FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Resilience consultants

Professional indemnity insurance for business continuity and disaster recovery consultants

Yes. Business continuity and disaster recovery consultants are hired so that a client can rely on a plan when everything else has failed, and that reliance is what makes professional indemnity insurance essential. If a recovery time was never achievable, a backup design could not meet the recovery point you advised, or an exercise skipped the scenario that actually happened, the client’s losses can dwarf your fee. Those losses are financial, so public liability will not respond; PI is the policy built for them, subject to its terms.

In short

Business continuity consultants are judged on whether their analysis, plans and recovery designs hold up in a real incident. The allegations to expect are an unachievable recovery time objective (RTO) or recovery point objective (RPO), a dependency missed in the business impact analysis, or a test that proved less than the client was told. ISO 22301:2019, amended in 2024, sets the requirements for a business continuity management system. For FCA-regulated clients, SYSC 15A requires important business services, impact tolerances, mapping and scenario testing, and firms had until 31 March 2025 to be able to stay within tolerance. PI usually covers negligent advice; the client’s own outage losses belong to its business interruption and cyber cover.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

Why continuity advice needs PI

Last reviewed 5 October 2026 by the Apex professional indemnity team.

Your work is only truly tested on the worst day a client has. You run the business impact analysis, decide which activities matter and how fast they must return, design the recovery strategy and the disaster recovery (DR) architecture behind it, write the plans and run the exercises. The client invests on your advice and then, when a fire, a supplier failure or a ransomware attack arrives, it finds out whether you were right.

If you were not, the losses are financial and they can be large: days of lost trading, missed regulatory obligations, penalties under the client’s own contracts, and the cost of an emergency rebuild. Public liability (PL) insurance has no part to play unless someone is hurt or property is damaged, for example a fall during a live evacuation drill you organised. The allegation that matters is that your analysis, design or advice was negligent, and that is answered by professional indemnity (PI), which insurers often write for technology-heavy work as technology errors and omissions cover.

Cyber insurance plays two roles. The client’s own cyber policy pays for its incident response, and its insurer may then look to recover from you if your DR design failed. Your own cyber policy usually protects you, because you hold plans, call trees, supplier lists and network diagrams for many clients.

How claims arise for business continuity consultants

These examples are illustrative. They are not real claims, but they reflect the allegations continuity consultants meet.

  1. A recovery time the architecture could never meet. You agree a four-hour RTO for order processing, but the recovery design restores from backups that take two days at the client’s data volumes. After a ransomware attack the business is down for three days, and the client claims the lost margin, alleging you never checked the RTO against restore performance.
  2. The supplier nobody mapped. Your business impact analysis treats payroll as an internal process and misses the outsourced provider behind it. When that provider suffers an outage, staff are paid late and the client claims emergency payment costs and the cost of redoing the analysis.
  3. An exercise that tested the wrong thing. Three years of exercises rehearse the loss of a building. None simulates losing IT. In a real cyber incident the call tree sits on the encrypted email system, and the client alleges your exercise programme gave it false assurance.
  4. Backups inside the blast radius. Your DR design keeps backups reachable with the same administrator credentials as production. The attacker encrypts both, and the client claims the extended outage, alleging the design ignored a known attack pattern.
  5. Impact tolerances without evidence. An FCA-regulated payments firm adopts the impact tolerances and mapping you produced. A supervisory review finds the mapping incomplete and the testing too narrow. The firm runs a remediation programme and claims its cost from you.

None of these involves accidental injury or damage. Each alleges that you fell short of the care expected of a competent continuity professional.

Standards, bodies and laws your work is measured against

Reference pointWhat it saysWhy it matters to your PI
ISO 22301:2019 and Amendment 1:2024 (BS EN ISO 22301:2019+A1:2024 in the UK)Requirements for a business continuity management system. The 2024 amendment covers climate action changes. ISO now lists the standard as to be revised, with a new edition in development.Implementation and audit-readiness work is judged against the edition the client is working to, so name it in every engagement.
ISO/IEC 27031:2025Guidance on making sure information and communication technology is prepared to support business continuity. It replaced the 2011 edition.The natural benchmark for DR and ICT recovery designs.
BCI Good Practice Guidelines (GPG 7.0)The Business Continuity Institute’s guide to good practice, organised in six Professional Practices: establishing a business continuity management system, embracing business continuity, analysis, solutions design, enabling solutions and validation.Experts use it to describe what a competent practitioner would have done at each stage.
BCI certificationPassing the Certificate of the BCI (CBCI) exam starts the BCI membership route.Insurers and clients use credentials to judge who signs off your work.
Civil Contingencies Act 2004, s.2(1)(c)Category 1 responders must maintain plans to ensure, so far as is reasonably practicable, that they can continue to perform their functions if an emergency occurs.Plans you write for councils and other responders support a statutory duty.

Operational resilience for FCA-regulated clients

For financial services clients, your advice now sits inside a rulebook. Chapter 15A of the FCA’s Senior Management Arrangements, Systems and Controls sourcebook (SYSC 15A) applies to banks, building societies, PRA-designated investment firms, insurers, recognised investment exchanges, enhanced scope SM&CR firms, payment and e-money firms and others listed by the FCA.

The firm keeps the regulatory responsibility. Your exposure is that it relied on your mapping, tolerances or testing and has to pay to put them right. PI can respond to that allegation, subject to the terms, but fines and penalties are commonly excluded, and claims against you as a director or senior manager of the firm need D&O cover rather than PI.

RTO, RPO and the test that proves them

A recovery objective agreed in a workshop and never proved is the first weakness a claim will look for. Treat every RTO and RPO as a statement you may one day have to defend.

What PI covers for continuity consultants, and what it doesn’t

Usually covered by PIOften excluded or limitedNeeds a different policy
Negligent business impact analysis and risk assessmentGuarantees that a plan or recovery will workThe client’s own lost income during an outage (its business interruption cover)
RTO, RPO and DR design errorsFines and penalties, which PI wordings commonly excludeAn attack on your systems and the client plans you hold (cyber)
Plan writing and maintenance errorsFailures of third-party infrastructure you do not controlInjury during a live exercise or evacuation drill (public liability)
Exercise and test design and reportingService credits under a DR service you operateClaims against you as a director or senior manager of a client (D&O)
Operational resilience mapping, tolerance and self-assessment adviceWork outside the business description you declaredInjury to your own staff (employers’ liability)
Defence costs, including resilience and IT forensic expertsProblems you were aware of before cover startedLaptops and recovery kit you own (equipment cover)

What is covered depends on the wording and on the insurer accepting your proposal. If you also run recovery infrastructure for clients, describe it separately: operating a service is a different risk from advising on one.

How much cover, and for how long

Regulated firms, public bodies and larger companies usually set the PI limit in their contracts. Think about what a failed recovery would cost your largest client, not about your fee, and negotiate a liability cap that your limit can meet.

If a client asks for more cover than you hold, see what to do when a contract requires a higher PI limit.

What insurers will ask you

A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:

Speak to a broker

PI for business continuity and disaster recovery consultants, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

Do business continuity and disaster recovery consultants need professional indemnity insurance?

Yes. Clients rely on your analysis, plans and recovery designs when an incident strikes, and a flaw can cost them far more than your fee. Those are financial losses that public liability does not cover. PI meets the cost of defending the allegation and any compensation due, subject to the policy terms.

Is PI a legal requirement for business continuity consultants?

No law or regulator requires business continuity consultants to hold PI. In practice regulated financial firms, public bodies and larger companies usually write a PI requirement into the engagement terms, commonly with a minimum limit, and some expect the cover to continue for a period after the work is finished.

Does PI cover us if a client’s plan fails in a real incident?

It can, if the client alleges the failure came from negligent analysis, design or advice, such as an untested recovery assumption. PI does not guarantee that a plan works, and it will not pay the client’s own lost income, which belongs to the client’s business interruption or cyber insurance.

Are we liable if an FCA-regulated client breaches its impact tolerance?

Responsibility for meeting SYSC 15A stays with the firm. If it alleges your mapping, testing or tolerance advice was negligent and claims the cost of putting it right, PI may respond, subject to the terms. Regulatory fines are a different matter: PI wordings commonly exclude them.

Which edition of ISO 22301 should we work to?

The current standard is ISO 22301:2019 with Amendment 1:2024, published in the UK as BS EN ISO 22301:2019+A1:2024. ISO has marked it for revision and a new edition is in development, so state in each engagement which edition you are working to and review plans when it changes.

Does PI cover a disaster recovery service we run for clients?

Only if the policy describes it. Running recovery infrastructure is a technology service judged on availability as well as advice. Tell your insurer, check how service credits and contractual commitments are treated, and consider cyber cover for the platform itself.

Ready to compare cover?

Apex arranges professional indemnity insurance for business continuity and disaster recovery consultants across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.