·The Hindu·15 marks·250–350 wordsEconomy

Examine the evolving role of SEBI in regulating technology risk in Market Infrastructure Institutions. What are the challenges in ensuring compliance?

In this answer
  1. From reactive audit to continuous oversight
  2. ITRI: resilience made measurable
  3. Challenges in ensuring compliance

Market Infrastructure Institutions (MIIs) — stock exchanges, depositories and clearing corporations — are systemically critical: a single outage halts price discovery and settlement. SEBI's technology regulation has accordingly shifted from post-incident audit to pre-emptive, measurable supervision.

From reactive audit to continuous oversight

  • Audit-based phase: mandatory System and Network Audit of MIIs [1], later given a standardised reporting format, plus a Testing Framework for IT systems covering software change and disaster-recovery testing [2].
  • Consolidation phase: the Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 replaced fragmented circulars with one outcome-based framework built on anticipate–withstand–contain–recover–evolve [3].
  • Governance phase: statutory Standing Committee on Technology (SCOT) at each MII embeds technology risk in board-level accountability [4].

ITRI: resilience made measurable

  • SEBI's IT Resilience Index (ITRI), proposed in March 2026 and introduced by circular in August 2026, scores MIIs on nine parameters over 100 points, with availability and security weighted highest (20 each) [5][6].
  • Computed half-yearly through a system-driven, non-discretionary process, with comparative analysis and corrective action reported to SCOT and the governing board [5][6].
  • A mandated Early Warning System shifts detection ahead of failure, flagging slowness before disruption [5].

Challenges in ensuring compliance

  • Self-assessment risk: scores are computed by the MII itself, inviting box-ticking rather than genuine resilience.
  • Capacity asymmetry: smaller depositories and clearing corporations lack the engineering depth of large exchanges.
  • Layered compliance burden: CSCRF audits, system audits and ITRI reporting overlap, diverting scarce technical staff.
  • Third-party dependence: cloud, data-centre and vendor failures lie outside direct MII control.
  • Supervisory capacity: SEBI must retain specialised talent to interrogate scores meaningfully.

Technology risk is now treated as systemic risk, and ITRI converts resilience from an audit finding into a monitored metric. Its success will depend on independent validation of scores, calibrated timelines and capacity-building support — turning compliance into genuine investor protection, SEBI's core statutory mandate.

Sources

  1. 1SEBI, System and Network Audit of Market Infrastructure Institutions (May 2022)audit-based phase of MII technology oversight
  2. 2SEBI, Testing Framework for the IT Systems of MIIs (May 2023)software change and disaster-recovery testing mandate
  3. 3SEBI, Cybersecurity and Cyber Resilience Framework (CSCRF) for Regulated Entities (Aug 2024)consolidation of cyber circulars; resilience goals
  4. 4SEBI, Statutory Committees at Market Infrastructure Institutions (Jun 2024)Standing Committee on Technology (SCOT)
  5. 5SEBI, Consultation Paper on Framework of IT Resilience Index for MIIs (Mar 2026)nine parameters, weightages, half-yearly computation, Early Warning System
  6. 6Business Standard, "Sebi to introduce IT Resilience Index for market infra institutions" (Aug 2026)introduction of ITRI by circular; reporting to SCOT and boards
Practice
11 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

More from this note

More on Economy