Know where AI and ML are used
Applicable firms need a defensible inventory and reporting path across internally developed and third-party systems.
Govern client data, model and tool actions, human responsibility, retention, and audit reconstruction across advisory, trading, and market-infrastructure workflows.
SEBI's AI/ML position is layered. Reporting circulars have applied to several securities-market populations since 2019. Regulation 16C strengthened the regulated entity's responsibility for client data, output, and legal compliance in 2025. SEBI's June 2025 responsible-AI paper was a consultation, so teams should verify whether later circulars have adopted specific proposals.
Applicable firms need a defensible inventory and reporting path across internally developed and third-party systems.
The regulated entity remains responsible for client-data safeguards, outputs, and compliance even when an external AI tool is used.
Advisory, research, trading, surveillance, and investor-facing outputs require traceable policy and human responsibility.
| Review question | Runtime control | Evidence path |
|---|---|---|
| Was client data exposed? | Detect configured personal and financial identifiers before model or connector access. | Detection category, policy action, request context, and downstream access logs. |
| Who was responsible for the output? | Attach user, system, tenant, model, and policy context to governed activity. | Correlated record plus the firm's system inventory and accountable owner. |
| Was a material action reviewed? | Pause configured advisory, trading, disclosure, or customer-impacting actions. | Reviewer identity, decision, reason, timestamp, and execution outcome. |
| Can the event be reconstructed? | Carry correlation context across policy, model, connector, and downstream systems. | AxonFlow decision records joined to order, trade, communication, or case logs. |
| Is the evidence ready for review? | Use licensed SEBI-oriented retention, readiness, dashboard, and export workflows. | Scoped export plus gaps identified before internal audit or regulator engagement. |
Control client-specific context, disclosure, unsupported claims, and the human responsibility for recommendations or published research.
Require deterministic policy and approval outside the model before a tool can place, modify, or cancel an order.
Record how an AI-assisted alert was generated, triaged, escalated, and resolved without treating the model as final authority.
Protect personal data and preserve the model, policy, source context, and reviewer path behind material communications.
Enforce controls at the runtime boundary even when the regulated entity does not own the model or external tool.
Test the ability to stop affected workflows, preserve records, correct downstream effects, and demonstrate accountable recovery.
Use the Evaluation license to assess policy enforcement, human review, evidence records, and deployment boundaries before a regulated rollout.