Insurance requirements in IT and technology contracts
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06
If you build software, manage infrastructure, consult on systems or supply IT services, you will sooner or later meet a contract that tells you what insurance to carry. It might be a one-page statement of work from a small client, or a 60-page master services agreement (MSA) from an enterprise buyer with a dedicated insurance schedule. Either way, the clause is doing real work: it sets out what the client expects to be able to recover from if your work causes them a loss, and it turns insurance from a nice-to-have into a condition of getting paid.
This page walks through the covers you will typically be asked for, what the limits and maintenance obligations actually mean, what tends to be negotiable, and why it pays to have someone check the insurance schedule before you commit. It is general guidance rather than advice on your specific contract, and for the legal wording itself you should take proper legal input.
What insurance do IT and technology contracts usually require?
There is no single standard clause, and you should be wary of anyone who tells you there is. That said, the covers requested of technology suppliers cluster into a familiar set, and understanding what each one is for makes the schedule far less intimidating.
- Professional indemnity (technology PI). This is the headline requirement for most IT firms. It responds to claims that your advice, code, design or service caused a client financial loss — a failed implementation, a defect, missed requirements, a project that overran. You may see it called technology errors & omissions (tech E&O); that is the US term for broadly the same cover, so if a US-headquartered client's contract asks for "E&O", they mean professional indemnity. Increasingly, tech PI and cyber are bought together as a combined technology policy so the wordings dovetail.
- Cyber insurance. Common now that clients are alert to data breaches and supply-chain risk, especially where you hold or process their data. Cyber funds breach response — forensics, notification, legal support, restoring systems — along with business interruption and third-party liability arising from an incident.
- Public liability (PL). Covers injury to people or damage to property caused by your business, typically relevant if your staff attend client sites or handle client equipment.
- Employers' liability (EL). Required by contract, but also a legal requirement once you employ staff (more on that below).
Which of these a given contract demands depends on what you do and how the client sees the risk. A data-heavy SaaS provider will almost always be asked for cyber; a firm sending engineers on site will be asked for public liability. If you want a plain-English tour of the whole set, our guide to what insurance an IT company needs is a good companion to this page.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Got a contract on your desk with an insurance schedule you're not sure you meet? Send it over and we'll tell you where you stand before you sign.
Get a tailored quote →Is professional indemnity a legal requirement for IT firms?
No — and this is worth being clear about, because it is widely misunderstood. Professional indemnity is not a statutory requirement for technology businesses the way it is for solicitors or accountants. For an IT firm, PI is almost always a contractual requirement: it is your clients, agencies and framework operators who insist on it, not the law. That distinction matters, because it means the level of cover you carry is driven by what your contracts demand and what your real exposure is, not by a fixed legal minimum.
Employers' liability is the exception. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you are generally required by law to hold EL cover, subject to narrow exceptions (for example, some family businesses or companies with a single employee who owns most of the shares). If you are a sole trader or a limited company with no employees, that requirement may not bite — but a client contract can still ask you to hold it, and many do as a standard term. Take the wording at face value and check whether it applies to your situation.
What minimum indemnity limits do clients ask for, and should you just meet them?
Contracts usually state a minimum limit of indemnity for each cover — the most the insurer will pay — and you will commonly see figures such as £1m, £5m or £10m used as thresholds, with larger enterprise and public-sector buyers tending toward the higher end. These are illustrative; your contract will specify its own numbers.
Meeting the stated minimum is the price of entry, but treating the client's number as the whole answer is a mistake in both directions. If the limit is far below the value of the project or the size of loss you could realistically cause, you have met the letter of the contract while leaving your own business exposed — because a claim that exhausts the limit doesn't stop there; the balance falls on you. Equally, agreeing to a limit far above your genuine exposure can mean paying for cover you will never need. The right limit is the one that reflects your real-world risk: contract values, the criticality of the systems you touch, the volume and sensitivity of data you handle, and how large a single mistake could plausibly become.
One more detail that trips people up: most PI and cyber policies are written on an aggregate basis, meaning the limit is the total available across all claims in the policy year, not per claim. A contract that requires "£5m per claim" or "each and every claim" is asking for something different from "£5m in the aggregate", and the wording needs to line up with what your policy actually provides. This is exactly the kind of mismatch a broker catches.
Why do contracts say you must keep cover in place after the work ends?
Because the damage from IT work often surfaces long after go-live. A defect in code you shipped this year might not cause a measurable client loss until a couple of years down the line. Professional indemnity and cyber are typically written on a claims-made basis, which means the policy that responds is the one in force when the claim is made against you, not the one in force when you did the work. If you let cover lapse the day the project ends, a claim arriving afterwards may have no policy to answer it.
That is why so many contracts include a maintenance obligation: a requirement to keep the relevant cover in force for a set period after the engagement finishes — often expressed in years, sometimes tied to the limitation period for bringing a claim. Before you sign, make sure that runs as long as you can realistically maintain, and be alert to what happens if you ever stop trading or switch insurers — run-off cover exists precisely to bridge that gap. Our overview of technology professional indemnity insurance explains the claims-made mechanism in more depth.
What evidence of insurance will you have to provide?
Almost every insurance clause comes with a proof requirement. Expect to be asked, on request and often annually, to produce evidence that your cover is genuinely in place. The usual forms are:
- A broker's certificate or letter confirming the covers, limits and renewal dates.
- Sometimes a copy of the policy schedule itself.
- Occasionally a specific request to note the client's interest or add them as an additional insured — something your insurer needs to agree to, so don't promise it in the contract before checking it's achievable.
Some larger buyers set up an automated portal that chases your evidence each year and can suspend you as an approved supplier if it lapses. Keeping renewal dates and certificates tidy is not admin busywork here — it is a contractual condition, and a broker who holds your documentation can turn these requests around quickly rather than leaving you scrambling.
What's negotiable in an insurance schedule?
More than people assume. An insurance schedule is a commercial term like any other, and while some clients treat it as fixed, many will engage if you raise a point sensibly and early. Areas that are often open to discussion include:
- The limit, particularly where the requested figure is disproportionate to a small, well-defined piece of work.
- The maintenance period, if the run-off obligation is longer than is reasonable for the engagement.
- Which covers apply, for instance dropping a public liability requirement where you never attend site, or aligning a cyber requirement with the data you actually handle.
- The basis of the limit — reconciling "per claim" versus "aggregate" language with what your policy provides.
What you should not do is sign up to a requirement you cannot actually meet, or quietly assume your existing policy is close enough. If the contract asks for cover you don't hold, or at a limit above yours, the honest options are to arrange the cover, negotiate the clause, or walk away — not to sign and hope. Where a contract's demands and your policy don't line up, it is usually faster to talk it through with a specialist than to guess. You can start a conversation with an Apex specialist here.
Does insurance affect IR35 or GDPR fines?
Two common misconceptions are worth clearing up, because both appear in contract conversations.
First, IR35. If you contract through a limited company, the off-payroll working rules may come up alongside insurance in the same conversation — but they are separate matters. IR35 is a tax question about your employment status for tax purposes on a given engagement. Holding insurance does not change, improve or determine your IR35 position in any way; the two are unrelated. For your actual status, take advice from a qualified accountant or tax adviser, not from an insurer or a contract clause.
Second, regulatory fines. It is tempting to read a cyber requirement as "the insurer will pay any data-protection fine we incur", but that is not a safe assumption. UK data-protection law — the UK GDPR and the Data Protection Act 2018, enforced by the Information Commissioner's Office (ICO) — can result in monetary penalties, and whether such fines are insurable at all is legally uncertain and frequently excluded or restricted by policy. The genuine value of cyber cover is in funding breach response, business interruption and third-party liability after an incident — not in a promise to pay a regulator's fine. If your contract implies otherwise, that is a point to clarify rather than rely on. Our explainer on cyber insurance sets out what it does and doesn't do.
Should you get a broker to check a contract before you sign?
Yes — on the insurance schedule specifically, and ideally before the ink is dry. A broker who knows technology risk can read the schedule against your actual policies in minutes and tell you three things that matter: whether you already meet the requirements, where a gap exists and what it would take to close it, and whether any clause is asking for something no policy realistically provides (uncapped liability being the classic red flag that no insurance will fully back). That last point is important — a contract can require cover that doesn't exist, and spotting it before signature saves an ugly conversation later.
A broker check is not a substitute for legal review of the contract as a whole. The insurance schedule sits alongside indemnity clauses, liability caps and warranties that a solicitor should look at — and for anything material, taking legal input is the right call. But on the insurance mechanics — limits, basis, maintenance periods, evidence, and whether your programme lines up — that is squarely a broker's job, and getting it right upfront means you win the work without quietly taking on risk you never priced for.
Apex specialises in insurance for IT and technology firms — we'll review your contract's insurance schedule, tell you where you stand, and arrange cover that actually matches the deal in front of you.
Get a tailored quote →Whether you are a solo contractor weighing an agency's requirements or a growing consultancy signing enterprise MSAs, the pattern is the same: read the schedule, match the cover to your genuine exposure rather than the bare minimum, keep it in force for as long as the contract asks, and be ready to prove it. Get those four things right and the insurance clause stops being a hurdle and starts being what it should be — evidence that you are a supplier worth trusting. If you want a second pair of eyes, our guide to IT contractor insurance and a quick call with the team will get you there.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
