Compliance hub
IRDAI Information & Cyber Security Guidelines: the identity layer
IRDAI's Information and Cyber Security Guidelines (2023) make insurers accountable — at board level — for controlling access to policyholder data across employees, agents and third parties. IamLogic implements the access-management chapter of those guidelines as running software rather than policy documents.
Context
What the framework expects
The guidelines require a governance structure (CISO, board committee), and concrete controls: identity and access management, privileged access management, periodic access reviews and logging.
Insurers' distinctive challenge is population diversity: employees, tied agents, brokers, TPAs and group entities all touch policyholder data under different lifecycles.
Evidence matters: IRDAI expects insurers to demonstrate reviews happened and exceptions were acted on.
Identity obligations
The requirements that touch IAM
- Identity and access management across employees and intermediaries
- MFA for access to critical applications and remote access
- Periodic review of user access with documented outcomes
- Prompt revocation on exit or role change
- Logging and monitoring of access to sensitive data
Control mapping
Requirement → IamLogic control
The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.
| Requirement | IamLogic control | Product |
|---|---|---|
| Access management across diverse populations | Lifecycle automation driven by HRMS for employees and agency/partner systems for intermediaries | IamLogic IGA |
| MFA on critical and remote access | Adaptive MFA with context policies distinguishing office, remote and intermediary access | Access Manager |
| Periodic documented access review | Certification campaigns scoped to policyholder-data systems with retained evidence | IamLogic IGA |
| Prompt revocation | Immediate, automated deprovisioning on exit/lapse events across all connected systems | IamLogic IGA |
| Access logging and monitoring | Centralised authentication logs including legacy insurance systems via browser plugin | Access Manager |
This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.
FAQ
Common questions
Can agent portals be covered as well as internal systems?
Yes — agent and partner identities are governed on the same platform, with their own lifecycle sources, authentication policies and review campaigns.
Map IRDAI Guidelines to your environment
A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.