IRDAI ISNP & INSURANCE CYBERSECURITY AUDIT

IRDAI ISNP Audit

Mandatory annual Information Security and VAPT audits for Insurance Self-Network Platforms (ISNP), Web Aggregators, Corporate Agents, and Insurance Brokers under IRDAI Guidelines on Information and Cyber Security (April 2023).

IRDAI April 2023
Cyber Security Guidelines Aligned
ISNP & Brokers
Web Aggregators & InsurTech
CERT-In Empanelled
Official Safe-to-Host SAR

Request IRDAI ISNP Audit

Receive statutory insurance audit proposal in 4 hours

6 Core Pillars of IRDAI ISNP Cyber Auditing

Our certified insurance cybersecurity auditors ensure your digital insurance platforms satisfy all IRDAI mandates, protecting policyholder data integrity.

ISNP Web & Mobile App VAPT

Comprehensive penetration testing of online policy quotation engines, e-Insurance Accounts (eIA), payment gateway callbacks, and customer KYC portals.

  • Policy purchase & payment gateway VAPT
  • e-KYC document upload tampering checks
  • Customer self-service portal auth review

Policyholder SPDI Data Protection

Verifying AES-256 database encryption for medical history, bank account details, PAN/Aadhaar masking, and cryptographic key management practices.

  • Aadhaar & PAN number masking audits
  • Sensitive Personal Data (SPDI) encryption
  • TLS 1.3 cipher suite validation

InsurTech & Broker API Security

Auditing RESTful APIs connecting web aggregators, brokers, telematics trackers, and insurance core administrative systems (PAS) for authentication flaws.

  • B2B insurer partner API penetration tests
  • API token authorization & rate limiting
  • Web Aggregator data feeds isolation

CISO Governance & CCMP Plans

Reviewing Information Security Committee (ISC) charters, CISO board reporting, annual Cyber Crisis Management Plans (CCMP), and cyber insurance coverage.

  • Board Information Security Committee review
  • Annual Cyber Crisis Management Plan (CCMP)
  • Cyber insurance policy scoping validation

SOC Operations & IRDAI Reporting

Verifying 24/7 Security Operations Center (SOC) logging, SIEM rule coverage, and ensuring strict compliance with mandatory IRDAI/CERT-In incident notification rules.

  • 24/7 continuous SOC monitoring verification
  • Cyber incident reporting runbook audit
  • 180-day tamper-proof audit log storage

Form A / SAR Filing & Certificate

Delivering digitally-signed System Audit Reports (SAR) with complete executive checklists, CERT-In Safe-to-Host certificates, and filing documents for the IRDAI portal.

  • Digitally-signed Form A statutory report
  • Official CERT-In Safe-to-Host Certificate
  • Complete IRDAI regulatory filing submission pack

5-Stage IRDAI ISNP Audit Lifecycle

Our certified auditors follow a proven compliance roadmap designed to achieve zero-deficiency filings with the insurance regulator.

1
STAGE 1: ISNP PLATFORM SCOPING & ASSET MAPPING

Architecture & Core PAS Integration Scoping

Cataloging all customer-facing ISNP portals, mobile apps, broker aggregators, and core policy administration systems (PAS) subject to IRDAI guidelines.

2
STAGE 2: GOVERNANCE & IRDAI CHECKLIST AUDIT

Evidence Collection & CISO Governance Review

Reviewing Information Security policies, CISO board reporting, third-party InsurTech contracts, and 180-day domestic log archival practices.

3
STAGE 3: TECHNICAL VAPT & SPDI ENCRYPTION AUDIT

Safe-to-Host VAPT & InsurTech API Probes

Conducting comprehensive penetration testing across web/mobile portals and auditing policyholder data encryption and Aadhaar masking.

4
STAGE 4: REMEDIATION & 30-DAY RETESTING VERIFICATION

Vulnerability Remediation & Closure Attestation

Assisting engineering teams with vulnerability patches and conducting free 30-day retesting to ensure 100% closure of all High/Medium findings.

5
STAGE 5: SYSTEM AUDIT REPORT & IRDAI PORTAL SUBMISSION

Digitally Signed SAR & Safe-to-Host Certificate

Delivering the formal digitally-signed Form A System Audit Report and CERT-In Safe-to-Host Certificate ready for upload to the IRDAI regulatory portal.

Frequently Asked Questions

Key details on ISNP audit applicability, CERT-In requirements, and IRDAI submission binders.

Under IRDAI Regulations, all Insurance Companies (Life, General, Health), Insurance Web Aggregators, Insurance Brokers, and Corporate Agents operating an Insurance Self-Network Platform (ISNP) to sell or service policies online must conduct an annual cybersecurity audit.
Key requirements include mandatory annual Safe-to-Host VAPT by CERT-In empanelled auditors, two-factor authentication (2FA) for admin access, masking of Aadhaar/PAN identifiers, end-to-end encryption of policyholder data, and continuous 24/7 SOC monitoring.
We deliver the formal digitally-signed Form A System Audit Report (SAR), Executive Summary for the Board Risk Committee, CERT-In Safe-to-Host Certificate, and a complete remediation closure matrix formatted specifically for IRDAI portal upload.

Achieve 100% IRDAI ISNP Compliance & Safe-to-Host Certification

Schedule an IRDAI ISNP / Insurance Information Security Audit Consultation with our Certified Lead Auditors (CISA, CISSP, ISO 27001 LA).

Book a Free Consultation