Compliance/India/IRDAI Guidelines 2023
Twenty-four domain policies: nine hold evidence in the file.
IRDAI asks insurers to label, track, encrypt and dispose of data by class, wherever it is. Vaultize keeps those records on the file itself.
- IRDAI/GA&HR/GDL/MISC/88/04/2023 · 24 Apr 2023
- Insurers, FRBs and intermediaries
- Capability mapping, not legal advice
The answer in 30 seconds
Vaultize adds file-level evidence to nine of the twenty-four security domain policies: data classification, access control, incidents, cryptography, continuity, third parties, logging, cloud and remote work. Governance, people, networks, premises and the rest belong to other owners.
The Guidelines in one view
Twenty-four domain policies. Where file evidence lands.
The general guidelines set governance, roles, risk and audit. Twenty-four security domain policies follow, numbered 2.1 to 2.24 in the Guidelines and 1 to 24 here. Each purpose is quoted, longer ones excerpted. Select a policy to see what a governed file can evidence.
1
Data Classification
“To provide a framework for information owners to determine and classify the sensitivity levels for the information that Organization uses, processes, and stores.”
IRDAI/GA&HR/GDL/MISC/88/04/2023
Outcomes the file can evidence
- How Vaultize contributes
- Discover & Classify assigns the class. Vaultize Seal carries it in the file with the label, the encryption, the rights and the per-access record the lifecycle processes ask for. Deletion at the end of retention needs approval and leaves a record.
- Evidence to retain
- Classification history. Sealed-file state. Per-access records with identity, location and time. Deletion approval records.
Policy by policy
What each item asks. What the file can answer.
Wording is quoted from the IRDAI Information and Cyber Security Guidelines, 2023. Each row ID gives the policy number (2.1 to 2.24 in the Guidelines), then the item within it. Each row is a capability mapping, not legal advice.
Using this page
Where these rows fit under the Guidelines.
The Guidelines apply now. Entities that had already completed their FY 2022-23 audit comply from the following financial year. The rows above are evidence for the policies that touch documents.
- 1
Confirm coverage
Insurers, foreign reinsurance branches and intermediaries regulated by IRDAI. Agents, micro-insurance agents, point of sale persons and individual surveyors are outside the Guidelines.
- 2
Classify the data
Policy 1, Data Classification. Confidential, Restricted, Internal Use Only and Public, with PII identified in addition.
- 3
Apply the domain controls
Policies 1 to 24. These rows belong here, as evidence for nine of them.
Bring the rows above as evidence for the auditor’s checklist under the nine policies.
- 4
Audit every year
An independent assurance audit, reported in Annexure III with the Board’s comments.
- 5
File with IRDAI
Within 90 days of the financial year end or 30 days of audit completion, whichever is earlier.
Responsibility boundary
Records support the audit. They do not pass it.
Vaultize contributes file-level records for documents. It does not write the policy, run the audit, classify incidents, secure networks or manage people and premises. Read the Guidelines, their annexures and IRDAI’s later circulars, and take qualified advice before relying on this page.
“These guidelines are applicable to all data created, received or maintained by regulated entities wherever these data records are and whatever form they are in, in the course of carrying out their designated duties and functions.”
IRDAI Information and Cyber Security Guidelines, 2023, paragraph 1.4
Official references
Read the source before relying on the mapping.
Policy wording comes from the first item. The second is the circular that issued it.
- IRDAI Information and Cyber Security Guidelines, 2023Version 1.0, April 2023, 175 pages. General guidelines, twenty-four security domain policies and annexures I to VI. Every item quoted on this page is from it.
- Circular IRDAI/GA&HR/GDL/MISC/88/04/2023, 24 April 2023Issues the Guidelines to all insurers, insurance intermediaries and IIB, and supersedes the 2017, 2020 and 2022 circulars.
A practical next step
Bring one Confidential document.
We will show what its records can say for the data classification policy today: label, transfer, tracking and disposal. We will name the owner responsible for the rest.
