FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
MSPs & IT Support

MSP professional indemnity insurance UK

In short: Professional indemnity is the policy that stands behind an MSP’s promises. When a client alleges that a missed backup, a botched migration or a security failure on your watch caused them loss, PI funds the defence and pays what you legally owe. In the US market the same product is called tech E&O. It is not required by statute — the pressure comes from client contracts — and for an MSP the hard questions are all about limits: what one incident could cost when it touches many clients at once.

What MSP PI actually responds to

PI covers claims for financial loss arising from your professional services. For an MSP the recurring patterns are familiar to anyone who has run one: the backup that was quietly failing for months and was discovered the day it was needed; the migration that corrupted a line-of-business database; the firewall or email security change that opened a door; the patch pushed through RMM that took a client’s production system down; advice that turned out to be wrong. In each case the client’s allegation is the same shape — you were the experts, we relied on you, and your failure cost us money — and PI is the policy built for that shape.

It pays defence costs as well as damages, which matters more than it sounds: many technology disputes are arguments about causation and scope that cost real money to fight even when you win.

Contractual, not statutory

No law requires an IT business to carry PI. What requires it, in practice, is the market: master services agreements, framework tenders and partner programmes that will not proceed without evidence of cover at a specified limit. That distinction matters because it puts your contracts, not a regulator, at the centre of limit decisions — the starting question is always what you have already promised, and to whom.

Liability caps and the MSA

A well-drafted MSA is an MSP’s first and cheapest risk-management tool. Limitation of liability clauses, exclusions of consequential loss and clearly defined scopes of service all shrink the target a claimant can aim at. But caps are a defence, not a guarantee: they can be attacked as unreasonable, they may not bite on every kind of claim, and a cap negotiated years ago may bear no relationship to what the client relationship has become. PI exists for the distance between what the contract says and what a court, or a settlement, eventually decides. A broker who reads your MSA alongside your policy is checking that the two documents tell the same story.

The aggregation problem: one incident, many clients

The question that should drive an MSP’s limit is not “what could one client claim?” but “what could one event generate across every client it touched?” A single compromised admin credential, a bad update pushed to an entire client base, a shared platform failure — these produce multiple simultaneous claims arising from one root cause. How the policy treats that scenario turns on wording: whether the limit applies to each and every claim or in the aggregate, and how related claims arising from one originating cause are counted. Two policies with the same headline limit can behave very differently here, and the difference only becomes visible on the worst day. This is wording work, and it is where a specialist broker earns their keep.

Claims-made cover and retroactive dates

PI is written on a claims-made basis: the policy in force when the claim arrives is the one that responds, however long ago the work was done. Two practical consequences. First, continuity matters — a gap in cover can leave years of past work uninsured, permanently. Second, the retroactive date on the policy needs to reach back over the work you have actually done, especially when switching insurers. Both are easy to get right at placement and impossible to fix after a claim.

How Apex places MSP PI

We describe the firm properly — services, contracts, client concentration, tooling, security posture — and put it to insurers whose technology wordings we know. We argue about the parts that matter: aggregation language, retroactive cover, cyber interfaces, defence costs. And we sanity-check the limit against your contracts and your real exposure rather than defaulting to the figure on last year’s schedule. PI is one layer of the stack; how it meets your own-breach cover is covered on our MSP cyber insurance page, and the who-pays-what scenario is walked through in MSP liability when a client is breached.

Frequently asked questions

Is MSP professional indemnity written on a claims-made basis?

Almost always. The policy that responds is the one in force when the claim is made against you, not when the work was done — which is why continuous cover and a retroactive date that reaches back over your past work both matter. Letting PI lapse between renewals can leave old work permanently uninsured.

Does our PI cover our own systems being breached?

No. PI responds to claims by clients alleging your work caused them loss. Your own breach — the response costs, the forensics, the downtime — is the job of your own cyber policy. The two often end up working the same incident from different ends, which is a good reason to arrange them together.

If our MSA caps our liability, can we buy less PI?

Treat that logic with caution. Caps can be challenged, may not apply to every head of loss, and some claims arrive from angles the cap does not cover. The cap is your first line of defence and the PI limit is what stands behind it if the first line does not hold — they are complements, not substitutes.

How much PI cover does an MSP need?

There is no single figure. The honest inputs are your client contracts’ requirements, the size and concentration of the clients you serve, and the aggregation question — what a single bad event could cost across every client it touched. Many MSP contracts specify £1m or £2m as a floor; whether that is actually enough for your book is a conversation, not a default.

Get your PI limit stress-tested
Bring us your MSA and your schedule — we’ll tell you whether they tell the same story. Bristol-based, FCA-regulated.
Get a quote  info@apexinsurancebrokers.co.uk

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.

Want a broker to look at your commercial cover?
If you have your renewal pack, Statement of Fact or schedule, send it over and we’ll come back with options — no forms to fill in. Arranging cover for the first time? That works too. Or call 0117 325 0027.
Start a commercial quote →
Larger or multi-site risk? We’ll come and see you.
Get a quote →