Trading on Thin Ice: A Critical Look at Sebi’s 2025 Consultation Paper on Brokers’ Trading Systems

[By Ayushman Shrivastava]

The author is a student of Hidayatullah National Law University (HNLU), Raipur.

Introduction

On 22nd September 2025, the Securities and Exchange Board of India (‘SEBI’) released a consultation paper on Review of Framework for ‘Technical Glitches’ in Brokers’ Trading Systems (‘Consultation Paper’), proposing revisions to its framework for managing technical glitches in brokers’ electronic trading systems. This is an effort to tweak an already existing regulatory regime (‘2022 Framework’), that has been operational since November 2022. The new proposals do not introduce new compliance burdens, but rather aim to adjust the balance between the protection of the investors and the practical realities of running a brokerage company. SEBI through these changes, signal a shift towards more precise and proportionality of regulation by reducing the definition of a technical glitch, confining the framework to bigger brokers, and streamlining the reporting mechanisms.

This rethinking has to be understood in the light of the 2022 Framework. Back then, SEBI was following the approach of unveiling a comprehensive framework for all brokers with detailed guidelines released by stock exchanges a month later. The framework mandated prompt reporting of technical glitches, imposed penalties for defaults, and treated all disruptions, whether technical or otherwise, as the broker’s responsibility.. While this seemed investor-centric, it quickly came under scrutiny for being too prescriptive. Brokers resented being penalized even for disruptions that resulted from circumstances beyond their control, such as cloud service provider outages or payment gateway issues. Smaller brokers who had little technology infrastructure also felt compliance unproportionately burdensome.

This article will critically examine the recent consultation paper on technical glitches by SEBI, and not just the gloss of the reforms it has offered. The redefinition of what should be considered a technical glitch seems to be exact, yet it risks absolving brokers of responsibility for disruptions that would affect investors outside regular trading hours. Equally, SEBI’s decision to exempt small brokers from the framework in the name of proportionality could inadvertently create a patchwork of regulation, leaving retail investors at the mercy of their brokers depending on size.

Although the fact that reporting is being centralized and penalties are being softened is an indication of progress, the same changes can also lead to lack of accountability, as they put the burden of self-assessment and internal controls directly on the brokers. Finally, this article raises the question of whether the re-calibrated method of SEBI is sufficient in protecting the interests of investors or is too focused on regulatory convenience and industry comfort, which may compromise the integrity of the market.

Glitches Redefined: Fine-Tuning Oversight or Diluting Accountability?

SEBI’s idea to restrict the scope of what can be called a “technical glitch” marks one of its most consequential changes in the new Consultation Paper. Under the proposed definition, only malfunctioning during trading hours that are directly hindering trading or risk management (such as login failures, errors in placing orders or margin allocation) will fall into the regulatory net. Substitutions or failures that take place because of cloud service providers, banks, payment gateways, KYC onboarding, back-office systems, or analytical tools are specifically excluded. This seems like a logical change over the 2022 Framework, which unfairly burdened brokers with liability for things they cannot control.

However, the accuracy of this new definition is purchased at a price. By excluding such broad areas of disruptions as “non-glitches”, SEBI risks undermining accountability in ways that have a direct bearing on investors. Take the example of payment gateway failures: while they are not trading, they can cause customers to miss their chance to be able to deposit their accounts in time and therefore lose out on trades, or worse, put them at the mercy of market volatility.

There is also a temporal blind spot. By ignoring after-hours glitches, SEBI assumes that risks are confined to market hours. In reality, modern trading never really stops. Investors keep preparing strategies, transferring funds, and analysing their positions long after the trading bell has rung. A systemic outage at 6 p.m. may not register under SEBI’s framework, but it could undermine trading decisions the next morning.

The underlying tension is apparent: SEBI does not wish to unfairly penalize brokers, but in doing so, it threatens to impose the burden of technological weakness on investors themselves. Overcorrection in regulation towards intermediaries can ultimately destroy trust in the very markets it aims to stabilize. Accuracy of definition must not be a codeword for avoidance of responsibility.

Applicability and the Two-Tier Market: Proportionality or Privileged Protection?

One of the most striking proposals in SEBI’s consultation paper is the narrowing of the framework’s applicability. Under the revised regime, only brokers offering Internet-Based Trading (IBT) or Securities Trading Using Wireless Technology (STWT) platforms with more than 10,000 registered clients as of March 31 of the preceding financial year will be covered. By SEBI’s own estimates, this would exempt around 457 smaller brokers from the compliance obligations.

This threshold has been set by SEBI with reference to proportionality. But the larger and more technologically intensive a broker is, the more systemic its impact. Smaller brokers with few clients are not levied with an excessive compliance charge. Theoretically this is a fair difference. The migration, however, is risky due to the fact that it will create a two-tier marketplace which will act as a safeguard to investors. While large brokerage firms’ customers will be able to take advantage of the improved glitch awareness, tracking, and enforcement of noncompliance. Meanwhile, clients of smaller brokers will remain frustrated by an ineffectively designed system.

There are namely three problems with this split. Firstly, these thresholds can create perverse incentives for regulatory gaming companies who are hovering over the 10,000-client threshold to not to expand their client base so that they do not have to pay to comply, and therefore ultimately restricting their own growth.

Secondly, this kind of approach will generate informational asymmetry. The bugs between the exempted brokers are going to be less visible to regulators but will keep causing enormous damage to investors

Third, that smaller brokers are less systemically risky, is simply assumed solely based on the fact of inter-dependent existence. Smaller brokers tend to be dependent on the same cloud providers and APIs or technology suppliers as the larger ones. The size-based exception is somewhat arbitrary in that a failure on such a node can be propagated on both large and small brokers.

From Disclosure to Durability: Centralised Reporting, Capacity Mandates, and the Danger of Window-Dressing

SEBI’s Consultation Paper has a strong emphasis on reporting efficiency and operational resilience. The key to it is the move to the Samuhik Prativedan Manch, a reporting portal through which every broker has to send in an initial incident report (T+1) and then a root-cause analysis (within 14 days). Along with a two-hour grace period concerning first glitch disclosures, this centralization will decrease redundancy and make the compliance smooth.

To be efficient is to pay the price of efficacy. The SEBI is at risk of turning reporting into an empty procedure instead of a real accountability process by extending periods and placing undue reliance on the reports that brokers churn out. However, the real question is who audits these reports? Root cause analyses can easily become self-serving unless they are verified by the exchanges or independent third-party auditors. Without strict checks, the process risks being nothing more than a transparency exercise on paper, while the real structural weaknesses in the system remain hidden.

When it comes to resilience, SEBI rightly expects robust capacity planning for servers and trading applications, thorough software testing, and strengthened BCP/DRS protocols. Exchanges are supposed to maintain disaster recovery sites in different seismic zones and monitor them continuously through API-based Logging and Monitoring Mechanisms (LAMA). On paper, these measures look solid, but the challenge is in the execution. Will exchanges actually be held accountable for meeting recovery time objectives (RTO) and recovery point objectives (RPO), or will this simply become another checklist item for audits, with no real consequences if things go wrong?

The danger, though, is the window dressing resistance: reporting portals and checklists create the illusion of compliance, but unless there is evidence that the system is being implemented and independently verified, the systemic weaknesses likely remain invisible until the next major outage pushes the overall system to the limit.

Way Forward & Conclusion

SEBI’s consultation paper is a step towards correcting the excesses of the 2022 framework, but the recalibration it proposes leaves critical questions unresolved. The narrowing of “technical glitch” may bring proportionality, yet it risks leaving investors vulnerable to failures that materially affect their trading capacity but fall outside SEBI’s definition. Equally, the removal of the burden of compliance placed on smaller brokers can make their thriving easier, but it creates a bifurcation of investor protection, one where some are stronger and some are weaker. Centralised reporting and capacity needs guarantee cleanliness, but without autonomous controls and punishments, these might become procedural rituals rather than mechanisms of resistance.

Any solution will have to address these gaps without undoing the efficiency gains that SEBI is trying to achieve. Instead of a simple yes/no cutoff, a tiered system should be introduced so that even the smallest brokers are required to meet the minimum reporting and resilience standards. Similarly, SEBI should require regular third-party audits of root cause analyses and BCP/DRS drills to ensure these exercises don’t become mere paperwork. Even for outages in areas that are currently exempt from penalties, such as payment systems or back-office functions, there should still be mandatory disclosure and reporting to ensure the regulator remains aware of potential risks.

SEBI’s recalibration will only matter if it genuinely strengthens market integrity instead of pushing more risk onto investors in the name of pragmatism. Precision and proportionality are important, but they should never come at the cost of accountability. It is much harder for brokers to rebuild trust after a failure than to restore market confidence, which is always fragile. In the end, the framework should focus on protecting investor trust, because that is what truly keeps the market fair and resilient.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top