Financial Services2 min read

One Evidence Set for the Examiner, the Carrier and the Client

Financial firms answer the same security questions three times a year to three different audiences. Maintaining one current evidence set instead of three narratives is the difference.

In a given year a mid-sized financial services firm will describe its security posture to a regulator, to a cyber insurance underwriter, and to at least one institutional client's vendor risk team. Three audiences, three formats, three deadlines, and in most firms three separate scrambles.

The questions barely differ. What differs is the wording and the consequence of getting it wrong.

Three audiences, one underlying question

The examiner wants to know whether you have a programme: written policies, a named owner, evidence that the controls you describe actually operate, and a record of what you did about the last set of findings.

The underwriter wants to know your exposure: multi-factor authentication coverage, backup and recovery arrangements, endpoint controls, email security, and whether you have had an incident.

The institutional client wants to know whether you are a risk to them: access controls, encryption, incident response, subcontractors, and business continuity.

Underneath all three is the same set of facts. Firms that treat them as three separate exercises answer from three different sources, and the answers drift.

Drift is the actual risk

A firm tells its insurer that multi-factor authentication is enforced everywhere. Six months later the examiner's sample finds four service accounts that bypass it. Nine months after that there is a claim.

Nobody lied. The application was completed by the operations lead using what was true for staff email. The exception was created by a vendor integration eighteen months earlier and was never in anybody's mental model. But the insurer's claim investigation will not read it that way, and the coverage argument that follows will be expensive whether or not it succeeds.

The same drift in front of an examiner produces a finding. The same drift in front of a client produces a contract that does not renew.

What one evidence set looks like

It is not a binder. It is a small number of maintained artefacts with dates and owners:

An asset and data inventory. What systems exist, what they hold, who the vendor is, and which of them touch client information.

A control register. Each control, whether it is fully in place, partially in place or absent, who owns it, and what the evidence is. Partial is a legitimate state and should be recorded as one.

A risk register. What is not fixed, what the exposure is, who accepted it, and when it is reviewed next.

A vendor register. Who you rely on, what they see, what the contract says, and when it renews.

An incident response plan that names people and works at 2am.

Evidence of operation. Training records, access review dates, restore tests, phishing simulation results. This is the part firms most often lack, and the part every audience asks for.

Every question from every audience maps onto that. The mapping takes an afternoon. Building the evidence from scratch under a deadline takes a quarter and produces worse answers.

Who owns it

The most common failure is not the absence of documents but the absence of an owner. Compliance owns the regulatory answer, operations owns the insurance form, the relationship partner owns the client questionnaire, and no single person is accountable for the underlying facts being true and current.

That is a governance problem, not a technology problem, and it is solved by naming somebody.