We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

IRDAI · Insurance

ISNP: Full Form, IRDAI Permission and Security Audit

ISNP stands for Insurance Self Network Platform — the electronic platform an insurer or intermediary sets up, with IRDAI's permission, to sell and service insurance online. Permission and continued operation both depend on a security audit.

Reviewed by Sharwan Jha, CyberSigma — CERT-In Empanelled & PCI QSA Authorised firm

Quick answer

ISNP is the full form of Insurance Self Network Platform — an electronic platform established by an insurer, intermediary or applicant with the permission of IRDAI to conduct insurance business online. Before permission is granted the platform must demonstrate its functionality and pass security testing, and thereafter it must be audited annually by a qualified information systems auditor, with adverse findings reported to IRDAI alongside a remediation plan. CyberSigma is CERT-In empanelled and PCI QSA authorised (CEMEA, Asia Pacific and the USA).

What an ISNP is, and who needs one

If you sell or service insurance through your own digital platform in India, that platform is very likely an ISNP and needs IRDAI's permission before it goes live.

  • ISNP — Insurance Self Network Platform. An electronic platform set up with the authority's permission to solicit, sell and service insurance products directly.
  • It applies to insurers operating their own digital channel, and to intermediaries running a platform through which insurance is distributed.
  • Permission is granted against the platform as built: IRDAI expects a demonstration of functionality and evidence that security testing has been performed before go-live.
  • Grievance handling is part of the assessment, not an afterthought — a working customer complaint mechanism is a condition of permission.
  • Record-keeping and data security expectations continue for the life of the platform, which is what the annual audit exists to verify.

The audit requirement in practice

Two distinct moments matter, and firms routinely prepare for the first and forget the second:

  • Pre-permission — security testing and a functionality demonstration before IRDAI grants permission. Findings here delay launch, so this is the one with commercial urgency.
  • Annual — an audit by an external auditor holding a recognised information systems audit qualification such as CISA, or a Chartered Accountant with DISA. Alignment to an information security management standard such as ISO/IEC 27001 is expected.
  • Adverse findings that could affect policyholders must be reported to IRDAI together with an action plan — so the report is written on the assumption the regulator will read it.
  • Material changes to the platform reopen the question: a significant new module or a re-platforming is not covered by last year's audit.

What we assess

An ISNP audit is an application-security engagement wrapped in a regulatory frame, so we do both halves properly:

  • The platform itself — authentication and session handling, authorisation and privilege boundaries, injection and business-logic flaws, and the APIs behind the front end.
  • Policyholder data — where it is stored, who can reach it, how it is encrypted in transit and at rest, and how long it is kept.
  • Payment flows and any card data in scope, where PCI DSS obligations may run alongside the IRDAI ones.
  • Integrations with insurers, aggregators and payment gateways, which is where access control most often leaks.
  • The governance layer IRDAI actually asks about: information security policy, access reviews, change management, incident response and the grievance mechanism.
  • Evidence pack assembly, so what you send IRDAI is complete the first time.

Sequencing an ISNP launch

The common mistake is booking the security test the week before the permission application. Testing finds things, fixing them takes development time, and the retest has to fit before submission. We would rather scope the assessment early, run it against a build that is feature-complete but not yet frozen, and give you a remediation window that does not sit on your launch date. Where you are already live and this is the annual cycle, we work to your renewal date and keep the disruption to your platform minimal.

Why CyberSigma for an ISNP audit

We are CERT-In empanelled and PCI QSA authorised, so an insurance platform that also handles card payments can be assessed once against both regimes instead of twice. Testing is manual-led rather than scanner output, findings are proven, and the report is structured for IRDAI's reading rather than as a raw tool export.

Related services

Frequently asked questions

What is the full form of ISNP?

ISNP stands for Insurance Self Network Platform — an electronic platform established by an insurer, intermediary or other applicant, with the permission of IRDAI, to solicit, sell and service insurance products online.

Do we need IRDAI permission before launching our insurance platform?

Yes. An ISNP operates under permission from the authority, and that permission is granted against the platform as built — including a demonstration of its functionality, evidence of security testing, and a working grievance-handling mechanism. Launching first and regularising later is not a route we would advise.

Who is qualified to audit an ISNP?

An external auditor holding a recognised information systems audit qualification — commonly CISA, or a Chartered Accountant with the DISA qualification. Alignment to an information security management standard such as ISO/IEC 27001 is expected alongside. CyberSigma performs the security assessment and evidence work; where a specific signing qualification is required for your filing, we tell you plainly and coordinate rather than overstate what we can sign.

How often does an ISNP need to be audited?

Annually, and again on a need basis — which in practice means after any material change to the platform. A significant new module, a payment-provider change or a re-platforming is not covered by the previous year's audit.

What happens if the audit finds something serious?

Adverse findings capable of affecting policyholders are reported to IRDAI along with an action plan to resolve them. That is why the sequencing matters: finding issues early, in a scoped assessment with time to remediate, is materially better than finding them in the audit that goes to the regulator.

Can one engagement cover ISNP and PCI DSS?

Usually, yes. If your platform takes card payments you may carry PCI DSS obligations alongside the IRDAI ones, and the underlying evidence overlaps heavily. Because we are also a PCI QSA company, we can scope a single engagement producing what each regime needs.

Sources & references

Free tool
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Free resource
Get the free NIST CSF 2.0 readiness checklist
Executive checklist built by our CERT-In empanelled, PCI QSA authorised consultants. Delivered instantly.
Download checklist →

Ready to discuss your ISNP Security Audit requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Talk to an expert →Request a scope review

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →