SIHL uses purchase orders for essential trading software
Ask Iris
SIHL uses purchase orders, rather than a formal agreement, to obtain software essential to its core trading activities from a National Stock Exchange of India (NSE)-empanelled third-party provider. The arrangement supports its market interface and digital platforms, while SIHL reported technical glitches and processed average daily transactions of 19,702 in Fiscal 2025.
Why does SIHL use purchase orders for trading software?
SIHL is materially dependent on an NSE-empanelled third-party software provider for front-end trading software, which it identifies as essential to executing core trading activities. The front-end software forms an essential part of SIHL’s market interface, making the dependency relevant to the technology through which trading activity is accessed and executed.
SIHL also obtains services from third-party software providers for its app-based platforms, SIHL Moneymaker and SIHL Fundspro. The prospectus says the licensing arrangements are intended to avoid technical glitches and maintain operational efficiency, but does not identify the providers, quantify expenditure, or state how many providers supply the services.
SIHL says it has not entered into any agreement with these third-party software providers and avails their services through purchase orders. The disclosure does not state the duration of the purchase orders, service-level commitments, renewal conditions, termination rights or contingency arrangements for replacing a provider.
The purchase-order structure matters because SIHL’s information-technology systems must record and process a large number of transactions every day accurately, comprehensively and on time. For the arrangement to continue supporting the business, the providers must continue supplying the front-end and app-related services, while SIHL’s systems must keep pace with technology and industry requirements.
What software glitches has SIHL reported?
SIHL has disclosed various technical software glitches, while also stating that it has not experienced prolonged disruptions or failures of its information-technology systems. The incidents included portfolios not being visible on its trading application, last traded prices not being updated, and a critical failure of a risk-management application server for a few hours.
The risk-management server failure delayed regular automated fund information to exchanges, according to SIHL. The prospectus gives no date for the incidents, does not state how many clients or transactions were affected, and does not quantify any associated financial loss.
The portfolio-display and price-update incidents concerned information shown through the trading interface, whereas the risk-management server incident affected exchange reporting. SIHL does not state that trades failed, client funds were lost, or that an exchange imposed a penalty in relation to these particular glitches.
SIHL separately says it has faced penalties from regulators and exchanges in the past for non-compliance with regulations, rules and byelaws relating to operational failures, including some beyond its control. That disclosure concerns operational failures generally and does not connect the past penalties to the three technical incidents described in its technology-risk disclosure.
How many transactions do SIHL’s systems process?
SIHL’s average daily transaction volume was highest in Fiscal 2025 at 19,702 transactions, before declining to 17,318 in Fiscal 2026. The Fiscal 2026 average remained above Fiscal 2024’s 16,416 transactions, showing an increase between Fiscal 2024 and Fiscal 2025 followed by a reduction in Fiscal 2026.
SIHL says its systems must accurately and comprehensively record and process transactions in a timely manner to provide a seamless client experience. Average daily transactions increased by 2,384 from Fiscal 2024 to Fiscal 2025, then declined by 2,384 in Fiscal 2026, leaving the Fiscal 2026 average 902 above Fiscal 2024.
SIHL identifies peak trading periods and unusual market volatility as circumstances that may place pressure on technology capacity. Its risk disclosure also identifies capacity constraints, power failures, computer viruses, ransomware, distributed denial-of-service attacks, unauthorised access and data leakage as potential causes of disruption.
For the financial years ended March 31, 2024, March 31, 2025 and March 31, 2026, SIHL says there were no security breaches in its information-technology systems, failures, corruption or criminal investigations. That historical statement does not remove the possibility of future incidents, which SIHL says could interrupt operations or expose sensitive company and client information.
What technology controls does SIHL say it has?
SIHL says it has deployed security systems, protocols and tools, including two-factor authentication across all software and hardware access points. Two-factor authentication requires more than one verification factor to gain access, and SIHL says it has implemented the measure to enhance system security.
SIHL also conducts continuous monitoring through a managed Security Operations Centre, or SOC, operated by a service provider empanelled and certified by the Indian Computer Emergency Response Team, known as CERT-In. SIHL says all endpoints and servers are protected through an Endpoint Detection and Response, or EDR, solution, while wide area networks use a third-party unified threat-management solution.
SIHL is required to maintain business-continuity plans, review them periodically, maintain disaster-recovery centres and conduct periodic drills. Business continuity refers to measures intended to maintain or restore operations after a disruption, while disaster recovery concerns the restoration of technology systems and data; SIHL says it cannot assure that these arrangements will be adequate for all eventualities.
SIHL says vulnerabilities in mobile applications are checked through reviews by the relevant application platform and developer, using automated security assessments and independent evaluations. However, its largely automated systems still require human involvement at different levels, and SIHL identifies human error as a risk to its technology systems and brokerage and distribution services.
What could affect SIHL’s technology operations?
SIHL says a prolonged disruption or failure of its information-processing or communications systems could limit transaction processing and harm operations. Its operations depend on systems that process trading activity daily, as demonstrated by the 17,318 average daily transactions reported in Fiscal 2026.
The company says rapid technological change, including artificial intelligence-based trading systems operating within microseconds, could affect its ability to compete if it cannot adapt its technology. SIHL does not disclose a technology-upgrade timetable, spending commitment or provider replacement plan in the cited risk disclosure.
SIHL also says cyberattacks, including hacking, phishing and trojans, may disrupt client services or lead to theft of sensitive internal or client data. Although it has an established cybersecurity policy, SIHL states that it cannot assure that attacks will be prevented before they occur or that their risks can always be mitigated or minimised.
A disruption could also arise from natural disasters, market volatility, power failures, viruses, spam attacks or ransomware, according to SIHL’s disclosure. The company says failure to update continuity plans, inadequacy of recovery centres, or improper maintenance could affect operations and could lead to regulatory action or penalties.
Conclusion
SIHL’s disclosures show that essential front-end trading software is supplied through purchase orders rather than a formal agreement, while third-party services also support SIHL Moneymaker and SIHL Fundspro. This operational dependency sits alongside disclosed glitches involving portfolio visibility, price updates and delayed automated fund information to exchanges, at transaction volumes that reached 19,702 daily in Fiscal 2025.
What to watch next is whether SIHL maintains the purchase-order arrangement while meeting its disclosed requirement to review business-continuity plans, maintain disaster-recovery centres and conduct drills. SIHL reported no security breaches, failures, corruption or criminal investigations for the financial years ended March 31, 2024 through March 31, 2026, but it also identifies future cyberattacks, capacity constraints and human error as unresolved technology risks.
Frequently Asked Questions
Did your stocks survive the war?
See what broke. See what stood.
Live Q1 Earnings Tracker
