We should not let asset management companies patch SWP confirmation gaps with call-centre scripts while retirement investors still receive plain-text emails that never prove which folio was debited. SEBI’s July 2026 circular finally extends systematic withdrawal and transfer mandates to demat-held units, but the millions of households on statement-of-account folios still depend on registrar emails that lack cryptographic folio hashes—a hole fraudsters exploit when spoofed “SWP processed” messages arrive ahead of real redemptions.
The mechanism that is missing
A systematic withdrawal plan is only as trustworthy as the confirmation trail. SEBI’s working group envisioned registrars returning retrieval reference numbers and matching mandate details when depositories route demat instructions. For SOA investors—the majority of older balanced-fund holders—confirmation still means an AMC-branded email with a folio number in cleartext and a toll-free number that agents answer without seeing the investor’s signed mandate image.
Requiring a folio hash in every SWP confirmation email would let investors verify that the message corresponds to a registrar ledger entry without publishing full folio numbers in subject lines. Hashing is not exotic; RTAs already generate internal keys for payment files. The editorial board’s claim is narrow: until that hash ships, AMCs should stop telling callers that “the email is enough proof” when disputes reach the banking ombudsman.
Why call centres make it worse
AMC call centres are optimized for sales ratios, not forensic disputes. Agents can read SWP dates from CRM tabs populated by nightly batch files, yet they cannot show whether a withdrawal was initiated by the investor or by a compromised mailbox rule forwarding OTPs. Livemint’s reporting on the demat SWP reform noted how many steps demat STPs still require across exchanges and clearing corporations; SOA investors face a parallel maze with fewer digital rails and more phone trees.
When a spoofed email arrives, the victim calls the AMC, hears that a withdrawal “looks legitimate,” and only discovers fraud after the credit hits an unknown account. Registrars then argue about whether the email domain was spoofed or the folio credentials leaked—a fight that hashes would shorten by giving investors an independent check against registrar portals.
What SEBI’s reform does not fix yet
The regulator’s phased timeline—unit-based demat SWP by January 2027 and amount-based by April 2027—addresses convenience, not confirmation integrity for legacy folios. Depositories will become nodal facilitators, but SOA holders are not required to migrate. AMCs that celebrate demat automation while leaving SOA emails unchanged are exporting risk to the least sophisticated slice of unit holders, often retirees running monthly SWPs for household expenses.
The strongest objection is cost: RTAs will say hashing every email requires core banking changes. That objection ignores that payment aggregators already sign webhook payloads for UPI. Mutual fund redemptions move comparable rupee sums with weaker attestations.
What AMCs and RTAs should do now
Asset managers should publish a verification endpoint where investors paste the hash from any SWP email and see mandate date, scheme, and bank account tail digits. RTAs should refuse to mark tickets “resolved” on call-centre notes alone when the investor disputes an SWP debit. SEBI should extend the demat working group’s RRN logic to SOA confirmations before the January 2027 demat phase creates a two-tier trust model.
We are not asking for perfect fraud elimination. We are asking AMCs to stop using call-centre reassurance as a substitute for a folio hash that registrars can issue tomorrow. Until then, every SWP confirmation email without that hash is a liability dressed as customer service.








