Siam Thanat Hack Co., Ltd.

Office of Insurance Commission (OIC)

IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

Executive Summary and Mandate Overview
Target Audience Life and Non-Life Insurance Companies, Corporate Brokers, and InsurTech Platforms
Mandatory Frequency Regular external penetration testing of internet-facing systems, or after significant change (clause 21(6))
Required Scope Online Policy Systems, Claims Management Apps, Customer and Agent Portals, Insurance APIs, Core Databases
Non-Compliance Risk OIC regulatory audit orders, administrative warnings, and forced system remediation

Penetration testing and IT-risk management under OIC regulations

OIC regulations require insurance companies to engage external specialists for regular internet-facing penetration testing, combined with technical vulnerability management and risk treatment plans.

Thai infographic explaining: Penetration testing and IT-risk management under OIC regulations
Visual summary: Penetration testing and IT-risk management under OIC regulations
  • Maintain an information asset inventory and criticality classification for core insurance systems, customer and agent portals, mobile applications, insurance APIs, and underlying infrastructure.
  • Clause 21(6) mandates external penetration testing for internet-facing applications and networks regularly or upon significant system changes, alongside systematic vulnerability management.
  • Integrate test findings into formal risk assessments, assigning issues to control owners, establishing a Risk Treatment Plan with remediation deadlines, and capturing retest evidence to demonstrate control effectiveness.
  • Report assessment findings and testing evidence to the risk management committee and the board to support mandatory annual IT audits under clauses 34 and 35.

OFFICE OF INSURANCE COMMISSION / IT RISK

IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

OIC Penetration Testing Requirements and IT Risk Management

  • Applies to life and non-life insurance companies supervised by the Office of Insurance Commission, establishing expectations for IT Governance, Information Asset Management, IT Risk Management, and Cybersecurity Controls.
  • Clause 21(6) explicitly mandates that insurers engage external specialists to perform penetration testing on internet-facing applications and networks regularly, or whenever significant system changes occur.
  • Testing must be executed alongside vulnerability management and security monitoring aligned with evaluated risk levels, scoped from the information asset inventory and formal risk assessments.
  • Critical systems within scope include online policy issuance systems, claims processing applications, customer and agent portals, mobile applications, insurance APIs, internet-facing systems, core insurance platforms, and policyholder databases.
  • Findings must feed into a formal Risk Treatment Plan with assigned control owners and documented retest evidence, supporting executive reporting and mandatory annual IT audits.
Key Regulatory Alignment

OIC regulations require regular external penetration testing for internet-facing systems. Technical test results provide auditable evidence of control effectiveness, supporting ongoing IT risk management and mandatory annual IT audits.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
OIC Notification B.E. 2563 clause 21(6) External penetration testing of internet-facing applications and networks Online Policy Systems, Claims Processing Apps, Web Portals, Insurance APIs, Core Databases Regularly or after significant change
Chapters 4 and 6 (clauses 28, 29, and 34) Risk assessment, Risk Treatment Plans, and annual independent IT audits IT Risk assessments, outsourced system verification (clause 23), board reporting, and auditor evaluations Annual independent IT audit

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview of OIC IT risk management notification (life insurance)

OIC IT risk management notification (life insurance)

By OIC

Open document (PDF) Download Source

First-page preview of OIC IT risk management notification (non-life insurance)

OIC IT risk management notification (non-life insurance)

By OIC

Open document (PDF) Download Source