IT consultants professional indemnity insurance — the complete UK guide 2026
~13 min readProfessional indemnity insurance for IT consultants covers the legal liability that arises when a consultant's advice, code, configuration or project delivery causes a client to suffer financial loss. The UK IT-consulting market carries around £90m of primary PI premium across roughly 40,000 firms — broad breadth, wide rate variance. This guide explains how the class actually works: what triggers a claim, how insurers rate different consultancy profiles, where PI ends and cyber begins, and how to structure cover so a claim lands within limit rather than outside it.
IT consulting is not directly regulated in the UK. BCS Chartered IT Professional (CITP) status, GDPR/DPA 2018 obligations, PECR/NIS regulations, and IR35 off-payroll rules all shape how PI is structured. Client-contract requirements — particularly public-sector and large-corporate — are the practical driver of cover limits.
The regulatory framework for IT consultants
IT consultancy is not a directly regulated activity in the UK. There is no equivalent to the SRA for solicitors or ARB for architects. That said, several regulatory frameworks affect how PI cover is structured and priced.
BCS (British Computer Society) — Chartered Institute status
BCS is the professional body for IT consultants in the UK. It offers Chartered IT Professional (CITP) status, Chartered Engineer (CEng) status routed through BCS as licensed nominating body, and Chartered Fellow (FBCS CITP) recognition. BCS Code of Conduct sets four pillars: public interest, professional competence and integrity, duty to the profession, and duty to relevant authority. Membership is optional; roughly 68,000 UK members currently.
GDPR and Data Protection Act 2018
IT consultants routinely process personal data on behalf of clients — either as data processors under a data processing agreement, or as data controllers where they retain client data for their own analytical purposes. Article 82 GDPR gives data subjects a direct right of compensation. ICO fines under Article 83 reach 4% of worldwide turnover or €20m, whichever is higher, for the most serious breaches. Cyber policies rather than PI typically respond to first-party breach costs.
PECR and NIS Regulations
The Privacy and Electronic Communications Regulations 2003 (PECR) and the Network and Information Systems Regulations 2018 (NIS) impose additional operator-specific obligations. Consultants advising on marketing systems, telemedicine, or operator-of-essential-services infrastructure need to price these into their PI wording review.
IR35 — off-payroll working rules
Since April 2021 the IR35 status determination sits with the end-client for medium and large private-sector engagements, and with the public-sector body for public engagements. Where the consultant is deemed inside IR35 they are employed for tax purposes but remain the contracting party for PI purposes. Sole-trader consultants inside IR35 need PI in their own name; personal-service-company consultants have their PI in the PSC name.
What IT-consultants PI insurance actually covers
IT-consultants PI (also called technology PI, or tech E&O in North American markets) covers legal liability arising from a breach of professional duty in the course of consulting work. Standard cover includes:
- Negligent act, error or omission in the professional service — advice, design, code, configuration, project management.
- Loss of client documents or data that the consultant is responsible for.
- Unintentional breach of confidence — inadvertent disclosure of client-confidential information.
- Defamation — typically included as an extension.
- Intellectual property infringement — a critical extension for software developers; not always automatic.
- Defence costs for allegations, whether valid or not. Typically paid within the limit; wordings that pay defence outside the limit are more valuable and more expensive.
Standard exclusions include: known claims and circumstances existing at inception; fraud, dishonesty and criminal acts; contractual liability assumed beyond common-law duty of care; bodily injury and property damage (typically covered by public liability); asbestos, nuclear, war and cyber-terrorism.
What claims typically look like
Claims patterns for IT consultants tend to cluster around a small number of scenarios. Each has its own defence and reserve profile. The list below is illustrative of the types insurers actively track for pricing and appetite decisions.
Choosing the right cover limit
Cover limit selection is the single biggest structural decision in a PI placement. Under-cover means an aggregation event exhausts limit before defence costs are paid. Over-cover wastes premium on a limit no realistic claim would reach. The bands below reflect how experienced professional insurers think about limit selection for IT consultants.
Run-off cover and long-tail exposure
IT consultancy claims often surface long after the engagement completes. A software system delivered in 2023 that later causes client business interruption in 2026 can trigger a PI notification three years after the invoice was paid.
PI cover is claims-made — the policy in force when the claim is notified pays, not the one in force when the work was done. If a consultant closes their firm or retires, run-off cover fills the tail. Standard market practice is:
- Six-year run-off as a minimum where limitation runs six years from breach.
- 12-year run-off where contracts were executed as a deed — common in public-sector and large-corporate IT contracts.
- Run-off premium is typically 250-350% of the final annual premium, priced upfront at exit.
The single most common IT-consultancy claims-tail failure is retiring without arranging run-off. If a claim arrives three years later and no run-off is in place, personal exposure follows the consultant — whether they were the shareholder, director or sole practitioner.
How insurers rate this class
Insurers segment IT consultants across a small number of appetite bands. Where a firm sits determines rate, limit-availability, wording extras and how easy it is to renew.
- Standard advisory consultancy — strategy, business-analysis, requirements-mapping work. Broadest appetite. Rate typically 0.4% to 1% of fee income.
- Implementation and delivery consultancy — SAP, Oracle, Microsoft Dynamics deployments; ERP configuration; cloud migration project management. Wider spread. Rate typically 1% to 2%.
- Software development and integration — custom-code development, systems integration, API/middleware work. Rating steps up. Rate typically 1.5% to 3%.
- High-risk projects — fixed-price large contracts, novated designer roles, safety-critical or financial-services production systems, public-sector prime contracts. Specialist markets only. Rate 2% to 4%+ with detailed underwriting scrutiny.
Firms operating across bands need declarative underwriting — the presentation should break fee income by activity type, not lump it together.
Deep-dive sub-topics
The topics below explore the technical decisions that most affect IT consultants PI outcomes. Each links out to the standalone deep-dive page.
Aggregation clauses in IT-consultants PI
Aggregation is how a wording treats multiple claims arising from a common cause. A single-limit-per-claim wording can pay multiple limits if claims are treated as separate. An aggregated wording pays one limit per common cause — often materially less. For consultants delivering repeatable products (SaaS, code libraries, framework-based systems), aggregation wording matters more than sticker limit.
The Aggregation of claims deep-dive covers the specific wordings to test and the case law that drives them.
PI vs cyber: buying both
Professional service failure and cyber breach are separate exposures. Consultants routinely carry both. PI defends third-party claims from client-loss allegations. Cyber pays first-party breach-response costs plus specific extensions for regulatory-fine legal defence, cyber-extortion, and business-interruption. Overlap is uncommon; gap is common.
The PI vs cyber for consultants deep-dive covers the specific claim scenarios that each product handles.
Software project failure — who bears the risk
Fixed-price contracts push failure-risk onto the consultant. Time-and-materials contracts push risk onto the client. Hybrid contracts split risk by phase. Insurers price these differently. A firm delivering purely fixed-price work rates 40-60% higher than a firm delivering purely time-and-materials advice at equivalent fee income.
The Software project failure deep-dive unpacks the standard contract-structure decisions.
BCS Code of Conduct and PI adequacy
BCS members are subject to the BCS Code of Conduct. The Code sets a professional-competence standard but does not itself impose a specific PI cover limit. That said, BCS Chartered members typically hold at least £1m limit as a proxy for adequate. Where BCS refers a member to disciplinary panel following a client complaint, PI cover documentation is one item the panel considers.
Frequently asked
Do IT consultants need PI insurance in the UK?
What does IT-consultants PI cover?
How much does IT-consultants PI cost?
Do I need PI and cyber both?
What limit should IT consultants carry?
What about IR35?
What's aggregation and why does it matter?
Do I need PI as an in-house IT professional?
What's run-off cover and when do I need it?
Can Apex place IT-consultants PI?
Related reading
- PI vs cyber for consultants
- Software project failure liability
- Aggregation of claims in PI
- Cyber insurance for IT consultants
- Run-off cover for IT consultants
- BCS Code of Conduct and PI adequacy
- GDPR and IT-consultants PI
- IR35 and PI for consultants
Leave a name and number — a named broker calls you back, usually the same working day. No documents needed to start.
The it consultants PI market at a glance
Regulator specifics: BCS CITP standards + GDPR/DPA 2018 + PECR + IR35 off-payroll rules
Market figures are indicative of current UK conditions per publicly available broker and regulator commentary. Individual placements depend on firm-specific circumstances. Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Firm reference number 724952.
