India

IRDAI

IRDAI Information and Cyber Security Guidelines

Information and cyber-security for India's insurers and intermediaries.

Map your IRDAI evidence →All frameworks

Issuer

IRDAI

Region

India

Scope

Information & cyber security

Applies to

Insurers & intermediaries

Overview

What is IRDAI?

The IRDAI Information and Cyber Security Guidelines set the security expectations for insurers and insurance intermediaries. They cover governance (a board-approved policy, a CISO and an Information Security Committee), risk management, access control, network and application security, data protection, monitoring and incident response.

They place particular weight on protecting policyholder data, third-party/outsourcing controls, periodic VAPT and security audit, business continuity, and reporting cyber incidents to IRDAI and CERT-In within prescribed timelines.

Who needs it: Insurers and insurance intermediaries regulated by IRDAI — life, general and health insurers, and the brokers and intermediaries serving them.

Inside the framework

What it covers

1

Governance

Board-approved policy, a CISO, and an Information Security Committee.

2

Access & infrastructure

Role-based access, MFA, network segmentation and secure configuration.

3

Application & data security

Secure SDLC, encryption, and policyholder-data privacy.

4

Detection & response

Monitoring, VAPT, incident response and reporting to IRDAI / CERT-In.

5

Continuity & assurance

Business continuity, security audit and awareness training.

With RegShield

Get IRDAI-ready in a fraction of the time

AI evidence mapping

Upload a policy, screenshot, or config and RegShield maps it to the right IRDAI controls in seconds — with confidence scores you can defend in front of an auditor.

Reuse across frameworks

Evidence you collect for IRDAI is automatically reused across every other framework you've activated — so the work compounds instead of repeating.

Gaps & audit-ready reports

See your IRDAI readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.

FAQ

Common questions

Who does this apply to?

Insurers (life, general, health) and insurance intermediaries regulated by IRDAI. The depth of controls scales with the entity's size and risk.

How is it different from ISO 27001?

It follows the same security fundamentals but adds insurance-specific expectations — policyholder-data protection and reporting to IRDAI. ISO 27001 / SOC 2 evidence carries over, and RegShield reuses it.

Does RegShield certify us?

No. RegShield maps evidence, scores readiness and produces the gap list and audit-ready reports. The security audit and IRDAI filings are completed by you and your auditor.

Make compliance
disappear.

Twenty-minute demo. Bring a policy document. We'll map it live.

Book a demo →info@regshield.in