Manav.id
Definitional · 4 min read

Underwriting on questionnaires when the control is bypassed daily

Underwriting on questionnaires when the control is bypassed daily

An underwriter asks whether dual authorisation is enforced on wires above a threshold. The answer is yes, and it is true of the policy. Whether it was true of the wire that generated the claim is a different question, answered eighteen months later by lawyers.

Why do cyber questionnaires produce coverage disputes?

Because they measure declared policy and losses come from operational reality. An underwriter asks whether dual authorisation is enforced; the answer is true of the policy and unknown for the specific wire that generated the claim. The gap is discovered eighteen months later, by lawyers.

Key takeaways
  • A questionnaire measures declared policy. Losses arise from operational reality, and the two diverge in predictable ways.
  • Both outcomes of that divergence are bad for the insurer: pay for a bypassed control, or litigate a warranty and damage the relationship.
  • Evidence that a control operated on a specific transaction lets an underwriter price the control rather than the answer.

What a questionnaire can and cannot measure

Questionnaire answereddescribes the policyException path usedurgencyLoss occurscontrol bypassedInsurer pays, or contests the warrantyboth bad
Neither party is acting badly. The instrument cannot reach the fact that matters.
QuestionWhat it measuresWhat the loss depends on
Is MFA enforced everywhere?Policy intentWhether legacy protocols and service accounts were exempt
Do you require dual authorisation above a threshold?Policy intentWhether the specific wire had two approvers
Do you verify payment changes out of band?Policy intentWhether verification happened for this beneficiary
Do you conduct security awareness training?Programme existenceWhether the specific employee was deceived

The third column is what the claim turns on. A questionnaire cannot reach it, because at the time of answering that transaction has not happened.

Why answers drift from reality

Rarely dishonesty. The usual causes are structural.

  1. The answerer does not know. A risk manager completing a questionnaire relies on what IT and finance tell them, which reflects the designed process.
  2. Exceptions accumulate. The control exists and has carve-outs for urgent payments, particular subsidiaries, or an executive who found it inconvenient.
  3. Scope is narrower than the answer. MFA is enforced on the primary identity provider and not on a legacy system nobody remembered.
  4. The control degraded. It was true at renewal and something changed six months later.

Item two is the most common and the most consequential, because the exception path is exactly where an attacker applies pressure. Urgency is the social engineer's primary tool, and the control's urgency exception is the door.

The insurer's bad choice at claim time

When a loss involves a bypassed control, the insurer picks between two unattractive options.

OptionCost
PayA loss the pricing assumed would not occur, on a portfolio basis this drives the loss ratio
Contest the warrantyLegal expense, delay, a customer relationship damaged, broker relationship damaged

Neither is good, and the choice tends to be made on the size of the claim rather than on principle — which is itself a source of inconsistency that brokers and insureds resent.

What evidence changes

Not the questionnaire. The unit of underwriting.

# Questionnaire
  "Dual authorisation above $10,000?"  →  Yes

# Evidence
  Period:                   12 months
  Payments above $10,000:   2,184
  With two signed approvals: 2,151    (98.5%)
  Exceptions:                  33
    28 × emergency path, documented, single approver
     5 × approver = initiator

# The underwriter now knows the exception rate and the
# exception shape, not a yes.

A 98.5% figure is more useful to an underwriter than a yes, and it is more honest. It also tells them where the residual risk is concentrated, which is what pricing is supposed to reflect.

Why this should appeal to insureds too

The instinct is to resist — more scrutiny, more to be held to. The counter-argument is concrete.

The last item is often the most valuable in the first year, and it has nothing to do with insurance.

What would have to happen

This is a market-structure change, not a product feature, and it moves slowly.

  1. An insurer offers a concrete term — a higher sub-limit or a premium credit — conditioned on verifiable evidence for a specific control.
  2. Brokers use it as a differentiator, because it gives them something to negotiate with.
  3. Insureds instrument the control to obtain the term.
  4. Loss experience on evidenced versus attested controls diverges, and pricing follows.

Step four is the one that settles it. Until there is loss experience distinguishing the two populations, this remains an argument rather than an actuarial fact — and it is worth being honest that the data does not yet exist.

Why answers drift from reality

Four structural causes, none of them dishonesty
CauseMechanism
The answerer does not knowRisk managers rely on what IT and finance describe
Exceptions accumulateUrgent payments, subsidiaries, an inconvenienced executive
Scope is narrower than the answerLegacy systems nobody remembered
The control degradedTrue at renewal, changed six months later

The second is where losses concentrate, because urgency is the social engineer's primary tool and the urgency exception is the door.

Objections and honest limits

“This is an argument for stricter warranties.” It is an argument against warranties as the mechanism. A stricter warranty on an unmeasurable control produces more denials, not fewer losses.

“Insureds will resist measurement.” Some will. The ones who measure get coverage certainty, a case for higher sub-limits, and their own exception rate — which most have never seen.

What a measurable control looks like

  1. A defined scope. Which payments, by threshold and trigger.
  2. A measured coverage rate. Over twelve months, not a policy statement.
  3. Categorised exceptions. Where the residual risk sits.
  4. Adjuster-verifiable evidence. Without contacting the insured.

Terms used here

Warranty
A policy term the insured promises to maintain, and the basis on which claims are frequently contested.
Coverage rate
The proportion of in-scope transactions that actually carried the control.
Exception path
The route that bypasses a control under time pressure — and the one attackers aim for.

Frequently asked questions

Are insureds lying on questionnaires? Rarely. The answerer describes the designed process, exceptions accumulate below their visibility, and scope is often narrower than the question implies.

Why is the exception path the problem? Urgency is the social engineer's main tool, and the control's urgency exception is precisely the door they push on.

Why would an insured want more scrutiny? Coverage certainty, an argument for higher social engineering sub-limits, pricing differentiation, and knowing their own exception rate.

Is this proven actuarially? No. Until loss experience distinguishes evidenced from attested controls, it is a structural argument rather than a priced fact.

Is this actuarially proven? No. Until loss experience separates evidenced from attested controls it is a structural argument, and saying otherwise damages the case.

Where this fits in Manav

Manav produces the artefact underwriting and claims both lack: a per-transaction receipt an adjuster can verify without contacting the insured, and a measurable coverage rate across a defined scope.

See the evidence a claim needs →

Sources and further reading