IFSCA Annual Compliance Audit Framework for Capital Market Intermediaries

IFSCA Prescribes Annual Compliance Audit Reporting Framework for CMIs: What Capital Market Intermediaries Need to Know

The IFSCA (Capital Market Intermediaries) Regulations, 2025 establish the Annual Compliance Audit requirement for Capital Market Intermediaries (CMIs) operating in GIFT IFSC. Building on this requirement, IFSCA issued a circular dated 5 June 2026 prescribing a standardised Annual Compliance Audit Reporting Framework for documenting and reporting the audit process.

The framework introduces the Annual Compliance Audit Report (ACAR) and Annual Compliance Audit Checklist (ACAC), bringing greater consistency and structure to the assessment and reporting of applicable regulatory and compliance requirements.

The framework is relevant to Capital Market Intermediaries registered with IFSCA, with the specific requirements depending on the intermediary’s registration category, activities and, where applicable, membership with a Market Infrastructure Institution (MII). The circular also prescribes additional reporting requirements for relevant MII members and addresses the integration of audit reporting relating to Global Access activities into the broader Annual Compliance Audit framework.

In this guide, we explain the IFSCA Annual Compliance Audit Reporting Framework, including the purpose of the ACAR and ACAC, key changes introduced through the 5 June 2026 circular, filing requirements and practical steps CMIs can take to prepare for the annual compliance audit.

What is the IFSCA Annual Compliance Audit?

The Annual Compliance Audit is a mandatory annual review of a Capital Market Intermediary’s compliance with applicable requirements under the IFSCA regulatory framework. The scope of the audit may vary depending on the intermediary’s registration category, business activities and applicable regulatory obligations.

The audit may cover areas such as governance, internal controls, risk management, AML/KYC compliance, investor protection, record-keeping and regulatory reporting, depending on the requirements applicable to the intermediary.

The circular dated 5 June 2026 provides a standardised framework for documenting and reporting the Annual Compliance Audit through the prescribed Annual Compliance Audit Report (ACAR) and Annual Compliance Audit Checklist (ACAC). This brings greater consistency and structure to the annual compliance reporting process for CMIs operating in GIFT IFSC.

Quick Facts: IFSCA Annual Compliance Audit Framework

Particular Details
Regulator International Financial Services Centres Authority (IFSCA)
Circular Date 5 June 2026
Applicable To Capital Market Intermediaries, subject to applicable registration and regulatory requirements
Legal Framework IFSCA (Capital Market Intermediaries) Regulations, 2025
Audit Frequency Annual
Reporting Documents Annual Compliance Audit Report (ACAR) and Annual Compliance Audit Checklist (ACAC)
Submission Deadline 30 September each year
Additional Filing Applicable additional submission requirements for relevant MII members

Background of the Annual Compliance Audit Requirement

The CMI Regulations, 2025 establish the Annual Compliance Audit requirement for Capital Market Intermediaries, requiring them to assess compliance with applicable regulatory requirements. The audit is intended to support effective compliance, governance and internal control processes.

For a broader overview of the underlying audit requirements and practical preparation steps, read our guide on the Annual Compliance Audit under the IFSCA CMI Regulations, 2025.

Building on this requirement, IFSCA issued the circular dated 5 June 2026, prescribing a standardised framework for documenting and reporting the Annual Compliance Audit through the Annual Compliance Audit Report (ACAR) and Annual Compliance Audit Checklist (ACAC).

What Has Changed Through the Circular Dated 5 June 2026?

One of the most significant developments introduced by the circular is the standardization of annual compliance audit reporting.

The 5 June 2026 circular provides a standardised framework for documenting and reporting the Annual Compliance Audit through the prescribed ACAR and ACAC. The circular now introduces:

  • Annual Compliance Audit Report (ACAR)
  • Annual Compliance Audit Checklist (ACAC)
  • Standardized submission requirements
  • Category-specific compliance reporting
  • Additional reporting obligations for MII members
  • Integration of Global Access audit reporting into the annual audit framework

The introduction of a uniform reporting format is expected to improve consistency, transparency, and comparability of compliance audits across various categories of intermediaries operating within GIFT IFSC.

Understanding the ACAR and ACAC Framework

The circular requires every Capital Market Intermediary to submit an Annual Compliance Audit Report (ACAR) together with the Annual Compliance Audit Checklist (ACAC).

The ACAC has been structured into distinct sections to ensure comprehensive coverage of compliance obligations.

Annual Compliance Audit Report (ACAR)

The ACAR is the prescribed report through which the findings of the Annual Compliance Audit are documented and reported in accordance with the IFSCA framework.

Annual Compliance Audit Checklist (ACAC)

The ACAC provides the structured checklist for assessing and documenting compliance with applicable requirements. The relevant checklist requirements may include general obligations, category-specific requirements and, where applicable, requirements prescribed by the relevant MII.

Part A – General Obligations Applicable to All CMIs

Part A covers the general compliance obligations applicable across CMIs under the prescribed framework.

These generally include:

  • Governance and oversight requirements
  • Compliance monitoring mechanisms
  • Regulatory reporting obligations
  • Investor protection measures
  • Record-keeping requirements
  • Risk management processes
  • AML/CFT compliance obligations

This section ensures that fundamental compliance requirements are assessed consistently across all intermediaries.

Part B – Category-Specific Compliance Requirements

Part B covers compliance requirements specific to an intermediary’s category of registration, authorization or activities.

Depending on the intermediary’s registration category and the nature of its activities, the applicable checklist may include requirements relevant to:

  • Broker Dealers
  • Investment Advisers
  • Research Entities
  • Distributors
  • Custodians
  • Depository Participants
  • Clearing Members
  • Global Access Providers
  • Other registered CMIs, as applicable

This category-specific approach helps ensure that the Annual Compliance Audit addresses the regulatory requirements relevant to an intermediary’s business activities and regulatory responsibilities.

Part C – Compliance Requirements Prescribed by MIIs

The circular introduces an additional layer of compliance reporting for entities that hold memberships with Market Infrastructure Institutions (MIIs).

Market Infrastructure Institutions include:

  • Stock Exchanges
  • Clearing Corporations
  • Depositories

The respective MII is required to provide a compliance checklist covering applicable rules, regulations, bye-laws, and circulars governing its members.

Where applicable, this MII-related checklist forms part of the Annual Compliance Audit Checklist and enables relevant members to address compliance requirements arising from applicable MII rules, regulations, bye-laws and circulars.

Filing Requirements and Compliance Timeline

The circular prescribes a clear annual filing framework for all CMIs.

Every intermediary is required to submit:

  • Annual Compliance Audit Report (ACAR)
  • Annual Compliance Audit Checklist (ACAC)

The submission must be made to IFSCA on an annual basis for the preceding financial year.

The due date prescribed by the circular is 30 September of each year.

CMIs should begin their compliance review and audit preparation sufficiently in advance of the filing deadline to allow time for documentation review, identification of compliance gaps, corrective action and completion of the prescribed reporting requirements.

Early preparation can significantly reduce the risk of last-minute compliance gaps and regulatory observations.

Additional Requirements for Broker Dealers, Clearing Members and Depository Participants

The circular prescribes additional reporting requirements for certain categories of intermediaries.

A Capital Market Intermediary registered as a:

  • Broker Dealer
  • Clearing Member
  • Depository Participant

is required to submit the prescribed Annual Compliance Audit documentation to IFSCA and, where applicable, to the respective Market Infrastructure Institution (MII) in accordance with the circular.

This means that relevant entities may need to address compliance not only with applicable IFSCA requirements but also with relevant rules, regulations, bye-laws and circulars issued by the stock exchange, clearing corporation or depository of which they are members.

The requirement supports greater accountability and regulatory coordination between IFSCA and the relevant MIIs.

Annual Compliance Audit for Global Access Providers and Introducing Brokers

The circular also addresses annual audit requirements relating to Global Access activities.

The framework integrates the relevant audit reporting relating to Global Access Providers (GAPs) and Introducing Broker activities into the broader Annual Compliance Audit framework.

Accordingly, applicable audit findings relating to Global Access activities are addressed through the prescribed Annual Compliance Audit Report (ACAR) and Annual Compliance Audit Checklist (ACAC) framework.

This provides a more consolidated approach to documenting and reporting applicable compliance requirements.

Practical Steps for CMIs to Prepare for the Annual Compliance Audit

Given the standardised reporting framework introduced by IFSCA, CMIs should take a structured approach to audit readiness.

Identify Applicable Compliance Requirements

Entities should identify the regulatory obligations applicable to their registration category and business activities. This exercise should include a review of applicable regulations, directions and IFSCA Master Circulars relevant to ongoing compliance, particularly where requirements have been consolidated or updated.

Map Applicable Requirements to the ACAC

CMIs should review the applicable Annual Compliance Audit Checklist (ACAC) and map their relevant regulatory obligations to the appropriate checklist requirements. This can help identify missing documentation, incomplete controls and potential compliance gaps before the audit is completed.

Use the Applicable Prescribed Audit Formats

CMIs should ensure that they use the applicable prescribed reporting formats and checklists issued under the IFSCA framework before finalising the Annual Compliance Audit and reporting process.

This is better than saying “Download Latest Audit Checklist”, which sounds operational rather than regulatory.

Conduct an Internal Gap Assessment

A detailed internal review should be undertaken to identify potential compliance gaps before commencement of the audit.

Verify Regulatory Filings

All applicable periodic filings, returns, disclosures and submissions should be reviewed for completeness and accuracy.

Review AML and KYC Documentation

Client onboarding records, due diligence documentation, risk categorisation processes and applicable AML monitoring procedures should be reviewed. CMIs should also periodically assess their broader AML compliance framework for regulated entities in GIFT IFSC, including customer due diligence, transaction monitoring and risk-based controls.

Reconcile Client Accounts and Records

Entities dealing with client assets should review applicable reconciliation processes and segregation requirements.

Organise Supporting Documentation

Relevant policies, procedures, compliance records, risk assessments and regulatory correspondence should be maintained in an organised and audit-ready manner.

A structured compliance review before the audit can help CMIs identify and address gaps before completing the prescribed reporting process.

Common Compliance Mistakes to Avoid During the Annual Compliance Audit

Depending on their activities and applicable regulatory requirements, CMIs may encounter compliance gaps during the Annual Compliance Audit process. Identifying and addressing these gaps before the audit can help reduce regulatory observations and strengthen the overall compliance framework.

Some common compliance mistakes include:

  • Incomplete or outdated AML/KYC documentation for clients.
  • Delayed regulatory filings or non-submission of periodic reports to IFSCA.
  • Insufficient documentation to support compliance with internal policies and regulatory requirements.
  • Weak governance practices, including missing board or committee approvals where required.
  • Inadequate record-keeping and failure to retain compliance records for the prescribed period.
  • Gaps in risk management and internal control processes, particularly where business activities have evolved.
  • Failure to comply with Market Infrastructure Institution (MII) requirements by Broker Dealers, Clearing Members, and Depository Participants.
  • Using outdated or inapplicable compliance checklists and reporting formats instead of the prescribed formats applicable under the IFSCA framework.

Conducting periodic internal compliance reviews throughout the year, rather than waiting until the annual audit, can help identify these issues early and ensure a smoother audit process.

Consequences of Non-Compliance with the IFSCA Annual Compliance Audit Framework

Failure to comply with applicable Annual Compliance Audit and reporting requirements may result in regulatory scrutiny or observations from IFSCA. CMIs are required to comply with the applicable provisions of the IFSCA (Capital Market Intermediaries) Regulations, 2025, the circular dated 5 June 2026 and other relevant directions or requirements applicable to their activities.

Depending on the nature and extent of the non-compliance, this may involve:

  • Regulatory observations requiring corrective action.
  • Requests for additional information, documentation or clarifications.
  • Increased supervisory scrutiny or review.
  • Requirements to address identified deficiencies within applicable timelines.
  • Further supervisory or enforcement action in accordance with the applicable regulatory framework.

Maintaining an effective compliance framework, conducting periodic internal reviews and addressing identified gaps well before the applicable reporting deadline can help CMIs meet regulatory expectations and reduce the risk of adverse observations.

How Nexpective Advisors Helps Capital Market Intermediaries

Navigating the IFSCA regulatory framework requires a proactive and well-structured approach to compliance, documentation and regulatory readiness. Nexpective Advisors supports Capital Market Intermediaries (CMIs) operating in GIFT IFSC with compliance advisory and audit-readiness services tailored to their applicable regulatory requirements.

Our support includes:

  • Annual Compliance Audit readiness assessments and gap analysis
  • Review of applicable regulatory and compliance requirements
  • Assistance with ACAR and ACAC readiness and supporting compliance documentation
  • Compliance monitoring and regulatory reporting support
  • AML/KYC and risk management framework reviews
  • Development and review of internal policies, procedures and compliance manuals
  • Ongoing advisory on applicable IFSCA regulations, circulars and compliance updates

Whether you are a Broker Dealer, Investment Adviser, Clearing Member, Custodian, Depository Participant, Research Entity or another IFSCA-regulated intermediary, our team provides practical, regulator-focused guidance to support compliance readiness and preparation for the Annual Compliance Audit.

Conclusion

The circular dated 5 June 2026 provides a standardised reporting framework for the Annual Compliance Audit requirement applicable to Capital Market Intermediaries under the IFSCA (Capital Market Intermediaries) Regulations, 2025. Through the introduction of the Annual Compliance Audit Report (ACAR) and Annual Compliance Audit Checklist (ACAC), the framework brings greater consistency and structure to the documentation and reporting of annual compliance audits in GIFT IFSC.

For CMIs, the Annual Compliance Audit is an important part of the broader compliance framework. It provides an opportunity to review applicable regulatory requirements, assess governance and internal controls, identify compliance gaps and strengthen relevant risk management and compliance processes.

The immediate priority for intermediaries is to identify the requirements applicable to their registration category and activities, review the relevant ACAC requirements, maintain appropriate supporting documentation and complete the prescribed reporting process within the applicable timeline. A proactive approach to compliance can help CMIs address potential gaps before the Annual Compliance Audit and strengthen their overall regulatory readiness.

Subscribe on LinkedIn

About the Author

Nitin Pahilwani

Chartered Accountant | Registered Valuer | IFSC & International Tax Advisor

Nitin Pahilwani is a Chartered Accountant, Registered Valuer and advisor specialising in GIFT IFSC, international taxation, regulatory compliance, financial structuring, valuation and cross-border advisory. He works with businesses and financial services entities on regulatory, tax and valuation matters relating to GIFT City and international operations.

Connect on LinkedIn →

Leave A Comment

Subscribe to our Updates

Sign up to receive latest news, updates delivered directly to your inbox. No Spams
Not now, May be later
Subscribe to our Updates