The ICICI Lombard Penalty imposed by IRDAI totals ₹1 crore for outsourcing, vendor-management and governance failures found through a 2019 onsite inspection. The September 7 order says event-management services involving agents of other insurers were not properly classified or reported as outsourced activity, reducing timely regulatory visibility over the spending.
What the ICICI Lombard Penalty covers
The ICICI Lombard penalty is not about a single rejected claim or a pricing dispute. It concerns the control framework around third-party activities and whether the insurer gave the regulator a complete view of outsourced work. IRDAI’s 22-page order follows an onsite inspection conducted in September 2019, written submissions and a personal hearing before two whole-time members.
According to the order and independent reports, ICICI Lombard recorded ₹709.57 crore in FY2018-19 under “sales marketing and business support.” The insurer said roughly ₹35 crore to ₹37 crore was paid to individual agents of other insurers for event-management work. IRDAI found the activity had not been classified as outsourcing and the expense was therefore omitted from outsourcing returns.
The regulator’s concern was the consequence of that classification. Outsourcing rules require a regulated insurer to identify relevant third parties, conduct due diligence, maintain agreements and records, oversee performance and give its board and regulator visibility. Calling a service something else does not remove those obligations when its substance meets the regulated definition.
| Item | Verified detail |
|---|---|
| Insurer | ICICI Lombard General Insurance Company Limited |
| Order date | September 7, 2026 |
| Reference | IRDAI/E&C/ORD/MISC/116/9/2026 |
| Inspection period | September 2019 |
| Penalty | ₹1 crore |
| Legal basis | Section 102 of the Insurance Act, 1938 |
| Required follow-up | Board placement and action-taken report |
How the enforcement process unfolded
The long gap between inspection and order does not make the findings current operating data. It means the enforcement file moved through inspection findings, insurer responses and adjudication before a final decision. Readers should not infer that every figure in the order describes ICICI Lombard’s present-day processes.
The order records the insurer’s position as well as the regulator’s conclusion. ICICI Lombard argued, among other things, that event management was not a core insurance function and relied on earlier guidance distinguishing core and non-core services. IRDAI focused on the 2017 outsourcing regulations and the need to report the arrangement so that regulatory scrutiny could occur on time.
This is why the enforcement action is best read as a control case. The disputed activity sat at the intersection of marketing, agents, vendors and regulated outsourcing. When ownership is split across departments, classification decisions can fall between procurement, compliance and distribution teams unless one accountable function reviews the substance.
Why outsourcing classification matters
Insurers can outsource many operational activities, but they do not outsource regulatory responsibility. A vendor’s failure can affect customers, records, data, sales conduct and the insurer’s reputation. The regulatory framework therefore expects the insurer to know who performs the service, why the vendor was selected, how it is monitored and what evidence supports payments.
Reporting returns are part of that control chain. They allow IRDAI to see concentrations, unusual arrangements and activities involving intermediaries. If a material service is absent from the return because it was labelled as marketing support, the regulator loses the opportunity to assess the risk when the activity occurs.
The agents-of-other-insurers element adds a distribution dimension. Independent reports said ICICI Lombard used such agents for events without adequate supporting documents. The order should not be read as a finding against every individual agent; it addresses the insurer’s classification, documentation and governance obligations.
Board and management consequences
IRDAI directed the insurer to place the order before its board. That turns enforcement into a governance task rather than a payment-only event. Directors need to understand the root cause, whether similar classifications remain in use, how past vendor records were remediated and what independent assurance supports management’s response.
The action-taken report gives the regulator a formal follow-through mechanism. A credible response should connect each finding to an owner, deadline, evidence set and effectiveness test. Merely rewriting a policy will not establish that procurement, finance, distribution and compliance teams now make consistent decisions.
The order also included advisories rather than monetary penalties for some issues, including unallocated premium and delays involving free-look cancellation requests. Advisories still require attention. They indicate processes the regulator expects the insurer to strengthen even where the final sanction took another form.
What the penalty means for policyholders
The order does not say ICICI Lombard policies are invalid, and it does not automatically create compensation for customers. It addresses enterprise controls and specified regulatory violations. Policyholders with an individual complaint should continue to use the insurer’s grievance process and the official escalation channels applicable to their case.
However, outsourcing controls matter to customers indirectly. Vendors may handle communication, assistance, records or events that shape how insurance is sold and serviced. Weak due diligence or incomplete records can make it harder to trace accountability when something goes wrong.
The customer-protection value of the order is therefore systemic. It reinforces that regulated insurers remain answerable for third parties and must maintain evidence that allows the board and IRDAI to supervise those relationships.
The broader compliance lesson
The central lesson is to classify by substance, not by expense label. A finance code such as “sales marketing and business support” cannot determine the regulatory character of work. Compliance review must examine what the third party actually does, whose agents participate, what information is handled and how the service affects insurance operations.
This is consistent with the operational-control theme in recent business developments. Lapaas Voice’s reports on Intellect’s AI-first banking architecture and NSE’s revised pre-open controls both show that governance must be embedded in workflows rather than added after an event.
Insurers should maintain a complete outsourcing inventory, reconcile it with vendor payments, require compliance sign-off for classification changes and test whether board reporting matches regulatory returns. Data matching between procurement ledgers and compliance registers can expose services that have fallen outside the formal inventory.
In plain terms, IRDAI fined ICICI Lombard because the regulator concluded that material event-management work was treated and reported in a way that bypassed the outsourcing-control framework; the order requires both a financial penalty and documented board-level remediation.
What to watch next
The next verifiable milestones are ICICI Lombard’s board consideration and its action-taken report. The company’s exchange disclosure said the order had no material impact on operations, but remediation quality will depend on the controls and evidence submitted to IRDAI.
For the sector, the order may prompt insurers to recheck marketing-support vendors, event services and arrangements involving agents. The highest-risk gap is often not an obviously outsourced claims or IT function, but a peripheral service that grew without being added to the formal register.
The ₹709.57 crore figure requires careful reading. It was the broad FY2018-19 expense recorded under sales marketing and business support, not the amount of the penalty and not necessarily the value of every disputed service. Independent reporting says the insurer identified roughly ₹35 crore to ₹37 crore within that category as payments to individual agents of other insurers for event work.
That accounting distinction is exactly why a cross-functional reconciliation matters. Procurement sees vendor purpose, finance sees payment codes, distribution sees agent relationships and compliance sees the regulatory definition. A defensible system joins those views before returns are filed. It also retains agreements, invoices, attendance evidence, approval records and monitoring results so that a later inspection can reconstruct the transaction.
Boards should ask whether the remediation looks backward as well as forward. A revised policy may govern new vendors, but management may also need to scan existing arrangements for the same classification pattern. Testing a sample of payments against the outsourcing inventory can reveal whether the root cause was isolated or systemic.
The exact IRDAI order, reference IRDAI/E&C/ORD/MISC/116/9/2026, is the controlling source for the enforcement event. It identifies the September 2019 inspection, the subsequent correspondence and hearing, the ₹1 crore sanction and the required board follow-up. The order also separates the penalised outsourcing charge from matters addressed through advisories, an important distinction when assessing the scope of the regulator’s conclusions.
A practical remediation test is whether the insurer can now reconcile every relevant payment code to an approved outsourcing inventory and documented owner. Exceptions should be escalated before a return is filed, not reconstructed years later during enforcement. Board reporting should then show both the control change and evidence from sample testing that the revised process works.
Frequently asked questions
How much did IRDAI fine ICICI Lombard?
IRDAI imposed a ₹1 crore penalty under Section 102 of the Insurance Act, 1938, in its order dated September 7, 2026.
What was the main outsourcing issue?
The regulator said event-management services involving agents of other insurers were not classified and reported as outsourcing, preventing timely scrutiny through the outsourcing returns.
Does the order affect existing insurance policies?
The order does not invalidate policies. It concerns the insurer’s compliance, outsourcing and governance controls and requires board-level follow-up.
Sources: Exact IRDAI order; ICICI Lombard investor relations; Economic Times; Moneycontrol; The Insurance Reporter; Navbharat Times.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



