Critically analyse the significance of treating IT resilience as a systemic risk parameter, comparable to capital adequacy in banking regulation.
SEBI's IT Resilience Index (ITRI), notified for Market Infrastructure Institutions (MIIs) in August 2026 [1], scores exchanges, clearing corporations and depositories on the robustness of their technology rather than on mere compliance. It extends to technology the logic of capital adequacy — a measurable buffer against systemic shock — a shift that is significant but not without limits.
Why the analogy holds: IT as systemic risk
- MIIs were designated systemically important in 2015; trading, clearing, settlement and securities-holding systems are single points of failure whose outage halts the entire market, much as a bank's capital erosion transmits contagion.
- Rising algorithmic trading, mass retail participation through online platforms and faster settlement cycles compress the margin for error to minutes [2].
- Quantification aids supervision: a numerical score makes resilience comparable across MIIs and trackable over time, replacing checklist audits with outcome-based regulation [2].
- It builds on a graded evolution — cyber resilience circulars (2018), extension to portfolio managers (2023), and the consolidated CSCRF with its Cyber Capability Index (2024) [3].
Where the comparison strains
- Capital adequacy rests on decades of Basel calibration; ITRI's ~9 parameters — availability, integrity, scalability, business continuity and others [2] — involve weightings that are qualitative judgments, risking a false precision.
- Unlike capital, technology risk cannot be "topped up" instantly; a poor score signals a problem but no equivalent remedial buffer exists.
- Scores may invite box-ticking optimisation rather than genuine resilience, and depend heavily on MIIs' self-reported monitoring capacity.
- Coverage is confined to MIIs, while brokers and third-party vendors — frequent vectors of disruption — remain under the broader CSCRF [3].
Treating IT resilience as a prudential variable rightly recognises that digital continuity is now market infrastructure itself. Its promise will be realised if SEBI pairs the index with periodic recalibration, independent verification and disclosure, and coordination through the FSDC — making ITRI, potentially a global template, a living instrument of financial stability rather than a static scorecard.
Sources
- 1SEBI Circular — IT Resilience Index for Market Infrastructure Institutions (MIIs), August 24, 2026formal introduction of ITRI for MIIs
- 2SEBI — Consultation Paper on Framework of IT Resilience Index for MIIs, March 25, 2026rationale, parameters assessed, outcome-based scoring approach
- 3SEBI Circular — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, August 20, 2024consolidated cyber framework, Cyber Capability Index, wider RE coverage