A provider can explain the systems it manages, and an internal team can contribute records of its own. The person coordinating the application needs to know which answer came from which source and what has actually been examined.
Start with the application and its instructions
Confirm the version, submission deadline and signature requirements. Keep the insurer's or broker's clarification with the application. Do not assume the form, signatory or requirements match a previous year or another organization's policy.
The Canadian BOXX application linked below illustrates control questions and an authorized-representative declaration. It is one example, not a universal checklist or an Ontario-specific rule. Questions about disclosure duties, contractual consequences or coverage belong with the insurer or broker and your appropriate advisers.
Separate reported answers from examined evidence
| Question area | Evidence to examine | Limit to record |
|---|---|---|
| MFA | Applicable policies, assignments, exceptions and relevant sign-in evidence | Registration or capability alone does not establish enforcement. |
| Recovery | Job results, selected recovery tests and remaining dependencies | A tested file or system does not establish every recovery scenario. |
| Backup protection | Storage, permissions, retention and protection configuration | One setting alone does not establish protection against every deletion path. |
| Privileged access | Roles, purposes, responsible owners and review records | Distinguish ordinary, service and emergency accounts. |
| Endpoint protection | Device inventory reconciled with coverage and agent health | Define the population before interpreting a percentage. |
| Training | Assignment and completion records for the relevant period | Completion is different from demonstrated behavior in an incident. |
Microsoft's reporting documentation distinguishes MFA registration/capability from usage and describes limits to its reports. Ask a qualified administrator to explain which views and policy evidence address the application question.
An exception list is information to examine. Its length alone does not make the configuration acceptable or unacceptable. Ask how each exception affects the stated answer and how the insurer wants it disclosed.
A review sequence before submission
- Identify the technical owner and authorized signatory under the application's instructions.
- For each answer, record its source, scope, date and any exceptions.
- Separate verified observations from reported claims and missing evidence.
- Resolve unclear question wording with the insurer or broker rather than guessing yes or no.
- Keep the submitted version and supporting records, and agree how relevant changes will be reviewed.
Plan backwards from the actual deadline and the work needed to resolve questions. There is no universal lead time that fits every application. If the deadline is close, discuss unresolved items promptly with the responsible parties.
When an independent examination can help
Provider and internal records can be useful evidence. An independent reviewer can examine selected records and configurations within an agreed scope, explain findings and identify what remains unverified. Independence alone does not make a report acceptable to an insurer.
Discuss cybersecurity verification if you need that external view. Confirm the intended use and any reader requirements before commissioning it. Implementation remains with your internal team or appointed provider.
For examples of evidence organization, read the insurance evidence guide. For a broader service question, use evaluating your IT provider and the ten-question checklist.
