IRDAI ISNP Audit
Mandatory annual Information Security and VAPT audits for Insurance Self-Network Platforms (ISNP), Web Aggregators, Corporate Agents, and Insurance Brokers under IRDAI Guidelines on Information and Cyber Security (April 2023).
Request IRDAI ISNP Audit
Receive statutory insurance audit proposal in 4 hours
6 Core Pillars of IRDAI ISNP Cyber Auditing
Our certified insurance cybersecurity auditors ensure your digital insurance platforms satisfy all IRDAI mandates, protecting policyholder data integrity.
ISNP Web & Mobile App VAPT
Comprehensive penetration testing of online policy quotation engines, e-Insurance Accounts (eIA), payment gateway callbacks, and customer KYC portals.
- Policy purchase & payment gateway VAPT
- e-KYC document upload tampering checks
- Customer self-service portal auth review
Policyholder SPDI Data Protection
Verifying AES-256 database encryption for medical history, bank account details, PAN/Aadhaar masking, and cryptographic key management practices.
- Aadhaar & PAN number masking audits
- Sensitive Personal Data (SPDI) encryption
- TLS 1.3 cipher suite validation
InsurTech & Broker API Security
Auditing RESTful APIs connecting web aggregators, brokers, telematics trackers, and insurance core administrative systems (PAS) for authentication flaws.
- B2B insurer partner API penetration tests
- API token authorization & rate limiting
- Web Aggregator data feeds isolation
CISO Governance & CCMP Plans
Reviewing Information Security Committee (ISC) charters, CISO board reporting, annual Cyber Crisis Management Plans (CCMP), and cyber insurance coverage.
- Board Information Security Committee review
- Annual Cyber Crisis Management Plan (CCMP)
- Cyber insurance policy scoping validation
SOC Operations & IRDAI Reporting
Verifying 24/7 Security Operations Center (SOC) logging, SIEM rule coverage, and ensuring strict compliance with mandatory IRDAI/CERT-In incident notification rules.
- 24/7 continuous SOC monitoring verification
- Cyber incident reporting runbook audit
- 180-day tamper-proof audit log storage
Form A / SAR Filing & Certificate
Delivering digitally-signed System Audit Reports (SAR) with complete executive checklists, CERT-In Safe-to-Host certificates, and filing documents for the IRDAI portal.
- Digitally-signed Form A statutory report
- Official CERT-In Safe-to-Host Certificate
- Complete IRDAI regulatory filing submission pack
5-Stage IRDAI ISNP Audit Lifecycle
Our certified auditors follow a proven compliance roadmap designed to achieve zero-deficiency filings with the insurance regulator.
Architecture & Core PAS Integration Scoping
Cataloging all customer-facing ISNP portals, mobile apps, broker aggregators, and core policy administration systems (PAS) subject to IRDAI guidelines.
Evidence Collection & CISO Governance Review
Reviewing Information Security policies, CISO board reporting, third-party InsurTech contracts, and 180-day domestic log archival practices.
Safe-to-Host VAPT & InsurTech API Probes
Conducting comprehensive penetration testing across web/mobile portals and auditing policyholder data encryption and Aadhaar masking.
Vulnerability Remediation & Closure Attestation
Assisting engineering teams with vulnerability patches and conducting free 30-day retesting to ensure 100% closure of all High/Medium findings.
Digitally Signed SAR & Safe-to-Host Certificate
Delivering the formal digitally-signed Form A System Audit Report and CERT-In Safe-to-Host Certificate ready for upload to the IRDAI regulatory portal.
Frequently Asked Questions
Key details on ISNP audit applicability, CERT-In requirements, and IRDAI submission binders.