SB StartupBasket
All ideas
76 /100 GO Medium complexity

SellerTag — seller authorisation register for Indian brokers

Proves every policy your firm sold was solicited by someone certified that day, before IRDAI's January 2027 deadline.

— views
Evaluation Scores
76/100

GO

Overall Score

16
Problem
11
Demand
12
Build
12
Distrib.
11
Revenue
8
Time
6
Defense

SellerTag

1. One-liner

Proves every policy your firm sold was solicited by someone certified that day, before IRDAI’s January 2027 deadline.

2. Trend signal — why now?

On 30 July 2026 IRDAI notified the Insurance Intermediaries (Amendment) Regulations, 2026 (IRDAI/Reg/8/222/2026). Buried in it is a change that converts a soft internal-HR problem into a dated, per-policy evidence problem.

From 1 January 2027, the proposal form, the insurance policy and the certificate of insurance must each record the name and functional identity of the person who sold the policy — a specified person, POSP, designated person, authorised verifier or other authorised salesperson. IRDAI accepted industry’s objection to using PAN/Aadhaar and instead settled on a unique identification number for the salesperson. Corporate agents must additionally maintain policy-wise sales records in a format the regulator can access remotely.

The same amendment package swaps periodic renewal for continuous registration (annual fee + continued compliance), adds compulsory enrolment letters for designated sales personnel, and keeps the NOC requirement from the previous employer before a designated person can move to another intermediary. Existing corporate agents and brokers must obtain fresh certificates by 31 January 2027, grace to 31 March 2027 on an extra fee.

Now the thing that makes this a product rather than a memo: a POSP certificate is valid for exactly 3 years and then simply expires. Renewal needs 30 hours of refresher training and is meant to be started 30 days before expiry. Nobody’s system stops an expired POSP from logging in and selling — the certificate lapses silently while the person keeps writing business. Selling on a lapsed certificate puts both the individual and the sponsoring intermediary in breach.

Stack that against enforcement pressure: IRDAI logged 26,667 mis-selling complaints in FY25, up 14% year-on-year. From January 2027 every one of those complaints resolves to a named, uniquely-identified seller — and the firm gets asked, on the record, whether that person was authorised on the date of sale.

Provenance:

3. The opportunity

Every existing tool in this market is built around the policy. Insuraa, Mzapp, Mindzen, BrokerEdge — they all track policies, renewals, commissions, leads. They answer “what did we sell and what are we owed?”

From January 2027 the regulator asks a different question: “who sold it, and were they allowed to?”

That question is a join between two datasets that live in different places and are maintained by different people. The policy book lives in the broking system. The certification roster — who passed which exam, when, valid until when, who has an NOC pending, who resigned last Tuesday — lives in a spreadsheet on the compliance officer’s laptop, or in the training vendor’s portal, or nowhere.

The gap is structural, and it’s the classic scoring-vs-proving split. Incumbent broker software sells you the number (policies sold, commission due, agent performance). Nobody sells the evidence that the person attached to each of those policies held a live certificate on that specific date. Three properties make this genuinely unbuilt:

  1. The failure is silent. An expired POSP doesn’t get locked out. There’s no error, no hard stop. The certificate lapses and the person keeps selling. You find out during inspection — retrospectively, across a book you can no longer fix.
  2. The exposure is retroactive. Policies written by a lapsed seller in March are still on the books in November when the inspector arrives. IRDAI gives roughly 10 days’ notice for routine onsite inspection and focus inspections are generally conducted without prior notice.
  3. The two systems never talk. HR knows the person resigned. The broking system keeps letting their ID be attached to proposals until someone remembers to deactivate it. The NOC/enrolment-letter machinery in the 2026 amendments makes joiner/leaver events regulatory events, not just HR events.

The giants are fine. PB Partners (~40% PoSP share), the merged InsuranceDekho–RenewBuy entity (600,000+ digital partners), Turtlemint (₹506 crore FY24 revenue) — they have in-house engineering and will build this themselves in a quarter. That’s exactly why the opportunity is real: those players have solved it privately for themselves and have zero interest in selling the solution downmarket.

The market is the band underneath: 751 licensed insurance brokers and ~675 corporate agents who each run somewhere between 40 and 3,000 POSPs. Too many people to track in Excel honestly. Nowhere near enough scale to justify an in-house compliance engineering team.

4. Target market

  • Primary customer: The Principal Officer or Compliance Officer at an IRDAI-registered direct/composite insurance broker or non-bank corporate agent in India, running 50–2,000 POSPs / specified persons, typically 8–120 staff, ₹3–60 crore annual premium placed. Concentrated in Mumbai, Delhi NCR, Bengaluru, Ahmedabad, Chennai, Pune, Jaipur, Indore. Explicitly not the banks (their compliance stack is enterprise) and not the four PoSP giants (they build in-house).

  • Why they buy: The compliance officer is personally named. The 2026 amendments put named-officer accountability at the centre — Principal Officers and Designated Persons carry enhanced training obligations, and the draft rules raise the maximum penalty for omissions by corporate agent officers to ₹10 crore annually. The Principal Officer is the human being who signs the statement that the firm’s records are accurate. Right now they sign it on the basis of a spreadsheet they know is stale. From January 2027 that spreadsheet has to survive a regulator who can pull policy-wise sales records remotely and check each seller ID against a certification date.

  • Rough TAM reasoning: 751 brokers + 675 corporate agents ≈ 1,426 registered intermediaries. Strip out the ~150 banks/large NBFCs (enterprise stack, won’t buy SaaS from a startup) and the ~40 giants who build in-house. Serviceable target ≈ 1,200 firms. At ₹8,000–35,000/month that’s a theoretical ₹11–50 crore ARR ceiling — roughly $1.3M–$6M. Deliberately small. That’s the point: too small for VC-scale insurtech, correctly sized for a two-person team, and defended by the fact that the giants have already solved it privately.

  • Why now for them: Three dates, all hard. 1 Jan 2027 — tagging goes live on every proposal, policy and certificate. 31 Jan 2027 — existing registrants must hold fresh certificates. 31 Mar 2027 — grace period ends. A compliance officer reading this in September 2026 has roughly one quarter to get the roster clean before the first tagged policy is issued, and every policy written before that date with an unverifiable seller stays in the book.

5. Product sketch (MVP)

  • Authorisation register — one row per salesperson: unique ID, role (specified person / POSP / designated person / authorised verifier), certificate number, exam date, valid-from, valid-until, sponsoring entity, current status. The single source of truth the compliance officer currently doesn’t have.
  • Lapse countdown — flags every certificate hitting expiry in 90 / 60 / 30 days, ranked by how much premium that person wrote last quarter. Renewal needs 30 hours of refresher training, so 30 days’ notice is already tight; the product pushes the warning out to 90.
  • Sold-by-lapsed sweep — the retroactive one, and the reason people buy. Point it at your policy book and it returns every policy whose attached seller was not certified on the issue date. This is the report that tells you the size of the hole before the inspector does.
  • Joiner / leaver control — tracks the NOC-from-previous-employer and Letter of Enrolment state for every designated person, and flags anyone still active in the sales system whose enrolment isn’t complete or who has resigned.
  • Tagging readiness check — takes a sample of proposals/policies and reports which ones are missing the seller’s name, functional identity, unique ID, or the branch mobile/email now required on the document.
  • Inspection pack — one click produces the dated, policy-wise authorisation evidence file in the format an IRDAI onsite inspection asks for. Built for the focus inspections that arrive without prior notice.
  • Signed monthly attestation — a timestamped record the Principal Officer signs each month saying the roster was clean on that date, retained for the 7-year record-keeping period.

6. AI angle — what’s load-bearing

Honest answer: AI is doing extraction and reconciliation, not judgement. Remove it and this becomes a data-entry product nobody buys — which is the correct test.

The load-bearing work is that certification evidence arrives as garbage. A firm with 600 POSPs has certificates as PDFs from four different training partners, exam results as portal screenshots, insurer-issued codes in emailed XLSX with inconsistent headers, and joiner/leaver records in an HR system that doesn’t know what a POSP is. Getting from that pile to a clean valid-from/valid-until register is the whole job, and it’s the reason the compliance officer hasn’t already built this in Excel.

So the AI does three things:

  1. Reads certificates and exam results — pulls certificate number, holder name, category (life 50h / general 25h / health), issue date and validity from heterogeneous PDFs and portal exports.
  2. Resolves identity across systems — the same human is “Rajesh Kumar S”, “R. Kumar”, employee 4471 and POSP code TM-88213 across four systems. Fuzzy matching plus the new unique identification number to anchor against. This is where the reconciliation actually happens.
  3. Explains each exception in plain language — not just “policy 88213 flagged” but “sold 14 Mar 2026 by Rajesh Kumar, whose general-insurance certificate expired 2 Feb 2026; 23 other policies affected; renewal training not started.”

What is deliberately not AI: the validity rule itself. Whether a certificate was live on a date is deterministic arithmetic, and it must be, because the output is evidence handed to a regulator. An LLM guessing at compliance verdicts is a liability, not a feature. AI cleans the inputs; a rules engine renders the verdict.

7. Localization angle

This is India-only by construction — it exists because of one Indian regulator’s amendment with an Indian commencement date. Not a localized version of a global product; there is no global product.

That said, the shape is portable. Any regulator that moves to per-policy seller attribution creates the same join. Worth noting as a later option, not as part of this plan.

Local specifics that matter for building it:

  • Pricing in rupees, sized to Indian compliance budgets. ₹8,000/month is an easy approval for a Principal Officer; $500/month is a board conversation.
  • WhatsApp for the lapse warnings. POSPs are field agents across 1,500+ cities. Renewal nudges reach them on WhatsApp or they don’t reach them.
  • Regional-language renewal nudges. The compliance officer reads English. The POSP in a Tier-3 town whose certificate expires in 40 days often doesn’t.
  • The training-partner ecosystem is the distribution channel — see section 9.

8. Business model — path to $1M–$5M ARR

  • Pricing: Banded by roster size, billed annually (Indian compliance budgets are annual):

    • Starter — up to 100 salespersons — ₹8,000/mo (₹96K/yr)
    • Growth — 101–500 — ₹18,000/mo (₹2.16L/yr)
    • Broker — 501–2,000 — ₹35,000/mo (₹4.2L/yr)
    • One-time historical sweep — ₹40,000–1,50,000 depending on book size. This is the wedge: sold as a fixed-fee diagnostic before anyone commits to a subscription.
  • ACV: Blended ≈ ₹2.4L (~$2,900), assuming the mix skews to Starter/Growth.

  • Rough math to $1M ARR: ₹8.7 crore ≈ 360 firms at blended ₹2.4L. That’s 30% of the ~1,200-firm serviceable base. Achievable but genuinely hard — it means being the default in this category.

  • Rough math to $5M ARR: Not reachable from Indian intermediaries alone; the base is too small and I’d rather say so than invent a number. It needs one of: (a) selling the same register to insurers who must supervise their intermediaries’ rosters — a much larger per-account ACV, (b) expanding to adjacent Indian distribution licences with the same lapse-and-attest shape (mutual fund distributors, AMFI ARN renewals; SEBI IA/RA under its own 2026 digital-compliance regime), or (c) exporting the shape to another regulator that adopts seller attribution. Treat $5M as a hypothesis, not a plan. The honest ceiling on the core play is ₹8–12 crore ARR.

  • Expansion path: Roster growth moves firms up bands automatically. Then: per-branch modules, the insurer-side supervision product, and CPD/refresher-training booking as a passthrough (the firm has to buy 30 hours of refresher training per lapsing POSP anyway — brokering that is natural adjacent revenue, though it needs care to avoid conflict with the training partners who are also the distribution channel).

9. Go-to-market wedge — first 100 customers

The buyer list is public and finite. IRDAI publishes the list of licensed brokers and the list of valid corporate agents as downloadable registers, with entity names, registration numbers and Principal Officer contact details. That is the entire addressable market in two PDFs — roughly 1,426 named firms with named accountable officers.

  1. The free lapse audit, run before the first email. Take the public register, pick the 400 mid-size non-bank intermediaries, and for each one send the Principal Officer a two-page note: the three dates they’re facing (1 Jan / 31 Jan / 31 Mar 2027), what “sold by a lapsed seller” exposure looks like on a book their size, and an offer to run the historical sweep for a fixed fee. Named-officer accountability means this lands on someone personally exposed, not in a procurement queue. Expect 8–12% reply on a personally-relevant regulatory deadline — well above cold-SaaS norms, because the email is about their signature.

  2. Sell the sweep, not the subscription. ₹40K for a one-time report answering “how many policies in my book were sold by someone uncertified on the date?” is an easy yes — it’s a diagnostic with a number at the end, and it doesn’t require ripping out their broking system. Every sweep that returns a non-zero count converts to subscription on its own evidence. Target ~40% sweep-to-subscription. Sweeps that return zero are still worth doing: that firm becomes a reference, and their roster still lapses next year.

  3. Training partners as the channel. POSP training and certification is delivered by a dense ecosystem of IRDAI-approved training partners who already hold the relationship with hundreds of intermediaries and who profit when a lapsing POSP books 30 hours of refresher training. The product generates their pipeline — every 90-day lapse warning is a training booking. Revenue-share referral with 8–10 of them. This is the highest-leverage channel and the one a competitor can’t trivially replicate.

  4. The Insurance Brokers Association of India (IBAI) and regional chapters. IBAI runs member education around exactly these regulatory changes, and the January 2027 tagging deadline is going to be on every chapter agenda this quarter. Speak at three; a 45-minute session explaining the tagging rule to a room of Principal Officers converts better than any ad, because the session is the demo.

  5. Compliance-consultant referrals. Firms like Enterslice and Compliance Calendar already sell IRDAI broker compliance services and audits manually. They hit the roster problem on every engagement and currently solve it with billable hours. Referral fee, and they keep the advisory work.

First 100 realistically: ~35 from direct outreach on the public register, ~30 via training partners, ~20 from IBAI chapter sessions, ~15 from consultant referrals. Over 9–12 months.

10. Build complexity — justification

Medium. ~14–18 weeks to a sellable v1 for two people.

Off-the-shelf: the rules engine (date arithmetic against certificate validity), the register itself, standard web stack, WhatsApp Business API for nudges, document extraction via off-the-shelf vision models. None of that is novel.

The real work is in three places. Ingestion breadth — certificate PDFs and portal exports from many training partners and insurers, all differently shaped, with no standard schema. Identity resolution — matching one human across HR, the broking system, the training partner’s records and the insurer’s agent code, which is fuzzy-matching work that needs to be right because the output is regulatory evidence. Policy-book ingestion — getting the sold-by field out of whatever the firm uses, which for the target segment means CSV/XLSX exports far more often than a clean API.

The saving grace: v1 can be CSV-in, report-out. No deep integration required to sell the first sweep. Integrations get built against the two or three broking systems that actually show up in the target segment, once you know which ones those are. That ordering is what keeps this Medium and not High.

11. Gating checklist

GatePass?Note
Legal in target market✅Compliance tooling built on published IRDAI regulations. Not a regulated activity itself — no IRDAI licence needed to sell software to intermediaries.
Ethical — no harm / dark patterns✅Helps firms find and fix their own unauthorised-solicitation exposure. Aligned with the policyholder-protection intent. Handles personnel data, so DPDP-grade handling is table stakes.
Market exists (evidence above)✅1,426 registered intermediaries, dated statutory duty, existing manual spend on compliance consultants and audits.
1–5 person team can build this✅Two people, 14–18 weeks. Domain advisor essential.
Launchable with <$50K / ₹40L✅₹12–18L covers build, a domain advisor, and the first two quarters of outreach.

12. Feasibility score

AxisWeightScoreNotes
Problem intensity2016/20Dated statutory duty with named-officer accountability and retroactive exposure — the compliance officer is personally on the hook. Held back from higher because the pain is quarterly/annual and inspection-triggered, not daily. It’s a deadline problem, not a bleeding-every-day problem, and deferred pain converts worse than continuous pain.
Demand evidence1511/15Strong regulatory and enforcement evidence (26,667 FY25 mis-selling complaints, +14%; active s.40(1) enforcement; explicit gap in incumbent feature lists). Docked meaningfully: I found no direct customer voice — no forum threads, no Principal Officers complaining publicly about roster lapses. This is a segment that doesn’t post online, which is plausible but unverified. That’s a real hole.
Build feasibility1512/15Standard stack, deterministic core, AI confined to extraction. Ingestion breadth and identity resolution are the grind. CSV-in/report-out v1 de-risks it.
Distribution clarity1512/15Buyer list is public, finite, and named — rare and valuable. Training-partner channel is genuinely high-leverage. Docked because 1,426 firms is a small pond: burn the list with a bad first email and there’s no second list.
Revenue mechanics1511/15Pricing fits Indian compliance budgets; the fixed-fee sweep is a clean low-friction entry. Docked because the honest ceiling on the core play is ₹8–12 crore ARR and $5M needs a second act that isn’t proven.
Time to first revenue108/10The ₹40K historical sweep can be sold and delivered semi-manually before the product is finished. Revenue in 6–8 weeks is realistic.
Defensibility106/10Soft moat: accumulated ingestion adapters for messy training-partner formats, the training-partner channel relationships, and workflow lock-in once a firm’s signed monthly attestations live in your system (switching means abandoning the audit trail). But the giants could build this and any competent team could copy it in six months. Regulatory knowledge is the durable part.
Total10076/100

13. Qualitative modifiers

Founder-fit tags

domain-expertise-required · sales-heavy

This does not work as a purely technical build. Someone on the founding team needs to sit credibly in a room with a Principal Officer and discuss IRDAI intermediary regulations without flinching — ideally an ex-compliance officer from a broker. The build is the easy half.

Key assumptions to validate (3–5)

  1. Assumption: Mid-size intermediaries genuinely have lapsed-seller exposure they can’t currently see — i.e. the sweep returns a non-zero number for most firms. How to test: Run the historical sweep free for 5 firms. If the median result is zero policies sold by a lapsed seller, the core report has no punch and the product loses its wedge. This is the assumption the whole thing rests on.
  2. Assumption: The Principal Officer, not IT or procurement, can approve ₹8–18K/month. How to test: 20 discovery calls off the public register. Ask directly who signs and what the threshold is.
  3. Assumption: Training partners will refer, and see the lapse warnings as pipeline rather than competitive threat. How to test: Pitch 6 IRDAI-approved training partners with a revenue-share. Two signed referral agreements = validated.
  4. Assumption: Policy books in this segment can be exported with a usable sold-by field. How to test: Get sample exports from 5 firms across different broking systems. If the seller identity isn’t in the export, the sweep can’t be automated and unit economics break.
  5. Assumption: The January 2027 dates hold and aren’t deferred. How to test: Track IRDAI circulars monthly. Indian compliance deadlines slip often — see section 13 risk 1.

Risk flags

  1. Regulatory timing risk — the big one. Indian regulators defer deadlines routinely; SEBI just extended its own digital-accessibility timelines for investment advisers twice. If IRDAI pushes the tagging date from January 2027 to 2028, urgency evaporates for a year and the sales cycle stretches past the runway. Mitigation: lead with the retroactive sweep, which has value regardless of the date, rather than with the deadline.
  2. Incumbent absorption. Insuraa, Mzapp, Mindzen and BrokerEdge already sit in these firms with the policy data. Adding a certification-validity table is not hard for them; they just haven’t bothered because it doesn’t sell software today. Once the deadline creates demand, it becomes an obvious feature. The window is roughly 12–18 months to become the category default.
  3. Small pond. ~1,200 serviceable firms. There’s no second market to fall back to if the segment doesn’t convert, and the outreach list is not replenishable. A bad first campaign is expensive in a way it wouldn’t be with a 50,000-firm TAM.
  4. Data sensitivity. The system holds personnel records, certification status and commission-adjacent data under DPDP. A breach in a product whose entire value proposition is compliance is fatal to the brand, not just to the customer.
  5. Unverified customer voice. Section 12 docks demand for this and it deserves repeating as a risk: the entire demand case is inferred from regulation and enforcement statistics, not from anyone saying out loud that they need this. The 20 discovery calls are not optional.

14. Structured verdict

Score:                  76/100
Verdict:                GO
Confidence:             Medium
Best-fit builder:       Two people — one ex-compliance officer from an Indian
                        broker or corporate agent, one full-stack engineer.
                        Domain credibility is the binding constraint, not code.
Time to revenue:        6–8 weeks (fixed-fee historical sweep, sold before the
                        product is finished)
Capital to launch:      ₹12–18 lakh (~$14–21K)
Top 3 assumptions to validate first:
  1. Lapsed-seller exposure is real and visible — run the sweep free for 5 firms;
     need a non-zero median result
  2. Principal Officer can approve ₹8–18K/mo without procurement — 20 discovery
     calls off the public IRDAI register
  3. Training partners will refer — pitch 6, need 2 signed revenue-share deals
Kill criteria:
  - Abandon if the free sweep across 5 real policy books returns zero lapsed-seller
    policies for 4 or more of them — the core report has no punch
  - Abandon if <5 of 40 Principal Officers contacted will take a 20-minute call
    about the January 2027 tagging deadline
  - Abandon if IRDAI defers the tagging commencement beyond January 2028
  - Abandon if two incumbent broker platforms ship certification-validity tracking
    before your v1

15. Next step — 1-week validation sprint

  • Day 1: Pull the IRDAI registers of licensed brokers and valid corporate agents. Build the real target list — strip banks, large NBFCs and the four PoSP giants. Confirm the count of genuinely mid-size non-bank intermediaries with named Principal Officers. If that number is under 400, the pond is too small and the economics in section 8 need revisiting before anything else happens.
  • Day 2: Read the Amendment Regulations 2026 text in full against the IRDAI gazette copy — not the vendor blogs. Confirm the 1 January 2027 commencement, the exact tagging fields, and the record-keeping format. Vendor blogs invent commencement dates; verify at the source.
  • Day 3–4: Twenty calls to Principal Officers from the register. One question above all others: “If IRDAI asked today for every policy sold in the last 12 months by someone whose certificate had expired, how long would that take you and how confident are you in the answer?” Anyone who answers “an hour, very confident” is not a customer. Count how many say “weeks” or laugh.
  • Day 5a: Offer 5 of those firms a free historical sweep. Get at least 2 policy-book exports in hand — this simultaneously tests whether the sold-by field even exists in their exports (assumption 4).
  • Day 5b: Pitch 6 IRDAI-approved POSP training partners on a referral revenue-share.

Go/no-go, falsifiable: Proceed only if ≥8 of 20 Principal Officers say the lapsed-seller question would take them more than a week to answer, ≥2 hand over a policy-book export containing a usable seller field, and ≥2 training partners agree to a referral deal. Anything less and the demand is inferred from regulation rather than felt by customers — which is precisely the failure mode the demand score already flags at 11/15.

Interested in a detailed proposal?

Get a deep-dive with market research, competitive analysis, and implementation roadmap.

Contact us

info@startupbasket.ai