The purpose of this Access Control Policy is to establish a structured framework for controlling access to the Broker’s websites, internal systems, and digital platforms used for insurance broking operations. This policy ensures that access to information and systems is authorized, role-based, secure, and auditable, thereby safeguarding client data, insurer information, and operational integrity.
This policy applies to:
The Broker follows these core access control principles:
Users are granted only the minimum level of access necessary to perform their assigned duties.
System access is assigned based on predefined job roles rather than individual users.
Critical operational and administrative functions are segregated to reduce the risk of misuse or unauthorized actions.
Access to sensitive client, insurer, financial, or personal data is restricted strictly to users with a legitimate business requirement.
Access rights are categorized by role, including but not limited to:
Each role has clearly documented permissions approved by management.
The Broker enforces the following authentication measures:
Access is revoked promptly upon:
This policy is aligned with:
This Access Control Policy is owned, maintained, and enforced by:
RiskBirbal Insurance Brokers Pvt. Ltd.
Management and Authorized IT Personnel