Sebi proposes extending IT, cyber security framework of MIIs to their arms
Sebi proposed extending IT and cyber security rules to subsidiaries of market infrastructure institutions. This move aims to strengthen regulatory oversight over these evolving business structures. Subsidiaries undertaking core MII activities will...

While MIIs are governed by Sebi and operate in compliance with its IT and cybersecurity frameworks, the applicability and regulatory jurisdiction of these framework are not explicitly defined over their subsidiaries.
The move comes even as Sebi highlighted that there could be a case for MIIs to take services of their subsidiaries to carry out certain activities.
These subsidiaries may need to operate in close coordination with the parent MII and might use shared technology infrastructure, applications, market data or other critical IT resources.
"As MIIs continue to diversify their business models through subsidiaries, extending the applicability of the framework would ensure that the regulatory framework remains aligned with the evolving market structure," Sebi said in its consultation paper.
Under the proposal, the IT and cyber security framework applicable to the parent MII will also apply to any subsidiary undertaking activity that directly contributes to that MII's domain.
In other words, the subsidiary is carrying out an activity which the MII is supposed to do, handling data that the MII is supposed to handle or sharing infrastructure with MII.
Such subsidiaries will comply with all applicable requirements relating to cyber security, system audits, incident reporting and technology governance.
The IT and cyber security framework applicable to the parent MII will not apply to the subsidiary if the arm does not meet any of these three criteria, Sebi said.
If an MII believes its IT and cyber security framework should not be extended to a subsidiary that only meets the condition of sharing IT infrastructure with the MII, it must follow prescribed steps to seek an exemption.
Such MIIs may seek exemption from Sebi regarding not extending the IT and cyber framework to that subsidiary.
Such proposals must include details of compensatory controls put in place/ proposed to be put in place by MIIs to ensure that the cyber and IT resilience of MIIs is not affected, along with the views of SCOT (Standing Committee on Technology) and the board of the MIIs, the regulator said.
The Securities and Exchange Board of India (Sebi) has sought public comments till October 2 on the proposal.
Download ET Markets APP