The circular addresses various queries from REs and updates the guidelines to ensure a robust and clear implementation of the framework. A key part of the new circular is the introduction of the ‘Principle of Exclusivity’ and ‘Principle of Equivalence’ for entities that are regulated by multiple bodies, such as the SEBI and the Reserve Bank of India. These principles aim to streamline compliance by limiting the scope of the CSCRF to systems exclusively used for SEBI-related activities and by accepting equivalent cybersecurity measures followed under another regulator’s framework. It also updates the categorization thresholds for Portfolio Managers and Merchant Bankers.
