IFSCA circular · 16 Nov 2022
1 | P a g e CIRCULAR IFSCA/CMD-DMIIT/DR/774/2022/01 November 16, 2022 To, All the Stock Exchanges, including Bullion Exchange, in the International Financial Services Centres (IFSC) All the Clearing Corporations in the International Financial Services Centres (IFSC) All the Depositories in the International Financial S…
1 | P a g e CIRCULAR IFSCA/CMD-DMIIT/DR/774/2022/01 November 16, 2022 To, All the Stock Exchanges, including Bullion Exchange, in the International Financial Services Centres (IFSC) All the Clearing Corporations in the International Financial Services Centres (IFSC) All the Depositories in the International Financial Services Centres (IFSC) Dear Sir/Madam, Sub: Guidelines for Business Continuity Plan (BCP) and Disaster Recovery (DR) for Market Infrastructure institutions (MIIs) 1. IFSCA, as a member of IOSCO, has adopted the Principles for Financial Market Infrastructures (PFMIs) laid down by CPMI-IOSCO. 2. Principle 17 of PFMI that relates to management and mitigation of ‘Operational risk’ requires that systemically important market infrastructures institutions “should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.” 3. The Stock Exchanges (including Bullion Exchange), Clearing Corporations and Depositories (hereinafter referred to as Market Infrastructure Institutions or MIIs) in IFSC form the backbone of capital market ecosystem. As part of the operational risk management, these MIIs are required to set up Disaster Recovery (DR) site to provide essential facilities and perform systemically critical functions relating to trading, clearing and settlement in securities market during any unforeseen circumstances. 4. Considering the advancement in technology and improved automation of various processes, a framework for Business Continuity Plan (BCP) and Disaster Recovery Site (DRS) 2 | P a g e for the MIIs in the IFSC is prescribed hereunder. a) The MIIs shall have in place BCP and DRS to maintain data and transaction integrity. b) Apart from DRS, all MIIs shall also have a Near Site (NS) to ensure zero data loss. c) The DRS should preferably be set up in different seismic zones and in case due to certain reasons such as operational constraints, change of seismic zones, etc., a minimum distance of 500 kilometres shall be ensured between the Primary Data Centre (PDC) and the DRS so that both DRS and PDC are not affected by the same disaster. d) The manpower deployed at a DRS/NS shall have the same expertise as available at the PDC in terms of knowledge/ awareness of various technological and procedural systems and processes relating to all operations such that the DRS/NS can function at a short notice, independently. The MIIs shall deploy a sufficient number of trained staff at their DRS in order to ensure the capability of running live operations from DRS without involving staff of the PDC. e) All the MIIs shall constitute an Incident and Response Team (IRT)/ Crisis Management Team (CMT), which shall be chaired by the Managing Director (MD) of the MII or by the Chief Technology Officer (CTO), in case of non- availability of MD. The IRT/ CMT shall be responsible for the actual declaration of disaster, invoking the BCP and shifting of operations from PDC to DRS whenever required. Details of roles, responsibilities and actions to be performed by employees, IRT/ CMT and support/outsourced staff in the event of any Disaster shall be defined and documented by the MII as part of BCP-DR Policy Document. f) The Technology Committee of the MIIs shall review the implementation of the BCP- DR policy approved by the Governing Board of the MII, on a quarterly basis. g) The MIIs shall conduct periodic training programs to enhance the preparedness and awareness level among their employees and outsourced staff, vendors, etc. so as to discharge their duties as per the BCP policy. Configuration of DRS/NS with PDC 5. The following guidelines shall apply with respect to the configuration of DRS/NS with PDC: 3 | P a g e a. Hardware, system software, application environment, network and security devices and associated application environments of DRS / NS and PDC shall have one to one correspondence between them. b. The MIIs shall develop the necessary systems in a manner that does not require system configuration changes at the intermediary level (broker dealers/ clearing members/ depository participants) for switchover from the PDC to the DRS. Further, the MIIs shall test such a switchover functionality by conducting unannounced live operations from the DRS for at least 1 day in every six months. Unannounced commencement of live operations from the DRS of the MIIs shall be done at a short notice of 45 minutes, after 90 days from the date of this circular. c. The ‘Critical Systems’ for an Exchange/ Clearing Corporation shall include Trading, Risk Management, Collateral Management, Clearing and Settlement and Index computation. ‘Critical Systems’ for a Depository shall include systems supporting settlement process and inter-depository transfer system. d. In the event of a disruption of any one or more of the ‘Critical Systems’, the MII shall, within 30 minutes of the incident, declare that incident as a ‘Disaster’ and take necessary measures to restore operations, including from the DRS, within 45 minutes of declaration of a ‘Disaster’. Accordingly, the Recovery Time Objective (RTO) i.e., the maximum time taken to restore operations of ‘Critical Systems’ from DRS after declaration of Disaster- shall be 45 minutes, to be implemented within 90 days from the date of the circular. e. The MIIs shall ensure that the Recovery Point Objective (RPO) i.e., the maximum tolerable period for which data loss is experienced, due to a major incident, shall be 15 minutes. f. The solution architecture of PDC and DRS / NS shall ensure: i. high availability, ii. fault tolerance, iii. no single point of failure, iv. zero data loss, and v. data and transaction integrity g. Any updates made at the PDC should be reflected at DRS/ NS immediately (before end of day) with head room flexibility without compromising any of the performance metrics. 4 | P a g e h. The replication architecture, bandwidth, and load consideration between the DRS / NS and PDC shall be within the stipulated RTO and shall ensure high availability, right sizing, and no single point of failure. i. The replication between PDC and NS shall be synchronous so as to ensure zero data loss whereas, the one between PDC and DRS and between NS and DRS may be asynchronous. j. Adequate resources (with appropriate training and experience) should be available at all times to handle operations at PDC, NS or DRS, as the case may be, on a regular basis as well as during disasters. DR Drills/Testing 6. The following guidelines with respect to the DR drills/ testing shall apply: a) DR drills should be conducted on a quarterly basis. In case of Exchanges and Clearing Corporations, these drills shall be closer to real life scenario (trading days) with minimal notice to the DRS staff involved. b) During the drills, the staff based at PDC shall not be involved in supporting operations in any manner. c) The drill shall include the execution of all operations from DRS for at least 1 full trading day. d) The timing diagrams clearly identifying resources at both ends (DRS as well as PDC) shall be in place, before the commencement of DR drills.