IRU Circular 21/2026Insurance Regulatory Unit

IRU Circular 21/2026 — Minimum QR-code data in compulsory insurance policies

IRU Circular 21/2026 reminds supervised entities of the minimum information required in a compulsory-policy QR code under Article 4(2) of Decision 19/2025. Check the QR-resolved content, not only that a QR image prints on the policy. Official sources and an evidence-led implementation checklist.

تعميم رقم (21) لسنة 2026 بشأن الالتزام بالحد الأدنى من البيانات التي يجب ان يحتوي عليها رمز الاستجابة السريع (QR CODE) في وثائق التأمين الاجبارية وفقاً للقرار رقم (19) لسنة 2025 بشأن قواعد إصدار وثائق التأمين الإجباريةOfficial Arabic title

Issued
08.10.2026
Published
11.10.2026
Guide reviewed
11.10.2026
Instrument
IRU Circular 21/2026

Action at a glance

What this instrument asks you to do

IRU Circular 21/2026 reminds supervised entities of the minimum information required in a compulsory-policy QR code under Article 4(2) of Decision 19/2025. Check the QR-resolved content, not only that a QR image prints on the policy.

Source-backed

Stated legal requirements

Requirements below are attributed to the instrument or cited guidance; each item includes its source location.

  1. 01

    The QR content includes the policy number and schedule, sum insured, general conditions, exclusions, deductibles and special conditions.

    Citation · Page 1, minimum-data list

  2. 02

    The listed minimum also includes premium/subscription amount, broker/agent details, endorsements, debt notices, cover period, issue date and QR code, plus any other data.

    Citation · Page 1, continuation of minimum-data list

  3. 03

    Observe Article 4(2) of Decision 19/2025 governing compulsory-policy issue.

    Citation · Page 1, operative paragraph referring to the base decision

Dates and applicability

Timing, grace period and deadline

Timing

Signed 8 October; published 11 October. The circular reiterates the base decision; it does not state a new general grace period.

Grace period

Only the specifically stated submission period or validity condition applies. No additional general grace period is asserted.

Expit suggested practices

Build a reviewable closure record

These suggested actions are implementation practices, not additional legal requirements.

  1. 01

    Test the QR-resolved policy record against the official minimum list.

    Suggested owner
    Policy issuance / quality assurance
    Evidence to retain
    QR scan test, field mapping and cross-check to the issued policy
    Complete when
    Every listed field is represented accurately in the controlled resolved record for the sampled issue workflow.
    Expit support context
    Extraction can support field reconciliation; the insurer validates completeness.
  2. 02

    Control access and version changes to policy data.

    Suggested owner
    IT security / policy operations
    Evidence to retain
    Access review, endorsement/version history and exception log
    Complete when
    Correct current policy data is retrievable under approved controls without uncontrolled disclosure.
    Expit support context
    Document workflows can maintain traceability; Expit does not certify QR or privacy compliance.

Further clarification

Frequently asked questions

Is printing a QR-code image enough?

The circular is about minimum information in the QR content. Test the actual resolved policy information against the official list.

Can Expit declare our minimum qr-code data in compulsory insurance policies gap closed?

No. Expit can support document processing, evidence reconciliation and accountable workflows. Your responsible officers and advisers must assess legal applicability, complete any required official submission and approve closure.

Primary references

Official sources

  1. Official IRU Circular 21/2026 PDF (opens in a new tab)

    Operative circular visually reviewed. This guide is limited to the one-page reminder and its data list. Review the base decision for full policy issuance requirements. It does not say every compulsory policy can expose all data without authentication or appropriate privacy controls.

    SOURCE 01

Read with care

Enforcement and limitations

Enforcement stated in source

The circular refers to IRU's powers under Insurance Law 125/2019 and applicable regulations/instructions. No fixed fine or individual enforcement outcome is inferred.

Limitations of this guide

This guide is limited to the one-page reminder and its data list. Review the base decision for full policy issuance requirements. It does not say every compulsory policy can expose all data without authentication or appropriate privacy controls.