1
Responsible for the governance of Technology Risks.
2
Ensure adherence to the guidelines pertinent to SEBI in respect of RMF and relevant principles thereunder including risk identification,
risk management, risk reporting (both periodic and escalation of material incident) and corrective actions taken, if any.
3
Assess the performance and reliability of Technology related third-party vendors, service providers, and technology platforms supporting
operations to mitigate outsourcing and vendor-related risks.
4
Define and delegate roles to the key personnel within the IT function for identifying and reporting risks.
5
Assess the risks associated with technology innovation initiatives, including emerging technologies, pilot projects, and proof-of-concept
experiments, to ensure alignment with business objectives and mitigate potential risks of investment, adoption, or integration.
6
Ensure disaster recovery and business continuity plan are in place for both internal operations and third‑party vendors/contracted services, and
their adequacy and effectiveness are maintained and tested regularly by the service providers.
7
Adherence to guidance as provided by Technology Committee of the Board.
8
Ensure minimal system failures affecting business and deliverables of other functions.
9
Measure the organization's exposure to technology-related risks, including infrastructure vulnerabilities, software dependencies, and emerging
threats, to proactively address potential issues and mitigate disruptions in conjunction with Chief Information Security Officer (CISO).
10
Provide inputs and relevant information to the CRO to help define risk thresholds, risk appetite, and to support the preparation of risk reports.
11
Perform and report outcomes of periodic testing of the RCSA to CRO.
12
Identify and implement corrective actions / recommend action plans for deviations in the controls and present to CRO/ CEO.
13
Undertake immediate corrective action for non-compliance or major finding post approval from CEO as per DoP and shall report to CRO regarding
the risk reports.
14
For the relevant functional risks, identify, analyse and report and escalate the following to the CRO and CEO along with recommended action plan for
Early warning signals, Emerging risks, Major findings, Near miss and loss events and fraud incidents in conjunction with Chief Information Security Officer (CISO).
15
Responsible for the governance (incl. reputation and conduct risk associated for the respective function)
16
Maintaining risk level as per the risk metric
17
Perform adequate due diligence of outsourced vendors prior to onboarding.
18
Ensure periodic assessment of outsourced vendors considering following elements:
- Review of vendors' people, systems and processes
- Documentation and communication of error tolerance and code of conduct and monitoring breaches
- Monitor fraud vulnerabilities in the outsourced process
- Report SLA breaches