Built for a Regulated Industry
Secured to Match

BeyondSure handles sensitive financial and health data for insurance transactions. We treat security not as a checklist, but as the product.

BeyondSure security whitepaper preview showing IRDAI compliance, VAPT certification, AES-256 encryption and 99.9% uptime SLA
6 hr

IRDAI Incident Reporting
Window

100 %

Data stored within India,
no exceptions

0

Third-party data sharing,
ever

256 bit

AES encryption,
at rest and in transit

Scope

Who Does This Apply To?

The circular covers all IRDAI registered insurance intermediaries — not just large insurers. Direct brokers, composite brokers, web aggregators, corporate agents, and insurance marketing firms are all within scope.

The most common misconception: that cybersecurity compliance is an insurer problem, not an intermediary one. The 2025 guidelines are unambiguous, they apply to you.

"Size is not a mitigating factor."

An eight-person brokerage using a third-party SaaS platform is held to the same cybersecurity standard as a 200-person composite broker with its own IT department.

Direct Brokers Corporate Agents IMFs Composite Brokers Web Aggregators
  • Mandatory cloud policy

    Any cloud-hosted platform requires a documented cloud governance policy covering data classification, vendor assessment, and access controls.

  • Vendor risk assessment framework

    Every third party handling policyholder data must be formally assessed. This cannot be delegated to the vendor.

  • Defined incident response timelines

    First report to IRDAI within 6 hours of detecting a cybersecurity incident. Not best-effort.

  • Data residency requirements

    All policyholder data must be stored within India. Cloud platforms hosting data outside India are non-compliant.

2025 Update

What Changed
in the 2025 Update?

"The 2019 circular was principles-based, broad direction, reasonable auditor judgement. The 2025 update is prescriptive: specific timelines, specific technical controls, documentary evidence required."

IRDAI 2025 Cybersecurity Circular

The 7 Mandatory Controls Auditors Check.
We Have All 7.

IRDAI's 2025 update is prescriptive: specific timelines, specific technical controls, specific reporting windows. Here's how BeyondSure maps to every mandatory control.

Control 01

Board-Approved IT & Cybersecurity Policy

Our cybersecurity policy is formally approved by the Board, reviewed annually, and signed by a Board member not a senior employee. Board resolution on file and auditable.

✓ Board-Signed

Control 02

Annual VAPT by CERT-In Empanelled Vendor

Annual Vulnerability Assessment & Penetration Testing conducted by a CERT-In empanelled vendor. Severity-rated findings with documented remediation plans, not just a clean report.

✓ CERT-In Certified

Control 03

Data Classification & Localisation

All policyholder data stored exclusively on servers physically within India. Written confirmation from every infrastructure vendor. Zero data residency violations ever.

✓ India-Only Infra

Control 04

Incident Reporting Within 6 Hours

Documented incident response plan with named contacts, escalation paths, and pre-drafted IRDAI notification templates. The tightest window in Indian financial services regulation, we're ready before anything goes wrong.

✓ Sub-6hr Ready

Control 05

Business Continuity + Disaster Recovery

Documented BCP with RPO ≤ 4 hours and RTO ≤ 8 hours for all critical systems. DR tests are run, logged, and dated — not just documented. Auditors see test logs, not promises.

✓ Tested & Logged

Control 07

Third-Party Vendor Risk Assessment

Every SaaS platform, cloud service, and outsourced function touching policyholder data is formally assessed. Security certifications, data handling practices, incident response documented and updated with every new vendor.

✓ Formally Assessed

Control 06

Staff Cybersecurity Awareness Training

Mandatory cybersecurity training for all staff not just IT with attendance records and dates. Annual cycle, dated documentation, and a repeatable schedule, not a one-off induction session.

✓ Annual Cycle

Regulatory Risk

The Audit Risk Is Real

IRDAI has significantly increased scrutiny on intermediaries following several data incidents. The consequences aren't theoretical: show-cause notices, financial penalties, and in serious cases, licence suspension.

The most common gap: brokers using technology platforms for policy management, CRM, and client portals that have never been VAPT tested — with no confirmation of where policyholder data is hosted. An IRDAI auditor asking "show me the VAPT report" surfaces this gap in the first ten minutes.

Common Compliance Gaps

No VAPT report78%
Data residency unconfirmed65%
No Board-approved policy54%
No incident response plan70%

% of intermediaries missing this control at audit time

Not sure where your platform stands on VAPT or data residency?

Get a compliance snapshot, we'll walk through your current platform against all 7 controls.

What to Ask Your Technology Platform Provider

If you use any third-party platform for policy management, CRM, client portal, or document management, get written answers to these before your next audit. These aren't nice-to-haves, they're required for your vendor risk assessment register.

1

VAPT Status

Is the platform VAPT tested by a CERT-In empanelled vendor? Can you share the most recent report, or a summary of findings and remediation status? A vendor that can't answer this within 48 hours is itself a compliance risk.

✓ BeyondSure: Annual CERT-In VAPT, Full Report Available

2

Data Residency

Where is the data hosted? Are all servers within India? Can you provide written confirmation? US-hosted or EU-hosted platforms storing Indian policyholder data are non-compliant full stop.

✓ BeyondSure: Written India-Only Confirmation On File

3

Incident Response SLA

What's your incident response SLA? How and when do you notify customers of a breach? IRDAI requires first notification within 6 hours, your vendor's process directly affects your compliance window.

✓ BeyondSure: Sub-6hr Process, Documented And Tested

4

Audit Documentation

Can you provide a security compliance letter for our IRDAI audit file, confirming VAPT status, data residency, and controls? A vendor that takes weeks to respond or won't engage is material information for your risk register.

✓ BeyondSure: Compliance Letter Provided Same Day

Get a Compliance Snapshot in 30 Minutes

We'll check your current platform against all 7 IRDAI controls and tell you exactly where your audit gaps are before an auditor does.