The Centre must clear the regulatory labyrinth

    Kumardeep Banerjee

    If the Government wants to see a faster pace of development in the country, regulatory hurdles must be cleared at the earliest

    A few days ago the highest court in the country gave two weeks’ notice to a Government department for no show on an exact regulatory intent and action point in a certain case relating to a policy issue. The Government department had in its response to the Supreme Court mentioned that it was contemplating some regulation.

    Meanwhile, Prime Minister Narendra Modi has repeated in various forums, including the floor of the Parliament, as to how the bureaucracy can’t be entrusted to fly planes and run factories. Citizens should respect wealth and job creators, as in a dynamic world order it is not the business of the Government to be in business. This promise of a completely meritocracy-fed economy, was one of the key planks which got the voters’ attention seven years ago, until an ill-thought, self-defeating sharp criticism had set the ball rolling to back a harder form of a State-controlled socialist order.

    Finance Minister Nirmala Sitharaman set the ball rolling when she mentioned that “the intent of the Government is maximum governance, minimum Government,” during her Budget speech (the second time this phrase was heard) in the two-term regime.

    What has shifted in the seven years of the National Democratic Alliance’s two-term regime is the nature and predictability of the economy and its determinants, and almost an end to the multilateral high table of trade negotiations.

    Therefore, it is time for the Government to get out of business. Consider, for example, a poorly-explained Securities and Exchange Board of India (SEBI) circular issued in November 2020, advising intermediaries to ensure compliance with the Indian Computer Emergency Response Team (CERT-in) Advisory for Financial Sector Organisations regarding Software as a Service (SaaS)-based solution and to ensure complete protection and seamless control over vital systems while keeping critical data within the legal boundaries of India.

    SaaS is a relatively new concept where Information Technology (IT) solutions are almost streamed over the internet to the customer’s premises, however the software can be owned, operated or hosted by a third party vendor.

    As it always happens with global companies, including banks or their intermediaries having multi-geography presence, the IT processes are uniform across the chain and, therefore, purchase of software solutions is done at a centralised office. This kind of cloud storage and delivery of solutions has many potential advantages which includes cost savings from trying to find multiple and complex processes for each geography if not the customer; uniform and globally accepted interoperable safe and secure security measures; besides the obvious benefits of being nimble with scaling up and down and running an amost clutter-free IT department.

    It is here that the SEBI circular which states that, “the Government of India has informed SEBI that the financial sector institutions are availing or thinking of availing SaaS-based solutions for managing their Governance, Risk and Compliance (GRC) functions so as to improve their cyber security posture. As observed by the IT Ministry, though SaaS may provide ease of doing business and quick turnaround, but it may bring significant risk to the health of the financial sector as many a time risk and compliance data of the institution moves beyond the legal and jurisdictional boundary of India due to the nature of shared cloud SaaS, thereby posing risk to the data safety and security,” creates significant confusion.

    Naturally, some industry associations tried to reach out to the SEBI to seek clarifications on the nature and scope of the circular. After repeated attempts when they were able to get the regulator’s attention, the officials seemed to have no significant solutions to offer, except for passing the buck to the next department. It may be noted that the circular itself mentions the criticality of SaaS for improving the ease of doing business but fails to give the reason why, and how the same solution can be a problem from a cybersecurity standpoint. This shows how the bureaucracy and Government departments are grappling with a new-age digital economy, which they are trying to regulate with an old-world licence regime.

    Another aspect of the hydra-headed regulatory regime is duplication of regulations by intra-governmental departments trying to regulate the same bunch of market players.

    However, bringing investments, creating jobs, removing the Government from tight lease governance and having a significant say in bilateral/plurilateral forms are sometimes complex and slow drawn negotiations to say the least. If the Government wants to see faster pace of development, regulatory hurdles must be cleared.

    The writer is a policy analyst. The views expressed are personal.