Market Infrastructure Institution: Exchanges and Depositories
A market infrastructure institution is an exchange, a depository or a clearing corporation. The market stops if one of them stops, so each is recognised rather than merely registered. Recognition carries obligations an ordinary registration does not: how the institution is run, who controls it, and whether it keeps working through disruption. The regulations of the Securities and Exchange Board of India (SEBI) set out what each must do, and the current text is read at sebi.gov.in.
A town shows the shape more clearly than a market does. Suppose a town has eleven tailors and one bridge. If a tailor closes on a Monday, the inconvenience is mild and the next tailor is a short walk away. Nobody writes a rule about it. If the bridge closes on a Monday, the schools empty, the vegetable trucks stop, and the hospital on the far bank might as well be in another district. The simple question about the two is which one anybody in the town actually chose. A resident chose the tailor. No resident has ever once chosen the bridge. The bridge was there before they moved in and it will be there after they leave, and the only decision anybody ever made about it was to drive across it.
The town does not regulate the bridge more heavily than the tailor because the bridge is bigger, but because there is no second bridge. One sentence carries everything that follows. Nothing else here is difficult once it is in hand. When a rule about who may sit on a certain board, or who may hold shares in a certain company, or how quickly a certain service must come back after a failure, looks excessive at first sight, the useful question is never how large the thing is. The right question is whether the people affected can walk away from it.
The rules below are Indian throughout, and they run from which bodies count as market infrastructure institutions to where the current requirement is found.
One holding runs through this guide. Anasuya Kolhapure, an invented investor, holds securities through Bhadra Securities Private Limited, her broker and also her depository participant. She once held 3 physical certificates covering 1,200 shares, and the 3 certificates became one electronic holding of 1,200. She later sold 400 of those, leaving 800. Bhadra Securities Private Limited carries 11,400 client accounts as a depository participant, and Anasuya Kolhapure is one of them.
What is a market infrastructure institution, and which bodies are one?
A market infrastructure institutionAn exchange, depository or clearing corporation recognised because the market depends on it. is one of three things: a stock exchange, a depository, or a clearing corporation. The list has three entries and no fourth. The label is not a compliment paid to a large firm, and no company can adopt it for itself in its own marketing. Market infrastructure institution is a legal category, and an entity is either inside it or outside it.
Notice what is not on the list. The exclusions teach faster than the inclusions. A broker is not one. A depository participant is not one. A merchant banker, a registrar, a custodian, an investment adviser, a portfolio manager, a mutual fund and an insurance company are all regulated, some of them heavily, and not one of them is a market infrastructure institution. Bhadra Securities Private Limited, with its 11,400 client accounts, is not one either. The firm is a participant, standing at the counter of the infrastructure without being the infrastructure, and holding that distinction clearly is worth more on this subject than memorising anything else.
Take the three in the order a holding meets them. An exchange is the venue where a transaction in a security happens. A clearing corporationThe institution standing between the two sides of a completed transaction. is the institution standing between the two sides of a completed transaction. A depository is where the electronic record of a holding actually lives. Anasuya Kolhapure therefore has 800 in a record rather than 800 in a drawer. How each of those does its work is set out under dematerialisation, under pay-in and pay-out, and under settlement finality. Only two things matter here: where each one sits, and what its position obliges it to carry.
The most useful fact about all three is not what they do but how an ordinary investor comes to be attached to them. She does not choose any of them and mostly does not know their names. Anasuya Kolhapure chose Bhadra Securities Private Limited. She compared it against two others, she disliked one of them, she signed a form. She has never compared depositories, never assessed a clearing corporation, and could not say which exchange her security is admitted on without going and looking. Three relationships she never entered into, all of them load-bearing.
Which set below is the complete list of market infrastructure institutions?
What makes these institutions different from every other regulated entity?
Here is the trap, and almost everybody walks into it once. The obvious answer is scale. Exchanges, depositories and clearing corporations are enormous, thousands of firms connect to them, and enormous things get watched more closely. The scale answer sounds right and is wrong, and the reason it is wrong is worth twenty minutes of anybody's attention.
The real test is substitutabilityWhether a user can move to an alternative if one fails.: whether a user can move to an alternative. Run it on a broker. A very large broker with lakhs of clients fails, and every one of those clients is inconvenienced, some of them badly, and then they open accounts elsewhere and the market carries on. Painful, sometimes ruinous for individuals, and contained. Now run it on a depository. Its users do not open accounts elsewhere. There is nothing they can reach on their own initiative to move the record to, and the record is the holding rather than a description of it.
The difference is therefore not one of degree. A large broker and a small broker are the same kind of thing in different sizes, and the rules that apply to both differ mainly in how much capital and how much supervision each carries. An exchange and a large broker are different kinds of thing altogether. One of them has clients, who can leave. The other has a market, and a market cannot leave.
Every unusual rule in this area answers what happens to people who cannot leave, and none of it looks arbitrary once that is seen. The governance requirements, the restrictions on who may hold shares, the obligation to keep working and the resilience requirements are all doing the same job. Each one stands in for a choice that the affected people do not have. A client who can leave is their own regulator, in a small way. A client who cannot leave has to be given one.
What actually separates a market infrastructure institution from a very large broker?
The test carries into subjects far beyond these three institutions once it is in hand, and that reach is the real reason to learn it as a test rather than as a fact. Any rule can be tested by asking who it protects and whether those people could take their business elsewhere. If they could, the rule will be about disclosure, conduct and fair dealing, aimed at making the choice they already have a better informed one. If they could not, there is no choice to improve and something has to take its place. The rule will then be about how the institution is run and who stands behind it.
How does recognition differ from registration here?
Recognition and registration are two different permissions, and the difference is not one of grandeur. RecognitionThe status the law requires such an institution to hold before it may operate. is the status the law requires a market infrastructure institution to hold before it may operate as one, and it is granted, held and withdrawn by the regulator. Registration is the permission a firm holds to carry on an activity. Both are decisions of the same regulator and they answer different questions.
Take the difference through what each one implies when it goes. Bhadra Securities Private Limited surrenders its registration, or has it withdrawn. Its 11,400 client accounts have to be moved, there is disruption and expense and a great deal of paperwork, and after a period the clients are somewhere else and the market is exactly as it was. Now do the same for a depository. The record of every holding sitting with a depository is not a book of business that another firm picks up on Tuesday. There is no equivalent sentence to write. Recognition, unlike registration, is therefore not really a permission to do something. Recognition is closer to a statement that the institution may exist as what it is.
There is a second difference and it is the practical one. Registration comes with conditions about the activity: what the firm may do, how it must conduct itself, what it must keep. Recognition comes with all of that and then keeps going, into how the institution is governed, who stands behind it, and whether it can be relied upon to still be working tomorrow. A registration asks what a firm does. Recognition asks what a firm is.
India, and where the recognition rules actually sit
In India, recognition on the exchange and clearing side sits in the SEBI regulations made for stock exchanges and clearing corporations, and recognition on the depository side sits in the SEBI regulations made for depositories and participants. Both are issued by the Securities and Exchange Board of India and both are read at sebi.gov.in. Net worth figures, shareholding ceilings, availability standards and periods are read there rather than recalled. Numbers of that kind move, and a number carried from memory would be wrong on exactly the day somebody relied on it. The current text is open at sebi.gov.in, and the document title and the date read are worth noting together.
Is recognition simply a grander word for registration?
Why are the governance requirements heavier here than anywhere else?
A governance requirementA rule about how an institution is run, rather than about what it does. is a rule about how an institution is run rather than about what it does. Most regulation of most firms is about the activity: do this properly, disclose that, keep the other. Governance rules step behind the activity and ask who is making the decisions, who checks them, and who they answer to.
For an ordinary registered firm, that question is largely private. A broking company has shareholders, the shareholders appoint a board, the board runs the firm, and if they run it badly the shareholders lose money and the clients go elsewhere. The people harmed by a poor board have an exit, so the regulator cares about conduct and about capital and much less about the composition of the board.
For a market infrastructure institution the people who bear the consequences of a bad decision are not the shareholders and cannot leave, so the composition of the board stops being a shareholders' question and becomes a public one. Think about who is in the room when a depository decides something. Not Anasuya Kolhapure. Not any of the 11,400 client accounts at Bhadra Securities Private Limited. Not the millions of people whose holdings exist as records on those systems. Not one of them has a vote, a representative or, in most cases, any idea the meeting is happening. Something has to sit in that empty chair, and the governance rules are what sits in it.
The rules therefore go further than they do elsewhere: into who may be appointed, into what proportion of a board must be independent of the business, into how key officers are approved, into what the regulator must be told before certain appointments happen, and into the separation between the people who run the institution and the people who profit from it. Whether any of those is currently framed that way, and in what terms, is a matter for the regulations at sebi.gov.in.
Why do the rules reach into how the board of one of these institutions is composed?
Why do the rules reach into who holds these institutions and who controls them?
Readers find this part strangest, so it is worth going slowly. In an ordinary company, who holds the shares is nobody's business but the shareholders'. Somebody buys a stake, somebody sells one, control changes hands, and the regulator is interested only where a specific law makes it interested. Here the position is reversed, and the reason is a single sentence: whoever controls a market infrastructure institution controls the terms on which everybody else reaches the market.
Give it a shape from ordinary life again. Return to the town with one bridge. A bridge run by somebody whose only interest is that the bridge works is one thing. A bridge bought by the largest haulage company in the district is quite another. The haulage company would then be setting the toll for its own competitors, deciding whose trucks queue and whose do not, and seeing every rival's traffic pass under its own office window. Nothing about that is illegal in the abstract. The arrangement simply leaves the party running the shared thing with a private interest in how the shared thing is used.
Now put the market version beside it. A market infrastructure institution sees the traffic of every participant that connects to it. The institution sets the terms on which they connect. The institution decides what is admitted and what is not. A participant that came to hold a controlling position in the institution its competitors have to use would be sitting in a place no amount of good behaviour makes comfortable. The restrictions on who may hold and control these institutions exist to prevent one participant sitting in the position that decides how every other participant reaches the market, and that problem is not solved by trusting anybody.
There is a second reason and it is quieter. An institution the whole market depends on should not be pushed into decisions by whoever happens to hold the most of it. Diffusing the holding, and restricting who may accumulate it, is one way of making sure the institution answers to its function rather than to a single interest. The actual restrictions, in numbers, are once again a matter for the regulations at sebi.gov.in.
What does the continuity obligation ask of an institution?
ContinuityThe obligation to keep operating, including through disruption. is the obligation to keep operating, including through disruption, and it is the requirement that most clearly separates infrastructure from a participant. Almost every regulated firm carries a duty to be careful, to hold capital, to have arrangements in place. Very few carry a duty to still be working.
Watch how differently the same event lands on either side of that line. Bhadra Securities Private Limited loses its systems for a morning. The outage is bad, its 11,400 clients are angry, some of them lose the chance to do something they wanted to do, and there are consequences the regulator may take an interest in. The failure is a firm-level problem with firm-level victims. Now let a depository lose its systems for the same morning. Nobody can establish what anybody holds. Nothing that depends on knowing what anybody holds can proceed. A depository barely has clients in the ordinary sense, so the problem is not the depository's clients. The problem is everyone.
The difference has a name. A failure is systemicAffecting the market as a whole rather than one firm and its clients. when it affects the market as a whole rather than one firm and the people who dealt with it. And once a failure is capable of being systemic, the obligation stops being about care and becomes about outcome. Careful is not enough. The service has to be there.
In practice the continuity obligation shows up as requirements about recovery arrangements, alternate sites, tested plans, and the ability to bring a service back rather than merely to explain why it went. Every one of those carries figures in the actual rulebook. The reasoning holds steady, and the reasoning is what survives the next revision of the numbers.
A broker and a depository each lose their systems for one morning. Why is only one of those a market-wide problem?
What is Cyber Resilience, and how is it different from keeping attackers out?
Cyber resilienceThe ability to keep operating through an attack, as distinct from preventing one. is the ability to keep operating through an attack rather than the ability to prevent one. Resilience and prevention get said in the same breath so often that the difference stops being audible, and the difference is the entire point of the requirement.
Here is the everyday version, and it is worth holding on to. A shop can spend everything it has on the strongest shutter on the street. Excellent shutter. Now the power goes out for six hours on a Saturday. Nobody ever asked what the shop would do if the lights went off, so the shutter did its job perfectly and the shop still lost the day. Security was the shutter. Resilience is the question nobody asked.
Security asks whether somebody can get in. Security is tested by trying to get in, and a good result is that nobody did. Resilience asks whether the institution keeps working when somebody does, or when a system simply fails on its own. Resilience is tested by assuming the way in worked, and a good result is that the service continued anyway. An institution can be genuinely strong on one and genuinely weak on the other, and the reason both appear in the same framework is that neither one says anything about the other.
Of the two, resilience is the harder sell inside an organisation. Security spending has a story to tell: things were stopped. The visible result of good resilience is a completely ordinary day, so resilience spending has no story at all when it works. Sumana Rege, the head of technology at Bhadra Securities Private Limited, runs an assessment programme precisely because a finding on paper is the only evidence that exists before something happens. The assessment is not a formality. The assessment is the mechanism by which a weakness gets found by somebody who is looking rather than by somebody who is exploiting it.
The reason cyber resilience attaches to this category so tightly follows from everything above. A participant that stops has customers who are inconvenienced. An institution that stops has a market that stops, and the people affected have no alternative to move to during the outage, no relationship through which to complain, and often no knowledge that the institution exists. The obligation is therefore framed as continuing to operate rather than as trying hard not to be attacked.
India, and where the cyber resilience obligation sits
In India the requirement is set out in the cyber security and cyber resilience framework issued by the Securities and Exchange Board of India, together with the circulars that have amended it since, and it is read at sebi.gov.in. The framework applies to market infrastructure institutions and, in its own terms, to other regulated entities as well. A depository participant such as Bhadra Securities Private Limited is therefore inside the conversation without being infrastructure itself. The assessment intervals, the classification of incidents, the reporting windows and the availability figures all sit in the framework itself. The framework has been amended more than once, and a description of an older version is not a description of the one in force. The current version is the one to open, with the document title and the date read noted.
An institution has never been breached, and one failed system stopped it for a full day. The institution is strong on which of the two?
What must be reported when something goes wrong, and to whom?
Reporting is the part of this subject that people assume is the boring part, and it is where the whole design becomes visible. The obligation runs to the regulator, and it runs to the regulator whether or not anybody outside the institution noticed anything. The last clause is the interesting one. A firm reporting only what its customers complained about is reporting the effects of its problems. An institution reporting what it found is reporting its problems.
The framework named above sets what has to be reported, in what form, and inside what period. The shape of the response is worth carrying instead, and the shape does not change when the periods do.
The sequence runs: detect, contain, report, restore, review. Detect is finding it, and a well run institution finds most things by looking rather than by somebody noticing an effect. Contain is stopping it spreading, and containing comes before understanding it. Understanding takes time and spreading does not. Report is telling the regulator. Restore is bringing the service back, and for an institution this is not a courtesy, it is the obligation itself. Review is writing down what happened so the next version of the plan is better than this one.
The reason that sequence is written down in advance is that the day it is needed is the worst possible day on which to be designing it. On the day, three things are true at once: nobody has slept, everybody has an opinion, and the person who understands the affected system best is also the person being asked to explain it to somebody senior every eleven minutes. A plan agreed in calm conditions is the only kind that gets followed in those conditions. Yashodhan Pai, the compliance officer at Bhadra Securities Private Limited, keeps the reporting steps written and rehearsed for exactly that reason, and Bhadra Securities Private Limited is only a participant. The institutions above it carry the same logic with more weight on it.
Why is the response sequence to a disruption written down before anything happens?
What are these institutions not allowed to do?
Some of the sharpest rules in this area are prohibitions rather than requirements, and they are easier to remember than anything else here because each one names a conflict somebody could otherwise walk into.
The first group keeps the institution out of the trade its own users carry on. An institution that decides who may connect, and on what terms, should not be competing with them. The terms of connection would then be a commercial weapon rather than a neutral condition. The second group keeps the institution's own commercial appetite away from its regulatory function. Where an institution performs a function that looks like supervision of its members, that function is expected to sit apart from the commercial side that would rather keep those members happy. The third group concerns information. An institution sees things about every participant that no participant sees about another, and the rules on what it may do with that are not a courtesy.
Every prohibition in this area answers the same question as everything above it: how to handle a party whose position is not one the affected people agreed to. If they could leave, a conflict would be handled by disclosure: the interest is stated and the affected people decide. The affected people cannot leave. So the conflicts are not disclosed, they are refused.
Anasuya Kolhapure is unhappy with all three institutions on the path her holding travels. How many of the three can she change?
How many of these institutions can one investor actually change?
Count it out properly, because the count is the argument. Anasuya Kolhapure has four relationships on the path her holding travels, and she entered into exactly one of them.
| On the path | Did she choose it? | Can she change it? | What changing it would take |
|---|---|---|---|
| Bhadra Securities Private Limited, her broker and her depository participant | Yes, after comparing three of them | Yes | A fortnight of paperwork and some irritation |
| The exchange where the security is admitted | No | No | Nothing she can do, for a security admitted on one venue |
| The clearing corporation | No | No | She has no relationship with it and never will |
| The depository holding the electronic record of her 800 | No | No | Only by giving up the holding itself |
| Four relationships in total | One chosen | One changeable | Three she cannot leave |
Look at the last row for a moment. One out of four. And the one she chose is the one whose failure would hurt her most visibly and matter to the market least. The three she never chose are the three whose failure would barely touch her personally on the day and would stop everybody.
Scaling the count without changing anything else makes the point. Bhadra Securities Private Limited carries 11,400 client accounts. Every one of those 11,400 has the same four relationships and the same one out of four. Not one of the 11,400 assessed a depository. Not one of them has an opinion about a clearing corporation. Multiplied across every participant in the market, that is the population these rules are written for: people who did not choose, cannot assess, cannot avoid and, in most cases, have never heard the names.
Recognition answers that one out of four, and it is why the governance rules, the restrictions on holding and control and the resilience requirements are coherent rather than bureaucratic. The rules are not proportionate to the institution's size. The rules are proportionate to the absence of an exit.
How does an analyst, an investor or a compliance officer use any of this?
Three readers use this material and none of them uses it the way a textbook presents it. Take them in the order they turn up.
A compliance officer at a participant uses it as a map of which obligations flow downhill. Yashodhan Pai at Bhadra Securities Private Limited is not running a market infrastructure institution, and a good deal of what an institution must do reaches him anyway. A participant connects to the institution, and the conditions of that connection carry obligations with them. The useful habit is to separate the two sources of a requirement: this one comes from what Bhadra Securities Private Limited is registered to do, and that one comes from the fact that it connects to something recognised. When somebody asks why a particular control exists, an answer that names the source is worth ten answers that name the control.
An analyst or a lender looking at a firm in this market uses it as a dependency map. Every regulated participant has a set of connections it cannot replace, and a question worth asking of any such firm is what happens to it when something it does not control stops. The question is not a prediction. The question is structural, and a firm that has never asked it of itself has revealed something about how it thinks.
A household investor uses it for one thing only, and it is the most valuable thing in this guide for them: knowing which door to knock on. If the problem is the account, the statement, a charge, or something that was not done when it was asked for, the party is the participant. For Anasuya Kolhapure the participant is Bhadra Securities Private Limited. If the problem is the record of the holding itself, that reaches further back. A letter sent to the wrong party is weeks lost at the moment weeks matter most, so knowing which of the four relationships a problem actually belongs to saves a household more time than any amount of general knowledge about how markets work.
Where does a reader look up what any of these institutions must do?
At the regulator, and nowhere else, and the distinction matters more here than on most subjects. An institution's own site sets out what it offers, how to connect to it, what its services are called and how its charges work. All of that is operational fact and genuinely useful. None of it is the source of an obligation. The obligation lives in the regulations and circulars made by the Securities and Exchange Board of India, read at sebi.gov.in.
The route has four steps and none of them needs anybody's cooperation. First comes naming which of the three kinds of institution is actually in question. The regulations are made separately for the exchange and clearing side and for the depository side. Second, finding the regulations made for that kind, remembering that a framework or a circular can sit alongside the regulations and change what they mean. Third, reading them at the regulator rather than in any summary. Fourth, writing down the document title and the date read, and keeping both with whatever followed.
A requirement read once and quoted afterwards is a requirement nobody has actually checked, so the date a requirement was read is part of the answer. Net worth requirements, shareholding ceilings, availability standards, assessment intervals and reporting windows are each a number that has changed at least once and will change again. Each one is read at its source on the day it matters rather than carried from memory.
A reader needs to know what a depository must do. Where does that search end?
The failure: reading these institutions as very large versions of ordinary firms
The reading is entirely understandable and almost everybody arrives with it. Exchanges, depositories and clearing corporations are companies. Each one has a board, revenue, staff, offices and an annual report. Each one is regulated, as the firms around them are regulated. So the mind does the natural thing and files them as the same kind of object at a larger size, and concludes that the extra rules are what large things attract.
The wrong reading is that the difference is scale, when the difference is that nobody can leave. The misreading matters because it changes what the rules appear to be for. Rules aimed at an ordinary firm mostly protect that firm's own clients, and those clients hold a form of power the rules assume: they can go elsewhere. Rules aimed at infrastructure protect people who cannot go elsewhere and who mostly do not know the institution exists. The two are not the same job, and a rule written for the second job will always look excessive when it is measured against the first.
The cost is specific and it lands on the reader rather than on the market. Somebody who files these rules under bureaucracy cannot say why they exist, and therefore cannot tell a well aimed rule from a pointless one. Telling those two apart is precisely the judgement anybody working in this area is eventually paid to make. A model that predicts nothing also leaves them surprised every time the regulation goes somewhere they did not expect, into a board composition or a shareholding or a recovery arrangement. Substitutability predicts all of it. Prediction is the whole reason to carry substitutability instead.
Net worth requirements, shareholding and control limits, availability standards, assessment intervals, reporting windows, fees and effective dates all sit in the instruments named below and are read there on the day they matter. How trading, clearing and settlement actually work as processes, including how a transaction is matched and how obligations between two sides are worked out, is set out under pay-in and pay-out and under settlement finality. Any institution's current requirements of the firms that connect to it are a matter for that institution and its own conditions. How securities are held and how a holding moves is set out under dematerialisation and under beneficial owner.
References
| Source | Document | Where |
|---|---|---|
| Securities and Exchange Board of India | The regulations made for stock exchanges and clearing corporations: recognition, the conditions attached to it and the governance obligations that follow from it | sebi.gov.in |
| Securities and Exchange Board of India | The regulations made for depositories and for depository participants: recognition on the depository side, and the separate regulation of the participant and the institution | sebi.gov.in |
| Securities and Exchange Board of India | The cyber security and cyber resilience framework issued to market infrastructure institutions and to regulated entities, with the circulars amending it: the assessment obligation and the incident reporting obligation | sebi.gov.in |
| Ministry of Corporate Affairs | The Companies Act and the rules made under it: these institutions are companies as well, so the company law obligations on a board sit alongside everything above | mca.gov.in |
| Securities Appellate Tribunal | The appeal route for an order made against one of these institutions, or against a firm connected to one, set out under the Securities Appellate Tribunal | sat.gov.in |
| Reserve Bank of India | Where money moves through the payment system, a second regulator's requirements apply and are read at that source | rbi.org.in |
| The recognised exchanges and depositories, on their own sites | Operational fact only, such as which services exist and how a firm connects, rather than the source of any obligation | nseindia.com, bseindia.com, nsdl.co.in, cdslindia.com |
| International Organization of Securities Commissions | The international principles for financial market infrastructures, where the cross border framing of this category sits | iosco.org |
Anasuya Kolhapure, Bhadra Securities Private Limited, Yashodhan Pai and Sumana Rege are invented.
Educational material. Not advice on any investment, tax, budget or market position.
