Underwriting the control: what insurers should ask about authorization evidence
An application question that can only be answered yes is not a question. It is a formality that both parties complete so the policy can issue, and it is the basis on which funds transfer fraud risk is currently priced.
What should an insurer ask about authorisation evidence?
Not whether a control exists, but what it produces. Underwriters price controls they cannot verify: an insured attests to callbacks and MFA, the claim arrives anyway, and the underwriter learns nothing transferable. The useful questions ask for scope, coverage rate and exception shape.
- Control questions are yes/no attestations about procedures, and procedures are defeated by impersonation, which is the dominant loss driver.
- Nothing an insured holds today is verifiable by an underwriter, so pricing cannot distinguish a strong control from a well-worded policy document.
- The proposal is a measurement design, not a finding: whether authorisation evidence predicts loss frequency is testable and untested.
Part of Insurance and payer identity
A conversation in a renewal meeting
The broker walks through the application. Does the insured require dual authorisation on wire transfers above a threshold? Yes. Does it require out-of-band callback verification for changes to vendor banking details? Yes. Is multi-factor authentication deployed on email? Yes.
Every answer is true. The insured's procedures say exactly those things, the staff have been trained, and the policy document is current.
Eight months later the insured suffers a funds transfer loss. The callback was performed. It reached the attacker. Dual authorisation was obtained — both approvers saw the same fraudulent instruction. Multi-factor authentication was in place and was not invoked, because the attacker never logged in.
Every control question was answered honestly and none of them predicted anything.
Why the questions cannot discriminate
An underwriting question is useful when the answers vary across the population and correlate with outcomes. These questions fail on the first condition before the second is reachable.
| Question | Share answering yes | Discriminating power |
|---|---|---|
| Dual authorisation above a threshold? | Nearly all commercial insureds | None |
| Callback verification for banking changes? | Nearly all | None |
| MFA on email? | Nearly all, by 2026 | Low and falling |
| Security awareness training? | Nearly all | None |
When ninety-five percent of a population answers yes, the question is carrying almost no information into the price.
What a verifiable question looks like
The distinguishing property is that the answer produces an artefact the underwriter can sample rather than a claim the underwriter must accept.
- Attested: Do you require callback verification on vendor banking changes? — answerable yes by everyone.
- Verifiable: For the last ten vendor banking changes, can you produce a record, verifiable by us without access to your systems, showing who authorised each and what they were shown?
The second question has a distribution of answers today, and the distribution is mostly no. That is exactly what makes it useful for pricing.
A sampling protocol at renewal
Underwriters do not have time for deep verification, so the protocol has to be cheap.
- Request five randomly selected authorisation records from the trailing year, for a named high-risk action class.
- Verify the signatures offline using open-source tooling. This takes minutes and requires no access to the insured.
- Record three observations: coverage (what share of that action class carries a record), completeness (do the records render the full instruction detail), and independence (were approvals from distinct credentials).
- Feed those three observations into the rating, alongside everything else.
The measurement design, which is the actual proposal
There is no published evidence that authorisation evidence predicts funds transfer fraud frequency. Claiming otherwise would be inventing data, and this article does not.
What can be designed is the study. A carrier with a book of several thousand commercial policies could:
- Record the three observations above at renewal for two years, without initially using them in pricing.
- Track funds transfer fraud frequency and severity across the cohort.
- Test whether coverage of authorisation evidence correlates with loss experience, controlling for size, sector and prior claims.
- Publish the result either way. A null result is genuinely informative and would end this line of argument.
That is a two-year study with almost no incremental cost, and no carrier has run it.
Why an insured would cooperate
Premium credit is the obvious answer and it is the weakest one, because credits are small and hard to attribute.
The stronger answer is coverage certainty. Funds transfer fraud and social engineering coverage is frequently sub-limited and conditioned on the insured having followed its stated procedures. An insured holding verifiable records of its own authorisations is in a materially better position at claim time than one relying on a callback log — and that is worth more than a rate credit.
Twelve questions worth adding to a proposal form
| Question | Reveals |
|---|---|
| Which actions are in scope, by threshold and trigger? | Whether the scope is defined at all |
| What proportion of in-scope actions carried the control? | The real coverage rate |
| What do the exceptions look like? | Where the residual risk sits |
| Can a third party verify an instance without calling you? | Whether the evidence survives a dispute |
| What is releasable in 24 hours with no human approval? | The maximum single-incident exposure |
Objections and honest limits
“Insureds will not answer these.” Many cannot, which is itself the answer. An insured who can produce a coverage rate and an exception breakdown is demonstrably different from one who ticks a box.
“There is no actuarial basis for pricing this yet.” Correct, and worth saying plainly. These questions build the data that would create one, which is a reason to ask them now rather than a reason to wait.
Adding evidence questions to underwriting
- Ask for scope before asking for compliance. A yes against an undefined scope means nothing.
- Ask for a coverage rate, not a policy. A percentage over twelve months.
- Ask for the exception shape. It is the most informative answer on the form.
- Ask what an adjuster could verify. And whether they would need the insured's cooperation.
Terms used here
- Coverage rate
- The proportion of in-scope actions that actually carried the control over a period.
- Exception shape
- The distribution and reasons for cases where a control was not applied — more informative than the rate itself.
- Warranty
- A policy term the insured promises to maintain, and the basis on which claims are frequently denied.
Frequently asked questions
Are you claiming this reduces loss frequency? No. The article is explicit that the correlation is untested and proposes a study design rather than asserting a finding.
Would underwriters actually verify records? Verification is a signature check using open-source tooling and takes minutes for a sample of five. The barrier is process change, not effort.
What if an insured has no such records? That is a valid answer and it is informative, which is the point. Today every insured answers the equivalent question identically.
Does this create a coverage dispute risk? It should reduce it. Disputes arise where the insured's control representations cannot be evidenced; verifiable records resolve that question before it becomes contested.
Why ask for scope first? Because a yes against an undefined scope is unfalsifiable. Scope is what makes the coverage rate meaningful.
Why is the exception shape so informative? It shows where the residual risk actually sits, and it distinguishes an insured who measures from one who asserts.
Is there actuarial support for pricing this? Not yet. Asking these questions is how the data that would support it gets created.
Where this fits in Manav
Manav binds the authorising person to the exact change, determination or attestation, and produces a receipt a carrier, a regulator or a counterparty can verify without calling the issuer.
Sources and further reading
- FBI IC3 2025 Internet Crime Report
- Published cyber and crime underwriting guidance and application questionnaires.
- NAIC — cyber insurance market report