The Insurance Regulatory and Development Authority of India (IRDAI) has issued a comprehensive fraud risk management framework to strengthen cybersecurity and internal controls among insurers and reinsurers. Scheduled to come into effect from April 1, 2026, the new guidelines mandate all insurance entities to establish a Board-approved fraud risk policy, maintain a fraud risk management function, and report frauds above ₹1 crore within 30 days.
The framework classifies frauds into four categories: policyholder fraud, intermediary fraud, internal fraud, and third-party fraud. It requires insurers to use advanced analytics and early warning systems to detect potential red flags and minimise losses. A centralised fraud repository must be maintained, with periodic reviews and board-level oversight. Insurers must also submit half-yearly fraud monitoring reports and conduct employee training on fraud risk.
To further bolster accountability, each insurer must designate a Chief Risk Officer or another senior executive as the nodal officer for fraud monitoring and regulatory reporting. Reinsurers and foreign reinsurance branches operating in India are also covered under the directive. This proactive initiative by IRDAI aims to build trust and resilience in the insurance sector by minimising financial leakages and improving governance standards.
For more details and structured learning, please explore our Fraud Risk Management Course.
