Subject: GS 3: Economy
Context: Recently, the Securities and Exchange Board of India (SEBI) has introduced the IT Resilience Index (ITRI).
About ITRI
- The IT Resilience Index (ITRI) is a quantitative resilience barometer introduced by the Securities and Exchange Board of India (SEBI) to assess the robustness of critical IT systems of Market Infrastructure Institutions (MIIs).
UPSC Coaching Classes
About Market Infrastructure Institutions (MIIs)
- MIIs are institutions that provide the essential infrastructure required for the functioning of securities markets.
- They include stock exchanges, clearing corporations and depositories.
- They perform critical functions such as trading, clearing, settlement and securities holding.
- Due to their systemic importance, disruption in their operations can affect the wider financial market.
Reasons For SEBI Introducing ITRI
- Rising Technological Dependence: Indian capital markets increasingly depend on technology, with even a few minutes of disruption potentially affecting millions of investors and billions of rupees in trades.
- Protection of Critical Functions: ITRI assesses whether systems supporting trading, clearing, settlement and securities holding can withstand disruptions.
- Growing Digitalisation: Increased retail participation through online platforms, algorithmic trading and faster settlement cycles has made market efficiency inseparable from technology reliability.
- Systemic Importance of MIIs: In 2015, SEBI classified MIIs as “systemically important” and called for a robust cybersecurity framework for their systemically critical functions.
- Shift from Compliance to Resilience: It moves regulatory assessment from merely checking compliance towards quantitative risk monitoring.
How will ITRI Work?
- Assessment Approach: ITRI will move from mere compliance checking to quantitative measurement of IT resilience and technology risk.
- Nine Parameters: It will assess IT resilience through nine parameters, with weights based on their systemic-risk importance.
- Key Weights: Availability and Security carry 20% each, Business Continuity and Reliability 10%, and Scalability 5%.
- Measurement: The Industry Standards Forum of MIIs will define the detailed sub-parameters and measurement criteria.
- Periodic Refinement: The weights may be refined using actual outage data, cyber incidents and stress tests.
- Early Warning System: MIIs will develop an Early Warning System (EWS) to detect deterioration in resilience parameters and enable timely remedial action.
How is ITRI Different?
- Measurable Resilience: ITRI converts IT resilience into a measurable index, unlike the predominantly principle-based global approach.
- Financial Stability: MII-level technology failures can pose a financial stability risk, not merely an IT risk.
- Early Detection: The Early Warning System (EWS) identifies weaknesses before they become failures.
- Future Readiness: SEBI’s technology roadmap addresses risks from AI, cloud, high-frequency trading, DLT and quantum technologies, along with SupTech, RegTech and tokenisation.
Click to Know UPSC OnlyIAS Coaching Centres
ITRI: Comparison with Global Standards
- United Kingdom: The Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) require institutions to identify important business services, set disruption tolerances and demonstrate recovery capacity.
- European Union: The Digital Operational Resilience Act (DORA) provides a comprehensive regulatory framework for digital resilience, rather than a numerical scorecard.
- United States: Technology resilience is incorporated into broader regulatory oversight, without a single ITRI for stock exchanges.
- Singapore: The Monetary Authority of Singapore (MAS) follows strong technology-risk management guidelines.
- Hong Kong: Regulators use cyber-resilience assessment frameworks and measurable maturity levels.
- Australia: The Australian Securities and Investments Commission (ASIC) and Australian Prudential Regulation Authority (APRA) focus on critical operations, technology dependencies, outsourcing risks and cyber recovery.