IRDAI Cybersecurity Compliance for Insurance Brokers

IRDAI cybersecurity compliance for insurance brokers guide
IRDAI Cybersecurity for Brokers: 6 Complete Rules | Osto

IRDAI cybersecurity compliance for insurance brokers is not optional, and it is not lighter than it is for insurers. If you hold policyholder data, the full framework applies. Here is exactly what you must do, and how a lean team meets it.

Osto Security Team10 min readIRDAI Compliance

The short answer

IRDAI cybersecurity compliance for insurance brokers comes from the IRDAI Information and Cyber Security Guidelines, which bind every IRDAI-regulated intermediary that handles policyholder data, not just insurers. The core duties are board-level governance with an Information Security Risk Management Committee, an independent CISO, VAPT at least annually with six-monthly external penetration testing, critical incident reporting to CERT-In within six hours, an annual assurance audit by a CERT-In empanelled auditor, and third-party risk management. Accountability stays with the broker even when work is outsourced.

What IRDAI cybersecurity compliance for insurance brokers covers

A frequent misconception is that the IRDAI cyber rules are mainly for insurers. They are not. The IRDAI Information and Cyber Security Guidelines, issued by the Insurance Regulatory and Development Authority of India, bind every regulated intermediary that touches policyholder data, brokers, third-party administrators, web aggregators, and corporate agents included. If your broking firm collects, stores, or processes customer or policy data, the guidelines apply to you in full, and IRDAI checks adherence through its inspection and audit process.

The core obligations for insurance brokers under IRDAI

The guidelines are broad, but the practical substance comes down to a recognisable set of controls that a broker has to run and evidence.

What applies
The obligations you have to meet
The rules are not lighter for brokers than for insurers. Brokers hold policyholder data, so the IRDAI Information and Cyber Security Guidelines apply in full. Six obligations carry most of the weight in day-to-day practice.
The core obligations for insurance brokersGovernanceISRMC and board-level oversightIndependent CISOReporting outside the ITfunctionVAPTAnnual, plus six-monthlyexternal testsSix-hour reportingCritical incidents to CERT-Inand IRDAIAssurance auditCERT-In empanelled, filed toIRDAIVendor riskAssess and monitor every datapartner

In practice that means constituting an Information Security Risk Management Committee with board-level oversight, appointing a Chief Information Security Officer whose role sits outside the IT function, running a vulnerability assessment and penetration testing programme, reporting critical incidents within six hours, completing an annual assurance audit through a CERT-In empanelled auditor, and managing third-party risk across every vendor that handles your data. A structured VAPT programme is usually the quickest way to evidence the testing pillar.

Governance is board-level now
The guidelines treat cybersecurity as a board responsibility, not an IT task. For a broker, that means a committee that meets, a CISO with real independence, and decisions that are minuted, the kind of evidence an inspection looks for first.

Testing and remediation

Testing is where compliance becomes an ongoing discipline rather than a one-time exercise, and the remediation clock is strict.

Testing
How often you test, and how fast you fix
A large part of IRDAI cybersecurity compliance for insurance brokers is a defined testing rhythm with strict remediation. This is the leg most brokers underestimate, because it repeats all year.
The testing and remediation cadence VAPT At least once a year on core systems. External PT Six-monthly black-box tests on internet-facing assets. Remediation High and critical findings closed within 30 days.

Brokers must conduct VAPT at least once a year, and layer six-monthly external, black-box penetration testing on internet-facing assets on top of it. Critically, high and critical findings have to be closed within thirty days, and an internet-facing application still carrying a high-severity finding past that window is a common inspection failure. Running the test is only half of it, the remediation and the evidence of closure are what an assurance audit actually checks. Note that an automated scan alone does not satisfy this, our guide on VAPT versus vulnerability scanning explains why.

Incident reporting

The reporting rules are tight and measured from detection, which makes monitoring, not paperwork, the real requirement.

Reporting
Detection starts the clock
Incident reporting is time-bound and unforgiving. The window runs from when you detect an incident, not when you finish investigating it, so brokers need monitoring good enough to catch and confirm issues quickly.
Two clocks run on every incident 6 hours Critical incidents to CERT-In, with a copy to IRDAI. 24 hours All other cyber incidents, reported in the set format.

Critical cyber incidents, such as a data breach or ransomware, must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and all other incidents within twenty-four hours, in the prescribed format. Because the clock starts at detection, a broker that learns of an incident from a customer has already missed it. Meeting the six-hour window is really a demand for continuous monitoring that catches and confirms an incident fast, which is why detection capability is where lean broking teams are most exposed.

Vendor risk and accountability

Brokers rely heavily on technology vendors and platforms, and the guidelines are clear that outsourcing the work never outsources the responsibility. Third-party risk management is mandatory: a pre-contract security assessment of each vendor, contractual clauses covering data protection and breach notification, periodic vendor reviews, an inventory of every data relationship, and an exit plan for secure data retrieval and deletion. The broker remains accountable for the data practices of its vendors, so compliance extends to everyone in your supply chain, not just your own systems.

The broker owns the risk
Even when a platform or administrator processes the data, the broker answers to IRDAI for it. That is why vendor assessment, contracts, and exit management are not optional extras, they are part of the core obligation.

How Osto helps brokers comply

Meeting all of this, governance evidence, a VAPT and external-testing cadence, six-hour-ready incident detection, vendor risk, and an audit-ready file, is a heavy lift for a broking firm without a dedicated security team. Assembling it from separate tools and consultants is slow and hard to keep current, which is exactly the gap Osto is built to close.

Osto is a one-stop security and compliance platform purpose-built for fast-moving teams. For a broker working toward IRDAI compliance, it runs the VAPT and testing the guidelines expect, correlates security events for faster incident detection and reporting, supports encryption, data-handling, and third-party risk controls, and keeps organised, audit-ready evidence, mapped across the IRDAI expectations, DPDP, and other frameworks in one place. Osto does not act as your CERT-In empanelled auditor or your insurer, it gets you audit-ready and keeps you there, so the assurance audit becomes a verification rather than a scramble.

Get IRDAI-ready without a big security team.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving teams. Run VAPT, stand up monitoring for fast incident reporting, manage vendor risk, and keep audit-ready evidence, on one platform. No security team required.

Book a Demo →

Frequently asked questions

Does IRDAI cybersecurity compliance apply to insurance brokers?

Yes. The IRDAI Information and Cyber Security Guidelines bind every regulated intermediary that handles policyholder data, including brokers, third-party administrators, web aggregators, and corporate agents, not only insurers.

Do insurance brokers need a CISO?

Yes. Brokers must appoint a Chief Information Security Officer whose role is independent of the IT function, alongside an Information Security Risk Management Committee. Smaller intermediaries may assign the CISO responsibility to a functionary who reports to the board.

How often must a broker run VAPT?

At least once a year, plus six-monthly external black-box penetration testing on internet-facing assets. High and critical findings must be remediated within thirty days, and evidence of closure is checked at the annual assurance audit.

What is the incident reporting timeline?

Critical incidents must be reported to CERT-In within six hours of detection, with a copy to IRDAI, and all other incidents within twenty-four hours, in the prescribed format. The clock runs from detection, not investigation.

Who audits a broker’s IRDAI cybersecurity compliance?

An annual assurance audit is conducted by a CERT-In empanelled auditor, and the signed report is filed to IRDAI within the prescribed timeline. A platform like Osto gets you audit-ready but does not act as the empanelled auditor.

Is a broker responsible for its vendors’ security?

Yes. Third-party risk management is mandatory, and the broker remains accountable for the data practices of its vendors. That means pre-contract assessments, security clauses, periodic reviews, a vendor inventory, and an exit plan for secure data deletion.