CIOPages
All RFP question modules

Commercial & Legal

Risk, insurance & financial stability questions to ask a software vendor

Questions on whether the vendor can pay if something goes wrong: cyber and professional liability insurance, financial statements and runway, and parent-company backing. Contract indemnities are in Legal, contracting & IP.

97
questions
23
RFI
37
RFP
37
deep-dive

8 questions from the RFI stage, free

These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.

1. State the per-occurrence and aggregate limits of your current cyber-liability insurance policy, and identify the underwriter.

Why it matters. Cyber-liability limits cap the vendor's ability to make the customer whole after a breach, data loss, or AI-mediated security incident. The underwriter's financial-strength rating shows whether the carrier can pay a large claim.

Good answer
  • Specific dollar figures for both per-occurrence and aggregate limits
  • Named underwriter from a recognized carrier (e.g. AIG, Beazley, Chubb, Lloyd's syndicate)
  • Limits proportionate to vendor's customer base and data exposure
Red flags
  • Refusal to disclose limits or underwriter
  • Aggregate limit below the minimum [your organization] sets for vendors processing its sensitive data
  • Coverage placed through an unrated carrier without explanation

2. State the per-claim and aggregate limits of your errors-and-omissions (technology professional liability) insurance, and identify the underwriter.

Why it matters. E&O coverage responds to professional-service failures and defective deliverables, including AI outputs that cause downstream harm. Limits and underwriter quality determine whether the customer can recover for service-quality failures distinct from security breaches.

Good answer
  • Specific per-claim and aggregate limits disclosed
  • Named carrier from a recognized technology E&O market
  • Confirmation that AI service delivery is within the covered scope
Red flags
  • No E&O coverage in force
  • Limits well below the buyer's likely contract value
  • Refusal to disclose underwriter

3. Provide your most recent audited financial statements, or state when audited statements were last produced and by which audit firm.

Why it matters. Audited statements are the baseline disclosure for assessing vendor solvency and going-concern risk. The audit firm's identity lets the buyer check that the auditor is licensed and, for a US public company, registered with the PCAOB.

Good answer
  • Provision of audited statements under NDA, or willingness to do so
  • Audit by a licensed CPA firm, registered with the PCAOB if the vendor is a US public company
  • Audit cadence consistent with company stage (annual for mature; reviewed for earlier-stage)
Red flags
  • Refusal to provide any financial disclosure even under NDA
  • No audited statements have ever been produced for a mature vendor
  • Qualified opinion or going-concern paragraph not proactively disclosed

4. Identify the legal entity that will contract with [your organization], including jurisdiction of incorporation and parent / ultimate holding company.

Why it matters. Contracting entity, not brand, determines who is on the hook for performance and liability. A thinly-capitalized subsidiary contracting under a well-known brand can leave the buyer without practical recovery if something goes wrong.

Good answer
  • Specific entity name, jurisdiction, and parent disclosed
  • Contracting entity is the operating company or parent, not a shell
  • Clear corporate organizational chart available on request
Red flags
  • Contracting entity is a shell with minimal assets
  • Jurisdiction chosen for limited-recourse reasons (e.g. offshore haven without operating substance)
  • Evasion about parent identity

5. Does your cyber-liability policy explicitly cover incidents arising from AI/ML model behavior, including hallucinated outputs, prompt-injection exploits, and training-data contamination?

Why it matters. Cyber policies may exclude algorithmic or model-behavior incidents, or say nothing about them. Buyers need to know whether AI-specific harms are within the covered scope or carved out.

Good answer
  • Explicit confirmation that AI/ML incidents are covered
  • Reference to specific endorsements or AI-coverage riders
  • Acknowledgment of indirect / cross-channel prompt-injection scenarios
Red flags
  • Uncertainty about whether AI incidents are covered
  • Blanket statement that 'all cyber events are covered' without specifics
  • Explicit AI exclusion in the policy

6. Does your E&O policy explicitly cover claims arising from incorrect, biased, or hallucinated AI model outputs delivered to customers?

Why it matters. Standard tech E&O wordings may not clearly respond to AI output failures, leaving a coverage gap on the failure mode most specific to AI tooling. Explicit confirmation prevents the vendor from later disclaiming coverage when an AI output causes customer harm.

Good answer
  • Explicit yes with reference to specific policy language or endorsement
  • Acknowledgment that AI output quality is a covered service obligation
  • No exclusion for algorithmic decisions or model outputs
Red flags
  • Policy excludes algorithmic or automated decision-making
  • Vague 'professional services are covered' answer without addressing AI specifically
  • Uncertainty about how the carrier would treat such a claim

7. State your current cash position and estimated runway at present burn rate, or confirm that you are operating-cash-flow positive on a sustained basis.

Why it matters. Runway and cash-flow status show near-term solvency risk for venture-funded vendors and operating durability for mature ones. Buyers need this to assess the risk of vendor failure during the contract term.

Good answer
  • Specific runway figure (months) or confirmation of sustained operating-cash-flow positivity
  • Disclosure of last fundraising round and date
  • Context on path to profitability if not yet profitable
Red flags
  • Refusal to disclose runway
  • Runway shorter than the proposed contract term without committed financing
  • Evasive framing such as 'well-capitalized' without numbers

8. Confirm whether the contracting entity has its own insurance policies or relies on group / parent-level coverage, and identify which.

Why it matters. Group-level policies may exclude or sublimit coverage for individual subsidiaries, and named insured status affects claim mechanics. Buyers need to know whose policies actually respond when an incident affects the contracting entity.

Good answer
  • Clear identification of named insured(s)
  • Confirmation that the contracting entity is a named insured on group policies
  • Disclosure of any insured-versus-insured exclusions
Red flags
  • Contracting entity is not a named insured on relied-upon policies
  • Group policy excludes the contracting entity's jurisdiction or activities
  • Inability to identify the named insured

The full set: 97 questions in a scored Excel workbook

  • RFI, RFP and deep-dive sheets, with an evaluator guide on every question
  • A 0–5 score column, suggested weights and a scorecard that totals by depth and section
  • An RFP cover template in Word
  • An audit log of all 178 changes made to the draft

Consultancy License $399, for use with any number of clients.

What the module covers

  • Cyber-liability insurance coverage & limits (24)
  • Errors & omissions / professional-liability coverage (22)
  • Financial strength & audited disclosures (33)
  • Parent / holding company backing & guarantees (18)

What the audit changed

A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 178 changes. Three examples:

Wrong or outdated citation

Draft: Coverage placed through an unrated or offshore carrier without explanation

Now: Coverage placed through an unrated carrier without explanation

Alien (non-US) surplus-lines insurers, including the Lloyd's syndicates this question lists as a good answer, are a lawful part of the US cyber market; NAIC's 2025 Report on the Cybersecurity Insurance Market counts alien surplus lines in its premium totals (https://content.naic.org/sites/default/files/inline-files/2025_Cybersecurity_Insurance%20Report.pdf). The rating is the solvency signal, as in pass 1's edit to deep-dive.009.

Wrong or outdated citation

Draft: Deflection to general E&O coverage without confirming cyber overlap

Now: Answer names neither the cyber nor the E&O policy as responding to AI-output claims

Cyber policies cover security and privacy events. Claims over wrong or hallucinated outputs are professional-liability (tech E&O) exposures, so pointing to E&O for them is a correct answer, not a deflection. E&O output coverage is asked in rfi.007.

Wrong or outdated citation

Draft: Claims-made policies only respond to claims first made during the policy period and after the retroactive date, creating gaps if coverage lapses or the retroactive date is recent.

Now: Claims-made policies respond only to claims first made during the policy period for wrongful acts committed on or after the retroactive date, creating gaps if coverage lapses or the retroactive date is recent.

Claims-made policies respond to claims first made during the policy period (or an extended reporting period) for wrongful acts committed on or after the retroactive date. The retroactive date applies to the act, not to when the claim is made.

Questions about this module

How many risk, insurance & financial stability questions are there?

97: 23 for the RFI stage, 37 for the RFP and 37 deep-dive questions for the finalists.

What comes with each question?

Why it matters, what a good answer looks like, the red flags, follow-up questions, the response format, whether most buyers treat it as mandatory, and a suggested weight for scoring.

Were the questions checked?

A language model drafted them and a second model critiqued them. Three audit passes followed (2026-10-05) and made 178 changes, each listed in the workbook with the old and new text. No named subject-matter expert wrote them.

Related