Regulation

IRDAI Information and Cyber Security Guidelines, 2026

IRDAI replaced its 2023 Guidelines on 6 April 2026. What changed for insurers, intermediaries and TPAs: board committees, CISO independence, half-yearly testing, and the third-party obligations.

In short
IRDAI issued the Information and Cyber Security Guidelines, 2026 on 6 April 2026, replacing its 2023 Guidelines and binding all insurers, intermediaries and the Insurance Information Bureau of India. The sharpest changes are structural: the CISO may not report to the head of IT or carry business targets, the risk committee meets quarterly, and gaps must close within twelve months.

The insurance sector had been running on guidelines issued in April 2023. On 6 April 2026, under reference IRDAI/GA&HR/CIR/MISC/51/4/2026, IRDAI replaced them — citing the evolving threat landscape, feedback from the industry and the recommendations of its own committees. The Guidelines and their annexures are published on the IRDAI site, with the amendments to the 2023 position set out separately so an insurer can see exactly what moved.

Who is in scope

The addressees are “All Insurers, Insurance Intermediaries and IIB”, and the intermediary limb is broad. It reaches foreign reinsurance branches, brokers, corporate agents, web aggregators, third-party administrators, insurance marketing firms, insurance repositories, corporate surveyors, motor insurance service providers and the CSC special purpose vehicle, alongside the Insurance Information Bureau of India.

That breadth is the operative fact for most readers. An insurer that has read the Guidelines and mapped its own controls has done perhaps half the work, because a large part of the sector's attack surface sits in the intermediary chain — and every one of those intermediaries is separately in scope rather than covered by the insurer's compliance.

Foreign reinsurance branches get one accommodation. Committees are not required at branch level where the specified governance responsibilities are discharged by the regional or controlling office, and the compliance checklist is rationalised for FRBs as part of the empanelment process.

Governance: three changes a board should read closely

Provision20232026
Information Security Risk Management CommitteeMeets at least twice a yearMeets at least quarterly
Board responsibility for security budgetNot specifiedMust ensure the information security budget is adequate and proportionate to the organisation's risk-bearing capacity
Closing audit gapsNot specifiedBoard obtains the status of non-conformities from the annual assurance audit and risk report, approves time-bound remediation, and ensures gaps close within twelve months of being reported
CISO reporting lineNot specified in these termsNo direct reporting relationship with the head of the IT function, and no business targets
Selected amendments to the 2023 position, from IRDAI's own schedule of changes.

The CISO provisions are the ones to check first

The reporting-line rule is the provision an insurer can fail on an organisation chart, which makes it unusually easy for a board to verify and unusually hard to explain away. The logic is the same one the RBI applies: the person raising a security risk should not report to the person whose delivery timetable that risk inconveniences, and should not be paid on targets the risk would jeopardise.

The Guidelines also give the CISO a defined set of duties:

  • Adequate staffing with relevant technical expertise — the role is not a title held by someone doing it alongside another job.
  • Briefing both the information security risk committee and the board.
  • Reviewing and approving every exception requested to information security policies, standards and procedures, with comment. Exceptions become a logged, owned decision rather than an informal accommodation.
  • Developing and exercising scenario-based response plans for cyber crises, contingencies, disasters and attacks on IT systems.
  • Responsibility for complying with CERT-In directions as they are issued.

Testing, cloud and the supply chain

Beneath the governance sits a substantially expanded control set, carried in the annexures rather than the covering circular. It extends the 2023 position into cloud security, supply chain and third-party controls, data protection aligned to the DPDP regime, and incident response readiness, alongside periodic vulnerability assessment, penetration testing and a continuous audit process. Requirements that need infrastructure work — full encryption coverage in particular — are phased over a longer runway than the governance provisions, which apply immediately.

Insurers should read the annexures directly rather than a summary of them, this one included: the frequencies and remediation windows are stated per control, and they differ.

The third-party obligation is the commercially significant one

Insurance runs on an intermediary chain — brokers, corporate agents, web aggregators, TPAs handling claims and health data, repositories holding policy records, marketing firms with customer contact. The Guidelines require third parties to be classified and overseen by risk tier, with cloud provider compliance and contractual safeguards validated rather than assumed.

That is a materially harder obligation than it reads, because the assurance model most insurers inherited is an annual questionnaire. A TPA's security posture can deteriorate in a fortnight, and nothing in a filed questionnaire will detect it. Third-party risk management for Indian BFSI sets out what replaces it.

The DPDP interlock

Insurers hold some of the most sensitive personal data in the economy — health records, financial position, nominee and family detail — so the Guidelines and the DPDP regime meet squarely. The DPDP Rules 2025 phase to full compliance by 13 May 2027, and the data protection provisions here run alongside them rather than in place of them. Neither can be discharged by satisfying the other, and the CERT-In six-hour reporting clock applies on top of both.

Reference, date, addressees and the amendments described above are read from IRDAI's covering circular IRDAI/GA&HR/CIR/MISC/51/4/2026 of 6 April 2026 and its schedule of amendments, published at the link above; the guidelines supersede those issued under IRDAI/GA&HR/GDL/MISC/88/04/2023 of 24 April 2023. The detailed control set sits in the annexures and should be read in full. Every instrument cited here was verified against the issuing regulator's own notification on . This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.

Where BitScore fits, and where it does not

Two obligations in the Guidelines are hard to discharge from inside the organisation alone, and both are ones an external, continuously calculated measurement speaks to.

  • Third-party classification and oversight by risk tier. A tier assigned from a continuously observed external rating is a measurement of the intermediary rather than an assertion by it, and it updates between review cycles instead of at them. It also gives a defensible basis for the minimum standard written into a TPA or broker contract.
  • Board reporting on posture and gap closure. The twelve-month clock needs a measurement that moves visibly between board meetings. An independent, benchmarked, trended number is something a board can interrogate; a status narrative is not.

What a rating does not do is satisfy these Guidelines. It is not a vulnerability assessment, not a penetration test, not an assurance audit, and it says nothing about encryption, access control, incident response capability or consent architecture. It evidences external hygiene and supports third-party due diligence. Presented to IRDAI as compliance, it would be a serious misreading of both the Guidelines and the rating.

For a worked example in the sector, Axis Max Life Insurance reached a Bitsight rating of 810 and replaced its manual vendor questionnaires with continuous monitoring — the case study sets out how the vendor tiering was structured.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ