Business and financial profile

How many records of PII / PHI / PCI / biometric does Applicant process?

Notification cost scales with records, not with revenue. This number is the best predictor of what a breach would cost you.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier wants the volume of regulated records you hold or process, broken down by type where the form allows. It is the direct input to modelling the notification and credit monitoring exposure.

Why it is underwritten

Per-record response costs are reasonably predictable, so the record count multiplied by a per-record figure gives a first-order estimate of a breach. That estimate drives limit adequacy. An understated count produces a limit that looks adequate and is not.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Record volumes in the platforms Insurance Posture reads are partly discoverable, which helps ground an estimate that is otherwise guesswork.

PlatformWhere the setting livesWhat has to be true
DatabasesRow counts in systems holding personal dataThe structured footprint, including historical and archived records
Microsoft 365Content discovery for sensitive information typesThe unstructured footprint in mail and collaboration, which is routinely omitted from estimates
AzureStorage and database inventory with data classificationCloud data stores including backups and reporting copies
RetentionHow long records are keptWhether historical records could have been deleted, since retained data is exposure
MethodHow the estimate was producedA stated method, which is what makes an approximation defensible
Deleted records cannot be breached

The fastest way to reduce this number is retention enforcement. Most organisations hold years of records they have no reason to keep, and every one of them is inside the notification population. Deletion is the only control that reduces exposure to zero.

What a defensible yes requires

  • The estimate covers structured and unstructured data.
  • Historical, archived, and backup copies are included.
  • The method is stated and repeatable.
  • Types are separated, since health and payment records cost differently from general personal data.
  • Retention enforcement is in place so the number falls rather than grows.

How this answer goes wrong

The count comes from the active customer table, excluding a decade of historical records, the reporting copy, and the exports in mailboxes. A breach reaches all of them, and the limit was sized against a fraction.

Frequently asked

How precise must this be?

An order of magnitude with a stated method. Precision is impossible and a defensible method is not.

Do employee records count?

Yes, and they are commonly omitted. Human resources records are personal data and often include health information.

Should we count records we process for clients?

Yes, with the distinction noted. Processor obligations differ from controller obligations, and the records are still in scope of an incident.

How does this affect our limit?

Directly. Multiply the count by a per-record response cost and compare it to the limit. The comparison is often uncomfortable and always useful.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture