IRDAI · Insurance
ISNP: Full Form, IRDAI Permission and Security Audit
ISNP stands for Insurance Self Network Platform — the electronic platform an insurer or intermediary sets up, with IRDAI's permission, to sell and service insurance online. Permission and continued operation both depend on a security audit.
Reviewed by Sharwan Jha, CyberSigma — CERT-In Empanelled & PCI QSA Authorised firm
ISNP is the full form of Insurance Self Network Platform — an electronic platform established by an insurer, intermediary or applicant with the permission of IRDAI to conduct insurance business online. Before permission is granted the platform must demonstrate its functionality and pass security testing, and thereafter it must be audited annually by a qualified information systems auditor, with adverse findings reported to IRDAI alongside a remediation plan. CyberSigma is CERT-In empanelled and PCI QSA authorised (CEMEA, Asia Pacific and the USA).
What an ISNP is, and who needs one
If you sell or service insurance through your own digital platform in India, that platform is very likely an ISNP and needs IRDAI's permission before it goes live.
- ISNP — Insurance Self Network Platform. An electronic platform set up with the authority's permission to solicit, sell and service insurance products directly.
- It applies to insurers operating their own digital channel, and to intermediaries running a platform through which insurance is distributed.
- Permission is granted against the platform as built: IRDAI expects a demonstration of functionality and evidence that security testing has been performed before go-live.
- Grievance handling is part of the assessment, not an afterthought — a working customer complaint mechanism is a condition of permission.
- Record-keeping and data security expectations continue for the life of the platform, which is what the annual audit exists to verify.
The audit requirement in practice
Two distinct moments matter, and firms routinely prepare for the first and forget the second:
- Pre-permission — security testing and a functionality demonstration before IRDAI grants permission. Findings here delay launch, so this is the one with commercial urgency.
- Annual — an audit by an external auditor holding a recognised information systems audit qualification such as CISA, or a Chartered Accountant with DISA. Alignment to an information security management standard such as ISO/IEC 27001 is expected.
- Adverse findings that could affect policyholders must be reported to IRDAI together with an action plan — so the report is written on the assumption the regulator will read it.
- Material changes to the platform reopen the question: a significant new module or a re-platforming is not covered by last year's audit.
What we assess
An ISNP audit is an application-security engagement wrapped in a regulatory frame, so we do both halves properly:
- The platform itself — authentication and session handling, authorisation and privilege boundaries, injection and business-logic flaws, and the APIs behind the front end.
- Policyholder data — where it is stored, who can reach it, how it is encrypted in transit and at rest, and how long it is kept.
- Payment flows and any card data in scope, where PCI DSS obligations may run alongside the IRDAI ones.
- Integrations with insurers, aggregators and payment gateways, which is where access control most often leaks.
- The governance layer IRDAI actually asks about: information security policy, access reviews, change management, incident response and the grievance mechanism.
- Evidence pack assembly, so what you send IRDAI is complete the first time.
Sequencing an ISNP launch
The common mistake is booking the security test the week before the permission application. Testing finds things, fixing them takes development time, and the retest has to fit before submission. We would rather scope the assessment early, run it against a build that is feature-complete but not yet frozen, and give you a remediation window that does not sit on your launch date. Where you are already live and this is the annual cycle, we work to your renewal date and keep the disruption to your platform minimal.
Why CyberSigma for an ISNP audit
We are CERT-In empanelled and PCI QSA authorised, so an insurance platform that also handles card payments can be assessed once against both regimes instead of twice. Testing is manual-led rather than scanner output, findings are proven, and the report is structured for IRDAI's reading rather than as a raw tool export.
Related services
SEBI CSCRF compliance
Cybersecurity and Cyber Resilience Framework audit for SEBI entities.
AUA / KUA audit
UIDAI Aadhaar authentication audit for AUA, KUA and Sub-AUA entities.
VAPT services in India
CERT-In empanelled penetration testing across web, mobile, API, network and cloud.
Cybersecurity audit
Independent audit against CERT-In, RBI, SEBI and ISO 27001.
Frequently asked questions
What is the full form of ISNP?
ISNP stands for Insurance Self Network Platform — an electronic platform established by an insurer, intermediary or other applicant, with the permission of IRDAI, to solicit, sell and service insurance products online.
Do we need IRDAI permission before launching our insurance platform?
Yes. An ISNP operates under permission from the authority, and that permission is granted against the platform as built — including a demonstration of its functionality, evidence of security testing, and a working grievance-handling mechanism. Launching first and regularising later is not a route we would advise.
Who is qualified to audit an ISNP?
An external auditor holding a recognised information systems audit qualification — commonly CISA, or a Chartered Accountant with the DISA qualification. Alignment to an information security management standard such as ISO/IEC 27001 is expected alongside. CyberSigma performs the security assessment and evidence work; where a specific signing qualification is required for your filing, we tell you plainly and coordinate rather than overstate what we can sign.
How often does an ISNP need to be audited?
Annually, and again on a need basis — which in practice means after any material change to the platform. A significant new module, a payment-provider change or a re-platforming is not covered by the previous year's audit.
What happens if the audit finds something serious?
Adverse findings capable of affecting policyholders are reported to IRDAI along with an action plan to resolve them. That is why the sequencing matters: finding issues early, in a scoped assessment with time to remediate, is materially better than finding them in the audit that goes to the regulator.
Can one engagement cover ISNP and PCI DSS?
Usually, yes. If your platform takes card payments you may carry PCI DSS obligations alongside the IRDAI ones, and the underlying evidence overlaps heavily. Because we are also a PCI QSA company, we can scope a single engagement producing what each regime needs.
Sources & references
- Insurance Regulatory and Development Authority of India — the authority granting ISNP permission and setting audit expectations
- CERT-In (Indian Computer Emergency Response Team) — the national nodal agency; maintains the empanelled auditor list

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
