IRDAI Information and Cyber Security Guidelines

IRDAI BFSI Guideline Active 1 Jan 2023

Applies to: Insurers and insurance intermediaries

The insurance-sector cyber overlay. The guidelines mandate a designated CISO, a board-approved information-security policy, periodic risk assessment, VAPT, and incident reporting aligned to the 6-hour national baseline. They emphasise data integrity and confidentiality given the volume of sensitive health and financial data insurers hold, and require audit and assurance through CERT-In empanelled auditors. As with the other financial regulators, the DPDP Act adds a parallel data-protection compliance layer that insurers must operationalise ahead of May 2027.
Why it matters
Insurers carry a double sensitivity load — health plus financial data — which makes them a natural early SDF candidate under DPDP and a high-value target for the AI-driven attacks CERT-In flagged in May. The mandatory-CISO requirement is long-standing, so examiners have moved past existence to effectiveness: board authority, reporting line and demonstrated incident-response practice are what get tested. Read this guideline alongside the DPDP Rules, not on its own — the consent and erasure obligations landing in 2027 will reshape how insurers handle claims and underwriting data.