IRDAI
IRDAI Information and Cyber Security Guidelines
Information and cyber-security for India's insurers and intermediaries.
Issuer
IRDAI
Region
India
Scope
Information & cyber security
Applies to
Insurers & intermediaries
Overview
What is IRDAI?
The IRDAI Information and Cyber Security Guidelines set the security expectations for insurers and insurance intermediaries. They cover governance (a board-approved policy, a CISO and an Information Security Committee), risk management, access control, network and application security, data protection, monitoring and incident response.
They place particular weight on protecting policyholder data, third-party/outsourcing controls, periodic VAPT and security audit, business continuity, and reporting cyber incidents to IRDAI and CERT-In within prescribed timelines.
Who needs it: Insurers and insurance intermediaries regulated by IRDAI — life, general and health insurers, and the brokers and intermediaries serving them.
Inside the framework
What it covers
Governance
Board-approved policy, a CISO, and an Information Security Committee.
Access & infrastructure
Role-based access, MFA, network segmentation and secure configuration.
Application & data security
Secure SDLC, encryption, and policyholder-data privacy.
Detection & response
Monitoring, VAPT, incident response and reporting to IRDAI / CERT-In.
Continuity & assurance
Business continuity, security audit and awareness training.
With RegShield
Get IRDAI-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right IRDAI controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for IRDAI is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your IRDAI readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Who does this apply to?
Insurers (life, general, health) and insurance intermediaries regulated by IRDAI. The depth of controls scales with the entity's size and risk.
How is it different from ISO 27001?
It follows the same security fundamentals but adds insurance-specific expectations — policyholder-data protection and reporting to IRDAI. ISO 27001 / SOC 2 evidence carries over, and RegShield reuses it.
Does RegShield certify us?
No. RegShield maps evidence, scores readiness and produces the gap list and audit-ready reports. The security audit and IRDAI filings are completed by you and your auditor.