Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Indian Markets, Regulation & Professional Standards
1Registration, Professional Standards and the Rulebook
Portfolio ManagerResearch AnalystActs, Rules, Regulations, Circulars…Financial Regulators in IndiaCompliance FunctionInvestment AdviceResearch Analyst vs Adviser…NISM CertificationRecord RetentionLicence, Recognition and What…Risk ProfilingHow to Map a…
2Intermediaries
UnderwriterDebenture TrusteeInvestment ManagerForeign Portfolio Investor vs…Merchant BankerRegistrar to an Issue…Stock BrokerCredit Rating Agency
3Market Infrastructure, Settlement and Technology
Market Infrastructure InstitutionAlgorithmic Trading in IndiaAlgorithmic Trading vs API TradingDematerialisationPay-In and Pay-OutBeneficial OwnerCybersecurity for Regulated EntitiesSettlement FinalityDepository ParticipantsForeign Portfolio InvestorInvestor Protection FundPrepaid Payment InstrumentHow Payment-System Regulation Works…Securities Appellate TribunalSelf-Regulatory Organisation
4Issuance
Offer DocumentHow to Read a…Public Issue TypesListingLock-InAnchor InvestorBook Building and the Price BandQualified Institutions PlacementRed Herring Prospectus
5Listed Markets
Compliance OfficerDisclosure ObligationsHow to Map a…Listing ObligationsListed Entity vs Intermediary
6Market Conduct
Market ConductSupervisory ActionsEnforcement OrdersAdjudication and PenaltyInsider TradingAnti-Money LaunderingHow to Identify a…How Financial-Promotion Rules Differ…
7Pensions and Insurance
Insurance IntermediariesHow Insurance and Pension…The NPS ArchitectureNPS vs APYPension AdviserPension Fund Under the NPS

Market Infrastructure Institution: Exchanges and Depositories

A market infrastructure institution is an exchange, a depository or a clearing corporation. The market stops if one of them stops, so each is recognised rather than merely registered. Recognition carries obligations an ordinary registration does not: how the institution is run, who controls it, and whether it keeps working through disruption. The regulations of the Securities and Exchange Board of India (SEBI) set out what each must do, and the current text is read at sebi.gov.in.

A town shows the shape more clearly than a market does. Suppose a town has eleven tailors and one bridge. If a tailor closes on a Monday, the inconvenience is mild and the next tailor is a short walk away. Nobody writes a rule about it. If the bridge closes on a Monday, the schools empty, the vegetable trucks stop, and the hospital on the far bank might as well be in another district. The simple question about the two is which one anybody in the town actually chose. A resident chose the tailor. No resident has ever once chosen the bridge. The bridge was there before they moved in and it will be there after they leave, and the only decision anybody ever made about it was to drive across it.

The town does not regulate the bridge more heavily than the tailor because the bridge is bigger, but because there is no second bridge. One sentence carries everything that follows. Nothing else here is difficult once it is in hand. When a rule about who may sit on a certain board, or who may hold shares in a certain company, or how quickly a certain service must come back after a failure, looks excessive at first sight, the useful question is never how large the thing is. The right question is whether the people affected can walk away from it.

The rules below are Indian throughout, and they run from which bodies count as market infrastructure institutions to where the current requirement is found.

One holding runs through this guide. Anasuya Kolhapure, an invented investor, holds securities through Bhadra Securities Private Limited, her broker and also her depository participant. She once held 3 physical certificates covering 1,200 shares, and the 3 certificates became one electronic holding of 1,200. She later sold 400 of those, leaving 800. Bhadra Securities Private Limited carries 11,400 client accounts as a depository participant, and Anasuya Kolhapure is one of them.

What is a market infrastructure institution, and which bodies are one?

A market infrastructure institutionAn exchange, depository or clearing corporation recognised because the market depends on it. is one of three things: a stock exchange, a depository, or a clearing corporation. The list has three entries and no fourth. The label is not a compliment paid to a large firm, and no company can adopt it for itself in its own marketing. Market infrastructure institution is a legal category, and an entity is either inside it or outside it.

Notice what is not on the list. The exclusions teach faster than the inclusions. A broker is not one. A depository participant is not one. A merchant banker, a registrar, a custodian, an investment adviser, a portfolio manager, a mutual fund and an insurance company are all regulated, some of them heavily, and not one of them is a market infrastructure institution. Bhadra Securities Private Limited, with its 11,400 client accounts, is not one either. The firm is a participant, standing at the counter of the infrastructure without being the infrastructure, and holding that distinction clearly is worth more on this subject than memorising anything else.

Take the three in the order a holding meets them. An exchange is the venue where a transaction in a security happens. A clearing corporationThe institution standing between the two sides of a completed transaction. is the institution standing between the two sides of a completed transaction. A depository is where the electronic record of a holding actually lives. Anasuya Kolhapure therefore has 800 in a record rather than 800 in a drawer. How each of those does its work is set out under dematerialisation, under pay-in and pay-out, and under settlement finality. Only two things matter here: where each one sits, and what its position obliges it to carry.

The most useful fact about all three is not what they do but how an ordinary investor comes to be attached to them. She does not choose any of them and mostly does not know their names. Anasuya Kolhapure chose Bhadra Securities Private Limited. She compared it against two others, she disliked one of them, she signed a form. She has never compared depositories, never assessed a clearing corporation, and could not say which exchange her security is admitted on without going and looking. Three relationships she never entered into, all of them load-bearing.

Four stops on the path, and only one of them she chose ANASUYA KOLHAPURE the investor, and holder of the 800 BHADRA SECURITIES her broker and her participant THE EXCHANGE where the security is admitted THE CLEARING CORPORATION she has no dealing with it at all THE DEPOSITORY where the record of the 800 lives SHE CHOSE THIS ONE SHE CHOSE NONE OF THESE, AND CAN CHANGE NONE OF THEM The one she chose is the one she can leave. Moving broker is a fortnight of paperwork and a mild irritation. The three she did not choose are the three she cannot leave, and two of them she will never deal with directly. All 11,400 client accounts at Bhadra Securities Private Limited sit behind the same three, on the same terms. That count is the whole argument of this guide. The heavier rules on the last three are not answering their size. They are answering the fact that nobody standing behind them can walk away.
An exchange, a depository and a clearing corporation each sit on the path a holding travels, and the only party on that path an ordinary investor actually selected is the broker she is free to leave.
Try it out

Which set below is the complete list of market infrastructure institutions?

What makes these institutions different from every other regulated entity?

Here is the trap, and almost everybody walks into it once. The obvious answer is scale. Exchanges, depositories and clearing corporations are enormous, thousands of firms connect to them, and enormous things get watched more closely. The scale answer sounds right and is wrong, and the reason it is wrong is worth twenty minutes of anybody's attention.

The real test is substitutabilityWhether a user can move to an alternative if one fails.: whether a user can move to an alternative. Run it on a broker. A very large broker with lakhs of clients fails, and every one of those clients is inconvenienced, some of them badly, and then they open accounts elsewhere and the market carries on. Painful, sometimes ruinous for individuals, and contained. Now run it on a depository. Its users do not open accounts elsewhere. There is nothing they can reach on their own initiative to move the record to, and the record is the holding rather than a description of it.

The difference is therefore not one of degree. A large broker and a small broker are the same kind of thing in different sizes, and the rules that apply to both differ mainly in how much capital and how much supervision each carries. An exchange and a large broker are different kinds of thing altogether. One of them has clients, who can leave. The other has a market, and a market cannot leave.

Every unusual rule in this area answers what happens to people who cannot leave, and none of it looks arbitrary once that is seen. The governance requirements, the restrictions on who may hold shares, the obligation to keep working and the resilience requirements are all doing the same job. Each one stands in for a choice that the affected people do not have. A client who can leave is their own regulator, in a small way. A client who cannot leave has to be given one.

Plot them by size and by whether anybody can walk away How large the institution is, left to right Can the people affected move elsewhere? YES, EASILY NO, NOT AT ALL the line the heavier rules follow and it is not a size line A small broker Bhadra Securities Private Limited 11,400 client accounts, all free to go A very large broker The exchange The depository The clearing corporation Nothing on this drawing separates the two groups by size. The three at the bottom are there because the people who depend on them have nowhere to go. That, and not scale, is the test the heavier rules are built on.
A very small broker and a very large one sit at almost the same height on this plot while the three institutions sit far below both, which shows the dividing line the heavier rules follow is whether anybody can walk away rather than how large a firm has grown.
Try it out

What actually separates a market infrastructure institution from a very large broker?

The test carries into subjects far beyond these three institutions once it is in hand, and that reach is the real reason to learn it as a test rather than as a fact. Any rule can be tested by asking who it protects and whether those people could take their business elsewhere. If they could, the rule will be about disclosure, conduct and fair dealing, aimed at making the choice they already have a better informed one. If they could not, there is no choice to improve and something has to take its place. The rule will then be about how the institution is run and who stands behind it.

One question that predicts how heavy the rule will be CAN THE PEOPLE THIS RULE PROTECTS MOVE ELSEWHERE? ask this before asking anything about size YES NO THEN THE RULE IS MOSTLY PROTECTING ITS OWN CLIENTS and a client who dislikes it can take the business somewhere else THEN THE RULE IS PROTECTING A MARKET, NOT A CLIENT LIST and it will look heavier, because nobody affected can walk away A broker sits on this branch. Bhadra Securities Private Limited. All three sit on this one. Exchange, depository, clearing. The test is a walk away test, and it runs in one sentence. Ask whether the people the rule protects could move elsewhere if they disliked what they saw. If the answer is no, the weight of the rule stops being a puzzle.
Asking whether the people a rule protects could move elsewhere sorts a broker onto one branch and an exchange, a depository and a clearing corporation onto the other, and it predicts the weight of a rule far better than any measure of size does.

How does recognition differ from registration here?

Recognition and registration are two different permissions, and the difference is not one of grandeur. RecognitionThe status the law requires such an institution to hold before it may operate. is the status the law requires a market infrastructure institution to hold before it may operate as one, and it is granted, held and withdrawn by the regulator. Registration is the permission a firm holds to carry on an activity. Both are decisions of the same regulator and they answer different questions.

Take the difference through what each one implies when it goes. Bhadra Securities Private Limited surrenders its registration, or has it withdrawn. Its 11,400 client accounts have to be moved, there is disruption and expense and a great deal of paperwork, and after a period the clients are somewhere else and the market is exactly as it was. Now do the same for a depository. The record of every holding sitting with a depository is not a book of business that another firm picks up on Tuesday. There is no equivalent sentence to write. Recognition, unlike registration, is therefore not really a permission to do something. Recognition is closer to a statement that the institution may exist as what it is.

There is a second difference and it is the practical one. Registration comes with conditions about the activity: what the firm may do, how it must conduct itself, what it must keep. Recognition comes with all of that and then keeps going, into how the institution is governed, who stands behind it, and whether it can be relied upon to still be working tomorrow. A registration asks what a firm does. Recognition asks what a firm is.

Two permissions that are not two words for the same thing THE QUESTION REGISTRATION RECOGNITION What does it permit? A firm may carry on the activity it is registered for. An institution may exist as that institution at all. Who is harmed if it fails? Mostly its own clients, who can take their business away. Everybody in the market, most of whom never dealt with it. How far do the rules reach? To conduct, to capital and to what has to be kept on record. To all of that, and then to the board, the holding, the control. What if it stops? Its clients move to another firm, and the market carries on. There is nowhere for its users to move, so nothing carries on. Registration answers what a firm may do. Recognition answers whether an institution may be there at all, which is a different question.
Registration permits an activity and can be given up without the market noticing, while recognition is the status that lets an institution exist as that institution, so the two are different permissions with different consequences when either is lost.

India, and where the recognition rules actually sit

In India, recognition on the exchange and clearing side sits in the SEBI regulations made for stock exchanges and clearing corporations, and recognition on the depository side sits in the SEBI regulations made for depositories and participants. Both are issued by the Securities and Exchange Board of India and both are read at sebi.gov.in. Net worth figures, shareholding ceilings, availability standards and periods are read there rather than recalled. Numbers of that kind move, and a number carried from memory would be wrong on exactly the day somebody relied on it. The current text is open at sebi.gov.in, and the document title and the date read are worth noting together.

Try it out

Is recognition simply a grander word for registration?

Why are the governance requirements heavier here than anywhere else?

A governance requirementA rule about how an institution is run, rather than about what it does. is a rule about how an institution is run rather than about what it does. Most regulation of most firms is about the activity: do this properly, disclose that, keep the other. Governance rules step behind the activity and ask who is making the decisions, who checks them, and who they answer to.

For an ordinary registered firm, that question is largely private. A broking company has shareholders, the shareholders appoint a board, the board runs the firm, and if they run it badly the shareholders lose money and the clients go elsewhere. The people harmed by a poor board have an exit, so the regulator cares about conduct and about capital and much less about the composition of the board.

For a market infrastructure institution the people who bear the consequences of a bad decision are not the shareholders and cannot leave, so the composition of the board stops being a shareholders' question and becomes a public one. Think about who is in the room when a depository decides something. Not Anasuya Kolhapure. Not any of the 11,400 client accounts at Bhadra Securities Private Limited. Not the millions of people whose holdings exist as records on those systems. Not one of them has a vote, a representative or, in most cases, any idea the meeting is happening. Something has to sit in that empty chair, and the governance rules are what sits in it.

The rules therefore go further than they do elsewhere: into who may be appointed, into what proportion of a board must be independent of the business, into how key officers are approved, into what the regulator must be told before certain appointments happen, and into the separation between the people who run the institution and the people who profit from it. Whether any of those is currently framed that way, and in what terms, is a matter for the regulations at sebi.gov.in.

How far down each set of rules actually reaches DEEPER 1. What the institution does for the people using it the activity itself, and what it may charge for 2. How it conducts itself and what it keeps on record conduct, capital, records, disclosure 3. How its board is composed and how it is run who may sit on it, who is independent, who is approved 4. Who holds it, and who controls it the shareholding, and the levers standing behind it how far an ordinary registration reaches: two levels how far recognition reaches: all four of them Levels three and four are the entire difference. An ordinary registration does not ask who sits on the board or who stands behind the shareholding.
An ordinary registration reaches an entity's conduct and its records, while recognition reaches two levels further into how the board is composed and who stands behind the shareholding, and that extra reach is the whole of the governance difference.
Try it out

Why do the rules reach into how the board of one of these institutions is composed?

Why do the rules reach into who holds these institutions and who controls them?

Readers find this part strangest, so it is worth going slowly. In an ordinary company, who holds the shares is nobody's business but the shareholders'. Somebody buys a stake, somebody sells one, control changes hands, and the regulator is interested only where a specific law makes it interested. Here the position is reversed, and the reason is a single sentence: whoever controls a market infrastructure institution controls the terms on which everybody else reaches the market.

Give it a shape from ordinary life again. Return to the town with one bridge. A bridge run by somebody whose only interest is that the bridge works is one thing. A bridge bought by the largest haulage company in the district is quite another. The haulage company would then be setting the toll for its own competitors, deciding whose trucks queue and whose do not, and seeing every rival's traffic pass under its own office window. Nothing about that is illegal in the abstract. The arrangement simply leaves the party running the shared thing with a private interest in how the shared thing is used.

Now put the market version beside it. A market infrastructure institution sees the traffic of every participant that connects to it. The institution sets the terms on which they connect. The institution decides what is admitted and what is not. A participant that came to hold a controlling position in the institution its competitors have to use would be sitting in a place no amount of good behaviour makes comfortable. The restrictions on who may hold and control these institutions exist to prevent one participant sitting in the position that decides how every other participant reaches the market, and that problem is not solved by trusting anybody.

There is a second reason and it is quieter. An institution the whole market depends on should not be pushed into decisions by whoever happens to hold the most of it. Diffusing the holding, and restricting who may accumulate it, is one way of making sure the institution answers to its function rather than to a single interest. The actual restrictions, in numbers, are once again a matter for the regulations at sebi.gov.in.

Breaking Into Quants Bootcamp — Fin Maverick

What does the continuity obligation ask of an institution?

ContinuityThe obligation to keep operating, including through disruption. is the obligation to keep operating, including through disruption, and it is the requirement that most clearly separates infrastructure from a participant. Almost every regulated firm carries a duty to be careful, to hold capital, to have arrangements in place. Very few carry a duty to still be working.

Watch how differently the same event lands on either side of that line. Bhadra Securities Private Limited loses its systems for a morning. The outage is bad, its 11,400 clients are angry, some of them lose the chance to do something they wanted to do, and there are consequences the regulator may take an interest in. The failure is a firm-level problem with firm-level victims. Now let a depository lose its systems for the same morning. Nobody can establish what anybody holds. Nothing that depends on knowing what anybody holds can proceed. A depository barely has clients in the ordinary sense, so the problem is not the depository's clients. The problem is everyone.

The difference has a name. A failure is systemicAffecting the market as a whole rather than one firm and its clients. when it affects the market as a whole rather than one firm and the people who dealt with it. And once a failure is capable of being systemic, the obligation stops being about care and becomes about outcome. Careful is not enough. The service has to be there.

In practice the continuity obligation shows up as requirements about recovery arrangements, alternate sites, tested plans, and the ability to bring a service back rather than merely to explain why it went. Every one of those carries figures in the actual rulebook. The reasoning holds steady, and the reasoning is what survives the next revision of the numbers.

Try it out

A broker and a depository each lose their systems for one morning. Why is only one of those a market-wide problem?

Financial Literacy Bootcamp — Fin Maverick

What is Cyber Resilience, and how is it different from keeping attackers out?

Cyber resilienceThe ability to keep operating through an attack, as distinct from preventing one. is the ability to keep operating through an attack rather than the ability to prevent one. Resilience and prevention get said in the same breath so often that the difference stops being audible, and the difference is the entire point of the requirement.

Here is the everyday version, and it is worth holding on to. A shop can spend everything it has on the strongest shutter on the street. Excellent shutter. Now the power goes out for six hours on a Saturday. Nobody ever asked what the shop would do if the lights went off, so the shutter did its job perfectly and the shop still lost the day. Security was the shutter. Resilience is the question nobody asked.

Security asks whether somebody can get in. Security is tested by trying to get in, and a good result is that nobody did. Resilience asks whether the institution keeps working when somebody does, or when a system simply fails on its own. Resilience is tested by assuming the way in worked, and a good result is that the service continued anyway. An institution can be genuinely strong on one and genuinely weak on the other, and the reason both appear in the same framework is that neither one says anything about the other.

Of the two, resilience is the harder sell inside an organisation. Security spending has a story to tell: things were stopped. The visible result of good resilience is a completely ordinary day, so resilience spending has no story at all when it works. Sumana Rege, the head of technology at Bhadra Securities Private Limited, runs an assessment programme precisely because a finding on paper is the only evidence that exists before something happens. The assessment is not a formality. The assessment is the mechanism by which a weakness gets found by somebody who is looking rather than by somebody who is exploiting it.

The reason cyber resilience attaches to this category so tightly follows from everything above. A participant that stops has customers who are inconvenienced. An institution that stops has a market that stops, and the people affected have no alternative to move to during the outage, no relationship through which to complain, and often no knowledge that the institution exists. The obligation is therefore framed as continuing to operate rather than as trying hard not to be attacked.

Two questions that sound alike and test opposite things THE TEST KEEPING ATTACKERS OUT CARRYING ON REGARDLESS The question it asks Can somebody get in? Can the institution keep working when somebody does? What a good result is Nobody got in. The service kept running. How it is found out By testing the way in and looking for weaknesses. By assuming the way in worked, then rehearsing. What it cannot tell Whether the institution would still be working tomorrow morning. Whether anybody got in at all, or ever will. An institution can be strong on one and weak on the other. Never breached, and stopped for a day by one failure, scores well on the left and badly on the right.
Keeping attackers out and continuing to work when one gets in are tested in opposite ways, so an institution that has never been breached and still stops for a day is strong on the first and weak on the second.

India, and where the cyber resilience obligation sits

In India the requirement is set out in the cyber security and cyber resilience framework issued by the Securities and Exchange Board of India, together with the circulars that have amended it since, and it is read at sebi.gov.in. The framework applies to market infrastructure institutions and, in its own terms, to other regulated entities as well. A depository participant such as Bhadra Securities Private Limited is therefore inside the conversation without being infrastructure itself. The assessment intervals, the classification of incidents, the reporting windows and the availability figures all sit in the framework itself. The framework has been amended more than once, and a description of an older version is not a description of the one in force. The current version is the one to open, with the document title and the date read noted.

Try it out

An institution has never been breached, and one failed system stopped it for a full day. The institution is strong on which of the two?

What must be reported when something goes wrong, and to whom?

Reporting is the part of this subject that people assume is the boring part, and it is where the whole design becomes visible. The obligation runs to the regulator, and it runs to the regulator whether or not anybody outside the institution noticed anything. The last clause is the interesting one. A firm reporting only what its customers complained about is reporting the effects of its problems. An institution reporting what it found is reporting its problems.

The framework named above sets what has to be reported, in what form, and inside what period. The shape of the response is worth carrying instead, and the shape does not change when the periods do.

The sequence runs: detect, contain, report, restore, review. Detect is finding it, and a well run institution finds most things by looking rather than by somebody noticing an effect. Contain is stopping it spreading, and containing comes before understanding it. Understanding takes time and spreading does not. Report is telling the regulator. Restore is bringing the service back, and for an institution this is not a courtesy, it is the obligation itself. Review is writing down what happened so the next version of the plan is better than this one.

The reason that sequence is written down in advance is that the day it is needed is the worst possible day on which to be designing it. On the day, three things are true at once: nobody has slept, everybody has an opinion, and the person who understands the affected system best is also the person being asked to explain it to somebody senior every eleven minutes. A plan agreed in calm conditions is the only kind that gets followed in those conditions. Yashodhan Pai, the compliance officer at Bhadra Securities Private Limited, keeps the reporting steps written and rehearsed for exactly that reason, and Bhadra Securities Private Limited is only a participant. The institutions above it carry the same logic with more weight on it.

The sequence exists before the day it is needed DETECT CONTAIN REPORT RESTORE REVIEW Widths on this drawing are not to any scale. 1. DETECT: something is found, and it is usually found by looking rather than by anybody noticing an effect. 2. CONTAIN: the thing is stopped from spreading, before anybody works out how it started. 3. REPORT: the institution tells the regulator. What must be sent, and how soon, is set in the framework. 4. RESTORE: the service comes back, and coming back is the duty that separates infrastructure from a participant. 5. REVIEW: what happened is written down, so the next version of the plan is better than this one. This drawing carries no clock. Every period in the real sequence is set in the framework and is read there. The plan is written in calm conditions for a reason. The day it is needed is the worst possible day to be designing it.
Detect, contain, report, restore and review is a sequence agreed in advance, and the reason it is written down in calm conditions is that nobody designs a workable response on the morning they need one.
Try it out

Why is the response sequence to a disruption written down before anything happens?

Debt Capital Markets Bootcamp — Fin Maverick

What are these institutions not allowed to do?

Some of the sharpest rules in this area are prohibitions rather than requirements, and they are easier to remember than anything else here because each one names a conflict somebody could otherwise walk into.

The first group keeps the institution out of the trade its own users carry on. An institution that decides who may connect, and on what terms, should not be competing with them. The terms of connection would then be a commercial weapon rather than a neutral condition. The second group keeps the institution's own commercial appetite away from its regulatory function. Where an institution performs a function that looks like supervision of its members, that function is expected to sit apart from the commercial side that would rather keep those members happy. The third group concerns information. An institution sees things about every participant that no participant sees about another, and the rules on what it may do with that are not a courtesy.

Every prohibition in this area answers the same question as everything above it: how to handle a party whose position is not one the affected people agreed to. If they could leave, a conflict would be handled by disclosure: the interest is stated and the affected people decide. The affected people cannot leave. So the conflicts are not disclosed, they are refused.

Try it out

Anasuya Kolhapure is unhappy with all three institutions on the path her holding travels. How many of the three can she change?

How many of these institutions can one investor actually change?

Count it out properly, because the count is the argument. Anasuya Kolhapure has four relationships on the path her holding travels, and she entered into exactly one of them.

On the pathDid she choose it?Can she change it?What changing it would take
Bhadra Securities Private Limited, her broker and her depository participantYes, after comparing three of themYesA fortnight of paperwork and some irritation
The exchange where the security is admittedNoNoNothing she can do, for a security admitted on one venue
The clearing corporationNoNoShe has no relationship with it and never will
The depository holding the electronic record of her 800NoNoOnly by giving up the holding itself
Four relationships in totalOne chosenOne changeableThree she cannot leave

Look at the last row for a moment. One out of four. And the one she chose is the one whose failure would hurt her most visibly and matter to the market least. The three she never chose are the three whose failure would barely touch her personally on the day and would stop everybody.

Scaling the count without changing anything else makes the point. Bhadra Securities Private Limited carries 11,400 client accounts. Every one of those 11,400 has the same four relationships and the same one out of four. Not one of the 11,400 assessed a depository. Not one of them has an opinion about a clearing corporation. Multiplied across every participant in the market, that is the population these rules are written for: people who did not choose, cannot assess, cannot avoid and, in most cases, have never heard the names.

Recognition answers that one out of four, and it is why the governance rules, the restrictions on holding and control and the resilience requirements are coherent rather than bureaucratic. The rules are not proportionate to the institution's size. The rules are proportionate to the absence of an exit.

How does an analyst, an investor or a compliance officer use any of this?

Three readers use this material and none of them uses it the way a textbook presents it. Take them in the order they turn up.

A compliance officer at a participant uses it as a map of which obligations flow downhill. Yashodhan Pai at Bhadra Securities Private Limited is not running a market infrastructure institution, and a good deal of what an institution must do reaches him anyway. A participant connects to the institution, and the conditions of that connection carry obligations with them. The useful habit is to separate the two sources of a requirement: this one comes from what Bhadra Securities Private Limited is registered to do, and that one comes from the fact that it connects to something recognised. When somebody asks why a particular control exists, an answer that names the source is worth ten answers that name the control.

An analyst or a lender looking at a firm in this market uses it as a dependency map. Every regulated participant has a set of connections it cannot replace, and a question worth asking of any such firm is what happens to it when something it does not control stops. The question is not a prediction. The question is structural, and a firm that has never asked it of itself has revealed something about how it thinks.

A household investor uses it for one thing only, and it is the most valuable thing in this guide for them: knowing which door to knock on. If the problem is the account, the statement, a charge, or something that was not done when it was asked for, the party is the participant. For Anasuya Kolhapure the participant is Bhadra Securities Private Limited. If the problem is the record of the holding itself, that reaches further back. A letter sent to the wrong party is weeks lost at the moment weeks matter most, so knowing which of the four relationships a problem actually belongs to saves a household more time than any amount of general knowledge about how markets work.

Credit Exposure and How It Is Reduced — free micro-course from Fin Maverick

Where does a reader look up what any of these institutions must do?

At the regulator, and nowhere else, and the distinction matters more here than on most subjects. An institution's own site sets out what it offers, how to connect to it, what its services are called and how its charges work. All of that is operational fact and genuinely useful. None of it is the source of an obligation. The obligation lives in the regulations and circulars made by the Securities and Exchange Board of India, read at sebi.gov.in.

The route has four steps and none of them needs anybody's cooperation. First comes naming which of the three kinds of institution is actually in question. The regulations are made separately for the exchange and clearing side and for the depository side. Second, finding the regulations made for that kind, remembering that a framework or a circular can sit alongside the regulations and change what they mean. Third, reading them at the regulator rather than in any summary. Fourth, writing down the document title and the date read, and keeping both with whatever followed.

A requirement read once and quoted afterwards is a requirement nobody has actually checked, so the date a requirement was read is part of the answer. Net worth requirements, shareholding ceilings, availability standards, assessment intervals and reporting windows are each a number that has changed at least once and will change again. Each one is read at its source on the day it matters rather than carried from memory.

Where to look, in four steps that need nobody's help 1 Name which of the three the institution is. 2 Find the regulations made for that kind of institution. 3 Read them at the regulator and not in a summary. 4 Write down the document title and the date read NOT THE ROUTE: THE INSTITUTION ITSELF it describes its services, not its obligations Every step here is public, and no step asks the institution to agree to anything. The requirements themselves are read in those documents rather than recalled, because a requirement carried from memory would be wrong on exactly the day somebody needed it. The date it was read is part of the answer. A rule read once and quoted afterwards is a rule nobody has actually checked.
Naming which of the three institutions is in question, finding the regulations made for that kind, reading them at the regulator and noting the date read is a route that needs nobody at the institution to cooperate.
Try it out

A reader needs to know what a depository must do. Where does that search end?

The failure: reading these institutions as very large versions of ordinary firms

The reading is entirely understandable and almost everybody arrives with it. Exchanges, depositories and clearing corporations are companies. Each one has a board, revenue, staff, offices and an annual report. Each one is regulated, as the firms around them are regulated. So the mind does the natural thing and files them as the same kind of object at a larger size, and concludes that the extra rules are what large things attract.

The wrong reading is that the difference is scale, when the difference is that nobody can leave. The misreading matters because it changes what the rules appear to be for. Rules aimed at an ordinary firm mostly protect that firm's own clients, and those clients hold a form of power the rules assume: they can go elsewhere. Rules aimed at infrastructure protect people who cannot go elsewhere and who mostly do not know the institution exists. The two are not the same job, and a rule written for the second job will always look excessive when it is measured against the first.

The margin note that costs the reader the whole point WHAT THE INSTITUTION MUST DO the composition of its board is a matter for the rules who may hold it, and how much, is a matter for the rules THE NOTE IN THE MARGIN why is this so heavy? they are just large companies. shorten it to: bureaucracy. WHAT THE NOTE MISSED The rules are not answering size. They are answering the fact that the people they protect cannot leave, and mostly do not know the institution exists at all. Then nothing looks arbitrary. The cost is not a wrong definition. It is a reader who cannot say why any of it is there, and who therefore cannot tell a heavy rule from a pointless one.
A reader who writes bureaucracy in the margin beside the board rules and the shareholding rules has not misdefined anything, and has lost the one idea that makes those two rules follow from each other.

The cost is specific and it lands on the reader rather than on the market. Somebody who files these rules under bureaucracy cannot say why they exist, and therefore cannot tell a well aimed rule from a pointless one. Telling those two apart is precisely the judgement anybody working in this area is eventually paid to make. A model that predicts nothing also leaves them surprised every time the regulation goes somewhere they did not expect, into a board composition or a shareholding or a recovery arrangement. Substitutability predicts all of it. Prediction is the whole reason to carry substitutability instead.

Net worth requirements, shareholding and control limits, availability standards, assessment intervals, reporting windows, fees and effective dates all sit in the instruments named below and are read there on the day they matter. How trading, clearing and settlement actually work as processes, including how a transaction is matched and how obligations between two sides are worked out, is set out under pay-in and pay-out and under settlement finality. Any institution's current requirements of the firms that connect to it are a matter for that institution and its own conditions. How securities are held and how a holding moves is set out under dematerialisation and under beneficial owner.

A requirement quoted later is a requirement unchecked. See where the market publishes it.

References

SourceDocumentWhere
Securities and Exchange Board of IndiaThe regulations made for stock exchanges and clearing corporations: recognition, the conditions attached to it and the governance obligations that follow from itsebi.gov.in
Securities and Exchange Board of IndiaThe regulations made for depositories and for depository participants: recognition on the depository side, and the separate regulation of the participant and the institutionsebi.gov.in
Securities and Exchange Board of IndiaThe cyber security and cyber resilience framework issued to market infrastructure institutions and to regulated entities, with the circulars amending it: the assessment obligation and the incident reporting obligationsebi.gov.in
Ministry of Corporate AffairsThe Companies Act and the rules made under it: these institutions are companies as well, so the company law obligations on a board sit alongside everything abovemca.gov.in
Securities Appellate TribunalThe appeal route for an order made against one of these institutions, or against a firm connected to one, set out under the Securities Appellate Tribunalsat.gov.in
Reserve Bank of IndiaWhere money moves through the payment system, a second regulator's requirements apply and are read at that sourcerbi.org.in
The recognised exchanges and depositories, on their own sitesOperational fact only, such as which services exist and how a firm connects, rather than the source of any obligationnseindia.com, bseindia.com, nsdl.co.in, cdslindia.com
International Organization of Securities CommissionsThe international principles for financial market infrastructures, where the cross border framing of this category sitsiosco.org

Anasuya Kolhapure, Bhadra Securities Private Limited, Yashodhan Pai and Sumana Rege are invented.
Educational material. Not advice on any investment, tax, budget or market position.

Covered in this topic

Subtopics

Cyber Resilience
Next →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.