
The Securities and Exchange Board of India (Sebi) has introduced an IT Resilience Index (ITRI) framework for market infrastructure institutions (MIIs) that represents a global first in regulatory technology resilience assessment. As reported by The Hindu, SEBI's ITRI appears to be among the first attempts globally by a regulator to design a quantitative resilience barometer, as measurable as capital adequacy for banks, for MIIs such as stock exchanges, clearing corporations and depositories. The framework comes at a time when India's securities market is experiencing sea changes in digital transformation, with increased participation of retail investors through online platforms, higher algorithmic trading volumes and faster settlement cycles. The move addresses the reality that even a few minutes of disruption can affect millions of investors and billions of rupees in trades, making technology reliability a boardroom issue rather than just a compliance matter.
The ITRI will measure nine parameters with respective weightages under a 100-point system-driven framework, each weighted on the basis of a systemic-risk hierarchy. As reported by The Hindu, availability and security carry the highest weightage of 20% each, while integrity, governance, reliability and monitoring, business continuity, and modularity and flexibility each account for 10% of the score. The remaining 5% will be split between scalability and other aspects, including incident handling. The Industry Standards Forum (ISF) of MIIs, constituted by Sebi, will finalize sub-parameters and detailed measurement criteria for each parameter by November 30, 2026. The framework will cover critical systems identified under Sebi's master circulars for stock exchanges, clearing corporations, depositories and the commodity derivatives segment, along with other systems that feed into or relate to these critical systems. The weighting exercise implies a risk-prioritisation approach, giving greater importance to parameters whose failure can immediately disrupt the functioning of MIIs, with availability and security representing the first line of defence for a financial market's functioning.
MIIs will be required to compute the ITRI on a half-yearly basis within 60 days from the end of each half-year, with the first submission covering the half-year ending March 31, 2027. According to The Hindu, MIIs must submit a comparative analysis of two consecutive half-years on a rolling basis, along with corrective actions taken or proposed, to their Standing Committee on Technology (SCOT) and Governing Board. The ITRI computation must be system-driven, meaning generated automatically from IT systems without manual intervention to ensure non-discretionary and foolproof results. The framework is designed as a self-operating model under which MIIs will periodically compute the ITRI and provide their governing boards with an assessment of the overall health of IT systems and areas requiring improvement. Unlike global counterparts, SEBI's distinctive model attempts to convert resilience into a measurable index, with the U.K.'s Financial Conduct Authority and Prudential Regulation Authority having operational resilience rules requiring financial institutions to identify important business services and demonstrate recovery from severe operational shocks, while the European Union's Digital Operational Resilience Act (DORA) is a regulatory rulebook rather than a numerical scorecard.
As part of the framework, MIIs must develop an Early Warning System (EWS) to detect possible deterioration in any ITRI parameter that could lead to performance issues, system slowness or other disruptions. As reported by The Hindu, the regulator has mandated continuous monitoring of service delivery to market participants, requiring systems that provide continuous visibility into service delivery, including consolidated dashboards to monitor system and application performance. MIIs must also formulate Standard Operating Procedures (SOPs) to monitor system availability and flag any disruption or deviation. The Information Systems Framework will set the baseline parameters, acceptable thresholds and standard operating procedures for calculating the index, along with an objective, system-driven scoring methodology to ensure comparability across MIIs. The framework builds on existing requirements for MIIs to continuously monitor process and application performance and system-resource utilization at the level of each IT component for early detection of performance issues and slowness.
SEBI has already constituted a working group to formulate a short-term and long-term technology roadmap for MIIs, taking a holistic view on the adoption of emerging technologies including AI/machine learning, Suptech, RegTech and tokenisation. As reported by The Hindu, the regulator has initiated discussions on a long-term technology roadmap covering areas such as AI, cloud computing, distributed ledger technology and quantum-safe systems. The biggest challenge before SEBI is the pace of technological change, as technology risks evolve faster than regulatory frameworks. Questions may arise on a common index when stock exchanges, clearing corporations and depositories have different technology architectures and functions, while substantial investments are needed to build automated monitoring systems, conduct continuous testing and maintain redundant infrastructure. The framework's success will depend on whether a high score translates into faster recovery in the event of actual cyberattacks, system outages or technology shocks, potentially becoming a global template to safeguard the digital foundations of finance.