Does the Applicant have written information security policy reviewed and updated annually?
The policy itself is rarely read by an underwriter. Its existence, its date, and whether reality matches it are what get examined.
What the carrier is actually asking
The carrier is asking whether a written information security policy exists, whether it is approved at an appropriate level, and whether it is reviewed and updated annually. Some forms ask which framework it aligns to, which is a separate question in the governance section.
Why it is underwritten
The policy is the document that makes every other control attributable to a decision rather than to habit. It also becomes evidence in litigation and regulatory inquiry, where a policy that describes controls the organisation does not operate is worse than no policy at all.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Policy documents live in your governance repository, so this is attested. The technical controls the policy describes are measurable, which is where drift becomes visible.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Policy repository | The policy document, its version, approval, and review date | Approved at management level, reviewed within the last year, with a documented review record. Attested |
| Policy content | Coverage of access control, data handling, incident response, third parties, and acceptable use | The topics the rest of the application asks about are addressed rather than omitted |
| Microsoft 365 | Whether the technical settings match what the policy asserts | Consistency between the stated policy and the configured state, which is where the document either helps or hurts |
| Training records | Policy acknowledgement by workforce | Acknowledgement recorded at onboarding and on material change |
| Exception register | Documented deviations from policy with owners and end dates | Exceptions handled explicitly, since an unrecorded deviation is a policy contradiction |
If the policy says passwords rotate every sixty days and logs are retained for a year, and neither is true, you have documented the gap yourself. Regulators and plaintiffs read policies precisely because they are the organisation's own account of what it should have been doing.
What a defensible yes requires
- The policy is written, approved at management level, and dated within the last year.
- It covers the domains the application asks about.
- It matches what the environment actually does, or the differences are recorded as exceptions.
- The workforce acknowledges it, and the acknowledgement is recorded.
- The review is a real review, with a record of what changed.
How this answer goes wrong
The policy was written for a certification effort three years ago, describes an on-premises estate the organisation has since left, and has been reviewed in name each year without changes. It reads as current and describes a company that no longer exists, which is exactly the document you do not want quoted back to you.
Frequently asked
How long should it be?
Long enough to cover the domains and short enough to be read. A concise policy with supporting standards works better than a single long document nobody opens.
Does a template count?
As a starting point. A template not adapted to your environment produces exactly the mismatch that causes trouble later.
Who should approve it?
Executive management or the board. Approval level is part of what the question is asking, because it establishes that security has ownership above the IT function.
What does annual review mean?
A documented review with a record of what was examined and what changed. A date stamp with no substance is what a claims review will characterise it as.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture