CKYCRR issued the Standard Operating Procedure (SOP) reporting mechanism by REs on the Cyber-Incidents reported/identified pertaining to Unauthorized Access to KYC Information on CKYCRR

Nov 30, 2025 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Central KYC Records Registry (CKYCRR) on November 28, 2025, issued the Standard Operating Procedure (SOP) reporting mechanism by REs on the Cyber-Incidents reported/identified pertaining to Unauthorized Access to KYC Information on CKYCRR.

The following has been stated namely: -

• Reporting Entities (REs) registered with CKYCRR shall promptly report any suspected or actual unauthorized access to CKYCRR data — including attempts, breaches, or anomalies. 

• The SOP requires REs to have a defined incident-management process: identify the incident, assess severity, contain the breach, and document the full details (who, when, what data, how). 

• As soon as unauthorized access is detected, REs shall notify CKYCRR (and relevant authorities as applicable), and if the breach affects confidentiality, integrity, or availability, also suspend access or disconnect systems until resolved. 

• REs are required to maintain audit trails and logs and periodically review user-access permissions, to prevent misuse or unintended access via shared IPs, VPNs, or third-party vendors. 

• The SOP emphasizes security best practices and compliance — including regular security training, infrastructure hardening, and adherence to data-protection standards — to minimize risk of unauthorized CKYCRR database access.


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT