Back to blog
Complianceirdaicomplianceinsurance-agents

IRDAI Compliance Checklist for Insurance Agents in India (2026)

A practical 2026 IRDAI compliance checklist for insurance agents in India: licensing, POSP rules, disclosures, DPDP consent, record-keeping and renewals.

SP

Shefali P.

Insurance Compliance & Advisory Writer

21 July 202610 min read
Illustrated IRDAI compliance checklist for Indian insurance agents covering a valid licence, written disclosures, KYC and AML verification, DPDP Act consent logging, record retention and renewal persistency
Share
Key takeaways
  • Keep your IRDAI agent or POSP licence current, sell only lines you are certified for, and complete mandatory training and CPD hours before renewal.
  • Disclose commission, product features, and material facts in writing at the point of sale; never rebate premium or mis-sell to hit a target.
  • The DPDP Act 2023 now sits alongside IRDAI rules: capture explicit consent for client data and maintain an auditable record of it.
  • Retain policy, proposal, KYC, and consent records for the period regulators expect (commonly several years past policy termination) and store them securely.
  • Compliance is mostly a record-keeping discipline; software that logs consent, tracks renewals, and stores documents turns audits into a non-event.

IRDAI compliance for an insurance agent in India comes down to five things done consistently: hold a valid licence for the products you sell, complete your mandatory training and continuing education, disclose commissions and material facts to every client in writing, capture and protect client data under the DPDP Act 2023, and keep clean, retrievable records of it all. Get those right and an audit is a formality rather than a fire drill. This checklist walks through each obligation for individual agents, POSPs, and small agencies, and shows where a little systemisation saves a lot of pain.

Why IRDAI compliance matters more in 2026

The Insurance Regulatory and Development Authority of India (IRDAI) has spent recent years tightening how policies are sold and how customer data is handled. Add the Digital Personal Data Protection (DPDP) Act 2023, and agents now answer to two overlapping regimes: one for how you sell, one for how you store what you learn about clients.

The penalties for slipping are real: licence suspension, clawed-back commissions, mis-selling complaints that follow you, and reputational damage in a business built entirely on trust. The good news is that compliance is largely predictable and repeatable. Once you understand the obligations, most of the work is disciplined record-keeping rather than judgement calls.

1. Licensing and certification

Everything starts with your authorisation to sell. Selling a product you are not certified for, or letting a certification lapse, is the fastest way to invite trouble.

Your licensing checklist:

  • Hold a valid IRDAI agent licence, or a POSP (Point of Sale Person) certificate if you operate in that capacity, and confirm it covers the lines you sell (life, general, or health).
  • Complete the mandatory pre-appointment training and pass the required examination before you start selling.
  • Track your licence validity and renewal date, and renew before expiry to avoid a gap in authorisation.
  • Complete any continuing professional development (CPD) or refresher training your insurer or the regulator requires for renewal.
  • If you represent more than one insurer, ensure each appointment is properly registered and that you comply with the rules on tied versus multiple agency arrangements.
  • Keep a copy of your licence, certificates, and appointment letters where you can produce them on demand.

If you are unsure which category you fall into, our explainer on the differences between POSP, agent and broker roles in India breaks down what each is allowed to sell and the compliance load that comes with it.

2. Point-of-sale conduct and disclosures

The bulk of mis-selling complaints trace back to what was, or was not, said at the point of sale. IRDAI expects a fair, transparent transaction where the customer understands what they are buying.

At every sale, make sure you:

  • Assess suitability: recommend products that genuinely match the client's needs, life stage, and risk appetite rather than the highest-commission option.
  • Disclose material features clearly: premium, sum assured, term, exclusions, waiting periods, lock-ins, surrender values, and any riders.
  • Give an accurate picture of returns; never present non-guaranteed or projected values as guaranteed.
  • Disclose your commission where required and never offer a rebate of premium to close a sale, which is prohibited.
  • Provide the benefit illustration and policy document, and make the client aware of the free-look period.
  • Avoid pressure tactics, misleading comparisons, and any claim you cannot support in writing.

Document what you told the client

A written trail of the recommendation and disclosures protects you if a client later claims they were mis-sold. Keep the signed proposal form, benefit illustration, and any needs-analysis notes. If a dispute arises, the file is your defence.

3. KYC and anti-money-laundering obligations

Insurance sits within India's anti-money-laundering framework, so proper Know Your Customer (KYC) verification is not optional. Collect and verify identity and address proof, capture PAN where required, and be alert to red flags such as unusually large single-premium payments or a mismatch between a client's stated income and the cover sought.

Keep your KYC hygiene tight:

  • Collect valid identity and address proof for every proposer and, where relevant, the life assured.
  • Record PAN for transactions above the prescribed thresholds.
  • Retain KYC documents securely and link them to the correct policy and client record.
  • Flag and escalate suspicious transactions rather than processing them quietly.

4. DPDP Act 2023: the new data layer

As an agent you handle sensitive personal data every day: health details, income, family structure, nominee information. The DPDP Act 2023 treats you as a handler of that data and expects you to collect it lawfully, use it only for the purpose consented to, and protect it.

Your DPDP checklist:

  • Capture explicit, informed consent before collecting client data, and state the purpose clearly.
  • Use data only for that stated purpose; do not repurpose a client's health details for unrelated marketing.
  • Maintain an auditable record of when and how consent was given, and honour withdrawal requests.
  • Store personal data securely with access controls, and avoid keeping data in unsecured spreadsheets or personal messaging apps.
  • Have a plan to delete or return data when it is no longer needed.

This is where manual methods start to fail: an Excel sheet does not timestamp consent or prove who accessed what. Our DPDP Act guide for insurance agents covers the practical steps in depth. Polisync captures DPDP consent on the customer form and writes it to an audit log, so the proof exists without extra effort on your part.

5. Record-keeping and retention

Almost every compliance obligation ends in the same place: can you produce the record when asked? Regulators and insurers expect you to retain policy, proposal, KYC, and consent records for a meaningful period, commonly several years beyond the policy's termination or claim settlement.

Keep retrievable, organised records of:

  • Proposal forms, benefit illustrations, and signed disclosures.
  • KYC and identity documents for each client.
  • Policy documents, endorsements, and nominee details.
  • Consent records and any withdrawal or update requests.
  • Premium receipts, commission statements, and renewal history.

Scattered paper files and folders on a laptop make retrieval slow and risky. Storing policy documents against each client in one place, with validated uploads, means a request for a five-year-old proposal takes seconds. If you are still running your book on spreadsheets, our piece on when to switch from managing policies in Excel is worth a read.

6. Renewals, persistency, and lapse management

Renewal discipline is both a compliance and a business issue. Insurers watch persistency (the share of policies that stay in force), and a book full of lapsed policies reflects poorly on conduct. More importantly, a lapsed policy can leave a family without cover exactly when they need it, which is the outcome the whole system exists to prevent.

The practical answer is a reliable reminder system. Missing a renewal date because it was buried in a diary is avoidable. Polisync tracks policy expiry and sends automated renewal reminders by email, with a renewal lifecycle and grace or lapse tracking so nothing falls through. For the wider playbook, see our guide to reducing policy lapse rates through better renewal management.

7. Commission, GST, and financial records

Keep your financial house in order alongside the regulatory one. Reconcile commission statements against the policies you have placed, account for GST correctly on your services, and keep clean books for income-tax purposes. Discrepancies between what you were paid and what you booked are a common source of avoidable stress at year-end.

Tracking commission per policy, rather than relying on insurer statements alone, gives you an independent record. Polisync includes commission tracking with AI-assisted capture from policy drafts, and our commission tracking guide and GST and tax guide for insurance agents cover the details.

8. Build compliance into your workflow, not around it

The agents who stay compliant without stress are not the ones with the best memory; they are the ones whose tools make the right thing the default. When consent is captured on the same form as the client's details, when renewals chase themselves, and when every document lives against the right policy, compliance stops being a separate chore.

That is the case for moving off paper and spreadsheets to a purpose-built system. A good insurance agency management platform enforces the record-keeping and reminders that regulators expect. If you are weighing options, our guide to choosing agency management software lays out what to look for, and you can see how Polisync approaches the Indian market or try the free plan to get started.

Your annual compliance rhythm

Turn the checklist into a calendar. A predictable rhythm beats a scramble every time a deadline or audit appears.

A simple cadence to adopt:

  • Monthly: reconcile commissions, review upcoming renewals, and clear any pending KYC or consent gaps.
  • Quarterly: audit a sample of recent files for complete disclosures and documentation.
  • Before licence renewal: complete CPD or training hours and confirm certifications cover every line you sell.
  • Annually: review your data-handling practices against the DPDP Act and confirm retention and deletion are on track.

Compliance rewards consistency, not heroics. Systematise the routine parts, keep an honest paper trail, and put the client's genuine interest first, and the regulatory side of the business largely takes care of itself. For more on running a modern practice, browse the rest of the Polisync blog.

Frequently asked questions

What documents must an insurance agent keep for IRDAI compliance?+

At a minimum, keep signed proposal forms, benefit illustrations, KYC and identity documents, policy documents and endorsements, nominee details, consent records, and commission and premium receipts. Retain them for the period regulators and insurers expect, commonly several years beyond policy termination, and store them securely so you can produce any file on demand.

How does the DPDP Act 2023 affect insurance agents?+

The DPDP Act treats agents as handlers of clients' personal data, including sensitive health and financial details. You must capture explicit, informed consent, use the data only for its stated purpose, protect it with access controls, and keep an auditable record of consent. Our DPDP Act guide for insurance agents explains the practical steps.

Can an insurance agent offer a rebate on premium to close a sale?+

No. Offering a rebate of premium or commission to a customer is prohibited and is treated as a serious conduct breach. Compete on advice, service, and product suitability instead, and disclose your recommendation and the product's features clearly in writing.

What is the difference between an IRDAI agent and a POSP?+

An agent typically holds a broader licence and can sell a wider range of products after passing the required examination, while a POSP (Point of Sale Person) is certified to sell specific, pre-underwritten products with lighter training. The compliance load differs accordingly. See our breakdown of POSP, agent and broker roles.

Does Polisync send SMS or WhatsApp renewal reminders?+

No. Polisync sends automated renewal reminders by email only, and tracks policy expiry, a renewal lifecycle, and grace or lapse status so no renewal is missed. You can read more about cutting lapses in our renewal management guide.

How can software help me stay IRDAI compliant?+

Purpose-built agency management software builds compliance into your daily workflow: it captures DPDP consent with an audit log, stores policy documents against each client, tracks renewals and lapses, and records commissions. That turns record-keeping from a chore into a by-product of doing business. See what to look for in our software selection guide.

Found this useful? Share it with your network.

Share
SP

Shefali P.

Insurance Compliance & Advisory Writer

Shefali writes about insurance regulation, compliance, and product guidance for agents in India. She covers IRDAI norms, the DPDP Act, GST, and helping clients choose the right cover.

Ready to simplify your insurance management?

Join hundreds of agencies already using Polisync. Get started in under 15 minutes with a free plan.