Technology leadership
Yes, most interim CTOs, CIOs and IT interim managers need professional indemnity insurance, usually held by their own limited company. That is the company the client or agency contracts with, and the one it will pursue if your technology decisions cost it money. If you join the board, or act as a director in all but name, directors’ and officers’ (D&O) cover matters just as much. The two policies answer different allegations, and an interim technology role can attract both.
Part of: Professional indemnity for IT professionals
In short
An interim CTO makes decisions that move a client’s money: platform choices, supplier contracts, cloud migrations and security priorities. If those decisions are said to be negligent, the claim usually lands on the company that contracted to provide you, and PI is the policy that defends it. If you sit on the board or behave as if you do, company law duties apply to you personally and claims come through D&O, ideally the client’s policy with you as an insured. IR35 decides how your fees are taxed, not whether you can be sued. In some financial services firms, running technology is a senior management function that needs regulatory approval.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
Clients hire an interim CTO or IT interim manager to make decisions quickly, often in a crisis: a stalled migration, a security incident, a departed technology leader, a sale or funding round. You are trusted because of your expertise, and the client acts on what you recommend or decide.
That reliance is the source of the risk. When a platform choice fails, a supplier contract turns out to be a trap or a security decision is followed by a breach, the client’s loss is financial, and its complaint is that you did not show the skill and care expected of an experienced technology leader. Public liability insurance, which deals with injury and property damage, has nothing to say about it.
Professional indemnity (PI) insurance, which insurers often write for technology work as technology errors and omissions cover, pays your defence costs and any compensation when a client alleges your advice, decisions or work were negligent, subject to the policy terms. Most interims work through their own company, so the policy is normally bought by that company and should name the work you do as technology leadership and interim management, not just “IT consultancy”.
These scenarios are illustrative. They show the type of allegation an interim CTO can face, not real claims or outcomes.
The first, second, fourth and fifth are classic PI allegations. The third could arrive as a PI claim against your company or, if you were acting as a director, as a D&O claim against you personally.
This is the question that decides which policy responds, and it turns on what you actually did, not on your job title.
The line is easier to cross than many interims expect. Section 250 of the Act says “director” includes any person occupying the position of director, “by whatever name called”, and section 1173 says an “officer” includes a director, manager or secretary. An interim CTO who attends board meetings, votes on decisions and is presented to investors as part of the leadership team may be treated as a director whatever the contract says.
The duty of care in section 174 also bites harder on specialists. It is judged against the knowledge and experience reasonably expected of someone in your role and against the knowledge and experience you actually have, so a seasoned CTO on a board is measured by that expertise.
Many PI policies exclude claims made against you as a director or officer of a client, so do not assume PI will step in. Section 233 allows a company to buy insurance for its directors, so ask the client to confirm in writing that its D&O policy treats you as an insured person, and how long that protection lasts after you leave.
Under the off-payroll working rules, as changed from 6 April 2021, a public sector client or a medium or large private sector client decides your employment status for tax and should give you a status determination statement. For a small private sector client, your own intermediary makes that decision.
The rules exist to make a worker supplied through an intermediary pay broadly the same income tax and National Insurance as an employee. An inside-IR35 determination is a tax decision. It does not, by itself, change the contract between your company and the client, so a claim that your work was negligent can still be brought against your company.
| Rule or code | What it says | Why it matters to an interim CTO |
|---|---|---|
| Companies Act 2006, ss.174, 250 and 1173 | Directors must exercise reasonable care, skill and diligence; “director” covers anyone occupying the position by whatever name; “officer” includes a manager. | Your title does not settle your exposure. What you do in the role does. |
| Companies Act 2006, s.233 | A company may buy and maintain insurance for its directors against liability for negligence, default, breach of duty or breach of trust in relation to the company. | The legal basis for asking to be covered by the client’s D&O policy. |
| Off-payroll working rules (HMRC) | Public sector and medium or large clients decide status and issue a status determination statement; small clients leave the decision to your intermediary. | Affects your tax, not your liability. Keep insurance and contracting entity aligned. |
| FCA Handbook, SUP 10C.6B.2R | The chief operations function (SMF24) covers overall responsibility for the internal operations or technology of a firm. | In some regulated firms, an interim head of technology performs a senior management function that needs approval. |
| FCA Handbook, SUP 10C.3A.6R (the 12-week rule) | Cover for a temporarily or unexpectedly absent senior manager can run without approval for less than 12 weeks in a consecutive 12-month period. | Longer interim cover means approval, personal regulatory accountability and a stronger case for D&O. |
| Institute of Interim Management Code of Conduct | Members should accept only work they are competent to do and disclose any interests that might influence or impair their independent judgement. | Undisclosed supplier relationships are a common thread in disputes about technology choices. |
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Negligent advice on architecture, platforms, suppliers and sourcing | Claims against you as a director or officer of the client | Breach of directors’ duties (D&O, ideally the client’s policy) |
| Errors in technology assessments, due diligence and board papers you prepared | Promises of a result, such as a guaranteed go-live date | Claims from staff you restructured or dismissed (the client’s employment practices cover) |
| Breach of confidentiality and unintentional IP infringement, on many wordings | Regulatory fines imposed on you personally, where uninsurable | Costs of a regulator’s investigation into your conduct in a senior role (D&O) |
| Defence costs and expert fees | Work outside the business description you declared | An attack on your own laptop, email or password manager (cyber) |
| Loss of client documents or data in your care | Matters you knew about before the policy began | Injury or damage at client premises (public liability) |
Cyber is easy to overlook as an interim. The client’s own cyber policy pays for its incident, and if that insurer then pursues you, alleging your decisions caused the breach, your PI usually defends you. But you also hold the keys: admin credentials, architecture diagrams and supplier access, often on your own company’s devices. A small cyber policy for your company covers your own incident response and, on many wordings, claims from clients affected by a compromise that started with you.
The limit is usually set by the interim provider’s terms or the client’s contract. Size it to the decisions you influence, not your day rate: an interim CTO steering a multi-million pound programme carries a larger exposure than the fee suggests. D&O limits are normally the client’s, which is another reason to see the policy schedule before you start.
PI is claims-made. The policy in force when a claim is made is the one that responds, and claims about a programme often surface long after you have moved on. An interim career is a run of short assignments, so keep PI continuous, protect the retroactive date when you change insurer, and if you stop working as an interim, arrange run-off cover rather than letting the policy lapse. For board roles, ask whether the client’s D&O policy covers former directors and officers.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for interim CTOs and IT interim managers, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
In most cases, yes. Clients and agencies contract with your company and can claim against it if your technology advice or decisions cause a loss. PI pays defence costs and compensation for negligence allegations, subject to the policy terms. If you sit on the board or act as a director, you also need D&O protection.
No law requires interim technology leaders to hold PI. In practice interim providers and clients usually make it a condition of the contract, often with a minimum limit. If you perform a regulated senior management function, the regulatory requirement is approval, not insurance, but the role brings personal regulatory exposure.
Possibly. Under the Companies Act 2006, “director” includes anyone occupying the position by whatever name called, and “officer” includes a manager. If you act as part of the board, ask the client to confirm in writing that its D&O policy covers you.
Not directly. The off-payroll rules decide how your fees are taxed. An inside determination does not by itself change the contract between your company and the client, so your company can still be sued over your work. Tell your insurer how each assignment is structured.
No. D&O usually protects insured directors and officers against claims about how they ran the company. It does not cover your company’s liability to the client for negligent advice under your contract. You usually need both, and confirmation that you are an insured person under the client’s policy.
Keep your PI running. It is claims-made, so a claim about an assignment that ended last year is handled by the policy in force when the claim arrives. If there is no policy then, there is no cover, even though you were insured when you did the work.
Apex arranges professional indemnity insurance for interim CTOs and IT interim managers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.