## Report on SEBI Circular SEBI/HO/DDHS/DDHS/PoD-2/CIR/2025/68 Regarding Composition of Internal Audit Team for Credit Rating Agencies (CRAs)
**1. Executive Summary:**
This report analyzes SEBI Circular SEBI/HO/DDHS/DDHS/PoD-2/CIR/2025/68, dated May 14, 2025, which amends the Master Circular for Credit Rating Agencies (CRAs) dated May 16, 2024. The amendment expands the pool of eligible professionals who can be part of the internal audit team for CRAs by including Cost Accountants (ACMA/FCMA) and individuals holding the Diploma in Information System Security Audit (DISSA). The core purpose of this amendment, based on the text, is to provide CRAs with a larger selection of qualified professionals to conduct internal audits. The key finding is that the amendment broadens the qualification criteria for internal audit team members, potentially easing compliance and enhancing the availability of qualified auditors.
**2. Introduction:**
The purpose of this report is to provide a comprehensive overview of SEBI Circular SEBI/HO/DDHS/DDHS/PoD-2/CIR/2025/68, dated May 14, 2025, which amends the Master Circular for Credit Rating Agencies (CRAs) regarding the composition of the internal audit team. This analysis is based solely on the text of the circular provided.
**3. Policy Overview:**
* The circular amends Para 33.1.3 of the Master Circular for Credit Rating Agencies (CRAs) dated May 16, 2024.
* The core objective of the *original* policy, inferred from the amendment's rationale, is to ensure qualified professionals conduct internal audits of CRAs. The *amendment's* objective, based on the provided text, is to broaden the pool of eligible professionals for these internal audits.
**4. Background and Rationale:**
This is an amendment to an existing policy. The likely reason for this amendment, inferred from the provided text, is to address a potential constraint in the availability of qualified professionals to serve on the internal audit teams of CRAs. The original policy limited the pool to Chartered Accountants and Certified Information Systems Auditors. By including Cost Accountants and holders of the Diploma in Information System Security Audit, the amendment seeks to alleviate this constraint and provide CRAs with a wider selection of eligible candidates. The text specifically states this rationale: "In order to provide CRAs with a larger pool of eligible professionals with the relevant experience qualifications for conducting the internal audit..."
**5. Key Provisions / Changes:**
This section focuses specifically on the changes introduced by the amendment.
* **Specific Part of Original Policy Changed:** Para 33.1.3 of the Master Circular for Credit Rating Agencies CRAs dated May 16, 2024.
* **New Rule/Provision:** The amended Para 33.1.3 now states: "The audit team must be composed of at least a Chartered Accountant (ACA/FCA) or a Cost Accountant (ACMA/FCMA) and a Certified Information Systems Auditor/Diploma in Information System Auditor/Diploma in Information System Security Audit (CISA/DISA/DISSA)."
* **Difference/Effect of the Change:** The original requirement was that the audit team must include at least a Chartered Accountant (ACA/FCA) and a Certified Information Systems Auditor/Diploma in Information Systems Auditor (CISA/DISA). The amendment *adds* Cost Accountants (ACMA/FCMA) as an alternative to Chartered Accountants, and adds Diploma in Information System Security Audit (DISSA) as an alternative to Certified Information Systems Auditor/Diploma in Information Systems Auditor (CISA/DISA). This effectively expands the acceptable qualifications for the internal audit team.
**6. Target Audience and Stakeholders:**
Based on the provided text, the primary target audience and stakeholders directly affected by this amendment are:
* All Registered Credit Rating Agencies (CRAs).
* Chartered Accountants (ACA/FCA).
* Cost Accountants (ACMA/FCMA).
* Certified Information Systems Auditors/Diploma in Information Systems Auditors (CISA/DISA).
* Individuals holding the Diploma in Information System Security Audit (DISSA).
**7. Implementation Aspects (Inferred):**
* **Responsible Agency:** Securities and Exchange Board of India (SEBI).
* **Timelines:** The circular states, "The circular shall be applicable with immediate effect."
* **Procedures:** The amendment implies that CRAs must now consider Cost Accountants and DISSA holders as eligible candidates when forming their internal audit teams. The specific procedure for selecting auditors is not detailed in this text.
**8. Expected Outcomes / Impact of Changes:**
The likely intended outcome of these specific changes is to increase the availability of qualified professionals for internal audit teams within CRAs. This may lead to:
* Easier compliance for CRAs in meeting internal audit requirements.
* Potentially lower costs for CRAs in securing qualified auditors, due to an increased supply.
* A broader range of expertise within the internal audit teams.
**9. Conclusion:**
SEBI Circular SEBI/HO/DDHS/DDHS/PoD-2/CIR/2025/68 represents a targeted amendment to the Master Circular for Credit Rating Agencies. By expanding the eligibility criteria for internal audit team members to include Cost Accountants and DISSA holders, the amendment aims to address potential resource constraints and enhance the availability of qualified professionals for CRAs' internal audits. This change is effective immediately and is expected to facilitate compliance and potentially improve the overall effectiveness of internal audits within the credit rating industry.
Key Entities Referenced
SEBI: Securities and Exchange Board of India, the issuer of the circular.
CIRCULAR SEBIHODDHSDDHSPoD2PCIR202568: The identifier or reference number of the circular.
May 14, 2025: Date of the circular's issuance.
All Registered Credit Rating Agencies: Addressees of the circular.
CRAs: Credit Rating Agencies, the entities to which the circular pertains.
Internal Audit: Subject of the circular, specifically the composition of the Internal Audit team for CRAs.
Master Circular for Credit Rating Agencies: A previously issued circular that this document modifies.
May 16, 2024: Date of the Master Circular for Credit Rating Agencies being referenced.
Chartered Accountant: One of the qualifications required for the audit team.
ACA FCA: Abbreviations relating to Chartered Accountant qualifications.
Certified Information Systems Auditor: Another qualification for the audit team.
Diploma in Information Systems Auditor: Another qualification for the audit team.
CISA DISA: Abbreviations related to Certified Information Systems Auditor and Diploma in Information Systems Auditor qualifications.
Cost Accountant ACMA FCMA: Included as another eligible qualification for conducting internal audit.
Diploma in Information System Security Audit DISSA: Another included qualification for conducting internal audit.
Institute of Cost Accounts of India ICMAI: The institute from which the Cost Accountant ACMA FCMA and DISSA qualifications are obtained.
Section 11 1 of Securities and Exchange Board of India Act, 1992: Legal provision under which the circular is issued.
Regulation 20 of SEBI Credit Rating Agencies Regulations, 1999: Another legal provision under which the circular is issued.
Ritesh Nandwani: Deputy General Manager, Department of Debt and Hybrid Securities at SEBI.
Department of Debt and Hybrid Securities: Department within SEBI responsible for the circular.
www.sebi.gov.in: SEBI's official website where the circular is available.
CIRCULAR
SEBI/HO/DDHS/DDHS-PoD-2/P/CIR/2025/68 May 14, 2025
To,
All Registered Credit Rating Agencies,
Madam/ Sir,
Sub: Composition of the Internal Audit team for CRAs
1. Para 33.1.3 of the Master Circular for Credit Rating Agencies (CRAs) dated May
16, 2024, in respect of requirements related to Internal Audit of CRAs, specifies
as under:
“The audit team must be composed of, at least, a Chartered Accountant (ACA/
FCA) and a Certified Information Systems Auditor/ Diploma in Information
Systems Auditor (CISA/ DISA).”
2. In order to provide CRAs with a larger pool of eligible professionals with the
relevant experience/ qualifications for conducting the internal audit, it has been
decided to include Cost Accountant (ACMA/ FCMA) and Diploma in Information
System Security Audit (DISSA) qualifications from the Institute of Cost Accounts
of India (ICMAI) to the audit team. Accordingly, Para 33.1.3 of the Master Circular
for CRAs stands modified as under:
“The audit team must be composed of at least a Chartered Accountant (ACA/
FCA) or a Cost Accountant (ACMA/ FCMA) and a Certified Information Systems
Auditor/ Diploma in Information System Auditor/ Diploma in Information System
Security Audit (CISA/ DISA/ DISSA).”
Page 1 of 23. The circular shall be applicable with immediate effect.
4. This circular is issued with the approval of competent authority, in exercise of the
powers conferred by Section 11 (1) of Securities and Exchange Board of India
Act, 1992 read with the provisions of Regulation 20 of SEBI (Credit Rating
Agencies) Regulations, 1999 to protect the interest of investors in securities and
to promote the development of, and to regulate, the securities market.
5. This Circular is available on the website of the Securities and Exchange Board of
India at www.sebi.gov.in under the category “Legal” and under the drop down
“Circulars”.
Yours faithfully,
Ritesh Nandwani
Deputy General Manager
Department of Debt and Hybrid Securities
Tel No.022-2644-9696
Email ID - riteshn@sebi.gov.in
Page 2 of 2