Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. A company discovers on a Sunday evening that a customer database has been exfiltrated. The theft actually happened three weeks earlier. When does the GDPR's seventy-two hour clock start?
From the moment the controller became aware of it
Article 33 of the GDPR requires a controller to notify a breach likely to result in a risk to the rights and freedoms of individuals to the competent supervisory authority, in France the CNIL, within seventy-two hours of becoming aware of it. The clock therefore starts at awareness, not at occurrence: an intrusion three weeks old and discovered on a Sunday evening starts the countdown that Sunday evening. Two practical consequences bite. The first is that working days play no part in the calculation: the weekend counts, and the deadline falls on Wednesday evening. The second is that you must notify before you know everything, since seventy-two hours almost never suffice to establish the exact scope of an exfiltration; the regulation accepts this and allows notification in stages. Where the breach carries a high risk, article 34 adds informing the individuals concerned without undue delay, a separate obligation rather than an automatic consequence of the first.
Glossary entry · notification-violation-donnees2. What is the GDPR's maximum penalty for the most serious infringements?
4 percent of worldwide annual turnover, or 20 million euros if that is higher
The General Data Protection Regulation, applicable since May 2018, governs the processing of personal data through principles, lawfulness, minimisation, purpose limitation, security, and through rights for individuals, access, rectification, erasure, portability. What changed corporate behaviour was none of those principles but the scale of the penalties: up to four percent of worldwide annual turnover, or twenty million euros if that is greater, for the most serious infringements. Two details of that formula matter. The figure is worldwide, not European, which changes everything for a group whose Union activity is a minor share. And the higher of the two amounts applies, so a small company is not protected by its size. That is what moves compliance risk into the category of exposures an insurer must assess, on the same footing as a loss.
Glossary entry · rgpd3. A French life insurer has applied DORA since January 2025. It has mapped its forty-two IT providers and identified two critical cloud suppliers. What does this regulation add that earlier frameworks did not?
Control of the risk from critical third-party providers
The Digital Operational Resilience Act, applicable since January 2025, targets the digital operational resilience of the financial sector, banks, insurers, asset managers and associated providers. It covers IT risk governance, incident detection and handling, reporting to authorities, and resilience testing including advanced penetration tests. Most of those requirements already existed, scattered across sectoral texts and national guidance. What the regulation genuinely adds lies elsewhere and is structural: control of the risk from critical third-party providers, with an oversight regime reaching the large infrastructure suppliers directly. It is the legal recognition of something loss experience had established first: an insurer's resilience no longer depends on its own systems alone, but on two or three suppliers the whole market shares, which shifts the risk from individual outage to sector-wide accumulation.
Glossary entry · dora4. The NIS2 Directive succeeds the first network and information systems security directive. Which of its novelties engages the management of covered entities personally?
Liability of senior management for non-compliance
NIS2 greatly widens the scope of the original text, covering a broad range of sectors deemed essential or important, energy, transport, health, digital infrastructure, public administration, manufacturing and others, and requires those entities to manage cybersecurity risk, apply minimum technical and organisational measures, and report incidents. The widened scope is what gets discussed, but it is not what changes behaviour. The real lever is management liability, senior managers being answerable for non-compliance: cybersecurity stops being a matter delegated to a technical department and becomes a board subject, with personal consequences. For an insurer that shift reads directly into two covers, directors and officers on one side and cyber on the other, whose underwriting questionnaires now ask whether a compliance plan exists.
Glossary entry · nis25. Under NIS2, a large city authority is designated an essential entity and a mid-sized regional hospital an important entity. What actually separates the two regimes?
The supervision model: proactive and continuous for one, triggered after an incident for the other
NIS2 distinguishes two categories of entity by size, sector and criticality to the economy and society. Essential entities are generally the large organisations in the most sensitive sectors, energy, transport, health, water, public administration, digital infrastructure. Important entities cover a wider but less critical perimeter. The difference that matters is not in the substantive obligations, which are largely common, but in how the national authority verifies them: essential entities face ex ante supervision, proactive and continuous, the authority being free to audit with no incident whatsoever, while important entities are supervised ex post, on a report or an incident. Put plainly, an essential entity must be able to prove compliance at any moment; an important entity must be able to prove it on the day something happens.
Glossary entry · entite-essentielle-importante6. Solvency II sets two regulatory capital thresholds. Which one, if breached, can lead the supervisor to withdraw the licence?
The MCR, Minimum Capital Requirement
Solvency II is the European prudential framework for insurers and reinsurers, in force since January 2016 through the transposition of directive 2009/138/EC, built on three pillars: quantitative requirements, qualitative governance requirements, and disclosure. The first pillar carries the two thresholds that must not be confused. The SCR is the own funds figure matching the capacity to absorb a one-in-two-hundred-year shock; falling below it triggers a recovery plan and close supervision, but the company continues to exist. The MCR is the absolute floor, and it is the one that brings withdrawal of the licence, that is, the end of the business. The distinction is therefore between a warning and leaving the road. The second pillar also explains why a cyber book concentrated on a single infrastructure provider pushes the SCR up: the model must reflect correlation between losses in a common outage, where a genuinely diversified book earns the benefit of pooling.
Glossary entry · solvabilite-ii7. An insurer deploys an artificial intelligence model for pricing. How does the EU AI Act classify that use, and what follows from it?
High risk, with data documentation, no prohibited discrimination and effective human oversight
The EU AI Act is the first comprehensive regulatory framework for artificial intelligence, applying in stages from 2025 and 2026. Its logic is a risk-tier approach, and that is what to retain rather than a list of articles: uses deemed unacceptable, such as certain forms of social scoring, are banned; high-risk uses, among them recruitment, credit, insurance and critical infrastructure, face strict requirements; the rest carry much lighter transparency duties. Insurance pricing belongs to the second category, which brings three concrete obligations: documenting training datasets, demonstrating the absence of prohibited discrimination, and guaranteeing effective human oversight of decisions. The word effective carries the weight, because oversight that merely rubber-stamps the model's output satisfies the form while intercepting nothing.
Glossary entry · eu-ai-act8. A French insurer departs from Solvency II requirements. Which authority can require it to strengthen its own funds or its governance?
The ACPR, the French prudential supervision and resolution authority
Prudential supervision of a European insurer remains national, and that is the point the existence of a European authority most often obscures. The Autorité de contrôle prudentiel et de résolution, attached to the Banque de France, supervises banking and insurance in France: it authorises firms, oversees solvency requirements, policyholder protection, governance quality and risk management, carries out desk-based and on-site inspections, and can impose sanctions. EIOPA, created in 2011 after the financial crisis, does not supervise insurers directly: it drafts technical standards, guidelines and conventions that harmonise the application of Solvency II across member states, and runs European-level stress tests. The division is therefore clean and worth holding: the European body writes and harmonises, the national one authorises, inspects and sanctions.
Glossary entry · acpr9. A cyber underwriter finds that a prospect is not ISO 27001 certified. What does that mean for how the file is examined?
The file remains admissible, but the audit of existing controls goes deeper
ISO/IEC 27001 is the international standard for information security management systems, revised in 2022. It sets out what an organisation must satisfy to establish, implement, maintain and improve a structured set of policies, procedures and controls protecting the confidentiality, integrity and availability of information, on a risk-based approach where the organisation identifies its assets and assesses its threats. What matters from an underwriting standpoint is that certification does not measure a level of security, it attests to the existence of a management system and to its verification by a third party. It therefore stands as a presumption of maturity and as saved work for the underwriter, not as a guarantee that nothing will happen. Its absence disqualifies nobody: it shifts the workload, since controls must then be checked one by one instead of leaning on an audit already done, and many very secure organisations are not certified, having had no commercial reason to be.
Glossary entry · iso-27001