Skip to content

Evidence request lists

Lloyd's of London Cyber Insurance Requirements and Underwriting Standards

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Affirmative Coverage + LMA Model Clauses + March 2023

LLOYDS-CI-Affirmative-Coverage-Property-Cyber-Mandatory-Clarity-LMA-Model-Clauses-March-2023-Implementation
Lloyds Cyber Insurance Affirmative Coverage + LMA Model Clauses + March 2023

Lloyds of London Cyber Insurance Requirements - Affirmative Cyber Coverage Mandate. Following Lloyds Market Bulletin Y5258 (issued 16 August 2022) all Property Policies underwritten by Lloyds market participants must clearly state from 31 March 2023 onwards whether cyber-related losses are covered + excluded + with no implicit ambiguity (silent cyber elimination). Lloyds Market Association (LMA) issued LMA Model Clauses set including: LMA5400 Cyber War and Cyber Operation Exclusion + LMA5401 Cyber War and Cyber Operation Exclusion (No Attribution Required) + LMA5402 Cyber War and Cyber Operation Exclusion with Carve-Backs + LMA5403 Cyber War and Cyber Operation Exclusion with Attribution Bureau + LMA5404 + LMA5405 various carve-backs and definitions. Coverholder + delegated authority business must use compliant LMA model clauses or equivalent + filed with Lloyds Coverholder Services. All

Artefacts an auditor will ask for
  • Property policy wordings post-March 2023
  • LMA5400-5405 model clause incorporation
  • Coverholder binder LMA compliance evidence
  • Lloyds Risk Code CY separation
  • Class of Business Review compliance
Where this commonly fails
  • Property policies still silent
  • Pre-2023 clauses used
  • Coverholder non-compliant
  • Silent cyber unmonitored

Claims + Sanctions + Ransomware Payment + OFAC

LLOYDS-CI-Claims-Handling-Standards-Cyber-Events-Sanctions-Ransomware-Payment-Compliance-OFAC-HMT
Lloyds Cyber Insurance Claims + Sanctions + Ransomware Payment + OFAC

Lloyds Cyber Insurance Requirements - Claims Handling Standards for Cyber Events and Sanctions/Ransomware Compliance. Claims Handling Standards for Cyber Events: (a) Specialised cyber claims handling capability + Lloyds claims handler training in cyber-specific issues + Computer Forensics + Digital Forensics and Incident Response (DFIR) integration + Coalition + Crawford + Sedgwick cyber claims specialists; (b) 24/7 cyber incident response hotline + breach coach lawyer + IR firm appointment (Mandiant + CrowdStrike + Coalition Incident Response + Kroll + Aon Crisis Management + Marsh Cyber); (c) Lloyds Claims Standards alignment + LMG ECF (Electronic Claims File) + IUA (International Underwriting Association) cyber claims handling; (d) Pre-approved vendor panels for forensics + legal + crisis communications + ransomware negotiation + cryptocurrency tracing; (e) Cyber claim severity assess

Artefacts an auditor will ask for
  • Cyber-specialised claims handler evidence
  • 24/7 incident response hotline
  • Pre-approved vendor panels
  • OFAC SDN screening procedure
  • HMT OFSI compliance evidence
  • Ransomware payment decision protocols
  • Cryptocurrency tracing evidence (Chainalysis/Elliptic)
  • Mandatory ransomware reporting compliance
Where this commonly fails
  • No specialised cyber claims
  • No OFAC screening
  • No vendor panels
  • No cryptocurrency tracing
  • No ransomware payment protocol

Conduct + TCF + Silent Cyber + Regulatory

LLOYDS-CI-Conduct-Risk-Treating-Customers-Fairly-Silent-Cyber-Reviews-Regulatory-Notifications-Material
Lloyds Cyber Insurance Conduct + TCF + Silent Cyber + Regulatory Notifications

Lloyds Cyber Insurance Requirements - Conduct Risk, Cross-Class Reviews and Regulatory Notifications. Conduct Risk and Treating Customers Fairly (TCF): (a) FCA Principles for Businesses Principle 6 (TCF) + Principle 7 (Communications) + Principle 8 (Conflicts of Interest) + Principle 9 (Vulnerable Customers); (b) Insurance Conduct of Business Sourcebook (ICOBS) + Insurance Distribution Directive (IDD) + UK Senior Managers and Certification Regime (SM&CR) + Consumer Duty (effective 31 July 2023); (c) Plain English policy wording + cyber-specific terminology glossary + clear communication of exclusions including war + state-backed + retroactive date + sub-limits + sublimits per occurrence + aggregate; (d) Treating Cyber claimants fairly + responsive claims handling + access to specialist resources; (e) Vulnerable customer considerations including SME with limited cyber expertise + protecte

Artefacts an auditor will ask for
  • FCA Principles 6/7/8/9 compliance evidence
  • Consumer Duty 2023 evidence
  • Plain English policy wordings
  • Annual cross-class silent cyber review
  • PRA SS5/14 + SS3/15 notifications
  • FCA Principle 11 evidence
  • SFCR cyber disclosure
  • Bank of England Stress Test cyber participation
Where this commonly fails
  • No Consumer Duty alignment
  • No cross-class review
  • No PRA notifications
  • Silent cyber unresolved
  • No Stress Test participation

Pricing + Rate + Authority + Bordereaux

LLOYDS-CI-Pricing-Rate-Adequacy-Underwriter-Authority-Reference-Limits-Exposure-Data-Bordereaux
Lloyds Cyber Insurance Pricing + Rate Adequacy + Authority + Exposure Data

Lloyds Cyber Insurance Requirements - Pricing, Rate Adequacy and Underwriter Authority. Pricing and Rate Adequacy Monitoring: (a) Risk-based pricing methodology + actuarial loss models + frequency-severity modeling + cyber-specific loss development triangles (long-tail vs short-tail nature of cyber loss) + IBNR reserving + industry-wide cyber loss ratios; (b) Lloyds Pricing Standards aligned with Solvency II + Internal Model + Standard Formula technical provisions + best estimate + risk margin; (c) Cycle Management monitoring (cyber market hard 2020-2022 + softening 2023-2024); (d) Rate Adequacy Monitoring per Lloyds Class of Business Review + benchmarking against industry standards; (e) Reinsurance pricing alignment + retrocession; (f) Capital adequacy linked to cyber portfolio aggregate risk. Underwriter Authority: (a) Tiered underwriting authority limits by referral threshold + Lloyds

Artefacts an auditor will ask for
  • Actuarial loss models
  • Rate Adequacy Monitoring evidence
  • Underwriter authority matrix + referral limits
  • SM&CR SIMF allocation
  • LM TOM Phase 2 Bordereaux Format v3
  • Lloyds Risk Code CY documentation
Where this commonly fails
  • No actuarial methodology
  • No rate monitoring
  • No authority matrix
  • No bordereaux compliance

Reinsurance + Capital + Solvency II + Coverholder

LLOYDS-CI-Reinsurance-Capital-Protection-Solvency-II-ORSA-Coverholder-Delegated-Authority-Cyber-Underwriting
Lloyds Cyber Insurance Reinsurance + Capital + Solvency II + Coverholder

Lloyds Cyber Insurance Requirements - Reinsurance, Capital Protection and Solvency II Alignment. Reinsurance and Capital Protection for Cyber: (a) Cyber-specific retrocession programmes + per-event + aggregate excess of loss + quota share + facultative; (b) Lloyds Reinsurance Programme participation + ABI Cyber Reinsurance Pool consideration + Lloyds-recognised reinsurers (Munich Re + Swiss Re + Hannover Re + Lloyds Reinsurance Syndicates); (c) Industry Loss Warranties (ILW) cyber + parametric cyber covers; (d) Cyber Catastrophe Bond consideration (cyber CAT bond market $1B+ outstanding) + Insurance Linked Securities (ILS) + alternative capital sources; (e) Cyber Retro pricing + capacity constraints; (f) Stop-loss reinsurance with cyber-specific triggers (named cyber event + cyber catastrophe + government attribution). Solvency II and ORSA Alignment for Cyber: (a) Own Risk and Solvency A

Artefacts an auditor will ask for
  • Cyber-specific reinsurance programme
  • ILS/CAT bond evidence
  • ORSA cyber risk section
  • SFCR cyber disclosure
  • Coverholder Cyber Risk Assessment
  • Binder cyber-specific provisions
  • Lloyds Capital Sub-Group cyber assessment
Where this commonly fails
  • No cyber reinsurance
  • No ORSA cyber
  • No coverholder assessment
  • No SFCR cyber

Risk Selection + Cyber Hygiene + Pre-Bind

LLOYDS-CI-Risk-Selection-Cyber-Hygiene-Underwriting-Criteria-Pre-Bind-Risk-Engineering-MFA-Backup-EDR
Lloyds Cyber Insurance Risk Selection + Hygiene + Pre-Bind Engineering

Lloyds Cyber Insurance Requirements - Risk Selection and Cyber Hygiene Underwriting Criteria. Underwriters must conduct rigorous risk selection + due diligence assessing insured-cyber hygiene including: (a) Mandatory cyber hygiene requirements (insurance-grade baseline expectation): Multi-Factor Authentication (MFA) on all privileged accounts + all remote access + email + cloud admin consoles + Endpoint Detection and Response (EDR) on all endpoints + immutable + air-gapped + tested backups + Email Security Gateway + DMARC + SPF + DKIM + Patch SLA Critical 7 days + High 30 days + Vulnerability Disclosure programme + Security Operations Centre (SOC) capability + Incident Response Plan + tabletop exercises + Privileged Access Management (PAM); (b) Additional underwriting criteria for higher coverage: NIST Cybersecurity Framework alignment + ISO 27001 certification + SOC 2 Type II + Penetrat

Artefacts an auditor will ask for
  • Mandatory hygiene requirements documented (MFA + EDR + backups)
  • External attack surface scan reports (Bitsight/SecurityScorecard)
  • Dark web monitoring
  • Industry-specific underwriting criteria
  • SME tiered hygiene
  • Cyber hygiene declarations + warranties
Where this commonly fails
  • No mandatory hygiene
  • No external scan
  • No dark web monitoring
  • No SME tier

Systemic Aggregation + Catastrophe Modelling

LLOYDS-CI-Systemic-Cyber-Risk-Aggregation-Cyber-Catastrophe-Modelling-Vendor-Use-RDS-Scenario-Testing
Lloyds Cyber Insurance Systemic Aggregation + Catastrophe Modelling + RDS

Lloyds Cyber Insurance Requirements - Systemic Cyber Risk Aggregation + Catastrophe Modelling. Lloyds Catastrophe Modelling Standards require all managing agents to: (a) Model Cyber Realistic Disaster Scenarios (Cyber RDS) developed by Lloyds + Cambridge Centre for Risk Studies + Aon + Marsh + Munich Re including: Cyber Cloud Outage (USD 53B industry loss scenario) + Cyber Ransomware Pandemic (USD 193B) + Cyber Data Exfiltration (USD 17B) + Cyber DDoS Wave + Cyber Power Grid Attack + Cyber Industrial Control System; (b) Use Lloyds-approved Catastrophe Models: Verisk Cyber Catastrophe Model + AIR Cyber + RMS Cyber Solutions + CyberCube Industry Exposure Databases + Moodys ESG + Guy Carpenter + (c) Maintain industry-wide concentration risk analysis: cloud provider concentration (AWS + Azure + GCP outage exposure) + software supply chain concentration (Microsoft + Oracle + SAP) + ransomware

Artefacts an auditor will ask for
  • Lloyds Cyber RDS modelling outputs
  • Verisk/AIR/RMS/CyberCube vendor model use
  • PML 1-in-100/200/250/500 analysis
  • Cloud concentration risk analysis
  • Supply chain compromise scenarios
  • Independent PMD validation
Where this commonly fails
  • No Cyber RDS
  • No vendor catastrophe model
  • No PML analysis
  • No concentration analysis

War + State-Backed Exclusions + Attribution

LLOYDS-CI-War-Cyber-Operation-State-Backed-Exclusions-LMA5400-5403-Attribution-Mechanism-Carve-Backs
Lloyds Cyber Insurance War + Cyber Operation + State-Backed Exclusions + Attribution

Lloyds Cyber Insurance Requirements - War, Cyber Operation, and State-Backed Exclusions. Following NotPetya 2017 + WannaCry 2017 + SolarWinds 2020 + Colonial Pipeline 2021 industry-wide reassessment of war + state-backed cyber exclusion language driven by Lloyds Market Bulletin Y5258. LMA5400-LMA5403 model exclusions for war + cyber operation provide tiered language: (a) LMA5400 broadest exclusion requires no attribution + state-backed cyber excluded; (b) LMA5401 limited carve-back for bystander attacks where target not government/military; (c) LMA5402 narrower exclusion with explicit carve-backs for ransomware + denial of service even if state-backed; (d) LMA5403 attribution bureau mechanism requires government attribution or independent cyber attribution service. Attribution Mechanisms: (a) Government Attribution - sovereign attribution by impacted government (US + UK + EU + Five Eyes

Artefacts an auditor will ask for
  • LMA5400/5401/5402/5403 selection rationale
  • Attribution mechanism documentation
  • Government attribution monitoring
  • Independent attribution service contracts
  • War-cyber claims handling procedure
Where this commonly fails
  • No attribution mechanism
  • Outdated war exclusion
  • No state-backed analysis
  • No carve-back consideration
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.