BeyondSure handles sensitive financial and health data for insurance transactions. We treat security not as a checklist, but as the product.
Scope
The circular covers all IRDAI registered insurance intermediaries — not just large insurers. Direct brokers, composite brokers, web aggregators, corporate agents, and insurance marketing firms are all within scope.
The most common misconception: that cybersecurity compliance is an insurer problem, not an intermediary one. The 2025 guidelines are unambiguous, they apply to you.
"Size is not a mitigating factor."
An eight-person brokerage using a third-party SaaS platform is held to the same cybersecurity standard as a 200-person composite broker with its own IT department.
Mandatory cloud policy
Any cloud-hosted platform requires a documented cloud governance policy covering data classification, vendor assessment, and access controls.
Vendor risk assessment framework
Every third party handling policyholder data must be formally assessed. This cannot be delegated to the vendor.
Defined incident response timelines
First report to IRDAI within 6 hours of detecting a cybersecurity incident. Not best-effort.
Data residency requirements
All policyholder data must be stored within India. Cloud platforms hosting data outside India are non-compliant.
2025 Update
"The 2019 circular was principles-based, broad direction, reasonable auditor judgement. The 2025 update is prescriptive: specific timelines, specific technical controls, documentary evidence required."
IRDAI's 2025 update is prescriptive: specific timelines, specific technical controls, specific reporting windows. Here's how BeyondSure maps to every mandatory control.
Control 01
Board-Approved IT & Cybersecurity Policy
Our cybersecurity policy is formally approved by the Board, reviewed annually, and signed by a Board member not a senior employee. Board resolution on file and auditable.
✓ Board-SignedControl 02
Annual VAPT by CERT-In Empanelled Vendor
Annual Vulnerability Assessment & Penetration Testing conducted by a CERT-In empanelled vendor. Severity-rated findings with documented remediation plans, not just a clean report.
✓ CERT-In CertifiedControl 03
Data Classification & Localisation
All policyholder data stored exclusively on servers physically within India. Written confirmation from every infrastructure vendor. Zero data residency violations ever.
✓ India-Only InfraControl 04
Incident Reporting Within 6 Hours
Documented incident response plan with named contacts, escalation paths, and pre-drafted IRDAI notification templates. The tightest window in Indian financial services regulation, we're ready before anything goes wrong.
✓ Sub-6hr ReadyControl 05
Business Continuity + Disaster Recovery
Documented BCP with RPO ≤ 4 hours and RTO ≤ 8 hours for all critical systems. DR tests are run, logged, and dated — not just documented. Auditors see test logs, not promises.
✓ Tested & LoggedControl 07
Third-Party Vendor Risk Assessment
Every SaaS platform, cloud service, and outsourced function touching policyholder data is formally assessed. Security certifications, data handling practices, incident response documented and updated with every new vendor.
✓ Formally AssessedControl 06
Staff Cybersecurity Awareness Training
Mandatory cybersecurity training for all staff not just IT with attendance records and dates. Annual cycle, dated documentation, and a repeatable schedule, not a one-off induction session.
✓ Annual CycleRegulatory Risk
IRDAI has significantly increased scrutiny on intermediaries following several data incidents. The consequences aren't theoretical: show-cause notices, financial penalties, and in serious cases, licence suspension.
The most common gap: brokers using technology platforms for policy management, CRM, and client portals that have never been VAPT tested — with no confirmation of where policyholder data is hosted. An IRDAI auditor asking "show me the VAPT report" surfaces this gap in the first ten minutes.
Common Compliance Gaps
% of intermediaries missing this control at audit time
Get a compliance snapshot, we'll walk through your current platform against all 7 controls.
If you use any third-party platform for policy management, CRM, client portal, or document management, get written answers to these before your next audit. These aren't nice-to-haves, they're required for your vendor risk assessment register.
1
VAPT Status
Is the platform VAPT tested by a CERT-In empanelled vendor? Can you share the most recent report, or a summary of findings and remediation status? A vendor that can't answer this within 48 hours is itself a compliance risk.
✓ BeyondSure: Annual CERT-In VAPT, Full Report Available
2
Data Residency
Where is the data hosted? Are all servers within India? Can you provide written confirmation? US-hosted or EU-hosted platforms storing Indian policyholder data are non-compliant full stop.
✓ BeyondSure: Written India-Only Confirmation On File
3
Incident Response SLA
What's your incident response SLA? How and when do you notify customers of a breach? IRDAI requires first notification within 6 hours, your vendor's process directly affects your compliance window.
✓ BeyondSure: Sub-6hr Process, Documented And Tested
4
Audit Documentation
Can you provide a security compliance letter for our IRDAI audit file, confirming VAPT status, data residency, and controls? A vendor that takes weeks to respond or won't engage is material information for your risk register.
✓ BeyondSure: Compliance Letter Provided Same Day
We'll check your current platform against all 7 IRDAI controls and tell you exactly where your audit gaps are before an auditor does.