Governance, Risk & Compliance

Insurance runs on data somebody trusted you with.

The IRDAI Information and Cyber Security Guidelines put governance first — a board-approved policy, a CISO with real independence, and a committee that meets and minutes. Then they ask you to prove the controls underneath.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
BoardApproved policy, reviewed annually
CISOIndependent of IT operations
AnnualAudit by a CERT-In empanelled auditor
24h / 6hTwo incident clocks

Governance first, and it is not a formality

The guidelines apply to insurers, intermediaries and other regulated entities, and they are structured as a governance layer over a control set aligned to ISO/IEC 27001 domains. That structure is good news for anyone already running an ISMS — most of the underlying controls are ones you hold already, which is why we run both programmes from one control set rather than two.

The governance layer, though, is assessed on its own terms. A **board-approved information and cyber security policy**, reviewed annually. A **CISO with a reporting line independent of the function that operates IT** — a CISO reporting to the CTO is a finding, not a technicality. An **Information Security Committee with terms of reference that meets and produces minutes**, because the minutes are the evidence and the terms of reference alone are not.

Beneath that, the two areas where insurers most often come up short are **periodic access recertification** — evidence here expires faster than anywhere else in the guidelines, and a review from fourteen months ago is not evidence of a current control — and the **joiner, mover and leaver process**, where the leaver half is both the weakest and the part an auditor samples.

Coverage

What we work on

The governance layer, the control set, and the assurance cycle.

Governance

Board-approved policy, CISO appointment and independence, Information Security Committee terms of reference, and the cyber crisis management plan — exercised rather than filed.

Risk assessment and treatment

Assessed, treated, and residual risk accepted by somebody with the authority to accept it.

Access governance

Least privilege, privileged access monitoring, multi-factor authentication, and periodic recertification with dated evidence.

Data protection and localisation

Classification, encryption in transit and at rest, retention and disposal, and where policyholder data physically resides.

Operations and application security

Hardening, patching, change management, logging and audit-trail retention, and security testing before release.

Third-party and outsourcing governance

Due diligence before onboarding, contractual security obligations and audit rights, and continued monitoring.

Annual audit and VAPT

Preparation for the annual information security audit by a CERT-In empanelled auditor, and the VAPT cycle — including after significant change, not only annually.

Incident response and reporting

One incident record serving both the IRDAI obligation and the parallel CERT-In six-hour clock, which is the tighter of the two.

Approach

How the engagement runs

Governance first — it is assessed first, and it is the cheapest layer to put right before an audit.

  1. 01 · Governance review

    Policy, CISO independence, committee, crisis plan. The layer that is assessed first and fixed most cheaply.

  2. 02 · Control gap assessment

    The control set against real evidence, mapped alongside ISO 27001 so one programme serves both.

  3. 03 · Test and close

    VAPT, access recertification, restoration testing — the controls the guidelines expect to have been exercised.

  4. 04 · Hold the position

    Evidence collected on a cycle in SemperWise One™, dated and expiring, so the annual audit finds a maintained programme rather than a reconstructed one.

In the platform

What SemperWise One carries for this framework.

Not a claim about coverage in the abstract — this is the clause library and the evidence collection that ship today.

37
Clauses in the library

Each one carried as a control with its own state, owner, test date and evidence — not a checklist item.

7
Artefacts collected automatically

Gathered on a cycle and filed against the clauses they evidence, with a collection date and an expiry.

25
Control subjects it spans

Of the 29 subjects our unified control model defines. This is what makes a second framework cheaper than the first.

How the framework divides up

  • 6 Operations
  • 5 Governance
  • 5 Data
  • 4 Access
  • 3 Assurance
  • 3 Third parties

Evidence the platform gathers by itself

  • Who had access
  • Policies in force
  • Audit trail continuity
  • Security safeguards in force
  • Processors engaged
  • Where personal data goes
  • Retention and erasure

Each artefact carries a collection date and an expiry, because evidence that is two years old is not evidence — it is history. When one lapses, everything resting on it is flagged rather than left quietly asserting something that stopped being true.

Already hold another framework? Most of the subjects here are ones your existing programme already covers. SemperWise One works out which, clause by clause, and proposes them — it never marks anything verified on your behalf, because verified means evidenced, and the evidence has to be pointed at this framework deliberately.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Governance gap report

Policy, CISO, committee and crisis plan assessed against the guidelines.

Control gap assessment

Area by area, cross-mapped to ISO 27001 so nothing is done twice.

VAPT report with closure tracking

Findings verified, mapped to the control they affect, tracked and retested.

Audit-ready evidence register

Every control with its owner, test date and dated artefact, for the annual audit.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You are an insurer, intermediary or TPA preparing for the annual information security audit.
  • Your CISO reports into the function that operates IT.
  • The Information Security Committee exists in the policy and not in the calendar.
  • Access recertification last happened more than a year ago.
  • You hold ISO 27001 and are being asked to demonstrate IRDAI compliance separately.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

IRDAI Cyber Security — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Is this a certification?

No. The IRDAI guidelines are a regulatory requirement assessed through the annual information security audit and through IRDAI supervision. There is no IRDAI cyber security certificate. We do readiness, remediation, testing and evidence; the annual audit itself must be conducted by a CERT-In empanelled auditing organisation, which is a separate and independent party.

We already hold ISO 27001. How much extra work is this?

Less than you would expect on the control set and more than you would expect on governance. The controls are aligned to ISO/IEC 27001 domains, so an existing ISMS carries most of them across — we map rather than rebuild. The governance requirements, particularly CISO independence and the committee's operating record, are specific to the guidelines and are where the real work usually is.

Does our CISO really have to be independent of IT?

The guidelines are clear that the role requires a reporting line independent of the function operating IT, and a CISO reporting to the CTO or Head of IT is a recurring finding. It is a governance point rather than a technical one, and it is cheap to fix before an audit and awkward to explain during one.

How do the IRDAI and CERT-In reporting obligations interact?

They run in parallel and they are not the same clock. The CERT-In Directions require reporting within six hours of noticing a listed incident; the IRDAI obligation runs on its own timeline. One incident record can serve both, and should — but the process has to be built to the tighter clock or it will miss it.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.