Cyber Insurance Application Scannermap an application to controls

How to answer the funds-transfer verification question

The funds-transfer question is tied to the largest share of cyber claims, so a wrong answer is costly. This page lists every funds-transfer, dual-control and payment-change question in the held carrier documents, the ISO 27001:2022, SOC 2 and NIST CSF 2.0 controls each one reaches, and the evidence to have on file. It is drawn only from the held applications and the held control text.

The evidence that answers this question is the bank or treasury platform dual-authorisation setup and the payee-change verification, not an IT segregation-of-duties matrix on its own. An applicant can hold a duties matrix and still let one person release a payment.

What to have on file before you answer Yes

Where a form offers a partial option (for example Sometimes), it tells the carrier the control is partial; answer it as it is rather than rounding up. Whether an applicant is offered cover stays the carrier's underwriting decision.

The held funds-transfer questions, mapped

Does Named Insured require dual control when transferring funds in excess of $25,000? Answer options on this form: No / Yes.
Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?
Is approval by more than one person required to initiate a wire transfer?
When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?
Does your organization send and/or receive wire transfers?
Tokio Marine HCC its held application
If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?
Tokio Marine HCC its held application
(2) A protocol for obtaining proper written authorization for wire transfers?
Tokio Marine HCC its held application
(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?
Tokio Marine HCC its held application
Does the Applicant employ a protocol to confirm transfer instructions including a call back, email or an alternative method of authenticating the instruction?
AXIS Insurance its held application
Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?
Prior to executing an electronic payment, does the applicant verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?
Prior to executing an electronic payment, do you verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?
Corvus Insurance its held application
Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?
Cowbell Cyber its held application
Does the organization prevent unauthorized employees from initiating wire transfers?
Cowbell Cyber its held application
ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?
Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?
The Hanover Insurance Group its held application
Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?
The Hanover Insurance Group its held application
web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?
Does any applicant accept fund transfer requests from customers?
If yes, is the funds transfer instruction validated by a method other than the original means of request?
Does your organization send and/or receive wire transfers?
Encore Fiduciary its held application
If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?
Encore Fiduciary its held application
(2) A protocol for obtaining proper written authorization for wire transfers?
Encore Fiduciary its held application
(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?
Encore Fiduciary its held application
Do you ensure multi-factor authentication for any fund transfer?

Map your own answers in the tool. The other worked answer is what counts as MFA on an application.