India SEBI Compliance Enforcement Orders — July 20, 2026
The July 20, 2026 enforcement digest reveals a concentrated regulatory crackdown on India's cooperative banking sector, with three separate RBI penalties totaling ₹17.30 lakh for non-compliance with the Banking Regulation Act, 1949. All three cooperative banks—Kolhapur District Central Co-op Bank, United Puri-Nimapara Central Co-operative Bank, and Manmad Urban Co-operative Bank—were penalized for governance failures, including sanctioning director-related loans and failing to upload KYC records to the Central KYC Records Registry (CKYCR). These actions, all stemming from NABARD inspections as of March 31, 2025, signal a systemic pattern of weak internal controls and conflict-of-interest management in smaller cooperative banks. In stark contrast, the fourth filing involves a high-materiality (8/10) SEBI adjudication order against Central Depository Services India Limited (CDSL) for a cybersecurity lapse—a malware attack on November 18, 2022—highlighting a nearly four-year regulatory lag and raising serious questions about CDSL's incident response and data protection protocols. The period-over-period data shows no revenue or margin trends, but the concentration of penalties on director-related loans (2 of 3 cooperative banks) points to a recurring theme of related-party transaction oversight failures. The CDSL case stands out as the most market-moving event, given its systemic importance as India's largest depository, and the lengthy gap between the incident and the order suggests potential for further regulatory escalation or shareholder litigation.