Insurance
Resolve the exact IRDAI category: insurer, intermediary, broker, corporate agent, web aggregator, TPA, surveyor or another participant. Cyber and outsourcing obligations vary by entity and service.
Data and flows
Section titled “Data and flows”Proposal/KYC, family/nominee, financial, health/genetic where collected, underwriting, telematics, policy, premium, claims, hospital/provider, fraud, call and grievance data flow among insurer, intermediary, reinsurer, TPA, hospital/lab, surveyor, repair network, distribution partner and technology vendors.
The purpose inventory separates quotation, underwriting, issuance, servicing, claims, fraud, regulatory reporting, product analytics and cross-sell. A health disclosure for underwriting is not a standing permission for unrelated marketing.
System map
Section titled “System map”Policy administration, underwriting/rules engine, distribution/CRM, payment, document management, claims, TPA/provider portals, fraud/SIU, telephony, grievance, actuarial/data platform and outsourced cloud. Record authoritative sources and duplicates; claims packages often contain third-party and dependent data that cannot be disclosed wholesale.
Retention
Section titled “Retention”Configure proposal, policy, claims, medical evidence, KYC, recordings, grievance, fraud investigation, actuarial aggregates and security logs separately. A claim/legal limitation period, regulator record rule or litigation hold may justify preservation; consent withdrawal should still stop optional processing and delete unrelated copies.
Security and breach
Section titled “Security and breach”Apply IRDAI Information and Cyber Security Guidelines, 2023 to the correct category and audit classification, plus CERT-In and future DPDP clocks. The incident record captures insurer, intermediary/TPA notification chains, affected policyholders/claimants/dependants and accessible protective guidance.
Minimum product configuration
Section titled “Minimum product configuration”- entity/IRDAI registration and participant roles;
- sensitive purpose/data matrix for health, financial, family and fraud data;
- processor/recipient chain including TPA, hospital, reinsurer and distributor;
- policy/claim identifier-based rights matching;
- scoped third-party redaction and legal-review route;
- record-class retention and hold matrix;
- cyber audit/evidence calendar;
- grievance and ombudsman/escalation information where applicable.
Sample flow
Section titled “Sample flow”A policyholder requests correction of an address and erasure of an old marketing profile. Existing account authentication verifies the request. Policy administration receives the correction; marketing copies are deleted/suppressed; issued policy/claim records remain under the documented retention source; processors acknowledge; the response explains each outcome without exposing other insured persons.
Evidence
Section titled “Evidence”Notice/consent proof, underwriting purpose approval, health-data access reviews, contract instructions, TPA/provider propagation, retention rationale, claim-document redaction, cyber audit reference, incident submissions and grievance resolution.
Open counsel questions
Section titled “Open counsel questions”- Which IRDAI consolidation/master circular currently governs each entity and record class?
- Is each distributor, TPA, reinsurer or wellness provider a processor or independent Fiduciary for the specific purpose?
- Which claims/medical records can be corrected or erased without impairing contract, fraud or dispute evidence?
- What overseas reinsurance or support flows require sector and transfer controls?