Cybersecurity Compliance
IRDAI Cyber Security Guidelines: A Guide for Insurers & Intermediaries
The Insurance Regulatory and Development Authority of India (IRDAI) requires insurers and intermediaries to implement a structured information and cyber-security program, with periodic audit. If you operate an Insurance Self-Network Platform (ISNP) or handle policyholder data, this guide explains your obligations.
Who IRDAI's cyber guidelines cover
IRDAI's information and cyber-security guidelines apply to insurers, reinsurers and registered intermediaries (brokers, corporate agents, web aggregators and ISNP operators). Obligations scale with the scale and sensitivity of the operation.
Core requirements
- Board-approved information and cyber-security policy, with a designated CISO
- Access control, encryption and data classification for policyholder data
- Security monitoring, incident management and cyber-crisis response
- Third-party / outsourcing security controls
- Business continuity and disaster recovery testing
- Periodic information-security audit and assurance
ISNP audits
Insurance Self-Network Platforms - the digital channels through which insurers and intermediaries sell and service policies online - require specific security audits before and during operation. We audit ISNPs against IRDAI expectations and produce the assurance documentation the regulator requires.
Reaching IRDAI compliance
- Gap-assess your controls against the IRDAI guidelines
- Implement governance, access, encryption and incident management
- Audit your ISNP and core systems (VAPT + configuration review)
- Test BCP/DR and remediate findings
- Maintain evidence and periodic assurance for the regulator
Need help with this in practice?
A5 Cyber Nexus audits, remediates and certifies against these frameworks.
Frequently asked questions
What is an ISNP audit?
An Insurance Self-Network Platform (ISNP) audit is a security assessment of the online insurance sales/servicing platform, required by IRDAI. It covers application security (VAPT), configuration and policy controls, with documented assurance.
Make it accessible.
Make it attack-ready.
Prove both before launch.
Bring us your app, audit deadline, or security concern. We'll map the fastest path to WCAG conformance, VAPT coverage, and regulator-ready evidence.
