Skip to contentAbout Fig Group

Insurer-grade evidence from live compliance data.

Fig organises continuous compliance data into clear, traceable evidence. You control whether to share it with your chosen insurer, broker, or underwriter.

Fig provides compliance software and evidence reporting. Fig does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance.

How it works

Turn compliance activity into shareable evidence.

Five connected steps turn live compliance posture into insurer-grade evidence.

  1. 01

    Compliance data collection

    Fig monitors your compliance posture across chosen frameworks. Data flows continuously.

  2. 02

    Evidence aggregation

    Automatically compile control evidence, audit trails, and assessment results.

  3. 03

    Insurer-grade evidence

    Organise relevant records into a clear, consistent view for external review.

  4. 04

    Customer review

    Choose which records to include and confirm that the export is appropriate for its intended recipient.

  5. 05

    Customer-controlled sharing

    Download and share the evidence with your chosen insurer, broker, or underwriter.

Fig exposure analysis dashboard showing financial impact trending and risk exposure
Four pillars

Coverage types where compliance data matters.

Cyber liability

Technical controls, incident readiness, vulnerability management, and audit history.

Evidence relevance

Give your chosen insurer, broker, or underwriter a documented view of cyber controls.

Professional indemnity

Governance, quality controls, documented procedures, and corrective actions.

Evidence relevance

Share evidence of how professional and operational risks are governed.

Directors & officers (D&O)

Board oversight, risk ownership, policy approval, and management reporting.

Evidence relevance

Present a traceable record of governance activity and accountability.

Management liability

Policies, training, people processes, and issue management.

Evidence relevance

Export current records for external review when your organisation chooses.

For MSPs

Help clients maintain evidence they control.

Give each client a clear record they can review and share with their own insurer, broker, or underwriter.

Insurer-grade evidence

Give each client a structured record of controls, assessments, and audit activity.

Customer-controlled sharing

Clients decide whether to export their evidence and share it with an insurer, broker, or underwriter.

Reusable records

Maintain evidence continuously so clients can respond to external information requests without starting again.

Clear role separation

Fig supplies compliance software and evidence reporting; insurance decisions and services remain with the client and their chosen provider.

For corporates

Be prepared for external information requests.

Keep control evidence current and export the records your chosen recipient requests.

01

Structured control evidence

Present current controls, ownership, testing, and remediation in a consistent format.

02

Export on demand

Create a customer-controlled export for an insurer, broker, or underwriter when requested.

03

Renewal preparation

Keep supporting records current ahead of external reviews and renewal discussions.

04

Third-party risk evidence

Show how suppliers and MSPs are assessed, monitored, and followed up.

Why this works

How is this different?

Replace one-off evidence gathering with maintained, traceable records.

Traditional

Annual questionnaires

Fig model

Continuous monitoring with real-time data

Traditional

Self-reported compliance status

Fig model

Evidence-based control verification

Traditional

Priced with limited visibility

Fig model

Underwriters assess documented controls

Traditional

One-time snapshot

Fig model

Ongoing audit trail of compliance management

FAQ

Questions?

Everything you need to know about compliance and insurance.

What does insurer-grade evidence mean?

It means structured, dated, and traceable compliance evidence that a customer can review and share with an insurer, broker, or underwriter. It does not mean that Fig has approved the evidence on behalf of an insurance provider or that any insurance outcome is guaranteed.

Does Fig decide what an insurer or underwriter will accept?

No. Each insurer, broker, and underwriter sets its own information requirements and makes its own decisions. Fig helps customers organise and export their compliance records.

Can we use Fig to prepare information requested during an insurance review?

Yes. You can use Fig to collect and organise control evidence, audit trails, assessment results, policies, and remediation records, then choose what to share with your selected recipient.

Which types of insurance reviews can the evidence support?

Customers may find the same governance and control records relevant to cyber liability, professional indemnity, D&O, or management liability reviews. The insurer or adviser determines what information is required.

Can we share Fig compliance data with multiple insurers or brokers?

Yes. You control what gets exported and who receives it. Fig does not select the recipient or submit an insurance application on your behalf.

What happens when the evidence shows a compliance gap?

Fig records the gap, its owner, remediation activity, and progress. Your organisation decides whether and how that information is shared externally.

How much compliance data should we share?

That depends on the request and your organisation's disclosure obligations. Review each export before sharing it and take advice from your chosen insurance or legal adviser where needed.

Can MSPs use Fig to prepare evidence for their clients?

Yes. MSPs can maintain documented controls, audit trails, and monitoring evidence for each client. The client controls whether that evidence is shared with an insurer, broker, or underwriter.

Do MSP clients see their own compliance data when Fig is white-labelled?

Yes. Clients can log in to a branded view of their own compliance posture and evidence. White-labelling applies only to the Fig compliance workspace.

Do MSP clients need a Cyber Essentials certificate to use insurer-grade evidence exports?

No. Cyber Essentials certification and the compliance platform are separate products. Customers can maintain and export their compliance evidence whether or not they currently hold Cyber Essentials.

Does Fig send evidence directly to insurance providers?

No. Customers review and export their own evidence, then choose whether to share it with an insurer, broker, or underwriter. Fig does not select providers or submit applications.

Can Fig help a customer choose or apply for insurance?

No. Fig does not recommend insurance products or providers and does not advise on, arrange, distribute, place, bind, underwrite, or administer insurance. Customers should use an appropriately authorised insurance provider or adviser.

Contact

Build insurer-grade compliance evidence.

See how Fig can help your organisation maintain records for customer-controlled sharing.