FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

IT integration

Professional indemnity insurance for systems integrators

Yes. If you connect several vendors’ systems so that they work as one, you need professional indemnity insurance, because you are often the only party contracted to make the joins work. When an interface drops orders, a mapping corrupts data or an integration fails at cutover, the client’s loss is financial, which public liability does not cover. PI covers claims that your design, build or running of the integration was negligent, including work you subcontracted, subject to the policy terms.

In short

Systems integrators carry the risk in the spaces between other people’s products. Each vendor may be able to show its own system worked as documented, which leaves the integrator answering for the interface. As prime contractor you are usually liable to the client for your subcontractors, and for personal data UK GDPR Article 28(4) keeps an initial processor fully liable to the controller for a sub-processor’s obligations. Back-to-back subcontracts narrow that gap but rarely close it. The Civil Liability (Contribution) Act 1978 lets you seek a share from others liable for the same damage. PI answers negligence claims; cyber covers attacks on the integration layer you run.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

Why systems integration needs PI

Last reviewed 5 October 2026 by the Apex professional indemnity team.

An integrator’s job is to make separately bought systems behave as one: an online shop talking to a warehouse system, a CRM feeding finance, identity flowing to every application. You design the integration architecture, specify each interface, build or configure the middleware, run end-to-end testing and manage cutover. Often you also lead the other suppliers as prime contractor.

The client’s exposure sits in the joins. When data moves wrongly or stops moving, orders are lost, customers are billed twice or operations halt, and the loss is financial. Public liability (PL) insurance responds to injury and property damage, so it does not help. The allegation is that you designed, built or ran the integration without reasonable care and skill, and professional indemnity (PI), which technology insurers write as errors and omissions cover, is the policy for it.

How claims arise for systems integrators

The scenarios that follow are illustrative only; none describes a real claim. Each names the failure, the party that lost money and the allegation.

  1. Retries that doubled the orders. When the warehouse system is slow to acknowledge, your middleware resends orders without checking whether they were already received. Hundreds of orders ship twice before anyone notices. The retailer claims the cost of returns and write-offs, alleging your interface design had no protection against duplicates.
  2. A time field nobody owned. A field service platform sends appointment times in UTC and the scheduling system reads them as local time. All summer, engineers arrive an hour out and the client pays penalties to its own customers. Both vendors show their systems behaved as documented, and the client says the mapping was yours.
  3. A subcontractor’s component, your liability. You subcontract the mobile app integration to a specialist firm whose code exposes session tokens. Customer accounts are accessed and the client claims against you as prime contractor. The subcontract caps the specialist’s liability at its fee, leaving most of the loss with you.
  4. A retired API version. Under your managed integration service, a vendor gives notice that an API version will be withdrawn. Your team misses it, the integration fails on a Monday morning and orders stop flowing for two days. The client claims its lost sales.
  5. A stock feed that failed at cutover. After a weekend go-live, the feed between warehouse and website stops. The site keeps selling items that are out of stock, and the client claims the cost of cancellations, goodwill vouchers and extra customer service.

None of these involves a single faulty product. Each concerns the design, running or supervision of the connections between products, which is the integrator’s professional territory.

The contracts, law and standards integrators work under

Integration disputes are decided mainly by contracts, because several sets of terms meet at every interface.

Reference pointWhat it saysWhy it matters to you
Your head contract with the clientYour scope, the interfaces you own, acceptance, the liability cap and which vendor answers for what.If it does not say who owns each interface, expect the client to argue that you do.
Your subcontractsThe obligations you pass down to specialist suppliers: scope, standards, caps, insurance, data protection and claims procedure.Every mismatch with the head contract is risk you keep.
UK GDPR, Article 28(2) and (4)A processor needs the controller’s prior written authorisation to engage another processor, must impose the same data protection obligations on it by contract, and remains fully liable to the controller for that processor’s performance.If a subcontractor handles personal data, its failure is yours to answer.
Civil Liability (Contribution) Act 1978, ss.1 and 2A person liable for damage can recover contribution from anyone else liable for the same damage, whether the liability arises in tort, contract or otherwise. The court sets an amount that is just and equitable having regard to each party’s responsibility.When a client sues you alone over a multi-vendor failure, this is how you seek a share from the others.
Contracts (Rights of Third Parties) Act 1999, s.1A non-party can enforce a term if the contract expressly allows it, or if the term purports to benefit them and the parties did not intend otherwise. They must be identified in the contract.Subcontracts often exclude the Act, so the client usually has no contractual route to your subcontractors and comes to you.
ISO/IEC/IEEE 15288:2023A common framework of system life cycle processes for acquirers and suppliers, applicable to systems of systems, without prescribing a particular life cycle model.A recognised reference for what disciplined integration and verification look like.

Who owns the join? Closing gaps at the interfaces

Each vendor’s contract describes its own product. The interface between two products is often described in nobody’s contract except yours, so close the gap on paper before it opens in production.

Where a client buys products directly and asks you only to connect them, say so in the contract and list the vendor obligations you are relying on.

Prime contractor: back-to-back terms and where they leak

As prime contractor you normally answer to the client for the whole delivery, including subcontracted work. Back-to-back terms pass the same obligations down the chain, but they rarely pass down all of the risk. Look for these leaks:

Tell your insurer how much work you subcontract. PI usually covers your liability for work done on your behalf where it is declared, and your insurer may later try to recover its outlay from the subcontractor.

What PI covers for integrators, and what it doesn’t

Usually covered by PIOften excluded or limitedNeeds a different policy
Negligent integration design, mapping and interface specificationLiquidated damages and service creditsAn attack on your own integration platform or network (cyber)
Your liability for subcontractors’ work, where declaredLiability accepted by contract beyond what the law would impose, such as uncapped indemnitiesFaulty hardware you resold (product liability)
Negligent cutover, end-to-end testing and go-live adviceDefects in third-party products themselvesInjury or damage at client sites (public liability)
Negligent running of a managed integration serviceRegulatory fines and penalties, commonly excludedClaims by your employees for injury (employers’ liability)
Defence costs, including independent expertsCircumstances known before the policy beganDishonesty by your employees that costs a client money (crime or fidelity cover)

Cover is subject to the policy terms and the insurer’s acceptance. If you resell hardware or licences, declare it: claims about a product’s own defects usually fall outside PI.

Integration platforms, downtime and cyber

The integration layer attracts attackers because it holds the service accounts and API keys that reach into every connected system. That shapes how PI and cyber fit together.

If one shared platform serves many clients, ask how each policy groups claims with a common cause. One incident can produce many claims against a single limit.

How much cover, and for how long

Your PI limit is usually set by the head contract and should sit at or above the liability cap you agree, bearing in mind that on some policies defence costs count towards the limit. When you subcontract, decide what limit each subcontractor must carry and check it before work starts. Read the clause for whether the limit applies to each and every claim or in the aggregate.

Integration defects can stay hidden until a year-end reconciliation or an audit. In England and Wales, a negligence claim for latent damage can be brought within six years of the cause of action accruing or, if later, three years from when the claimant first had the knowledge needed to sue, subject to a 15-year longstop from the negligent act or omission. PI is claims-made, so keep cover continuous, protect your retroactive date and arrange run-off cover if you sell or close the business.

What insurers will ask you

A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:

Speak to a broker

PI for systems integrators, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

Do systems integrators need professional indemnity insurance?

Yes. Clients rely on you to make separately bought systems work together, and a faulty interface, mapping or cutover can stop orders, corrupt data or halt operations. Those losses are financial, so public liability won’t cover them. PI pays defence costs and compensation when your integration work is alleged to be negligent, subject to the policy terms.

Is PI a legal requirement for systems integrators?

No UK law requires systems integrators to hold PI. In practice clients and public sector buyers make it a contract condition with a minimum limit, and if you work under another prime contractor, its head contract terms are usually passed down to you. Check the insurance clause before you sign.

Are we liable for our subcontractors’ mistakes?

Usually, as far as the client is concerned. As prime contractor you answer for the delivery, then seek recovery from the subcontractor under your subcontract. For personal data, UK GDPR Article 28(4) keeps you fully liable to the controller for a sub-processor’s obligations. PI generally covers liability for subcontracted work if you declare it.

What does back-to-back mean for our insurance?

Back-to-back means passing your head contract obligations down to subcontractors on matching terms. Where they don’t match, such as a lower cap or a shorter claims period, you carry the difference. PI covers your negligence liability, not extra obligations you accepted, so align terms and check subcontractors’ PI.

Can we share liability with the other vendors if the client sues only us?

Possibly. The Civil Liability (Contribution) Act 1978 lets a person liable for damage recover contribution from anyone else liable for the same damage, in a share the court finds just and equitable. Recovery is not guaranteed, so define each party’s responsibilities in the head contract and keep records of vendor failures.

Does PI cover downtime caused by an integration we built?

It can, if the downtime resulted from negligence in design, testing or operation and the client sues for the money it lost, subject to the policy terms. Service credits and liquidated damages are usually excluded. If the downtime was caused by an attack on a platform you run, your cyber policy also comes into play.

Ready to compare cover?

Apex arranges professional indemnity insurance for systems integrators across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.