SEBI's Digital Accessibility Audit Deadline Is 31 October. The Audit Is the Easy Part.
Three weeks remain. Logged-in flows, OTP timeouts and generated PDFs are where regulated entities fail.
SEBI has extended the deadline for regulated entities to complete their digital accessibility audit and fix what it finds to 31 October 2026. That leaves three weeks. The extension circular is dated 31 July 2026, and it addresses stock exchanges, clearing corporations, depositories, intermediaries and industry bodies such as AMFI. If you run a broker app, an AMC portal or an advisory platform, or you build one for a client who does, the SEBI digital accessibility audit is now a dated engineering task.
Most coverage treats this as a paperwork exercise: hire an auditor, file the report. The harder part is the second half of the sentence, remediation, and the part of your product an auditor spends the most time on: logged-in flows with OTPs, timeouts, charts and generated PDFs.
Where the SEBI digital accessibility audit comes from
The chain starts in the Supreme Court. On 30 April 2025, in Pragya Prasun v. Union of India and Amar Jain v. Union of India, the Court described digital access as part of the right to life and personal liberty and directed that digital KYC and similar public-facing systems be made accessible. SEBI followed with a circular on 31 July 2025 for all its regulated entities, and compliance guidelines on 25 September 2025, according to law-firm summaries.
The legal footing for the 2026 extension is the Rights of Persons with Disabilities Act, 2016 and its rules, with SEBI acting under Section 11(1) of the SEBI Act, 1992. All other provisions of the earlier circulars stay in force. An extension changes one date. It does not soften the obligation.
The detail that changes your vendor contract
Several law-firm summaries make the same point: responsibility for accessibility sits with the regulated entity, not with the vendor that built the platform. If your customer is a SEBI-registered intermediary, their audit finding is their regulatory problem, and the contract is where it becomes yours.
Vendors serving this segment should expect three requests in the next three weeks. A copy of any accessibility conformance statement for the product. A remediation timeline for known failures. A clause making accessibility defects a warranty item rather than a feature request. Having a dated answer ready is cheaper than negotiating one under deadline pressure.
Where logged-in financial flows fail
Marketing pages are rarely the problem. Failures cluster in the flows where a user proves identity or moves money, because those flows were built with security controls that assume a sighted user with a mouse and quick reflexes.
| Flow | Typical failure | WCAG criterion | Fix |
|---|---|---|---|
| Login and OTP | Image CAPTCHA with no alternative | 1.1.1 Non-text content | Offer a non-visual challenge or drop the CAPTCHA for risk-based checks |
| Login and OTP | OTP expires in 30 seconds with no way to extend | 2.2.1 Timing adjustable | Let users request more time or resend without losing the form |
| Order entry | Error shown only as a red border | 1.4.1 Use of colour; 3.3.1 Error identification | Add text that names the field and the problem, linked with aria-describedby |
| Dashboards | Portfolio chart readable only visually | 1.1.1; 1.3.1 Info and relationships | Provide a data table or text summary alongside the chart |
| Modals and sheets | Focus escapes the dialog or is lost on close | 2.4.3 Focus order; 4.1.2 Name, role, value | Trap focus, return it to the trigger, label the dialog |
| Statements | Generated PDF has no tags or reading order | 1.3.1 | Emit tagged PDFs from the generator, test with a screen reader |
| Video KYC | Liveness prompt relies on sight or speech only | 1.1.1; 2.1.1 Keyboard | Provide the human-assisted alternative the circulars describe |
The KYC row deserves attention. Summaries of the circulars describe accessible alternatives for digital KYC, such as human-assisted video KYC and document upload, and say that automated rejections of applicants with disabilities should get human review. That is a process requirement as much as an interface one, so engineering cannot close it alone.
A three-week plan for the audit and remediation
Three weeks is enough to triage and fix the highest-impact defects. It is not enough to rebuild a design system. Sequence the work so that the audit report shows a defensible trajectory.
- Days 1 to 3: list every user-facing flow, including authenticated ones, and mark which an auditor must test with a login. Get test accounts provisioned now.
- Days 3 to 7: run automated checks on each flow and fix what they find. Automated tools catch only a portion of WCAG failures, so treat a clean run as the floor.
- Days 7 to 14: do manual passes with keyboard only and a screen reader (NVDA on Windows, VoiceOver on iOS) on login, KYC, order entry and statements.
- Days 14 to 21: fix, retest, and write down every defect you chose not to fix, with a date and an owner. An honest backlog reads better to an auditor than a claim of zero.
import { test, expect } from '@playwright/test';
import AxeBuilder from '@axe-core/playwright';
// Authenticated flows need a stored session: use storageState in playwright.config.
const flows = ['/login', '/kyc/start', '/orders/new', '/statements'];
for (const path of flows) {
test(`axe: ${path}`, async ({ page }) => {
await page.goto(path);
const results = await new AxeBuilder({ page })
.withTags(['wcag2a', 'wcag2aa', 'wcag21a', 'wcag21aa'])
.analyze();
expect(results.violations).toEqual([]);
});
}Wire this into CI so a regression fails the build. It will not replace the manual passes, but it stops fixed defects from returning in the next release.
What 31 October does and does not close
Passing the audit window means a report exists and findings are being fixed. It does not make a product accessible for good. Every release that adds a modal, a chart or a new verification step can reintroduce a failure, and SEBI's summaries describe accessibility as an ongoing compliance duty rather than a one-time certificate.
The more interesting question is what happens next. Other Indian regulators have the same Supreme Court judgment to work from, and banking, insurance and payments flows share most of the failure modes in the table above. Teams that build the CI checks and the manual test habit now will carry them into those next circulars.
Frequently asked questions
Related reading
Cross-Border Card Authentication: RBI's 1 October Deadline Is a Switch, Not an OTP on Every Purchase
RBI's 1 October 2026 deadline obliges Indian card issuers to honour authentication requests from overseas merchants. It does not put an OTP on every foreign purchase.
The 13 November DPDP Consent Manager Deadline Is Not Your Deadline
Rule 4 of the DPDP Rules starts on 13 November 2026, but it regulates who may register as a consent manager. Your own obligations begin on 13 May 2027.
India's UPI Moved 22 Billion Transactions in March. ONDC Moved Under 4 Million.
UPI cleared 22 billion transactions in March 2026. ONDC's retail volume is under 4 million a month and falling. The difference isn't technical — it's who has to give up revenue to participate.