IRDAI IT Audit: What Indian Insurance Companies Need to Know About IT Security
Insurance companies manage highly sensitive information, including policyholder details, health records, financial data, payment information, claims documents and identity records. A cyber incident affecting this information can cause financial loss, regulatory action, customer distrust and serious business disruption.
That is why an Insurance Regulatory and Development Authority of India Audit is not only a compliance exercise. It is an opportunity for insurers to test whether their technology, people and processes can protect information and continue operations during a cyberattack, system failure or environmental incident.
The IRDAI Information and Cyber Security Guidelines, 2023 provide the primary framework for information and cybersecurity controls applicable to insurers and regulated insurance intermediaries.
This guide explains what insurance company leaders should know about the audit, what regulators and auditors typically examine, how to prepare, and where AKCP monitoring can support physical and environmental security evidence.
What is an IRDAI IT security audit?
An IRDAI IT audit, commonly referred to in the guidelines as an independent information and cyber security assurance audit, is an independent review of an insurer’s security governance, technology controls and operational practices.
The guidelines apply to:
- Life, general and health insurers
- Reinsurers and Foreign Re-insurance Branches
- Insurance brokers and corporate agents
- Third-party administrators
- Web aggregators
- Insurance repositories
- Insurance Information Bureau of India
- Other regulated intermediaries covered by IRDAI
The audit is expected to be carried out every year by a competent independent auditor. The audit plan and report should be presented to the appropriate Audit Committee, Board of Directors or Principal Officer.
For insurers, the signed audit report, together with the Board’s comments, must be submitted to IRDAI within 90 days from the end of the financial year or within 30 days of completion of the audit, whichever is earlier.
Because regulatory requirements and circulars can change, every insurance company should confirm current submission formats and timelines directly through the IRDAI website and applicable communications.
What does the regulator expect from insurance companies?
The IRDAI framework follows a broad approach. It does not focus only on firewalls or antivirus software. It examines whether the organisation has an effective system for protecting the confidentiality, integrity and availability of information.
Key areas include the following.
1. Board-level governance and accountability
Auditors will review whether information security is owned and supported by senior leadership.
Important evidence may include:
- Board-approved Information and Cyber Security Policy
- Defined responsibilities for the Board, CRO, CISO, CTO and business owners
- Information Security Risk Management Committee meetings
- Periodic reporting to the Board or Audit Committee
- Documented risk acceptance and exception approvals
- Annual policy review and updates
A policy document alone is not sufficient. The auditor may ask whether the policy is implemented, measured and reviewed through operational evidence.
2. Asset management and data classification
Insurance companies should maintain a current inventory of their hardware, software, applications, databases, networks, cloud services and critical information assets.
The inventory should identify:
- Asset owner and custodian
- Business criticality
- Location
- Data classification
- Support and maintenance details
- Dependencies and recovery requirements
- Third-party involvement
Customer and employee information should be classified according to its sensitivity. The classification should determine how the data is stored, accessed, transmitted, monitored, backed up and destroyed.
3. Identity and access management
Access control is one of the most important areas in an IT security audit checklist.
Auditors typically examine whether:
- Every user has a unique identity
- Access is granted according to business need
- Privileged accounts are restricted and monitored
- Multi-factor authentication is used where required
- Access is removed promptly when an employee leaves
- User access is reviewed periodically
- Segregation of duties is implemented
- Vendor and remote access is time-bound
- Administrative activity is logged and reviewed
Insurance companies should maintain evidence of access approvals, access reviews, joiner-mover-leaver processes and privileged-user monitoring.
4. Network, application and cloud security
The audit generally covers the security of internal networks, internet-facing applications, APIs, mobile applications, databases and cloud environments.
Common review areas include:
- Network segmentation
- Firewall and WAF configuration
- Secure remote access and VPN
- Vulnerability scanning
- Penetration testing
- Secure software development
- Change and release management
- Database security
- Encryption in transit and at rest
- API authentication and authorisation
- Cloud access controls and logging
- Backup and disaster recovery arrangements
The IRDAI guidelines specifically refer to protecting web applications through web application firewalls and require appropriate monitoring and security testing for critical systems.
Internet-facing applications and infrastructure should be tested periodically. High-risk findings should be assigned owners, target dates and validation testing after remediation.

5. Security logging and incident response
A mature insurer should be able to answer four questions quickly:
- What happened?
- When did it happen?
- Which systems and data were affected?
- What action was taken?
The guidelines require monitoring and logging for critical information systems, applications, networks and privileged-user activity. Logs must be protected from unauthorised modification and made available to relevant authorities when required.
The framework also refers to maintaining ICT infrastructure logs for a rolling period of 180 days within Indian jurisdiction, in line with applicable directions.
Insurance companies should also maintain:
- Incident response procedures
- Cyber Crisis Management Plan
- Escalation matrix
- Incident classification criteria
- Evidence preservation procedures
- Root-cause analysis records
- Corrective-action tracking
- Communication procedures for IRDAI and CERT-In
Cyber incidents must be reported according to applicable regulatory requirements. The guidelines reference reporting cyber incidents to CERT-In within six hours of noticing or being informed of an incident, with a copy to IRDAI and other concerned authorities.
6. Business continuity and disaster recovery
Insurance services depend on continuous access to policy, claims, payment and customer-service systems. Auditors will therefore review whether business continuity and disaster recovery plans are practical and tested.
Evidence may include:
- Business impact analysis
- Recovery Time Objective and Recovery Point Objective
- Data backup policies
- Off-site or alternate-site arrangements
- Restoration test results
- Annual DR drill reports
- Application-level recovery procedures
- Network redundancy
- Data-centre monitoring records
- Corrective actions from previous tests
A disaster recovery plan that has never been tested is not reliable evidence of resilience.
Why physical and environmental security matters
Cybersecurity controls can be strong, but a water leak, overheating rack, electrical failure or unauthorised server-room entry can still interrupt critical insurance systems.
The IRDAI guidelines include physical and environmental security requirements for sensitive areas such as server rooms and data centres. These controls include:
- Restricted access to sensitive areas
- Fire detection and suppression
- Water-leak protection
- Temperature monitoring
- Precision air conditioning
- Backup power
- Dual power supply where appropriate
- Monitoring of environmental anomalies
- Response procedures for physical incidents
This is where continuous monitoring becomes important.

How AKCP supports audit readiness
AKCP data-centre monitoring solutions can support the physical and environmental security portion of an insurer’s compliance programme.
Depending on the facility design, AKCP solutions can monitor:
- Rack and room temperature
- Humidity
- Hot and cold aisle conditions
- Airflow and pressure
- Water leaks
- Smoke and air quality
- Power consumption and fluctuations
- UPS and battery status
- Generator-related parameters
- Rack-door access
- Physical security events
AKCP platforms can provide real-time alerts, historical graphs and event records. These records can help an insurance company demonstrate that it continuously monitors critical infrastructure rather than relying only on manual inspections.
For example, an insurer can use monitoring records to show:
- Temperature remained within defined thresholds
- A water-leak alert was generated and acknowledged
- UPS battery conditions were reviewed
- A server-room access event was recorded
- A power anomaly was escalated to the facilities team
- Corrective action was completed within the required timeframe
AKCP does not replace an independent cybersecurity assurance audit, VAPT, SIEM, access review or Board governance process. Instead, it strengthens the evidence for physical protection, availability management and operational resilience.
The AKCP environmental monitoring guide explains how real-time and historical sensor data can help teams identify trends, diagnose problems and respond to abnormal conditions.
Practical preparation plan for CIOs and CISOs
Insurance companies can prepare more effectively by starting several months before the audit.
Step 1: Confirm the audit scope
Map all business applications, branches, data centres, cloud workloads, third parties and regulated intermediaries included in the review.
Step 2: Create a control-to-evidence matrix
For every control, record:
- Control owner
- Current status
- Required evidence
- Last test date
- Open gaps
- Risk rating
- Remediation deadline
Step 3: Review high-risk technology areas
Prioritise internet-facing applications, privileged accounts, unsupported systems, exposed APIs, backup systems, cloud administration and third-party access.
Step 4: Test operational effectiveness
Do not only review policies. Test whether controls work in practice through access recertification, incident simulations, vulnerability validation, backup restoration and DR exercises.
Step 5: Strengthen data-centre evidence
Review temperature, humidity, power, water-leak, access-control and battery-monitoring records. Make sure alerts have owners, escalation paths and closure evidence.
Step 6: Prepare the Board and Audit Committee
Present key risks in business language: customer impact, downtime exposure, regulatory risk, financial loss and remediation status.
Final thoughts
An IRDAI IT audit should be treated as a continuous improvement programme, not an annual paperwork exercise. Indian insurance companies need integrated protection across governance, identity, applications, networks, cloud, data, people, physical facilities and recovery processes.
A strong Insurance Regulatory and Development Authority of India Audit programme helps leadership understand where the organisation is resilient and where urgent investment is required. Continuous AKCP monitoring can add valuable visibility into the physical environment supporting critical insurance systems.
For guidance on the latest technology, IT audits, AKCP solutions or career growth and job planning for Gulf countries, contact Shelesh:
Useful references
- IRDAI Information and Cyber Security Guidelines, 2023
- IRDAI Guidelines
- IRDAI Cyber Security Checklist
- AKCP Data Center Monitoring and Optimization
- AKCP Environmental Monitoring for Data Centers
#ServerRoom #datacenter #serverroom #monitoring #uptime #modbus #remotemanagement #datacenterPUE #datacenteroperations #datacenterhealth #ThermalOptimization #uptime