Compliance · IRDAI ISNP Audit IRDAI e-commerce/ISNP Guidelines · Cyber Security Guidelines 2023

IRDAI ISNP Security Audit for Insurers & Intermediaries

If you sell or service insurance online through an Insurance Self-Network Platform, IRDAI expects that platform — and the controls around it — to be independently reviewed by a CERT-In empanelled auditor, before you go live and every year after. Intect is CERT-In empaneled, so we conduct that audit and validate your platform's controls the way an attacker would test them — so the assurance you file with IRDAI is earned, not assumed.

CERT-In Empaneled. Aligned to the IRDAI e-commerce/ISNP Guidelines and the IRDAI Information & Cyber Security Guidelines, 2023. We test the controls we audit.

CERT-In Empaneled IRDAI e-commerce/ISNP Guidelines (2017) IRDAI Cyber Security Guidelines 2023 ISNP Audit
Mandate
IRDAI e-commerce/ISNP Guidelines (2017) · Cyber Security Guidelines, 2023
Auditor
CERT-In Empaneled — Intect conducts the audit directly
Cadence
Before go-live, then an independent assurance audit every year
Validation
VAPT-backed technical control validation
02

Selling insurance online means proving the platform is secure

An Insurance Self-Network Platform — an ISNP — is the website or mobile application an insurer or insurance intermediary uses to sell and service insurance policies online.

Because that platform handles policy applications, KYC, premiums and the personal and financial data of policyholders, the Insurance Regulatory and Development Authority of India (IRDAI) treats its security as a condition of doing business, not an afterthought. An ISNP audit is the independent security review through which an insurer or intermediary demonstrates — to its own Board and to IRDAI — that the platform's controls are designed well and genuinely operating.

IRDAI's expectation rests on two instruments. The Guidelines on Insurance e-commerce, which introduced the ISNP, require the platform's controls, systems, procedures and safeguards to be independently reviewed by an external, appropriately qualified auditor — and the recognized credential for that work is CERT-In empanelment. Layered on top, the IRDAI Information and Cyber Security Guidelines, 2023 set a comprehensive cyber-security regime for every insurer and intermediary — board-governed information security, a Chief Information Security Officer, periodic vulnerability assessment and penetration testing, a Security Operations Centre, strict incident-reporting timelines, and an independent assurance audit every year whose report goes to IRDAI. Together they make one thing clear: if you operate online, your security has to be tested, not just documented.

"A platform you have documented is a claim. A platform we have tested is assurance. IRDAI — and your policyholders — should be able to tell the difference."
03

Who needs an ISNP audit

The ISNP audit applies to any IRDAI-regulated entity that operates an Insurance Self-Network Platform to transact insurance online — and the broader cyber-security audit under the 2023 guidelines reaches every insurer and intermediary, whether or not they run an ISNP.

The depth of the engagement scales with the size of the platform, the data it handles and the entity's place in the distribution chain. We scope every engagement to the IRDAI instruments that apply to you.

Whatever your entity type, the audit examines the same families of control — application & API security, access control, data protection, infrastructure and network, logging and monitoring, business continuity and third-party risk — calibrated to your platform and the IRDAI instruments that bind you.

04

The IRDAI instruments this audit is built on

We anchor every engagement to the live IRDAI text — so the audit you file is current, defensible and mapped to the right source.

01

Guidelines on Insurance e-commerce (the ISNP framework)

IRDAI's framework for selling and servicing insurance online. It introduced the Insurance Self-Network Platform, set out how insurers and intermediaries obtain permission to operate one, and requires the platform's controls, systems, procedures and safeguards to be independently reviewed by an external, appropriately qualified auditor — the recognized credential for which is CERT-In empanelment.

IRDA/INT/GDL/ECM/055/03/20179 MAR 2017
02

IRDAI Information and Cyber Security Guidelines, 2023

IRDAI's consolidated cyber-security regime for all insurers (including Foreign Re-Insurance Branches) and insurance intermediaries. Across its security domains it requires board-governed information security (an Information Security Risk Management Committee), an independent Chief Information Security Officer, periodic VAPT, a 24×7 Security Operations Centre, incident reporting to CERT-In within six hours, and an independent assurance audit carried out every year whose report is submitted to IRDAI.

VERSION 1.0APRIL 2023
03

The CERT-In empanelled auditor requirement

IRDAI's ISNP review and annual assurance audit are to be performed by a competent, independent external auditor — and CERT-In empanelment is the recognized credential for cyber-security audits and penetration testing of regulated entities in India. Intect is CERT-In empaneled.

04

IRDAI filing & the Board

The audit isn't an internal exercise. The annual assurance-audit report, with the comments of the Board, is filed with IRDAI within the timelines the 2023 guidelines prescribe — so the audit has to stand up to both your Audit Committee and the regulator.

05

How an ISNP audit runs

A disciplined, evidence-led path from scoping to IRDAI submission — built so your team always knows where the audit stands and what to act on next.

01
Scoping
Define the regulated perimeter: the ISNP and its supporting systems, the IRDAI instruments that apply to you, the data and integrations in scope, and what "good" looks like for each control domain.
02
Architecture & Document Review
Examine the platform's architecture, network and data-flow diagrams, security policies, the Information and Cyber Security Policy, access matrices, configurations and prior audit findings — establishing the design of your controls.
03
Control Testing
Test controls in operation, not just on paper: access provisioning and reviews, KYC and payment-data handling, change and patch management, logging and monitoring, backup and recovery, and third-party governance.
04 · VAPT-BACKED
Technical Validation (VAPT)
Independently validate the platform's security by testing it — vulnerability assessment and penetration testing of the ISNP's web and mobile applications, APIs and supporting infrastructure, so exposure is proven, not assumed.
05
Gap Analysis
Measure each finding against the applicable IRDAI instrument and control objective, assign severity and risk, and separate true gaps from documentation issues.
06
Reporting
Deliver a clear, prioritized report for both the engineers who will fix issues and the Board that must understand the risk — with evidence and concrete remediation guidance, in a form ready for IRDAI.
07
Remediation
Work alongside your team as fixes are implemented and re-verify remediated controls, so high-risk gaps are closed within the window the guidelines expect and closure is evidenced, not just claimed.
08 · FILED
IRDAI Submission / Closure
Produce the signed audit report and certificate your Board signs off and files with IRDAI, and establish the cadence for the next annual review and ongoing assurance.

FIG. 02 — IRDAI ISNP audit lifecycle · 04 the offensive-edge differentiator · 08 filed with IRDAI

06

What we audit against

Our coverage maps to the security review the ISNP framework requires and the security domains set out in the IRDAI Information and Cyber Security Guidelines, 2023. Across an engagement we systematically examine the following domains:

Application & API Security

The security of the ISNP's web and mobile applications and the APIs behind them: secure development, input and session handling, secure-code review and pre–go-live security testing for every change.

Access Control & Identity

User provisioning and de-provisioning, privileged access, multi-factor authentication, role-based access and segregation of duties, and periodic access reviews across the platform.

Data Protection & Privacy

Classification and protection of policyholder and KYC data, cryptographic controls, data-leakage prevention, and the privacy obligations that attach to selling insurance online.

Infrastructure & Network Security

Network segmentation, perimeter and server hardening, secure configuration and the protection of the hosting environment the ISNP runs on.

Logging, Monitoring & Incident Response

Centralized logging, 24×7 security monitoring, vulnerability management, and incident detection and response — including reporting cyber incidents to CERT-In within six hours and to IRDAI as required.

Business Continuity & Disaster Recovery

Continuity and recovery plans for the platform, tested and restorable backups, and the ability to keep policyholders served through disruption.

Third-Party & Cloud Risk

Due diligence and contractual controls over hosting, payment, KYC and other service providers, and the security of any cloud the platform depends on.

Governance & Compliance

The Information and Cyber Security Policy, the CISO and the Information Security Risk Management Committee, the annual assurance audit, and alignment to the IRDAI instruments that bind you.

07

We don't just read your controls. We test them.

A document-only audit confirms that a control exists. An attacker doesn't care whether it exists — only whether it works. We close that gap.

Confirms the claim

The document-only audit

A traditional ISNP review reads policies, interviews owners and samples evidence to confirm a control is designed and, on paper, operating. It is necessary work — and it is where most audits stop. The trouble is that a well-written access-control policy and a platform an attacker can walk through are not the same thing, and the difference is exactly what an attacker exploits — on the very platform your policyholders trust with their data and their premiums.

Proves the control

The technically validated audit

Intect comes from offensive security. So where it matters, we validate the platform by testing it — vulnerability assessment and penetration testing of the ISNP's applications, APIs and infrastructure that turns "we have access controls" into demonstrated evidence of what an unauthorized user can and cannot reach. You get findings backed by proof of real exposure, not a checklist of assertions — and a report your Board and IRDAI can trust because it has been earned.

We are CERT-In empaneled, so the audit is the one IRDAI recognizes — and we come from offensive security, so it is technically validated. That combination is the point.

VAPT-BACKED EVIDENCE
08

What you receive

Every engagement ends in an audit your team and your Board can act on — and that's ready to file with IRDAI. Written for the engineers who will remediate and the leadership accountable for the risk.

01

ISNP audit report

A structured report covering each control domain, findings, severity and risk, mapped to the applicable IRDAI instrument and control objective.

02

IRDAI-ready audit certificate & filing support

The signed audit report and certificate, in a form your Board can sign off and submit to IRDAI within the prescribed timelines, with our support through the filing.

03

Executive & Board summary

Security posture and the state of compliance in plain language for the Board and senior management.

04

Technical validation evidence (the offensive edge)

VAPT findings with reproducible proof-of-concept and demonstrated impact, so control failures are evidenced, not asserted.

VAPT-BACKED
05

Gap analysis & remediation roadmap

Prioritized, specific remediation guidance with clear ownership and sequencing — not generic advice.

06

Remediation support & retest

We support your team through remediation and re-verify fixes so high-risk gaps are closed and closure is evidenced — not just claimed.

07

Direct assessor access

A debrief with the people who performed the audit, not a handoff to a call centre.

CERT-In Empaneled IRDAI e-commerce / ISNP Guidelines IRDAI Information & Cyber Security Guidelines 2023 VAPT-backed validation
09

Why insurers and intermediaries choose Intect

CERT-In Empaneled Researcher-led · offensive heritage

CERT-In Empaneled — The credential IRDAI expects for the ISNP review — so the audit and the technical validation behind it are accepted where it counts.

Offensive heritage — We come from penetration testing and red teaming. We audit the platform by testing it, surfacing the exposure a paper review misses.

Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the IRDAI instruments and the adversary — so findings are accurate, contextual and defensible.

Delhi-based, regulator-fluent — An India-based team that speaks the language of IRDAI guidelines and Indian insurance-sector supervision, available to your team through the engagement.

10

Frequently asked questions

Is an ISNP audit a certification?

No. An ISNP audit is an independent security-assurance engagement, not a certificate. It produces an audit report and certificate — for your Board and for IRDAI — evidencing how well your platform's controls are designed and operating against the applicable IRDAI instruments. There is no "IRDAI certificate" for an ISNP; there is credible, independent assurance that you file with the regulator.

Who is allowed to conduct it?

IRDAI expects the ISNP review and the annual assurance audit to be performed by a competent, independent external auditor, and CERT-In empanelment is the recognized credential for cyber-security audits and penetration testing of regulated entities. Intect is CERT-In empaneled, so we can conduct the audit and the technical validation behind it.

Do we need the audit before we go live, or only afterwards?

Both. IRDAI's ISNP framework expects the platform's controls to be independently reviewed before you operate it, and the cyber-security regime requires an independent assurance audit every year thereafter, whose report is filed with IRDAI. We support new applicants getting their platform audit-ready for permission, and established operators meeting the annual obligation.

Does an ISNP audit cover the whole organization, or just the platform?

The ISNP audit centres on the Self-Network Platform and the controls, systems and data around it. The broader IRDAI Information and Cyber Security Guidelines, 2023 reach your whole organization — governance, the CISO, the SOC, incident reporting and the annual assurance audit. We scope to what you need: a focused ISNP review, the wider cyber-security audit, or both in one coordinated engagement.

Do we still need ISO 27001?

ISO 27001 is a widely used information-security management standard and a strong foundation for an ISNP, but it is a separate, voluntary certification issued by an accredited certification body — not the IRDAI audit. The two are complementary: a well-run ISMS makes the ISNP audit smoother, and our audit tells you exactly where your platform's controls stand against IRDAI's expectations. We can align the two so you don't do the work twice.

Do you help us fix the findings, or just report them?

Both. We deliver a prioritized remediation roadmap, support your team through the fixes, and re-verify remediated controls so high-risk gaps are closed and closure is evidenced — not just claimed — before the report goes to IRDAI.

11

Related regulatory assurance

Indian financial-sector compliance spans several distinct, regulator-mandated audits. This page covers the IRDAI ISNP audit; for the adjacent mandates below, see the dedicated pages.

Scope an engagement

Prove your platform. Satisfy IRDAI.

Tell us whether you're applying for an ISNP or meeting your annual obligation, and we'll scope an audit that fits — or connect you directly with an assessor.