[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

SEBI CSCRF

Capital Markets runs on vendor software. Prove the critical stack can recover

Identify the vendor-built systems inside regulated services, keep every release current, and produce independent recovery evidence before an incident.

CAPITAL MARKETS SYSTEMS

The vendor-built systems inside the critical path

Trading platform

CRITICAL

Clearing and settlement

CRITICAL

Market surveillance

HIGH

Risk and margin engine

HIGH

WHAT THE REGULATOR ASKS

SEBI CSCRF

In summary

Market institutions and regulated entities must govern third-party cyber risk, continuity and testing for critical systems supporting market operations.

Read the regulation evidence map

THE EVIDENCE PACK

The artefacts that make the obligation examinable

Build Report

Deployment Runbook

Replication Report

SBOM

Signed Proof of Recovery

Institutional proof

Approved institutions across Castler’s trust infrastructure

A growing network of banks, payment institutions and financial-services leaders relies on Castler’s trust infrastructure for controlled, accountable money movement.

Named institutions across banking, payments and lending
Castler trust networkApproved institutions
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
BanksPayment institutionsNBFCsFintech

REGULATORY OBLIGATIONS

Regulatory obligations for capital markets firms

Market Infrastructure Institutions and Qualified Regulated Entities are subject to SEBI CSCRF. Global capital markets firms operating in the EU are additionally subject to DORA.

CAPITAL MARKETS

Make the Capital Markets Software Estate recoverable.

Bring the critical system stack and applicable rulebook. We’ll map custody, verification and signed evidence.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day