NISM Professor

Regulatory sandbox

Also written Sandbox

A SEBI framework letting registered market participants live-test FinTech innovations with a limited set of customers, for a limited period, under the regulator's supervision.

In plain language

Financial regulation is written for products that already exist. That leaves anyone with a genuinely new idea in an awkward spot: the rules do not contemplate what they are building, so the safe regulatory answer is no.

The workbook frames it as friction. The Global Financial Crisis of 2008 sharpened the case for tighter regulation of financial services firms, and ever since there has been "constant friction between the regulators and the financial services providers". The concept of a Regulatory Sandbox aims at resolving this friction.

The idea is a walled garden. A regulated entity may run its innovation live — real customers, real money — but on a small scale, for a fixed period, inside boundaries agreed with SEBI and under SEBI's supervision. If it works, it graduates. If it fails, it fails small, and the damage is contained by design.

The term was coined by the UK Financial Conduct Authority in 2015, and regulators in more than 20 countries have since adopted it.

How it works

SEBI runs two sandboxes, and the paper expects you to tell them apart.

Innovation SandboxRegulatory Sandbox
TestingOffline, in isolation from the live marketLive, in a real environment
Who may use itFinTech firms, start-ups and entities not regulated by SEBI, including individualsSEBI-registered market participants, on their own or using a FinTech firm's services
CustomersNone — no live marketA limited set of customers, for a limited period
OversightA Steering Committee of representatives from the enabling organisations — stock exchanges, depositories and qualified RTAsSEBI
FrameworkRevised framework, SEBI circular dated 2 February 2021SEBI circular dated 5 June 2020

The natural path runs left to right: an unregulated start-up builds and tests offline in the Innovation Sandbox, then partners with a SEBI-registered entity to go live in the Regulatory Sandbox.

Entry is not automatic. SEBI has specified strict eligibility criteria for registered participants wishing to use the Regulatory Sandbox, and the proposed innovation must be genuine and add value to existing offerings in the Indian market — an existing product with a new label does not qualify. The limits on customers, duration and exposure are set case by case as part of the approval, not fixed by a published number.

A worked example

A SEBI-registered stockbroker wants to launch voice-based order placement in regional languages for first-time investors in smaller towns. It is a genuine gap: a large number of new demat accounts belong to people who find an English trading app hard to use.

The technology comes from a two-year-old start-up with no SEBI registration of its own.

Stage 1 — Innovation Sandbox. The start-up is not regulated by SEBI, so it cannot go live. It uses the Innovation Sandbox to test offline, in isolation from the live market: no real orders, no real money, and therefore no investor at risk if the speech model mishears a quantity.

Stage 2 — Regulatory Sandbox. The broker, being SEBI-registered, applies for live testing using the start-up's solution. SEBI approves a cohort bounded by conditions the broker proposes and SEBI accepts — for instance 400 consenting clients in two states, an order-value ceiling of Rs 25,000 per voice order, and a six-month window, with a spoken confirmation replayed before every order is sent. (Those figures are the terms of one hypothetical approval; SEBI does not publish a standard cap.)

Why the boundary matters in rupees. Suppose the system mis-hears "buy 50" as "buy 500" on a Rs 480 share. Inside the sandbox, with a Rs 25,000 ceiling, the erroneous order is rejected before it reaches the exchange. Rolled out untested to 4 lakh clients, the same defect at a 1 per cent error rate would be 4,000 wrong orders, each averaging perhaps Rs 24,000 — roughly Rs 9.6 crore of unintended exposure, plus the complaints and the investigation.

That is the trade the sandbox is making: accept a small, supervised, reversible failure in order to avoid a large, unsupervised, irreversible one.

Why NISM asks about it

Chapter 1 (Understanding Securities Markets and Performance), section 1.5.2 (Innovations in Financial Technology (FinTech) and Regulatory Sandbox), which follows the block on cyber security and cyber resilience; the definition is repeated in the workbook's glossary. Questions are definitional and comparative: what a Regulatory Sandbox is, who coined the term (the UK Financial Conduct Authority) and when (2015), how many countries have adopted the concept (more than 20), and above all the Innovation Sandbox versus Regulatory Sandbox distinction — offline versus live, unregulated entities versus SEBI-registered ones. Two-column comparison questions on that pair are the standard form.

Common exam traps

  • Innovation Sandbox = offline; Regulatory Sandbox = live. This is the distinction the section exists to teach and the one most often reversed under exam conditions.
  • The Regulatory Sandbox is only for SEBI-registered entities. A start-up cannot enter it directly; it participates through a registered entity, or uses the Innovation Sandbox instead.
  • The Innovation Sandbox is supervised by a Steering Committee, not by SEBI directly — and that committee is drawn from stock exchanges, depositories and qualified RTAs.
  • "Limited customers, limited period" is the definition, not a detail. A sandbox is not a licence, an approval, or a permanent exemption; it ends.
  • The FCA coined the term in 2015, not SEBI, and the 2008 crisis is given as the background to the friction, not the origin of the sandbox.
  • The innovation must be genuine and add value in the Indian market. Re-packaging an existing offering does not meet the eligibility bar.

Where this is taught

Free preparation for NISM Series XIX-D

Related terms

← All terms
Something look wrong? Report it