IRDAI cybersecurity compliance for insurance brokers is not optional, and it is not lighter than it is for insurers. If you hold policyholder data, the full framework applies. Here is exactly what you must do, and how a lean team meets it.
The short answer
IRDAI cybersecurity compliance for insurance brokers comes from the IRDAI Information and Cyber Security Guidelines, which bind every IRDAI-regulated intermediary that handles policyholder data, not just insurers. The core duties are board-level governance with an Information Security Risk Management Committee, an independent CISO, VAPT at least annually with six-monthly external penetration testing, critical incident reporting to CERT-In within six hours, an annual assurance audit by a CERT-In empanelled auditor, and third-party risk management. Accountability stays with the broker even when work is outsourced.
On this page
What IRDAI cybersecurity compliance for insurance brokers covers
A frequent misconception is that the IRDAI cyber rules are mainly for insurers. They are not. The IRDAI Information and Cyber Security Guidelines, issued by the Insurance Regulatory and Development Authority of India, bind every regulated intermediary that touches policyholder data, brokers, third-party administrators, web aggregators, and corporate agents included. If your broking firm collects, stores, or processes customer or policy data, the guidelines apply to you in full, and IRDAI checks adherence through its inspection and audit process.
The core obligations for insurance brokers under IRDAI
The guidelines are broad, but the practical substance comes down to a recognisable set of controls that a broker has to run and evidence.
In practice that means constituting an Information Security Risk Management Committee with board-level oversight, appointing a Chief Information Security Officer whose role sits outside the IT function, running a vulnerability assessment and penetration testing programme, reporting critical incidents within six hours, completing an annual assurance audit through a CERT-In empanelled auditor, and managing third-party risk across every vendor that handles your data. A structured VAPT programme is usually the quickest way to evidence the testing pillar.
Testing and remediation
Testing is where compliance becomes an ongoing discipline rather than a one-time exercise, and the remediation clock is strict.
Brokers must conduct VAPT at least once a year, and layer six-monthly external, black-box penetration testing on internet-facing assets on top of it. Critically, high and critical findings have to be closed within thirty days, and an internet-facing application still carrying a high-severity finding past that window is a common inspection failure. Running the test is only half of it, the remediation and the evidence of closure are what an assurance audit actually checks. Note that an automated scan alone does not satisfy this, our guide on VAPT versus vulnerability scanning explains why.
Incident reporting
The reporting rules are tight and measured from detection, which makes monitoring, not paperwork, the real requirement.
Critical cyber incidents, such as a data breach or ransomware, must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and all other incidents within twenty-four hours, in the prescribed format. Because the clock starts at detection, a broker that learns of an incident from a customer has already missed it. Meeting the six-hour window is really a demand for continuous monitoring that catches and confirms an incident fast, which is why detection capability is where lean broking teams are most exposed.
Vendor risk and accountability
Brokers rely heavily on technology vendors and platforms, and the guidelines are clear that outsourcing the work never outsources the responsibility. Third-party risk management is mandatory: a pre-contract security assessment of each vendor, contractual clauses covering data protection and breach notification, periodic vendor reviews, an inventory of every data relationship, and an exit plan for secure data retrieval and deletion. The broker remains accountable for the data practices of its vendors, so compliance extends to everyone in your supply chain, not just your own systems.
How Osto helps brokers comply
Meeting all of this, governance evidence, a VAPT and external-testing cadence, six-hour-ready incident detection, vendor risk, and an audit-ready file, is a heavy lift for a broking firm without a dedicated security team. Assembling it from separate tools and consultants is slow and hard to keep current, which is exactly the gap Osto is built to close.
Osto is a one-stop security and compliance platform purpose-built for fast-moving teams. For a broker working toward IRDAI compliance, it runs the VAPT and testing the guidelines expect, correlates security events for faster incident detection and reporting, supports encryption, data-handling, and third-party risk controls, and keeps organised, audit-ready evidence, mapped across the IRDAI expectations, DPDP, and other frameworks in one place. Osto does not act as your CERT-In empanelled auditor or your insurer, it gets you audit-ready and keeps you there, so the assurance audit becomes a verification rather than a scramble.
Get IRDAI-ready without a big security team.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving teams. Run VAPT, stand up monitoring for fast incident reporting, manage vendor risk, and keep audit-ready evidence, on one platform. No security team required.
Book a Demo →Frequently asked questions
Does IRDAI cybersecurity compliance apply to insurance brokers?
Yes. The IRDAI Information and Cyber Security Guidelines bind every regulated intermediary that handles policyholder data, including brokers, third-party administrators, web aggregators, and corporate agents, not only insurers.
Do insurance brokers need a CISO?
Yes. Brokers must appoint a Chief Information Security Officer whose role is independent of the IT function, alongside an Information Security Risk Management Committee. Smaller intermediaries may assign the CISO responsibility to a functionary who reports to the board.
How often must a broker run VAPT?
At least once a year, plus six-monthly external black-box penetration testing on internet-facing assets. High and critical findings must be remediated within thirty days, and evidence of closure is checked at the annual assurance audit.
What is the incident reporting timeline?
Critical incidents must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and all other incidents within twenty-four hours, in the prescribed format. The clock runs from detection, not investigation.
Who audits a broker’s IRDAI cybersecurity compliance?
An annual assurance audit is conducted by a CERT-In empanelled auditor, and the signed report is filed to IRDAI within the prescribed timeline. A platform like Osto gets you audit-ready but does not act as the empanelled auditor.
Is a broker responsible for its vendors’ security?
Yes. Third-party risk management is mandatory, and the broker remains accountable for the data practices of its vendors. That means pre-contract assessments, security clauses, periodic reviews, a vendor inventory, and an exit plan for secure data deletion.

