Governance
Board-approved policy, CISO appointment and independence, Information Security Committee terms of reference, and the cyber crisis management plan — exercised rather than filed.
Governance, Risk & Compliance
The IRDAI Information and Cyber Security Guidelines put governance first — a board-approved policy, a CISO with real independence, and a committee that meets and minutes. Then they ask you to prove the controls underneath.
The guidelines apply to insurers, intermediaries and other regulated entities, and they are structured as a governance layer over a control set aligned to ISO/IEC 27001 domains. That structure is good news for anyone already running an ISMS — most of the underlying controls are ones you hold already, which is why we run both programmes from one control set rather than two.
The governance layer, though, is assessed on its own terms. A **board-approved information and cyber security policy**, reviewed annually. A **CISO with a reporting line independent of the function that operates IT** — a CISO reporting to the CTO is a finding, not a technicality. An **Information Security Committee with terms of reference that meets and produces minutes**, because the minutes are the evidence and the terms of reference alone are not.
Beneath that, the two areas where insurers most often come up short are **periodic access recertification** — evidence here expires faster than anywhere else in the guidelines, and a review from fourteen months ago is not evidence of a current control — and the **joiner, mover and leaver process**, where the leaver half is both the weakest and the part an auditor samples.
Coverage
The governance layer, the control set, and the assurance cycle.
Board-approved policy, CISO appointment and independence, Information Security Committee terms of reference, and the cyber crisis management plan — exercised rather than filed.
Assessed, treated, and residual risk accepted by somebody with the authority to accept it.
Least privilege, privileged access monitoring, multi-factor authentication, and periodic recertification with dated evidence.
Classification, encryption in transit and at rest, retention and disposal, and where policyholder data physically resides.
Hardening, patching, change management, logging and audit-trail retention, and security testing before release.
Due diligence before onboarding, contractual security obligations and audit rights, and continued monitoring.
Preparation for the annual information security audit by a CERT-In empanelled auditor, and the VAPT cycle — including after significant change, not only annually.
One incident record serving both the IRDAI obligation and the parallel CERT-In six-hour clock, which is the tighter of the two.
Approach
Governance first — it is assessed first, and it is the cheapest layer to put right before an audit.
Policy, CISO independence, committee, crisis plan. The layer that is assessed first and fixed most cheaply.
The control set against real evidence, mapped alongside ISO 27001 so one programme serves both.
VAPT, access recertification, restoration testing — the controls the guidelines expect to have been exercised.
Evidence collected on a cycle in SemperWise One™, dated and expiring, so the annual audit finds a maintained programme rather than a reconstructed one.
In the platform
Not a claim about coverage in the abstract — this is the clause library and the evidence collection that ship today.
Each one carried as a control with its own state, owner, test date and evidence — not a checklist item.
Gathered on a cycle and filed against the clauses they evidence, with a collection date and an expiry.
Of the 29 subjects our unified control model defines. This is what makes a second framework cheaper than the first.
Each artefact carries a collection date and an expiry, because evidence that is two years old is not evidence — it is history. When one lapses, everything resting on it is flagged rather than left quietly asserting something that stopped being true.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Policy, CISO, committee and crisis plan assessed against the guidelines.
Area by area, cross-mapped to ISO 27001 so nothing is done twice.
Findings verified, mapped to the control they affect, tracked and retested.
Every control with its owner, test date and dated artefact, for the annual audit.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No. The IRDAI guidelines are a regulatory requirement assessed through the annual information security audit and through IRDAI supervision. There is no IRDAI cyber security certificate. We do readiness, remediation, testing and evidence; the annual audit itself must be conducted by a CERT-In empanelled auditing organisation, which is a separate and independent party.
Less than you would expect on the control set and more than you would expect on governance. The controls are aligned to ISO/IEC 27001 domains, so an existing ISMS carries most of them across — we map rather than rebuild. The governance requirements, particularly CISO independence and the committee's operating record, are specific to the guidelines and are where the real work usually is.
The guidelines are clear that the role requires a reporting line independent of the function operating IT, and a CISO reporting to the CTO or Head of IT is a recurring finding. It is a governance point rather than a technical one, and it is cheap to fix before an audit and awkward to explain during one.
They run in parallel and they are not the same clock. The CERT-In Directions require reporting within six hours of noticing a listed incident; the IRDAI obligation runs on its own timeline. One incident record can serve both, and should — but the process has to be built to the tighter clock or it will miss it.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.