IRDAI door. Cyber + reporting + consumer protection.

IRDAI compliance for the modern insurer.

Regulatory reporting, cybersecurity guidelines, consumer protection, policyholder data under DPDP. Every IRDAI obligation, one workspace. dcomply tracks IRDAI Master Circulars on cybersecurity, corporate governance, expenses of management, and product filing; enforces the 30-day claims settlement SLA under Regulation 27; and produces the quarterly reporting draft for life, general and health insurers, brokers, and web aggregators.

✓ IRDAI Corporate Governance Guidelines
✓ Cyber Security Framework
⚠ 2 controls need attention
Last assessed: Today
Real-time IRDAI compliance posture dashboard
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

IRDAI reporting deadlines catch you every quarter.

Cybersecurity guidelines were reviewed once and filed.

Policyholder data policy is a paragraph in the privacy policy.

Consumer complaint handling isn't a real workflow.

If you're a listed insurer, the SEBI door pairs LODR + CSCRF alongside IRDAI. Every insurer also needs CERT-In: see the CERT-In door.

Your regulator stack

Here's what sits above the foundation.

Insurers live under IRDAI plus multiple central regulators. dcomply ships modules for each layer.

POSH + Labour
Applies to every insurer with 10+ employees. IC constitution, annual return, training.
CERT-In Directions 2022
6-hour incident reporting, 180-day log retention (parallel to IRDAI 2-6 hour clock).
DPDP Act 2023 (policyholder data)
Health data, financial data, children's data. Consent, DSR portal, breach notification.
IRDA Cybersecurity Master Circular 2023
Board-approved policy, CISO appointment, quarterly VAPT, annual audit, 2-6 hour incident reporting.
IRDAI (foundation)
The foundation. Master Circulars on governance, EoM (Expenses of Management) ceiling, product filing, claims 30-day SLA (Regulation 27), consumer protection.
The Problem

IRDAI Regulations Are Complex and Constantly Updated

Insurance companies face a growing stack of IRDAI guidelines, manual tracking leads to missed obligations, audit findings, and regulatory penalties.

Guideline Overload

Dozens of IRDAI circulars spanning governance, cyber, outsourcing, and data, impossible to track without a system

Audit Findings Risk

Non-compliance with governance and cyber security directives leads to costly IRDAI audit observations and enforcement

Manual Tracking Errors

Spreadsheet-based compliance management creates gaps, version confusion, and incomplete evidence trails

Capabilities

Everything You Need for IRDAI Compliance

IRDAI Corporate Governance Guidelines

Structured checklist mapped to IRDAI Corporate Governance Guidelines with board-level controls, committee obligations, and compliance status tracking.

Cyber Security Framework Mapping

Map and track all controls under the IRDAI Cyber Security Framework for insurers, with evidence collection and gap identification.

Outsourcing and Third-Party Tracking

Track IRDAI outsourcing obligations, vendor due diligence, and concentration risk monitoring for critical service providers to insurers.

Incident Reporting Workflows

Automated workflows for cyber and operational incident reporting to IRDAI with prescribed timeline alerts, template generation, and escalation tracking.

Compliance Posture Score

Real-time compliance score across all IRDAI frameworks with gap identification, risk prioritization, and board-ready reporting dashboards.

Circular Update Alerts

Instant alerts when IRDAI issues new circulars, guidelines, or exposure drafts relevant to life, non-life, or health insurance entities.

What's Included

Full IRDAI Compliance Coverage

Every major IRDAI regulatory framework mapped to actionable controls with evidence collection and audit trail.

Corporate governance checklist

Board composition, committee mandates, fit-and-proper criteria, and disclosure obligations mapped to IRDAI governance guidelines.

Cyber security directives mapping

All controls under the IRDAI Information and Cyber Security Guidelines with implementation guidance and evidence templates.

Outsourcing due diligence tracker

Vendor assessment, contract compliance, exit plan documentation, and sub-outsourcing monitoring as required by IRDAI.

Incident response timelines

Statutory incident reporting windows tracked with automated reminders and auto-generated incident reports for IRDAI submission.

Board reporting templates

Ready-to-use board and management committee report templates aligned with IRDAI corporate governance requirements.

Penalty risk calculator

Quantify penalty exposure for non-compliance across IRDAI frameworks to prioritise remediation efforts.

IRDAI compliance FAQs

Questions Heads of Compliance at insurers actually ask.

The Insurance Regulatory and Development Authority of India regulates insurers, corporate agents, brokers, insurance marketing firms, and web aggregators. Obligations include Master Circulars on cybersecurity, information security, expenses of management, product filing, claims settlement, and outsourcing.

IRDAI Master Circular on Cybersecurity 2023 mandates: board-approved cybersecurity policy, CISO appointment, quarterly VAPT, annual comprehensive audit, incident reporting to IRDAI within 2 to 6 hours, and cyber-insurance for large insurers. Parallels SEBI CSCRF and RBI Cybersecurity Framework.

Insurers process significant volumes of health data, financial data and children's data. All sensitive under DPDP. IRDAI's cybersecurity framework provides the security floor; DPDP adds consent, DSR, breach notification and retention obligations. dcomply cross-maps controls.

Regulation 27 of IRDAI (Protection of Policyholders' Interests) Regulations 2017 requires insurers to settle or repudiate a claim within 30 days of receipt of last document. Non-compliance attracts penalties and reputational risk. dcomply tracks claim-file timelines.

IRDAI (Expenses of Management, including Commission of Insurers) Regulations 2024 caps EoM by product category as a percentage of premium. Non-compliance attracts penalties. dcomply's IRDAI module tracks EoM per product per period.

Every applicable IRDAI filing (financial returns, cybersecurity audit report, expenses-of-management statement, claims returns) has a tracked deadline and pre-fill workflow. Evidence for regulatory inspection is organised in the evidence locker.

Yes, and web aggregators and brokers.

No, filing is manual through IRDAI portals. dcomply produces the file and archives.

Handled by the Consumer Protection module.

Full DSR and consent workflows.

Included in every dcomply tenant.
Real teams, real programmes

"Two days from the platform-generated draft."

"Quarterly IRDAI reporting used to consume two people for a week. Now it takes two days from the platform-generated draft."
Head of Compliance, a general insurance intermediary.

Automate IRDAI Compliance

Stay audit-ready with automated tracking of every IRDAI guideline, circular, and reporting obligation

View All Features