Skip to main content

Cybersecurity Compliance

IRDAI Cyber Security Guidelines: A Guide for Insurers & Intermediaries

8 min readUpdated June 2026

The Insurance Regulatory and Development Authority of India (IRDAI) requires insurers and intermediaries to implement a structured information and cyber-security program, with periodic audit. If you operate an Insurance Self-Network Platform (ISNP) or handle policyholder data, this guide explains your obligations.

Who IRDAI's cyber guidelines cover

IRDAI's information and cyber-security guidelines apply to insurers, reinsurers and registered intermediaries (brokers, corporate agents, web aggregators and ISNP operators). Obligations scale with the scale and sensitivity of the operation.

Core requirements

  • Board-approved information and cyber-security policy, with a designated CISO
  • Access control, encryption and data classification for policyholder data
  • Security monitoring, incident management and cyber-crisis response
  • Third-party / outsourcing security controls
  • Business continuity and disaster recovery testing
  • Periodic information-security audit and assurance

ISNP audits

Insurance Self-Network Platforms - the digital channels through which insurers and intermediaries sell and service policies online - require specific security audits before and during operation. We audit ISNPs against IRDAI expectations and produce the assurance documentation the regulator requires.

Reaching IRDAI compliance

  • Gap-assess your controls against the IRDAI guidelines
  • Implement governance, access, encryption and incident management
  • Audit your ISNP and core systems (VAPT + configuration review)
  • Test BCP/DR and remediate findings
  • Maintain evidence and periodic assurance for the regulator

Need help with this in practice?

A5 Cyber Nexus audits, remediates and certifies against these frameworks.

Talk to a specialist

Frequently asked questions

What is an ISNP audit?

An Insurance Self-Network Platform (ISNP) audit is a security assessment of the online insurance sales/servicing platform, required by IRDAI. It covers application security (VAPT), configuration and policy controls, with documented assurance.

Make it accessible.
Make it attack-ready.

Prove both before launch.

Bring us your app, audit deadline, or security concern. We'll map the fastest path to WCAG conformance, VAPT coverage, and regulator-ready evidence.

A5 Cardinal character in a futuristic chair