Blog

IRDAI Cyber Security Guidelines: Email Checklist for Insurers

On 24 April 2023 IRDAI replaced its 2017 cyber guidelines with the Information and Cyber Security Guidelines, 2023. The scope widened deliberately: not only insurers and foreign reinsurance branches, but every intermediary, which means brokers, corporate agents, web aggregators, third-party administrators, insurance marketing firms, repositories, insurance self-network platforms, corporate surveyors, motor insurance service providers and the Insurance Information Bureau. If you touch policyholder data, the guidelines touch you.

Unlike most frameworks, IRDAI's does not leave email implied. Among the organisation-level policies every regulated entity must adopt and maintain, alongside access control, network security, incident management and data classification, is an Email Security Policy. Policyholder communication, claims documents, medical reports and premium instructions all travel by mail, and the regulator wants the controls around that written down and evidenced.

What the guidelines expect of email

  • A written Email Security Policy covering acceptable use, authentication, encryption, attachment and link handling, retention and monitoring, owned by the CISO and approved by the board or its committee.
  • Access control. Multi-factor authentication, role-based administration and prompt de-provisioning, under the Access Control Policy the guidelines also require.
  • Data classification and protection. Policyholder data, health information and claim files classified, encrypted in transit and at rest, and stopped at the gateway when they should not leave.
  • Logging, time and retention. ICT logs maintained and monitored for 180 days with system clocks synchronised to authorised NTP servers, matching CERT-In's directions.
  • Incident reporting. Cyber incidents reported within six hours of detection, to CERT-In and to IRDAI as the guidelines direct, with the Incident and Problem Management Policy defining who does what.
  • Assurance. Periodic independent audits and vulnerability assessments of the systems that carry policyholder data, and your email platform is one of them.

On location: the 2023 guidelines are about governance and control, and they expect you to know and govern where policyholder data is processed. They are not, in themselves, a blanket data-localisation order for email. The reasons to keep mail in India or on your own servers are the same as elsewhere in Indian finance: evidencing control at audit, CERT-In's in-India log retention, and what your corporate policyholders and reinsurers ask in due diligence.

The honest part nobody markets

No email product is "IRDAI-compliant" on its own. Compliance belongs to the regulated entity and is evidenced through policies, controls and audits. What a platform can do is make each line of your Email Security Policy true and provable: MFA and role-based admin, SPF, DKIM and DMARC enforced so your policyholders are not phished in your name, S/MIME with a certificate authority you control for claims and medical correspondence, DLP rules that recognise policy numbers, Aadhaar and PAN, exportable audit trails, retention controls, and the choice of hosting in India or on your own infrastructure. Aligned and evidenced controls, not a badge, is the language your auditor and your board committee will accept.

A checklist for the next IRDAI audit

  1. An Email Security Policy exists, is board-approved, has an owner, and was reviewed within the last year.
  2. MFA is enforced on every mailbox and administrator account, including intermediaries' shared inboxes.
  3. SPF, DKIM and DMARC are published for every domain that sends to policyholders, with DMARC at quarantine or reject.
  4. Claims, medical and KYC documents are encrypted in transit and, where policy requires, signed or encrypted with S/MIME.
  5. DLP rules cover policy numbers, Aadhaar, PAN and health information, with alerts reaching a named owner.
  6. Login, access and admin logs are retained for at least 180 days, monitored, with clocks on authorised NTP.
  7. A tested playbook gets a compromised mailbox to a six-hour report to CERT-In and IRDAI.
  8. Mail retention and deletion match your record-keeping rules and your DPDP erasure duties for policyholders.
  9. The contract with your email provider covers data location, access, breach cooperation and audit rights.
  10. The email platform is inside the scope of your periodic independent audit and vulnerability assessment.

The same controls, mapped to the banking regulator, are in our RBI-aligned BFSI checklist; the duties every entity now carries under the data-protection law are on the DPDP and business email page; and insurers that want the server inside their own perimeter can read the on-premise edition page.

Frequently asked questions

Do the IRDAI cyber security guidelines apply to insurance brokers and agents, or only insurers?
To both. The 2023 guidelines apply to all insurers including foreign reinsurance branches, and to intermediaries: brokers, corporate agents, web aggregators, TPAs, insurance marketing firms, repositories, insurance self-network platforms, corporate surveyors, motor insurance service providers and the Insurance Information Bureau.
Do the guidelines specifically mention email?
Yes. An Email Security Policy is one of the organisation-level policies every regulated entity must adopt and maintain, alongside access control, network security, incident management and data classification policies.
How fast must an incident be reported, and how long must logs be kept?
Cyber incidents must be reported within six hours of detection, and ICT logs maintained and monitored for 180 days with clocks synchronised to authorised NTP servers, in line with CERT-In's 2022 directions.
Do the IRDAI guidelines require email to be hosted in India?
They require you to govern and evidence where policyholder data is processed rather than issuing a blanket localisation order for email. Hosting in India or on your own servers is the easiest way to evidence that control and to satisfy CERT-In's in-India log retention and reinsurer due diligence, but the guidelines themselves are about governance, not geography.

← All posts