VaulithNine questions, free
The canon · Security · SEC-1.1

Describe the information security controls applicable to the insurer’s nonpublic information held or processed by the third party.

This is one of the twenty-five questions a carrier reviewer sends a vendor, in the words an examiner uses. Below it: the answers that make a reviewer stop on this item, derived by running Vaulith's rules engine on an estate that gets everything wrong, and the free questions that reach it.

What stops a reviewer here

4 findings reach this item.

Will stop the reviewR-SUBPROCESSOR · degrades this item

No subprocessor or sub-model register

One model (MDL-001 Claims triage) runs on a third-party provider that is not named in any approved record. "A leading commercial provider" is not an answer a reviewer can write down. The carrier has to name every third party in its own examination response, so an unnamed provider makes your gap their finding, and a reviewer who cannot close a question in their own file will stop and ask rather than accept it.

To fix: Name every model provider, hosting region, and data processor that touches insurer data, with contract reference and an accountable owner. A single approved table is enough, as long as it is kept current.

Will escalateR-MFA · degrades this item

Multi-factor authentication is not stated for access to insurer data

You have not said whether multi-factor authentication is enforced for everyone who can reach insurer data. Section 500.12 requires the carrier to have it for any access to nonpublic information, and the carrier cannot answer that question for its own examiner while a vendor holding the same data cannot. A reviewer treats silence here as a no, because every vendor that has it says so in the first sentence.

To fix: Enforce a second factor for every account, including administrators, service accounts that a person can use, and any third party with access. Then say so, with the mechanism named, in the security section of the profile.

Will escalateR-PEN-TEST · degrades this item

No penetration test is on record

There is no penetration test on record, or you have not said when the last one was. Section 500.5 has the carrier test its own systems on a cycle, and the questionnaire asks a vendor for evidence of the same from the last twelve months. A reviewer does not accept a description of the programme in place of the report; they ask for the report, and its date is the first thing they read.

To fix: Commission an external penetration test, keep the report as an evidence record, and attach it here. The report can be redacted; the date, the scope and the summary of findings cannot be.

Will be questionedR-INCIDENT-NOTICE · degrades this item

No incident notification commitment to the insurer is stated

You have not committed to a time within which the insurer is told of a security incident. Section 500.17 gives the carrier seventy-two hours to notify its own regulator, and that clock starts when the carrier learns of the event, not when you do. A reviewer therefore looks for a vendor commitment inside that window, and treats a longer one, or none, as a term to be negotiated before the contract can be signed.

To fix: Commit to notifying the insurer within seventy-two hours or less of discovering an incident that touches their data, write it into the contract and the incident response plan, and record the number here.

How it is scored

Credit per verdict, times the weight.

A standard item carries weight 2. A pass earns 1.00 of it, a questioned answer 0.60, an escalated one 0.20 and a stop 0.00. An unanswered item earns nothing and still takes the citation penalty, so a profile cannot be improved by leaving an inconvenient question blank. The whole arithmetic is shown on the homepage and in every assessment.

Try it in ninety seconds

The free snapshot asks about this.