On 24 April 2023 IRDAI replaced its 2017 cyber guidelines with the Information and Cyber Security Guidelines, 2023. The scope widened deliberately: not only insurers and foreign reinsurance branches, but every intermediary, which means brokers, corporate agents, web aggregators, third-party administrators, insurance marketing firms, repositories, insurance self-network platforms, corporate surveyors, motor insurance service providers and the Insurance Information Bureau. If you touch policyholder data, the guidelines touch you.
Unlike most frameworks, IRDAI's does not leave email implied. Among the organisation-level policies every regulated entity must adopt and maintain, alongside access control, network security, incident management and data classification, is an Email Security Policy. Policyholder communication, claims documents, medical reports and premium instructions all travel by mail, and the regulator wants the controls around that written down and evidenced.
What the guidelines expect of email
- A written Email Security Policy covering acceptable use, authentication, encryption, attachment and link handling, retention and monitoring, owned by the CISO and approved by the board or its committee.
- Access control. Multi-factor authentication, role-based administration and prompt de-provisioning, under the Access Control Policy the guidelines also require.
- Data classification and protection. Policyholder data, health information and claim files classified, encrypted in transit and at rest, and stopped at the gateway when they should not leave.
- Logging, time and retention. ICT logs maintained and monitored for 180 days with system clocks synchronised to authorised NTP servers, matching CERT-In's directions.
- Incident reporting. Cyber incidents reported within six hours of detection, to CERT-In and to IRDAI as the guidelines direct, with the Incident and Problem Management Policy defining who does what.
- Assurance. Periodic independent audits and vulnerability assessments of the systems that carry policyholder data, and your email platform is one of them.
On location: the 2023 guidelines are about governance and control, and they expect you to know and govern where policyholder data is processed. They are not, in themselves, a blanket data-localisation order for email. The reasons to keep mail in India or on your own servers are the same as elsewhere in Indian finance: evidencing control at audit, CERT-In's in-India log retention, and what your corporate policyholders and reinsurers ask in due diligence.
The honest part nobody markets
No email product is "IRDAI-compliant" on its own. Compliance belongs to the regulated entity and is evidenced through policies, controls and audits. What a platform can do is make each line of your Email Security Policy true and provable: MFA and role-based admin, SPF, DKIM and DMARC enforced so your policyholders are not phished in your name, S/MIME with a certificate authority you control for claims and medical correspondence, DLP rules that recognise policy numbers, Aadhaar and PAN, exportable audit trails, retention controls, and the choice of hosting in India or on your own infrastructure. Aligned and evidenced controls, not a badge, is the language your auditor and your board committee will accept.
A checklist for the next IRDAI audit
- An Email Security Policy exists, is board-approved, has an owner, and was reviewed within the last year.
- MFA is enforced on every mailbox and administrator account, including intermediaries' shared inboxes.
- SPF, DKIM and DMARC are published for every domain that sends to policyholders, with DMARC at quarantine or reject.
- Claims, medical and KYC documents are encrypted in transit and, where policy requires, signed or encrypted with S/MIME.
- DLP rules cover policy numbers, Aadhaar, PAN and health information, with alerts reaching a named owner.
- Login, access and admin logs are retained for at least 180 days, monitored, with clocks on authorised NTP.
- A tested playbook gets a compromised mailbox to a six-hour report to CERT-In and IRDAI.
- Mail retention and deletion match your record-keeping rules and your DPDP erasure duties for policyholders.
- The contract with your email provider covers data location, access, breach cooperation and audit rights.
- The email platform is inside the scope of your periodic independent audit and vulnerability assessment.
The same controls, mapped to the banking regulator, are in our RBI-aligned BFSI checklist; the duties every entity now carries under the data-protection law are on the DPDP and business email page; and insurers that want the server inside their own perimeter can read the on-premise edition page.

