SEBI Gives MIIs Until February 2027 to Operationalise IT Resilience Index, Early Warning and Real-Time Monitoring
Read Time:
The Securities and Exchange Board of India has issued a final framework for an IT Resilience Index (ITRI) for major Market Infrastructure Institutions, creating a structured way to measure the resilience of critical market systems and requiring new early-warning and real-time service-monitoring capabilities.
SEBI’s circular dated August 24, 2026, Circular No. HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026, applies to stock exchanges, clearing corporations and depositories covered by the framework. The measure follows SEBI’s March consultation on an ITRI for MIIs and now sets an implementation timetable extending into early 2027.
Nine parameters will make up the resilience score
The final framework assigns the largest weights to Availability and Security, at 20% each. Integrity, Governance, Reliability and Monitoring, Business Continuity, and Modularity and Flexibility carry 10% each. Scalability carries 5%, while an “Others” category, including areas such as incident handling, carries another 5%.
The index is intended to cover Critical Systems and related systems rather than operate as a high-level policy scorecard. The practical implication for MIIs is that technology operations, information security, continuity arrangements and governance data will have to feed a common measurement framework that can be reviewed over time.
Industry Standards Forum to finalise detailed criteria
Under the circular, the Industry Standards Forum is to finalise the detailed sub-parameters and criteria used in the ITRI framework. The published implementation schedule requires these building blocks to be translated into operating procedures and systems rather than left as a manual periodic assessment.
MIIs are expected to compute ITRI on a half-yearly basis and place comparative analysis of consecutive half-years, together with corrective actions, before the relevant technology oversight and governing structures. The framework also calls for system-driven computation using information already captured in IT systems and data sources, with manual intervention to be avoided as far as possible.
Early warning and real-time monitoring become part of the framework
A major operational element is the requirement for an Early Warning System and Real Time Monitoring of Service Delivery. MIIs are expected to build continuous visibility into services through consolidated dashboards and documented procedures so that resilience weaknesses can be identified before they translate into serious market disruption.
SEBI’s implementation timetable requires the ITRI framework, including the Early Warning System and real-time service monitoring, to be operationalised by February 28, 2027. Detailed Standard Operating Procedures, after finalisation of the sub-parameters, are to be submitted to SEBI after review by the MIIs’ technology oversight structure by January 31, 2027. The first ITRI submission under the framework will cover the half-year ending March 31, 2027.
What the circular means for governance and assurance teams
Although the immediate compliance obligation sits with MIIs, the framework is relevant to finance, risk, internal audit, technology assurance and governance professionals because it formalises technology resilience as a measurable, recurring control outcome. Boards and senior oversight committees will need more than incident counts: they will need trend information, root-cause visibility, corrective-action tracking and evidence that the resilience metrics are being generated consistently.
For internal auditors and technology assurance teams, key areas to watch include the completeness of source data, integrity of automated computation, governance over changes to sub-parameters, evidence supporting dashboard alerts, closure of corrective actions and alignment between business-continuity plans and actual service availability. Where manual inputs remain necessary, the control rationale and review trail will become especially important.
Implementation should start before the February deadline
The February 2027 operational deadline leaves MIIs a limited window to convert the framework into production-grade monitoring. Work is likely to span inventory and classification of Critical Systems, data-source mapping, automated metric capture, thresholds and alert logic, dashboard design, SOP approval, escalation protocols, testing and governance reporting.
The first half-yearly submission for March 31, 2027 also means organisations will need reliable data collection in place before the reporting date; a system completed only at the end of February cannot be treated as a substitute for disciplined implementation and evidence throughout the measurement period.
Practical takeaway: MIIs should treat the ITRI circular as an operational resilience programme, not merely a new regulatory return. Technology, cyber-security, business-continuity, risk, compliance and internal-audit teams should establish ownership of each ITRI parameter, map source systems, close automation gaps and prepare the governance trail needed for the first March 2027 reporting cycle.
Useful official links
SEBI — IT Resilience Index for Market Infrastructure Institutions (MIIs)
Key takeaway
New final SEBI circular with defined technology-resilience metrics and hard 2027 implementation/reporting milestones.