An IT security consultant and an insurance operations manager reviewing an endpoint protection checklist on a laptop during an IRDAI IT compliance review in a Navi Mumbai office

IRDAI IT compliance checklist: endpoint protection for insurance companies

An IT security consultant and an insurance operations manager reviewing an endpoint protection checklist on a laptop during an IRDAI IT compliance review in a Navi Mumbai office

Short answer. An IRDAI IT compliance checklist is the set of endpoint controls an insurer must be able to prove on the day an auditor asks: a full device inventory, encryption on every laptop, endpoint DLP that logs data movement, centrally managed EDR, patched machines, MDM with remote wipe, file-level access logs, a same-day offboarding drill, and certified secure disposal. The auditor is not testing whether you feel secure. They are testing whether you can produce evidence in one document instead of forty.

09:10 on a Tuesday. A 240-person life insurance intermediary in Andheri, halfway through an IRDAI information and cyber security review, had produced every policy document the auditor asked for. The board-approved security policy. The CISO appointment letter. The VAPT report from March. Then came the question that lives outside the policy binder. Which laptop last opened the policyholder KYC folder, and did that laptop have permission to. The room went quiet. This is where an IRDAI IT compliance checklist stops being paperwork and becomes a search for evidence that either exists or does not.

09:10 AM: the review starts friendly

The auditor was polite. They usually are. Deepak, the IT lead, walked them through the antivirus console first, because that is the thing every IT lead is proudest of. Green ticks across the fleet, definitions current. He was answering a different question from the one being asked.

Antivirus watches for things coming in. The IRDAI framework, at its core, cares about policyholder data going out. A KYC scan on a personal drive. A claims file forwarded to a Gmail address. A commission statement copied to a USB stick on someone’s last working day. The antivirus dashboard has no page for any of that. Deepak had built a wall facing the wrong direction, and nobody had told him, because until an auditor sits across the table, the wall looks complete.

10:40 AM: the gap nobody had named

I want to be honest about a mistake, because the mistake is the lesson, and it was mine as much as theirs. When we scoped this account two months earlier, I had ticked the endpoint box myself. Managed antivirus, present. MDM, present on the newer machines. I moved past it. What I had not checked was whether any of it produced a record the insurer could hand to a regulator.

It did not. The MDM covered 180 of 240 laptops. The other 60 were older machines that had quietly aged out of enrolment. Encryption was on by default on the new fleet and switched off on the old one. And the access log, which existed, recorded logins to the server. It said nothing about who touched the file. Eleven people had a login. Nobody could say who had opened the folder on the 14th. Amber, all of it. I had read amber as green because the tools were installed. Installed is not the same as reporting.

This is not carelessness. It is how most insurance IT estates get built. You buy antivirus because procurement understands antivirus. You add MDM when the first phone goes missing. Data movement logging never enters the conversation until the person asking it is holding a clipboard and a deadline. If you want the longer version of that gap, we wrote a plain guide to what data loss prevention actually does.

The IRDAI IT compliance checklist for endpoint protection

Here is the list we rebuilt with Deepak that afternoon. Not the policy layer, which he already had. The endpoint layer, which is where IRDAI reviews and DPDP audits both land. Work down it in order.

  1. A single device inventory. Every laptop, desktop, and tablet that touches policyholder data, with the name of the person holding it. If you cannot list your devices, you cannot protect them, and the auditor starts here for exactly that reason.
  2. Full-disk encryption on every machine. New fleet and old. A lost laptop with an encrypted disk is a paperwork event. The same laptop unencrypted is a reportable breach under the DPDP Act.
  3. Endpoint DLP that logs data movement. USB, email, upload forms, cloud sync, a screenshot pasted into a personal chat. The who, the what, the when. This single record is what an IRDAI reviewer and a DPDP-compliant data protection setup both stand on.
  4. Centrally managed EDR with real reporting. Not agents scattered across machines reporting to nobody. One console, one exportable status. If you are choosing a platform, our EDR buying guide for India lays out the shortlist.
  5. Patch and OS currency. No machine running an operating system past its support date. End-of-support endpoints are the first thing a VAPT flags and the easiest finding for an auditor to write up.
  6. MDM on the full fleet, with remote wipe. Every device enrolled, not 75 percent of them. The 60 unenrolled laptops were the whole risk, and they were invisible on the dashboard that looked green.
  7. File-level access logs. Not server logins. A record that maps a person to the policyholder file they opened. This is the exact question that stopped the room, so it is the exact evidence you build first.
  8. A same-day offboarding drill. When someone resigns, device recovered and access revoked the same day, on a checklist someone signs. Most quiet data loss walks out on a resignation. We described how in the DPDP readiness checklist for HR and IT teams.
  9. Certified secure disposal at end of life. When a device retires, the data is wiped to a standard you can certify, not sold on with the drive intact. This is the last mile of device lifecycle management, and IRDAI reviewers do ask what happens to old machines.
  10. One evidence export. Every control above, producing a single document you can hand over. The difference between passing and failing a review is rarely the security. It is whether the proof lives in one file or forty.

The framework behind items one through nine sits in the IRDAI information and cyber security guidelines, the six-hour incident reporting clock in the CERT-In 2022 directions, and the breach-notification duty in the DPDP Act. Read them in that order. They ask the same question three ways: can you prove what happened to the data.

What I told the operations head

She asked the fair question. Do we fail. No, I said. You have a gap, not a breach, and a gap you can close before the follow-up date is a finding you get to answer rather than a fine you get to pay. The 60 unenrolled laptops go first. Encryption on all of them by Friday. DLP logging switched on next, so that the next time an auditor asks who opened the folder on the 14th, there is a name and a timestamp, not a shrug.

We have run this exact sequence for a national insurer across a 2,500-device fleet, so it is not theory. Inventory, then encryption, then the data-movement log, in that order every time.

If you are doing this yourself

Start with the inventory, even if it is a spreadsheet for now. You cannot protect a device you have not written down. Then check one thing that most teams skip: open your access log and try to answer, for a single sensitive file, who touched it last week. If you cannot, that is your first project, and it is smaller than it sounds. Encryption and MDM are usually a configuration, not a purchase. The data-movement log is the piece that needs a real tool and a real owner. A DLP nobody watches is just a false sense of cover, so be honest about who owns the alert on the day it fires.

Key takeaways

  • An IRDAI IT compliance checklist is about evidence, not installed software. Green ticks on an antivirus console answer the wrong question.
  • The endpoint layer is where insurance reviews and DPDP audits both land: inventory, encryption, DLP logging, EDR, patching, MDM, file-level access logs, offboarding, secure disposal.
  • Installed is not reporting. MDM on 75 percent of the fleet is a gap, not a control.
  • Fix in order: inventory, encryption, data-movement log. Each step makes the next provable.

Frequently asked questions

What does IRDAI actually require for endpoint protection?

IRDAI’s cyber security framework asks insurers and intermediaries to protect policyholder data across its full life, which in practice means a board-approved policy, a CISO, regular VAPT, and controls at the device level that you can evidence. The endpoint pieces reviewers probe are encryption, managed antivirus or EDR, patching, device management, and a record of how data moves and who accessed it.

Is antivirus enough to pass an IRDAI review?

For malware, mostly yes. For the review, no. Antivirus watches for threats coming in. The finding at an insurance audit is almost always about data going out: a KYC file on a personal drive, a claims folder in a chat app. Different tool, different question. The gap between the two is where the audit finding lives.

How long does it take to close an endpoint gap before a follow-up date?

For a mid-size insurer, the inventory and encryption pass usually take a week or two. Enrolling the stray machines into MDM is a few days. The data-movement logging layer needs scoping and an owner, so plan two to four weeks for that to run correctly. We reply to a scoping request within 24 working hours and can tell you the honest timeline for your fleet.

Does DPDP change anything for insurers already under IRDAI?

It raises the stakes on the same controls. IRDAI wants your policyholder data protected. The DPDP Act adds a breach-notification duty and penalties that can reach 250 crore rupees. The good news is that one well-built endpoint evidence layer satisfies both, which is why we scope it once and map it to each regulator rather than building twice.

Still deciding

If your next IRDAI review or DPDP audit is on the calendar, the cheapest hour you will spend is the one that finds the gaps before the auditor does. We have done this for 200+ Indian businesses, delivered pan-India from Vashi, Navi Mumbai. Start with the free endpoint and data-movement audit, no card and no contract.

Prefer to read first. Our DPDP readiness checklist covers the paperwork side, and the Secure Data Guard page shows what the data-movement log looks like in practice.

P.S. Priya here. Three weeks after that Tuesday, Deepak sent me one line. The auditor asked who opened the master file, and this time the log had a name. That is the only sentence I needed to know the project worked. If that is your week, you already know who to call.


Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *