IRDAI · India
IRDAI wants every employee’s
training on record.
IRDAI’s Information and Cyber Security Guidelines, revised on 6 April 2026, require employees and third-party users to receive regular awareness training, a way to track each person’s attendance, users trained to handle phishing and fraudulent emails, and cyber incidents reported to CERT-In within 6 hours with a copy to IRDAI.
- Framework
- IRDAI Information and Cyber Security Guidelines 2026, IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026
- Applies to
- Insurers and listed intermediaries, including brokers, corporate agents, web aggregators and TPAs
- People
- Awareness training with tracked attendance, phishing handling, incident training for leaders
- Audit
- An independent assurance audit every year
What the 2026 guidelines say
Training is required,
and so is proof of it.
References are to the 2026 guidelines and their audit checklist, plus IRDAI’s 2025 fraud framework.
| Topic | What IRDAI says | Reference |
|---|---|---|
| Awareness training | Employees and relevant third-party users receive appropriate awareness training and regular updates. | Policy 2.4, section 3.2 |
| Tracked attendance | A training programme with a set periodicity, and a way to track each staff member’s attendance. | Policy 2.4, section 3.2 |
| Phishing | Users are trained to handle spam, phishing scams and fraudulent emails. | Policy 2.22, section 3.2 |
| What auditors check | Whether awareness is evaluated periodically, how non-completion is handled, and whether the Board is trained at least once a year. | Annexure III audit checklist |
| Fraud awareness | Periodic training for employees, senior management and Board members, in force from 1 April 2026. | Insurance Fraud Monitoring Framework 2025, section 11.2.1 |
Impersonation calls
Genuine insurer calls now
come from 1600 numbers.
IRDAI directed insurers and intermediaries to move service and transactional calls to the 1600 number series by 15 February 2026, to prevent impersonation fraud. Policyholders and staff both need to know it.
“Policy services” · +91 98XXX XX214
“Your bonus is ready to release”
“Your policy has matured with a bonus of ₹2.4 lakh. To release it today, pay the processing fee and confirm the OTP we just sent.”
- Not a 1600-series number
- A fee to receive money
- Asks for a one-time code
Expectation to record
The records your
assurance auditor asks for.
Who trained, and when.
LMS completions and certificates per person, including contractors and third parties.
Gaps chased.
Automated reminders and manager escalations for anyone outstanding.
Evaluated periodically.
Simulation results by team and channel over time.
Annual Board training.
Completion records for Board and leadership sessions.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- IRDAI Information and Cyber Security Guidelines, 20266 April 2026 · IRDAI/GA&HR/CIR/MISC/51/4/2026 · version 2.0
- IRDAI (Insurance Fraud Monitoring Framework) Guidelines, 20259 October 2025 · IRDAI/IID/GDL/MISC/112/10/2025 · in force 1 April 2026
- Implementation of TRAI directions on 1600-series numbers6 January 2026 · IRDAI/PP&GR/CIR/MISC/02/01/2026
- Circular on Cyber Incident or Crisis Preparedness24 March 2025 · IRDAI/GA&HR/CIR/MISC/49/03/2025
- Reporting of Cyber Security Incidents by Regulated Entities13 June 2023 · IRDAI/GA&HR/CIR/MISC/128/06/2023
- IRDAI Information and Cyber Security Guidelines, 2023 (predecessor)24 April 2023 · IRDAI/GA&HR/GDL/MISC/88/04/2023
Questions buyers ask
Frequently asked questions.
Which IRDAI cyber security guidelines apply now?
The Information and Cyber Security Guidelines revised on 6 April 2026, which IRDAI asked regulated entities to comply with from the current financial year. They build on the 2023 guidelines.
Do the guidelines require phishing simulation?
Not by name. They require users to be trained to handle phishing and fraudulent emails, and the audit checklist asks whether awareness is evaluated periodically. Simulation results are a practical way to show both.
How quickly must cyber incidents be reported?
The guidelines require reporting to CERT-In within 6 hours of noticing an incident, with a copy to IRDAI. IRDAI circulars also set formats and timelines for reporting to IRDAI, so follow the latest circular that applies to you.
Do the guidelines cover intermediaries?
Yes. They apply to insurers and to listed intermediaries such as brokers, corporate agents, web aggregators and TPAs, with the controls that apply depending on their access to insurer systems. Individual agents are excluded.
Let’s connect the dots
Every employee trained.
Every session on record.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo