FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

Salesforce consultant insurance: cover for UK consultants, partners and admins

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06

In short: UK Salesforce consultants, partners and admins typically need technology professional indemnity (tech PI) insurance for claims arising from implementation errors, failed migrations or automation faults that cost a client money, plus cyber insurance because admin access to client orgs concentrates data risk. Neither is required by law, but client MSAs and partner-ecosystem procurement almost always demand stated limits. Employers’ liability becomes a legal requirement once you hire staff.

What insurance does a Salesforce consultant actually need?

If you implement, customise or administer Salesforce orgs for clients — whether as an independent consultant, a consulting partner or a contract admin — your insurance needs cluster around three covers. Technology professional indemnity (tech PI) responds when a client says your work caused them financial loss. Cyber insurance responds when something goes wrong with data or systems — a real concern when you routinely hold admin credentials to other people’s CRM environments. And employers’ liability becomes relevant, and in most cases legally required, the moment you take on staff.

One point of terminology before we go further, because it trips people up when reading contracts from US-headquartered clients: technology professional indemnity and technology errors & omissions (tech E&O) are broadly the same product. E&O is simply the American name. If a US client’s master services agreement demands “errors and omissions insurance” and your UK policy says “professional indemnity”, you are almost certainly looking at the same cover — though it is worth checking that your policy’s jurisdiction and territorial limits actually extend to where your clients are.

None of this is a statutory requirement for consultancy work. Professional indemnity is a contractual requirement, imposed by clients, agencies and procurement teams — and in the Salesforce ecosystem, those requirements are unusually consistent and unusually firm, for reasons we’ll come to.

Why is a botched deployment or failed migration a professional indemnity claim?

Because Salesforce work sits directly on top of a client’s revenue engine. When something you built misbehaves, the loss is rarely abstract — it shows up in their pipeline, their invoicing or their customer relationships, and it is measurable in pounds. That is exactly the kind of loss a professional indemnity claim is made of.

Consider the failure modes specific to this work. A data migration maps a field incorrectly and thousands of records land in the new org with corrupted values — or worse, a truncation or deduplication step silently drops records that only surface as missing weeks later, after the legacy system has been decommissioned. A flow or automation you built fires against the wrong record set and sends incorrect renewal pricing to a client’s entire customer base. An integration you configured between the org and a client’s finance system double-posts invoices, or stops syncing without anyone noticing until month-end reconciliation fails. A deployment pushes changes to production that overwrite validation rules or sharing settings, exposing records to the wrong internal teams. None of these require negligence in the everyday sense of carelessness — complex org work has many moving parts, and a defensible mistake can still produce a very real client loss and a very real claim.

Tech PI is designed for precisely this: it covers your legal defence costs and any damages you become liable to pay when a client alleges your professional work fell short. For a consultancy whose entire deliverable is configuration, code and data, it is the foundational cover.

Does admin access to client orgs create cyber exposure?

Yes — and it is the reason we treat Salesforce specialists differently from many other IT contractors. A typical consultant holds system administrator or near-admin access to one or more client orgs at any given time. Each of those orgs is likely to contain personal data on customers, prospects and staff, plus commercially sensitive pipeline and pricing information. Your credentials, your laptop and your own email account become a route into all of it.

Think about how that goes wrong in practice. A phishing email harvests your login and an attacker exports a client’s contact database before anyone notices. A data extract you pulled for migration testing sits unencrypted on a stolen laptop. A connected app or integration user you set up with broad permissions is compromised months after the project ended because nobody deprovisioned it. In each case the data belongs to your client, but the incident traces back to you — and your contract will usually make clear whose problem that is.

A good cyber policy funds the response: forensic investigation, legal advice on notification obligations under the UK GDPR and the Data Protection Act 2018, communication with affected individuals, and liability to third parties who suffer loss. It can also cover your own business interruption if an attack takes your systems down mid-project. One thing to be clear-eyed about: whether regulatory fines from the Information Commissioner’s Office can be insured is legally uncertain in the UK, and policies commonly exclude or restrict them. Treat cyber insurance as funding the response and the liability, not as a way to pay a fine — we cover this in more depth in our guide to how cyber insurance works.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Apex arranges tech PI and cyber cover for Salesforce consultants and partners across the UK — tell us what you build and who you build it for, and we’ll match the cover to your contracts.

Get a tailored quote →

What insurance do client MSAs and partner procurement usually require?

This is where most Salesforce consultants first go looking for insurance: a contract lands and clause after clause of insurance requirements lands with it. End-client master services agreements routinely require professional indemnity at a stated limit — £1m is a common floor, with £2m or £5m appearing on larger enterprise engagements — and increasingly cyber cover at a stated limit too. If you subcontract to a larger consulting partner or a systems integrator, their procurement team will typically flow the same requirements down to you before you can start, and will ask for evidence in the form of a certificate or confirmation from your broker.

Two details are worth watching in these clauses. First, retroactive cover: PI policies work on a claims-made basis, meaning the policy in force when the claim arrives is the one that responds — so contracts often require you to maintain cover for a period after the project ends, and letting a policy lapse can leave past work unprotected. Second, territorial and jurisdictional scope: if the end client is US-based, check that your policy doesn’t exclude claims brought in North American courts, because plenty of standard UK wordings do unless extended.

To be precise about one thing: these are contractual requirements between you and your clients or the firms you subcontract to. Carrying insurance is not a condition of using or working with the Salesforce platform itself, and holding a policy implies no endorsement by anyone — it is simply what the buyers of this kind of work demand before they let you into their org.

Should I buy tech PI and cyber separately or combined?

For Salesforce work specifically, there is a strong practical argument for a combined technology policy that packages PI and cyber under one insurer. The reason is that the claims you are most exposed to often refuse to sit neatly on one side of the line. Suppose records are lost during a migration: is that a professional error (a PI matter) or a data incident (a cyber matter)? If your integration user is compromised and client data leaks, the client may frame it as both negligent configuration and a breach. With two separate insurers, you risk each pointing at the other while you sit in the middle; with a combined policy, one insurer owns the whole claim.

Combined policies also tend to be simpler to evidence against MSA requirements, since a single schedule shows both limits. We’ve written a fuller comparison in our guide to combined technology insurance. Separate policies can still make sense — for instance if you already hold strong standalone cyber cover, or a client mandates a specific structure — which is exactly the kind of judgement call a specialist broker earns its keep on. If you’d rather talk it through than fill in a form, speak to an Apex technology specialist and we’ll map your contracts to a structure that works.

I’m hiring my first admin or developer — do I legally need employers’ liability?

Almost certainly, yes. Unlike PI and cyber, employers’ liability insurance is a legal requirement under the Employers’ Liability (Compulsory Insurance) Act 1969 once you employ staff, with only narrow exceptions — for example, some limited companies whose only employee is a director holding a majority of the shares. If your consultancy is growing from a one-person practice into a small partner team, EL needs to be in place from the first hire, and it can also matter for arrangements that look informal but count as employment in practice, such as a junior admin you pay through payroll. The position of genuinely self-employed subcontractors is different, but the boundary is not always obvious, so it is worth checking rather than assuming.

Growing teams usually also pick up public liability at the same time — not because config work is physically dangerous, but because client site visits, workshops and on-site go-lives create the ordinary third-party injury and property risks that client facilities teams expect you to be covered for. For the wider picture of how these covers fit together as a consultancy scales, see what insurance an IT company needs.

Does holding insurance affect my IR35 status?

No — and it is important to be straight about this, because the two topics get muddled. IR35 (the off-payroll working rules) is a tax matter: it concerns whether your engagement would look like employment for tax purposes if the intermediary were stripped away. Holding professional indemnity or any other insurance does not change or determine that status. What is true is that clients and agencies commonly require contractors to carry PI regardless of how an engagement is taxed, so you may well need cover on both inside- and outside-IR35 contracts. For the status question itself, take advice from a qualified accountant or tax adviser rather than an insurance broker — that is their lane, and this is ours.

What limit of cover should a Salesforce consultant choose?

Start with your contracts, because they set the floor: if your biggest client’s MSA demands £2m of PI, that is your minimum. Beyond that, think about the realistic worst case in your actual work rather than a generic rule of thumb. The factors that push limits up for Salesforce specialists include the size of the orgs you touch (a migration for an enterprise client with hundreds of thousands of customer records carries more downside than a five-seat startup org), how close your work sits to revenue (CPQ, billing and quoting automation can turn a defect directly into mispriced sales), the volume of personal data involved, and whether any of your end clients are in the US. Illustrative limits of £1m, £2m and £5m are the common shapes we place, but the right answer comes from your contract stack and your project profile, not a table.

The same logic drives what cover costs: insurers price on your fee income, the nature of the work, the limits and excess you choose, your claims history, and the security practices you can evidence — things like MFA on all org logins, least-privilege access and prompt deprovisioning genuinely matter to cyber underwriters. Getting those basics documented before you approach the market tends to be rewarded.

Why arrange cover through Apex?

Because generalist policies and Salesforce work are a poor match. A wording written for a management consultant may sit awkwardly over data migration, automation and integration work; a form-filled online policy may quietly exclude the US jurisdiction your biggest end client sues in. Apex is an independent, FCA-authorised broker based in Bristol, and technology firms are the core of what we do — we read your MSAs and subcontract flow-downs, match wordings to the failure modes of platform consultancy, and give your clients’ procurement teams the evidence they ask for without back-and-forth. When a claim or a circumstance arises mid-project, you deal with a broker who understands what a sandbox, a deployment and an org actually are.

Whether you’re an independent admin signing your first MSA or a consulting partner scaling a delivery team, Apex will build a tech PI and cyber programme that matches how you actually work.

Get a tailored quote →

Salesforce is a trademark of Salesforce, Inc. Apex Insurance Brokers Limited is an independent insurance broker with no affiliation to, or endorsement from, Salesforce, Inc.; references to the platform are made solely to describe the work our clients do.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →