IRDAI cybersecurity audit
IRDAI replaced its 2023 Information and Cyber Security Guidelines in April 2026 with Version 2.0, and regulated entities are expected to comply from the current financial year. It reaches further than insurers alone — foreign reinsurance branches, brokers, corporate agents, web aggregators, TPAs and insurance repositories are all in scope. CyberSigma is a CERT-In empanelled auditor: we assess your governance, controls, VAPT posture, third-party and cloud risk and incident readiness against the current guidelines, and deliver a board-ready report and remediation plan you can file and defend.
The 2023 guidelines have been superseded
IRDAI issued Version 2.0 of its Information and Cyber Security Guidelines in April 2026, replacing the guidelines dated 24 April 2023. Regulated entities are expected to comply from the current financial year, so an audit programme still scoped against the 2023 text is evidencing the wrong baseline.
If your last assessment was mapped to the 2023 guidelines, the practical questions are which control expectations have moved, what your board needs to see this year, and whether entities you previously treated as out of scope — intermediaries, TPAs, repositories — are now in it. We will confirm the applicable version and reference against IRDAI’s published document before any scoping is fixed.
Who this applies to
The guidelines apply to all Insurers including Foreign Re-Insurance Branches (FRBs) and to Insurance Intermediaries regulated by IRDAI, covering all data created, received or maintained in any form. Insurance Agents, Micro-Insurance Agents, Point of Sale Persons and Individual Surveyors are expressly outside their purview — though Insurers remain responsible for ensuring those entities follow a minimum security framework under the Insurer’s Board-approved policy.
Not every firm is permitted to perform this audit
Annexure IV of the guidelines sets two alternative routes. One is a Chartered Accountant firm registered with ICAI holding at least five years of continuous practice and four partners, including a CISA/DISA holder, an ICAI Fellow, a partner with three years of cyber or information security audit experience in insurance, banking or mutual funds, and a partner experienced in IT-environment and remote audits.
The other route, in the guidelines’ own words, is a “Cert-In empanelled external systems Auditor holding CISA / DISA certifications”. CyberSigma qualifies under that route — we are listed at Sl. No. 57 of the CERT-In empanelled organisations list, which you can verify independently at cert-in.org.in rather than taking our word for it.
The guidelines also state that certification may not rest on management representation or on reliance upon another auditor’s work: the auditor must perform interviews, document verification, compliance checks and adequate testing of controls. A questionnaire-led engagement does not meet the requirement.
What the audit covers
Timeline and cost factors
What you receive
Common findings
- Weak third-party and cloud governance
- Incomplete logging/monitoring and untested incident response
- VAPT findings without documented closure
- Board-reporting and governance gaps
See how we’ve done it before
Worried about a supplier becoming your breach?
Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.
IRDAI cyber audit — FAQs
Are you eligible to perform the IRDAI audit?
Yes. Annexure IV permits a CERT-In empanelled external systems auditor holding CISA/DISA certifications as an alternative to the Chartered Accountant firm route. CyberSigma is listed at Sl. No. 57 of the CERT-In empanelled organisations list, which is publicly verifiable at cert-in.org.in.
Which version of the IRDAI guidelines applies now?
Version 2.0, issued in April 2026, which replaced the Information and Cyber Security Guidelines dated 24 April 2023. Compliance is expected from the current financial year. We confirm the applicable version and its reference against IRDAI’s published document at the start of every engagement rather than assuming it.
Who must comply with IRDAI cyber-security guidelines?
IRDAI-regulated entities — insurers, intermediaries, web-aggregators and insurance-tech — on a scale-appropriate basis, with periodic audits and VAPT.
Is VAPT part of the audit?
Yes. As a CERT-In empanelled auditor we combine the governance audit with application and infrastructure VAPT and document closure.
Talk to our insurance audit practice
We map your applicable IRDAI guidelines, run the audit and VAPT, and give you a board-ready report. Reply within four business hours.
Book a 20-minute call →