Why is board-level accountability for IT governance important for systemically important financial market institutions? Discuss with reference to recent SEBI measures.
In this answer
Market Infrastructure Institutions (MIIs) — stock exchanges, depositories and clearing corporations — form the operational backbone of India's securities market. A single technology outage here halts price discovery and settlement market-wide, making IT resilience a board-level governance obligation rather than a back-office IT function.
Why board accountability matters
- Systemic externality: MIIs are quasi-utilities; their failure imposes losses on lakhs of investors who are not their clients. Only the board can weigh this public interest against commercial returns.
- Resource trade-offs: capital expenditure on redundancy, capacity and cyber defence competes with profitability. Sustained investment requires board ownership, not departmental advocacy.
- Statutory anchoring: SEBI mandates a Standing Committee on Technology (SCOT) as a statutory oversight committee at MIIs, placing technology risk formally within the governance structure [1].
- From reactive to anticipatory: without board scrutiny, IT oversight collapses into post-incident audits and tick-box compliance.
Recent SEBI measures
- IT Resilience Index (ITRI), introduced by circular in August 2026, scores MIIs out of 100 across nine parameters, with availability and security weighted highest (20 points each) and scalability and incident handling lowest [2][3].
- ITRI is computed half-yearly through a system-driven, non-discretionary process; a comparative analysis of two consecutive half-years plus corrective actions must be placed before SCOT and the governing board — a direct accountability loop [3].
- MIIs must operationalise an Early Warning System and real-time service monitoring by 28 February 2027, shifting supervision toward prediction [3].
- This builds on the Cybersecurity and Cyber Resilience Framework (CSCRF), 2024, structured around anticipate–withstand–contain–recover–evolve goals [4], and SEBI's December 2025 provisions strengthening MII governance [5].
Quantified, board-reported resilience metrics convert an opaque technical domain into a measurable governance responsibility. Going forward, linking ITRI outcomes to key management personnel performance evaluation, and harmonising SEBI's approach with RBI's financial-sector cyber norms, would deepen this reform — safeguarding investor confidence that underpins capital formation and India's growth.
Sources
- 1SEBI Circular, Statutory Committees at Market Infrastructure Institutions (MIIs), June 2024SCOT as a statutory oversight committee at MIIs
- 2SEBI unveils index for market infrastructure institutions — The Hindu (25 August 2026)introduction of ITRI via SEBI circular
- 3SEBI, Consultation Paper on Framework of IT Resilience Index for Market Infrastructure Institutions (MIIs), 25 March 2026nine parameters and weightages, half-yearly computation, SCOT/board reporting, Early Warning System and 28 February 2027 deadline
- 4SEBI Circular, Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, August 2024five cyber resilience goals
- 5SEBI Circular, Provisions relating to Strengthening Governance of Market Infrastructure Institutions (MIIs), December 2025recent strengthening of MII governance architecture