Insurance intermediaries play a key role in connecting insurance companies with individuals and businesses. They assist customers in understanding policy features, comparing products, completing proposal forms, paying premiums through authorised channels and obtaining support during policy servicing and claim settlement. Since their advice and conduct can directly influence a customer’s insurance decision, these intermediaries are closely supervised by the Insurance Regulatory and Development Authority of India.
IRDAI protects policyholders’ interests and regulates the orderly development of India’s insurance sector. Insurance intermediaries must comply with the Insurance Act, 1938, the IRDA Act, 1999, applicable regulations, circulars, guidelines and master directions. Compliance requirements vary depending on whether the entity is an insurance broker, corporate agent, insurance marketing firm, web aggregator, third-party administrator, surveyor or loss assessor. However, most intermediaries must follow common obligations relating to registration, governance, professional conduct, customer protection, employee training, financial soundness, record maintenance, cyber security, grievance redressal and timely regulatory reporting.
Meaning of an Insurance Intermediary
An insurance intermediary is a person or regulated organisation that facilitates insurance-related transactions between an insurer and a customer. The intermediary does not ordinarily carry the insurance risk in its own name. Instead, it helps in the solicitation, distribution, placement, servicing, administration or assessment of insurance business. The nature of an intermediary’s responsibilities depends on its registration category. An insurance broker may represent clients and arrange suitable insurance coverage from insurers.
A corporate agent may solicit and service insurance products under arrangements with authorised insurers. An insurance web aggregator may provide online information and comparison facilities for insurance products. A third-party administrator may provide health insurance servicing and claim-administration support under an agreement with an insurer. Similarly, a surveyor and loss assessor may investigate and assess the extent of an insured loss. An entity must identify the exact category under which it proposes to operate before commencing insurance-related activities. Undertaking activities beyond the permitted category may be treated as unauthorised insurance intermediation.
Major Categories of Insurance Intermediaries
Insurance Brokers
Insurance brokers are entities registered by IRDAI to arrange insurance business and provide permitted services to clients. A direct broker may arrange life, general or health insurance for clients from insurers operating in India. A reinsurance broker primarily arranges reinsurance business between insurers and reinsurers, whereas a composite broker may undertake both direct insurance and reinsurance broking activities.
Apart from arranging insurance, a broker may provide permitted services such as risk-management support, claim consultancy and advice relating to insurance coverage. However, the broker must operate within the functions permitted under the IRDAI (Insurance Brokers) Regulations, 2018.
Corporate Agents
A corporate agent is an eligible organisation holding a valid Certificate of Registration from IRDAI for soliciting and servicing insurance business. Banks, non-banking financial companies, cooperative societies, companies, limited liability partnerships and certain other permitted entities may apply for registration as corporate agents, subject to satisfaction of the applicable conditions.
Corporate agents may operate in life, general or health insurance categories, depending on their registration. They must enter into arrangements with permitted insurers and ensure that insurance products are solicited only through qualified and certified personnel. The corporate agent must also maintain a board-approved policy covering insurer tie-ups, business mix, products to be distributed, servicing standards, grievance handling and regulatory reporting.
Insurance Marketing Firms
An Insurance Marketing Firm, commonly called an IMF, is permitted to solicit and procure insurance products within the scope of its registration. It may also distribute certain other financial products where such distribution is expressly permitted under the applicable regulations.
An IMF must appoint qualified personnel, including a principal officer and insurance sales persons, and must maintain the prescribed infrastructure and financial requirements. It must ensure that insurance solicitation is undertaken only in the geographical area, product category and operational structure authorised by IRDAI.
Insurance Web Aggregators
An insurance web aggregator operates an online platform that provides information and comparison facilities relating to insurance products. Its website may allow customers to understand and compare features, premiums and benefits of insurance products offered by different insurers.
The web aggregator must ensure that the information displayed on its platform is accurate, updated, unbiased and presented in the prescribed format. Its principal business must remain insurance web aggregation, and it cannot use the platform to undertake unrelated commercial activities that are prohibited under the applicable regulations. The intermediary must also comply with specific requirements relating to capital, net worth, authorised verifiers, telemarketing, lead generation and website operations.
Third-Party Administrators
A Third-Party Administrator, or TPA, is generally engaged by an insurer to provide health insurance services under a formal agreement. Its functions may include issuing health cards, maintaining hospital networks, processing cashless authorisation requests, verifying claim documents and assisting in health claim administration.
A TPA cannot act as an insurer or independently decide insurance coverage outside the terms authorised by the insurer. It must maintain confidentiality of medical records, establish claim-processing controls and comply with applicable timelines, reporting standards and customer-service requirements.
Surveyors and Loss Assessors
Surveyors and loss assessors are licensed professionals who investigate, quantify and report losses arising under general insurance policies. Their role is particularly important in property, fire, engineering, marine, motor and other general insurance claims.
A surveyor must conduct the assessment independently, objectively and professionally. The survey report should explain the cause of loss, extent of damage, policy coverage, salvage, depreciation and the amount of loss assessed. The surveyor cannot favour the insurer or the claimant and must maintain confidentiality of the information received during the assignment.
Legal Outline Governing Insurance Intermediaries
The compliance obligations of insurance intermediaries arise from several laws and regulations. The Insurance Act, 1938 contains important provisions concerning insurance business, commissions, rebates, licensing and regulatory action. The Insurance Regulatory and Development Authority Act, 1999 establishes IRDAI and provides it with powers to regulate the insurance industry and protect policyholders. In addition to these principal laws, every intermediary must comply with the regulations governing its specific category. Insurance brokers are governed by the IRDAI (Insurance Brokers) Regulations, 2018. Corporate agents are governed by the IRDAI (Registration of Corporate Agents) Regulations, 2015.
Web aggregators are governed by the IRDAI (Insurance Web Aggregators) Regulations, 2017. Insurance marketing firms, TPAs and surveyors are also regulated through their respective regulations. Common regulatory requirements may also arise under the IRDAI commission framework, policyholder-protection requirements, insurance-advertising rules, information and cyber-security guidelines and anti-money laundering directions. The intermediary must therefore monitor not only its principal regulations but also all subsequent amendments, circulars and master circulars issued by IRDAI.
Obtaining and Maintaining Valid IRDAI Registration
An insurance intermediary must obtain the appropriate Certificate of Registration, licence or regulatory approval before beginning insurance-related operations. Merely incorporating a company, registering an LLP or entering into an agreement with an insurer does not authorise the entity to solicit insurance business. The application must be submitted in the prescribed manner along with the required documents, application fee, business plan, financial information, infrastructure details and information regarding promoters, directors, partners, principal officers and key personnel. IRDAI may examine whether the applicant possesses adequate capital, competent management, suitable infrastructure, professional expertise and a viable business model.
After registration is granted, the intermediary must comply with all conditions mentioned in its Certificate of Registration. The registration number should be displayed on the website, official communications, advertisements and business documents wherever required. The intermediary should not represent itself as an insurer or suggest that IRDAI guarantees its business or the products it distributes. The registration must also be renewed within the prescribed period. The intermediary should maintain a regulatory calendar showing the registration expiry date, renewal window, filing requirements and applicable fees. Failure to obtain timely renewal can result in the intermediary being prohibited from undertaking new insurance business.
Operating Only Within the Permitted Scope
Every intermediary must limit its activities to the functions permitted under its registration. A direct broker may arrange direct insurance business and provide permitted risk-management or claim-related services. It cannot undertake reinsurance broking unless it holds the appropriate category of registration. Similarly, a corporate agent may distribute insurance products only through permitted insurer arrangements and authorised personnel. A web aggregator may provide online comparison and permitted lead-generation services, but it must not undertake unrelated activities that conflict with the restrictions imposed by its regulations.
A TPA may administer health insurance services on behalf of an insurer, but it cannot underwrite insurance risk or independently alter policy terms. A surveyor may assess losses but cannot guarantee that the insurer will settle the claim for the amount assessed. The intermediary should clearly document its permitted and prohibited activities in its internal compliance manual. Employees should also receive regular training so that they do not unintentionally provide services beyond the entity’s regulatory authority.
Capital, Contribution and Net-Worth Compliance
Many insurance intermediaries are required to maintain a prescribed minimum paid-up capital, contribution or net worth. These requirements are intended to ensure that the intermediary has sufficient financial strength to conduct its business responsibly and meet its operational obligations. The applicable amount varies according to the category of intermediary. Insurance brokers are subject to different capital and net-worth requirements depending on whether they are registered as direct, reinsurance or composite brokers. IRDAI’s broker guidance, for example, distinguishes the prescribed capital and continuing net-worth requirements for these three categories.
Corporate agents exclusively engaged in insurance intermediation and insurance web aggregators are also subject to category-specific capital and net-worth conditions. A web aggregator must ensure that its net worth does not fall below the level prescribed under the applicable regulations during the validity of its registration. The intermediary must monitor its financial position continuously. Accumulated losses, substantial expenses, dividend distributions, related-party transactions or withdrawal of capital by promoters may affect compliance. It is therefore advisable to calculate net worth periodically rather than waiting until the end of the financial year.
Where a chartered accountant’s net-worth certificate is required, it should be obtained and filed within the prescribed period. Any reduction below the required level should be immediately reported to senior management, and corrective steps should be taken without delay.
Regulatory Deposit Requirements
Certain intermediary categories, particularly insurance brokers, may be required to maintain a specified deposit with a scheduled bank. The deposit acts as a financial safeguard and must be maintained in the manner prescribed under the applicable regulations. The intermediary must ensure that the deposit remains free from charge, lien, pledge or encumbrance.
It should not be used as security for loans, working-capital facilities or other financial obligations without regulatory permission. The finance and compliance teams should periodically obtain confirmation from the bank regarding the existence and status of the deposit. Any accidental marking of a lien or charge should be corrected immediately and reported wherever required.
Fit-and-Proper Requirements
Promoters, shareholders, directors, partners, principal officers and other key management personnel of an insurance intermediary must satisfy the applicable fit-and-proper criteria. These criteria are designed to ensure that the intermediary is controlled and managed by persons having integrity, financial soundness, competence and a good reputation. While assessing fit-and-proper status, IRDAI may consider whether the individual has been convicted of an offence, declared insolvent, involved in fraud, subjected to regulatory action or associated with an entity whose licence was cancelled. The Authority may also examine pending criminal, civil or regulatory proceedings and the individual’s financial conduct.
Fit-and-proper status is not limited to the registration stage. It is a continuing requirement. The intermediary should obtain periodic declarations from directors, partners and key personnel confirming whether any material change has occurred in their status. Where a person becomes disqualified or is involved in a material regulatory or criminal proceeding, the matter should be placed before the board and reported to IRDAI in accordance with the applicable regulations.
Appointment of a Qualified Principal Officer
Most corporate insurance intermediaries must appoint a principal officer who is responsible for supervising the entity’s insurance activities. The principal officer acts as the primary regulatory and operational person responsible for ensuring that the organisation complies with IRDAI requirements. The principal officer must possess the educational qualifications, training and examination certification prescribed for the relevant category. In the case of an insurance broker, the principal officer must hold an executive position and must be specifically designated to perform the responsibilities connected with the broking business.
The responsibilities of the principal officer generally include supervising sales personnel, monitoring regulatory filings, reviewing customer complaints, maintaining communication with insurers and IRDAI, ensuring compliance with the code of conduct and escalating material violations to the board. The intermediary should also establish an effective succession plan. Where the principal officer resigns, dies, becomes disqualified or remains absent for an extended period, the entity should promptly appoint an eligible replacement and obtain the necessary approval or submit the required intimation.
Training and Certification of Insurance Personnel
Insurance products should be solicited or explained only by individuals who possess the necessary training and certification. Depending on the intermediary category, such individuals may be called specified persons, insurance sales persons, authorised verifiers, qualified persons, Point-of-Sales Persons or individual agents. Training helps personnel understand product features, exclusions, claim procedures, ethical selling standards, customer suitability and regulatory responsibilities. Passing the prescribed examination demonstrates that the person possesses the minimum level of insurance knowledge required to interact with customers.
The intermediary should maintain a central register containing the name, employee code, certificate number, training details, examination date, validity period and current status of every regulated salesperson. Automated reminders should be created before the expiry of each certification. An employee whose certification has expired or whose appointment has been terminated should not be allowed to solicit insurance. The organisation should also withdraw access to customer databases, insurer portals and sales systems when the employee leaves the organisation.
Board-Approved Policies and Governance Systems
Strong governance is essential for every insurance intermediary. The board or governing body should approve policies that clearly explain how insurance business will be solicited, serviced, monitored and controlled. A corporate agent is specifically expected to maintain a board-approved policy dealing with its approach to insurer tie-ups, the partners selected for distribution arrangements, business mix, types of products to be sold, grievance-redressal mechanism and reporting responsibilities.
The intermediary should also maintain policies on regulatory compliance, conflicts of interest, customer suitability, advertising, commission controls, anti-money laundering, information security, outsourcing, data retention, business continuity and employee conduct. These policies should not remain merely formal documents. Senior management should ensure that employees understand them and that actual business practices are regularly tested against the approved policies. The board should receive periodic compliance reports covering regulatory filings, complaints, mis-selling allegations, audit observations, cyber incidents, net-worth status and corrective-action plans.
Compliance with the Code of Conduct
Every insurance intermediary must follow the code of conduct prescribed under its applicable regulations. The code of conduct requires the intermediary and its employees to act honestly, professionally and in the best interests of customers. The intermediary must identify itself correctly and explain its relationship with the insurer. It should not create an impression that it is itself the insurance company. It must also disclose any material information that may influence the customer’s decision.
Employees should not make misleading claims regarding returns, bonuses, claim settlement, policy approval or future benefits. They should not conceal exclusions, waiting periods, deductibles, co-payment conditions, surrender charges or other important restrictions. The intermediary should also avoid pressuring customers to purchase a policy. Sales targets and employee incentives should be structured carefully so that they do not encourage mis-selling or replacement of suitable existing policies merely to earn fresh commission.
Needs Analysis and Product Suitability
Insurance products should be recommended on the basis of the customer’s actual requirements. Before suggesting a product, the intermediary should understand the customer’s age, income, dependants, financial liabilities, existing insurance, health condition, occupation and purpose for purchasing insurance. For life insurance, the intermediary should examine whether the proposed sum assured and premium are appropriate considering the customer’s income and financial responsibilities. For health insurance, it should consider the customer’s age, family composition, medical requirements, hospital preferences, waiting periods and affordability.
For commercial insurance, the intermediary should understand the nature of the customer’s business, assets, turnover, geographical exposure, contractual obligations and major operational risks. The reasons for recommending a particular policy should be documented. Proper documentation helps demonstrate that the product was selected on the basis of customer needs rather than the amount of commission payable.
Disclosure of Product Features and Exclusions
Before a customer purchases a policy, the intermediary should explain the material features of the product in clear and understandable language. The explanation should cover the premium, policy term, sum insured or sum assured, major benefits, exclusions, deductibles, waiting periods, renewal conditions and claim process. The customer should also be informed about the consequences of providing incorrect or incomplete information in the proposal form. Material non-disclosure may affect claim settlement, and the customer should therefore be encouraged to provide complete and truthful information.
In long-term policies, the intermediary should explain surrender conditions, premium-payment obligations, discontinuance consequences and investment risks, wherever applicable. Any benefit illustration should be presented in the form approved by the insurer. The intermediary should not selectively explain only the attractive features of the policy. Important restrictions must receive adequate prominence so that the customer can make an informed decision.
Proposal Form and Documentation Controls
The proposal form is the basis on which the insurer evaluates and accepts the risk. It must therefore contain accurate, complete and genuine information supplied by the proposer. An intermediary should not sign the proposal form on behalf of the customer unless legally and specifically authorised. It should not alter answers, omit medical information or provide incorrect income, occupation or address details merely to obtain policy issuance.
Where the proposal is submitted electronically, the intermediary should preserve the electronic audit trail, customer consent, authentication details and supporting documents. Any corrections should be acknowledged by the customer. The intermediary should also provide the customer with a copy of the completed proposal form or facilitate access to it through the insurer’s authorised system.
Commission and Remuneration Compliance
Commission and remuneration received by insurance intermediaries must comply with the applicable IRDAI framework and the agreements entered into with insurers. IRDAI’s Payment of Commission Regulations, 2023 introduced a framework under which insurers are required to maintain board-approved policies governing commission payments, subject to applicable regulatory limits. The intermediary must ensure that all commission income is properly recorded in its books of account and reconciled with statements issued by insurers. Payments should be received through legitimate banking channels and should be supported by invoices, statements and applicable tax documentation.
Commission should not be shared with unregistered persons who are not legally entitled to receive insurance remuneration. The intermediary must also avoid arrangements under which referral fees are used as disguised commission payments. Employee incentives should be reviewed from a customer-protection perspective. Incentive structures based solely on premium volume may encourage unsuitable sales. A balanced performance framework should also consider product suitability, complaint levels, persistency and service quality.
Prohibition on Rebates and Improper Inducements
Insurance intermediaries must not offer unauthorised rebates, cashback or financial inducements to persuade customers to purchase insurance. A portion of the commission should not be secretly returned to the customer unless the benefit is expressly permitted under the applicable legal and product. Improper inducements may also include gifts, vouchers, discounts on unrelated services or other benefits offered specifically in return for purchasing an insurance policy.
Promotional campaigns should therefore be reviewed by the compliance team before they are launched. Any discount that forms part of an insurer’s approved product or authorised programme should be accurately disclosed and documented. The intermediary should not create its own premium discount without authority from the insurer.
Premium Collection and Client-Money Controls
An intermediary should receive or handle insurance premiums only where it is legally permitted and authorised by the insurer. Premium amounts collected from customers must not be mixed with the intermediary’s general operational funds. Where premium collection is permitted, the intermediary should issue an appropriate acknowledgement and deposit the amount within the applicable time. The transaction should be reconciled with insurer records to ensure that the policy is issued or renewed without delay.
Premium should never be collected in the personal bank account of an employee, director, agent or principal officer. Cash payments, where accepted, should comply with applicable legal, tax and anti-money laundering requirements. Insurance brokers that handle client money must maintain the required separate accounts and follow the detailed controls prescribed under the broker regulations. Unauthorised use or delayed transfer of premium may expose the intermediary to serious regulatory and financial liability.
Anti-Money Laundering and KYC Compliance
Insurance products can be misused for money laundering, identity fraud, layering of funds and concealment of beneficial ownership. Insurance intermediaries must therefore support insurers in implementing customer due diligence and anti-money laundering controls. The intermediary should verify the identity and address of the customer through permitted documents and procedures. Where the customer is a company, partnership, trust or other legal entity, the intermediary should assist in identifying its beneficial owners and authorised representatives.
Higher-risk customers and unusual transactions may require enhanced due diligence. Examples may include unexplained third-party premium payments, frequent cancellation of policies, inconsistent income information, unusual assignments or transactions involving high-risk jurisdictions. Suspicious transactions should be escalated confidentially to the designated compliance or AML officer. Employees should not inform the customer that a suspicious-transaction review or reporting process has been initiated. IRDAI’s AML/CFT framework includes master guidelines and subsequent amendments dealing with customer due diligence, record maintenance, sanctions-related requirements and reporting controls.
Grievance-Redressal Mechanism
Every insurance intermediary should maintain an effective mechanism for receiving, recording and resolving customer complaints. The mechanism should be easily accessible and should include the name and contact details of the grievance officer. When a complaint is received, it should be acknowledged and assigned a unique reference number. The complaint should then be investigated by reviewing the sales record, proposal form, call recording, policy documents, employee explanation and insurer communication.
The intermediary should not close the complaint merely because it has forwarded the matter to the insurer. It should provide reasonable assistance to the customer and follow up until the issue reaches the appropriate authority. Where the complaint cannot be resolved internally, the customer should be informed about the insurer’s grievance process, IRDAI’s grievance platform and the Insurance Ombudsman mechanism, wherever applicable. Complaint data should be analysed periodically to identify repeated mis-selling, service delays or product-related issues. The findings should be reported to senior management and used to improve internal controls. IRDAI’s policyholder-protection framework places significant emphasis on fair treatment, service standards and effective complaint handling.
Insurance Advertising Compliance
Insurance advertisements must be accurate, fair, clear and capable of being substantiated. An intermediary should issue or publish advertisements only when it is legally authorised to do so and after obtaining the required insurer or internal approvals. Advertisements should clearly identify the insurer, product and intermediary. They should not exaggerate benefits, conceal exclusions or suggest that a particular return or claim outcome is guaranteed when it is not. Comparative advertisements should use a fair and consistent basis. The intermediary should not compare one product’s gross benefit with another product’s net benefit or selectively use information that creates a misleading impression.
Social-media posts, videos, blogs, search advertisements, influencer content, email campaigns and WhatsApp promotions may also qualify as insurance advertisements. They should therefore undergo the same review process as traditional print or television advertisements. The intermediary should preserve copies of advertisements along with approval records, publication dates, media details and the supporting information used to substantiate the claims. Only properly licensed intermediaries may advertise or solicit insurance through advertisements under the regulatory framework.
Telemarketing and Distance Marketing
Insurance solicitation conducted through telephone calls, video calls, email, websites or other electronic channels must comply with the applicable distance-marketing requirements. The intermediary should use approved sales scripts and ensure that callers correctly disclose their identity, the name of the intermediary and the insurer whose product is being discussed. The customer should not be misled into believing that the call is being made by IRDAI or a government authority.
Call recordings, customer consent, product explanations and electronic confirmations should be preserved for the prescribed period. The organisation should also comply with applicable telecom and customer-preference requirements. Where an insurance web aggregator undertakes permitted telemarketing, it must use properly trained and certified authorised verifiers and follow the conditions imposed under the web-aggregator framework.
Protection of Customer Information
Insurance intermediaries collect sensitive information, including Aadhaar details, PAN, financial information, medical records, nominee information and claim documents. This information must be protected against unauthorised access, disclosure, misuse, alteration or destruction. Access should be granted only to employees who require the information for their official responsibilities. Sensitive information should not be stored in personal email accounts, unprotected devices or unauthorised cloud applications.
The intermediary should obtain appropriate customer consent and use the information only for the purpose for which it was collected. Customer databases should not be sold or shared with unrelated businesses for marketing without lawful authority. Employees and vendors should be bound by confidentiality obligations. These obligations should continue even after termination of employment or completion of the vendor contract.
Information and Cyber-Security Compliance
Insurance intermediaries depend heavily on digital systems for customer onboarding, premium processing, policy servicing, document storage and communication with insurers. A cyber incident can expose customer information and disrupt insurance services. The intermediary should maintain an information-security framework that is proportionate to its size, business model and risk exposure. The framework should address user-access controls, password security, multi-factor authentication, encryption, backups, endpoint security and network monitoring.
Regular vulnerability assessments and penetration testing should be conducted wherever applicable. Identified weaknesses should be corrected within defined timelines and reported to senior management. The entity should maintain an incident-response plan explaining how a cyberattack, data breach or system failure will be detected, contained, investigated and reported. Business-continuity and disaster-recovery arrangements should also be tested periodically. IRDAI issued Information and Cyber Security Guidelines in 2023 for regulated entities falling within their scope. These guidelines form an important part of the technology-governance framework for the insurance sector.
Books, Accounts and Record Maintenance
Insurance intermediaries must maintain complete and accurate books of account and operational records. The records should enable the intermediary, its auditor and IRDAI to verify the nature of every insurance transaction. The intermediary should preserve proposal forms, quotations, customer-needs documents, KYC records, premium receipts, policy details, commission statements, insurer agreements, claim-assistance records and complaint files.
It should also maintain employee-certification registers, training records, call recordings, advertisement approvals, board minutes, regulatory returns, bank reconciliations and audit reports. Electronic records should remain readable, searchable and capable of being reproduced during an inspection. Appropriate controls should be established to prevent unauthorised alteration or deletion. Corporate agents are also required to comply with applicable record-maintenance requirements connected with regulatory investigations and inspections.
Financial Statements and Audit Requirements
An insurance intermediary must prepare annual financial statements in accordance with applicable accounting and corporate laws. The statements should accurately present the entity’s income, expenditure, assets, liabilities, capital and financial position. The statutory auditor should examine whether commission income has been properly recorded, prescribed capital and net worth have been maintained and client money has been handled correctly.
The auditor may also verify regulatory deposits, professional indemnity insurance, related-party transactions, outstanding balances with insurers and compliance with applicable accounting disclosures. Any qualification or adverse observation made by the auditor should be placed before the board. The management should prepare a corrective-action plan and monitor its implementation. Where a specific auditor’s certificate, compliance certificate or net-worth certificate is required under IRDAI regulations, it should be prepared in the prescribed format and submitted within the required period.
Periodic Regulatory Returns
Insurance intermediaries are required to submit periodic returns containing information about their insurance business, financial position, employees, insurer arrangements, complaints and other regulated matters. The nature and frequency of returns differ according to the intermediary category. Returns may be annual, half-yearly, quarterly or event based. A corporate agent may be required to report insurer tie-ups, business volumes, specified persons, complaints and financial details. Brokers may be required to provide premium, commission, claims-support, capital, net-worth and professional indemnity information.
The intermediary should establish a maker-checker system for regulatory filings. Information prepared by the operational team should be independently reviewed by the compliance or finance team before submission. Copies of filed returns, acknowledgements and supporting documents should be retained. Any incorrect information identified after filing should be promptly corrected through the permitted regulatory procedure.
Professional Indemnity Insurance
Certain insurance intermediaries must maintain professional indemnity insurance to protect against liabilities arising from negligence, errors, omissions or breach of professional duty. Professional indemnity cover may respond where the intermediary fails to transmit customer instructions, loses important documents, provides negligent professional advice or commits another covered professional error.
The policy should satisfy the minimum limit, deductible, continuity and other conditions prescribed for the relevant intermediary category. The intermediary should review the adequacy of the cover based on its turnover, customer base and risk exposure. Renewal should be completed before expiry to avoid a break in coverage. The policy documents and premium-payment evidence should be preserved for regulatory inspection. IRDAI has issued guidance concerning standard professional indemnity policies for insurance brokers, corporate agents, web aggregators and insurance marketing firms.
Outsourcing and Vendor Management
Insurance intermediaries frequently engage technology companies, cloud-service providers, call centres, document-storage agencies, marketing firms and other third-party vendors. Before appointing a vendor, the intermediary should conduct due diligence regarding the vendor’s financial stability, technical capability, information-security controls, reputation and ability to comply with regulatory requirements. The outsourcing agreement should clearly define the services, performance standards, confidentiality requirements, information-security obligations, audit rights, incident-reporting responsibilities and termination procedure.
The contract should also allow the intermediary and IRDAI to access relevant records where required. The vendor should not appoint a subcontractor for sensitive activities without appropriate permission. Outsourcing does not transfer the intermediary’s regulatory responsibility. The intermediary remains accountable for customer harm or regulatory violations arising from the outsourced activity.
Conflicts of Interest
A conflict of interest may arise where the intermediary’s financial or commercial interest affects the fairness of the recommendation given to a customer. For example, an intermediary may receive different levels of commission from different insurers. It may also have a group-company relationship with an insurer or service provider. Such relationships may influence the products recommended to customers.
The intermediary should identify and document potential conflicts. Material conflicts should be disclosed to customers in a clear and timely manner. Where disclosure alone is insufficient, the intermediary should establish internal information barriers, obtain independent review or decline the transaction. IRDAI has also issued guidelines concerning conflicts of interest and common directorship among insurance intermediaries.
Change in Ownership, Control or Management
Material changes in the ownership, control or management of an insurance intermediary may require prior approval or intimation to IRDAI. Such changes may include transfer of substantial shareholding, introduction of a new promoter, merger, amalgamation, conversion of legal structure or a change in control.
Changes involving directors, designated partners, principal officers, key management personnel, registered office or branch offices may also require regulatory action. The intermediary should assess IRDAI requirements before completing the transaction. Approval under the Companies Act, LLP Act or contractual documents may not be sufficient for regulatory purposes.
Change in Principal Officer or Key Personnel
The principal officer and other certified personnel are important elements of an intermediary’s registration. Any resignation, removal, death, disqualification or prolonged absence should be handled promptly. The intermediary should appoint an eligible replacement and complete the prescribed training, examination, certification, approval or intimation process.
Until the replacement is properly authorised, the organisation should ensure that regulated functions are not undertaken by an unqualified person. The handover process should include regulatory returns, complaint files, insurer communications, compliance registers and pending inspection matters.
Branch Office and Place-of-Business Compliance
An insurance intermediary should carry on business only from authorised premises and branches. Opening, closing or shifting an office may require approval or intimation under the applicable regulations. Each branch should maintain adequate infrastructure, trained personnel and secure systems. Customer records and official displays should be maintained in the prescribed manner.
The intermediary should periodically verify whether the actual operations of each branch are consistent with the information submitted to IRDAI. Unapproved offices, informal sales locations or unauthorised franchise arrangements may expose the intermediary to regulatory action.
Business Continuity and Disaster Recovery
Insurance services may be disrupted by cyberattacks, natural disasters, system failures, fire, power outages or loss of critical personnel. The intermediary should therefore maintain a documented business-continuity and disaster-recovery plan. The plan should identify critical functions such as customer service, premium transmission, policy renewal, complaint handling, claim assistance and regulatory reporting.
Alternative systems, backup locations and emergency communication procedures should be documented. Customer and regulatory data should be backed up securely. The plan should be tested periodically through simulations. Weaknesses identified during testing should be corrected and reported to senior management.
Cooperation During IRDAI Inspection
IRDAI may inspect the books, records, systems, offices and operations of an insurance intermediary. The purpose of an inspection may be to verify regulatory compliance, examine complaints, investigate suspected misconduct or assess financial and operational soundness.
The intermediary must provide complete and accurate information to the inspecting officers. Requested documents should be produced within the prescribed time. Employees, directors, partners and principal officers should cooperate with the inspection. Records must not be altered, concealed or destroyed. After the inspection, IRDAI may issue observations or directions. The intermediary should prepare a time-bound corrective-action plan and provide evidence of compliance.
Reporting Material Violations and Incidents
Material regulatory violations should be promptly escalated to the principal officer, compliance officer and board. Depending on the nature of the violation, IRDAI and the concerned insurer may also need to be informed. A material incident may include a cyber breach, misuse of customer money, unauthorised solicitation, major mis-selling, fraud, substantial customer-data leakage, net-worth shortfall or criminal action against key personnel.
The intermediary should investigate the cause, assess customer impact and preserve relevant evidence. Corrective and preventive measures should then be implemented. Delayed reporting may aggravate the regulatory consequences, particularly where the delay increases customer harm or affects the Authority’s ability to investigate.
Renewal of Registration
Renewal of registration should be treated as a structured compliance project rather than a routine filing. Before submitting the renewal application, the intermediary should verify its net worth, capital, deposit, professional indemnity insurance, principal-officer certification, employee records and pending regulatory obligations.
Outstanding complaints, inspection observations, penalties and litigation should be accurately disclosed. Any material change that occurred during the registration period should also be reported. The application should be filed within the prescribed window with the required fee and supporting documents. Late filing may attract additional requirements and may create a risk of interruption in business.
Penalties of Non-Compliance
Failure to comply with IRDAI requirements may result in regulatory action against the intermediary and its responsible officers. The action may include a warning, advisory, monetary penalty, restriction on new business, suspension or cancellation of registration. IRDAI may also direct the intermediary to correct its systems, refund improperly received amounts, compensate affected customers or remove disqualified personnel.
Serious violations involving fraud, customer-fund misuse, false statements or deliberate obstruction of inspection may lead to prosecution under applicable law. Non-compliance may also result in termination of insurer agreements, customer claims, reputational harm and loss of business continuity. The seriousness of the regulatory response generally depends on the nature of the violation, duration of non-compliance, customer impact, financial gain, past conduct and cooperation during the investigation.
Internal Compliance Programme for Insurance Intermediaries
An effective compliance programme should begin with the preparation of a regulatory-obligation register. The register should identify every applicable regulation, circular, filing, certificate and internal control. Each obligation should be assigned to a responsible employee with a clear due date. A second person should verify completion before the obligation is marked as closed.
The compliance officer should conduct periodic reviews of sales practices, customer complaints, premium handling, employee certifications, commission records, advertisements and cyber-security controls. The findings should be placed before senior management and the board. Corrective actions should be assigned to specific persons and tracked until completion. Regular employee training is also essential. Training should cover product suitability, customer disclosure, data protection, AML requirements, complaint handling and consequences of regulatory misconduct.
Annual Compliance Review
At the end of every financial year, the intermediary should undertake a comprehensive review of its regulatory position. The review should confirm whether the prescribed capital, net worth and regulatory deposit have been maintained. The organisation should verify that all principal-officer, salesperson and authorised-verifier certificates remain valid. It should also ensure that professional indemnity insurance has been renewed where applicable.
Annual financial statements, auditor certificates and regulatory returns should be prepared and submitted within the prescribed timelines. The board should review the intermediary’s compliance performance, material complaints, cyber incidents, inspection observations and policy changes. Internal policies should then be updated based on regulatory developments and operational experience.
Conclusion
IRDAI compliance for insurance intermediaries does not end after the Certificate of Registration is obtained. It is a continuous obligation that affects every aspect of the intermediary’s operations. An intermediary must maintain the prescribed capital and net worth, employ qualified personnel, follow fair sales practices, protect customer information, resolve grievances and submit accurate regulatory returns.
It must also ensure that advertisements, commission arrangements, premium handling, outsourcing, technology systems and customer communications comply with the applicable IRDAI. Since requirements differ between brokers, corporate agents, insurance marketing firms, web aggregators, TPAs and surveyors, every entity should prepare a category-specific compliance checklist. A well-designed compliance system protects policyholders, strengthens relationships with insurers and reduces the risk of penalties, business restrictions or cancellation of registration.
Frequently Asked Questions
Q1. Is IRDAI registration compulsory for an insurance intermediary?
Ans. An entity cannot undertake regulated insurance solicitation, distribution, broking, web aggregation, health claim administration or loss-assessment activities unless it holds the registration, licence or appointment required for its category.
Q2. Are the requirements the same for every intermediary?
Ans. The requirements are not identical. Capital, net worth, professional indemnity, training, reporting and operational conditions differ depending on whether the entity is a broker, corporate agent, IMF, web aggregator, TPA or surveyor.
Q3. Can an insurance intermediary operate after expiry of registration?
Ans. An intermediary should not continue regulated activities after its registration expires unless specifically permitted under the applicable regulatory framework. Renewal should therefore be completed within the prescribed period.
Q4. Why is the principal officer important?
Ans. The principal officer supervises the regulated insurance activities of the intermediary. The officer is responsible for ensuring that sales, servicing, reporting and compliance functions are performed in accordance with IRDAI requirements.
Q5. Can an intermediary advertise insurance products on social media?
Ans. Insurance products may be promoted on social media only in accordance with the applicable advertising rules, insurer approvals and disclosure requirements. The content must not be false, misleading or incomplete.
Q6. Can commission be shared with customers?
Ans. An intermediary cannot offer an unauthorised rebate or share commission with a customer as an inducement to purchase insurance. Any permitted discount must form part of an authorised insurer or product framework.
Q7. Is professional indemnity insurance compulsory?
Ans. Professional indemnity insurance is compulsory for intermediary categories for which it is prescribed under the applicable regulations. The required coverage and conditions vary according to the category.
Q8. Does outsourcing remove the intermediary’s responsibility?
Ans. Outsourcing does not remove regulatory accountability. The intermediary remains responsible for ensuring that its vendors protect customer information and comply with applicable standards.
Q9. What should an intermediary do after a cyber incident?
Ans. The intermediary should activate its incident-response plan, contain the incident, preserve evidence, assess customer impact and make the required regulatory and stakeholder notifications.
Q10. How frequently should compliance be reviewed?
Ans. A complete compliance review should generally be conducted at least annually, supported by more frequent monthly, quarterly or half-yearly monitoring of high-risk areas such as sales, complaints, premium handling, employee certification, KYC and cyber security.
