IT and telecoms
Yes. If you manage IT projects for clients, as a contractor, consultant or delivery firm, you need professional indemnity insurance. When a system goes live late, over budget or not at all, the client looks for someone whose planning, reporting or judgement it can blame, and the project manager is first in line. Public liability does not touch those financial losses. PI defends the allegation and pays compensation if it succeeds, subject to the policy terms.
Part of: Professional indemnity for IT professionals
In short
IT project managers are rarely blamed for writing bad code. They are blamed for what the client says they should have seen coming: an unrealistic plan, risks missing from the log, a go-live approved before testing finished, or status reports that stayed green until the money ran out. Those are allegations of professional negligence, and PI is usually the cover that responds. Methods such as PRINCE2 and agile frameworks don’t create legal duties, but they shape what an expert treats as competent practice. Your exposure also depends on your role: advising a client’s team is very different from owning delivery under a fixed-price contract.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
A project manager’s product is control: the plan, the budget, the risk log, the status report and the recommendation on whether to proceed. Clients make funding and go-live decisions on the strength of that work. When a project fails, the loss is wasted spend, delay, extra supplier charges and benefits that never arrive, and the client’s question is whether its project manager should have seen it and said so.
That is a complaint about professional skill and care. Public liability insurance covers injury and property damage, so it has nothing to offer. Professional indemnity (PI) insurance covers your legal liability for financial loss caused by negligent advice or services, plus the cost of defending the allegation, subject to the policy terms.
Your contract decides how far the duty reaches. A project manager placed in a client team through an agency, a consultancy running a programme management office and a delivery firm that has agreed a fixed price are judged by very different promises. Know which one you are before you sign, and make sure your policy describes it.
The examples below are illustrative. They show common allegations against IT project managers, not real claims or outcomes.
In each case the allegation is that you did not manage, report or escalate as a competent IT project manager would.
Most project disputes eventually focus on a handful of decision points, and the go-live decision is the biggest. If you can show what the criteria were, what you knew, what you recommended and who decided, you are in a far stronger position than a project manager relying on memory.
None of this stops a claim being made. It is what turns a long, expensive defence into a short one, and a well-documented file also helps your insurer when deciding whether to fight or settle.
No single method is a legal standard, but an expert asked whether you acted competently will compare your work with the frameworks you claimed to follow and with recognised practice.
| Reference point | What it is | Why it matters to your PI |
|---|---|---|
| PRINCE2 7 | The current edition of the PRINCE2 project method, launched in 2023, with a stronger focus on people and on working alongside agile. | If your contract or project initiation document says you will run the project under PRINCE2, its controls become the yardstick. |
| APM Code of Professional Conduct (November 2024) | The Association for Project Management holds a Royal Charter. Its code requires members to claim expertise only where their skills are demonstrably adequate, declare conflicts, and be accurate in reporting. | Reporting and conflicts sit at the heart of many project disputes. |
| ISO 21502:2020 | International guidance on project management, covering predictive, iterative, agile and hybrid approaches. It is currently being revised. | A neutral reference point an expert may use to describe good practice. |
| Government Functional Standard GovS 002: Project delivery (v2.1, September 2025) | The approved reference for project, programme and portfolio management in government departments and arm’s length bodies. | On government work, your governance and assurance will be compared with it. |
| GOV.UK Service Standard | Fourteen points for government digital services. Transactional central government services must be assessed against it. | A failed assessment can delay go-live, and the client may say your plan ignored it. |
Agile delivery doesn’t remove the duty to use reasonable care and skill. It changes the evidence: the backlog, sprint reviews and acceptance criteria replace the stage plan, so keep them as carefully as you would a Gantt chart.
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Negligent planning, estimating and risk management | Promises of a fixed outcome or a guaranteed go-live date | Injury or property damage at a client’s site (public liability) |
| Inaccurate status reporting that the client relied on | Liquidated damages for late delivery under a fixed-price contract | Injury to your own employees (employers’ liability) |
| Careless supplier evaluation or procurement advice | Disputes about your own fees, and refunds | An attack on your own laptop or systems (cyber) |
| Errors in cutover, migration and rollback planning | Faults in software or hardware you supplied | Claims against you as an appointed director of the client (D&O) |
| Defence costs, including project forensic experts | Circumstances you knew about before the policy started | Recovering unpaid fees (commercial legal expenses) |
Cover is always subject to the insurer’s acceptance and the policy terms. If you subcontract work to other project managers, testers or developers, declare it: the policy usually covers your liability for their work only if the insurer knows about it.
IT projects move data. Migrations, test environments and temporary access accounts all put personal data in places it does not normally live, and a leak from a test copy or a migration extract is a data breach like any other.
When the client is the controller and your firm handles its data, UK GDPR Article 28 requires a written contract under which you act only on the client’s documented instructions and, at the client’s choice, delete or return its personal data when the work ends. Project closure is when that last step is easiest to forget.
Some project firms hold only PI. If you handle client data on your own devices or systems, ask for cyber to be quoted alongside it, and check that neither wording excludes the claim the other expects to pay.
The limit is normally set by the client’s contract or the agency’s terms. Size it against the budget at risk on your largest project, not your fee: a project manager earning a day rate can still be blamed for millions of overspend. Check whether the contract asks for each and every claim or aggregate cover; they are not interchangeable.
PI is written on a claims-made basis, so the policy in force when the claim is made responds. Project claims often arrive late, when a post-implementation review or the next supplier uncovers what went wrong. Keep your cover continuous between contracts, keep the same retroactive date when you change insurer, and buy run-off if you retire or close your company. Our guide to claims-made and occurrence PI explains why this matters.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for IT project managers, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Yes, if you manage IT projects for clients. When a project overruns or a go-live fails, clients look at the project manager’s planning, reporting and judgement. PI pays defence costs and compensation for allegations of negligence, subject to the policy terms. Public liability does not cover these financial losses.
No UK law requires IT project managers to hold PI. In practice clients, agencies and public sector buyers write it into contracts, often with a minimum limit and sometimes a requirement to keep cover for several years after the work ends.
Not automatically. The supplier is responsible for its own performance. The question for you is whether you planned, monitored, reported and escalated as a competent project manager would. Clear records of the warnings you gave make a claim much easier to defend, and PI usually pays for that defence.
Usually, if the allegation is that your recommendation was negligent, subject to the policy terms. It is much easier to defend if the go-live criteria, open defects and the sponsor’s decision were written down. A contractual guarantee that go-live would succeed may not be covered.
Agile changes how scope and acceptance are agreed, not the duty to use reasonable care and skill. Make sure the contract reflects an agile approach, rather than a fixed scope at a fixed price, and keep the backlog, sprint reviews and acceptance decisions as your evidence.
Only if the retroactive date goes back far enough. A policy with a retroactive date of its start date covers nothing done before then. If you had PI before, keep the same retroactive date when you switch insurer so your earlier projects stay protected.
Apex arranges professional indemnity insurance for IT project managers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.