ICICI Lombard IRDAI penalty news broke this week after India’s insurance regulator closed out a multi-year enforcement case. The Insurance Regulatory and Development Authority of India (IRDAI) passed an Order against M/s ICICI Lombard General Insurance Co. Ltd. (‘Insurer’), pursuant to an onsite inspection conducted during September 2019 and subsequent enforcement proceedings. The order sets out both a monetary penalty and a set of compliance advisories that the insurer must now act on.
What the order establishes
Based on the findings of the inspection, the submissions made by the insurer, and the personal hearing conducted before a panel of two Whole-time Members, certain violations relating to outsourcing of activities, vendor selection and due diligence, record maintenance, internal controls, governance and compliance with applicable regulatory requirements were established. Outsourcing arrangements sit at the center of how many Indian insurers manage claims processing, IT infrastructure and back-office functions, which is why regulators increasingly treat vendor oversight as a core governance responsibility rather than a peripheral operational matter.
IRDAI introduced its outsourcing regulations to make sure insurers keep accountability for functions handed to third parties, pairing every vendor relationship with documented due diligence and ongoing monitoring. Its separate corporate governance guidelines set parallel expectations for board oversight, internal controls and record-keeping across an insurer’s operations. An order that draws on both frameworks at once, as this one does, generally signals that a regulator reads the underlying weaknesses as systemic rather than confined to a single vendor contract.
The case adds to a busy year of enforcement activity from the regulator. Earlier this month, IRDAI fined Canara HSBC Life over mis-selling to an elderly customer, a separate action that likewise stemmed from a formal inspection process and closed with a directive for corrective steps.
The penalty and its legal basis
After due consideration of the facts and submissions, the Competent Authority imposed a monetary penalty of Rs. 1 crore (Rupees One Crore only) under Section 102 of the Insurance Act, 1938, for violations of provisions of the IRDAI (Outsourcing of Activities by Indian Insurers) Regulations, 2017, and the Guidelines on Corporate Governance for Insurers in India. The penalty draws on two distinct regulatory frameworks at once, tying outsourcing conduct directly to the insurer’s broader corporate governance obligations rather than treating vendor management as a standalone compliance silo.
Section 102 of the Insurance Act, 1938 gives IRDAI the authority to levy financial penalties on insurers found in breach of the Act or of regulations issued under it, and the provision has featured in a string of enforcement orders as the regulator has stepped up supervisory activity in recent years. A penalty imposed jointly for outsourcing and governance failures, rather than for one narrow lapse, illustrates how IRDAI increasingly treats operational shortcomings as governance shortcomings by extension.
Details of the case are set out in the press release announcing the order and the underlying violations, which frames the penalty as the outcome of a formal hearing process rather than a summary finding.
Compliance gaps beyond the order
The Competent Authority also issued advisories in respect of certain compliance deficiencies, including matters relating to unallocated premium and delays in processing of free look cancellation requests. Advisories of this kind typically flag operational weak points the regulator wants addressed proactively, separate from the penalty itself, and often serve as an early warning ahead of any future inspection cycle.
Unallocated premium and free-look cancellation delays both sit on the customer-facing side of an insurer’s operations: the first concerns premium payments that have not yet been matched to a policy record, and the second concerns the window during which a new policyholder can cancel a policy and receive a refund. Advisories on both points point toward friction in reconciliation and customer service processes, areas regulators across the region have been pressing insurers to tighten as digital policy issuance accelerates.
They also line up with the regulator’s wider governance push, visible in how IRDAI’s Policyholders’ Protection Fund initiative has reshaped compliance expectations for insurers across the market, an effort that extends well beyond any single enforcement case.
What comes next for the insurer
The insurer has been directed to place the Order before its Board and submit an Action Taken Report (ATR) within the stipulated period. That structure keeps accountability at board level rather than leaving remediation to operational teams alone, and gives the regulator a documented record of the corrective measures the insurer commits to.
Board-level sign-off on an Action Taken Report is a standard mechanism IRDAI uses to keep corrective work visible at the top of an organization, rather than treating a penalty as a closed matter once paid. For ICICI Lombard, that means outsourcing controls, vendor due diligence and the flagged advisories are likely to remain agenda items for its board and compliance function well beyond the date of the order itself.
The requirement mirrors a broader governance agenda, including the regulator’s recent moves on perpetual registration and salesperson tagging that reshape how insurers are expected to operate, part of a steady expansion of supervisory tools aimed at the sector.
IRDAI remains committed to ensuring robust governance standards, policyholder protection, transparency and accountability across the insurance sector. The Authority will continue to take appropriate supervisory and enforcement action wherever regulatory violations are observed. That posture is spelled out directly in IRDAI’s own statement accompanying the order.