SEBI’s disaster-recovery consultation proposes shorter non-working-day drills, stronger stress tests at primary sites, configuration-drift controls and a way for stock exchanges to recover trade data from clearing corporations. Published on 15 September 2026, the plan is still a proposal; comments remain open until 5 October.
Everyone else is reporting a four-hour drill; we are explaining the failure chain SEBI is trying to break. The real objective is not a faster rehearsal. It is proof that exchanges, clearing corporations and depositories can preserve data and continue market functions when several safeguards fail together.
What the SEBI disaster-recovery proposal contains
SEBI’s consultation applies to market infrastructure institutions, or MIIs: stock exchanges, clearing corporations and depositories. It proposes moving full disaster-recovery drills to non-working days, beginning at the primary data centre and switching operations to the disaster-recovery site. Moneycontrol’s report describes a four-hour minimum drill.
The proposal also broadens what resilience testing should cover. MIIs would test transaction volumes and orders per second, but also master data, database and table sizes and other non-transactional components. That matters because a system can process a synthetic order stream yet still fail when reference data, logging or database limits are stressed.
| Control area | Proposed test | Risk addressed |
|---|---|---|
| Failover | Non-working-day PDC-to-DRS drill | Unproven recovery sequence |
| Primary site | Load and boundary-condition stress | Failure before failover is invoked |
| Configuration | Alignment checks and alerts | Drift between PDC, near site and DRS |
| Trade data | Recovery from clearing corporation | Replication loss at exchange sites |
Why primary-site resilience belongs in a recovery rule
Traditional disaster-recovery planning can over-focus on the backup site. Yet many outages start as a component failure, capacity limit or configuration error at the primary site. SEBI proposes regular fault-tolerance testing so redundant switches, servers and other components demonstrably take over.
The regulator also wants MIIs to identify system boundary conditions and upper limits, improve application-level error logging and maintain a ready reckoner for interpreting errors. Those controls shorten diagnosis time. They also make a drill more useful: a failover that succeeds without explaining the original fault can leave the underlying weakness untouched.
Configuration drift is the quiet operational risk
A disaster-recovery site can look healthy and still be unusable if its software, permissions or data definitions differ from production. The consultation therefore proposes tests and alerts to keep the primary data centre, near site and disaster-recovery site aligned.
For fintech vendors supplying exchanges or depositories, this creates a documentation burden as well as a technical one. Changes should be traceable across environments, dependencies must be included in drills, and exceptions need named owners. A green dashboard is not enough if the institution cannot show which version was tested.
The important new backstop: recovering trade data
The most consequential proposal concerns data loss. Where disruption affects replication at both an exchange’s near site and disaster-recovery site, SEBI envisages recovering lost trade data from clearing corporations. Exchanges and clearing corporations would establish standard operating procedures for that path.
This is sensible because the two institutions see different stages of the same market activity. But it requires exact agreement on identifiers, sequencing and cut-off times. Restored records must be complete, deduplicated and reconciled before the market treats them as authoritative.
What market institutions should do before the rule is final
MIIs can inventory failure scenarios now: power, network, storage, identity, database, application and third-party dependencies. They can also compare real capacity limits with assumptions used in the last drill. None of that prejudges the consultation outcome; it reveals whether current plans are testable.
Boards should ask for evidence of recovery-point and recovery-time performance, not simply a pass label. They should also insist that customer and participant communications are exercised. A technically successful failover can still damage the market if brokers do not know which venue state is authoritative.
The proposal fits a broader attempt to modernise market plumbing, including Demat 2.0 for tokenised bonds and SEBI’s closing-auction and expiry-settlement consultation. More automation raises the value of consistent resilience controls.
How to judge whether a drill was meaningful
A meaningful drill should begin with an explicit failure scenario and success criteria. It should record the last intact transaction, the first transaction processed after recovery and the evidence used to reconcile the gap. It should include delayed or corrupted messages, not only a clean shutdown and planned restart.
Independent observers should compare the timeline with system logs, alerts and participant communications. If the recovery team relies on undocumented knowledge held by one engineer, the test has revealed a key-person dependency even if systems eventually return. Findings need owners and deadlines, followed by a retest of the failed control.
Volume testing deserves similar discipline. Average traffic is not the right benchmark for market infrastructure. Scenarios should cover peak messages, concentration in one product, a surge in modifications or cancellations and heavy reference-data use. The consultation’s attention to boundary conditions suggests SEBI wants institutions to understand where graceful degradation ends and uncontrolled failure begins.
What investors should take from the consultation
The proposal does not guarantee uninterrupted trading, nor does it eliminate the possibility of erroneous orders or delayed settlement. It is an attempt to make failure recovery more observable and repeatable. Investors should distinguish a tested recovery plan from a promise that outages cannot happen.
When a real disruption occurs, the most useful disclosures will be precise: affected functions, time of the last consistent record, recovery point, reconciliation method and any trades requiring review. That information allows brokers and clients to manage exposure without speculation.
In plain terms, the SEBI disaster-recovery proposal asks market institutions to prove four things: the primary site can withstand stress, backups can take over, lost trade data can be reconstructed, and the market can restart from reconciled records.
Frequently asked questions
Is this SEBI proposal already binding?
No. It is a consultation paper published on 15 September 2026. Comments are invited until 5 October 2026.
Which institutions are covered?
Stock exchanges, clearing corporations and depositories, collectively described as market infrastructure institutions.
Why conduct drills on non-working days?
The proposal aims to make full operational tests easier to run while avoiding disruption to live trading and settlement.
What is configuration drift?
It is the gradual difference between production and backup environments that can make a disaster-recovery site fail when needed.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



