What IRDAI Actually Ordered, and to Whom
On 2 April 2026, IRDAI directed all regulated entities offering insurance products on digital platforms to conduct a self-assessment of their compliance with the Central Consumer Protection Authority's dark pattern guidelines. The direction carried two deadlines: the self-assessment itself within 15 days, with a report to the regulator, and a time-bound action plan within one month for whatever the self-assessment turned up.
The phrase that matters is regulated entities offering insurance products on digital platforms. It is not insurers. A composite broker running a quote-and-buy page is a regulated entity offering insurance products on a digital platform. So is a corporate agent with an embedded journey inside a lender's app. So is a POSP-aggregator platform whose entire distribution model is a mobile funnel. If your entity holds an IRDAI registration and there is a form on the internet that ends in a proposal, the direction reached you.
Most intermediaries did not read it that way in April, because the coverage framed it as an insurer story. That reading has a shelf life, and the shelf life ended when IRDAI brought in a monitor.
The Nine-Month Monitoring Window Changes the Risk
IRDAI partnered with the Institute of Public Auditors of India, a statutory body, to monitor dark patterns in the insurance sector over the following nine months. That is a different instrument from a circular, and it should be read differently.
A circular sets a standard and waits for a complaint to test it. A monitoring engagement sends someone to look. Monitoring a consumer-facing interface does not require access to your systems, your books, or your cooperation. Your journey is public. Anyone can open it on a phone, walk it end to end, and record what the screens did. The evidence gathers itself.
The practical consequence for a broking firm is that the compliance artefact is no longer a document. It is the live journey, on every device, on every day of the window, including the variants your growth team is A/B testing.
The Chairman Named the Pattern Intermediaries Use Most
On 25 July 2026, IRDAI Chairman Ajay Seth said consumers must be able to compare insurance products and pricing without being compelled to disclose personal information at the outset. He noted that many insurance websites seek names, mobile numbers and consent to receive marketing calls before displaying prices. The practices flagged alongside that included spam calls and barriers requiring users to share personal information before accessing products or pricing.
That is the gated quote, and it is close to universal in Indian intermediary distribution. The standard motor or health funnel asks for a mobile number on screen one, fires an OTP, and only then shows a premium. The commercial-lines equivalent is the enquiry form that collects company name, turnover and a contact before anything resembling an indication appears.
The defence intermediaries reach for is that pricing genuinely depends on inputs. That defence is real for the parts of the price that are rated, and it is irrelevant to the parts that are not. Age, sum insured, vehicle model and occupancy drive the rate. A mobile number does not. A marketing-call consent does not. When the fields that gate the price include fields that do not affect the price, the gate is a lead-capture mechanism wearing a rating explanation, and the Chairman has already described it in public.
The honest test
Remove one field at a time from your quote form and ask whether the number on the next screen changes. Every field that survives that test is rating. Every field that does not is collection. You are entitled to collect, and you are not entitled to make the price conditional on it.
The Thirteen Patterns, Read Against a Broker Journey
The CCPA's Guidelines for Prevention and Regulation of Dark Patterns, 2023 name thirteen specified practices. Most compliance summaries list them and stop. The useful exercise is to walk each one into the screens intermediaries actually build.
- False urgency. Countdown timers on a quote validity that regenerates identically the next day. Renewal banners claiming a rate expires tonight when the insurer's rate table has not moved.
- Basket sneaking. The single most common intermediary breach: add-ons pre-ticked in the quote summary. Personal accident cover bundled into a motor quote, a consumables rider defaulted on, a top-up defaulted into a health basket.
- Confirm shaming. "No thanks, my family can manage the hospital bill" as the decline copy on a sum insured upgrade. Guilt written into the negative option.
- Forced action. Requiring marketing-call consent to receive a quote, or forcing app installation to view a policy schedule that a browser could render.
- Subscription trap. Auto-debit mandates enabled by default at purchase, with cancellation routed through a call centre rather than the same screen that enabled them.
- Interface interference. The continue button in insurer brand colour and 18px, the decline link in grey 11px below the fold. Also the pre-selected higher sum insured tile.
- Bait and switch. Advertising a headline premium that no realistic risk profile obtains, then producing a materially different number after data entry.
- Drip pricing. Showing a base premium and revealing GST, add-ons and platform or convenience fees only at the payment step.
- Disguised advertisement. A "top 5 health plans" comparison page ranked by payout to the intermediary and presented as editorial. Advisor-authored content promoting a product without disclosing the tie.
- Nagging. Repeat push notifications and calls after a user abandoned a quote, with no suppression on request.
- Trick question. Double negatives in consent checkboxes, or a single tick covering both the proposal declaration and a marketing permission.
- SaaS billing. Less common in insurance distribution, though relevant to broker-operated risk-management subscriptions billed alongside placement.
- Rogue malwares. Not a realistic intermediary exposure, and listing it honestly as inapplicable is part of a defensible self-assessment.
Eleven of the thirteen map onto screens that exist in Indian intermediary journeys today. Recurring SaaS billing and rogue malwares rarely do. A self-assessment that addresses all thirteen and explains why two are inapplicable reads as work. One that returns "no dark patterns identified" across the board reads as a form filled in.
Consent, and Where the DPDP Overlap Bites
Bundling marketing consent into a quote form is a dark pattern under the forced-action head and a separate problem under data-protection law. Consent obtained as the price of access is not freely given, and a proposal-stage tick that silently covers marketing calls fails on two tests at once.
The practical fix is unglamorous. Separate the consents. One tick for processing the data needed to produce a quote and place the risk, which is a purpose the customer came for. A distinct, unticked, plainly worded tick for marketing contact, which the customer did not. The quote must render either way.
Intermediaries resist this because unbundled marketing consent converts at a fraction of the bundled rate. That is precisely the point. The bundled rate was never consent, it was a toll, and the conversion delta is the measure of how much of your lead pipeline depends on customers not noticing. Our post on advisor handling of client data under the DPDP Act covers the storage and retention side of the same exposure.
Renewals: The Asymmetry Nobody Documents
Renewal journeys accumulate patterns because nobody redesigns them. They get patched, year after year, in the direction of retention.
The asymmetry is easy to demonstrate and hard to defend. Count the taps required to increase a sum insured at renewal, then count the taps required to reduce it. Count the taps to add a rider against the taps to drop one. In most intermediary renewal flows the upgrade is one tap on the summary screen, and the downgrade routes through a service request, a call-back, or a form that resolves in two working days.
That asymmetry is interface interference plus forced action operating together, and it shows up cleanly in an audit because it is measurable without any access to your systems. A monitor with a stopwatch and a test account produces the finding.
The related trap is the carried-forward add-on. A rider the customer accepted three renewals ago, quietly rolled into every subsequent renewal quote, pre-ticked, never re-consented. It is basket sneaking with a long tail, and it is worth more to a broker's book than most people want to admit before they audit it. The conduct-risk framing in our note on conduct risk management in bancassurance applies directly, because the mechanism is the same one: a default that serves the distributor and survives because nobody is asked to re-approve it.
The Afternoon Self-Assessment
A broking firm can run a first-pass assessment in a single afternoon with two people, a phone, a laptop and a screen recorder. No consultant is required for the first pass.
- Pick your three highest-volume journeys. Typically motor new business, health renewal, and whatever commercial enquiry form sits on your site. Do not start with the journey you are proudest of.
- Record each one end to end as a new user, on mobile and desktop, in an incognito session. Screen recording, not screenshots. Patterns live in transitions.
- Log every field before the price appears and mark each as rating or collection using the one-field-at-a-time test above. Every collection field ahead of the price is a finding.
- Screenshot every default state. Every checkbox, toggle and pre-selected tile, in its state on first load. Pre-ticked anything is a finding.
- Read the decline copy aloud. If the negative option shames, minimises, or is visually subordinate to the accept, it is a finding.
- Time the symmetry. Taps and elapsed time to upgrade against downgrade, to add against remove, to enable auto-debit against cancel it. Any ratio worse than roughly two to one needs a written justification.
- Walk all thirteen CCPA heads and write one line each: present, absent, or not applicable with a reason.
- Include your A/B variants and your partner-embedded journeys. A pattern shipped to 10 percent of traffic by an experiment is still shipped, and a journey your API powers inside a partner's app is still your journey.
The output is a short document listing every finding, an owner, and a date. That is the time-bound action plan the April direction asked for, and it is also the thing you hand a monitor who asks what you have done. Firms that already filed in April should re-run this against the live product, because the code has moved since.
The underlying shift is worth stating plainly. Conversion optimisation in Indian insurance distribution has been an unregulated craft for a decade, and a large share of intermediary funnel performance was built on defaults, gates and asymmetries that nobody had to defend. For the next nine months, somebody is looking. Firms that rebuild their journeys around informed choice will lose some measured conversion and keep it, and the rest of the market will find out what its numbers looked like without the gate.