SEBI Audit Checklist: Are Your IT Systems Ready for Regulatory Scrutiny?
Technology now sits at the centre of India’s securities market. Trading platforms, mobile applications, APIs, algorithmic trading engines, cloud systems, data centres and vendor networks all support critical financial activity.
That also means IT systems are firmly within the scope of regulatory scrutiny.
For CIOs, CTOs, IT Heads, Compliance Officers and CEOs, a SEBI audit is not simply a review of policies. It is an examination of whether technology controls actually protect market access, client data, order integrity, system availability and business continuity.
This guide provides a practical IT security audit checklist covering SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF), system audits, algorithmic trading controls and audit preparation.
Important: SEBI requirements can change through new circulars, clarifications and exchange-specific instructions. Always validate the applicable requirements for your entity category and audit period against the latest official SEBI communications.
What does a SEBI IT audit examine?
The exact scope depends on your type of regulated entity, technology environment and services. It may include:
- Stock exchange, broker or depository systems
- Internet-based trading and mobile trading applications
- Direct Market Access (DMA), CTCL or API-based trading
- Algorithmic trading platforms
- Smart Order Routing systems
- Risk Management Systems (RMS)
- Client-facing websites and back-office applications
- Primary Data Centre, Disaster Recovery and cloud environments
- Network infrastructure, firewalls, WAF and security devices
- User access, privileged accounts and audit logs
- Vendors, SaaS providers and outsourced IT operations
- Backup, recovery and incident response processes
SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) brings many cybersecurity expectations into a common framework for SEBI-regulated entities.
SEBI audit checklist for IT systems
1. Governance, accountability and policies
Auditors first want to understand who owns cybersecurity risk.
Your organisation should have:
- A Board- or management-approved cybersecurity and cyber resilience policy
- Clearly assigned roles for the CIO, CTO, CISO, IT Head and business owners
- A documented cyber risk management process
- An approved list of critical systems
- Defined risk appetite and risk acceptance procedures
- A current IT and cybersecurity budget
- A documented IT Committee structure, where applicable
- Periodic reviews of policies, risks, incidents and remediation status
- Security responsibilities included in employee and vendor agreements
For Qualified REs and larger entities, the CISO function must have sufficient authority, seniority and access to senior management. Responsibility cannot be transferred entirely to a vendor or cloud provider. The regulated entity remains accountable for its systems, data, logs and regulatory compliance.
2. Asset inventory and critical system classification
An incomplete asset inventory is one of the fastest ways to create audit findings.
Maintain an up-to-date inventory of:
- Servers and databases
- Network and security devices
- Applications and APIs
- Domains, URLs and internet-facing assets
- Cloud resources and shared services
- Endpoints and mobile devices
- Third-party connections
- Data flows and communication channels
- Primary, DR, near-site and colocation infrastructure
Your inventory should identify which systems are critical and why. Critical systems commonly include platforms that support core operations, process regulatory data, connect to market infrastructure or could significantly affect clients if compromised.
The list of critical systems should be formally approved by the Board, partners or proprietor, as applicable.

3. Identity, access and authentication controls
SEBI expects access to be controlled according to business need and risk.
Check whether your organisation has:
- Multi-factor authentication for critical and internet-facing systems
- Strong password and account-lockout policies
- Privileged Identity Management or equivalent controls
- Role-based access and segregation of duties
- Maker-checker approval for access changes
- Periodic access reviews
- Immediate removal of access when employees or vendors leave
- Controls for generic, dormant and shared accounts
- Monitoring of privileged user activity
- Controlled and time-bound remote access
- Secure access to cloud platforms, APIs and databases
A useful test is to select a sample of employees, administrators and vendors and trace their complete access lifecycle: approval, provisioning, usage review and removal.
4. Network security and application protection
The audit should cover both external exposure and internal movement.
Key controls include:
- Network segmentation between trading, corporate, development and user environments
- Firewalls with documented rule reviews
- Web Application Firewall (WAF) for internet-facing applications
- Intrusion Prevention Systems and endpoint protection
- Secure configuration baselines for operating systems and databases
- DDoS protection where relevant
- Secure DNS and email controls, including SPF, DKIM and DMARC
- API authentication, authorisation, rate limiting and throttling
- Secure encryption for data in transit and at rest
- Vulnerability management and patching
- Monitoring for unauthorised devices and shadow IT
For customer-facing applications, auditors may review authentication, session management, input validation, access control, data masking, secure coding and protection against common application vulnerabilities.
5. Logging, monitoring and SOC readiness
Cybersecurity controls are not effective if nobody is watching them.
SEBI’s framework expects appropriate security monitoring through an internal, group, third-party or market SOC, depending on the entity and applicable requirements.
Your audit evidence should demonstrate:
- Logs are collected from relevant systems, applications, databases and network devices
- Logs are protected against unauthorised modification
- Critical systems are connected to the SIEM or monitoring platform
- Alerts are investigated within defined timelines
- Use cases and response playbooks are documented
- Security incidents are tracked to closure
- SOC performance and efficacy are periodically reviewed
- Threat intelligence is received and acted upon
- MTTD, MTTR and MTTC metrics are measured
A dashboard showing control status, open vulnerabilities, incident trends, access reviews and remediation progress can significantly improve management oversight.
6. Vulnerability assessment, penetration testing and cyber audits
VAPT should not be treated as a once-a-year scanning exercise. It should cover the complete technology environment relevant to your SEBI activities.
The scope may include:
- Internal and external infrastructure
- Internet-facing applications
- APIs
- Mobile applications
- Cloud deployments
- Databases and operating systems
- Wi-Fi networks
- Network segmentation
- Security device configurations
- WAF and firewall configurations
Under the CSCRF, applicable audits and VAPT activities must be conducted by eligible auditors, including CERT-In empanelled information security auditing organisations where required.
Plan early for:
- Audit scope approval
- Evidence collection
- VAPT execution
- Management responses
- Submission of reports
- Closure of findings
- Revalidation or follow-on audit
The CSCRF generally requires VAPT findings to be addressed within defined timelines, with open items tracked through governance forums. A vulnerability without an owner, target date and risk acceptance is likely to remain an audit problem.
Algo Audit: additional checks for algorithmic trading
Algorithmic trading receives enhanced scrutiny because a software error, unauthorised change or runaway algorithm can affect market integrity quickly.

For an Algo Audit, check the following:
- Prior approval of algorithms from the relevant exchange
- Documented algorithm inventory and version history
- Approval for modifications and parameter changes
- Segregated and secured algo infrastructure
- Strong access controls for algo servers and repositories
- Price, quantity and order-value checks
- Cumulative open-order value limits
- Automated execution and runaway-loop controls
- Real-time monitoring for abnormal behaviour
- Automatic stopping or shutdown capability
- Unique identification and tagging of algo orders
- Complete logs of orders, trades, parameters and data feeds
- Controls for data-feed failure or stale data
- Participation in required mock or simulated trading tests
- Independent system audits at the required frequency
- Immediate reporting of serious deficiencies to the exchange
The SEBI Trading Software and Technology chapter provides detailed requirements covering internet trading, DMA, algorithmic trading, system audits, business continuity and technology controls.
7. Business continuity, disaster recovery and resilience
A compliant organisation must be able to continue critical operations during a cyberattack, system failure, vendor outage or site disaster.
Review whether you have:
- A Board-approved BCP, DR and Cyber Crisis Management Plan
- Clearly defined RTO and RPO
- Tested backups, including offline or immutable copies
- Secure golden images for critical systems, where applicable
- Documented recovery procedures
- Alternate communication channels
- Tested failover between primary and recovery environments
- Vendor participation in recovery exercises
- Evidence from live drills and restoration tests
- Post-drill lessons learned and remediation tracking

For many REs, CSCRF expectations include declaring a disaster within a defined period and working towards an RTO of two hours and an RPO of 15 minutes for critical operations. Confirm the precise requirement applicable to your entity.
8. Third-party, cloud and supply-chain risk
Your vendor’s compliance certificate does not remove your responsibility.
Review:
- Vendor due diligence reports
- Security clauses in contracts and SLAs
- Incident notification obligations
- Audit and inspection rights
- Data location and access arrangements
- Subcontractor and concentration risk
- Vulnerability closure timelines
- Source-code escrow or equivalent safeguards
- Software Bill of Materials (SBOM) for critical software
- Exit and migration plans
- Evidence of cloud security testing
SEBI’s 2025 CSCRF FAQs clarify several issues involving classification, VAPT, cloud, SOC, SBOM, outsourcing and incident response.
How to prepare before the auditor arrives
Use this 30-day preparation plan:
- Confirm your entity category and audit frequency.
- Map all SEBI-regulated services and supporting systems.
- Approve the critical systems list.
- Review policies, SOPs and governance minutes.
- Complete access and privileged-user reviews.
- Validate network diagrams and asset inventories.
- Check VAPT, system audit and application-security reports.
- Track every open finding with an owner and deadline.
- Test backup restoration and DR procedures.
- Prepare evidence in a structured, auditor-friendly repository.
- Review vendor contracts, cloud responsibilities and audit rights.
- Conduct a mock audit with IT, compliance, risk, legal and business teams.
Final takeaway
A successful SEBI audit is built throughout the year, not during the final week before the auditor arrives. Strong governance, accurate asset visibility, secure access, tested applications, reliable logs, effective monitoring and proven recovery capabilities are the foundation of regulatory readiness.
For organisations using algorithmic trading, cloud infrastructure or outsourced technology, the standard is even higher. The question is not only whether a control exists, but whether you can demonstrate that it works consistently.
Need guidance on a SEBI audit, Algo Audit or an IT security audit checklist for your organisation?
Official references
- SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)
- SEBI Trading Software and Technology
- SEBI CSCRF FAQs, June 2025
- SEBI Framework for Adoption of Cloud Services by SEBI Regulated Entities
#SEBIAudit #AlgoAudit #ITSecurityAudit #CyberSecurity #CyberResilience #Compliance #StockBroker #FinancialServices #CIO #CTO #ITAudit #SEBI #RiskManagement