Accessibility insights

SEBI Accessibility 4 min read

SEBI Accessibility Audit Readiness Guide

Digital accessibility work is easier to govern when the organisation can show what was assessed, which requirements were applied, what barriers were found and how fixes were verified. This guide turns SEBI digital-accessibility audit preparation into a practical sequence for compliance, product and technology teams. It is general information, not legal advice; confirm applicability, reporting instructions and dates against current SEBI notices and your compliance team's advice.

1. Check the current regulatory position

Read the SEBI circular of 31 July 2025, its digital-accessibility compliance guidelines dated 25 September 2025, and any later clarifications or extensions together. The 31 July 2026 extension states 31 October 2026 for the digital accessibility audit and remediation of audit findings. Because regulatory directions can change, verify the current text and the requirements that apply to your entity before you set a project deadline.

The applicable regulatory materials refer to disability rights legislation and rules, WCAG 2.1 or the latest version, government website guidelines, and IS 17802. Confirm the exact assessment criteria and evidence expected for the relevant entity and platform; do not assume that a generic automated scan covers every reference.

2. Create an inventory of platforms and investor tasks

Start with a named inventory rather than a list of URLs copied from a sitemap. Ask product owners which websites, apps, portals and third-party journeys investors use, then record ownership, environment, release/version and the user tasks each platform supports. A useful scope can include account access, registration, KYC, viewing holdings, statements, transactions, support and complaint handling where those journeys are relevant to the entity.

For each task, note the entry point, important screens and success state. Include representative page templates, authenticated areas, responsive layouts, error states and documents that are part of the journey. Agree exclusions and dependencies in writing. This makes the scope understandable to auditors and helps teams avoid a report that tests only the public homepage while missing the actual investor workflow.

3. Confirm auditor credentials and independence

The SEBI framework refers to accessibility audits by IAAP-certified accessibility professionals and asks for auditor identification and credential details in the applicable compliance guidance. Confirm the requested evidence and format from the latest instructions. Keep the credential evidence with the engagement records and identify who performed the testing and who reviewed the findings.

An accessibility audit is an assessment of a defined platform and scope; it is not an IAAP-issued certificate for the product. Avoid describing a report as a guarantee of compliance. The regulated entity remains responsible for its compliance decisions, remediation and reporting.

4. Test representative journeys with people and tools

Combine automated checks with manual evaluation. Automated tools can flag some missing names, contrast concerns and markup patterns, but they cannot reliably judge every interaction, reading order, error recovery or task flow. Manual checks should include keyboard-only use, visible focus, semantic structure, screen-reader output, zoom/reflow, text and non-text contrast, form validation and touch interaction on supported devices.

Prioritise journeys by user impact and business importance. Where applicable, plan usability evaluation with persons with disabilities and assistive-technology users. Record the assistive technology, browser/device combination, task attempted and observed outcome so results are reproducible rather than anecdotal.

5. Write findings that teams can act on

A useful finding identifies the platform and screen, steps to reproduce, expected and actual result, affected users, applicable criterion, evidence and a practical remediation direction. For example, “the form has an accessibility issue” is hard to assign; “keyboard focus moves from the date field to the page footer and skips the Submit button on the registration form” gives an engineer a starting point.

Prioritise issues based on the barrier and task impact, not only an automated severity label. Assign an owner, target release and status. When the fix ships, re-test the original steps and related states, record the result and retain evidence. Track accepted risks and deferred work through the organisation's normal governance process.

Audit-readiness checklist

  • Current circulars and applicability reviewed by the compliance team
  • Platforms, key investor journeys, versions and exclusions documented
  • Auditor identity and applicable IAAP credential details confirmed
  • Agreed criteria, tools, assistive technologies and user testing approach recorded
  • Findings have reproducible evidence, an owner, a remediation status and a re-test result

For a scoped assessment, see our SEBI digital accessibility audit service or contact Access Setu. We are not endorsed by SEBI, and this guide does not replace regulatory or legal advice.