**Summary:**
SEBI Circular SEBI/HOM/ISD/CIR/P/2020/221, dated November 03, 2020, addresses the adoption of Software as a Service (SaaS) based solutions by Financial Sector Organizations (FSOs) for Governance, Risk, and Compliance (GRC) functions. The circular advises FSOs, including Stock Brokers, Depository Participants, Merchant Bankers, and others, to ensure the protection and control over critical systems by continuously monitoring through direct control and supervision protocol mechanisms, while keeping critical data within the legal boundary of India. This advisory is prompted by concerns raised by the Ministry of Electronics & Information Technology (MeitY) and the Indian Computer Emergency Response Team (CERT-in) regarding potential data security risks associated with SaaS solutions where data may move beyond India's jurisdictional boundaries. Compliance with this advisory must be reported in the half-yearly reports submitted by Stock Brokers and DPs to Stock Exchanges and Depositories, respectively, and by direct intermediaries to SEBI, accompanied by an undertaking confirming adherence to the circular. The advisory is effective immediately. The circular is issued under Section 11(1) of the Securities and Exchange Board of India Act, 1992. For further information, contact Anupma Chadha, Dy. General Manager, at 022-26449319 or anupmac@sebi.gov.in.
Key Entities Referenced
Securities and Exchange Board of India (SEBI): A regulatory body for the securities market in India, responsible for protecting investors' interests and regulating the market.
Ministry of Electronics Information Technology (MoEIT): A ministry within the Government of India that deals with policies related to electronics and information technology.
Software as a Service (SaaS): A software distribution model in which a third-party provider hosts applications and makes them available to customers over the Internet.
Governance, Risk Compliance (GRC): A set of processes and practices intended to help organizations operate ethically, effectively, and in accordance with their own risk appetite.
Indian Computer Emergency Response Team (CERT-In): A government-appointed agency that handles computer security incidents in India.
Securities and Exchange Board of India Act, 1992: The legislation that established the Securities and Exchange Board of India (SEBI) and defines its powers and functions.
Stock Brokers: Intermediaries that execute buy and sell orders for securities on behalf of investors through stock exchanges.
Depository Participants (DP): Agents of depositories (like NSDL and CDSL) that provide depository services to investors.
CIRCULAR
SEBI/HO/MIRSD2/DOR/CIR/P/2020/221 November 03, 2020
All Stock Brokers through exchanges
All Depository Participants through Depositories
All Merchant Bankers
All Registrar to an Issue and Share Transfer Agent
All Debenture Trustee
All Credit Rating Agencies
All Bankers to an issue
All STP Service Providers
All Approved Intermediaries
Dear Sir / Madam,
Sub: Advisory for Financial Sector Organizations regarding Software as a Service
(SaaS) based solutions
1. Ministry of Electronics & Information Technology, Govt. of India (MoE&IT), has
informed SEBI that the financial sector institutions are availing or thinking of
availing Software as a Service (SaaS) based solution for managing their
Governance, Risk & Compliance (GRC) functions so as to improve their cyber
Security Posture. As observed by MoE&IT, though SaaS may provide ease of
doing business and quick turnaround, but it may bring significant risk to health of
financial sector as many a time risk and compliance data of the institution moves
beyond the legal and jurisdictional boundary of India due to nature of shared cloud
SaaS, thereby posing risk to the data safety and security.
2. In this regard, Indian Computer Emergency Response Team (CERT-in) has issued
an advisory for Financial Sector organizations. The advisory has been forwarded
Page 1 of 2to SEBI for bringing the same to the notice of financial sector organization. The
advisory is enclosed at Annexure A of this circular.
3. It is advised to ensure complete protection and seamless control over the critical
systems at your organizations by continuous monitoring through direct control and
supervision protocol mechanisms while keeping the critical data within the legal
boundary of India.
4. The compliance of the advisory shall be reported in the half yearly report by stock
brokers and DP to stock exchanges and depositories respectively and by direct
intermediaries to SEBI with an undertaking, “Compliance of the SEBI circular for
Advisory for Financial Sector Organizations regarding Software as a Service
(SaaS) based solutions has been made.”
5. The advisory annexed with this circular shall be effective with immediate effect.
6. This circular is issued in exercise of powers conferred under Section 11 (1) of the
Securities and Exchange Board of India Act, 1992, to protect the interests of
investors in securities and to promote the development of, and to regulate the
securities market.
Yours faithfully
Anupma Chadha
Dy. General Manager
Phone:022-26449319
Email: anupmac@sebi.gov.in
Page 2 of 2