Why in news?
The Securities and Exchange Board of India issued a new technology-resilience framework on 24 August. It applies to stock exchanges, clearing corporations and depositories, with one stated exception. A 100-point index will measure the resilience of their critical systems. The first formal submission will cover the half-year ending 31 March 2027.
Why market infrastructure is critical
Stock exchanges match and record trades. Clearing corporations manage obligations after a trade occurs. Depositories hold securities in electronic form and support transfer of ownership. Together, these bodies are called Market Infrastructure Institutions.
A failure in one institution can spread across the market. Trading may stop, payments may be delayed or records may become uncertain. Technology is therefore part of financial stability. Resilience requires more than protection against a deliberate cyberattack.
What the index covers
The Information Technology Resilience Index covers critical systems and their connected systems. It also covers systems that supply essential data feeds. AMC Repo Clearing Limited is the circular’s sole stated exception. SEBI has divided the score across nine parameters.
Availability and security receive 20 points each. Integrity, governance, reliability and monitoring each receive 10 points. Business continuity also receives 10 points. Modularity and flexibility receive 10, scalability receives five, and other controls receive five.
The last category includes incident handling. The weighting reflects several kinds of failure. A system can be secure but unavailable. It can also remain online while producing unreliable data.
Availability, integrity and security
Availability asks whether users can reach a required system when needed. Redundant equipment and recovery sites can reduce downtime. Integrity asks whether data remain correct and complete. Reconciliation and controlled changes help protect it.
Security concerns unauthorised access, misuse and attack. Strong identity controls, monitoring and patching form part of it. The three qualities depend on each other. Restoring an available service with corrupted data would not represent true recovery.
Business continuity and flexibility
Business continuity plans define how essential work continues during disruption. Institutions need alternate sites, tested backups and clear decision authority. Recovery exercises should include realistic dependencies. A paper plan without testing gives false assurance.
Modular systems can isolate or replace a failed component more easily. Flexible design supports controlled change. Scalability allows systems to handle a sudden increase in traffic. Indian markets need this capacity during volatile sessions and major public issues.
How the score will be prepared
The index will be computed every six months. Each institution must complete it within sixty days of the period’s end. The score will be compared across consecutive rolling half-years. This can show improvement or emerging weakness.
The Industry Standards Forum for Market Infrastructure Institutions will develop detailed sub-parameters and metrics. It must complete that work by 30 November 2026. The calculation should be system-driven. Any manual exception needs review by the Standing Committee on Technology.
Governance and corrective action
The index is not only a reporting number. Institutions must examine weak areas and prepare corrective action. Their technology committee and governing board will review the result. Senior oversight prevents resilience from remaining only an information-technology concern.
Early-warning systems and real-time monitoring must support the framework. Standard operating procedures will define thresholds and escalation. Institutions must submit these procedures to SEBI by 31 January 2027. Full operationalisation is required by 28 February 2027.
What the index can improve
A common index creates a structured view across institutions. It can reveal repeated weakness before a major outage. Comparable metrics may also improve board attention and investment. Trend analysis is more useful than a one-time inspection.
The framework can support regulatory supervision without prescribing one technology. Different institutions can meet resilience goals through suitable architecture. Clear metrics also make follow-up easier. However, the score must remain connected with actual incidents and recovery performance.
Limits and safeguards
A high score cannot guarantee that no failure will occur. New attacks and software defects remain possible. Institutions may also optimise for a metric while missing a hidden dependency. Independent tests and incident reviews must continue.
Detailed security information requires careful handling. Public transparency should focus on service performance and accountability. It should not expose exploitable system design. Regulators must verify underlying evidence instead of relying only on self-reported scores.
The index is a supervisory tool, not a public investment rating
It measures the resilience of market institutions’ technology systems. It does not rate a listed company, predict market returns or remove operational risk.
Conclusion
SEBI’s index turns broad resilience expectations into measurable and repeated checks. Its balanced score recognises security, recovery, data integrity and governance together. The early-warning requirement may help detect weakness before disruption. Strong verification will matter more than a polished score. The framework succeeds when markets remain fair, continuous and trustworthy during real stress.