8 questions from the RFI stage, free
These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.
1. State the per-occurrence and aggregate limits of your current cyber-liability insurance policy, and identify the underwriter.
Why it matters. Cyber-liability limits cap the vendor's ability to make the customer whole after a breach, data loss, or AI-mediated security incident. The underwriter's financial-strength rating shows whether the carrier can pay a large claim.
- Specific dollar figures for both per-occurrence and aggregate limits
- Named underwriter from a recognized carrier (e.g. AIG, Beazley, Chubb, Lloyd's syndicate)
- Limits proportionate to vendor's customer base and data exposure
- Refusal to disclose limits or underwriter
- Aggregate limit below the minimum [your organization] sets for vendors processing its sensitive data
- Coverage placed through an unrated carrier without explanation
2. State the per-claim and aggregate limits of your errors-and-omissions (technology professional liability) insurance, and identify the underwriter.
Why it matters. E&O coverage responds to professional-service failures and defective deliverables, including AI outputs that cause downstream harm. Limits and underwriter quality determine whether the customer can recover for service-quality failures distinct from security breaches.
- Specific per-claim and aggregate limits disclosed
- Named carrier from a recognized technology E&O market
- Confirmation that AI service delivery is within the covered scope
- No E&O coverage in force
- Limits well below the buyer's likely contract value
- Refusal to disclose underwriter
3. Provide your most recent audited financial statements, or state when audited statements were last produced and by which audit firm.
Why it matters. Audited statements are the baseline disclosure for assessing vendor solvency and going-concern risk. The audit firm's identity lets the buyer check that the auditor is licensed and, for a US public company, registered with the PCAOB.
- Provision of audited statements under NDA, or willingness to do so
- Audit by a licensed CPA firm, registered with the PCAOB if the vendor is a US public company
- Audit cadence consistent with company stage (annual for mature; reviewed for earlier-stage)
- Refusal to provide any financial disclosure even under NDA
- No audited statements have ever been produced for a mature vendor
- Qualified opinion or going-concern paragraph not proactively disclosed
4. Identify the legal entity that will contract with [your organization], including jurisdiction of incorporation and parent / ultimate holding company.
Why it matters. Contracting entity, not brand, determines who is on the hook for performance and liability. A thinly-capitalized subsidiary contracting under a well-known brand can leave the buyer without practical recovery if something goes wrong.
- Specific entity name, jurisdiction, and parent disclosed
- Contracting entity is the operating company or parent, not a shell
- Clear corporate organizational chart available on request
- Contracting entity is a shell with minimal assets
- Jurisdiction chosen for limited-recourse reasons (e.g. offshore haven without operating substance)
- Evasion about parent identity
5. Does your cyber-liability policy explicitly cover incidents arising from AI/ML model behavior, including hallucinated outputs, prompt-injection exploits, and training-data contamination?
Why it matters. Cyber policies may exclude algorithmic or model-behavior incidents, or say nothing about them. Buyers need to know whether AI-specific harms are within the covered scope or carved out.
- Explicit confirmation that AI/ML incidents are covered
- Reference to specific endorsements or AI-coverage riders
- Acknowledgment of indirect / cross-channel prompt-injection scenarios
- Uncertainty about whether AI incidents are covered
- Blanket statement that 'all cyber events are covered' without specifics
- Explicit AI exclusion in the policy
6. Does your E&O policy explicitly cover claims arising from incorrect, biased, or hallucinated AI model outputs delivered to customers?
Why it matters. Standard tech E&O wordings may not clearly respond to AI output failures, leaving a coverage gap on the failure mode most specific to AI tooling. Explicit confirmation prevents the vendor from later disclaiming coverage when an AI output causes customer harm.
- Explicit yes with reference to specific policy language or endorsement
- Acknowledgment that AI output quality is a covered service obligation
- No exclusion for algorithmic decisions or model outputs
- Policy excludes algorithmic or automated decision-making
- Vague 'professional services are covered' answer without addressing AI specifically
- Uncertainty about how the carrier would treat such a claim
7. State your current cash position and estimated runway at present burn rate, or confirm that you are operating-cash-flow positive on a sustained basis.
Why it matters. Runway and cash-flow status show near-term solvency risk for venture-funded vendors and operating durability for mature ones. Buyers need this to assess the risk of vendor failure during the contract term.
- Specific runway figure (months) or confirmation of sustained operating-cash-flow positivity
- Disclosure of last fundraising round and date
- Context on path to profitability if not yet profitable
- Refusal to disclose runway
- Runway shorter than the proposed contract term without committed financing
- Evasive framing such as 'well-capitalized' without numbers
8. Confirm whether the contracting entity has its own insurance policies or relies on group / parent-level coverage, and identify which.
Why it matters. Group-level policies may exclude or sublimit coverage for individual subsidiaries, and named insured status affects claim mechanics. Buyers need to know whose policies actually respond when an incident affects the contracting entity.
- Clear identification of named insured(s)
- Confirmation that the contracting entity is a named insured on group policies
- Disclosure of any insured-versus-insured exclusions
- Contracting entity is not a named insured on relied-upon policies
- Group policy excludes the contracting entity's jurisdiction or activities
- Inability to identify the named insured
What the audit changed
A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 178 changes. Three examples:
Wrong or outdated citation
Draft: Coverage placed through an unrated or offshore carrier without explanation
Now: Coverage placed through an unrated carrier without explanation
Alien (non-US) surplus-lines insurers, including the Lloyd's syndicates this question lists as a good answer, are a lawful part of the US cyber market; NAIC's 2025 Report on the Cybersecurity Insurance Market counts alien surplus lines in its premium totals (https://content.naic.org/sites/default/files/inline-files/2025_Cybersecurity_Insurance%20Report.pdf). The rating is the solvency signal, as in pass 1's edit to deep-dive.009.
Wrong or outdated citation
Draft: Deflection to general E&O coverage without confirming cyber overlap
Now: Answer names neither the cyber nor the E&O policy as responding to AI-output claims
Cyber policies cover security and privacy events. Claims over wrong or hallucinated outputs are professional-liability (tech E&O) exposures, so pointing to E&O for them is a correct answer, not a deflection. E&O output coverage is asked in rfi.007.
Wrong or outdated citation
Draft: Claims-made policies only respond to claims first made during the policy period and after the retroactive date, creating gaps if coverage lapses or the retroactive date is recent.
Now: Claims-made policies respond only to claims first made during the policy period for wrongful acts committed on or after the retroactive date, creating gaps if coverage lapses or the retroactive date is recent.
Claims-made policies respond to claims first made during the policy period (or an extended reporting period) for wrongful acts committed on or after the retroactive date. The retroactive date applies to the act, not to when the claim is made.