Office of Insurance Commission (OIC)
IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.
Penetration testing and IT-risk management under OIC regulations
OIC regulations require insurance companies to engage external specialists for regular internet-facing penetration testing, combined with technical vulnerability management and risk treatment plans.

- Maintain an information asset inventory and criticality classification for core insurance systems, customer and agent portals, mobile applications, insurance APIs, and underlying infrastructure.
- Clause 21(6) mandates external penetration testing for internet-facing applications and networks regularly or upon significant system changes, alongside systematic vulnerability management.
- Integrate test findings into formal risk assessments, assigning issues to control owners, establishing a Risk Treatment Plan with remediation deadlines, and capturing retest evidence to demonstrate control effectiveness.
- Report assessment findings and testing evidence to the risk management committee and the board to support mandatory annual IT audits under clauses 34 and 35.
OFFICE OF INSURANCE COMMISSION / IT RISK
IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.
OIC Penetration Testing Requirements and IT Risk Management
- Applies to life and non-life insurance companies supervised by the Office of Insurance Commission, establishing expectations for IT Governance, Information Asset Management, IT Risk Management, and Cybersecurity Controls.
- Clause 21(6) explicitly mandates that insurers engage external specialists to perform penetration testing on internet-facing applications and networks regularly, or whenever significant system changes occur.
- Testing must be executed alongside vulnerability management and security monitoring aligned with evaluated risk levels, scoped from the information asset inventory and formal risk assessments.
- Critical systems within scope include online policy issuance systems, claims processing applications, customer and agent portals, mobile applications, insurance APIs, internet-facing systems, core insurance platforms, and policyholder databases.
- Findings must feed into a formal Risk Treatment Plan with assigned control owners and documented retest evidence, supporting executive reporting and mandatory annual IT audits.
OIC regulations require regular external penetration testing for internet-facing systems. Technical test results provide auditable evidence of control effectiveness, supporting ongoing IT risk management and mandatory annual IT audits.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| OIC Notification B.E. 2563 clause 21(6) | External penetration testing of internet-facing applications and networks | Online Policy Systems, Claims Processing Apps, Web Portals, Insurance APIs, Core Databases | Regularly or after significant change |
| Chapters 4 and 6 (clauses 28, 29, and 34) | Risk assessment, Risk Treatment Plans, and annual independent IT audits | IT Risk assessments, outsourced system verification (clause 23), board reporting, and auditor evaluations | Annual independent IT audit |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
