The amendments clarify the roles, responsibilities, and appointment procedures of managing directors, executive directors, chief technology officers (CTOs), and chief information security officers (CISOs). Managing directors now oversee overall operations, compliance, risk management, and infrastructure, while executive directors manage specific verticals with similar authority and responsibilities. CTOs are tasked with managing technology systems, IT policies, and risk frameworks, whereas CISOs handle cybersecurity governance, risk mitigation, and incident management. It also formalizes conditions for non-executive appointments on external boards and defines tenure, maximum age, and approval processes.
