← Executive Agenda

Bharat Pulse · Capital markets and regulatory strategy

SEBI's resilience agenda: business continuity, subsidiary cyber risk and the closing-market redesign

Four September consultations connect technology recovery, governance and market design. Exchanges, clearing corporations, depositories and their ecosystem should assess operating dependencies and submit evidence-led responses, with CAS comments due on 3 October.

TLGS Research & Perspective21 September 20265 min read

The executive brief

The decision in front of the business.

Respond to the proposals as one market-resilience programme, while evaluating each proposed rule on its own costs, benefits and implementation requirements.

01

Business continuity is not only a second data centre. It requires recoverable transaction records, tested participant connectivity and accountable decisions during a disruption.

02

Subsidiary cybersecurity and continuity of key management functions affect the MII group's real operating perimeter, not merely its corporate organisation chart.

03

The closing-auction and derivatives-settlement alternatives require testing by brokers, asset managers and technology providers as well as exchanges. Consultation proposals should remain distinct from final operating instructions.

Policy and project context

The developments that matter.

Four connected consultations

SEBI issued consultations on MII governance on 9 September, subsidiary IT and cybersecurity coverage on 11 September, CAS and derivatives settlement on 12 September, and BCP/disaster recovery on 15 September.

The operating proposals

SEBI seeks views on shorter mock-recovery timing, additional disruption scenarios, primary-site resilience and exchange recovery of lost data from clearing corporations. Other questions concern subsidiary coverage and exemptions, and deputies for key technology, security, compliance and risk roles.

The closing-market alternatives

The CAS consultation compares blended volume-weighted settlement pricing with continuous-trading-session VWAP, proposes changes to indicative index information, order handling and market timings, and invites comments by 3 October 2026.

TLGS assessment

The commercial and operating implications.

BCP and disaster recovery: test the complete transaction lifecycle

An MII's internal recovery can succeed while participants remain unable to trade, reconcile or settle. A useful readiness assessment should therefore follow the transaction from order entry through trade confirmation, risk calculation, clearing records and participant reconciliation. Identify dependencies on networks, time synchronisation, vendors and staff decisions.

The response to shorter or more demanding drills should be supported by test evidence: recovery timestamps, the last consistent record, reconnection behaviour, outstanding orders and reconciliation exceptions. Firms should distinguish recovery of infrastructure from restoration of a complete and reliable market service. This distinction is valuable both for implementation planning and for consultation feedback.

Data recovery needs reconciliation and accountability

The proposal involving recovery of exchange data from clearing corporations raises a practical control question: how will the parties establish a consistent record before resuming normal operations? Businesses should test which records are available, who authorises reconstruction and how mismatches are escalated.

For clearing members and brokers, the corresponding work is to assess their own books and customer communications during a recovery event. A successful drill should produce a documented sequence of decisions and reconciliation results. Recovery claims should be linked to evidence rather than to a statement that a backup site exists.

Subsidiary cybersecurity: follow the dependency, not just the legal entity

The subsidiary consultation addresses coverage criteria and exemptions. MII groups should begin with a functional inventory: which subsidiaries hold data, provide systems, share infrastructure, support essential services or rely on common vendors? Classify these relationships before debating the cost of applying a framework.

The strongest response will identify material dependencies and justify proportionate treatment with evidence. An exemption argument should demonstrate limited systemic relevance or effective alternative controls, rather than rely only on the existence of a separate company. Technology providers should expect customers to ask for clearer responsibility boundaries, access controls, incident reporting and assurance evidence.

Governance: continuity of authority matters during an incident

The proposed deputies for technology, information security, compliance and risk roles make succession and availability an operating issue. The commercial and governance task is to define authority, escalation, competence and handover arrangements—not merely add another designation.

Boards should examine who can make a recovery decision when a key officer is unavailable, how conflicts are resolved and what information reaches the governing body. A policy submission can use organisational evidence to address proportionality, independence and practical staffing. Critical responsibilities should remain identifiable even where several functions rely on shared technology or service providers.

CAS and settlement: measure the basis and execution effects

SEBI's published questions present a blended-VWAP approach and a continuous-trading-session VWAP alternative, alongside two timing options: cash continuous trading to 3:30 p.m. with derivatives to 3:45 p.m., or 3:15 p.m. and 3:30 p.m. respectively. These are alternatives for consultation, not simultaneous changes already in force.

Asset managers and trading members should test how the alternatives affect execution against the close, hedge alignment, expiry-day basis and reconciliation. Use historical or controlled test data to examine outcomes across liquid and less-liquid securities, ordinary days and stressed expiry conditions. An aggregate average can hide material effects on particular products or customer strategies.

Order handling and information: prepare systems and customers

The consultation also addresses dissemination of indicative index information, restrictions on cancelling certain CAS limit orders and conversion of unexecuted iceberg quantities. Brokers and technology vendors should map the affected order states, customer instructions, validation rules, displays and audit trails.

An implementation plan should cover order-management systems, risk checks, market-data consumption, contract-note or reporting interfaces where relevant, and customer education. Simulation should include rejection, modification and cancellation scenarios. Market design works through these operational details; a change in the closing-price formula alone does not describe the full business impact.

Where tangible business demand can arise

The response programme can generate work in recovery testing, system-integration assessment, data reconciliation, cybersecurity assurance, governance documentation and trading-system changes. Service providers should frame proposals around a customer's identified gap and measurable acceptance criteria, rather than sell generic 'SEBI compliance'.

The purchasing counterparties are the relevant MIIs, intermediaries or other businesses commissioning these services. SEBI is the regulator receiving policy feedback, not a universal tendering authority for private implementation work. Commercial opportunities should therefore be mapped to the institution that owns the system and budget.

A useful consultation submission has a proposed solution

Prepare a proposal-by-proposal matrix showing the issue, affected process, evidence, expected benefit, implementation cost and recommended wording or transition arrangement. Identify where the organisation supports the objective but proposes a different operating mechanism. Quantified testing is particularly valuable for recovery timing and settlement design.

An association response should distinguish common industry positions from member-specific concerns. It should also include smaller participants' implementation constraints without assuming that lower scale justifies weaker control. SEBI's response portal asks for comments and rationale; the submission should be designed around that structure.

From insight to action

Priorities for leadership.

Boards, CTOs and CISOs

Build one inventory of critical services, subsidiary dependencies, recovery evidence and accountable decision-makers across the four consultation tracks.

Brokers, AMCs and vendors

Test the closing and settlement alternatives against execution, hedge, order-state and reconciliation scenarios; quantify the implementation work.

Compliance and associations

Prepare a reasoned proposal-level response and complete the CAS submission before 3 October 2026; manage the other consultations to their respective published schedules.

Strategic milestones

What to track next.

Follow SEBI's final decisions, implementation dates, exchange and clearing-corporation operating instructions, testing windows and participant requirements. Maintain a change register that separates each consultation proposal from the measure ultimately adopted.

Reference documents

Sources and further reading.

  1. 1 · Consultation
    Measures to strengthen BCP and disaster recovery of market infrastructure institutionsSEBI · 15 September 2026Business continuity, recovery exercises and operational resilience proposals.
  2. 2 · Consultation
    Review of the Closing Auction Session, market timings and derivatives settlement methodologiesSEBI · 12 September 2026Closing-market design and expiry settlement alternatives.
  3. 3 · Consultation
    Applicability of the MII IT and cybersecurity framework to subsidiariesSEBI · 11 September 2026Subsidiary coverage and exemption criteria.
  4. 4 · Consultation
    Strengthening governance of market infrastructure institutionsSEBI · 9 September 2026Governance and continuity of key management roles.
  5. 5 · Official consultation portal
    Public consultation: proposal-by-proposal questions and response portalSEBIBCP/DR, subsidiary cybersecurity, governance and closing-auction consultation questions.
  6. 6 · Reporting
    India regulator plans changes to expiry-day derivatives settlement pricesReuters · 12 September 2026CAS settlement alternatives and the 3 October comment deadline.

Connected business questions

Explore the wider agenda.

Sanctions, energy and India–U.S. trade · Executive insight

The new U.S. Russia sanctions law: what Indian boards, exporters and energy businesses must separate

The law signed on 18 September links Russian energy purchases to potential country tariffs while expanding entity, financial and maritime sanctions. India's exposure must be assessed through separate trade, counterparty, banking and supply-chain channels.

Enacted 18 September 2026 · implementation and country determinations

Read the insight & business implications →21 September 2026 · 7 min read
Civil nuclear and small modular reactors · Executive insight

India's Bharat SMR opportunity: a practical entry strategy for investors, industry and suppliers

The reported 300-MW BARC commercialisation discussions point to a potential new industrial ecosystem. The opportunity extends beyond reactor ownership to industrial offtake, qualified manufacturing, infrastructure and coordinated project development.

Nuclear commercialisation and regulatory transition · industry-entry strategy

Read the insight & business implications →21 September 2026 · 6 min read
BRICS, AI and cross-border enterprise · Executive insight

BRICS open-source AI: where Indian startups and MSMEs can build practical value

The proposed BRICS AI open-source community creates an agenda for technology collaboration, localisation and industrial applications. Indian businesses should connect that agenda to customer demand, commercial rights and trusted deployment.

Summit proposal · collaboration and market-development strategy

Read the insight & business implications →21 September 2026 · 5 min read