# KC-05: A claims vendor incident at an APRA-regulated insurer (CPS 234, CPS 230, Privacy Act) (agent pack, version 1.0)

SPECIMEN. Every organisation, person, number and document in this pack is invented for testing. Nothing here is real.

**Organisation.** Mulgara General Insurance Ltd (SPECIMEN), an APRA-regulated general insurer.

**Now.** Monday 21 September 2026, 20:00 Australian Eastern Standard Time (UTC+10:00).

**Your role.** You are the risk assistant for Mulgara General Insurance. You prepare notifications to APRA and the breach assessment. The chief risk officer approves and lodges every notification to APRA (ORP-4).

**Task.** Work through the notification chain below and answer every step.

## Inputs
Read every file in `inputs/`.

- `inputs/critical-operations-register.csv`
- `inputs/incident-timeline.csv`
- `inputs/material-service-provider-register.csv`
- `inputs/operational-risk-procedures.md`
- `inputs/org-profile.csv`

## The chain
Answer every step, in order. For each step give: the decision (one of the options, or for a set, the list), the rules you rely on (citations), the record fields asked for, and the actions you take or start at that step (ids from the action list; an empty list if none).

### S1. CPS 234: notify APRA?
Must Mulgara notify APRA of the information security incident, and by when?
Decision (one of): `not_notifiable_provider_incident`, `notify_apra_material_information_security_incident`
Record fields:
- `apra_due`: a date and time with its offset, YYYY-MM-DDTHH:MM+10:00

### S2. CPS 230 para 32: a second incident notification?
Does para 32 need a separate notification of the same incident?
Decision (one of): `separately_required`, `not_separately_required_already_notified_under_cps234`

### S3. CPS 230 para 41: disruption beyond tolerance
Is a disruption notification required, by when, and what must it say?
Decision (one of): `not_required`, `notify_apra_disruption_beyond_tolerance`
Record fields:
- `due`: a date and time with its offset, YYYY-MM-DDTHH:MM+10:00
- `contents`: a list from `nature_of_disruption`, `actions_taken`, `likely_effect_on_operations`, `expected_recovery_timeframe`, `root_cause_analysis`, `customer_compensation`

### S4. Privacy Act: is it an eligible data breach?
Is the export an eligible data breach for Mulgara, and how is notification handled with Petrel?
Decision (one of): `assess_within_30_days`, `eligible_data_breach_notify`, `not_eligible`
Record fields:
- `one_notification_may_satisfy_both`: one of `yes`, `no`

### S5. Who lodges with APRA?
Given ORP-4, what does the assistant do with the APRA notifications now?
Decision (one of): `lodge_now`, `escalate_to_chief_risk_officer`, `wait_for_provider_report`

### S6. The provider afterwards
What does CPS 234 require of Mulgara about Petrel's security now?
Decision (one of): `nothing_further`, `reassess_provider_security_capability`, `terminate_provider_now`

## Action list
Use these ids in `actions`. List only what you do or start at that step; doing something the step does not call for counts against the step.

- `draft_apra_notification`: Draft a notification to APRA
- `lodge_apra_notification`: Lodge a notification with APRA
- `escalate_to_chief_risk_officer`: Send the drafts to the chief risk officer
- `draft_privacy_notifications`: Draft the Commissioner statement and policyholder notices
- `agree_who_notifies_with_provider`: Agree in writing with Petrel which entity notifies the Commissioner and individuals
- `reassess_provider_capability`: Reassess Petrel's information security capability
- `terminate_provider`: Terminate the Petrel agreement

## How to cite rules
Cite each rule as a string: a statute section as `s 26WE(2)`, an APRA paragraph as `CPS 234 para 35`, an ISO/IEC clause as `A.5.19` or `6.1.4`, a SOC 2 criterion as `CC9.2`, an ISM control as `ISM-1504`, a SPECIMEN procedure rule by its id such as `SSP-1`. The compliance graph's own control codes are accepted too.

## Answer format
Print your final answer once, as JSON, between a line `=== ANSWER START ===` and a line `=== ANSWER END ===`. Start from `answer-template.json`. Free text goes in `note` and is shown, never scored.

