“We’re using a third-party platform to provide services.”
“The risk profiling is done through our technology partner.”
“The technology provider generates the recommendations.”
“The vendor handles the KYC of clients.”
As technology continues to transform the investment advisory industry, these are conversations we increasingly have with SEBI Registered Investment Advisers (RIAs) and Research Analysts (RAs).
Digital onboarding, AI-powered research, automated risk profiling and white-labelled advisory platforms have made it easier than ever to scale advisory businesses.
There is nothing inherently wrong with this.
In fact, outsourcing operational activities and leveraging specialised technology providers is now an integral part of running an advisory practice.
However, recent SEBI enforcement actions highlight an important regulatory principle that every RIA and RA should keep in mind.
While processes may be outsourced, regulatory responsibility cannot.
The challenge is that the line between operational support and outsourcing of core functions is not always obvious.
A platform may appear to be providing only technology support, while in reality it may be performing activities that the regulations expect the registered intermediary to perform.
That distinction can have significant compliance implications.
SEBI permits outsourcing – but not of core functions
SEBI’s outsourcing framework recognises that intermediaries may outsource certain activities to improve operational efficiency.
However, it also provides that core business activities and compliance functions cannot be outsourced.
Activities that require professional judgment, fiduciary responsibility or regulatory accountability must continue to remain under the control of the registered intermediary.
The question, therefore, is not whether outsourcing is permitted.
The real question is: Which functions must always remain with the RIA or RA?
Core functions that cannot be outsourced
1. Risk Profiling and Suitability Assessment
Risk profiling and suitability assessment are at the heart of the investment advisory process.
Every advice given by an Investment Adviser must be appropriate for the client’s financial circumstances, investment objectives and risk appetite.
While technology can assist in collecting client information and automating workflows, the responsibility for conducting risk profiling and suitability assessment cannot be outsourced.
This principle is clearly illustrated in SEBI’s order in the matter of Bharosa Technoserve Pvt. Ltd.
SEBI observed that, for clients who subscribed to the intermediary’s advisory services through the Smallcase platform, the risk profiling was carried out by Smallcase. Once the risk profiling was completed, clients could access the intermediary’s advisory services without any intervention or review by the registered Investment Adviser.
SEBI viewed this as more than the use of a technology platform. It concluded that the intermediary had effectively outsourced the core functions of risk profiling and suitability assessment instead of performing these regulatory obligations itself.
The takeaway for RIAs is significant.
Risk profiling and suitability assessment are not procedural steps that can simply be delegated to a platform. They are core regulatory functions that require the active involvement, oversight and responsibility of the registered intermediary.
Using technology to facilitate the process is one thing.
Allowing the platform to perform the function on behalf of the intermediary is quite another.
2. Advice, Research and Investment Judgment
The value provided by an RIA or RA lies in its professional judgment.
While intermediaries may rely on market data, research tools, analytics, screening software and technology platforms, they cannot outsource the exercise of judgment that forms the basis of regulated advice or research.
Research Analysts cannot outsource core financial analysis, financial modelling or the preparation of research reports to a third party in a manner that effectively allows the third party to perform the role of a Research Analyst.
Similarly, Investment Advisers cannot outsource the final formulation of investment advice or financial plans where the exercise of advisory judgment is involved.
This principle is also reflected in SEBI’s order against First Global Finance Private Limited. Although the arrangement was described as a technology engagement, SEBI observed that the service provider’s involvement extended beyond technology support into investment-related decision-making.
The lesson is equally relevant for RIAs and RAs.
Whether recommendations originate from an AI engine, a research provider or a technology platform, the responsibility for the advice delivered to the client cannot shift away from the registered intermediary.
3. Compliance and AML Oversight
Compliance functions exist to ensure that the intermediary continuously meets its regulatory obligations.
While RIAs and RAs may engage independent professionals for annual compliance audits and regulatory advisory, the ultimate accountability for Anti-Money Laundering (AML) obligations cannot be delegated. The final decision to accept a client and the execution of the agreement must be conducted directly by the registered entity.
The regulatory obligation always remains with the entity holding the SEBI registration.
4. Client Onboarding and KYC Responsibilities
Technology has significantly simplified client onboarding through digital journeys, API integrations and KYC utilities.
However, the use of technology should not be confused with the transfer of regulatory responsibility.
Recently, while reviewing the workflow of a Research Analyst using an algorithmic advisory platform, we came across an arrangement where the platform was providing KYC-related services. The platform explained that it had an arrangement with NDML to facilitate these services. So, effectively, the platform was conducting the KYC of the clients on behalf of the research analyst.
From a commercial perspective, the arrangement appeared straightforward.
From a compliance perspective, however, a different question arose.
Had the research analyst retained ownership of the regulatory obligation, or had that responsibility effectively shifted to the service provider?
That distinction is often far more important than the contractual description of the service.
What we are seeing in practice
As more RIAs and RAs adopt white-labelled platforms, AI-powered tools and specialised service providers, we are increasingly coming across outsourcing arrangements where the actual operational workflow differs from what the intermediary believes is happening.
During compliance reviews, we have observed situations where:
- functions described as “technology support” extend into activities requiring regulatory judgment;
- platform workflows perform critical regulatory functions with limited oversight by the intermediary;
- responsibilities are fragmented across multiple vendors, making accountability unclear; and
- commercial agreements do not accurately reflect how the advisory process actually operates.
In most cases, these arrangements were implemented with the objective of improving efficiency rather than avoiding compliance.
However, SEBI’s enforcement orders demonstrate that the regulator will look beyond contractual descriptions and examine the substance of the arrangement.
For intermediaries, this means that compliance cannot be assessed by reading the vendor agreement alone. The actual workflow matters just as much.
What can be outsourced?
SEBI’s outsourcing framework does not prohibit outsourcing altogether. RIAs and RAs may outsource operational and administrative activities such as technology infrastructure, software development, cloud hosting, payroll, accounting, document management and marketing support, provided appropriate oversight, confidentiality measures and contractual safeguards are maintained.
The distinction is straightforward.
Operational support may be outsourced. Core business activities, compliance functions and regulatory responsibility cannot.
Conclusion
Technology has fundamentally changed the way RIAs and RAs operate, and that transformation will only accelerate with the increasing adoption of AI-driven advisory tools and digital platforms.
The Bharosa Club and the First Global orders are not just enforcement actions. They are reminders that SEBI will examine what actually happens in practice and not what the outsourcing agreement says.
As RIAs and RAs increasingly rely on white-labelled platforms, AI tools and third-party service providers, it is worth asking whether technology is merely supporting the advisory process or quietly performing functions that the regulations expect the intermediary to perform.
The greatest outsourcing risk today is often not visible in the platform. It lies in the workflow behind it.
Are you outsourcing any of the core functions? Its time to relook at your processes.
If you have any queries or want us to review your platform, feel free to reach out to us at kruti@cskruti.com.