Awareness of any fact / circumstance reasonably giving rise to a future claim?
This question draws the line between the old policy and the new one. Anything you knew about before binding belongs on the old side of it.
What the carrier is actually asking
The carrier is asking whether anyone in a position of responsibility knows of any fact or circumstance that might reasonably lead to a claim. It is deliberately forward-looking and it captures things that are not yet incidents: an unexplained alert under investigation, a threatening message from a former employee, a vendor breach that may have touched your data, a regulator's enquiry.
Why it is underwritten
Insurance covers fortuity. A circumstance already known when the policy incepts is not fortuitous, so it is excluded, and this question is the mechanism that establishes what was known. Answering yes usually moves that matter to the expiring policy, which is the correct place for it.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is a knowledge question, and the work is asking the right people before answering rather than checking a system.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Open investigations | Security incidents currently under investigation | Anything unresolved at the time of signing, however minor it appears |
| Legal | Demand letters, complaints, regulator correspondence, and threatened litigation | Matters that could develop into a claim, including those counsel considers unlikely |
| Vendors | Third-party breach notifications received | A vendor breach that may have exposed your data is a circumstance even before you know the impact |
| Human resources | Departures involving access disputes or threats | Insider matters, which are frequently known to human resources and nobody else |
| Enquiry record | Who was asked before answering | A documented enquiry across the responsible individuals, which is what makes the answer defensible |
If you become aware of something before the new policy incepts, notify it under the current policy. That is what circumstance notification exists for, and it preserves cover under the policy that was in force when you learned of it. Saying nothing and hoping it does not develop leaves the matter uninsured under both policies.
What a defensible yes requires
- A documented enquiry was made across IT, legal, finance, and human resources before answering.
- Open investigations are disclosed even where the outcome is unknown.
- Third-party breach notifications affecting your data are included.
- Anything disclosed here is also notified to the expiring policy where one exists.
- The answer reflects knowledge at the date of signing, and is refreshed if binding is delayed.
How this answer goes wrong
The security team is investigating unusual authentication activity and has not concluded anything, so the answer is no. That is a circumstance. If it becomes an incident after inception, the carrier will establish that it was known before, and cover for it is likely to fail under both the old policy and the new one.
Frequently asked
How certain does it have to be?
The test is whether a reasonable person would consider it might give rise to a claim. Uncertainty is a reason to disclose, not a reason to omit.
Who is in a position of responsibility?
Usually defined in the policy, and typically covering senior management and those with security or legal responsibility. Ask all of them.
Does disclosing prevent us getting cover?
It usually excludes that specific matter rather than the policy. Excluding one known matter is a far better outcome than a disputed claim later.
What if we learn of something between signing and inception?
Tell the carrier and notify the expiring policy. The duty runs to inception, not to the date you signed the form.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture