IRU Circular 21/2026 — Minimum QR-code data in compulsory insurance policies
IRU Circular 21/2026 reminds supervised entities of the minimum information required in a compulsory-policy QR code under Article 4(2) of Decision 19/2025. Check the QR-resolved content, not only that a QR image prints on the policy. Official sources and an evidence-led implementation checklist.
تعميم رقم (21) لسنة 2026 بشأن الالتزام بالحد الأدنى من البيانات التي يجب ان يحتوي عليها رمز الاستجابة السريع (QR CODE) في وثائق التأمين الاجبارية وفقاً للقرار رقم (19) لسنة 2025 بشأن قواعد إصدار وثائق التأمين الإجباريةOfficial Arabic title
- Issued
- 08.10.2026
- Published
- 11.10.2026
- Guide reviewed
- 11.10.2026
- Instrument
- IRU Circular 21/2026
Action at a glance
What this instrument asks you to do
IRU Circular 21/2026 reminds supervised entities of the minimum information required in a compulsory-policy QR code under Article 4(2) of Decision 19/2025. Check the QR-resolved content, not only that a QR image prints on the policy.
Source-backed
Stated legal requirements
Requirements below are attributed to the instrument or cited guidance; each item includes its source location.
- 01
The QR content includes the policy number and schedule, sum insured, general conditions, exclusions, deductibles and special conditions.
Citation · Page 1, minimum-data list
- 02
The listed minimum also includes premium/subscription amount, broker/agent details, endorsements, debt notices, cover period, issue date and QR code, plus any other data.
Citation · Page 1, continuation of minimum-data list
- 03
Observe Article 4(2) of Decision 19/2025 governing compulsory-policy issue.
Citation · Page 1, operative paragraph referring to the base decision
Dates and applicability
Timing, grace period and deadline
Timing
Signed 8 October; published 11 October. The circular reiterates the base decision; it does not state a new general grace period.
Grace period
Only the specifically stated submission period or validity condition applies. No additional general grace period is asserted.
Expit suggested practices
Build a reviewable closure record
These suggested actions are implementation practices, not additional legal requirements.
- 01
Test the QR-resolved policy record against the official minimum list.
- Suggested owner
- Policy issuance / quality assurance
- Evidence to retain
- QR scan test, field mapping and cross-check to the issued policy
- Complete when
- Every listed field is represented accurately in the controlled resolved record for the sampled issue workflow.
- Expit support context
- Extraction can support field reconciliation; the insurer validates completeness.
- 02
Control access and version changes to policy data.
- Suggested owner
- IT security / policy operations
- Evidence to retain
- Access review, endorsement/version history and exception log
- Complete when
- Correct current policy data is retrievable under approved controls without uncontrolled disclosure.
- Expit support context
- Document workflows can maintain traceability; Expit does not certify QR or privacy compliance.
Further clarification
Frequently asked questions
Is printing a QR-code image enough?
The circular is about minimum information in the QR content. Test the actual resolved policy information against the official list.
Can Expit declare our minimum qr-code data in compulsory insurance policies gap closed?
No. Expit can support document processing, evidence reconciliation and accountable workflows. Your responsible officers and advisers must assess legal applicability, complete any required official submission and approve closure.
Primary references
Official sources
- Official IRU Circular 21/2026 PDF (opens in a new tab)SOURCE 01
Operative circular visually reviewed. This guide is limited to the one-page reminder and its data list. Review the base decision for full policy issuance requirements. It does not say every compulsory policy can expose all data without authentication or appropriate privacy controls.
Read with care
Enforcement and limitations
Enforcement stated in source
The circular refers to IRU's powers under Insurance Law 125/2019 and applicable regulations/instructions. No fixed fine or individual enforcement outcome is inferred.
Limitations of this guide
This guide is limited to the one-page reminder and its data list. Review the base decision for full policy issuance requirements. It does not say every compulsory policy can expose all data without authentication or appropriate privacy controls.