·The Hindu

SEBI’s ITRI: Global test for India’s future-ready financial architecture

In this note
  1. At a Glance
  2. Why in the News
  3. Background & Evolution
  4. Core Static Facts
  5. Multi-Dimensional Analysis
  6. Recent Developments (last 12–18 months)
  7. Prelims Hooks
  8. Mains Relevance
  9. Related Topics to Study Next
  10. Common Errors / Trap Areas

1. At a Glance

  • ITRI (IT Resilience Index) is SEBI's new quantitative "technology health scorecard" for Market Infrastructure Institutions (MIIs) — stock exchanges, clearing corporations, and depositories [4].
  • It measures robustness of critical IT systems, not routine compliance — analogous to capital adequacy for banks, but for technology resilience [4].
  • Billed as among the first attempts globally by a securities regulator to design a measurable resilience barometer for market infrastructure [4].
  • Relevant for UPSC as it links financial regulation, cybersecurity governance, and fintech/digital market architecture — a recurring GS-III/GS-II theme.

2. Why in the News

  • SEBI introduced the ITRI amid a consultation paper (March 2026) on the framework, followed by a circular (August 2026) formally issuing the IT Resilience Index for MIIs [1][2].
  • Trigger: rising technological dependence of Indian capital markets — growing retail participation via online platforms, higher algorithmic trading volumes, and faster settlement cycles, where even minutes of IT disruption can affect millions of investors and billions of rupees in trades [4].

3. Background & Evolution

  • 2015: SEBI first classified MIIs (stock exchanges, clearing corporations, depositories) as systemically important, mandating a robust cybersecurity framework [4][3].
  • 2018: SEBI issued Cyber Security and Cyber Resilience framework circulars for Stock Exchanges, Clearing Corporations, Depositories, and separately for Stock Brokers/Depository Participants [3].
  • 2023: Extended cyber security/resilience framework to Portfolio Managers [3].
  • August 2024: SEBI issued the consolidated Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI-Regulated Entities (REs), which introduced related tools like the Cyber Capability Index (CCI) for annual self-assessment [3].
  • March 2026: SEBI released a Consultation Paper on the Framework of IT Resilience Index for MIIs [2].
  • August 2026: SEBI issued the final circular on the IT Resilience Index for MIIs, operationalising the ITRI [1].

4. Core Static Facts

Aspect Detail
Regulator Securities and Exchange Board of India (SEBI) [4]
Applicable entities Market Infrastructure Institutions (MIIs) — stock exchanges, clearing corporations, depositories [4]
Purpose Quantitative measure of IT/technology resilience, not routine compliance checking [4]
Predecessor concept MIIs declared "systemically important" in 2015, requiring robust cybersecurity framework [4]
Related index Cyber Capability Index (CCI) — annual self-assessment tool under CSCRF, 2024 [3]
Key parameters assessed Availability, security, integrity, governance, reliability & monitoring, business continuity, modularity & flexibility, scalability (reported as ~9 broad parameters) [3]
Key milestone documents Consultation Paper (March 2026) [2]; Circular (August 2026) [1]
Scope of resilience check Trading, clearing, settlement, and securities holding systems — tested against operational shocks, cyber threats, technical failures, and sudden activity spikes [4]

5. Multi-Dimensional Analysis

Economic

  • Capital markets now handle billions of rupees in trades daily; even brief IT outages carry systemic financial risk, justifying a resilience metric akin to bank capital adequacy [4].
  • Enhances investor confidence, potentially supporting deeper retail and institutional participation in equity/derivatives markets [4].

Scientific / Technological

  • Reflects growing algorithmic trading and faster settlement cycles (e.g., T+1/instant settlement trends) as key stress points for MII infrastructure [4].
  • Builds on cyber-resilience frameworks (2018, 2023, 2024) that increasingly formalise IT governance in financial market infrastructure [3].

Ethical / Governance

  • Shifts regulatory approach from checklist-based compliance to outcome-based, quantitative scoring, improving transparency and comparability across MIIs [4].
  • Introduces measurable accountability for MIIs' technology governance, akin to prudential norms in banking.

Administrative

  • Implementation will require MIIs to build monitoring capacity across nine-odd parameters (availability, integrity, business continuity, scalability, etc.) [3].
  • Consultation-to-circular process (March 2026 → August 2026) shows SEBI's standard regulatory rollout: draft → public comments → final framework [1][2].

Global/Comparative

  • Positioned as a first-of-its-kind global regulatory tool, potentially setting a template other securities regulators may study or replicate [4].

6. Recent Developments (last 12–18 months)

  • August 2024: SEBI notifies Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, introducing the Cyber Capability Index [3].
  • March 2026: SEBI releases Consultation Paper on Framework of IT Resilience Index for MIIs, inviting public comments [2].
  • August 2026: SEBI issues final circular formally introducing the IT Resilience Index (ITRI) for MIIs [1].

7. Prelims Hooks

  • ITRI = IT Resilience Index, introduced by SEBI for Market Infrastructure Institutions (MIIs) [1][4].
  • MIIs include: stock exchanges, clearing corporations, and depositories [4].
  • MIIs were first declared "systemically important" by SEBI in 2015 [4].
  • ITRI is described as analogous to capital adequacy norms for banks [4].
  • ITRI assesses IT systems for trading, clearing, settlement, and securities holding [4].
  • SEBI's Consultation Paper on ITRI was released in March 2026 [2].
  • SEBI's final circular on ITRI was issued in August 2026 [1].
  • Related tool: Cyber Capability Index (CCI), part of the Cybersecurity and Cyber Resilience Framework (CSCRF), notified August 2024 [3].
  • SEBI's first cyber security/resilience circular for exchanges, clearing corporations, and depositories was issued in December 2018 [3].
  • Cyber security framework extended to Portfolio Managers in March 2023 [3].
  • ITRI is claimed to be among the first such quantitative resilience indices designed by a securities regulator globally [4].
  • Key risk drivers behind ITRI: rising algorithmic trading, retail participation via online platforms, and faster settlement cycles [4].

8. Mains Relevance

9. Related Topics to Study Next

  • SEBI's regulatory architecture and functions — foundational body for understanding ITRI's institutional context.
  • Cybersecurity and Cyber Resilience Framework (CSCRF), 2024 — direct predecessor/related framework with Cyber Capability Index.
  • Basel norms / capital adequacy in banking (RBI) — comparative regulatory analogy explicitly used for ITRI.
  • Algorithmic trading regulation in India — key driver cited for ITRI's necessity.
  • Systemically Important Financial Institutions (SIFIs) concept — parallel to "systemically important" MIIs.
  • T+1/instant settlement reforms — linked to faster settlement cycle risks mentioned in the article.
  • National Cyber Security Policy / CERT-In — broader national cybersecurity governance ecosystem.
  • Financial Stability and Development Council (FSDC) — apex body coordinating financial sector regulators including SEBI, RBI.

10. Common Errors / Trap Areas

  • Do not confuse ITRI (IT Resilience Index, 2026) with Cyber Capability Index (CCI) — CCI is a self-assessment tool under CSCRF (2024); ITRI is a distinct, MII-specific quantitative index [3][1].
  • MIIs were declared systemically important in 2015, not the year ITRI was introduced — don't collapse these dates.
  • ITRI applies specifically to MIIs (exchanges, clearing corporations, depositories), not to all SEBI-regulated entities (which fall under the broader CSCRF) [3][4].
  • Avoid confusing SEBI's ITRI with RBI's cybersecurity/resilience frameworks for banks — different regulators, different regulated sectors.
  • Note the correct chronology: Consultation Paper (March 2026) → Circular (August 2026) — don't reverse the sequence.

Sources

  1. 1SEBI — IT Resilience Index for Market Infrastructure Institutions (MIIs) (Circular)sebi.gov.in · tier 1
  2. 2SEBI — Consultation Paper on Framework of IT Resilience Index for Market Infrastructure Institutions (MIIs)sebi.gov.in · tier 1
  3. 3SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs), Aug 2024sebi.gov.in · tier 1
  4. 4The Hindu BusinessLine — "SEBI's ITRI: Global test for India's future-ready financial architecture" (Santosh V. Perumal)thehindu.com · tier 4

Mains Q&A on this note

Also on 27 August

All 27 August articles →