Now partnering with TechDefence to deliver stronger cyber security outcomes — Learn more

Cyber News
All news →
Compliance · IRDAI

IRDAI cyber security guidelines compliance

The Insurance Regulatory and Development Authority of India (IRDAI) expects insurers and insurance intermediaries to run a documented information and cyber security programme with board oversight.

Overview

In plain English

The guidelines cover governance, risk assessment, technical controls, incident management and periodic audit, and they align with CERT-In reporting obligations.

Instruments covered

  • IRDAI Information and Cyber Security Guidelines, 2023

Last reviewed:

Key requirements

What IRDAI expects

  1. Governance and roles

    Board-approved information and cyber security policy and a designated CISO or equivalent responsible official.

  2. Risk assessment

    Periodic assessment of information and cyber security risks across systems and vendors.

  3. Technical controls

    Controls for access, data protection, network security, application security and endpoint security.

  4. Logging and monitoring

    Logging and monitoring of systems, aligned with CERT-In log retention expectations.

  5. Incident management

    Incident response procedures and reporting of cyber incidents, including to CERT-In within prescribed timelines.

  6. Periodic audit

    Regular information and cyber security audit, with findings reported and closed.

How TrustNet helps

From gap to evidence

  • Gap assessment against the IRDAI guidelines
  • Audit preparation and support
  • VAPT of policy, claims and customer-facing systems
  • Incident readiness and reporting playbooks
  • Policy suite drafting

Official sources

Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.

Services mapped to IRDAI

FAQ

IRDAI FAQ

Do the IRDAI guidelines apply to brokers?

They apply to insurers and insurance intermediaries as specified by IRDAI. We help you confirm your obligations.

How often is an audit needed?

The guidelines require periodic audit. We help you plan the audit cycle and prepare evidence.

Do we still need to report to CERT-In?

Yes. Insurers are also covered by the CERT-In Directions, so incident reporting to CERT-In applies alongside IRDAI requirements.

Book a consultation

Get IRDAI-ready

We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.

support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438

Under attack right now? Go to emergency help →

Today in Cyber

What's happening in cyber security

See all news →

Source: The Hacker News — headlines only, each linking to the original article.

Chat with us