IRDAI ISNP Security Audit for Insurers & Intermediaries
If you sell or service insurance online through an Insurance Self-Network Platform, IRDAI expects that platform — and the controls around it — to be independently reviewed by a CERT-In empanelled auditor, before you go live and every year after. Intect is CERT-In empaneled, so we conduct that audit and validate your platform's controls the way an attacker would test them — so the assurance you file with IRDAI is earned, not assumed.
CERT-In Empaneled. Aligned to the IRDAI e-commerce/ISNP Guidelines and the IRDAI Information & Cyber Security Guidelines, 2023. We test the controls we audit.
Selling insurance online means proving the platform is secure
An Insurance Self-Network Platform — an ISNP — is the website or mobile application an insurer or insurance intermediary uses to sell and service insurance policies online.
Because that platform handles policy applications, KYC, premiums and the personal and financial data of policyholders, the Insurance Regulatory and Development Authority of India (IRDAI) treats its security as a condition of doing business, not an afterthought. An ISNP audit is the independent security review through which an insurer or intermediary demonstrates — to its own Board and to IRDAI — that the platform's controls are designed well and genuinely operating.
IRDAI's expectation rests on two instruments. The Guidelines on Insurance e-commerce, which introduced the ISNP, require the platform's controls, systems, procedures and safeguards to be independently reviewed by an external, appropriately qualified auditor — and the recognized credential for that work is CERT-In empanelment. Layered on top, the IRDAI Information and Cyber Security Guidelines, 2023 set a comprehensive cyber-security regime for every insurer and intermediary — board-governed information security, a Chief Information Security Officer, periodic vulnerability assessment and penetration testing, a Security Operations Centre, strict incident-reporting timelines, and an independent assurance audit every year whose report goes to IRDAI. Together they make one thing clear: if you operate online, your security has to be tested, not just documented.
"A platform you have documented is a claim. A platform we have tested is assurance. IRDAI — and your policyholders — should be able to tell the difference."
Who needs an ISNP audit
The ISNP audit applies to any IRDAI-regulated entity that operates an Insurance Self-Network Platform to transact insurance online — and the broader cyber-security audit under the 2023 guidelines reaches every insurer and intermediary, whether or not they run an ISNP.
The depth of the engagement scales with the size of the platform, the data it handles and the entity's place in the distribution chain. We scope every engagement to the IRDAI instruments that apply to you.
Operating an ISNP to sell or service policies online.
Broking firms transacting insurance through a self-network platform.
Banks and corporates distributing insurance via an ISNP.
Digital aggregators displaying and selling policies online.
FRBs and other IRDAI-regulated intermediaries under the 2023 cyber-security regime.
Whatever your entity type, the audit examines the same families of control — application & API security, access control, data protection, infrastructure and network, logging and monitoring, business continuity and third-party risk — calibrated to your platform and the IRDAI instruments that bind you.
The IRDAI instruments this audit is built on
We anchor every engagement to the live IRDAI text — so the audit you file is current, defensible and mapped to the right source.
Guidelines on Insurance e-commerce (the ISNP framework)
IRDAI's framework for selling and servicing insurance online. It introduced the Insurance Self-Network Platform, set out how insurers and intermediaries obtain permission to operate one, and requires the platform's controls, systems, procedures and safeguards to be independently reviewed by an external, appropriately qualified auditor — the recognized credential for which is CERT-In empanelment.
IRDAI Information and Cyber Security Guidelines, 2023
IRDAI's consolidated cyber-security regime for all insurers (including Foreign Re-Insurance Branches) and insurance intermediaries. Across its security domains it requires board-governed information security (an Information Security Risk Management Committee), an independent Chief Information Security Officer, periodic VAPT, a 24×7 Security Operations Centre, incident reporting to CERT-In within six hours, and an independent assurance audit carried out every year whose report is submitted to IRDAI.
The CERT-In empanelled auditor requirement
IRDAI's ISNP review and annual assurance audit are to be performed by a competent, independent external auditor — and CERT-In empanelment is the recognized credential for cyber-security audits and penetration testing of regulated entities in India. Intect is CERT-In empaneled.
IRDAI filing & the Board
The audit isn't an internal exercise. The annual assurance-audit report, with the comments of the Board, is filed with IRDAI within the timelines the 2023 guidelines prescribe — so the audit has to stand up to both your Audit Committee and the regulator.
How an ISNP audit runs
A disciplined, evidence-led path from scoping to IRDAI submission — built so your team always knows where the audit stands and what to act on next.
FIG. 02 — IRDAI ISNP audit lifecycle · 04 the offensive-edge differentiator · 08 filed with IRDAI
What we audit against
Our coverage maps to the security review the ISNP framework requires and the security domains set out in the IRDAI Information and Cyber Security Guidelines, 2023. Across an engagement we systematically examine the following domains:
Application & API Security
The security of the ISNP's web and mobile applications and the APIs behind them: secure development, input and session handling, secure-code review and pre–go-live security testing for every change.
Access Control & Identity
User provisioning and de-provisioning, privileged access, multi-factor authentication, role-based access and segregation of duties, and periodic access reviews across the platform.
Data Protection & Privacy
Classification and protection of policyholder and KYC data, cryptographic controls, data-leakage prevention, and the privacy obligations that attach to selling insurance online.
Infrastructure & Network Security
Network segmentation, perimeter and server hardening, secure configuration and the protection of the hosting environment the ISNP runs on.
Logging, Monitoring & Incident Response
Centralized logging, 24×7 security monitoring, vulnerability management, and incident detection and response — including reporting cyber incidents to CERT-In within six hours and to IRDAI as required.
Business Continuity & Disaster Recovery
Continuity and recovery plans for the platform, tested and restorable backups, and the ability to keep policyholders served through disruption.
Third-Party & Cloud Risk
Due diligence and contractual controls over hosting, payment, KYC and other service providers, and the security of any cloud the platform depends on.
Governance & Compliance
The Information and Cyber Security Policy, the CISO and the Information Security Risk Management Committee, the annual assurance audit, and alignment to the IRDAI instruments that bind you.
We don't just read your controls. We test them.
A document-only audit confirms that a control exists. An attacker doesn't care whether it exists — only whether it works. We close that gap.
The document-only audit
A traditional ISNP review reads policies, interviews owners and samples evidence to confirm a control is designed and, on paper, operating. It is necessary work — and it is where most audits stop. The trouble is that a well-written access-control policy and a platform an attacker can walk through are not the same thing, and the difference is exactly what an attacker exploits — on the very platform your policyholders trust with their data and their premiums.
The technically validated audit
Intect comes from offensive security. So where it matters, we validate the platform by testing it — vulnerability assessment and penetration testing of the ISNP's applications, APIs and infrastructure that turns "we have access controls" into demonstrated evidence of what an unauthorized user can and cannot reach. You get findings backed by proof of real exposure, not a checklist of assertions — and a report your Board and IRDAI can trust because it has been earned.
We are CERT-In empaneled, so the audit is the one IRDAI recognizes — and we come from offensive security, so it is technically validated. That combination is the point.
VAPT-BACKED EVIDENCEWhat you receive
Every engagement ends in an audit your team and your Board can act on — and that's ready to file with IRDAI. Written for the engineers who will remediate and the leadership accountable for the risk.
ISNP audit report
A structured report covering each control domain, findings, severity and risk, mapped to the applicable IRDAI instrument and control objective.
IRDAI-ready audit certificate & filing support
The signed audit report and certificate, in a form your Board can sign off and submit to IRDAI within the prescribed timelines, with our support through the filing.
Executive & Board summary
Security posture and the state of compliance in plain language for the Board and senior management.
Technical validation evidence (the offensive edge)
VAPT findings with reproducible proof-of-concept and demonstrated impact, so control failures are evidenced, not asserted.
Gap analysis & remediation roadmap
Prioritized, specific remediation guidance with clear ownership and sequencing — not generic advice.
Remediation support & retest
We support your team through remediation and re-verify fixes so high-risk gaps are closed and closure is evidenced — not just claimed.
Direct assessor access
A debrief with the people who performed the audit, not a handoff to a call centre.
Why insurers and intermediaries choose Intect
CERT-In Empaneled — The credential IRDAI expects for the ISNP review — so the audit and the technical validation behind it are accepted where it counts.
Offensive heritage — We come from penetration testing and red teaming. We audit the platform by testing it, surfacing the exposure a paper review misses.
Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the IRDAI instruments and the adversary — so findings are accurate, contextual and defensible.
Delhi-based, regulator-fluent — An India-based team that speaks the language of IRDAI guidelines and Indian insurance-sector supervision, available to your team through the engagement.
Frequently asked questions
Is an ISNP audit a certification?
No. An ISNP audit is an independent security-assurance engagement, not a certificate. It produces an audit report and certificate — for your Board and for IRDAI — evidencing how well your platform's controls are designed and operating against the applicable IRDAI instruments. There is no "IRDAI certificate" for an ISNP; there is credible, independent assurance that you file with the regulator.
Who is allowed to conduct it?
IRDAI expects the ISNP review and the annual assurance audit to be performed by a competent, independent external auditor, and CERT-In empanelment is the recognized credential for cyber-security audits and penetration testing of regulated entities. Intect is CERT-In empaneled, so we can conduct the audit and the technical validation behind it.
Do we need the audit before we go live, or only afterwards?
Both. IRDAI's ISNP framework expects the platform's controls to be independently reviewed before you operate it, and the cyber-security regime requires an independent assurance audit every year thereafter, whose report is filed with IRDAI. We support new applicants getting their platform audit-ready for permission, and established operators meeting the annual obligation.
Does an ISNP audit cover the whole organization, or just the platform?
The ISNP audit centres on the Self-Network Platform and the controls, systems and data around it. The broader IRDAI Information and Cyber Security Guidelines, 2023 reach your whole organization — governance, the CISO, the SOC, incident reporting and the annual assurance audit. We scope to what you need: a focused ISNP review, the wider cyber-security audit, or both in one coordinated engagement.
Do we still need ISO 27001?
ISO 27001 is a widely used information-security management standard and a strong foundation for an ISNP, but it is a separate, voluntary certification issued by an accredited certification body — not the IRDAI audit. The two are complementary: a well-run ISMS makes the ISNP audit smoother, and our audit tells you exactly where your platform's controls stand against IRDAI's expectations. We can align the two so you don't do the work twice.
Do you help us fix the findings, or just report them?
Both. We deliver a prioritized remediation roadmap, support your team through the fixes, and re-verify remediated controls so high-risk gaps are closed and closure is evidenced — not just claimed — before the report goes to IRDAI.
Related regulatory assurance
Indian financial-sector compliance spans several distinct, regulator-mandated audits. This page covers the IRDAI ISNP audit; for the adjacent mandates below, see the dedicated pages.
Prove your platform. Satisfy IRDAI.
Tell us whether you're applying for an ISNP or meeting your annual obligation, and we'll scope an audit that fits — or connect you directly with an assessor.