Loading Vaultize
Skip to main content

Compliance/India/IRDAI Guidelines 2023

Twenty-four domain policies: nine hold evidence in the file.

IRDAI asks insurers to label, track, encrypt and dispose of data by class, wherever it is. Vaultize keeps those records on the file itself.

123456789101112131415161718192021222324
1Data Classification5 outcomes
Read againstIRDAI Information and Cyber Security Guidelines, 2023IRDAI/GA&HR/GDL/MISC/88/04/2023 · 24 April 2023
  • IRDAI/GA&HR/GDL/MISC/88/04/2023 · 24 Apr 2023
  • Insurers, FRBs and intermediaries
  • Capability mapping, not legal advice
9of 24 domain policies, across 18 items

The answer in 30 seconds

Vaultize adds file-level evidence to nine of the twenty-four security domain policies: data classification, access control, incidents, cryptography, continuity, third parties, logging, cloud and remote work. Governance, people, networks, premises and the rest belong to other owners.

The Guidelines in one view

Twenty-four domain policies. Where file evidence lands.

The general guidelines set governance, roles, risk and audit. Twenty-four security domain policies follow, numbered 2.1 to 2.24 in the Guidelines and 1 to 24 here. Each purpose is quoted, longer ones excerpted. Select a policy to see what a governed file can evidence.

123456789101112131415161718192021222324

1

Data Classification

“To provide a framework for information owners to determine and classify the sensitivity levels for the information that Organization uses, processes, and stores.”

IRDAI/GA&HR/GDL/MISC/88/04/2023

Outcomes the file can evidence

How Vaultize contributes
Discover & Classify assigns the class. Vaultize Seal carries it in the file with the label, the encryption, the rights and the per-access record the lifecycle processes ask for. Deletion at the end of retention needs approval and leaves a record.
Evidence to retain
Classification history. Sealed-file state. Per-access records with identity, location and time. Deletion approval records.

Policy by policy

What each item asks. What the file can answer.

Wording is quoted from the IRDAI Information and Cyber Security Guidelines, 2023. Each row ID gives the policy number (2.1 to 2.24 in the Guidelines), then the item within it. Each row is a capability mapping, not legal advice.

Using this page

Where these rows fit under the Guidelines.

The Guidelines apply now. Entities that had already completed their FY 2022-23 audit comply from the following financial year. The rows above are evidence for the policies that touch documents.

  1. 1

    Confirm coverage

    Insurers, foreign reinsurance branches and intermediaries regulated by IRDAI. Agents, micro-insurance agents, point of sale persons and individual surveyors are outside the Guidelines.

  2. 2

    Classify the data

    Policy 1, Data Classification. Confidential, Restricted, Internal Use Only and Public, with PII identified in addition.

  3. 3

    Apply the domain controls

    Policies 1 to 24. These rows belong here, as evidence for nine of them.

    Bring the rows above as evidence for the auditor’s checklist under the nine policies.

  4. 4

    Audit every year

    An independent assurance audit, reported in Annexure III with the Board’s comments.

  5. 5

    File with IRDAI

    Within 90 days of the financial year end or 30 days of audit completion, whichever is earlier.

Responsibility boundary

Records support the audit. They do not pass it.

Vaultize contributes file-level records for documents. It does not write the policy, run the audit, classify incidents, secure networks or manage people and premises. Read the Guidelines, their annexures and IRDAI’s later circulars, and take qualified advice before relying on this page.

“These guidelines are applicable to all data created, received or maintained by regulated entities wherever these data records are and whatever form they are in, in the course of carrying out their designated duties and functions.”

IRDAI Information and Cyber Security Guidelines, 2023, paragraph 1.4

A practical next step

Bring one Confidential document.

We will show what its records can say for the data classification policy today: label, transfer, tracking and disposal. We will name the owner responsible for the rest.

Request a compliance mapping session