The Insurance Regulatory and Development Authority of India (IRDAI) issued its Information and Cyber Security Guidelines in 2023, and since then every insurer, reinsurer, broker, third-party administrator (TPA) and web aggregator it regulates has carried a standing obligation: an independent cyber security audit, conducted at least once a year, with findings reported to the Board. Many compliance teams are still treating this as a paperwork exercise their existing VAPT vendor already covers. It doesn't, and finding that out during a supervisory review is the expensive way to learn it.
Who the IRDAI audit applies to
The guidelines apply broadly across the regulated ecosystem: life, general and health insurers, reinsurers operating in India, insurance brokers, corporate agents, TPAs handling claims and policyholder data, web aggregators, and insurance marketing firms. If your entity holds an IRDAI licence or processes policyholder data on behalf of one that does, the audit obligation reaches you - including outsourced service providers under the guideline's third-party risk provisions.
What a standard VAPT report is missing
A penetration test report tells you which systems have exploitable vulnerabilities. IRDAI's guidelines ask a wider question: does the organisation have governance, accountability and data protection controls that make security durable, not just a system that passed one test. A VAPT-only submission typically leaves gaps in three areas auditors check first.
| IRDAI ICSG 2023 requirement | Typical VAPT-only gap |
|---|---|
| Board-level cybersecurity accountability | No documented reporting line or committee ownership |
| Policyholder data protection controls | Data flow and retention mapping absent |
| Outsourced vendor / TPA oversight | No vendor risk register or contractual security clauses |
| Incident response & breach notification | No tested playbook or notification timeline mapped to IRDAI expectations |
The 2026 pre-audit checklist
1. Governance and accountability
Confirm a named individual or committee owns cybersecurity at Board level, that policies are reviewed annually, and that minutes show cybersecurity was actually discussed - not just filed.
2. Data protection and policyholder data mapping
Map where policyholder PII and health data live, who can access it, and how long it's retained. IRDAI examiners increasingly cross-reference this against DPDP Act obligations, so the two efforts should be run together, not separately.
3. Technical security controls
VAPT of policy administration systems, customer-facing portals, claims processing systems and any third-party API integrations (payment gateways, KYC providers, hospital networks for health claims) - this is the layer most teams already have, but scope often misses claims and TPA integration points.
4. Third-party and outsourcing risk
Build or update a vendor register covering every TPA, IT service provider and outsourced call centre that touches policyholder data. IRDAI expects contractual security obligations to flow down to these vendors, not stop at your own perimeter.
5. Incident response readiness
A written, tested incident response plan with clear escalation and notification timelines. "We'll figure it out when it happens" does not satisfy the guideline, and auditors ask for evidence of at least a tabletop exercise.
What the audit report needs to look like
The finished report has to be regulator-submission-ready: scoped against the ICSG 2023 clauses explicitly, with findings mapped to governance, data protection, technical and outsourcing domains separately rather than bundled into a generic pentest writeup, and a remediation roadmap with realistic timelines the Board can sign off on. Praxis-Q's IRDAI Cyber Security Audit service is built around exactly this scope - governance review, policyholder data controls, technical VAPT and outsourcing risk, delivered as a single IRDAI-format report.
Frequently asked questions
How long does an IRDAI cyber security audit take?
For a mid-sized insurer or intermediary, plan for 3-5 weeks end to end: scoping, control assessment, technical testing and report delivery. Larger insurers with multiple business lines or TPA networks should budget more.
Does IRDAI accept a report from any auditor?
The guidelines require an independent audit; they don't mandate a specific empanelment list the way RBI does for banks. That said, examiners scrutinise reports that read as a rebadged generic VAPT deliverable, so scope and format matter as much as the auditor's credentials.
What happens if we miss the annual audit deadline?
Non-compliance exposes the entity to regulatory action under IRDAI's supervisory powers, and can surface as a licence condition or delay in unrelated approvals such as new product filings.
Can this audit double up for DPDP Act compliance?
Largely yes for the data protection sections - policyholder data mapping, consent and retention controls overlap heavily with DPDP Act obligations, so running both assessments together avoids duplicate work.
Ready to scope your IRDAI audit? Get in touch with Praxis-Q to start the conversation.
Free Consultation
Ready to Get Compliant?
ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.
Tags
Share this article
Praxis-Q Team
Compliance & Security Expert
Praxis-Q’s compliance and offensive-security practitioners deliver ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR and DPDP engagements for banks, payment gateways and regulated fintechs.
