A CERT-In Empanelled Auditing Organization
ISNP Audit IRDAI
CERT-In Auditor Services

Insurance Self-Network Platform (ISNP) audit

The CERT-In empanelled security audit IRDAI requires before your insurance e-commerce platform goes live, and the annual review that keeps it compliant.

Overview

Selling insurance online? IRDAI requires an independent security audit.

An Insurance Self-Network Platform (ISNP) is the electronic platform, a website, a mobile app, or both, through which an insurer or intermediary conducts insurance e-commerce. It can only operate with IRDAI’s prior permission, and under the Authority’s insurance e-commerce guidelines (IRDA/INT/GDU/ECM/055/03/2017), the platform’s controls, systems, procedures and safeguards must be independently reviewed.

Crucially, the platform cannot mark its own homework. IRDAI requires the assessment to come from outside the organisation, from a CERT-In empanelled auditing firm, or a professional holding an equivalent CISA or DISA (ICAI) qualification. It is required once before the platform opens for business, and then on a recurring annual basis for as long as it operates. What the auditor produces does not stop at the engineering team either: it travels up to the Board, or the sub-committee acting for it. As a CERT-In empanelled auditing organisation, SICHERTEN runs the assessment end to end and writes it up for both destinations, the regulator and the boardroom.

What’s covered

What the ISNP audit examines.

Application security & VAPT

Full vulnerability assessment and penetration testing of the platform, web portal, mobile app and APIs, against the OWASP Top 10.

Payment & premium flows

Payment-gateway integration, premium collection, refunds and the security of transaction and settlement paths.

Policyholder data protection

Protection of proposal, KYC, medical, financial and policy data, in transit and at rest, with access controls and encryption.

Monitoring & audit trail

Whether the platform can actually see what its own data-processing systems are doing, logging, alerting and an audit trail that would stand up to scrutiny.

Network & infrastructure

Network architecture, server and cloud hardening, exposed services, security headers and configuration review.

ISMS & ISO 27001 alignment

Information security management system, policies, logging, incident response and business continuity, aligned to ISO/IEC 27001.

Who needs this

Is this the right fit?

Any entity operating, or applying to operate, an insurance e-commerce platform under IRDAI permission.

Insurers (life, general, health)Running their own ISNP.
Insurance brokersSelling and servicing policies online.
Corporate agentsOperating a self-network platform.
Web aggregatorsDistributing insurance digitally.
New ISNP applicantsCertifying the platform before go-live.
Existing ISNP operatorsDue for the mandatory annual review.
Regulatory drivers

What IRDAI requires

IRDAI’s guidelines on insurance e-commerce set out what an ISNP must have in place, and who may attest to it. Requirements are updated by the Authority from time to time, so we confirm the current scope against the applicable circulars for your entity type before the engagement begins.

Independent external review
How the platform runs, and the safeguards wrapped around it, has to be examined by an assessor from outside the business: a CERT-In empanelled firm, or a CISA/DISA-qualified equivalent. This is a recurring annual obligation, not a one-time clearance.
Board oversight
The findings do not stay with IT. Both the auditor’s report and the platform’s security-management arrangements have to be tabled for the Board, or the sub-committee it delegates to, so that accountability sits at the top of the organisation.
Monitoring of data processing
The platform is expected to watch its own data-processing systems continuously, with monitoring controls it can point to and evidence, not simply assert.
A managed security system, not ad-hoc controls
Security has to be run as a system, benchmarked to ISO/IEC 27001 or an equivalent standard, and kept current through the yearly review rather than allowed to drift between audits.
Escalation of harmful findings
Where the audit turns up something capable of harming policyholders, the regulator has to hear about it, typically alongside the plan to put it right.
How we work

From scoping to a board-ready report.

A structured audit lifecycle that satisfies the regulator and gives your engineers something they can act on.

Scoping questionnaire

A structured intake defines the boundary, every portal, app, API, database and third-party integration in scope.

Vulnerability assessment

Automated, breadth-first discovery across the application, network, infrastructure and cloud layers.

Penetration testing

Manual, business-logic testing, policy purchase and servicing flows, premium payment, access control and policyholder-data exposure.

Controls & ISMS review

Verification of internal monitoring controls, access management, encryption, logging, BCP and ISO 27001 alignment.

Reporting

Risk-rated findings with evidence, business impact and prioritised remediation guidance, written for both engineers and the Board.

Remediation & revalidation

Support through closure of critical and high findings, then independent retesting and the final signed audit certificate.

What you receive

A report your Board and IRDAI can rely on.

  • ISNP security audit reportScope, methodology, control status, findings and evidence, structured for IRDAI submission.
  • Risk-rated findingsEach with CVSS severity, reproduction steps and concrete remediation guidance.
  • Board-ready summaryThe risk posture in business terms, for placing before the Board or its sub-committee.
  • Remediation & revalidationIndependent retesting to confirm critical and high findings are closed.
  • Signed audit certificateCompliance attestation signed under our CERT-In empanelment.

Standards & frameworks

The audit is anchored to the regulator’s expectations and the standards the platform is measured against.

IRDAICERT-InISO/IEC 27001OWASPECM/055/03/2017
Checklist

Are you ready? A quick checklist

What to have in place before the audit begins.

IRDAI permission / ISNP-1 filed
Platform build stable and frozen
Architecture & data-flow documentation
Test accounts for every user role
API collection (OpenAPI / Postman)
Information security policies & ISMS
Payment-gateway integration details
Named technical point of contact
FAQ

Common questions

Do we need the audit before launch, or only annually?
Both, and the second one catches people out. An independent assessment is needed before the platform opens to customers, but the obligation does not end at go-live: it repeats every year for as long as you operate the platform. Teams that budget only for the launch audit find themselves scrambling twelve months later, so we schedule the recurring review into the engagement from the start.
Must the auditor be CERT-In empanelled?
IRDAI requires the review to be conducted by an external, independent and suitably qualified auditor, a CERT-In empanelled organisation, or an equivalently qualified CISA or DISA (ICAI) professional. A CERT-In empanelled auditor is the route most insurers and intermediaries choose, because the empanelment is nationally recognised and independently verifiable. SICHERTEN is CERT-In empanelled.
What has to go to the Board?
Your directors do. The report, together with how the platform manages security, has to reach the Board or the sub-committee standing in for it, which means the document cannot be written purely for engineers. We therefore write it in two registers: a technical body your developers can remediate against line by line, and an executive summary that lets directors understand and discharge their oversight duty. Separately, anything the audit uncovers that could harm policyholders goes to IRDAI as well.
How long does it take?
For a typical platform, three to six weeks from scoping to final report, depending on the size of the platform, the number of integrations and how quickly findings are remediated. Engagements needing substantial remediation before the final report can run longer, so we recommend starting well ahead of your go-live or annual-review date.
Related services

Continue exploring

Launching or renewing your ISNP?

Tell us about your platform and we’ll scope the audit with you, and get you to a board-ready report.