← Insurers
IRDAI Cyber Security Compliance for Insurers
IRDAI requires insurers, reinsurers and intermediaries to run a formal information security programme with an annual audit. The scope reaches policy administration, claims and the distribution technology that most insurers outsource.
What IRDAI Cyber Security Guidelines requires of insurers
- Board-approved information security policy with a designated CISO reporting into governance.
- Annual cyber security audit by an external auditor, with findings tracked to closure.
- Coverage of policy administration, claims processing and customer portals — including intermediary-facing systems.
- Incident reporting to IRDAI alongside the CERT-In six-hour obligation.
- Third-party risk management for TPAs, brokers and technology partners in the policy lifecycle.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Annual audit report with a closed-loop remediation tracker
- CISO appointment and reporting line documentation
- VAPT of customer portals and intermediary systems, with retest
- Access governance across policy administration and claims
- Third-party assessments for TPAs and distribution technology
Where insurers usually come unstuck
- Scoping the audit to core systems and excluding intermediary-facing portals.
- Treating ISNP obligations as separate when the same systems carry both.
- No evidence that audit findings from the previous cycle were actually closed.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
