Compliance hub

IRDAI Information & Cyber Security Guidelines: the identity layer

IRDAI's Information and Cyber Security Guidelines (2023) make insurers accountable — at board level — for controlling access to policyholder data across employees, agents and third parties. IamLogic implements the access-management chapter of those guidelines as running software rather than policy documents.

  • ISO/IEC 27001:2022 certified
  • Made in India
  • On-premises · Cloud · Hybrid
  • SAML · OIDC · OAuth2 · RADIUS
  • 24×7 support

Context

What the framework expects

The guidelines require a governance structure (CISO, board committee), and concrete controls: identity and access management, privileged access management, periodic access reviews and logging.

Insurers' distinctive challenge is population diversity: employees, tied agents, brokers, TPAs and group entities all touch policyholder data under different lifecycles.

Evidence matters: IRDAI expects insurers to demonstrate reviews happened and exceptions were acted on.

Identity obligations

The requirements that touch IAM

  • Identity and access management across employees and intermediaries
  • MFA for access to critical applications and remote access
  • Periodic review of user access with documented outcomes
  • Prompt revocation on exit or role change
  • Logging and monitoring of access to sensitive data

Control mapping

Requirement → IamLogic control

The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.

RequirementIamLogic controlProduct
Access management across diverse populationsLifecycle automation driven by HRMS for employees and agency/partner systems for intermediariesIamLogic IGA
MFA on critical and remote accessAdaptive MFA with context policies distinguishing office, remote and intermediary accessAccess Manager
Periodic documented access reviewCertification campaigns scoped to policyholder-data systems with retained evidenceIamLogic IGA
Prompt revocationImmediate, automated deprovisioning on exit/lapse events across all connected systemsIamLogic IGA
Access logging and monitoringCentralised authentication logs including legacy insurance systems via browser pluginAccess Manager

This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.

FAQ

Common questions

Can agent portals be covered as well as internal systems?

Yes — agent and partner identities are governed on the same platform, with their own lifecycle sources, authentication policies and review campaigns.

Map IRDAI Guidelines to your environment

A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.