Professional indemnity insurance for IT contractors, consultants and technology firms.
Professional Indemnity Insurance for IT Contractors and Tech Firms
If you write code, architect systems, advise on a digital transformation or place contractors on a client's project, your biggest exposure is not fire or theft. It is the claim that says your work caused a financial loss. Professional indemnity insurance, often sold to technology businesses as tech errors & omissions (E&O) or a combined technology PI policy, is the cover that responds to allegations of negligence, faulty advice, defective code, missed deadlines and breach of a professional duty. For a limited company contractor or a growing software house, it is usually the single most important line of cover you buy.
Apex is a directly FCA-authorised broker (FRN 724952) built around a named-broker model: a director-level contact who handles your placement, argues your corner at claims and manages renewal. We work with more than 30 professional-lines insurer markets, which matters in technology because appetite varies enormously between underwriters. This is a national guide, and we place IT and tech risks across the UK.
What tech PI / E&O actually covers
A well-constructed technology policy is broader than a standard professional indemnity wording. It typically responds to:
- Professional negligence — errors, omissions or negligent advice in the services you deliver, from systems integration to consultancy.
- Defective code and product failure — where software you built or supplied does not perform and causes the client a financial loss.
- Breach of contract and failure to deliver — including missed milestones and specification disputes, subject to the wording.
- Intellectual property infringement — an inadvertent breach of copyright or third-party IP in what you deliver.
- Breach of confidence and unintentional breach of duty — increasingly relevant where you handle client data or systems.
Many technology wordings also bundle a measure of public liability and, importantly, an element of cyber cover. That overlap is where a lot of contractors get caught out, so it is worth understanding properly.
Why your clients and contracts demand it
Most IT contractors do not buy PI because they lie awake worrying about being sued. They buy it because they cannot win the work without it. Three contractual pressures drive almost every enquiry we see:
- Client procurement and MSAs. Enterprise and public-sector clients routinely require a stated limit of indemnity — commonly a minimum professional indemnity figure written into the master services agreement — before they will let you onto a project. No certificate, no purchase order.
- Agency and umbrella contracts. If you contract through a recruitment agency, the agency's terms will usually specify PI, public liability and often employers' liability limits. The agency is protecting itself and the end client, and it will not chase your renewal for you.
- IR35 and the perception of being a genuine business. Since the off-payroll reforms, being demonstrably in business on your own account matters. Carrying your own professional indemnity cover, invoicing under your own limited company and holding your own insurances all form part of the picture that distinguishes a genuine contractor from a disguised employee. PI is not an IR35 silver bullet, but its absence is conspicuous.
The practical takeaway: read the limit and the wording your client demands, not just the headline figure. We regularly see contractors under-insured against their own contracts because the MSA asked for a specific aggregate limit and the off-the-shelf policy only offered it on an each-and-every-claim basis, or vice versa.
The cyber overlap — and where PI stops
Technology and cyber risk sit next to each other, and the line is blurred by design. A tech PI policy may pick up a third party's financial loss that flows from your professional failure — including some situations where a security weakness in your work harms the client. What a PI policy is generally not built to do is respond to your own first-party cyber event: ransomware on your systems, business interruption while you rebuild, breach notification costs, regulatory response and the cost of restoring your own data.
For a solo contractor with a laptop and a GitHub account, the residual first-party exposure may be modest. For a firm hosting client environments, holding personal data or running a SaaS product, it is often material, and a standalone cyber policy alongside your PI is the sensible structure. The value of a broker here is mapping the two wordings against each other so there is no gap and no wasteful overlap. That is a conversation your named Apex broker will have with you rather than leaving you to reconcile two policy documents at 11pm.
Getting the limit, retroactive date and run-off right
Three technical points decide whether your cover actually works when you need it:
- Limit of indemnity. Set it against your largest contract's requirement and the realistic size of a claim, not the cheapest quote. Under-insuring to hit a price is a false economy the day a client alleges a six-figure loss.
- Retroactive date. PI is written on a claims-made basis. If you have been trading and switch insurer, you need continuous cover back to when the work was done, otherwise historic projects fall into a gap.
- Run-off cover. When you close the company, retire or move permanently inside IR35 as an employee, claims can still arrive for years. Run-off cover keeps you protected for past work after you stop trading.
Who we help
We place cover for independent contractors, IT and management consultancies, software developers, systems integrators, MSPs and digital agencies. If your work is more advisory than technical, our IT consultants' PI insurance in Cardiff and IT consultants' PI insurance in Swindon pages cover the consultancy angle in more detail, and the same brokers handle national enquiries. Firms that straddle IT and management advisory may also want our management consultants' PI guidance, while agencies delivering digital and creative work can read our marketing agency PI page. You can see the full range of professions we cover on our sectors page.
Frequently asked questions
Is professional indemnity insurance a legal requirement for IT contractors?
No, there is no statutory requirement, but it is almost always a contractual one. Client master services agreements, agency terms and umbrella arrangements routinely require a stated PI limit before you can start work, so in practice most contractors cannot trade without it.
What is the difference between tech PI and tech E&O?
They are essentially the same thing. Errors & omissions (E&O) is the term used in much of the technology market for professional indemnity cover. UK policies are usually branded as professional indemnity or combined technology PI, and often bundle elements of public liability and cyber.
Does PI cover a cyber attack or data breach?
Only partially. PI may respond to a third party's financial loss arising from your professional failure, but it is not designed to cover your own first-party costs such as ransomware, breach notification, regulatory response or restoring your own data. Most tech firms hold PI and a standalone cyber policy together, and we will make sure the two do not leave a gap.
How does PI relate to IR35?
Holding your own PI cover is one of several factors that show you are genuinely in business on your own account, alongside invoicing through your own company and carrying your own insurances. It is not decisive on its own, but its absence can weaken the argument that you are a bona fide contractor.
I am closing my limited company — do I still need cover?
Very likely, yes. PI is claims-made, so a claim about past work can arrive years after you deliver it. Run-off cover keeps you protected for historic projects after you stop trading, and we can arrange it as part of winding down.
Can you cover a firm that both consults and builds software?
Yes. Combined technology PI wordings are designed for mixed activities. The key is describing your full range of services accurately at placement so nothing important is excluded, which is exactly the sort of detail your named broker will work through with you.
Get a quote / Speak to a broker
Tell us what you do, the limits your contracts demand and where your cyber exposure sits, and we will place it against the right markets. Start with a quote request, use our commercial quote form for combined or bundled cover, or contact the team to speak to a named, director-level broker. With access to more than 30 professional-lines insurer markets and around 95% client retention, we place technology PI that actually matches your contracts.
