If you're a broker, corporate agent, TPA or web aggregator working under an IRDAI licence, "cyber security audit" probably sounds like something only the insurer you're contracted to needs to worry about. It isn't. IRDAI's Information and Cyber Security Guidelines (2023) extend obligations to the intermediary layer directly, and increasingly insurers are pushing audit evidence requirements down their vendor chain before renewing contracts.
Why intermediaries got pulled into scope
Intermediaries routinely handle exactly the data IRDAI is trying to protect - policyholder KYC documents, health records for claims processing, payment details - often with weaker security investment than the insurers they serve. The 2023 guidelines close that gap by making outsourced-partner oversight an explicit insurer obligation, which in practice means insurers now ask their brokers and TPAs for audit evidence as a condition of doing business, not just IRDAI asking directly.
What "in scope" actually means for you
- Insurance brokers and corporate agents - anyone handling proposal forms, KYC data or premium payment details
- Third-party administrators (TPAs) - claims processing, hospital network data, health records
- Web aggregators - comparison platforms holding customer contact and policy interest data
- Insurance marketing firms - lead generation and customer outreach systems touching personal data
The compliance guide: five things to get right
1. Data governance, not just data security
Know what personal and financial data you hold, why, for how long, and who can access it. This is the section examiners and insurer procurement teams check first, because it's the easiest to verify from a document review alone.
2. IT infrastructure and access controls
Basic hygiene matters more than exotic controls: multi-factor authentication on systems touching customer data, role-based access, and logging that can reconstruct who accessed what and when.
3. Vendor and sub-outsourcing transparency
If you outsource any part of your operation further (a call centre, a cloud host, a claims software vendor), IRDAI expects you to be able to show the insurer's auditor how that chain is managed.
4. Incident notification readiness
Know your notification obligations - to the insurer you're contracted with and to IRDAI - and have a plan that doesn't start with "let's find out who to call."
5. Independent audit evidence
An annual independent cyber security audit report, scoped to the ICSG 2023 guideline rather than a narrow penetration test, is what most insurers now request during vendor renewal.
What insurers are asking for from intermediaries in 2026
Procurement and compliance teams at insurers increasingly request three specific artifacts before renewing intermediary contracts: a current independent cyber security audit report, a data processing and retention summary, and evidence of an incident response plan. Intermediaries who can produce these on request move through renewal faster and win deals that get stuck for competitors who can't.
How Praxis-Q helps
Praxis-Q's IRDAI Cyber Security Audit is scoped for both insurers and the intermediary layer - brokers, TPAs, web aggregators and agents - covering governance, data protection, technical VAPT and vendor oversight in a single engagement, with a report format insurers' procurement teams recognise.
Frequently asked questions
Do small brokers really need a formal audit?
If you handle policyholder data and hold an IRDAI licence, yes - the guideline doesn't carve out a size exemption, and insurers are applying the requirement uniformly during vendor onboarding regardless of your headcount.
How is this different from the insurer's own audit?
The insurer's audit covers their own systems and governance. Yours covers the data and systems you control as an intermediary - they're complementary, not duplicative, and insurers usually want to see both exist independently.
What's the realistic cost driver?
Scope is the main driver: how many systems process policyholder data, whether claims/health data is involved, and how many sub-vendors are in your chain. A lean broker with a single CRM costs far less to audit than a TPA running claims infrastructure.
Can one audit satisfy multiple insurer relationships?
Yes - a single independent audit report, refreshed annually, is generally accepted across your different insurer relationships rather than needing a separate audit per partner.
Talk to Praxis-Q about scoping your intermediary audit - contact us to get started.
Free Consultation
Ready to Get Compliant?
ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.
Tags
Share this article
Praxis-Q Team
Compliance & Security Expert
Praxis-Q’s compliance and offensive-security practitioners deliver ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR and DPDP engagements for banks, payment gateways and regulated fintechs.
