evidoria

← Back to browse

Good practice Imported

C-SAC — SEBI's AI-Enabled Cybersecurity Audit Compliance Platform for India's Market Infrastructure

India · Mumbai · See the India profile · See the Mumbai profile

Top 83% 40/100 · Ask Evidence Copilot about this practice

SEBI's AI-enabled C-SAC platform analyses the mandatory cyber-audit reports regulated entities submit, producing comparative risk scores to focus supervisory attention. In FY2025-26 it processed reports from 8 market infrastructure institutions and 23 mutual funds.

Details

Promoter
Securities and Exchange Board of India (SEBI)
Period
2025–2026
Keywords
financial regulation, cybersecurity, capital markets supervision

Description

Under India's Cybersecurity and Cyber Resilience Framework, SEBI-regulated entities — stock exchanges, depositories, clearing corporations and mutual funds among them — must submit periodic cyber-audit reports. Reviewing these submitted reports manually is labour-intensive and makes it hard to compare cyber posture consistently across the sector.

C-SAC (Cyber-Sec Audit Compliance) is an AI-enabled platform SEBI built to automate this analysis: it ingests the cyber-audit reports entities file through SEBI's SI Portal, flags compliance gaps and risk areas, and generates comparative risk scores across regulated entities to support SEBI's risk-based supervision approach. According to Indian financial press coverage, in the 2025-26 financial year the platform processed reports for eight market infrastructure institutions and 23 mutual funds — SEBI's first disclosed usage figures for the tool.

C-SAC sits alongside other AI tools SEBI has rolled out in the same period, including InfoMerge for automating parts of investigation casework (data acquisition, analysis and report generation), and is distinct from SEBI's earlier, separately documented Project Sudarsan and R(ai)dar tools for flagging misleading financial content and advertisements. Coverage of C-SAC to date is limited: SEBI regulates many more market infrastructure institutions and thousands of registered mutual funds and intermediaries than the FY2025-26 figures cover, and neither SEBI nor independent reporting has yet published accuracy, false-positive rates, or an evaluation of whether the AI-generated risk scores changed supervisory outcomes. The risk-scoring methodology itself has not been made public.

Read the full analysis: https://www.newkerala.com/news/a/sebi-launches-three-new-it-platforms-transform-regulatory-971.htm

Implementation

Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Similar practices you may find useful