·The Hindu·15 marks·250–350 words

Discuss the rationale behind SEBI's IT Resilience Index for Market Infrastructure Institutions. How does it mark a shift from compliance-based to outcome-based regulation?

In this answer
  1. Rationale for the ITRI
  2. From compliance-based to outcome-based regulation

In August 2026, SEBI issued a circular introducing the IT Resilience Index (ITRI) for Market Infrastructure Institutions (MIIs) — stock exchanges, clearing corporations and depositories [1]. Preceded by a consultation paper in March 2026 [2], the ITRI converts technology robustness into a measurable score, marking a decisive move from checklist compliance to demonstrated outcomes.

Rationale for the ITRI

  • Systemic criticality: MIIs run the trading, clearing, settlement and securities-holding backbone; disruption of even minutes cascades across millions of investors, making IT failure a systemic — not merely operational — risk.
  • Rising technological dependence: surging retail participation through online platforms, higher algorithmic trading volumes and shorter settlement cycles have compressed tolerance for downtime.
  • Widening threat surface: cyber-attacks, technical failures and sudden activity spikes demand resilience testing beyond periodic audits.
  • Institutional continuity: SEBI's cyber framework evolved from sectoral circulars (2018, extended to portfolio managers in 2023) to the consolidated Cybersecurity and Cyber Resilience Framework (CSCRF), 2024, which introduced the Cyber Capability Index (CCI) for annual self-assessment [3]. The ITRI extends this logic specifically to MIIs.

From compliance-based to outcome-based regulation

  • Measurement over attestation: instead of certifying that controls exist, MIIs must score against broad parameters — availability, security, integrity, governance, reliability and monitoring, business continuity, modularity, scalability [2][3].
  • Comparability and benchmarking: a common index permits inter-institutional and year-on-year comparison, much as prudential ratios do in banking, rather than pass/fail audit findings.
  • Accountability of boards: quantified scores locate technology governance with MII management, incentivising continuous investment over episodic remediation.
  • Consultative rollout: draft-to-circular sequencing [2][1] embeds regulatory legitimacy and industry preparedness.

Thus the ITRI reframes technology resilience as a supervisable, quantifiable public good rather than a compliance formality. Its success will depend on credible verification, periodic recalibration of parameters and capacity-building within MIIs. Anchored in SEBI's mandate to protect investors and develop the securities market, the index strengthens trust in India's digital financial architecture.

Sources

  1. 1SEBI — IT Resilience Index for Market Infrastructure Institutions (MIIs), Circular, August 2026issuance of ITRI for MIIs; final circular stage
  2. 2SEBI — Consultation Paper on Framework of IT Resilience Index for MIIs, March 2026draft framework and index parameters; consultative process
  3. 3SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, August 2024consolidation of earlier cyber circulars; Cyber Capability Index

More from this note