Home/Questions/Business and financial profile/High-risk business classes
Business and financial profile

Is the Applicant engaged in adult content, cryptocurrency, gambling, payment processing, or MSP/MSSP business?

These categories are listed together because most markets have restricted appetite for each of them, for different reasons.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether you operate in a set of classes it treats as elevated risk: adult content, cryptocurrency, gambling, payment processing, and managed service provision. Each is on the list for its own reason.

Why it is underwritten

Cryptocurrency businesses hold directly stealable assets. Payment processors hold concentrated card data. Managed service providers carry correlated exposure across their clients. Gambling and adult content attract targeted attacks and regulatory complexity. Carriers manage appetite by class before considering controls.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is a disclosure about your activities and it should reflect what you actually do rather than how you describe yourself.

PlatformWhere the setting livesWhat has to be true
OperationsRevenue by activity against the listed categoriesAn honest mapping, including secondary activities. Attested
ServicesWhether you manage IT for third partiesManaged service provision includes arrangements you might not label as such, including managing systems for affiliates
PaymentsWhether you process payments on behalf of othersPayment facilitation, which is different from accepting payments for your own goods
AssetsCryptocurrency held, accepted, or custodiedAny digital asset activity, including accepting it as payment
TrajectoryPlanned entry into any of these areasDisclosed, since a mid-term change in operations is usually disclosable
Managed service is the one people miss

Organisations that manage IT for affiliates, franchisees, or a handful of clients as a sideline frequently answer no. If you hold administrative access to systems you do not own, carriers treat you as a service provider, and the underwriting changes accordingly.

What a defensible yes requires

  • Each category is considered against what you actually do rather than your self-description.
  • Secondary and incidental activities are included.
  • Managed service work is disclosed even where it is a small part of the business.
  • Digital asset activity is disclosed including acceptance as payment.
  • Planned entry into these areas is mentioned.

How this answer goes wrong

A technology company that manages infrastructure for three long-standing clients answers no because it does not call itself a managed service provider. If a client incident produces a claim, the undisclosed activity becomes the material fact.

Frequently asked

Does a yes make us uninsurable?

No, and it narrows the market. Specialist capacity exists for each of these categories, and it is better reached through accurate disclosure than discovered after a decline.

Are we an MSP if we manage a few clients?

Probably, for underwriting purposes. Holding administrative access to systems you do not own is the test that matters.

Does accepting crypto count?

Usually yes. Disclose it with the volume and how it is held, since custody is the part carriers care about.

What if we plan to enter one of these areas?

Mention it. Material changes in operations are usually disclosable during the policy period.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture