIS is operational, the review should consider the applicable
authorisation, authentication, mandate, transaction records, system logs and
reporting controls.
Importantly, audit procedures should be based on the facilities actually
operated by the DP. If a particular facility is not offered or was not
applicable during the audit period, the relevant section should be treated
accordingly rather than assuming that every DP uses the same mechanism.
7. Transaction Statements: Is the Client Receiving
Accurate Information?
Transaction and holding statements are
another important part of the audit trail. The review considers whether
statements generated from the back-office system agree with the corresponding
records generated from CDAS and whether the DP maintains adequate evidence of
statements sent to BOs.
Where the relevant records differ, the difference should be investigated. The
objective is to ensure that the information ultimately communicated to the
client is supported by consistent underlying records.
8. Account Closure and Transmission: Completing the
Lifecycle
The audit trail does not end with the last
transaction. Account closure is also subject to specific controls.
The review may cover the closure request, client authentication, holdings and
outstanding items, processing in the system, applicable authorisation and
maintenance of supporting records. Where online closure or
transfer-cum-shifting processes apply, the relevant procedure should also be
considered.
Transmission is a separate and important area, particularly in cases involving
the demise of a BO. The audit considers the applicable documentation,
processing requirements and relevant reporting mechanisms.
The overall objective is to ensure that an account is not merely marked as
closed in one system, but that the closure or transmission process is complete
and appropriately reflected across the relevant records.
9. Dematerialisation and Rematerialisation: Tracking
Securities Movement
Dematerialisation and rematerialisation
involve movement between physical and electronic form and therefore require
proper tracking.
The review may cover request forms, securities details, processing status,
accepted/rejected requests, pending cases, dispatch and rejection records and
compliance with applicable processing timelines.
Pending and rejected requests deserve particular attention because they may
point to documentation issues, processing delays or other exceptions. The audit
trail should make it possible to understand the status of each request and the
action taken on it.
10. Freeze/Unfreeze and Pledge/Unpledge
Freeze and unfreeze activities can directly
affect a client’s ability to transact. The audit therefore considers the basis
for the freeze, the authority or source of the instruction, the type and scope
of freeze, system status and the relevant unfreeze process, where applicable.
Similarly, pledge, unpledge and hypothecation transactions require appropriate
controls over creation, release and invocation, as applicable. The relevant
client/party details, securities, quantity, authorisation and depository
records should be consistent with the transaction processed.
These areas demonstrate why a small system status change can have a significant
operational impact and therefore requires an adequate audit trail.
11. Grievances: Another Source of Control Information
Grievance redressal is also relevant to the
DP control environment. The review may cover whether BO grievances received
through the applicable channels are recorded, monitored and resolved within the
prescribed timelines.
Pending grievances and recurring complaints can be particularly useful from an
audit perspective because they may highlight operational problems that are not
immediately visible through transaction testing alone.
In this sense, grievance records can provide another source of information
about the effectiveness of the DP’s processes and client-servicing controls.
12. Back-Office Controls: Keeping Systems in Sync
The back-office system supports many stages
of DP operations. The audit therefore considers whether transactions are
appropriately uploaded into CDAS, whether the back office is updated for
transactions processed in CDAS and whether relevant records remain consistent.
This is important because a mismatch between the back-office system and
depository records can create an incomplete or unreliable audit trail.
The key principle is simple: information should not merely exist somewhere in
the system. The relevant records should be complete, consistent and capable of
reconciliation.
What Does a Good DP Concurrent Audit Actually Achieve?
A DP concurrent audit brings together
multiple layers of control:
·
Client Documents
·
Authorisation / Instruction
·
DP Processing
·
CDAS / Back-Office Entry
·
Depository Record
·
Statement / Communication to BO
·
Reconciliation and Exception
Handling
At each stage, the objective is to
establish a reliable and traceable audit trail.
Where an exception is identified, the focus should not always stop at
correcting the individual entry. Repeated observations may indicate a weakness
in the underlying process and may require stronger preventive or detective
controls.
Conclusion
A Demat account has a much longer
operational journey than what a client sees on the screen.
From KYC and account opening to client modifications, DIS issuance, transaction
execution, statements, dematerialisation, freeze/unfreeze, pledge, transmission
and account closure, every stage creates records that need to work together.
This is the real value of DP concurrent audit. It provides timely review of
risk-prone areas and helps ensure that client instructions are properly
supported, transactions are processed through appropriate controls, records
across systems remain consistent and exceptions are identified and addressed.
Ultimately, DP concurrent audit is not just about finding mistakes. It is about
making sure that important client activities are properly authorised,
accurately processed, traceable and supported by an adequate audit trail.
That is what turns concurrent audit from a routine compliance exercise into a
meaningful risk and control mechanism for protecting client interests and
strengthening DP operations.