Skip to content
eQomply
  • Platform

    Platform

    • Governance
    • Risk Management
    • Compliance Management
    • Integrations
    0 +

    Evidences Tracked

    0 +

    Regulatory Workflows

  • GRC Solutions

    By Role

    • For Compliance Leaders
    • For Chief Risk Officers
    • For Data Protection Officers
    • For CISOs
    • For Internal Audit Teams

    by industry

    • Banks & NBFCs
    • Insurance
    • Capital Markets
    • Pharma & Healthcare
    • More..

    by regulations

    • RBI Compliance
    • SEBI Compliance
    • IRDAI Compliance
    • DPDP Act
    • More..

    Featured Resource

    • How to Measure Compliance Training Effectiveness
    • Fourth-Party Risk Management Explained
  • Resources
  • Company
eQomply
Request Demo
IRDAI Compliance

IRDAI Corporate Governance Requirements for Insurers

August 4, 2026 Pritesh Baviskar No comments yet

Corporate governance in the Indian insurance sector operates under a regulatory framework that has grown considerably more prescriptive over the past decade. IRDAI corporate governance insurance requirements now extend well beyond broad principles, reaching into specific structural mandates around board composition, committee functioning, related party transactions, and disclosure obligations. For compliance officers and risk leaders at insurance companies, understanding these requirements at a granular level is no longer optional.

The Insurance Regulatory and Development Authority of India (IRDAI) has issued multiple guidelines, circulars, and master directions that collectively form the governance architecture insurers must comply with. These include the IRDAI (Corporate Governance) Guidelines, 2016 (and subsequent amendments), the Insurance Act, 1938 provisions as amended, and various circular-level requirements that address emerging governance concerns. This post unpacks the structural requirements, role-specific obligations, and common failure points that surface during IRDAI inspections.

IRDAI’s Corporate Governance Guidelines: The Structural Foundation

The IRDAI Corporate Governance Guidelines, 2016, remain the primary reference document for governance obligations. These guidelines apply to all insurers registered under Section 3 of the Insurance Act, 1938, covering life insurers, general insurers, health insurers, and reinsurers. They were issued under Section 14(2)(e) of the IRDA Act, 1999, giving them statutory force.

The guidelines establish a governance framework built on four pillars: board structure and accountability, management oversight mechanisms, transparency and disclosure, and policyholder protection. Unlike principles-based governance codes in some jurisdictions, IRDAI’s approach is notably prescriptive. Specific timelines for board meetings, mandatory committee structures, and detailed reporting formats leave limited room for interpretation.

Subsequent amendments and circulars have expanded these requirements. The 2020 circular on related party transactions introduced stricter disclosure norms. The 2023 amendments to investment governance added board-level accountability for investment decisions. For compliance teams, this means tracking not just the base guidelines but also the evolving circular-level requirements that modify or supplement them.

Applicability and Proportionality

One aspect that creates operational complexity is that IRDAI applies certain governance requirements proportionally based on the insurer’s size and business model. However, the core structural requirements around board composition, committee formation, and compliance officer appointment apply uniformly. This means even a relatively new insurer with limited scale must comply with the full governance infrastructure from inception, creating significant compliance overhead during early operational years.

Board Composition and Committee Requirements Under IRDAI

IRDAI mandates specific composition requirements for insurance company boards that go beyond what the Companies Act, 2013 requires for general companies. The board must have a minimum of one-third independent directors, with the chairperson being a non-executive director in most cases. IRDAI’s definition of independence aligns broadly with Section 149(6) of the Companies Act but adds insurance-sector-specific disqualifications.

The board must meet at least once every quarter, with a maximum gap of 120 days between two consecutive meetings. At least one meeting per year must be dedicated exclusively to risk management oversight, a requirement that many insurers initially overlooked but which IRDAI inspections have increasingly scrutinized.

Mandatory Board Committees

IRDAI requires the following committee structure as a minimum:

Committee Composition Requirement Meeting Frequency Key Mandate
Audit Committee Minimum 3 members, majority independent, chair must be independent At least 4 times per year Financial oversight, internal controls, statutory audit liaison
Investment Committee Minimum 3 members including CEO/CFO, at least one independent director At least quarterly Investment policy oversight, exposure monitoring, compliance with investment regulations
Risk Management Committee Minimum 3 members, chaired by independent director At least quarterly Enterprise risk oversight, risk appetite framework, emerging risk identification
Policyholder Protection Committee Minimum 3 members, majority non-executive, chaired by independent director At least quarterly Grievance redressal oversight, claims settlement monitoring, fair practice compliance
Nomination and Remuneration Committee Minimum 3 non-executive directors, majority independent At least twice a year Board appointment recommendations, key management personnel compensation, fit and proper assessment

Beyond these mandatory committees, larger insurers typically also maintain an ALM (Asset Liability Management) Committee, an IT Strategy Committee, and a With Profits Committee (for participating life insurers). While some of these are not explicitly mandated by IRDAI guidelines alone, they are expected based on business complexity and have been flagged during inspections where absent.

Committee Effectiveness Requirements

IRDAI does not just mandate committee existence. The guidelines require documented terms of reference for each committee, attendance records, action-taken reports on committee recommendations, and annual effectiveness assessments. Consider an insurer where the Risk Management Committee meets quarterly but its recommendations are not formally tracked to closure. This creates a governance gap that IRDAI inspectors will identify, because the guidelines require evidence that committee deliberations translate into management action.

Tracking committee effectiveness across multiple mandatory committees, each with its own composition requirements, meeting cadences, and documentation obligations, represents a significant compliance coordination challenge. Platforms like eQomply help insurers consolidate committee governance tracking alongside broader compliance obligations, ensuring that composition changes, meeting schedules, and action-item closure are managed within a unified framework rather than through disconnected spreadsheets.

Compliance Officer and Appointed Actuary Roles

IRDAI governance requirements create specific role-based accountability that goes beyond what most corporate governance frameworks require. Two roles carry particular regulatory significance: the Compliance Officer and the Appointed Actuary.

The Compliance Officer

Every insurer must appoint a Compliance Officer at a sufficiently senior level, typically not below the rank of Vice President or equivalent. This individual is responsible for ensuring compliance with all IRDAI regulations, reporting breaches to the board and to IRDAI, maintaining a compliance register, and conducting periodic compliance reviews. The Compliance Officer must have direct access to the board and the Audit Committee without requiring management intermediation.

IRDAI expects the Compliance Officer to submit quarterly compliance reports to the board, covering the status of compliance with all applicable regulations, any breaches identified, remediation actions taken, and emerging regulatory developments that require board attention. The officer must also certify compliance annually, a certification that carries personal liability implications.

A structural challenge arises when the Compliance Officer role is combined with other functions (such as Legal or Company Secretary). While IRDAI has not explicitly prohibited this, inspection observations have increasingly noted that combining the role dilutes its effectiveness, particularly at larger insurers where the volume of regulatory requirements demands dedicated attention.

The Appointed Actuary

The Appointed Actuary holds a unique governance position in insurance companies. Under Section 64VA of the Insurance Act and IRDAI regulations, the Appointed Actuary is responsible for certifying the insurer’s solvency position, advising the board on product pricing adequacy, and ensuring that policyholder liabilities are appropriately valued. The role carries statutory immunity from management direction on technical actuarial matters, creating a governance check that operates independently of the management hierarchy.

The board must ensure the Appointed Actuary has adequate resources, independence, and access to information. Any disagreement between the Appointed Actuary and management on matters of actuarial judgment must be reported to IRDAI, a requirement that creates a governance escalation mechanism unique to the insurance sector.

Related Party Transaction Governance

Related party transactions (RPTs) in insurance companies attract heightened IRDAI scrutiny because of the fiduciary nature of insurance operations. Policyholders’ funds must be managed in their interest, and transactions with related parties create inherent conflict-of-interest risks.

IRDAI’s RPT governance framework requires insurers to maintain a comprehensive policy on related party transactions approved by the board. All material RPTs must receive prior approval from the Audit Committee, and transactions above specified thresholds require board approval. The definition of “related party” extends beyond the Companies Act definition to include promoter group entities, joint ventures of promoters, and entities where key management personnel hold significant influence.

Arm’s Length Pricing and Documentation

Every related party transaction must be conducted at arm’s length, with documented evidence of pricing benchmarking. This is particularly relevant for insurance companies that engage in distribution arrangements with promoter-group banks, reinsurance arrangements with group reinsurers, or IT services from group technology companies. Each of these common transaction types requires documented justification that the pricing reflects market terms.

Consider a life insurer whose bancassurance partnership with its promoter bank involves commission structures, infrastructure sharing, and data access arrangements. Each element of this relationship constitutes a related party transaction requiring separate arm’s length assessment, Audit Committee approval, and disclosure. The compliance burden of documenting, approving, and reporting these transactions across multiple touchpoints creates a governance workflow that requires structured tracking and evidence management.

Building an insurance compliance program that adequately addresses RPT governance requires both policy-level clarity and operational mechanisms for capturing transaction-level evidence as it occurs, not retrospectively assembling documentation before inspections.

Reporting and Disclosure Obligations

IRDAI corporate governance insurance requirements include extensive reporting and disclosure obligations, both to the regulator and to the public. These operate at multiple frequencies and cover different governance dimensions.

Periodic Filings with IRDAI

Report Frequency Key Contents
Corporate Governance Report Annual Board composition, meeting attendance, committee details, compliance certificate
Compliance Report Quarterly Compliance status with all regulations, breaches, remediation actions
Related Party Transaction Report Half-yearly All RPTs with details of nature, value, approval status
Solvency Certificate Quarterly Solvency margin position certified by Appointed Actuary
Risk Management Report Annual Enterprise risk profile, key risks, mitigation measures, risk appetite utilization
Investment Return Monthly/Quarterly Investment portfolio details, exposure concentrations, compliance with investment norms

Public Disclosures

Insurers must disclose governance structures, financial results, solvency positions, and grievance redressal statistics on their websites. The IRDAI Annual Report format requires detailed governance disclosures including director qualifications, committee compositions, number of meetings held, and attendance records. These disclosures create public accountability and make governance gaps visible to stakeholders including policyholders, rating agencies, and market analysts.

The operational challenge with these disclosures is ensuring consistency across multiple reporting channels. The same governance data must appear consistently in IRDAI filings, annual reports, website disclosures, and stock exchange filings (for listed insurers). Inconsistencies, even inadvertent ones, create inspection findings and raise questions about the reliability of the insurer’s governance reporting infrastructure.

Cybersecurity and Technology Governance Reporting

An increasingly important dimension of IRDAI governance reporting relates to technology and cybersecurity. The IRDAI cybersecurity guidelines require board-level oversight of information security, periodic reporting on cyber risk posture, and incident disclosure. This represents a newer governance obligation that many insurers are still operationalizing, with board members requiring education on cyber risk matters to discharge their oversight responsibilities effectively.

Common Governance Findings During IRDAI Inspections

IRDAI conducts periodic on-site inspections of insurers, and governance findings consistently feature in inspection reports. Understanding the most common findings helps compliance teams prioritize their governance strengthening efforts.

Board and Committee Functioning Gaps

Inspections frequently identify that while committees exist on paper, their functioning falls short of regulatory expectations. Common findings include: committees meeting with less than the required quorum, particularly for independent director attendance; action-taken reports not being presented to the board; committee terms of reference not being periodically updated to reflect evolving regulatory requirements; and board minutes lacking sufficient detail on deliberations before decisions.

A recurring finding involves the independence assessment of independent directors. IRDAI inspectors often find that the independence declaration process is perfunctory, without genuine assessment of whether circumstances have changed that might compromise independence. This is particularly relevant where independent directors serve on multiple boards within the same financial services group.

Compliance Function Deficiencies

Findings related to the compliance function typically involve inadequate staffing relative to the volume of regulatory requirements, absence of a formal compliance testing program, delayed identification of regulatory changes, and insufficient evidence of compliance monitoring (as distinct from reliance on management self-certification). Inspectors increasingly expect to see documented compliance testing methodologies and sampling approaches rather than blanket compliance assertions.

Related Party Transaction Documentation

RPT-related findings remain among the most common governance observations. These include transactions not being identified as related party transactions at the time of execution, retrospective approvals instead of prior approvals, insufficient arm’s length pricing documentation, and incomplete disclosure in periodic reports. The root cause is often systemic: the absence of an automated mechanism to flag transactions with related parties at the point of initiation.

Policy Management Failures

Inspectors expect insurers to maintain current, board-approved policies across multiple domains: investment, underwriting, claims, reinsurance, risk management, IT governance, outsourcing, and fraud prevention, among others. Common findings include policies that have not been reviewed within the mandated periodicity (typically annually), policies that do not reflect current regulatory requirements, and absence of evidence that policies have been disseminated to relevant personnel.

Managing policy lifecycles across twenty or more governance policies, each requiring periodic review, board approval, version control, and dissemination tracking, represents exactly the kind of structured compliance workflow where purpose-built GRC infrastructure adds measurable value. eQomply’s policy management capabilities help insurance compliance teams maintain version control, track approval workflows, and evidence attestation across their policy portfolio.

Disclosure and Reporting Inconsistencies

Inspectors cross-reference disclosures across multiple filings to identify inconsistencies. A governance report showing four Audit Committee meetings while minutes evidence only three, or a compliance certificate stating full compliance while internal audit reports identify regulatory gaps, creates credibility issues that extend the scope and intensity of the inspection. These inconsistencies typically arise from manual compilation processes where different teams prepare different reports without a single source of truth for governance data.

Building Governance Resilience: A Structural Approach

IRDAI corporate governance insurance compliance is not a static checkbox exercise. The regulatory framework evolves with each circular, the complexity of governance obligations increases with business growth, and inspection expectations continue to rise. Insurance compliance leaders need governance infrastructure that provides real-time visibility into compliance status, automates evidence capture, and enables consistent reporting across multiple regulatory touchpoints.

The interconnected nature of governance obligations, where board composition affects committee validity, committee functioning affects compliance certification, and compliance status affects disclosure accuracy, demands a consolidated approach. Fragmented governance tracking through disconnected registers, email-based workflows, and manual evidence compilation creates the very gaps that inspections identify.

For compliance officers and CROs managing IRDAI governance requirements alongside operational compliance obligations, the question is whether their current infrastructure can sustain increasing regulatory expectations without proportional increases in team size. If you are evaluating how to consolidate governance tracking, evidence management, and regulatory reporting into a unified framework built for Indian regulatory requirements, a focused conversation about your current governance architecture would be a practical starting point.

  • compliance
  • corporate governance
  • insurance
  • IRDAI
Pritesh Baviskar
Pritesh Baviskar

Founder at eQomply. Writes about compliance, regulatory shifts, and what it takes to build GRC functions that actually work.

Post navigation

Previous

Search

Categories

  • Board Reporting (5)
  • CERT-In (5)
  • Compliance Management (10)
  • DPDP Act (10)
  • Evidence Management (5)
  • GRC (8)
  • Guides (5)
  • IRDAI Compliance (5)
  • Perspectives (1)
  • RBI Compliance (9)
  • SEBI Compliance (5)
  • Third Party Risk (5)
  • Uncategorized (4)

Recent posts

  • IRDAI Corporate Governance Requirements for Insurers
  • How to Measure Compliance Training Effectiveness
  • Fourth-Party Risk Management Explained

Tags

AML audit audit readiness banking BFSI board reporting breach notification case-studies CERT-In circulars compliance compliance automation compliance calendar compliance culture CRO cybersecurity data processing data protection deadlines documentation DPDP evidence governance GRC incident reporting incident response inspection insurance IRDAI IT governance NBFC outsourcing payment aggregator payments privacy RBI regulation risk risk management risk register SEBI technology third party risk vendor agreements vendor risk

Related posts

Third Party Risk

Fourth-Party Risk Management Explained

July 30, 2026 Pritesh Baviskar No comments yet

Understand fourth-party risk management, including indirect vendor dependencies, concentration risk, and regulatory expectations.

CERT-In

Incident Response Plan Compliance in India

July 28, 2026 Pritesh Baviskar No comments yet

Understand incident response plan requirements across CERT-In, RBI, SEBI, and IRDAI, including reporting timelines and documentation.

Compliance Management

Understanding the Overlap Between CISO and CCO Roles

July 27, 2026 Pritesh Baviskar No comments yet

Explore how CISOs and CCOs collaborate on cybersecurity, regulatory compliance, vendor risk, incident response, and board reporting

Subscribe to Field Notes

    Enterprise GRC for regulated industries

    Platform
    • Overview
    • Policy Management
    • Risk Management
    • Compliance
    Solutions
    • By Role
    • By Industry
    • By Regulation
    Resources
    • Field Notes
    • Guides
    • Regulatory Library
    • Terms of Services
    • Privacy Policy

    © QomplySuite Private Limited Copyright 2026