Heading into a round and not sure which of these a new investor will actually insist on? We'll map your covers to your stage and your term sheet before diligence starts.
Get a tailored quote →Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06
There's a moment in almost every funding round where the data room throws up an insurance question, and the founder realises nobody on the team actually knows the answer. A term sheet mentions D&O. A prospective enterprise customer's contract demands a specific level of professional indemnity. A new investor's operations lead asks, politely but firmly, what happens if a key employee walks off with client funds. Suddenly insurance stops being a box-ticking chore and becomes something that can slow a round down.
The good news is that the covers investors and boards look for are predictable, and they tend to appear in a recognisable order as you scale. This page walks through them the way we'd walk a founder through them on a call: what each one does, when it usually shows up, and — crucially — whether it's something the law demands, something a customer contract demands, or something an investor simply expects to see before they wire the money.
Before we get into individual policies, it's worth being precise about the three very different reasons you might be asked to hold a cover, because founders (and, honestly, plenty of advisers) blur them together.
Getting these categories right saves you from two opposite mistakes: treating an investor's expectation as if it were optional, and treating a genuine legal duty as if it were merely a nice-to-have. Let's take the covers in the order they typically become relevant.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
If there's a single cover this page exists to explain, it's this one. Directors' & Officers' insurance protects the personal assets of your directors and senior officers when they're pursued for decisions made in running the company — claims alleging mismanagement, breach of duty, misleading statements, regulatory investigations, and similar. Importantly, it protects individuals, not just the company balance sheet.
D&O is not a legal or statutory requirement. You will not be breaking any law by trading without it. What actually drives founders to buy it is investors. Once professional money comes in — very commonly from Series A onward, though it can appear earlier — those investors typically want directors (often including their own appointee on your board) protected against personal liability. It's frequently written into the term sheet or the investment agreement as a condition, and a board seat is a good deal less attractive to an investor if the person filling it is personally exposed.
Because the requirement is contractual between you and your backers rather than fixed in law, the specifics — the limit, the definition of who's insured, run-off provisions — vary from deal to deal, and the wording matters. This is an area where we'd always suggest reviewing the actual clause with your broker and your corporate lawyer rather than assuming a standard policy ticks the box. We go deeper on how these policies are structured in our guide to directors and officers insurance explained.
Here's the cover founders most often overlook precisely because it feels mundane. The moment you employ staff in the UK, Employers' Liability (EL) insurance becomes a legal requirement under the Employers' Liability (Compulsory Insurance) Act 1969. It covers claims from employees who are injured or made ill as a result of their work.
Unlike D&O, this isn't investor preference — it's the law, and non-compliance carries penalties. There are a small number of narrow exceptions (for example, some businesses that employ only close family members, or certain public bodies), but for a typical venture-backed startup the day you make your first hire is the day you need EL in place. Investors doing diligence will expect to see it not as a favour to them but as evidence you're running the company properly.
Two practical notes founders get wrong. First, contractors and freelancers can, depending on the working relationship, still fall within the scope of EL — worth checking rather than assuming. Second, you're generally expected to keep the certificate accessible to employees. It's a small administrative point that signals a well-run business in a data room.
Professional Indemnity (PI) covers claims that your advice, service or work was negligent, caused a client a loss, or didn't do what you promised. For a services business, a consultancy or a software company delivering to clients, it's often the cover that unlocks revenue rather than the one that satisfies an investor.
That's because PI is usually contractually required. Enterprise customers, public-sector buyers and larger partners frequently write a minimum PI limit into their contracts — you'll see it in the insurance schedule of an MSA. No PI at the required level, no signature. So while investors are glad to see it, the real pressure to hold PI, and to hold it at a specific limit, tends to come from your sales pipeline.
Whether you need it, and at what level, depends heavily on what you sell and to whom. A design studio, a fintech and a management consultancy face very different exposures, and the limit a customer demands can jump the moment you move upmarket. Because it's so contract-driven, it pays to check incoming customer agreements early rather than discovering a £5m requirement the week before a deal closes. We cover how to read those clauses in our note on professional indemnity for startups.
If your company holds customer data, processes payments, or is itself a technology product, cyber cover moves quickly from optional to assumed. It typically responds to data breaches, ransomware and extortion, business interruption from an attack, and the costs of notification, investigation and putting things right — the expenses that turn a bad week into an existential one.
Cyber sits in an interesting spot across our three categories. It's not legally mandated as an insurance (though your data-protection obligations under UK law very much are). Increasingly it's contractually required — enterprise and regulated customers now routinely ask suppliers to carry it. And it's investor-expected, because a serious breach at a data-heavy startup is exactly the kind of event that can wipe out value, and boards want to know it's been thought about.
A word of caution founders appreciate: cyber policies vary a great deal in what they include and exclude, and the underwriting often now depends on the security controls you actually have in place — multi-factor authentication, backups, patching. It's less a commodity than most covers, so the detail of the wording, and honest answers on your controls, genuinely matter.
Every stage brings a new cover onto the list. We hand-hold founders through exactly what to add — and when — so nothing surfaces as a surprise in diligence.
Get a tailored quote →Crime (sometimes called commercial crime or fidelity) cover protects against losses from theft, fraud, forgery and social-engineering scams — including the internal risk of an employee misappropriating money, and the external risk of a convincing fraudster tricking your finance team into paying the wrong account.
This one tends to appear later, as the numbers get bigger. A five-person startup moving small sums has a different risk profile from a Series B company running payroll for a hundred people, holding client funds, or processing significant volumes. As finance functions scale, boards and investors start to ask how the company is protected if that trust is abused. It's rarely a legal requirement and rarely written into customer contracts — it's mostly investor-expected and prudent governance once the money at stake justifies it.
No two companies scale identically, and this is a guide rather than a rulebook — but here's the shape of it, which is exactly how we'd talk it through on a first call:
Alongside these, keep an eye on the covers that follow from simply operating — public liability if the public interact with your business, and the right cover if you take on office space. If you're mapping the whole picture, our overview of startup insurance by funding stage pulls it together.
The founders who breeze through the insurance section of a data room aren't the ones with the biggest programmes — they're the ones who can explain, cover by cover, why each policy is there and which category it falls into. That clarity reads as competence, and it stops insurance becoming a last-minute scramble that holds up a wire.
The other reason to sort it early is that limits and requirements have a habit of ratcheting up faster than founders expect — an enterprise contract or a term sheet can name a figure you're not yet carrying. It's far calmer to review your covers a stage ahead than to react in the closing days of a round. If you'd rather talk it through than fill in a form, speak to an Apex specialist and we'll build the checklist around your actual stage, contracts and cap table.
Raising soon? Let's get your D&O, EL, PI, cyber and crime cover lined up before diligence — so insurance is the easy part of the round.
Get a tailored quote →Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.