Advertisement
Advertisement
Skip to content
Follow Us on
Advertisement
TOP STORIES
SEBI

Process of SCORES Registration for SEBI Intermediary

Advertisement

Investor protection is a key objective of the Securities and Exchange Board of India (SEBI). To ensure that investor complaints are addressed fairly and within a fixed timeline, SEBI requires registered intermediaries and other regulated entities to maintain an effective grievance-redressal system. Investors may face issues such as unauthorised transactions, non-receipt of funds or securities, incorrect charges, delayed account statements, failure to update records or poor service. Such grievances can be filed and tracked through the SEBI Complaint Redress System, commonly known as SCORES.

For SEBI intermediaries, access to SCORES is a mandatory compliance requirement. The intermediary must review complaints, communicate with investors, take corrective action and submit an Action Taken Report within the prescribed period. Although commonly called SCORES Registration, the official term is SCORES Authentication. For most intermediaries registered after 2 August 2019, SCORES credentials are generated automatically and sent to the registered compliance officer or contact person.

Understanding the SCORES Platform

Meaning of SCORES

SCORES stands for the SEBI Complaint Redress System. It is an online platform established by SEBI to facilitate the lodging, forwarding, monitoring and resolution of complaints relating to the securities market. Through SCORES, an investor can lodge a complaint against a listed company, a SEBI-registered intermediary or a Market Infrastructure Institution. The complaint is forwarded to the concerned entity for examination and appropriate action.

SCORES also enables the complainant to monitor the progress of the grievance. The platform records the response of the regulated entity, the Action Taken Report submitted by it and any subsequent request for review. SEBI describes SCORES as a facilitative platform through which complainants may seek redressal of grievances from the concerned entity. It is not intended to replace every form of legal adjudication, arbitration or dispute resolution.

Objective of SCORES

The principal objective of SCORES is to ensure that investor grievances are not ignored or indefinitely delayed by regulated entities. The platform introduces accountability by fixing timelines, recording the complete history of action taken and automatically escalating matters where the concerned entity fails to respond within the prescribed period.

SCORES also improves transparency because the complainant can view the status of the complaint and the response submitted by the intermediary. Similarly, the intermediary can monitor pending complaints through its Entity Dashboard.

SCORES as a regulatory monitoring system

SCORES is not merely an electronic complaint mailbox. It is also a regulatory monitoring mechanism. The platform helps SEBI and the concerned Designated Bodies assess whether a particular intermediary is handling investor complaints promptly and effectively.

A recurring pattern of delayed, incomplete or unsatisfactory responses may indicate weakness in the intermediary’s compliance and grievance-redressal systems. For this reason, every complaint should be treated as a compliance matter rather than as an ordinary customer-service query.

Matters that may be raised on SCORES

Investors may use SCORES for grievances relating to securities-market services provided by regulated entities. For example, a complaint against an intermediary may relate to non-receipt of documents, improper charges, delay in execution of instructions, unauthorised transactions, non-payment of amounts, failure to update client information, misrepresentation, deficiency in advisory services or failure to respond to an earlier grievance. The exact nature of complaints will depend upon the intermediary’s category and the activities permitted under its SEBI registration.

Matters that may require another forum

SCORES is primarily meant to facilitate grievance redressal. Certain disputes may involve detailed examination of evidence, determination of third-party rights or adjudication of disputed questions of law and fact. Such matters may need to be taken to the Online Dispute Resolution mechanism, arbitration, consumer commission, civil court or another appropriate forum.

The current SCORES framework expressly recognises that a complaint may be disposed of where the issues require adjudication, involve a legal dispute between parties or where the complainant opts for the Online Dispute Resolution mechanism or another civil remedy.

Introduction and Importance of SCORES 2.0

Launch of the upgraded platform

SEBI introduced the upgraded SCORES 2.0 platform in April 2024. The upgraded system was designed to improve the speed, transparency and effectiveness of investor grievance redressal through greater automation and monitoring.

SCORES 2.0 introduced an improved workflow under which complaints are automatically routed to the concerned entity, timelines are displayed on the dashboard and unresolved matters are escalated through the review mechanism.

Automatic routing of complaints

Under the upgraded system, a complaint lodged by an investor is automatically assigned to the concerned entity. This reduces the time that would otherwise be spent manually identifying and forwarding the complaint. It also places immediate responsibility on the intermediary to examine the matter.

However, the entity must ensure that its registration category and profile details are accurate. An incorrect mapping may result in a complaint being assigned to the wrong category or being overlooked.

Time-bound redressal

The intermediary is required to submit its Action Taken Report within 21 calendar days from the date of receipt of the complaint on SCORES.

The use of the term “calendar days” is important. Weekends and public holidays are included while calculating the deadline. The intermediary should therefore not treat the available period as 21 working days.

Dashboard-based monitoring

The Entity Dashboard displays pending complaints and the time available for taking action. This facility enables the compliance officer to monitor the age of every complaint and identify matters approaching the deadline.

The intermediary should nevertheless maintain its own internal complaint tracker. Depending entirely upon the dashboard without internal control may create a risk of missed deadlines, particularly where several complaints are pending simultaneously.

Two-level review mechanism

SCORES 2.0 provides a two-level review mechanism. At the first stage, the complaint is initially handled by the concerned intermediary. If the complainant is dissatisfied with the Action Taken Report or if the intermediary fails to respond within the prescribed period, the matter may proceed to the first-level review by the Designated Body or SEBI where no Designated Body exists. Where the complainant remains dissatisfied with the result of the first-level review, a second-level review may be sought from SEBI.

Meaning of SCORES Registration and SCORES Authentication

Why the expression “registration” is commonly used

In professional practice, applicants often use the expression “SCORES Registration” because the entity is required to obtain portal access after receiving SEBI registration. However, SCORES access for an intermediary is technically referred to as authentication. The intermediary receives a user ID and password linked to its SEBI registration.

Difference between SEBI registration and SCORES authentication

SEBI registration permits an applicant to carry on a particular regulated activity. For example, an entity may be registered as a Portfolio Manager, Investment Adviser, Research Analyst, Merchant Banker or another category of intermediary.

SCORES authentication, on the other hand, enables that registered entity to access the grievance-redressal portal and respond to complaints lodged against it. Therefore, SCORES authentication does not replace the principal SEBI registration. It is a post-registration access requirement connected with the regulatory status of the entity.

Difference between an investor account and entity authentication

An investor who wishes to lodge a complaint creates an investor account on SCORES. The investor’s registration involves verification of personal and KYC details. A SEBI intermediary should not use an investor account to respond to complaints. It must use the entity-specific credentials issued against its SEBI registration. Creating an investor account in the name of the compliance officer will not provide access to the Entity Dashboard or complaints lodged against the intermediary.

Separate authentication for each registration category

Where an entity holds more than one category of SEBI registration, separate SCORES authentication is required for each category. For example, an entity registered both as a Merchant Banker and as a Portfolio Manager must ensure that authentication exists for both categories.

This requirement is important because complaints are classified and routed according to the relevant intermediary category. Authentication for one category should not be assumed to cover another registration.

Entities Required to Obtain SCORES Authentication

Mandatory nature of the requirement

SEBI’s official SCORES FAQs state that all listed companies, SEBI-registered intermediaries and Market Infrastructure Institutions are required to obtain SCORES authentication.

This means that authentication is not optional. An intermediary cannot avoid the requirement merely because it has a small number of clients or has not previously received any complaint.

Illustrative categories of intermediaries

The requirement may apply to different categories of SEBI-regulated entities, including stock brokers, depository participants, merchant bankers, portfolio managers, investment advisers, research analysts, debenture trustees, credit rating agencies, registrars to an issue and share transfer agents, bankers to an issue, custodians, underwriters and other registered intermediaries.

The exact compliance procedure may differ depending upon the intermediary category and the institution through which registration or post-registration activities are administered.

Requirement for newly registered intermediaries

A newly registered intermediary should verify the generation of its SCORES credentials immediately after receiving the registration certificate.

It should not assume that there is no obligation until a complaint is filed. A complaint may be lodged at any time, and inability to access the portal may result in failure to respond within the prescribed timeline.

Requirement for existing or older intermediaries

An intermediary registered before the introduction of the automated authentication process should verify whether it has valid and accessible SCORES credentials. Older credentials may have been sent to a former compliance officer, an outdated email address or an employee who is no longer associated with the entity. The intermediary must ensure that access remains active and that current authorised officers are able to receive OTPs and portal communications.

Legal and Regulatory Context

SEBI Act, 1992

The overall regulatory context derives from the Securities and Exchange Board of India Act, 1992. SEBI exercises powers to protect the interests of investors, promote the development of the securities market and regulate securities-market activities. The SCORES mechanism forms part of SEBI’s investor-protection and regulatory-supervision context.

Circular dated 2 August 2019

SEBI issued Circular No. SEBI/HO/OIAE/IGRD/CIR/P/2019/86 dated 2 August 2019 for streamlining the issuance of SCORES authentication to SEBI-registered intermediaries. The circular introduced an automated process for generating SCORES credentials after completion of the online registration process.

Circular dated 20 September 2023

SEBI issued Circular No. SEBI/HO/OIAE/IGRD/CIR/P/2023/156 dated 20 September 2023 relating to investor grievance redressal through SCORES and linkage with the Online Dispute Resolution platform. The circular forms an important part of the present grievance-handling framework and provides for automatic routing, timelines, Designated Bodies and review mechanisms.

Category-specific regulations and master circulars

Apart from the general SCORES framework, an intermediary must comply with the regulations and master circulars applicable to its category. Such provisions may require appointment of a compliance officer, maintenance of complaint records, disclosure of grievance-redressal contact details, submission of periodic reports and prompt resolution of complaints. Therefore, SCORES compliance should be read together with the intermediary’s category-specific regulatory obligations.

Investor Charter requirements

SEBI has issued Investor Charters for different categories of intermediaries. An Investor Charter generally explains the services provided by the intermediary, rights and responsibilities of investors, grievance-redressal procedure and expected timelines. The intermediary should ensure that the grievance process described in its Investor Charter, website, client agreements and internal policy is consistent with the current SCORES framework.

Preconditions for SCORES Authentication

Grant of SEBI registration

The applicant must first obtain registration as a SEBI intermediary. SCORES credentials are generally linked to the online grant of registration. Therefore, the applicant must complete the regulatory application process before expecting the credentials to be generated.

Correct identification of the intermediary category

The applicant must identify the correct registration category based on its proposed activities. This is important because the SCORES authentication will be linked to the registration number and category granted by SEBI. An incorrect category may create difficulties in complaint routing, profile mapping and regulatory reporting.

Appointment of a compliance officer

Where required under the applicable regulations, the intermediary must appoint a compliance officer. The compliance officer is ordinarily responsible for monitoring the SCORES dashboard, coordinating internal investigation, ensuring timely resolution and submitting the Action Taken Report.

The entity should appoint a person who has sufficient authority and access to records. Merely designating a junior employee without decision-making support may delay complaint resolution.

Availability of an official email address

The email address entered in the registration application is extremely important because the SCORES user ID and password are generally sent to the email address of the contact person or compliance officer.

The email address should be active, correctly spelled and continuously monitored. A role-based address connected with compliance or investor grievances is generally preferable to the personal email address of an employee.

Availability of an active mobile number

The contact number provided to SEBI should remain active and accessible to the authorised officer. The intermediary should promptly update the contact details when the compliance officer changes or the registered number is discontinued.

Accurate entity information

The intermediary should ensure that its legal name, PAN, registered office, correspondence address, registration category and constitution are correctly reflected in the registration records. Incorrect information may cause authentication errors or create inconsistency between the SEBI certificate, SI Portal and SCORES profile.

Documents and Information to Be Kept Ready

Whether a separate document application is required

For intermediaries registered after 2 August 2019, authentication is ordinarily automated. Therefore, a separate document-based SCORES application may not be required in a normal case.

However, the intermediary should keep all relevant records ready because documents may be required where credentials are not received, the account cannot be accessed or profile information needs correction.

SEBI registration certificate

The registration certificate is the principal document establishing the entity’s status as a SEBI intermediary. It generally contains the legal name, registration number and category of the intermediary. The compliance officer should verify that the details appearing in the SCORES profile correspond with the registration certificate.

PAN of the entity

The PAN should match the legal name appearing on the registration certificate and constitutional documents. Any difference caused by a change of name, merger or restructuring should be formally corrected through the applicable regulatory process.

Constitutional documents

Depending upon the legal structure of the intermediary, the relevant records may include the certificate of incorporation, memorandum and articles of association, LLP incorporation certificate, LLP agreement, partnership deed, trust deed or another constitutional document. These records may be required where the legal name or constitution appearing on the portal is disputed or incorrect.

Registered office proof

The intermediary should maintain updated proof of the registered office and correspondence address. This may include a utility bill, lease deed, ownership document or another record accepted under the applicable registration framework.

Compliance officer’s appointment documents

The entity should preserve the compliance officer’s appointment letter, Board resolution, partners’ resolution or management approval, wherever applicable. These documents establish that the person seeking correction or access is authorised to act on behalf of the intermediary.

Contact-person details

The entity should maintain the name, designation, official email address, mobile number and date of appointment of the compliance officer or contact person. A record should also be maintained of any previous contact person whose email may have been used during the original registration process.

SI Portal records

The intermediary should preserve the application number, acknowledgement, registration form, deficiency responses and approval communication generated through the SEBI Intermediaries Portal or other applicable registration platform. These records help identify the email address and contact details originally provided to SEBI.

Documents for resolving login discrepancies

Where the intermediary is unable to access SCORES, it should keep ready the registration certificate, PAN, screenshot of the error message, screenshot of the SI Portal profile, authorisation letter, compliance officer’s appointment document and proof of the registered email address. A properly documented request is more likely to be resolved promptly than a general email stating only that the login is not working.

Process for SCORES Authentication

Step 1: Complete the intermediary registration process

Determine the appropriate category

The applicant must first determine the registration category applicable to the proposed securities-market activity. The nature of the activity should be examined carefully. For example, investment advice, securities research, portfolio management, merchant banking and stock-broking are separately regulated activities.

Submit the registration application

The applicant should submit the registration application through the platform or institution prescribed for the relevant category. For several categories, the process may be undertaken through the SEBI Intermediaries Portal. For certain intermediaries, applications and post-registration activities may be routed through a recognised stock exchange, depository or recognised body.

Respond to regulatory queries

During examination of the application, the applicant may receive deficiency letters or requests for clarification. The applicant must provide complete and accurate responses regarding qualifications, experience, infrastructure, net worth, fit-and-proper status, internal policies and proposed operations.

Pay the applicable fees

The applicant should pay the application fee, registration fee and other charges prescribed for the relevant category. Proof of payment should be preserved as part of the registration records.

Obtain the certificate of registration

After the competent authority is satisfied that the applicant meets the applicable requirements, a certificate of registration may be granted. The applicant should carefully verify the registration number, legal name and intermediary category mentioned in the certificate.

Step 2: Verify details submitted during registration

Check the contact person’s name

The applicant should verify the name of the person entered as the contact person or compliance officer. Where the person has changed during the registration process, the information should be updated before completion of registration wherever possible.

Check the registered email address

The email address should be checked character by character. A minor spelling error can prevent delivery of the SCORES credentials. The mailbox should remain active even after the registration process is completed.

Use an institutional email address

An institutional or role-based email address provides better continuity. For example, a compliance-related mailbox can remain operational even where the individual compliance officer resigns or changes.

Review email security controls

The entity should ensure that automated emails from SEBI are not blocked by security filters. The information technology team may need to whitelist the relevant domain or search the organisation’s email quarantine system.

Step 3: Automatic generation of credentials

Applicability of the automated process

The procedure for generation of the SCORES user ID and password is fully automated for SEBI-registered intermediaries and Market Infrastructure Institutions registered or recognised after 2 August 2019. The credentials are generated upon completion of the online process for grant of registration.

Delivery of credentials

The user ID and password are sent through an automatically generated email to the contact person or compliance officer whose email address was provided in the online registration form. The intermediary should monitor that email account immediately after the registration is granted.

Separate credentials for each category

Where the entity has received more than one registration, it should verify whether authentication has been generated for each category. A category-wise record should be prepared containing the registration number, SCORES user ID, registered email address and responsible officer.

No need to create an investor account

The entity should not create a normal investor profile merely because the credential email has not been located. An investor profile is not connected to the intermediary’s regulated entity dashboard.

Step 4: Search and verify the credential email

Check the inbox and spam folder

The compliance officer should check the inbox, spam folder, junk folder, archived messages and email quarantine system. Automated emails may sometimes be filtered due to organisational security policies.

Search using relevant keywords

The mailbox may be searched using the terms “SCORES,” “SEBI,” “authentication,” “user ID,” “password” or the SEBI registration number.

Check former compliance mailboxes

Where the registration was granted several years ago, the credentials may have been sent to a previous compliance officer. The entity should review archived compliance records and mailboxes before requesting new credentials.

Confirm whether the mailbox is still active

Where the registered email address no longer exists, the intermediary may first need to update the email through the prescribed regulatory route. Creating a new email address with a similar name will not automatically redirect the original portal communications.

Step 5: Login to the SCORES portal

Access the official login page

The intermediary should access the current SCORES platform and select the sign-in option. The same landing page is used by complainants, entities and Designated Bodies.

Enter the entity user ID

The user ID issued against the SEBI registration should be entered. The entity must ensure that it is using the credentials associated with the correct registration category.

Complete OTP verification

The user ID is verified through an OTP sent to the entity’s registered email address. The person logging in should therefore have authorised access to that mailbox.

Enter the password

After OTP verification, the password should be entered to access the Entity Dashboard. Where the password is unavailable, the intermediary should use the portal’s recovery facility instead of repeatedly attempting incorrect passwords.

Secure the credentials after login

The initial password should be changed where the system permits or requires it. The credentials should be stored through a secure access-management process rather than in an unsecured spreadsheet, personal notebook or messaging application.

Step 6: Verify the Entity Profile

Verify the legal name

The legal name displayed on SCORES should match the registration certificate. Any mismatch involving abbreviations, change of name or conversion of legal structure should be examined and corrected.

Verify the registration number

The registration number should be checked carefully. The compliance officer should confirm that the account is linked to the correct certificate and not to an earlier, surrendered or unrelated registration.

Verify the intermediary category

The category displayed on the profile should correspond with the activities permitted under the registration. This is particularly important for entities holding several registrations.

Verify the address and telephone number

The registered office, correspondence address and telephone number should be current. The official FAQs permit entities to update certain details, including their address, compliance officer information and telephone numbers.

Verify the compliance officer’s details

The name, designation and contact information of the compliance officer should be reviewed. If the officer has changed, the information should be updated promptly.

Identify restricted fields

According to the official SCORES FAQs, certain fields such as the entity name, state and primary email address cannot ordinarily be updated directly by the entity. A formal request must be made through the prescribed process for changing such restricted details.

Step 7: Establish internal access controls

Nominate the primary responsible officer

The compliance officer should ordinarily be the principal person responsible for SCORES monitoring. The responsibility should be documented in the employment terms, compliance policy or internal SOP.

Nominate a backup officer

A backup officer should be appointed to monitor SCORES during the primary officer’s leave, illness, resignation or unavailability. The regulatory timeline continues to run even where an employee is absent.

Restrict credential sharing

The credentials should not be circulated among several employees without control. Where internal departments need complaint information, the compliance team should provide the relevant records without unnecessarily sharing the portal password.

Maintain an access register

The entity may maintain a record of persons authorised to access SCORES, dates of password changes and changes in the responsible officer. This becomes particularly useful during internal audits, inspections and employee transitions.

Understanding the SCORES Entity Dashboard

Pending Auto-Assigned Complaints

This section displays complaints automatically assigned to the intermediary. The entity is required to examine each complaint and submit an Action Taken Report within 21 calendar days. The compliance officer should review this section regularly and record the date on which each complaint was received.

Pending First-Level Review Complaints

This section contains complaints forwarded during the first-level review. A complaint may appear in this section where the complainant is dissatisfied with the entity’s initial Action Taken Report or where the entity failed to submit an ATR within 21 calendar days. The intermediary may be required to provide a revised report or further clarification.

Pending SEBI Review Complaints

This section contains second-level review matters forwarded by SEBI. Such matters may arise where the complainant is dissatisfied with the first-level review or where the Designated Body has not submitted its response within the prescribed period. A request received from SEBI at this stage should be treated as a high-priority regulatory matter.

CPGRAMS Complaints

Complaints received through the Centralised Public Grievance Redress and Monitoring System may also be routed through the SCORES dashboard. The Action Taken Report submitted by the intermediary in such cases may be routed to SEBI.

CPGRAMS Appeals

The dashboard may contain appeals relating to the closure of complaints received through CPGRAMS. The intermediary may be asked to provide a revised or more detailed response.

Reports section

The Reports section enables the intermediary to generate customised complaint reports. These reports may be used for ageing analysis, management reporting, inspection preparation and identification of recurring grievance categories.

My Profile section

The My Profile section contains registration details of the entity. The profile should be reviewed periodically and whenever there is a change in address, telephone number, compliance officer or other relevant information.

Procedure Where Credentials Are Not Received

  • Verify whether authentication already exists: The first step is to determine whether the credentials were previously generated. The intermediary should search old mailboxes, regulatory records and correspondence maintained by previous compliance officers.
  • Check the original registration form: The entity should verify the email address mentioned in the original registration application. The credentials may have been sent to an email address that is no longer actively monitored.
  • Use the password-recovery facility: Where the user ID is known but the password has been forgotten, the intermediary should use the portal’s password-recovery process. Repeated incorrect login attempts should be avoided because they may temporarily restrict access.
  • Verify access to the primary email address: Because OTP verification is linked to the registered email address, recovery of the password alone may not solve the problem if the mailbox is inaccessible. The entity may need to update the primary email address through the prescribed process.
  • Raise a detailed support request: Where the problem remains unresolved, the entity should raise a detailed request with the SCORES support or concerned regulatory authority. The request should state the legal name, PAN, SEBI registration number, intermediary category, registration date, name of the compliance officer, registered email address and exact nature of the error.
  • Attach supporting documents: The support request should be accompanied by the registration certificate, PAN, authorisation letter, compliance officer appointment proof, screenshot of the error and screenshot of the entity’s registration profile, wherever relevant.
  • Follow up through the appropriate regulatory channel: For certain intermediary categories, post-registration changes may be handled through a recognised body, stock exchange, depository or another institution. The entity should follow the channel applicable to its category rather than sending requests to unrelated departments.

Updating Details After Authentication

  • Obligation to maintain current information: Authentication is not a one-time exercise. The intermediary must ensure that its profile remains accurate throughout the period of registration. Outdated information may result in missed OTPs, complaints or regulatory communications.
  • Change of compliance officer: Whenever the compliance officer resigns or is replaced, the entity should immediately review the SCORES profile and email access. The outgoing officer’s access should be revoked, and the password should be changed. The new officer should be formally authorised and trained in the complaint-handling procedure.
  • Change of registered office: A change of registered office should be updated through the applicable regulatory process and in the SCORES profile. The entity should ensure consistency across the registration certificate, SEBI records, website, client documents and grievance-redressal disclosures.
  • Change of telephone number: An inactive telephone number may prevent effective communication. The number should be updated promptly and should ordinarily be connected with the compliance or grievance-redressal function.
  • Change of primary email address: The primary email address may be a restricted field that cannot be changed directly by the entity. The intermediary should submit a formal request through the prescribed process and maintain documentary evidence of the request until the change is completed.
  • Change of legal name or constitution: A change of legal name, conversion, merger, amalgamation or restructuring may require prior approval or intimation under the applicable regulations. After completing the regulatory process, corresponding changes should be made in SCORES and other official systems.

Duties After Obtaining SCORES Authentication

  • Regular monitoring: The intermediary should monitor the dashboard regularly, preferably on every working day. Email alerts should be treated as an additional facility and not as a substitute for direct portal monitoring.
  • Immediate download and recording of complaints: Whenever a complaint is received, the compliance officer should download the complaint and supporting documents. The complaint number, date of receipt and statutory due date should be entered in the internal grievance register.
  • Identification of the responsible department: The complaint should be forwarded internally to the department responsible for the relevant service or transaction. For example, the matter may require information from operations, finance, advisory, dealing, technology, client servicing or legal departments.
  • Fixing an internal deadline: Although the regulatory timeline is 21 calendar days, the intermediary should establish a shorter internal deadline. An internal period of approximately 10 to 15 days may provide sufficient time for verification, corrective action and compliance review.
  • Review of supporting records: The entity should examine all relevant records before responding. Such records may include client agreements, account statements, transaction logs, call recordings, emails, payment records, advisory reports, research reports, invoices, system logs and internal approvals.
  • Communication with the complainant: Where clarification is required, the entity may seek it through SCORES. The platform allows the entity to use the “Seek Clarification” function, and the complainant receives email and SMS notifications. The clarification should be specific and necessary. It should not be used merely to delay resolution.
  • Corrective action before filing the ATR: Where the complaint is valid, the intermediary should take actual corrective action before filing the Action Taken Report. Merely promising that the issue will be addressed later may not amount to proper redressal.

Preparation and Submission of the Action Taken Report

  • Meaning of ATR: The Action Taken Report, or ATR, is the formal response submitted by the intermediary explaining how the investor’s complaint has been examined and resolved. It should provide a complete picture of the facts, findings and remedial action.
  • Statutory timeline: The ATR must be submitted within 21 calendar days from the date of receipt of the complaint on SCORES. The intermediary should not wait until the final day. Technical issues, approval delays or absence of the authorised officer may otherwise result in non-compliance.
  • Opening part of the ATR: The ATR should begin by identifying the complaint and briefly summarising the grievance. The response should demonstrate that the entity has understood the actual issue raised by the investor.
  • Statement of facts: The entity should provide a concise but complete account of the relevant facts. The statement should include the nature of the relationship, relevant dates, transactions, communication and action already taken.
  • Examination undertaken: The ATR should explain the records reviewed and the findings reached. For example, it may state that the entity examined the client agreement, transaction records, payment confirmation, communication history and internal system logs.
  • Regulatory and contractual position: Where the entity relies upon a particular regulation, circular, agreement or policy, the relevant provision should be explained in simple language. The response should not merely cite a clause without explaining its relevance.
  • Corrective action: The ATR should clearly state the corrective action taken. This may include refunding an amount, reversing a charge, correcting an account, providing a pending document, updating client records or improving an internal process.
  • Date of completion: The date on which the corrective action was completed should be mentioned. Where payment has been made, the payment reference number may also be included.
  • Supporting documents: Relevant supporting documents should be attached. The intermediary should ensure that the annexures are readable, properly named and directly connected with the explanation given in the ATR.
  • Internal approval of the ATR: Complex or sensitive ATRs should be reviewed by the compliance officer and, where appropriate, the legal team or senior management before submission. However, the internal approval process must be structured so that it does not cause delay beyond 21 calendar days.

Examples of Inadequate Action Taken Reports

“The matter has been resolved”

This statement does not explain what action was taken, when it was taken or whether the investor received the required relief.

“The complaint is false”

A complaint should not be rejected using a bare allegation. The entity should provide reasons and supporting records demonstrating why the complaint is not maintainable or factually correct.

“The investor has been informed”

The ATR should specify what information was provided and attach the relevant communication.

“The matter does not pertain to us”

Where the complaint has been wrongly assigned, the entity should explain why it does not pertain to it and, where possible, identify the appropriate entity.

“The issue is under process”

This response may not amount to redressal. The entity should complete the necessary action within the prescribed period or clearly explain the legal or factual impediment.

Complaint Lodged Against the Wrong Entity

  • Request for transfer: Where a complaint does not pertain to the intermediary, the entity may request the concerned Designated Body, where available, to transfer it to the appropriate entity.
  • Alternative response through ATR: Alternatively, the intermediary may submit an ATR advising the complainant to lodge the complaint against the appropriate entity. The response should explain the basis on which the intermediary has concluded that the matter does not relate to it.
  • Importance of timely action: The intermediary should not ignore the complaint merely because it believes that it has been incorrectly assigned. Until the complaint is transferred or properly responded to, the regulatory timeline may continue to run.
  • Internal verification before denying responsibility: Before stating that a complaint does not pertain to the entity, the compliance officer should verify the investor’s name, PAN, account details, transaction reference and group-company records. A complaint may relate to a former name, business division, authorised person or another category of registration held by the same entity.

Penalties of Failure to Submit the ATR Within Time

  • Automatic escalation: Where the entity fails to submit the ATR within 21 calendar days, the complaint is treated as a failure to redress the grievance within the stipulated period. The matter is automatically escalated to the first-level review by the Designated Body or SEBI where no Designated Body exists.
  • Adverse compliance record: Repeated delay may create an adverse compliance history. The pattern may be considered during inspection, supervision, renewal-related review or examination of the intermediary’s internal controls.
  • Requirement to submit revised responses: The intermediary may be directed to provide a revised ATR, additional documents or clarification. This increases the regulatory burden and may require involvement of senior management.
  • Public disclosure of long-pending complaints: SEBI periodically publishes information relating to complaints pending for more than three months against companies, intermediaries and Market Infrastructure Institutions. As of July 2026, SEBI continues to publish such periodic notices, demonstrating the continuing regulatory focus on long-pending grievances.
  • Regulatory and enforcement consequences: Persistent failure to obtain SCORES authentication or resolve investor complaints may lead to regulatory directions, adjudication, recovery-related action or other proceedings depending upon the facts and applicable law. SEBI’s published records continue to reflect proceedings connected with failure to obtain SCORES authentication, showing that the requirement should not be treated as a minor procedural formality.
  • Reputational consequences: An intermediary with a large number of unresolved complaints may lose investor confidence. The issue may also affect relationships with institutional clients, distributors, business partners and regulators.

First-Level Review

  • Right of the complainant: After receiving the intermediary’s ATR, the complainant may seek a first-level review if dissatisfied with the response. The complaint remains in an “Awaiting Review” status for 15 calendar days after submission of the ATR.
  • Role of the Designated Body: The Designated Body examines the complaint, the entity’s ATR and supporting records. It may accept the response, seek clarification or forward the complaint back to the entity for a revised ATR.
  • Failure of the entity to submit the original ATR: A complaint may also enter first-level review where the intermediary failed to submit its ATR within 21 calendar days. In such a case, the failure itself becomes part of the compliance concern.
  • Revised ATR: Where the matter is forwarded back to the intermediary, the revised ATR should address the deficiencies identified by the Designated Body. The entity should not simply repeat its original response.

Second-Level Review by SEBI

  • Circumstances for second-level review: Where the complainant remains dissatisfied after the first-level review, the matter may be taken to SEBI for second-level review. A complaint may also reach SEBI where the Designated Body fails to submit its response within the prescribed period.
  • SEBI’s power to seek clarification: SEBI may forward the complaint to the intermediary for a revised ATR or additional clarification. The intermediary should respond comprehensively and within the period specified by SEBI.
  • Examination of the complete record: At this stage, SEBI may examine the original complaint, entity response, first-level review, supporting documents and further submissions. Inconsistency between different responses may adversely affect the credibility of the intermediary.
  • Disposal of the complaint: SEBI may dispose of the complaint after considering the material available. Where the matter requires adjudication of disputed rights or detailed evidence, the parties may be required to approach the appropriate dispute-resolution forum.

Linkage Between SCORES and Online Dispute Resolution

  • Nature of ODR: The Online Dispute Resolution framework provides an online mechanism for resolving eligible securities-market disputes through processes such as conciliation and arbitration. SCORES primarily facilitates grievance redressal by the entity, whereas ODR may involve more formal determination of disputes.
  • Option available to the investor: A complainant may approach ODR or another appropriate civil remedy at any stage. Where the complainant opts for ODR or another civil remedy while the complaint is pending on SCORES, the complaint may be treated as disposed of on SCORES.
  • ATR where the matter is pending before ODR: Where the dispute is already pending before the ODR mechanism, the intermediary may submit an ATR stating the relevant status and supporting details. The response should identify the dispute reference and stage of the proceedings where appropriate.
  • Consistency of legal positions: The intermediary must ensure that the position taken in SCORES is consistent with the position taken before the ODR institution, arbitrator, court or other forum. Contradictory submissions may weaken the intermediary’s case and create regulatory concerns.

Recommended Internal SCORES Compliance Framework

Written Standard Operating Procedure

Every intermediary should adopt a written SOP for handling SCORES complaints. The SOP should identify the responsible officers, internal timelines, escalation mechanism, approval process and record-retention requirements.

Central grievance register

The entity should maintain a central register containing the complaint number, investor’s name, date of receipt, nature of grievance, department responsible, regulatory due date, action taken, ATR submission date and review status.

Daily monitoring control

An officer should record whether the dashboard was checked on each working day. This simple control helps demonstrate regular monitoring during an inspection.

Internal escalation matrix

Complaints involving financial loss, fraud allegations, unauthorised transactions, regulatory violations or senior employees should be escalated to senior management and the legal team immediately.

Root-cause analysis

Each complaint should be examined to determine whether it reflects a broader operational problem. For example, repeated complaints about delayed statements may indicate a system or process failure affecting several clients.

Corrective and preventive action

The intermediary should not limit itself to resolving the individual complaint. It should also take preventive measures, such as modifying software, retraining employees, revising disclosures or strengthening approval controls.

Periodic management reporting

A periodic report should be submitted to the Board, partners, designated directors or senior management. The report may include the number of complaints received, resolved, pending, escalated and reviewed, along with ageing analysis and recurring issues.

Record retention

The complaint, ATR, attachments, internal investigation, approval records and investor communication should be preserved for the period prescribed under the applicable regulations and internal policy.

Business continuity arrangements

The entity should maintain access arrangements during system failures, staff transitions and office disruptions. The grievance-redressal process should not depend entirely upon one employee or one device.

Common Mistakes to Avoid

  • Treating authentication as optional: Every SEBI-registered intermediary should ensure that it has valid SCORES authentication. Absence of investor complaints does not remove the requirement.
  • Using an investor account: An investor account cannot be used to access complaints lodged against the intermediary. The entity must use its official credentials.
  • Using an individual employee’s personal email: This creates access problems when the employee resigns or changes roles. A controlled official mailbox is preferable.
  • Failing to obtain category-wise authentication: An entity holding several registrations may overlook complaints under a category for which it has not verified access.
  • Not updating the compliance officer: OTP and regulatory communications may continue to be sent to the former officer.
  • Relying only on email alerts: The dashboard should be checked independently and regularly.
  • Treating calendar days as working days: The 21-day period includes weekends and holidays.
  • Waiting until the last day: Last-minute submission increases the risk of technical failure, incomplete documents and missed deadlines.
  • Filing a generic ATR: An ATR should explain the facts, examination, findings, corrective action and conclusion.
  • Ignoring recurring complaints: Repeated grievances may indicate a systemic deficiency requiring wider corrective action.

Practical Compliance Checklist

  • Before obtaining registration: The applicant should verify its legal name, PAN, registration category, compliance officer’s name, official email address and mobile number.
  • Immediately after registration: The entity should download the registration certificate, check for the SCORES credential email and verify that authentication has been generated for the correct category.
  • During the first login: The compliance officer should complete OTP verification, secure the password and verify all profile details.
  • After authentication: The intermediary should establish an internal SOP, nominate a backup officer, create a complaint register and begin regular dashboard monitoring.
  • On receipt of a complaint: The complaint should be recorded immediately, assigned to the concerned department and examined with supporting documents.
  • Before submitting the ATR: The response should be reviewed for factual accuracy, regulatory consistency, clarity and completeness.
  • After submission: The intermediary should monitor the status for any first-level or second-level review request.
  • Whenever information changes: The SCORES profile, SI Portal and other regulatory records should be updated promptly.

Conclusion

SCORES authentication is a critical compliance requirement for every SEBI-registered intermediary. It enables the entity to receive investor complaints, submit Action Taken Reports and participate in the review mechanism available through the SCORES platform. For most intermediaries registered after 2 August 2019, the user ID and password are generated automatically after completion of the online registration process and are sent to the registered email address of the compliance officer or authorised contact person. Therefore, all registration, contact and compliance details must be entered accurately.

Obtaining credentials is only the beginning of compliance. The intermediary must monitor the dashboard regularly, maintain secure access, preserve complaint records and submit a detailed ATR within 21 calendar days. The response should clearly explain the grievance, records reviewed, findings and corrective action taken.

Frequently Asked Questions

Q1. Is SCORES authentication mandatory for every SEBI intermediary?

Ans. Yes. SEBI’s official FAQs state that all SEBI-registered intermediaries are required to obtain SCORES authentication.

Q2. Is a separate manual application required after registration?

Ans. For intermediaries registered after 2 August 2019, the user ID and password are generally generated automatically upon completion of the online registration process.

Q3. Where are the credentials sent?

Ans. The credentials are sent to the email address of the contact person or compliance officer provided in the online registration form.

Q4. Can one authentication cover several SEBI registrations?

Ans. No. Separate authentication is required for every category of intermediary registration granted to the entity.

Q5. What should be done where credentials are not received?

Ans. The intermediary should check the registered mailbox, spam folder, archived communications and SI Portal records. Where the matter remains unresolved, a documented support request should be submitted.

Q6. Can the compliance officer’s details be updated?

Ans. Yes. Certain details, including compliance officer information, address and telephone number, may be updated by the entity.

Q7. Can the primary email address be updated directly?

Ans. The primary email address is generally a restricted field and may require a formal request through the prescribed process.

Q8. What happens if the complaint does not relate to the entity?

Ans. The intermediary may request transfer through the concerned Designated Body, where available, or submit an ATR advising the complainant to approach the appropriate entity.

Q9. Does SCORES replace arbitration or legal proceedings?

Ans. No. SCORES is a facilitative grievance-redressal platform. Disputes requiring formal adjudication may need to be taken to ODR, arbitration, court or another appropriate forum.

Q10. Should records be maintained after the complaint is closed?

Ans. Yes. The intermediary should preserve the complaint, ATR, supporting evidence, internal investigation and closure records in accordance with the applicable regulations and record-retention policy.

Advertisement

Author Info

Compliance Calendar LLP
Qualification: Graduate
Company: Compliance Calendar LLP
Location: Delhi, Delhi
Articles Published: 49

Join TaxGuru's Network for the latest updates on Income Tax, GST, Company Law, Corporate Laws and other related subjects.

Leave a Reply

Your email address will not be published. Required fields are marked *