Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. The characteristic defect of a cyber questionnaire is almost never a lie. What is it, and why does good faith not help?
A word taken for another: the person answering thinks of the scope they have in mind, the insurer reads the question as written, and between the two sits a real estate of systems. Nobody lied and the disclosure is false
A company disclosing deployed authentication is thinking of its project, its servers, the decision taken in committee; the insurer reads full coverage of all remote access. It is a scope gap between two honest readings, and that is what makes it so hard to prevent. The three other answers describe real defects, all rare beside that one. Deliberate omission presupposes intent and falls under another, far harsher regime. Carrying over last year's questionnaire is a genuine risk, handled elsewhere in the module under ageing. The signatory's incompetence misses: whoever answers is almost always competent on THEIR scope, and that is exactly why they answer with confidence.
Glossary entry · declaration-de-risque2. The questionnaire arrives via the broker, passes to finance, and IT answers in good faith on its own scope. Where is the organizational problem?
An inaccurate disclosure binds the company and not the engineer who ticked the box: each technical answer must be validated by someone able to DEMONSTRATE it, and that validation kept on record
The document's route separates whoever answers from whoever is bound, and that is the one organizational point that decides the rest. The half day of validation is worth the size of the claim. The answer on finance's standing invents a formal defect, when a company's internal routing is no concern of the insurer's. The one on broker liability shifts the burden to a third party whose liability may exist separately, and which never discharges the insured's own disclosure. The one refusing to answer is the most tempting for an honest technician, and it is unworkable: the questionnaire is the basis of the contract, not filling it in yields no policy.
Glossary entry · bonne-foi3. An insured sincerely ticks a box in January. In June, its provider disables the measure to fix an application. What decides its position?
Whether the contract took that answer as a DISCLOSURE or as a CONDITION: the first describes a state at inception, the second imposes a state throughout. It honored its disclosure and breached its condition
The distinction is invisible on a quick read and changes everything, because it moves from a proportional reduction to an unmet condition. That is why the first useful step is to spot, among the forty answers, those the contract restates as conditions. The answer on thirty days invents a threshold. The one invoking the provider's act describes a fairness intuition and misses that the insured answers for its system, providers included, which is precisely why these clauses exist. The one keeping only causation sets the wording aside, when the wording decides the regime before the link is even examined.
Glossary entry · clause-exclusion4. The module asks to translate the ambiguous words, deployed, up to date, backed up. Into what, and what does that produce at the insurer?
Into a percentage of the estate and a named scope rather than a yes or a no: an insurer receiving 780 accounts out of 1,300 and the list of exceptions prices it or sets an explicit condition, instead of discovering at claim time
A figure and a scope remove the gap between two honest readings, and they give the insurer what it needs to decide knowingly, which is exactly what the company has an interest in giving it. The answer on the framework swaps one ambiguity for another, since a framework measures conformity and not scope. The one on dated commitments describes a useful practice and turns it into an answer to the questionnaire: that is a negotiation, not a disclosure, and it comes later. The one advising a cautious no looks safe and costs in both directions: it pays premium for a risk not carried, and it is no truer than the yes.
Glossary entry · tarification-exposition5. Many policies require material changes to be reported during the year. Nobody does it. What rule makes the obligation workable?
Whatever would have changed an answer on the questionnaire is reported, and nothing else: the rule gives an operational test where the word material gives none
The obligation stays a dead letter because nobody knows what material means, and the questionnaire supplies the missing definition: it already carries the forty points the insurer considers decisive. The answer limited to acquisitions keeps the most visible example and leaves out a migration, a replaced provider, an application opened for remote work. The one deferring to the board confuses a decision's strategic weight with its effect on risk, and many of these changes never reach the board. The one reporting everything makes the obligation unworkable by excess and produces the same result as silence.
Glossary entry · declaration-de-risque