+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

IRDAI's cyber security rules and insurance software

Security By Mits Engineering Team 2 min read
IRDAI's cyber security rules and insurance software

The IRDAI issued its Information and Cyber Security Guidelines on 24 April 2023, and their scope is considerably wider than the word insurer suggests. They apply to regulated entities across the sector: insurers, brokers, foreign reinsurance businesses, corporate agents, web aggregators, third-party administrators, insurance marketing firms, insurance repositories, insurance self-network platforms, corporate surveyors, motor insurance service providers, common service centres and the Insurance Information Bureau of India. If you build software for any of those, your client is inside the perimeter and your product is part of how they comply.

The governance structure is prescribed rather than suggested, and it is unusually specific. Three bodies carry responsibility: the Board, a Risk Management Committee, and an Information Security Risk Management Committee. The ISRMC is composed of named roles — the CTO, CITSO, CRO, CSO, CISO and CHRO — and must meet at least twice a year, with the CISO and at least two other members present. For a small insurtech, that is a real organisational commitment, and it is the sort of requirement that is easier to establish early than to retrofit before an inspection.

Data localisation applies with a distinction worth getting right. Non-insurer regulated entities must store ICT infrastructure logs, critical data and business data in India. Insurers must store primary data in India under separate regulations. In practice this means the same architectural discipline as the RBI's payment data rules: map where every copy of the data actually rests, including the ones in your logging vendor, your error tracker, your analytics warehouse and your support tooling, because those are where the findings come from rather than the primary database.

For a software vendor rather than a regulated entity, the useful framing is that you are supplying a component of somebody else's compliance obligation. That changes what you should offer proactively: documentation of your security controls, evidence of periodic security audits, a clear subprocessor list, defined incident notification commitments, and access controls granular enough that your client can demonstrate who could see what. A vendor who arrives with that pack shortens their client's audit and wins the renewal.

The incident path deserves particular attention because it is layered. An insurance sector entity notifies IRDAI under these guidelines and separately notifies CERT-In under the April 2022 Directions, which carry the six-hour clock. Two obligations, different recipients, overlapping timelines. Your product should be able to supply the facts each one needs — what happened, when it was noticed, which records were affected — quickly enough to be useful within those windows.

The commercial observation is that insurance technology in India has become a compliance-led market. Buyers evaluate on security posture earlier in the process than they used to, and a vendor who can speak fluently about the ISRMC structure, the localisation requirement and the audit cadence is treated differently from one who cannot. That fluency is cheap to acquire relative to what it unlocks.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security