Infosek
INFOSEK

SEBI IAAP Accessibility Audit: What It Is, Who Must Comply, and How to Pass

The SEBI IAAP accessibility audit is mandatory for market intermediaries. This guide explains what IAAP covers, who needs it, the audit process, and how to prepare.

SEBI IAAP Accessibility Audit: What It Is, Who Must Comply, and How to Pass

What Is SEBI IAAP?

IAAP stands for Information Assurance Audit Programme. This is SEBI's framework for annual information security audits of market intermediaries. A quick note on terminology: when market participants search for "SEBI accessibility audit," they are typically referring to IAAP — which is about information systems assurance and accessibility, not web accessibility for persons with disabilities. The two are completely different.

IAAP was established to ensure that market intermediaries maintain adequate information security controls and that those controls are independently verified on a regular basis. The audit is conducted by CERT-In empanelled information security auditing organisations.

Important: IAAP is a separate requirement from SEBI CSCRF. CSCRF is the broader cybersecurity framework (governance, controls, policies, VAPT). IAAP is the annual IS audit programme that verifies whether those controls are in place. You need to comply with both.

Who Must Get the IAAP Audit?

SEBI has mandated IAAP audits for a range of market intermediaries, including:

The requirement applies regardless of size, though smaller intermediaries may have a lighter scope. If you are registered with SEBI as any of the above, you must check your applicable circular to confirm audit frequency requirements.

What Does the IAAP Audit Cover?

IAAP auditors examine whether your information security controls are actually in place and functioning, not just documented. Key areas of review include:

How to Choose a CERT-In Empanelled Auditor

SEBI requires that the IAAP audit be conducted by an organisation empanelled with CERT-In (the Indian Computer Emergency Response Team) as an Information Security Auditing Organisation (ISAO). You can verify empanelment status on the CERT-In website.

Key factors to evaluate when selecting an auditor:

For a broader comparison of auditor vs. compliance partner models, read our guide on CERT-In Empanelled Auditor vs. Full-Service Compliance Partner.

Timeline and Frequency

IAAP audits must be conducted annually. The audit report must be submitted to SEBI (typically through the exchange or directly, depending on your intermediary type) within the specified deadline. Most firms schedule their audit in Q3 or Q4 of the financial year to allow time for gap remediation before the submission deadline.

Common Preparation Mistakes

The IAAP audit is not an assessment of your intentions — it is an evidence-based review. Auditors will ask to see records, logs, and approvals. If those do not exist, no amount of explaining will substitute for them.

Infosek Team

Common questions

Who needs a SEBI IAAP accessibility audit?

SEBI-regulated entities with public-facing digital interfaces. The audit assesses whether those interfaces are accessible to users with disabilities, and it is separate from the cyber security audit obligations under CSCRF.

How often is the accessibility audit required?

It is a recurring obligation rather than a one-off exercise, and remediation found in one cycle is expected to be closed before the next. Treating it as a single project is the most common planning error.

Topics SEBI

Get your DPDP readiness assessment today.

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment