Skip to content

Trading Risk: Client protection frameworks

Why this page is structured this way: Every control here answers the same question from a different angle — how does a client know that the account, the app and the payment address in front of them are genuinely theirs and genuinely the broker’s? The page follows the client’s own timeline: logging in (2FA, and the proposed device binding), paying money in (validated UPI handles and SEBI Check), understanding the relationship (MITC, Investor Charter), and stopping everything when something looks wrong (voluntary freeze). Each section states what is in force today, because several of these frameworks are at different stages of maturity.

  • Two-factor authentication for internet-based and wireless trading is mandatory, and the two factors must not be the same. Para 56.1.6 of the Master Circular for Stock Brokers traces to CIR/MRD/DP/08/2011 (30 June 2011); the cyber-security annexure states that for internet-based trading and securities trading through wireless technology “a minimum of two-factors in the authentication flow are mandatory”, originating in SEBI/HO/MIRSD/CIR/PB/2018/147 (3 December 2018). [not yet in index]
  • SIM and device binding is still a proposal. SEBI’s consultation paper of 18 February 2025 proposed One UCC–One Device–One SIM hard binding with biometric login, QR-based desktop authentication and a temporary account lock, initially for the top 10 Qualified Stock Brokers. No final circular was verified as issued through 11 September 2026.
  • Validated UPI handles went live for investors on 1 October 2025. SEBI/HO/DEPA-II/DEPA-II_SRG/P/CIR/2025/86 (11 June 2025) created the @valid handle structure; brokers use the username suffix brk. Implemented in the payment rails by NPCI/UPI/OC No. 217/2025-26 (3 July 2025). [SEBI circular not yet in index]
  • Coverage was later extended to every investor-facing collection account. Depositories and exchanges issued clarifications in August 2026 — MCX/MEM/461/2026 sets 6 September 2026 for upstream accounts, while CDSL/ADM/DP/GENRL/2026/543 and NSDL/POLICY/2026/0113 give participants 30 days and expressly include DP-charge accounts.
  • MITC has been acknowledged by new clients since 1 April 2024 and communicated to existing clients by 1 June 2024, under SEBI/HO/MIRSD/MIRSD-PoD-1/P/CIR/2023/180 (13 November 2023) as operationalised by NSE/INSP/59367 and NSE/INSP/60147.
  • Voluntary freeze of online trading access has been live since 1 July 2024, on the framework at NSE/INSP/61529 (8 April 2024) implementing SEBI/HO/MIRSD/POD-1/P/CIR/2024/4 (12 January 2024) — 15 minutes to freeze on an online request, acknowledgement by T+1 end of day, with a separate penalty structure for members that fail to implement it (MCX/INSP/820/2024).

India’s client-protection stack was built incrementally, and each layer was added in response to a specific fraud pattern. Password-only login gave way to two-factor authentication after account-takeover losses. Two-factor authentication delivered by SMS came under pressure once SIM swapping became common, which is why the current proposals move away from one-time passwords towards device binding. Payments to brokers went through a separate evolution: an investor transferring money to a “broker” bank account had no way to verify that the account belonged to a registered intermediary at all, which is precisely the gap that fake-app and fake-advisory frauds exploited — hence a reserved UPI handle and a public lookup tool.

The second half of the stack is about comprehension and control rather than authentication. The account-opening kit is long, so SEBI required a short standard document — the Most Important Terms and Conditions — that the client actually acknowledges. The Investor Charter tells the client what service levels to expect and where to complain. And the voluntary freeze facility gives the client a single lever, modelled explicitly on blocking a debit or credit card, to stop online access when something looks wrong.

  • SEBI/HO/MIRSD/POD-1/P/CIR/2024/118 (9 August 2024) — Master Circular for Stock Brokers. Para 56.1 internet-based trading and wireless-technology norms including 2FA; para 78 Investor Charter and monthly complaint disclosure; the Rights and Obligations document with its password and unauthorised-access clauses; the cyber-security annexure.
  • CIR/MRD/DP/08/2011 (30 June 2011) — the originating internet-based-trading authentication norms. Read with SMDRP/POLICY/CIR-06/2000 (31 January 2000) and CIR/MRD/DP/25/2010 (27 August 2010). [not yet in index]
  • SEBI/HO/MIRSD/CIR/PB/2018/147 (3 December 2018) — Cyber Security and Cyber Resilience framework for stock brokers and depository participants; the annexure’s authentication requirements, including a cryptographically secure biometric two-factor mechanism for mobile applications and the account-lock-after-failed-attempts rule. Now sitting under the wider CSCRF regime — see CSCRF deep dive. [not yet in index]
  • Consultation Paper on Technology based measures to secure trading environment and to prevent unauthorised transactions in trading/demat account of investors (18 February 2025, comments to 11 March 2025) — the SIM-binding proposal, with a draft circular at Annexure A. [not a circular]
  • SEBI/HO/DEPA-II/DEPA-II_SRG/P/CIR/2025/86 (11 June 2025) — standardised, validated and exclusive UPI IDs; handle structure, transaction limits, SEBI Check, and the activity-wise timetable ending with investor availability from 1 October 2025. [not yet in index]
  • NPCI/UPI/OC No. 217/2025-26 (3 July 2025) — the payments-side implementation: merchant category code 6211, the @validbankpsp nomenclature, handle length limits and the AutoPay mandate format.
  • SEBI Press Release 64/2025 (1 October 2025) — roll-out of Validated UPI Handles and SEBI Check. Press Release 69/2025 (6 November 2025) — SEBI’s approach to online investment scams, advertiser verification and verified-app labelling on platforms. Press Release 12/2026 (13 February 2026) — AI-driven calling campaign promoting SEBI Check. [not circulars]
  • SEBI/HO/MIRSD/MIRSD-PoD-1/P/CIR/2023/180 (13 November 2023) — Most Important Terms and Conditions. [not yet in index]
  • SEBI/HO/MIRSD/POD-1/P/CIR/2024/4 (12 January 2024) — facility of voluntary freezing and blocking of trading accounts, forwarded as NSE/INSP/60277 and operationalised by NSE/INSP/61529. [SEBI circular not yet in index]
  • SEBI/HO/MIRSD/MIRSD-PoD1/P/CIR/2025/22 (21 February 2025, in force 1 April 2025) — updated Investor Charter for stock brokers, replacing the December 2021 charter.

2. Two-factor authentication: what is actually required

Section titled “2. Two-factor authentication: what is actually required”
LayerRequirementSource
Internet-based trading and wireless tradingTwo-factor authentication for the login session, for all orders emanating using Internet Protocol; the two factors must not be the sameMaster Circular para 56.1.6
Session hygieneAutomatic trading-session logout on client inactivityMaster Circular para 56.1.7
Cyber-security baselineA minimum of two factors in the authentication flow are mandatory for internet-based trading and wireless trading; multi-factor schemes using cryptographic tokens, VPNs, biometric devices or PKI may be usedCyber-security annexure, clause 3
Mobile applicationsA cryptographically secure biometric two-factor mechanism may be usedCyber-security annexure, clause 4
LockoutAfter a reasonable number of failed login attempts the account may be locked until reset through an out-of-band channel — an emailed cryptographically secure link, an SMS one-time password, or manual identity verification by the brokerCyber-security annexure, clause 5
Client responsibilityThe client is responsible for keeping the username and password confidential, is solely responsible for all orders entered under their credentials whether or not the person was authorised, and must not reveal credentials to any third party including employees and dealers of the stock brokerRights and Obligations document, clauses 5 and 7
Incident notificationThe client must immediately notify the broker in writing on discovering or suspecting unauthorised access, with date, manner and the transactions effectedRights and Obligations document, clause 6

In practice the industry converged during 2022 on three second factors: an SMS one-time password, a time-based one-time password from an external authenticator application, and an in-app code on a biometrically-locked mobile session. The dominant retail broker’s public explanation of its implementation, published on 21 October 2022, describes the shift as taking effect from 30 September 2022 and argues that SMS one-time passwords are the weakest of the three for trading platforms specifically. [industry practice — unverified] for the exact industry-wide effective date, which was set through exchange communications rather than a single SEBI circular.

Note that two-factor authentication also appears in unrelated corners of the same rulebook — the nomination framework allows existing investors to submit or opt out of nomination through 2FA login on the broker’s internet trading platform (Master Circular para 22.6), and the depositories added 2FA to beneficial-owner portal logins (for example CDSL/OPS/DP/EASI/2024/310). The same phrase is doing different work in each place.

3. SIM and device binding: the 2025–26 proposal

Section titled “3. SIM and device binding: the 2025–26 proposal”

SEBI’s February 2025 consultation paper proposed replacing OTP-centric authentication with hard binding, on the explicit analogy of UPI payment applications. The draft circular at Annexure A is the best available statement of intent, and the following is a summary of that draft rather than of a rule in force.

ElementProposal
Primary SIM-bound deviceA mobile device holding the registered mobile number and a specific IMEI is linked to the client’s UCC. Exchanges to issue the hard-binding registration procedure
Secondary device and proximityOne additional SIM and device may be registered; binding is one-time. Both stay active only within 100 metres of each other, with trading through one at a time, and the secondary logs out automatically beyond that distance
LoginBiometric authentication on the primary bound device authorises login directly without a password; a PIN-based alternative may be offered
Desktop and browserQR-code based, proximity-sensitive and time-sensitive authentication through the bound device; access controls to prevent scanning a QR code from the phone gallery or a messaging app; one active instance per channel
Deceased clientWith no open position, freeze until nomination or transmission completes; with open positions, square off and then freeze
Call and tradeOnly through centralised dedicated phone numbers, email addresses or mobile numbers of the broker, including for authorised persons; uniform unchangeable time stamps on call recordings; OTP authentication of the order unless the call originates from the registered mobile number
Off-market transfer safetyBeneficiary-name verification before execution, or entering the target demat account twice with one entry masked; QR-scan or push-notification authorisation; IVR-keypad OTP for basic phones
ApplicabilityAuthentication binding initially mandatory for the top 10 Qualified Stock Brokers within six months, optional for investors at first and mandatory in phases. All other provisions apply to all brokers and depository participants

A validated handle has two halves. The username is a readable name chosen by the intermediary, followed by a suffix identifying its intermediary category — brk for stock brokers across segments, dp for depository participants, ra for research analysts, ia for investment advisers, mf for mutual funds, pms for portfolio managers. The handle itself is @valid combined with the name of the self-certified syndicate bank, allocated by NPCI. The result reads as abc.brk@validhdfc. Payments to such a handle display a thumbs-up icon inside a green triangle in the UPI application; its absence is the signal that the payee may be unauthorised.

ElementRule
Who issuesOnly the self-certified syndicate banks listed in Annexure C are allocated @valid handles by NPCI; intermediaries may use existing bank accounts and need not open new ones
Mandatory versus optionalUse by investors is optional; obtaining the handle and making it available to investors is mandatory for intermediaries
Transaction limitUp to ₹5 lakh per day for capital-market transactions, subject to periodic review
Old handlesUsable in parallel for a defined period, then discontinued — the timetable set discontinuation at T plus 180 days from 11 June 2025, with existing mutual-fund SIP mandates grandfathered and new or renewed SIPs required to use the new IDs
Investor availabilityFrom 1 October 2025

SEBI Check is the verification counterpart: the investor scans a QR code or enters a UPI ID and the tool confirms whether it belongs to a registered intermediary, and can also confirm the intermediary’s bank account number and IFSC. It is reachable at the SEBI intermediary portal path siportal.sebi.gov.in/intermediary/sebi-check and through the Saarthi app. SEBI’s November 2025 press release directs investors to use validated handles and SEBI Check for secure payments, alongside verifying registration on the intermediaries listing and using authentic apps verified through the investor-support page. It also records SEBI’s requests to social-media platforms and search engines for mandatory advertiser verification in the securities-market domain and verified labelling of registered intermediary apps.

Many intermediaries read the original circular as covering only the main client-funds collection account. The August 2026 clarifications closed that gap: every investor-facing bank account receiving money or fees from individual or non-institutional investors must be linked to an @valid UPI ID so it is verifiable through SEBI Check, expressly including DP-charge accounts, on a 30-day clock from each clarification; the commodity-exchange clarification sets 6 September 2026 for upstream accounts, covers newly-opened accounts, and tells members on multiple exchanges to apply through only one. A separate CDSL facility already allows beneficial owners to pay stamp duty through a validated UPI handle (CDSL/OPS/DP/SETT/2025/633).

MITC exists because the standard account-opening set — account opening form, rights and obligations, risk disclosure documents, guidance note, policies and procedures, tariff sheet — is voluminous, and SEBI concluded that investors lose focus on the critical terms. The MITC is a short standard text the client acknowledges, and its standards were published by the Brokers’ Industry Standards Forum under the aegis of the exchanges. New clients onboarded from 1 April 2024 acknowledge it as part of onboarding; existing clients were to be informed by 1 June 2024 by email or another preservable channel. The exchange circulars carry the standard text in an annexure.

The Investor Charter is the service-level counterpart: services provided, rights of investors, broker activities with timelines, dos and don’ts, and the grievance redressal mechanism. It must be on the broker’s website, at prominent places in the office, and in the account-opening kit, and brokers must publish monthly complaint data by the seventh of the following month. The current charter reflects SCORES 2.0 with its 21-day initial resolution, the online dispute resolution portal, the revamped nomination framework, the ₹10 lakh Basic Services Demat Account threshold and direct payout of securities.

6. Voluntary freezing and blocking of trading accounts

Section titled “6. Voluntary freezing and blocking of trading accounts”

SEBI’s reasoning was blunt: investors could already block ATM and credit cards and could already voluntarily freeze demat accounts, but most trading members had no equivalent facility even though investors regularly reported suspicious activity. The framework was finalised by the Industry Standards Forum and implemented from 1 July 2024.

ElementRequirement
ChannelsRegistered email, the broker’s app, web, and IVR are acceptable request channels
Freeze turnaround15 minutes for an online request
AcknowledgementIssued to the client on receipt; by T+1 end of day
Permanent blockAfter 7 days
ScopeFreezing or blocking of online access to the trading account
Open positionsSquare-off rules specified in the framework; a freeze does not by itself extinguish exposure
Re-enablementA defined process for re-enabling the client for trading and transfers
DisclosureReflected in the MITC and on the member’s website
Reporting and penaltyExchanges put in place reporting requirements; a separate penalty structure applies to members that fail to implement the framework

7. Field-level view: the freeze request record and the SEBI Check lookup

Section titled “7. Field-level view: the freeze request record and the SEBI Check lookup”
nametypelengthmandatorysource-systemdestination-system(s)notes
freeze_request_idCHAR20Yclient-servicing applicationaudit trail, exchange reportingImmutable; the acknowledgement quotes it
client_codeCHAR10Yclient identity on the request channelRMS, back-officeUCC whose online access is frozen
requested_atTIMESTAMP14Ychannel handler clockSLA engineStarts the 15-minute clock for online requests
frozen_atTIMESTAMP14YRMSSLA engine, audit trailEvidence of the 15-minute turnaround
ack_sent_atTIMESTAMP14Ycommunications platformaudit trailMust be by T+1 end of day
permanent_block_atTIMESTAMP14ConditionalRMSaudit trailSet on expiry of the 7-day period
upi_usernameVARCHAR30YSEBI username-generation utilityNPCI, SCSB, client-facing payment screenReadable name plus the brk suffix; generated only through the prescribed utility
upi_handleVARCHAR20YNPCI via the syndicate bankclient-facing payment screen@valid plus the bank identifier; maximum handle length 10 characters
collection_account_numberVARCHAR20Ybank mandateSEBI intermediary portal, SEBI CheckEvery investor-facing collection account must be linked
mitc_ack_atTIMESTAMP14Yonboarding flowback-office, audit trailClient acknowledgement of the MITC; mandatory for clients onboarded from 1 April 2024
Option AOption BWhen to pick whichWho uses what
SMS one-time password as second factorTOTP from an external authenticator, or an in-app code on a biometrically locked sessionA is universally available and needs no client setup; B is resistant to SIM swapping and interception, which is the whole reason the binding proposal existsDiscount brokers push B and retain A as fallback; full-service brokers keep A as default
Single collection account with one @valid handleA handle per business accountA is simpler to reconcile; B is required in substance after the August 2026 clarifications wherever separate investor-facing accounts exist, including DP-charge accountsMembers with separate DP, broking and commodity collections need B
  • [gotcha] The 11 June 2025 UPI circular contains an internal inconsistency in its own examples: paragraph 2.1(i) writes the broker suffix as abc.brk while 2.1(ii) writes abc.bkr. Annexure B, which is the operative abbreviation table, says brk. Use the annexure.
  • [gotcha] The @valid obligation is on the intermediary to obtain and make available the handle. Investor use is optional. A broker that treats low investor adoption as evidence of non-compliance is measuring the wrong thing; a broker that has not obtained handles for every investor-facing account is non-compliant regardless of adoption.
  • [risk trade-off] Freezing online access does not close open positions. A client who freezes and then cannot place a square-off order is exposed to market risk they can no longer manage, which is why the framework specifies square-off rules and why the re-enablement path needs to be genuinely fast, not merely documented.
  • [AI inference — verify before acting] The 30-day compliance clock in the depository @valid clarifications runs from the date of each clarification, so the effective deadline differs between CDSL and NSDL participants and from the commodity-exchange date. Read the clarification that applies to your registration rather than assuming a single market-wide date.

2026-09-11


AI-generated and not legal, financial, or compliance advice. See the project README for full disclaimer.