Skip to content
Insurance evidence

Insurer-grade evidence from live compliance data.

Fig organises continuous compliance data into clear, traceable evidence. You control whether to share it with your chosen insurer, broker, or underwriter.

Fig provides compliance software and evidence reporting. Fig does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance.

Evidence picture: High uncertainty

0 of 3 layers selected

Illustrative evidence overview · not a risk score, quote or prediction of premiums

How it works

Turn compliance activity into shareable evidence.

Five connected steps turn live compliance posture into insurer-grade evidence.

  1. Compliance data collection

    Fig monitors your compliance posture across chosen frameworks. Data flows continuously.

  2. Evidence aggregation

    Automatically compile control evidence, audit trails, and assessment results.

  3. Insurer-grade evidence

    Organise relevant records into a clear, consistent view for external review.

  4. Customer review

    Choose which records to include and confirm that the export is appropriate for its intended recipient.

  5. Customer-controlled sharing

    Download and share the evidence with your chosen insurer, broker, or underwriter.

Fig supplier governance overview showing contract coverage, criticality and review status
Fig mobile app Home screen showing framework compliance, monitoring coverage and device posture
Four pillars

Coverage types where compliance data matters.

Cyber liability

Technical controls, incident readiness, vulnerability management, and audit history.

Evidence relevance

Give your chosen insurer, broker, or underwriter a documented view of cyber controls.

Professional indemnity

Governance, quality controls, documented procedures, and corrective actions.

Evidence relevance

Share evidence of how professional and operational risks are governed.

Directors & officers (D&O)

Board oversight, risk ownership, policy approval, and management reporting.

Evidence relevance

Present a traceable record of governance activity and accountability.

Management liability

Policies, training, people processes, and issue management.

Evidence relevance

Export current records for external review when your organisation chooses.

For MSPs

Help clients maintain evidence they control.

Give each client a clear record they can review and share with their own insurer, broker, or underwriter.

Insurer-grade evidence

Give each client a structured record of controls, assessments, and audit activity.

Customer-controlled sharing

Clients decide whether to export their evidence and share it with an insurer, broker, or underwriter.

Reusable records

Maintain evidence continuously so clients can respond to external information requests without starting again.

Clear role separation

Fig supplies compliance software and evidence reporting; insurance decisions and services remain with the client and their chosen provider.

For corporates

Be prepared for external information requests.

Keep control evidence current and export the records your chosen recipient requests.

Structured control evidence

Present current controls, ownership, testing, and remediation in a consistent format.

Export on demand

Create a customer-controlled export for an insurer, broker, or underwriter when requested.

Renewal preparation

Keep supporting records current ahead of external reviews and renewal discussions.

Third-party risk evidence

Show how suppliers and MSPs are assessed, monitored, and followed up.

Why this works

How is this different?

Replace one-off evidence gathering with maintained, traceable records.

TraditionalThe Fig model
Annual questionnairesContinuous monitoring with real-time data
Self-reported compliance statusEvidence-based control verification
Priced with limited visibilityUnderwriters assess documented controls
One-time snapshotOngoing audit trail of compliance management
FAQ

Questions?

Everything you need to know about compliance and insurance.

What does insurer-grade evidence mean?

It means structured, dated, and traceable compliance evidence that a customer can review and share with an insurer, broker, or underwriter. It does not mean that Fig has approved the evidence on behalf of an insurance provider or that any insurance outcome is guaranteed.

Does Fig decide what an insurer or underwriter will accept?

No. Each insurer, broker, and underwriter sets its own information requirements and makes its own decisions. Fig helps customers organise and export their compliance records.

Can we use Fig to prepare information requested during an insurance review?

Yes. You can use Fig to collect and organise control evidence, audit trails, assessment results, policies, and remediation records, then choose what to share with your selected recipient.

Which types of insurance reviews can the evidence support?

Customers may find the same governance and control records relevant to cyber liability, professional indemnity, D&O, or management liability reviews. The insurer or adviser determines what information is required.

Can we share Fig Group compliance data with multiple insurers or brokers?

Yes. You control what gets exported and who receives it. Fig does not select the recipient or submit an insurance application on your behalf.

What happens when the evidence shows a compliance gap?

Fig records the gap, its owner, remediation activity, and progress. Your organisation decides whether and how that information is shared externally.

How much compliance data should we share?

That depends on the request and your organisation's disclosure obligations. Review each export before sharing it and take advice from your chosen insurance or legal adviser where needed.

Can MSPs use Fig to prepare evidence for their clients?

Yes. MSPs can maintain documented controls, audit trails, and monitoring evidence for each client. The client controls whether that evidence is shared with an insurer, broker, or underwriter.

Do MSP clients see their own compliance data when Fig is white-labelled?

Yes. Clients can log in to a branded view of their own compliance posture and evidence. White-labelling applies only to the Fig Group compliance workspace.

Do MSP clients need a Cyber Essentials certificate to use insurer-grade evidence exports?

No. Cyber Essentials certification and the compliance platform are separate products. Customers can maintain and export their compliance evidence whether or not they currently hold Cyber Essentials.

Does Fig send evidence directly to insurance providers?

No. Customers review and export their own evidence, then choose whether to share it with an insurer, broker, or underwriter. Fig does not select providers or submit applications.

Can Fig help a customer choose or apply for insurance?

No. Fig does not recommend insurance products or providers and does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance. Customers should use an appropriately authorised insurance provider or adviser.

Contact

Build insurer-grade compliance evidence.

See how Fig can help your organisation maintain records for customer-controlled sharing.

Speak to Fig

Tell us what you need. We’ll help you take the next step.

A brief message is all we need to get started.