A first look at the SEBI (Buy-Back of Securities) Amendment Regulations, 2026, and what the new Regulation 24A means for statutory auditors
Most SEBI amendments that make it into CA and CS practice discussions concern disclosure timelines, ICDR eligibility, or LODR governance thresholds. The SEBI (Buy-Back of Securities) Amendment Regulations, 2026 notified on 1 July 2026 and effective from 1 August 2026 deserves far more attention than it has received so far, because for the first time in nearly three decades of buyback regulation in India, SEBI has made the appointment of a Merchant Banker entirely optional. That single change, tucked into a new Regulation 24A, redraws who is actually accountable when a listed company buys back its own shares and a meaningful share of that redrawn accountability now lands on the Statutory Auditor's desk.

A Quick Recap of Where the Framework Stood
Buybacks in India can be executed through a tender offer or, historically, through an open-market route (further split into book-building and stock-exchange sub-routes). The 2023 amendment to the buyback regulations began winding down the stock-exchange route, progressively capping its size before prohibiting it outright from 1 April 2025. Throughout every iteration of the framework since 1998, the Merchant Banker sat at the centre of the transaction filing the letter of offer, certifying regulatory compliance, overseeing the escrow account, and submitting the final report to SEBI. Appointing one was never discretionary.
What Actually Changed on 1 August 2026
- The open-market buyback route through stock exchanges is quietly reinstated, in a more time-bound form than before the offer must open within four working days of the public announcement and close within sixty-six working days of opening, considerably tighter than the six-month window that existed before 2023.
- A new direct-intimation obligation requires companies to send an electronic communication to every shareholder on record within one working day of the public announcement shifting the burden of awareness from passive market disclosure to active company outreach.
- An ISIN-level freeze now locks promoter and promoter-group holdings from the date of the board resolution until the offer closes, closing a gap where promoters could otherwise deal in non-tendered shares during the buyback window.
- The word "may" in the escrow-form provision has been replaced with "shall" a small textual change that converts what was company discretion into a hard compliance requirement.
- Most significantly, new Regulation 24A allows a company to dispense with a Merchant Banker altogether, redistributing that role's obligations across the Company, the Secretarial Auditor, the Statutory Auditor, the Compliance Officer, and the stock exchanges.
Where the New Weight Actually Lands
The redistribution under Regulation 24A is specific, not vague. The Company itself takes on filing accuracy for the letter of offer and public announcement, and the final report. The Practising Company Secretary, acting as Secretarial Auditor, now issues the due diligence certificate that a Merchant Banker previously signed formally certifying to SEBI that the offer complies with the regulations. The Compliance Officer becomes personally responsible for presence at, and certification of, the extinguishment and destruction of securities.
For a CA audience, the provision that deserves the closest reading is the one handed to the Statutory Auditor: oversight of the escrow account itself its creation, funding, bank guarantee validity, invocation rights, and coordination with SEBI in case of company default. This is not a natural extension of a financial-statement audit mandate. It requires the Statutory Auditor to engage directly with an escrow bank, monitor a transaction timeline running up to sixty-six working days, and take on a function that, until 31 July 2026, sat exclusively with a SEBI-registered capital markets intermediary.
Why This Matters More Than It Looks
The immediate reading of Regulation 24A is cost-saving: smaller listed companies, for whom Merchant Banker fees are a disproportionate share of a modest buyback's total cost, now have a genuinely cheaper path to returning capital to shareholders. That reading is correct, but incomplete.
The more important reading is about where regulatory risk now sits. When a Merchant Banker was mandatorily engaged, it functioned as an independent, SEBI-registered check on the company's own compliance an intermediary with its own direct exposure to SEBI enforcement if something went wrong. Once a company opts out of that appointment, that external check disappears, and the professionals stepping into the gap the Practising Company Secretary issuing the due diligence certificate, and the Statutory Auditor overseeing the escrow are taking on a form of certification and operational responsibility that carries real professional exposure if the underlying work is not done with the same rigour a Merchant Banker's compliance function previously applied.
What This Means in Practice For Both CAs and CS Professionals
- For Statutory Auditors: before agreeing to take on escrow oversight for a Merchant Banker-free buyback, scope the engagement explicitly document exactly what oversight entails, the timeline commitment across a sixty-six working-day window, and ensure the audit engagement letter (or a separate letter) reflects this as a distinct, additionally-billed responsibility rather than an incidental extension of the statutory audit.
- For Practising Company Secretaries: treat the due diligence certificate under the new framework with the same seriousness SEBI itself is signalling this is a formal certification to the regulator, not an internal compliance sign-off, and should be backed by a documented verification programme covering Section 68 thresholds under the Companies Act, insider trading restrictions, and every disclosure in the letter of offer.
- For CFOs and boards: the decision to skip a Merchant Banker should be modelled on more than the fee saved factor in the incremental cost of the enhanced Secretarial Auditor and Statutory Auditor scope that replaces it, and honestly assess whether internal compliance bandwidth can absorb an end-to-end buyback execution without an external intermediary's coordination role.
- For groups with pledged or encumbered promoter shareholding: run a pre-buyback audit of every existing encumbrance well before the board resolution is passed the new ISIN-level freeze applies from that resolution date, and discovering a conflict after the freeze is imposed is far costlier than addressing it in advance.
- For companies with large retail shareholder bases: verify that RTA-held contact data (email IDs in particular) is current well ahead of any contemplated buyback, since the one-working-day direct intimation requirement is only as effective as the underlying shareholder data.
Closing Thought
SEBI's 2026 buyback amendment is easy to file away as a niche capital-markets update, relevant only to listed-company advisory teams. It is better read as a preview of a broader regulatory direction SEBI extending genuine trust to a company's internal governance professionals in place of a mandatory external intermediary, and expecting the Company Secretary and the Statutory Auditor to fill that space with real diligence, not paperwork. For practitioners on both sides of that divide, this is less a compliance footnote than a signal of where SEBI expects professional accountability to sit next.