Operations & Best Practices

IRDAI Flagged a Fake Grievance Website: The Script to Send Your Clients This Week

On 4 September IRDAI said the website igmsirdai.online, complaint-registration page included, is not an IRDAI site and told the public not to enter personal, policy, banking, KYC or OTP data there. Advisors are the ones clients call when a claim stalls, so here is the script to send the book.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
10 min read

Listen to this article

Audio version • 10 min read

pospgrievance redressalfraud alertbima bharosaclient servicing

Last reviewed: September 2026

What IRDAI Published on 4 September

On 4 September 2026 IRDAI issued a public caution about a website operating at igmsirdai.online. The regulator said the site, including its complaint registration webpage, is not an official IRDAI website, that the matter is under investigation, and that action will be taken.

The advisory went further than a disclaimer. IRDAI advised the public not to access the site and not to submit personal, policy, financial, banking, KYC, OTP or other sensitive information there, or on any other site claiming to represent the regulator without verification. It also cautioned against making payments on such a site and against sharing credentials, passwords or OTPs.

Read the domain slowly, because the design of the fraud is in the name. IGMS was the name of the Integrated Grievance Management System, the predecessor to the grievance portal policyholders use today. A client who half-remembers the acronym from an old email, or who types "IGMS IRDAI complaint" into a search box, is exactly the person that domain was registered to catch. The .online suffix does the rest of the work, because most policyholders have never been told that the regulator's only website is irdai.gov.in.

The people who reach a site like this are policyholders in the worst week of their policy: a claim held up, a query unanswered, a hospital asking who is paying. That state of mind is the product being farmed.

Why the Advisor Is the Distribution Point for the Correct Answer

A regulator's press advisory reaches the people who read regulator press advisories. That is not your client.

When a claim stalls, the first call a retail policyholder makes is to the person who sold them the policy. Not the insurer's call centre, not the grievance cell, and certainly not IRDAI. This is the structural fact that makes advisors and brokers the only channel with real reach into the affected population: you have the phone numbers, the WhatsApp threads, and the standing to be believed.

It also means the failure mode runs through you. A client who calls you about a delayed claim and gets "I will check and revert" is a client who then opens a search engine. What they find at that moment decides whether they end up on a regulator's portal or on a page harvesting their KYC. The gap between your callback and their search is the window the fake site is built for.

The advisor's job in this situation is narrow and it is achievable in an afternoon: make sure every client in your book knows the one route that is real before they need it. Our companion post on the advisor's role in a retail claim sets out what you owe a client while a claim is running. This post covers the part that happens when the client stops waiting for you.

The Route That Is Real: Grievance Officer First, Then Bima Bharosa

There are two doors, and both of them are reachable without typing a URL a stranger gave you.

Door one is the insurer. Every insurer maintains a grievance function with a designated officer to receive and answer policyholder grievances. The client reaches it through the contact details printed on the policy schedule or published on the insurer's own website. A grievance almost always has to start here, because the insurer is the party to the contract of insurance and the party that can actually move the claim.

Door two is Bima Bharosa, IRDAI's grievance portal, which is listed among the regulator's official E-Services on irdai.gov.in alongside the Corporate Agency Portal. It is where a policyholder registers a grievance and has it routed and tracked outside the insurer's own inbox when the insurer's response has not resolved the matter.

Teach clients to reach Bima Bharosa the safe way: open irdai.gov.in, find the E-Services listing on the regulator's own site, and follow the link from there. Never from a remembered address, a search result, or a forwarded link. The one habit worth drilling is that the client should arrive at the portal by starting at the regulator's own domain, every single time.

For the firm-side view of how these grievances arrive, get logged and get escalated, see the broker grievance redressal workflow.

What a Legitimate Escalation Never Asks For

Most clients cannot evaluate a domain name. Almost all of them can evaluate a request. So the test worth teaching is not "is this website real" but "is this request one a real grievance process would ever make".

A genuine complaint registration asks who you are, which policy you hold, and what went wrong. It does not ask for any of the following:

  • An OTP. No grievance process, insurer or regulator, needs a one-time password sent to the client's phone. IRDAI's 4 September advisory named OTPs specifically among the things not to share.
  • A password or login credential for net banking, an insurer portal, or an email account.
  • A payment of any kind. No fee to register a complaint, no fee to expedite it, no refundable deposit, no "processing charge" to release a claim.
  • Full banking details entered on a third-party page. Bank account information for a claim settlement goes to the insurer through the insurer's own channel, not to a complaints website.
  • Fresh KYC uploads to an unfamiliar site. The insurer already holds the client's KYC. A complaint about that insurer does not require re-uploading it somewhere new.
  • Remote access to the client's phone or laptop through a screen-sharing or support app, to "help complete the complaint".

Any one of these is enough to stop. A client who learns the list does not need to learn anything about domains, and the list keeps working when the fraudulent site changes its address next month.

Verifying a URL Before a Client Types Anything

For clients who want a check they can run themselves, keep it to four steps that fit in a message.

  1. Look at what comes immediately before the first single slash. IRDAI's website is irdai.gov.in, and Indian government portals sit on .gov.in. A domain ending in .online, .info, .co, .site or .in alone is not IRDAI, whatever words appear before it.
  2. Type the address, do not tap it. Reaching irdai.gov.in by typing it into the address bar removes every risk that comes from search-result ads, forwarded links and message previews.
  3. Start at the regulator's home page and click through from there. Never bookmark or reuse a deep link somebody sent you. If the portal cannot be reached by clicking through from irdai.gov.in, it is not the portal.
  4. Treat a payment screen as proof it is fake. Registering a grievance costs nothing. A request for money ends the conversation.

The same discipline applies inward. If your own firm's servicing pages, forms or WhatsApp templates send clients to shortened links, third-party form builders or unbranded domains, you are training your book to click on exactly the kind of thing this advisory warns about.

The Message to Send Your Book This Week

Copy this, change the name and number, and send it to every client you service. It is short on purpose, because a long message gets scrolled past.

Important, please read and save.

IRDAI has warned on 4 September that a website called igmsirdai.online is fake. It is not an IRDAI site, even though its complaint page looks official. Do not open it and do not enter your personal, policy, bank, KYC or OTP details there.

If you ever have a problem with a policy or a claim, there are only two correct places to go:

First, call or write to me. My number is [your number].

Second, raise it with your insurer's grievance officer, using the contact details on your policy document.

If the insurer does not resolve it, a complaint can be registered on IRDAI's Bima Bharosa portal. Reach it by typing irdai.gov.in in your browser and going to E-Services from there. Never through a link somebody sends you.

No genuine insurance complaint ever needs an OTP, a password, or a payment. If any website or caller asks for these, stop and call me.

Two notes on sending it. First, send it from the number your clients already know you by, so it reads as servicing and not as a forward. Second, do not add "share with your friends", because the moment it is forwarded past your book it loses the one thing that makes it credible, which is that it came from a person the reader knows.

If a Client Has Already Entered Something

Some clients will call after they have typed details in, not before. Handle that call in a fixed order and do not spend time on how it happened.

  1. Bank and card first. If banking details, card numbers, an OTP or a UPI PIN were entered or shared, the client calls their bank immediately to block the card or channel and flag the account. This is the only step that is time-sensitive in minutes.
  2. Change the reused password. If a password was entered, change it wherever else that password is used, starting with email, because email is the recovery path to everything else.
  3. Report it. A cyber fraud can be reported on the national cybercrime reporting portal at cybercrime.gov.in. Help the client do it rather than telling them to do it.
  4. Tell the insurer. If policy numbers or KYC documents were exposed, inform the insurer's grievance or service function in writing so the exposure is on record before anybody tries to use it for a fraudulent servicing request.
  5. Log it in your own file. Note the date, what the client says was entered, and what you advised. If a fraudulent endorsement or a bank-detail change surfaces on that policy later, a dated contemporaneous note is the difference between a documented incident and an argument.

Do not promise recovery of money and do not speculate about who is behind the site. IRDAI has said the matter is under investigation. That is the whole of what is known.

Make It a Servicing Habit, Not a One-Week Alert

One fake domain gets flagged, and another gets registered. The lasting value of this week is the client who has learned that grievances start with a phone call to their advisor and a .gov.in address typed by hand. The string igmsirdai.online will stop resolving at some point.

Build three things into normal servicing.

At onboarding, tell every new client the escalation path in one sentence and make sure it lands in writing: advisor first, insurer's grievance officer next, Bima Bharosa through irdai.gov.in after that. A client told at policy issue does not need to be rescued at claim stage.

At renewal, repeat it. Renewal is the one predictable annual contact where a client is already reading a message from you about their policy, and the marginal cost of two extra lines is nothing.

On your own digital surfaces, remove the friction that trains bad habits. IRDAI's chief urged insurers in July 2026 to eliminate dark patterns from websites and apps, citing the erosion of consumer trust in digital journeys, and that argument does not stop at insurers. Confusing consent screens, hidden opt-outs and unbranded third-party forms make a client less able to tell a legitimate journey from a fraudulent one, because they no longer expect the legitimate one to be clean. Our post on the dark patterns audit and what it means for broker and POSP digital journeys covers the review itself.

The advisor who runs this well ends up with something more durable than a fraud alert. When a client's first instinct on any doubt is to call you and check, you have removed most of the value from every impersonation attempt aimed at your book, and you have made yourself the verification layer. That position is also what keeps a stalled claim from becoming a complaint, a subject covered from the conduct side in what happens when a client complains.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

What exactly did IRDAI say about igmsirdai.online?
On 4 September 2026 IRDAI cautioned policyholders that the website igmsirdai.online, including its complaint registration webpage, is not an official IRDAI website, and said the matter is under investigation and that action will be taken. The regulator advised the public not to access the site or submit personal, policy, financial, banking, KYC, OTP or other sensitive information there, or on any other site claiming to represent the regulator without verification, and cautioned against making payments or sharing credentials, passwords or OTPs.
Where should a client actually register an insurance grievance?
Start with the insurer. Every insurer maintains a grievance function with a designated officer, reachable through the contact details on the policy schedule or the insurer's own website, and the insurer is the party to the contract that can move the claim. If that does not resolve the matter, a grievance can be registered on Bima Bharosa, IRDAI's grievance portal, which is listed among the regulator's official E-Services on irdai.gov.in. Reach it by typing irdai.gov.in into the browser and following the E-Services link from there rather than through a search result or a forwarded link.
How can a client tell a fake insurance complaint site from a real one?
Check the request before the address. A genuine complaint registration asks who you are, which policy you hold and what went wrong. It never asks for an OTP, a net banking or portal password, a payment or processing fee, full banking details typed into a third-party page, fresh KYC uploads to an unfamiliar site, or remote access to a phone or laptop. On the address itself, IRDAI's website is irdai.gov.in; a domain ending in .online or similar is not the regulator regardless of the words in front of it.
A client already entered their details on the fake site. What now?
Work in order. Call the bank first to block the card or channel if banking details, card numbers, an OTP or a UPI PIN were shared, since that is the only step that is time-sensitive in minutes. Change any password that was entered, starting with anywhere it was reused and with email first. Report the fraud on the national cybercrime reporting portal at cybercrime.gov.in, helping the client file rather than telling them to. Inform the insurer in writing if policy numbers or KYC documents were exposed. Log the date, what was entered and what you advised in your own client file.
Is it appropriate for an advisor to send clients a fraud warning like this?
Yes, and it is one of the few servicing messages clients reliably read. A retail policyholder with a stalled claim calls the person who sold the policy before calling anyone else, which makes the advisor the channel with real reach into the affected book. Send it from the number clients already know you by so it reads as servicing, keep it to the two correct escalation doors plus the rule that no genuine complaint needs an OTP or a payment, and repeat the same path at onboarding and at every renewal.

Related Glossary Terms

Related Insurance Types

Related Articles

Pratibimb by Sarvada

Bring your book to Pratibimb.

Every client, policy, renewal, and rupee of commission in one place, with Pratibimb on WhatsApp handling the follow-through.

Open Pratibimb