FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
Sector pillar · IT consultants

IT consultants professional indemnity insurance — the complete UK guide 2026

~13 min read

What might your premium be? See guideline professional indemnity ranges for your profession and fee income in about 30 seconds. A guideline range, not a quote.

Estimate your premium →
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited (FCA FRN 724952) · Published 14 July 2026

Professional indemnity insurance for IT consultants covers the legal liability that arises when a consultant's advice, code, configuration or project delivery causes a client to suffer financial loss. The UK IT-consulting market carries around £90m of primary PI premium across roughly 40,000 firms — broad breadth, wide rate variance. This guide explains how the class actually works: what triggers a claim, how insurers rate different consultancy profiles, where PI ends and cyber begins, and how to structure cover so a claim lands within limit rather than outside it.

IT consulting is not directly regulated in the UK. BCS Chartered IT Professional (CITP) status, GDPR/DPA 2018 obligations, PECR/NIS regulations, and IR35 off-payroll rules all shape how PI is structured. Client-contract requirements — particularly public-sector and large-corporate — are the practical driver of cover limits.

The regulatory framework for IT consultants

IT consultancy is not a directly regulated activity in the UK. There is no equivalent to the SRA for solicitors or ARB for architects. That said, several regulatory frameworks affect how PI cover is structured and priced.

BCS (British Computer Society) — Chartered Institute status

BCS is the professional body for IT consultants in the UK. It offers Chartered IT Professional (CITP) status, Chartered Engineer (CEng) status routed through BCS as licensed nominating body, and Chartered Fellow (FBCS CITP) recognition. BCS Code of Conduct sets four pillars: public interest, professional competence and integrity, duty to the profession, and duty to relevant authority. Membership is optional; roughly 68,000 UK members currently.

GDPR and Data Protection Act 2018

IT consultants routinely process personal data on behalf of clients — either as data processors under a data processing agreement, or as data controllers where they retain client data for their own analytical purposes. Article 82 GDPR gives data subjects a direct right of compensation. ICO fines under Article 83 reach 4% of worldwide turnover or €20m, whichever is higher, for the most serious breaches. Cyber policies rather than PI typically respond to first-party breach costs.

PECR and NIS Regulations

The Privacy and Electronic Communications Regulations 2003 (PECR) and the Network and Information Systems Regulations 2018 (NIS) impose additional operator-specific obligations. Consultants advising on marketing systems, telemedicine, or operator-of-essential-services infrastructure need to price these into their PI wording review.

IR35 — off-payroll working rules

Since April 2021 the IR35 status determination sits with the end-client for medium and large private-sector engagements, and with the public-sector body for public engagements. Where the consultant is deemed inside IR35 they are employed for tax purposes but remain the contracting party for PI purposes. Sole-trader consultants inside IR35 need PI in their own name; personal-service-company consultants have their PI in the PSC name.

What IT-consultants PI insurance actually covers

IT-consultants PI (also called technology PI, or tech E&O in North American markets) covers legal liability arising from a breach of professional duty in the course of consulting work. Standard cover includes:

Standard exclusions include: known claims and circumstances existing at inception; fraud, dishonesty and criminal acts; contractual liability assumed beyond common-law duty of care; bodily injury and property damage (typically covered by public liability); asbestos, nuclear, war and cyber-terrorism.

PI vs cyber — the distinction that matters. PI responds when a consultant's advice or code causes client loss. Cyber responds when the consultant's own systems are attacked, encrypted, or breached — the first-party costs of investigation, notification, forensic, and business interruption. Both are needed; neither substitutes for the other.

What claims typically look like

Claims patterns for IT consultants tend to cluster around a small number of scenarios. Each has its own defence and reserve profile. The list below is illustrative of the types insurers actively track for pricing and appetite decisions.

Fixed-price project overrun causing client business loss
Consultant delivered ERP migration at agreed fixed price. Project overran by 14 months, missing the client's go-live deadline for tax-year-end. Client claims lost revenue and additional interim system costs. Aggregate claim: £1.2m. Insurer responds subject to fee-income declared and adequacy of limit.
Failed integration causing client data loss
Consultant integrated legacy accounting system with new CRM. Field-mapping error caused six weeks of sales data to be miswritten to closed accounts. Client claims cost of manual reconciliation, staff overtime, and reputational damage from delayed customer response. Settled at £340k. Consultant carried £2m limit; margin comfortable.
Software licence advice error
Consultant advised client on Microsoft licence rationalisation. Licence audit two years later found under-licensing based on original advice. Client faced £450k of true-up costs. Consultant carried £1m limit; claim within limit, aggregation clause important.
GDPR notification failure by processor consultant
Consultant acted as data processor operating client's email marketing tool. Consultant's own credentials compromised via phishing. Attacker exported subscriber lists. ICO investigation; consultant faced fine and remediation costs. PI does not cover the ICO fine (uninsurable under s148 Financial Services Act); cyber policy responds to first-party notification and forensic costs. PI responds to third-party claims from the affected data subjects.
Public-sector prime-contractor liability
Consultant appointed by government department to deliver identity-verification system. Novated architect-role delivery. System went live with false-positive error rate outside SLA. Contract-executed-as-deed 12-year limitation applied. Claim landed 8 years after go-live. Consultant retired 4 years prior; run-off cover was 12 years so responded. Without deed-appropriate run-off, personal exposure would follow.
Software developer IP infringement
Developer consultant delivered custom app to client. Third-party library included in delivery had licence terms consultant had not reviewed. Rights-holder issued cease-and-desist plus damages claim. IP-infringement PI extension responded, subject to consultant's design-and-supply activity being properly declared at inception.

Choosing the right cover limit

Cover limit selection is the single biggest structural decision in a PI placement. Under-cover means an aggregation event exhausts limit before defence costs are paid. Over-cover wastes premium on a limit no realistic claim would reach. The bands below reflect how experienced professional insurers think about limit selection for IT consultants.

£250k limit
Sole-trader advisory consultant on small clients, individual project values under £20k, no delivery or code work, no public-sector. Rare in modern IT consultancy. Only defensible where all client contracts specify this as the maximum contractual limit.
£500k limit
Small advisory consultancy with clients in SME sector, no fixed-price delivery, no safety-critical systems. Increasingly rare as client contracts push for £1m+.
£1m limit
Standard advisory-consultancy default. Fits most small IT consultancy firms with fee income up to ~£500k. Where clients require £2m+ in contracts, must be moved.
£2m – £5m limit
Delivery and integration consultancy, mid-size firms, projects over £100k value, public-sector contracts, framework-agreement work. Common range for firms 5-30 people.
£10m limit
Software development firms with material product exposure, large-project delivery, novated designer roles on major projects, safety-critical or financial-services production systems. Layered programme typical — primary and excess layers separately underwritten.
Above £10m
Layered programme with wholesale Lloyd's excess placement. Firms with large individual contract values, prime-contractor exposure, or class-action-magnet product lines. Excess-of-loss market appetite matters.

Run-off cover and long-tail exposure

IT consultancy claims often surface long after the engagement completes. A software system delivered in 2023 that later causes client business interruption in 2026 can trigger a PI notification three years after the invoice was paid.

PI cover is claims-made — the policy in force when the claim is notified pays, not the one in force when the work was done. If a consultant closes their firm or retires, run-off cover fills the tail. Standard market practice is:

The single most common IT-consultancy claims-tail failure is retiring without arranging run-off. If a claim arrives three years later and no run-off is in place, personal exposure follows the consultant — whether they were the shareholder, director or sole practitioner.

How insurers rate this class

Insurers segment IT consultants across a small number of appetite bands. Where a firm sits determines rate, limit-availability, wording extras and how easy it is to renew.

Firms operating across bands need declarative underwriting — the presentation should break fee income by activity type, not lump it together.

Deep-dive sub-topics

The topics below explore the technical decisions that most affect IT consultants PI outcomes. Each links out to the standalone deep-dive page.

Aggregation clauses in IT-consultants PI

Aggregation is how a wording treats multiple claims arising from a common cause. A single-limit-per-claim wording can pay multiple limits if claims are treated as separate. An aggregated wording pays one limit per common cause — often materially less. For consultants delivering repeatable products (SaaS, code libraries, framework-based systems), aggregation wording matters more than sticker limit.

The Aggregation of claims deep-dive covers the specific wordings to test and the case law that drives them.

PI vs cyber: buying both

Professional service failure and cyber breach are separate exposures. Consultants routinely carry both. PI defends third-party claims from client-loss allegations. Cyber pays first-party breach-response costs plus specific extensions for regulatory-fine legal defence, cyber-extortion, and business-interruption. Overlap is uncommon; gap is common.

The PI vs cyber for consultants deep-dive covers the specific claim scenarios that each product handles.

Software project failure — who bears the risk

Fixed-price contracts push failure-risk onto the consultant. Time-and-materials contracts push risk onto the client. Hybrid contracts split risk by phase. Insurers price these differently. A firm delivering purely fixed-price work rates 40-60% higher than a firm delivering purely time-and-materials advice at equivalent fee income.

The Software project failure deep-dive unpacks the standard contract-structure decisions.

BCS Code of Conduct and PI adequacy

BCS members are subject to the BCS Code of Conduct. The Code sets a professional-competence standard but does not itself impose a specific PI cover limit. That said, BCS Chartered members typically hold at least £1m limit as a proxy for adequate. Where BCS refers a member to disciplinary panel following a client complaint, PI cover documentation is one item the panel considers.

Frequently asked

Do IT consultants need PI insurance in the UK?
There is no statutory requirement for IT consultants to hold PI. However, most client contracts — particularly public-sector and large-corporate — require £1m to £10m of PI as a contractual condition. Contract-required PI is the practical driver, not regulation.
What does IT-consultants PI cover?
Legal liability for professional negligence, errors or omissions in consultancy services. Advice, design, code, configuration, project management. Includes defence costs, IP infringement (as extension), unintentional confidentiality breach, loss of client documents.
How much does IT-consultants PI cost?
Highly variable with firm profile. Rate typically 0.4% to 4% of fee income depending on activity mix. Advisory-only rates lowest; software development and public-sector delivery rate highest.
Do I need PI and cyber both?
Typically yes. PI covers third-party claims (client loss caused by consultant error). Cyber covers first-party costs (consultant's own breach, ransomware, notification). Different exposures; both routinely bought together.
What limit should IT consultants carry?
Depends on contract requirements and largest individual project value. £1m is a common floor for advisory consultants; £2m to £10m is common for delivery and development firms. Public-sector prime-contractor exposure often pushes higher.
What about IR35?
IR35 affects tax status, not PI. Where the consultant is deemed inside IR35 they are still contracting on their own account for professional-liability purposes. PI cover must be in the correct legal name — sole trader or personal service company.
What's aggregation and why does it matter?
Aggregation is how a wording treats multiple claims arising from a common cause. Consultants delivering repeatable products (SaaS, code libraries) face aggregated-claim risk. Wording review at inception matters more than sticker limit.
Do I need PI as an in-house IT professional?
No. Employees are covered under employer's PI (if any) or general employer's vicarious liability. PI is a firm-level product for consultants operating on own account. In-house employees do not need individual PI.
What's run-off cover and when do I need it?
Run-off covers claims notified after a firm ceases trading. Standard: six years from closure; 12 years where contracts were executed as deed. Retiring without run-off exposes the consultant personally to any claim notified in the tail.
Can Apex place IT-consultants PI?
Yes. Apex places IT-consultants PI across the full range — sole-trader advisory through to layered programmes for development firms. Direct access to over 30 markets including Lloyd's via wholesale.

Related reading

Rather we called you?

Leave a name and number — a named broker calls you back, usually the same working day. No documents needed to start.

IT consultants PI market · 2026

The it consultants PI market at a glance

Market size
~£90m premium
Firms
~40,000 firms
Typical rate
0.4%-4% of fee income (advisory low, delivery/dev high)

Regulator specifics: BCS CITP standards + GDPR/DPA 2018 + PECR + IR35 off-payroll rules

M
Named broker for this class
Mark Fox
Broker, Renewals · Apex Insurance Brokers Limited
Named broker for IT consultants and software developers. Cyber-PI overlap and IR35 exposure covered.
Speak to Mark Fox →0117 325 0027

Market figures are indicative of current UK conditions per publicly available broker and regulator commentary. Individual placements depend on firm-specific circumstances. Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Firm reference number 724952.

Get a quote →