IRDAI compliance for an insurance agent in India comes down to five things done consistently: hold a valid licence for the products you sell, complete your mandatory training and continuing education, disclose commissions and material facts to every client in writing, capture and protect client data under the DPDP Act 2023, and keep clean, retrievable records of it all. Get those right and an audit is a formality rather than a fire drill. This checklist walks through each obligation for individual agents, POSPs, and small agencies, and shows where a little systemisation saves a lot of pain.
Why IRDAI compliance matters more in 2026
The Insurance Regulatory and Development Authority of India (IRDAI) has spent recent years tightening how policies are sold and how customer data is handled. Add the Digital Personal Data Protection (DPDP) Act 2023, and agents now answer to two overlapping regimes: one for how you sell, one for how you store what you learn about clients.
The penalties for slipping are real: licence suspension, clawed-back commissions, mis-selling complaints that follow you, and reputational damage in a business built entirely on trust. The good news is that compliance is largely predictable and repeatable. Once you understand the obligations, most of the work is disciplined record-keeping rather than judgement calls.
1. Licensing and certification
Everything starts with your authorisation to sell. Selling a product you are not certified for, or letting a certification lapse, is the fastest way to invite trouble.
Your licensing checklist:
- Hold a valid IRDAI agent licence, or a POSP (Point of Sale Person) certificate if you operate in that capacity, and confirm it covers the lines you sell (life, general, or health).
- Complete the mandatory pre-appointment training and pass the required examination before you start selling.
- Track your licence validity and renewal date, and renew before expiry to avoid a gap in authorisation.
- Complete any continuing professional development (CPD) or refresher training your insurer or the regulator requires for renewal.
- If you represent more than one insurer, ensure each appointment is properly registered and that you comply with the rules on tied versus multiple agency arrangements.
- Keep a copy of your licence, certificates, and appointment letters where you can produce them on demand.
If you are unsure which category you fall into, our explainer on the differences between POSP, agent and broker roles in India breaks down what each is allowed to sell and the compliance load that comes with it.
2. Point-of-sale conduct and disclosures
The bulk of mis-selling complaints trace back to what was, or was not, said at the point of sale. IRDAI expects a fair, transparent transaction where the customer understands what they are buying.
At every sale, make sure you:
- Assess suitability: recommend products that genuinely match the client's needs, life stage, and risk appetite rather than the highest-commission option.
- Disclose material features clearly: premium, sum assured, term, exclusions, waiting periods, lock-ins, surrender values, and any riders.
- Give an accurate picture of returns; never present non-guaranteed or projected values as guaranteed.
- Disclose your commission where required and never offer a rebate of premium to close a sale, which is prohibited.
- Provide the benefit illustration and policy document, and make the client aware of the free-look period.
- Avoid pressure tactics, misleading comparisons, and any claim you cannot support in writing.
Document what you told the client
A written trail of the recommendation and disclosures protects you if a client later claims they were mis-sold. Keep the signed proposal form, benefit illustration, and any needs-analysis notes. If a dispute arises, the file is your defence.
3. KYC and anti-money-laundering obligations
Insurance sits within India's anti-money-laundering framework, so proper Know Your Customer (KYC) verification is not optional. Collect and verify identity and address proof, capture PAN where required, and be alert to red flags such as unusually large single-premium payments or a mismatch between a client's stated income and the cover sought.
Keep your KYC hygiene tight:
- Collect valid identity and address proof for every proposer and, where relevant, the life assured.
- Record PAN for transactions above the prescribed thresholds.
- Retain KYC documents securely and link them to the correct policy and client record.
- Flag and escalate suspicious transactions rather than processing them quietly.
4. DPDP Act 2023: the new data layer
As an agent you handle sensitive personal data every day: health details, income, family structure, nominee information. The DPDP Act 2023 treats you as a handler of that data and expects you to collect it lawfully, use it only for the purpose consented to, and protect it.
Your DPDP checklist:
- Capture explicit, informed consent before collecting client data, and state the purpose clearly.
- Use data only for that stated purpose; do not repurpose a client's health details for unrelated marketing.
- Maintain an auditable record of when and how consent was given, and honour withdrawal requests.
- Store personal data securely with access controls, and avoid keeping data in unsecured spreadsheets or personal messaging apps.
- Have a plan to delete or return data when it is no longer needed.
This is where manual methods start to fail: an Excel sheet does not timestamp consent or prove who accessed what. Our DPDP Act guide for insurance agents covers the practical steps in depth. Polisync captures DPDP consent on the customer form and writes it to an audit log, so the proof exists without extra effort on your part.
5. Record-keeping and retention
Almost every compliance obligation ends in the same place: can you produce the record when asked? Regulators and insurers expect you to retain policy, proposal, KYC, and consent records for a meaningful period, commonly several years beyond the policy's termination or claim settlement.
Keep retrievable, organised records of:
- Proposal forms, benefit illustrations, and signed disclosures.
- KYC and identity documents for each client.
- Policy documents, endorsements, and nominee details.
- Consent records and any withdrawal or update requests.
- Premium receipts, commission statements, and renewal history.
Scattered paper files and folders on a laptop make retrieval slow and risky. Storing policy documents against each client in one place, with validated uploads, means a request for a five-year-old proposal takes seconds. If you are still running your book on spreadsheets, our piece on when to switch from managing policies in Excel is worth a read.
6. Renewals, persistency, and lapse management
Renewal discipline is both a compliance and a business issue. Insurers watch persistency (the share of policies that stay in force), and a book full of lapsed policies reflects poorly on conduct. More importantly, a lapsed policy can leave a family without cover exactly when they need it, which is the outcome the whole system exists to prevent.
The practical answer is a reliable reminder system. Missing a renewal date because it was buried in a diary is avoidable. Polisync tracks policy expiry and sends automated renewal reminders by email, with a renewal lifecycle and grace or lapse tracking so nothing falls through. For the wider playbook, see our guide to reducing policy lapse rates through better renewal management.
7. Commission, GST, and financial records
Keep your financial house in order alongside the regulatory one. Reconcile commission statements against the policies you have placed, account for GST correctly on your services, and keep clean books for income-tax purposes. Discrepancies between what you were paid and what you booked are a common source of avoidable stress at year-end.
Tracking commission per policy, rather than relying on insurer statements alone, gives you an independent record. Polisync includes commission tracking with AI-assisted capture from policy drafts, and our commission tracking guide and GST and tax guide for insurance agents cover the details.
8. Build compliance into your workflow, not around it
The agents who stay compliant without stress are not the ones with the best memory; they are the ones whose tools make the right thing the default. When consent is captured on the same form as the client's details, when renewals chase themselves, and when every document lives against the right policy, compliance stops being a separate chore.
That is the case for moving off paper and spreadsheets to a purpose-built system. A good insurance agency management platform enforces the record-keeping and reminders that regulators expect. If you are weighing options, our guide to choosing agency management software lays out what to look for, and you can see how Polisync approaches the Indian market or try the free plan to get started.
Your annual compliance rhythm
Turn the checklist into a calendar. A predictable rhythm beats a scramble every time a deadline or audit appears.
A simple cadence to adopt:
- Monthly: reconcile commissions, review upcoming renewals, and clear any pending KYC or consent gaps.
- Quarterly: audit a sample of recent files for complete disclosures and documentation.
- Before licence renewal: complete CPD or training hours and confirm certifications cover every line you sell.
- Annually: review your data-handling practices against the DPDP Act and confirm retention and deletion are on track.
Compliance rewards consistency, not heroics. Systematise the routine parts, keep an honest paper trail, and put the client's genuine interest first, and the regulatory side of the business largely takes care of itself. For more on running a modern practice, browse the rest of the Polisync blog.



