ERP and CRM implementation consultant insurance
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
If you implement, migrate or integrate enterprise systems for a living — ERP rollouts, CRM deployments, finance system replacements, the integration glue between them — you sit in one of the highest-stakes corners of the technology services market. The projects are long. They touch the systems a client literally cannot trade without. And the gap between what the client expected and what got delivered is where disputes are born. This page walks through the cover an implementation consultancy actually needs, how to size it, and why your contracts matter as much as your policy.
Why do ERP and CRM implementations produce some of the largest technology PI claims?
Ask anyone who handles technology professional indemnity claims what the big ones look like, and failed or late enterprise implementations come up again and again. The pattern is consistent, and it's worth understanding because it shapes everything else on this page.
First, the money at stake dwarfs your fees. A mid-market ERP programme might pay your consultancy a six-figure sum over eighteen months — but if the go-live fails, the client's alleged losses are measured in lost productivity, manual workarounds, remediation costs, a replacement implementation partner and sometimes lost revenue. When a dispute crystallises, the claim is framed around their losses, not your invoice.
Second, responsibility is genuinely blurry. Enterprise implementations depend on the client's own data quality, their internal project team, their willingness to change processes rather than customise the software to death, and decisions made by steering committees you don't control. When a programme runs late or under-delivers, the client's version of events tends to put the implementation partner at the centre of it — whatever the contemporaneous reality was. Common allegations include poor requirements gathering, over-promising the product's fit in pre-sales, botched data migration, inadequate testing, and missed milestones.
Third, the relationship sours slowly. Unlike a single catastrophic error, implementation disputes build over months of scope arguments and slipping dates, which means there is usually a long paper trail — and whether that paper trail helps or hurts you depends almost entirely on how disciplined your project documentation was. We come back to that below, because it is the single biggest thing you control.
What insurance does an ERP or CRM implementation consultancy actually need?
The core programme for an implementation consultancy is built around four covers:
- Technology professional indemnity (tech PI) — covers claims that your professional work caused a client financial loss: negligent advice, defective configuration, failed migration, missed deadlines attributed to you. You'll also see this called technology errors & omissions, or tech E&O — that's the US name for broadly the same product, not a separate policy. This is the cover that responds to the classic failed-implementation dispute. See our full guide to technology professional indemnity insurance.
- Cyber insurance — responds to security and data incidents affecting your own business: breach response, forensics, business interruption, and liability to third parties. Given the access implementation consultants hold in client environments, this matters more for you than for most tech firms.
- Employers' liability (EL) — a legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969 once you employ staff, with only narrow exceptions. Most consultancies of more than one person need it, and it's usually needed sooner than founders expect — it can extend to some contractors and temporary workers depending on how they work for you.
- Public liability (PL) — covers injury to third parties or damage to their property. For consultants regularly working on client premises during workshops, cutovers and hypercare, many enterprise clients simply won't let you on site without it.
Beyond those four, consultancies often add office and portable equipment cover, and directors' & officers' insurance as the business grows. If you're a one-person implementation specialist working through your own limited company, the same logic applies at smaller scale — our IT contractor insurance guide covers that setup in detail. One point worth being precise about for contractors: IR35 is a tax question about your employment status for tax purposes, and holding insurance has no bearing on it either way. For IR35 status itself, speak to a qualified accountant or tax adviser — your broker's job is the risk transfer, not the tax position.
How much professional indemnity cover should an implementation consultancy carry?
Professional indemnity isn't a statutory requirement for IT firms — no law says you must hold it. In practice it's a contractual one: enterprise clients, framework agreements and the software vendors whose partner programmes you belong to will almost always specify a minimum PI limit before you can sign, and often before you can even bid.
But treating the client's stated minimum as the right number is a mistake for this line of work. The contractual minimum tells you what the client's procurement template says; it doesn't tell you what a failed programme would actually cost. A more useful way to size PI for implementation work is to ask three questions:
What's the largest programme value you touch? Not your fees — the client's total programme spend, because that's the scale their losses will be argued at. A consultancy earning £400,000 on a £3m transformation programme is exposed to the £3m end of that equation, not the £400,000 end.
What does your limitation of liability clause say? If your contracts cap your liability at, say, twice the fees paid, your realistic exposure on any one contract has a ceiling — and your PI limit should comfortably clear it, including defence costs. If you've signed contracts with no cap, or with carve-outs that swallow the cap, your exposure is much harder to bound, and your limit needs to reflect that.
How many live programmes overlap? Implementations run for months or years, so a consultancy with four concurrent engagements carries four concurrent exposures. This is where the difference between an "any one claim" limit and an "aggregate" limit becomes real money: an aggregate limit is shared across every claim in the policy year, which is uncomfortable if two programmes go wrong in the same period.
Limits of £1m, £2m and £5m are common asks in this market, with £10m appearing on larger enterprise and public-sector work — but the right figure is specific to your contract book, and this is a conversation worth having with a human. Speak to an Apex technology specialist and we'll work through your actual engagements rather than guessing from turnover.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Apex arranges technology PI, cyber and liability cover for UK implementation and integration consultancies — sized to the programmes you actually deliver, not a generic IT template.
Get a tailored quote →Do I need cyber insurance if I'm working inside my clients' systems?
Yes — and arguably more than most technology businesses, because of the nature of the access you hold. An implementation consultant routinely has administrator credentials in client environments, handles full extracts of client data during migration, and connects into client networks from consultancy-owned devices. That makes you both a target and a potential route into your clients: attackers increasingly go after suppliers precisely because one compromised consultancy credential can open doors into several client estates.
It helps to be clear about what cyber insurance does and doesn't do here. A good cyber policy funds your own incident response — forensic investigation, legal advice, notification to affected individuals, credential resets, system restoration — covers business interruption while your own systems are down, and provides third-party liability cover if a security failure on your side causes loss to others. Where personal data is involved, the legal framework is the UK GDPR and the Data Protection Act 2018, with the Information Commissioner's Office (ICO) as regulator; a cyber policy typically pays for the legal and technical work of responding to the ICO. What it may not pay is a regulatory fine itself: the insurability of UK data-protection fines is legally uncertain, and policies often exclude or restrict them. Nobody should sell you cyber cover on the promise that "it pays your GDPR fines" — the honest framing is that it funds the response, the recovery and the liability, which in most incidents is where the real cost sits anyway.
One structural point specific to your trade: when an incident involves client data you were migrating, the resulting claim can sit in the seam between your PI policy (professional failure) and your cyber policy (security failure). Arranging both through one broker — ideally with the same insurer or as a combined policy — avoids the miserable scenario of two insurers each pointing at the other. Our guides to cyber insurance and combined tech PI and cyber cover unpack this in more detail.
How do contracts and insurance work together on a big implementation?
This is the section we most want implementation consultancies to take seriously, because insurance is your second line of defence. Your first is the contractual and documentary discipline that stops a difficult project becoming a claim at all — and that shapes how defensible you are if one lands anyway.
Four habits do most of the work. A precise statement of work, with the client's obligations (data quality, decision-making, resource commitments, sign-offs) written down as explicitly as yours — most implementation disputes are, at heart, arguments about whose job something was. Rigorous change control, so that every scope addition, descoped item and date movement is recorded and agreed in writing at the time, not reconstructed from memory two years later in a solicitor's letter. Defined acceptance criteria and staged sign-off, so "the system doesn't work" has to be argued against a record of what the client tested and accepted at each gate. And a limitation of liability clause that caps your exposure at a sensible multiple of fees, excludes indirect and consequential loss, and — critically — is set at or below a level your PI policy can actually respond to. A liability cap of £5m paired with a £1m PI limit isn't contract discipline; it's a £4m gap you're funding personally.
These things also matter at the underwriting stage. When we present an implementation consultancy to insurers, evidence of consistent change control, standard terms reviewed by a solicitor, and a track record of staged sign-offs materially changes how the risk is received. Insurers have seen how implementation claims go wrong; showing them you've engineered those failure modes out of your delivery model is the strongest story a broker can tell on your behalf. If your standard terms haven't been looked at since you founded the business, fixing that alongside your renewal is one of the highest-value hours you'll spend this year.
What happens if a project dispute actually turns into a claim?
Two features of PI insurance catch implementation consultancies out, and both are worth knowing before you need them.
First, PI is written on a claims-made basis: the policy that responds is the one in force when the claim is made against you, not the one in force when you did the work. For a trade where the gap between go-live and formal dispute can be a year or more, that means continuity of cover matters enormously. Let a policy lapse between engagements and you can find yourself uninsured for work you did while fully covered. It also means your retroactive date — the earliest work the policy will pick up — needs checking every time you change insurer, and run-off cover needs arranging if you ever close or sell the consultancy, because claims can arrive years after the last invoice.
Second, notify early. Most policies require you to report not just claims but circumstances that might reasonably give rise to one — and a steering committee meeting where the client's FD starts talking about "recovering the cost of delays" is exactly such a circumstance. Consultants understandably hesitate, hoping to trade their way back into the client's good books, but late notification is one of the most common reasons insurers push back on otherwise valid claims. Telling your insurer doesn't escalate the dispute; it protects your position while you carry on trying to fix the relationship. A good broker sits in the middle of that process — helping you frame the notification, keeping the insurer onside, and making sure a wobbly project doesn't quietly become an uninsured one.
Why arrange this through Apex?
Apex Insurance Brokers is an FCA-authorised broker based in Bristol, and technology firms are our specialism rather than a sideline. That matters for implementation consultancies in particular, because the difference between adequate and inadequate cover here lives in the details: whether your PI limit is any-one-claim or aggregate, whether your policy definition of "professional services" actually describes systems integration and data migration, whether your cyber and PI covers meet in the middle or leave a seam, and whether your contractual liability position is one insurers will stand behind. We read your contracts as well as your cover, and we'll tell you plainly where the gaps are. If you're mapping out cover for the wider business, start with our overview of what insurance an IT company needs — or go straight to a tailored quote and we'll take it from there.
Delivering ERP or CRM programmes and not certain your limits match your contract book? Tell us about your engagements and we'll build cover around them.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
