Regulated Entity (SEBI): Meaning, Types and Compliance Requirements

SEBI Regulated Entity types and compliance responsibilities across the Indian securities market

A SEBI Regulated Entity is a securities-market participant that operates under SEBI registration, recognition or supervision and must follow the rules attached to its activity.

  • Glossary
  • SEBI compliance
  • Securities market

The short answer

A SEBI Regulated Entity (RE) is an organisation or person that SEBI registers, recognises or otherwise regulates for carrying out a securities-market activity. Stock exchanges, clearing corporations, depositories, brokers, mutual funds, portfolio managers, investment advisers and several other intermediaries can be REs. “RE” is an umbrella label: the licence, duties and reporting route depend on what the entity does and which SEBI regulation, circular or framework applies.

Being a regulated entity affects more than permission to enter the market. It creates continuing obligations around governance, investor protection, books and records, disclosures, grievance handling, outsourcing, technology risk, cybersecurity, audits and regulatory reporting. The precise combination is different for each entity type.

What does Regulated Entity mean under SEBI?

SEBI uses “regulated entity” as a practical collective term for entities within its regulatory perimeter. The perimeter includes institutions that operate the market, intermediaries that connect issuers and investors, pooled investment vehicles and professional advisers or service providers.

Entry permission

Registration or recognition

The entity must hold the approval required for its specific securities-market activity.

Continuing supervision

Rules while operating

It must maintain eligibility, controls, records, disclosures and investor-facing processes.

Evidence and reporting

Prove compliance

It must produce prescribed filings, audit records and incident or grievance information when required.

There is no single universal “RE licence”

An entity becomes regulated because of the activity it performs and the legal route governing that activity. A stock broker’s obligations are not identical to an AMC’s, a credit rating agency’s or a stock exchange’s.

Who counts as a SEBI Regulated Entity?

SEBIregulatory perimeterMarket infrastructureExchanges · clearing corporationsdepositoriesTrading and custodyBrokers · DPs · custodiansbankers to an issueFunds and managersMutual funds · AMCs · AIFsportfolio managers · CISAdvice and analysisInvestment advisers · researchanalysts · rating agenciesIssue and investor servicesMerchant bankers · RTAs · trusteesMarket information and KYCKRAs · CRAs · designated participants
Swipe to see the full diagram. The perimeter is broad, but the legal and operational obligations are activity-specific.
Common RE typeRole in the securities market
Stock exchanges, clearing corporations and depositoriesProvide core trading, clearing, settlement and securities-holding infrastructure.
Stock brokers and depository participantsGive investors access to trading and depository services.
Mutual funds and AMCsPool investor money and manage schemes under the mutual-fund framework.
AIFs, portfolio managers and CISManage pooled or client-specific investment strategies under their respective regimes.
Investment advisers and research analystsProvide regulated investment advice or securities research.
Merchant bankers, RTAs and debenture trusteesSupport issues, investor records, transfers and debenture-holder interests.
Custodians, KRAs and credit rating agenciesSafeguard assets, maintain KYC records or provide regulated credit opinions.

This is a representative list, not a substitute for checking the regulation or circular relevant to a particular business model. One corporate group may also contain several separately registered entities.

Regulated Entity, intermediary and MII: the difference

TermWhat it describesRelationship
Regulated Entity (RE)The broad collective label for an entity within SEBI’s regulatory perimeter.Can include intermediaries, market infrastructure institutions, funds and other regulated participants.
IntermediaryA participant performing a regulated service between issuers, investors or market systems.Many intermediaries are REs, but “RE” is the broader term in frameworks such as CSCRF.
Market Infrastructure Institution (MII)A stock exchange, clearing corporation or depository forming core market infrastructure.An MII is an RE with heightened systemic importance and correspondingly extensive obligations.

How an RE’s obligations are decided

1 · ACTIVITYWhat service isbeing performed?2 · STATUSRegistration orrecognition type3 · SCALEClients, volume,AUM and reach4 · RULESRegulations, circularsand frameworks5 · EVIDENCEFilings, audits,records and reportsStart with the regulated activity; the resulting control and reporting map follows from it.
Swipe to see the full diagram. Applicability should be documented, owned and reviewed when the business or regulatory perimeter changes.

A sound compliance map begins with the entity’s exact registration and activities. It then identifies the governing regulations, master circulars, operational circulars and cross-cutting frameworks. Scale or systemic importance may determine which tier, frequency or reporting path applies.

Registration is the start, not the finish

An RE must maintain the conditions of registration throughout its operations. New products, outsourcing arrangements, technology changes, acquisitions or threshold movements can change the applicable obligations.

RE categories under SEBI’s CSCRF

For cybersecurity and cyber resilience, SEBI’s CSCRF follows a graded approach. It classifies covered REs using their span of operations and thresholds such as client count, trade volume and assets under management.

CSCRF categoryPractical meaning
Market Infrastructure InstitutionsSystemically important exchanges, clearing corporations and depositories; subject to the broadest requirements.
Qualified REsLarger entities crossing the relevant operational threshold; also included in Cyber Capability Index assessment.
Mid-size REsEntities in the middle threshold band, with controls and assurance scaled to their exposure.
Small-size REsSmaller entities subject to a proportionate but substantive cybersecurity baseline.
Self-certification REsThe smallest category, using a simplified assurance path for applicable requirements rather than an exemption from security.

CSCRF category is not the same as entity type

“Stock broker” describes the regulated activity. “Qualified RE” or “Small-size RE” describes how the CSCRF baseline is graded for that entity. Both labels may apply at the same time.

What cybersecurity responsibility means for an RE

ResponsibilityWhat operating evidence may look like
Governance and riskNamed accountability, committee oversight, a current risk assessment, treatment decisions and periodic review.
Identity and accessLeast privilege, access reviews, privileged-access control and multi-factor authentication.
Applications and APIsSecure development, change control, testing, web protection and API security.
Cloud and suppliersDue diligence, contractual controls, dependency mapping, posture monitoring and supplier-risk review.
Endpoints and dataEndpoint monitoring, encryption, classification, backups and data loss prevention.
Detection and responseCentralised logs, continuous monitoring, alert triage, escalation, incident reporting and retained evidence through a SIEM and SOC process.
Assurance and recoveryAudits, VAPT, remediation records, recovery testing and post-incident improvement.

CSCRF connects these areas through Governance, Identify, Protect, Detect, Respond and Recover. It also requires appropriate SOC-based security monitoring for covered REs, with delivery possible through an own, group, market or managed SOC.

Practical checklist for a SEBI RE

  1. Confirm every regulated activity. Map each registration, recognition, approval and responsible legal entity.
  2. Build the applicability register. List the regulations, circulars, frameworks, filings and responsible owners that attach to each activity.
  3. Record the current category. Where a graded framework applies, retain the data and reasoning supporting the category.
  4. Map critical systems and data. Include applications, APIs, cloud services, endpoints, vendors, market connections and investor information.
  5. Link controls to evidence. For every requirement, identify the live control, evidence source, review frequency and exception route.
  6. Monitor third parties. Treat outsourced technology and service providers as part of the control environment, not as a transfer of accountability.
  7. Rehearse incidents and reporting. Keep contacts, escalation paths, decision rights and reporting templates ready before an event.
  8. Close findings visibly. Track audit and VAPT findings to validated remediation, with risk acceptance approved at the right level.
  9. Review when the business changes. Reassess applicability after a new product, acquisition, system migration or threshold movement.

The broader Indian fintech compliance map is useful when the same group also falls within RBI, CERT-In, data-protection or payment-security requirements.

How Osto supports SEBI Regulated Entities

Osto brings preventive controls, continuous monitoring and compliance evidence into one operating view across cloud, applications, APIs, code, endpoints, identities, networks and data. Live controls can be mapped to the applicable requirement, owner, finding and closure record.

This reduces the gap between policy and proof. Instead of rebuilding the audit trail from separate tools and vendor reports, an RE can show the current control state, the issue identified, the remediation owner and the evidence that the issue was closed.

Free security assessment

Turn SEBI requirements into live controls

Map the applicable obligations, deploy the security stack and keep audit-ready evidence across one platform.

Get a free security assessment

Security controls · Continuous evidence · One platform, everything

Frequently asked questions

What is a SEBI Regulated Entity?

It is an organisation or person operating within SEBI’s regulatory perimeter under the registration, recognition or supervision applicable to a securities-market activity.

Is a Regulated Entity the same as a SEBI-registered intermediary?

Not always. Many intermediaries are REs, but “regulated entity” is broader and can also include market infrastructure institutions, funds and other participants covered by a particular SEBI framework.

Which entities are regulated by SEBI?

Examples include stock exchanges, clearing corporations, depositories, brokers, depository participants, mutual funds and AMCs, AIFs, portfolio managers, investment advisers, research analysts, merchant bankers, RTAs, custodians, KRAs, credit rating agencies and debenture trustees.

Does every SEBI RE follow the same rules?

No. The rules depend on the entity’s regulated activity, governing instrument, scale, systemic importance and the framework in question. Cross-cutting requirements may apply to many entity types, but not always in the same form.

What is an MII under SEBI?

A Market Infrastructure Institution is a stock exchange, clearing corporation or depository. MIIs provide systemically important market infrastructure and are treated as a distinct, high-obligation category.

What are the five RE categories under CSCRF?

Market Infrastructure Institutions, Qualified REs, Mid-size REs, Small-size REs and Self-certification REs. The category is based on the span of operations and relevant thresholds.

Is a small or self-certification RE exempt from cybersecurity?

No. CSCRF uses proportional requirements, but its stated aim includes ensuring that smaller REs have adequate cybersecurity measures and resilience.

Does outsourcing transfer an RE’s regulatory responsibility?

Generally, outsourcing a service does not remove the RE’s responsibility for overseeing risks and complying with applicable obligations. The exact contractual, due-diligence and monitoring duties depend on the relevant rules.

How should an RE prove compliance?

By maintaining current policies, registers, system and access records, risk decisions, control evidence, filings, audit and VAPT reports, incident records and verified remediation evidence appropriate to its obligations.