Examine the evolving role of SEBI in regulating technology risk in Market Infrastructure Institutions. What are the challenges in ensuring compliance?
In this answer
Market Infrastructure Institutions (MIIs) — stock exchanges, depositories and clearing corporations — are systemically critical: a single outage halts price discovery and settlement. SEBI's technology regulation has accordingly shifted from post-incident audit to pre-emptive, measurable supervision.
From reactive audit to continuous oversight
- Audit-based phase: mandatory System and Network Audit of MIIs [1], later given a standardised reporting format, plus a Testing Framework for IT systems covering software change and disaster-recovery testing [2].
- Consolidation phase: the Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 replaced fragmented circulars with one outcome-based framework built on anticipate–withstand–contain–recover–evolve [3].
- Governance phase: statutory Standing Committee on Technology (SCOT) at each MII embeds technology risk in board-level accountability [4].
ITRI: resilience made measurable
- SEBI's IT Resilience Index (ITRI), proposed in March 2026 and introduced by circular in August 2026, scores MIIs on nine parameters over 100 points, with availability and security weighted highest (20 each) [5][6].
- Computed half-yearly through a system-driven, non-discretionary process, with comparative analysis and corrective action reported to SCOT and the governing board [5][6].
- A mandated Early Warning System shifts detection ahead of failure, flagging slowness before disruption [5].
Challenges in ensuring compliance
- Self-assessment risk: scores are computed by the MII itself, inviting box-ticking rather than genuine resilience.
- Capacity asymmetry: smaller depositories and clearing corporations lack the engineering depth of large exchanges.
- Layered compliance burden: CSCRF audits, system audits and ITRI reporting overlap, diverting scarce technical staff.
- Third-party dependence: cloud, data-centre and vendor failures lie outside direct MII control.
- Supervisory capacity: SEBI must retain specialised talent to interrogate scores meaningfully.
Technology risk is now treated as systemic risk, and ITRI converts resilience from an audit finding into a monitored metric. Its success will depend on independent validation of scores, calibrated timelines and capacity-building support — turning compliance into genuine investor protection, SEBI's core statutory mandate.
Sources
- 1SEBI, System and Network Audit of Market Infrastructure Institutions (May 2022)audit-based phase of MII technology oversight
- 2SEBI, Testing Framework for the IT Systems of MIIs (May 2023)software change and disaster-recovery testing mandate
- 3SEBI, Cybersecurity and Cyber Resilience Framework (CSCRF) for Regulated Entities (Aug 2024)consolidation of cyber circulars; resilience goals
- 4SEBI, Statutory Committees at Market Infrastructure Institutions (Jun 2024)Standing Committee on Technology (SCOT)
- 5SEBI, Consultation Paper on Framework of IT Resilience Index for MIIs (Mar 2026)nine parameters, weightages, half-yearly computation, Early Warning System
- 6Business Standard, "Sebi to introduce IT Resilience Index for market infra institutions" (Aug 2026)introduction of ITRI by circular; reporting to SCOT and boards
Practice
11 questions on this article
Check the answer for each question, or reveal all at once.