Amendments to the Guidelines on Information and Cyber Security for Insurers


Quick Summary
The Insurance Regulatory and Development Authority of India (IRDAI) has updated its Information and Cyber Security Guidelines for insurers. These amendments focus on enhancing the Vulnerability Assessment and Penetration Testing (VAPT) process for ICT infrastructure and applications, introducing more frequent testing cycles and stricter timelines for closing identified security gaps. Additionally, the guidelines clarify the procedures and frequency for conducting annual Information System Audits and closing any audit-related gaps.

Insurance Regulatory and Development Authority of India

Ref. No: IRDA/IT/CIR/MISC/301/12/2020

Date:30-12-2020

Amendments to the Guidelines on Information and Cyber Security for Insurers dated 07.04.2017

To

All insurers,

Re:  Amendments to the Guidelines on Information and Cyber Security for Insurers dated 07.04.2017

IRDAI vide its Ref. No: IRDA/IT/GDL/MISC/082/04/2017 dated 07-4-2017 had issued Information and Cyber Security Guidelines containing comprehensive cyber security framework for Insurance sector for the purpose of implementing appropriate mechanism to mitigate cyber risks

Based on the review of the compliance process for cyber security by insurers and their subsequent feedback, the following sections of guidelines are amended as below.

14. PLATFORM/INFRASTRUCTURE SECURITY.

As per the action point 14.1 of the Guidelines, the Vulnerability Assessment and Penetration Testing (VAPT) on the entire ICT infrastructure should be conducted by the insurers on a periodic basis. Also, VA & PT has to be conducted on the software applications whenever there are changes in the configurations/applications.

In order to streamline the security assessment process, the following sub sections are added to Section 14.

14.3 Procedure for conducting VA&PT

(a) VA&PT of the entire ICT infrastructure components should be conducted annually in every financial year.

(b) Every VA&PT shall have two test cycles one at the beginning of VA&PT for identification of gaps and to check for known vulnerabilities, and a retesting post closure of vulnerabilities identified.

(c) VA&PT of critical applications should be conducted annually in every financial year. The remaining applications should be conducted once in a two-year cycle.

(d) VA&PT of all internet facing applications and Infrastructure components should be conducted at least once in a six months.

(e) An assessment of the need for security testing should be conducted whenever any change is made to any internet facing applications or to any infrastructure component irrespective of the magnitude of change.

(f) Mandatory security testing should be conducted in case of all applications and related infrastructure components so as to check for known vulnerabilities once initially and again whenever major changes in internet facing applications and related infrastructure components take place. However, all Internet facing applications should be tested for all major and minor changes either through internal or external VA, and any gap found must be closed.

(g) The Cycle of the above security testings should be aligned with Annual assurance audit.

14.4 Closure of VA&PT gaps

(a) Closure of identified gaps in critical applications should be completed within one month. This includes confirmatory testing to ensure that the identified gaps have been successfully closed.

(b) Similarly, closure of identified gaps in other remaining applications should be completed within two months. Confirmatory testing should also be done to ensure closure of such identified gaps.

(c) For closure of identified gaps in all internet facing applications and Infrastructure components, External Black Box Penetration Testing should be done within one month, followed by confirmatory testing to ensure closure of such identified gaps.

(d) Closure of identified gaps in the entire ICT infrastructure components during internal vulnerability scan should be done immediately and without any loss of time.

(e) Insurers should classify the VA&PT gaps based on their risk assessment, Priority should be given to the high risk issues. In case any high risk issue is not resolved within the prescribed timeline. The matter should be reported to the Risk Management Committee of the Board for deliberation and guidance.

23. INFORMATION SYSTEM AUDIT

Section 23.3 Frequency of Conducting Assurance Audit is amended as follows Assurance Audit shall be carried out annually for every financial yearthrough a qualified external systems Auditor holding certifications like CISA/DISA/Cert-in empanelled Auditors. Insurers shall indicate the specific quarter of the FY in which they would commence and complete their annual comprehensive assurance audit. Once the quarter is decided, the annual cyber security audit should be conducted during that quarter in every financial year.

The following Sub-section is newly added to Section23:

23.7 Procedure for closure of audit gaps

(a) Closure of reported audit gaps shoulddepend on the severity of the gaps and their impact on the overall service delivery, security, ensuring confidentiality of PII data, scope/coverage of implementation etc.

(b) Insurers should evaluate on the merits of issues based on the complexity of gaps and identify closure timelines as soon as possible, commit the same as a part of audit summary to be submitted to IRDAI.

(c) The major deficiencies/aberrations noticed during audit should be highlighted in a special note and given immediately to the Information Security Committee(ISC) and IT Department. Minor irregularities pointed out by the auditors are to be rectified immediately.

(d) Timelines for closure of audit gaps based on risk/impact of the reported gaps including the controls implemented in the interim to reduce the level of risk exposure will be put-up to Risk Management Committee of the Board through Information Security Committee (ISC).

(e) The outer time limit for closure of audit gaps is two months. However, priority for closure of gaps should be decided based on risks associated with each gap.

(f)Insurer should submit the closure report to IRDAI on the identified audit gaps within two months of completion of Annual Assurance Audit.

(g) Insurer need not wait completion of assurance audit to close the audit gaps. As soon as any gap is noticed during the course of the audit, effort should be made to close the gaps.

FAQ :

The amendments primarily concern the frequency and procedure for Vulnerability Assessment and Penetration Testing (VAPT) of ICT infrastructure and applications, as well as the process and timelines for closing identified audit gaps.

VAPT of the entire ICT infrastructure must be conducted annually. Critical applications require annual VAPT, while other applications need it once every two years. Internet-facing applications and infrastructure components must be tested at least every six months.

Gaps in critical applications must be closed within one month, and in other applications within two months. For internet-facing applications and infrastructure, external black box penetration testing and closure must be done within one month. Gaps from internal scans should be closed immediately.

An Assurance Audit must be carried out annually for every financial year by a qualified external systems auditor.

The outer time limit for closing audit gaps is two months from the completion of the Annual Assurance Audit, though insurers are encouraged to close gaps as soon as they are identified.

If any high-risk VAPT issue is not resolved within the prescribed timeline, the matter should be reported to the Risk Management Committee of the Board for deliberation and guidance.

 
Notification No : Ref. No: IRDA/IT/CIR/MISC/301/12/2020
Source : https://www.irdai.gov.in/ADMINCMS/cms/whatsNew_Layout.aspx?page=PageNo4315&flag=1



News posted by

Finance news reporter covering taxation, GST, income tax, business compliance, and economy updates. I simplify complex financial topics into easy-to-understand articles for professionals, taxpayers, and business owners on leading finance and tax platforms.

Comments



CCI Pro





Company
15 September 2026
Client-site CA associate

Aditya Muley and Co

Mumbai

CA

View Details
Company
ARTICLESHIP 16 September 2026
Article Assistant

MANUJ SHARMA AND COMPANY

Noida

CA Inter

View Details
Company
17 September 2026
Chartered Accountant

Dass Gupta & Associates

Gurgaon

CA

View Details
Company
08 October 2026
Account Executive

Elite Taxation

New Delhi

CA Foundation

View Details
Company
ARTICLESHIP 16 September 2026
CA Article Trainee

SR BAGAI & Co.

New Delhi

CA Inter

View Details
Company
Featured 12 September 2026
Assistant Manager - Finance & Compliance

Naveen Fintech Pvt Ltd

Kolkata

CA Inter

View Details
Company
22 September 2026
Account Assistant

Chirag P Shah & Co. Chartered Accountant

Pune

B.Com

View Details
Company
20 September 2026
Semi Qualified CA

Navin & Associates

Mumbai

CA Inter

View Details