Digital access has become a basic part of participation in the capital markets. Investors use websites, mobile applications, online forms, portals, digital KYC systems and other electronic channels to open accounts, access information and use financial services. For persons with disabilities, however, access can depend on whether these digital systems work with assistive technology and provide suitable alternatives.
SEBI has placed this issue within its regulatory framework. On July 31, 2025, SEBI issued a circular on mandatory compliance with the Rights of Persons with Disabilities Act, 2016 and the rules made under it by all regulated entities.
The immediate date that now requires close attention is October 31, 2026. On July 31, 2026, SEBI issued a further circular that extended the timelines for compliance with its digital accessibility circulars.
For capital-market intermediaries, this date should not be viewed only as a technology deadline. It also has implications for compliance, governance, customer service, vendor oversight and internal controls.
What the October 31 deadline means
The July 31, 2026 SEBI circular is important because it changes the timetable for the digital accessibility work required under the earlier framework. The extension gives regulated entities additional time to complete the required work. The October 31, 2026 date is therefore the key date for firms that still have audit or remediation work left to complete.
The earlier SEBI framework required regulated entities to undertake accessibility audits of their digital platforms. The scope includes websites, mobile applications and portals. The framework also refers to audits through the International Association of Accessibility Professionals, or IAAP, and requires action on issues found through the audit.
This creates an important practical point. A firm should not treat the audit report as the final step. Where the audit identifies accessibility gaps, the firm must also address those gaps within the applicable compliance framework.
| Area | Regulatory position |
|---|---|
| Main regulator | SEBI |
| Core law referred to by SEBI | Rights of Persons with Disabilities Act, 2016 |
| Main accessibility circular | July 31, 2025 |
| Latest timeline extension | July 31, 2026 |
| Key revised date | October 31, 2026 |
| Digital platforms | Websites, mobile applications and portals |
| Accessibility audit | Required under the SEBI framework |
| Auditor reference | IAAP |
| Remediation | Required for audit findings |
| Wider compliance focus | Digital access, KYC, investor service and governance |
The exact duties can vary by the type of regulated entity and the relevant SEBI circulars. Firms should therefore read the applicable circulars together rather than rely on a general accessibility checklist.
Why this matters for capital-market intermediaries
Capital-market services now depend heavily on digital channels. A broker may use a website and mobile application for account access, order placement and investor communication. An investment adviser may use an online portal, digital forms and video calls. A research analyst may publish research through digital channels. Other regulated entities may rely on online onboarding, KYC, customer support and document delivery.
If one of these systems cannot be used by a person with a disability, the problem is not simply a matter of website design. It can affect the person’s ability to access a regulated financial service.
SEBI’s framework recognises this broader issue. Its requirements cover more than visual design. They also address processes such as digital KYC, e-KYC and video KYC. The framework provides examples of alternatives for users who may face barriers with standard digital processes. These include human-assisted video KYC, scanned document uploads and voice-assisted KYC for visually impaired users.
This approach is significant because a technically accessible homepage does not necessarily mean that the full customer journey is accessible.
An investor may be able to open a website but may still face a barrier when completing a form, uploading a document, completing an OTP step, reading a PDF or contacting customer support.
The compliance review therefore needs to cover the full digital journey.
Accessibility is not limited to the website
A common mistake is to treat accessibility as a website-only issue. The SEBI framework takes a wider view.
Digital accessibility can affect websites, mobile applications, investor portals and other digital services. It can also affect digital documents and investor communications.
For example, a PDF may contain important investment information but may not work correctly with a screen reader. A mobile application may have buttons without suitable labels. A video may not have captions. A form may require a user to complete a step that is difficult or impossible with a keyboard or assistive technology.
These problems may not be visible during an ordinary business review. A page may appear normal to a person without a disability while remaining difficult to use for another investor.
This is why an accessibility audit has a different purpose from a normal software quality review. The question is not simply whether the system works. The question is whether it can be used by the intended range of users.
The KYC process needs special attention
KYC is one area where accessibility can have direct practical importance.
SEBI’s July 2025 framework specifically addresses digital KYC, e-KYC and video KYC. It says regulated entities should provide alternatives for differently abled users. The circular gives examples such as human-assisted video KYC, scanned document uploads and voice-assisted KYC for visually impaired users.
The framework also addresses KYC and client registration forms. It provides for a disability-status field and options for specific assistance, such as a helpdesk call back. It further states that an application from a client with a disability should not be rejected by the regulated entity without review by a designated human officer. The officer is to have authority to override an automated rejection on a case-by-case basis.
This part of the framework shows why accessibility cannot sit only with the technology team.
A technology team may fix a button, form or screen. It may not control the policy that determines what happens when an automated process rejects an application.
The compliance function, operations team, customer-service team and technology team therefore need a common process.
The role of the accessibility audit
The audit is a central part of the compliance framework.
An audit can identify technical barriers that internal teams may not notice during normal testing. It can also create a record of the issues found and the steps taken to address them.
The SEBI framework refers to an accessibility audit through IAAP and covers digital platforms such as websites, mobile applications and portals.
For an intermediary, the audit should therefore be treated as a formal compliance exercise rather than a one-time design review.
The firm should also maintain a clear record of what was tested, which issues were identified, which issues were fixed, which issues remain open and why any issue remains open.
This record can become important if the firm later needs to demonstrate its compliance process.
Remediation is as important as detection
Finding an accessibility issue does not by itself resolve the compliance concern.
A useful internal process should connect each audit finding to a corrective action. The responsible team should have a clear owner, a target date and evidence of completion. After a material change, the relevant function should also test whether the issue has actually been resolved.
| Compliance stage | Main question |
|---|---|
| Platform identification | Which digital services fall within scope? |
| Audit | What accessibility barriers exist? |
| Classification | Which findings require correction and with what priority? |
| Remediation | What technical or process change is required? |
| Retest | Has the corrective action resolved the finding? |
| Evidence | Can the firm show what it did and when? |
| Governance | Has the appropriate senior function reviewed compliance? |
This approach also helps avoid a common problem: a firm may close a software ticket while the underlying investor barrier remains.
For example, a development team may mark a technical defect as fixed. A later accessibility test may show that the user journey still does not work as intended. A retest can help identify this gap.
Governance cannot sit only with IT
Digital accessibility may begin as a technology issue, but regulatory responsibility is wider.
The SEBI framework contains governance requirements and identifies senior management responsibility. It also provides for a designated Nodal Officer for accessibility compliance.
This means the issue should have a clear place within the firm’s compliance structure.
The board or senior management may not need to manage individual website defects. It should, however, have enough information to understand whether the firm has a reasonable process for compliance, whether material findings remain open and whether the October 31 deadline is achievable.
A simple management report can cover the number of platforms reviewed, the audit status, material findings, remediation status and outstanding matters.
This can provide a more useful picture than a general statement that the firm is “working on accessibility”.
Third-party vendors also matter
Many intermediaries do not build all their digital systems themselves. They may use external vendors for mobile applications, websites, KYC services, customer portals, document systems or communication tools.
This can create a compliance risk if the contract does not clearly assign responsibility for accessibility.
A regulated entity may depend on a vendor for a critical part of its investor journey, but the regulatory obligation does not necessarily disappear because the technology comes from a third party.
Vendor contracts and service arrangements should therefore receive attention. The firm may need suitable rights to obtain audit evidence, require remediation, test changes and receive support when accessibility standards change.
The vendor’s role should also be clear where a platform is jointly maintained by several parties.
Investor communication also needs care
Accessibility applies not only to the core transaction system. Investor communications can also create barriers.
SEBI’s framework refers to measures such as alternative text, closed captions, descriptive audio and Indian Sign Language videos for digital content.
The practical effect is that firms should look at how they publish information, not only where they publish it.
An image with important information may require alternative text. A video may require captions. A document may need a format that works with assistive technology.
The same principle can apply to investor notices, educational material and other digital communications, subject to the requirements applicable to the particular entity and communication.
The deadline should shape the internal timetable
October 31, 2026 may appear to provide several weeks for firms that have not yet completed the work. In practice, the remaining period can be short.
An accessibility programme can involve several parties. The firm may first need to identify all relevant platforms. It may then need to arrange the audit, receive the findings, agree on remediation, make technical changes, test those changes and maintain the supporting records.
Some changes may also require third-party involvement or a software release cycle.
A firm that waits until the final weeks may therefore face practical pressure even if the legal deadline itself remains unchanged.
A sensible internal timetable should place the audit and remediation milestones before the regulatory date. This gives the firm time to address unexpected technical problems.
What firms should retain as evidence
Legal and regulatory compliance is easier to demonstrate when the firm has a clear evidence trail.
The evidence may include the list of platforms within scope, audit reports, accessibility findings, remediation records, test results, management approvals and relevant vendor correspondence.
The firm should also retain evidence of its internal decisions where an issue requires a different treatment or where remediation takes more time than expected.
The purpose is not to create paperwork for its own sake. A clear record can help the firm explain what it assessed, what it found and what it did.
It can also help different teams understand the status of the programme.
The continuing nature of accessibility compliance
October 31, 2026 should not be treated as the end of accessibility work.
Digital platforms change often. New screens, forms, features and third-party services can introduce new accessibility barriers. A platform that meets the relevant requirements at one point can develop problems after a later software change.
SEBI’s framework therefore provides for continuing audit and compliance activity. The regulatory approach includes annual accessibility audits and related reporting requirements.
This makes accessibility closer to an ongoing control than a one-time project.
A firm that builds accessibility into its software development, vendor management and change-control processes may find it easier to maintain compliance than a firm that treats each audit as a separate exercise.
A practical compliance view
The most important question for an intermediary is not simply whether an accessibility audit has been ordered.
The more useful question is whether the firm can demonstrate a complete compliance chain.
| Question | What the firm should be able to show |
|---|---|
| What is in scope? | A current list of relevant digital platforms |
| Has the audit taken place? | The required audit report |
| Who performed the audit? | Appropriate auditor credentials and engagement records |
| What did the audit find? | A documented findings register |
| What has been fixed? | Remediation records and technical evidence |
| Was the fix tested? | Retest or validation evidence |
| Who owns compliance? | Named internal responsibility |
| Has senior management reviewed the position? | Relevant governance records |
| Are vendors covered? | Contract and oversight evidence |
| What happens after October 31? | A continuing accessibility control process |
This approach also reduces the risk of a narrow interpretation of compliance.
For example, a firm may complete a website audit but overlook its mobile application. Another firm may fix its registration page but fail to examine KYC. A third may address the technology but overlook investor communications.
A complete review should consider the investor’s journey from the first digital interaction through registration, service use, communication and support.
What October 31 should mean for senior management
For senior management, the October 31 deadline should be treated as a compliance milestone that requires clear ownership and evidence.
The immediate focus should be on whether all relevant platforms have been identified, whether the required audit has taken place, whether the audit findings are known and whether the remediation plan can reach completion within the revised timeline.
The firm should also be careful with statements such as “fully compliant” unless it has sufficient evidence to support that statement.
A more defensible internal approach is to state the precise position. For example, management reporting can distinguish between platforms that have completed an audit, platforms under remediation and matters that remain open.
This makes the compliance position easier to understand and reduces the risk of broad statements that do not match the underlying evidence.
Conclusion
SEBI’s digital accessibility framework places accessibility within the compliance responsibilities of regulated entities. The July 31, 2025 circular established the wider framework, while subsequent SEBI circulars provided extensions to the compliance timetable.
The latest extension, dated July 31, 2026, makes October 31, 2026 the key date for the current compliance exercise.
For capital-market intermediaries, the practical task goes beyond checking whether a website looks accessible. The firm needs to consider its digital platforms, KYC processes, investor communications, customer support, third-party technology and internal governance.
The safest approach is also the simplest: identify what is in scope, obtain the required audit, record the findings, complete the required remediation, test the changes and preserve clear evidence of the work.
Accessibility should then remain part of the firm’s normal technology and compliance controls. The October 31 deadline is therefore best treated not as the end of the process, but as a major point by which the firm’s current digital accessibility position should be capable of clear demonstration.
This article is for general regulatory analysis and does not constitute legal advice. Applicability and specific obligations may differ based on the nature of the regulated entity, its digital services and subsequent SEBI directions. Firms should review the applicable SEBI circulars and obtain professional advice where required.
ALSO READ: SEBI’s Closing Auction: Surveillance Gains vs Trader Costs