FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

Technology professional indemnity insurance explained

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06

In short: Technology professional indemnity insurance (tech PI, also called technology errors & omissions or tech E&O) covers your legal defence costs and any damages if a client alleges that your technology work, advice, software or service failed and caused them financial loss. It is written for firms that both advise and build, so it responds to product and code failures as well as professional negligence.

If you build software, run a managed service, resell hardware, consult on architecture or contract as a developer, this is probably the single most important insurance you buy after Employers' Liability. It is the cover that stands between an unhappy client's claim and your own bank balance. This page walks through what technology professional indemnity actually does, why the ordinary "advice-only" version most professions buy tends to leave IT firms exposed, and how to think about the cover you need.

What does technology professional indemnity insurance actually cover?

Professional indemnity insurance exists to answer one question: what happens when a client says your work caused them a loss? For a technology firm, that allegation can arrive in a lot of shapes. A migration overruns and the client says the downtime cost them revenue. A piece of code you wrote has a defect that corrupts a customer database. Your advice on a platform choice turns out, the client argues, to have been negligent. A SaaS feature behaves differently from what the statement of work described.

Tech PI is designed to respond to those situations. Broadly, a policy will fund:

The crucial point is that the trigger is an allegation of a failing in your work — negligence, error, omission, breach of professional duty, or in tech wordings a failure of the technology product or service itself. You do not have to have actually been negligent for a claim to land and cost you money to see off. That is exactly why the defence-costs element matters so much.

Is tech PI the same thing as technology errors & omissions (E&O)?

Yes — broadly, they are the same product under two names. "Professional indemnity" is the term used in the UK. "Errors and omissions", or E&O, is the American term for essentially the same cover. If a US client, parent company or contract asks you to hold "technology E&O insurance", they are asking for the same category of protection a UK broker would call technology professional indemnity. You do not need to buy both as if they were separate things. What does matter is reading the specific wording, because the label tells you far less than the covered perils, exclusions and limits do.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Not sure whether your current PI actually covers the software and services side of what you do? That is exactly the question we help IT firms answer every week.

Get a tailored quote →

Why is standard "advice-only" PI often inadequate for a tech firm?

Most professional indemnity policies were designed around advisers — accountants, consultants, surveyors — whose work product is essentially guidance and documents. Their exposure is that they said the wrong thing. A generic PI wording written on that model protects you when your advice is negligent, and stops there.

The trouble is that a technology firm rarely just advises. You deliver a thing. You ship code, configure infrastructure, host an application, integrate systems, resell and implement someone else's product. When a claim comes, the client is usually complaining that the deliverable failed to work as promised — the software crashed, the integration lost data, the platform was unavailable — not merely that you gave poor counsel. A pure advice-only wording can leave a genuine argument about whether the loss flowed from your "professional advice" at all, which is precisely the wrong argument to be having with your insurer while a client is chasing you for damages.

Technology professional indemnity is written to close that gap. A proper tech PI wording is built to include the products, software and services dimension of what you do, so it responds whether the failure is characterised as bad advice or a defective deliverable. That single distinction is the reason a tech firm should not simply buy the cheapest "PI insurance" box on a comparison site and assume it fits.

Is technology PI a legal requirement, or just something clients ask for?

Professional indemnity is not a statutory legal requirement for IT firms — there is no law compelling a software house or IT contractor to hold it. In practice, though, it is almost always a contractual requirement. Enterprise clients, public-sector frameworks, recruitment agencies and prime contractors routinely make a stated level of PI — commonly £1m, £2m or £5m — a condition of signing. So while nobody will prosecute you for not having it, a great many contracts simply will not proceed without it, and you may be in breach if your cover lapses mid-engagement.

It is worth being precise here, because the requirements get conflated. The insurance the law does compel is Employers' Liability: under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you must hold it, with only narrow exceptions (such as some family-only or single-director companies). If you are a limited company with employees, that one is not optional. Professional indemnity, by contrast, is driven by your contracts and your own risk appetite — but for a working IT firm those two forces usually point firmly towards holding it anyway.

Does insurance have anything to do with my IR35 status?

No — and this is worth stating plainly because it comes up constantly with contractors. IR35, the off-payroll working rules, is a tax matter about whether HMRC regards you as employed or self-employed for tax purposes. Holding professional indemnity, or any other insurance, does not change, improve or determine your IR35 status. Insurers sometimes market "IR35 cover" meaning help with the costs of an enquiry, but no policy makes you "outside IR35". Your status turns on the reality of your working arrangements, and the right person to advise on it is a qualified accountant or specialist tax adviser — not your broker. What we can do is make sure that, whatever your status, the professional risks of the actual work are properly covered.

Where does tech PI stop and cyber insurance begin?

This is the boundary that catches people out. Technology PI is about liability to your clients for the performance of your work. Cyber insurance is about your own exposure to a security incident or data breach — whether that hits you or, through you, third parties. They overlap at the edges but they answer different questions, and most technology firms genuinely need both.

Cyber insurance is typically there to fund the response to an incident — forensic investigation, breach notification, legal and PR support — along with business interruption from downtime and third-party liability where others are affected. One thing to be careful about: whether UK regulatory fines under UK GDPR and the Data Protection Act 2018 can be insured at all is legally uncertain, and policies commonly exclude or restrict them. Do not assume cyber cover will simply pay a fine from the Information Commissioner's Office (ICO); treat cyber as funding breach response and liability, and take any specific fine question on its own facts. Many IT firms end up holding tech PI and cyber together, sometimes on a combined technology wording, so there is no gap where each insurer points at the other.

We go deeper on this in professional indemnity vs cyber insurance for tech companies and in our overview of cyber insurance explained.

What drives the cost of technology professional indemnity?

There is no single price, and any figure quoted without knowing your business is guesswork. What an underwriter actually weighs includes:

Because PI is almost always written on a claims-made basis, one further factor matters more than most realise: continuity. A claims-made policy responds to claims made during the period it is in force, regardless of when the work was done — so letting cover lapse can strip protection from years of past projects. Keeping cover live, and maintaining "retroactive" cover back to when you started trading, is central to getting the value out of it.

Whether you are meeting a client's contract requirement or building cover from scratch, an Apex specialist will size the limit and wording around the work you actually do.

Get a tailored quote →

How much cover do I actually need?

Start with your contracts. If clients specify a required PI limit, that sets your floor — you cannot sign for £5m of cover you do not hold. Above that floor, the sensible question is the size of the worst realistic claim: not the value of a single invoice, but the downstream loss a client could argue your failure caused them, plus the defence costs of fighting it. For many independent contractors a £1m limit satisfies most agency and end-client requirements; firms delivering larger or more critical systems often carry £5m or £10m. Limits like these are illustrative options, not a recommendation — the right number is the one that matches your contracts and your exposure, which is a conversation worth having rather than a box to guess at.

It is also worth thinking of PI as one part of a programme rather than a standalone purchase. Most technology businesses pair it with public liability, Employers' Liability where they have staff, and cyber. Our guide to what insurance an IT company needs maps how the pieces fit, and IT contractor insurance covers the specifics for independent contractors.

Getting it right for your firm

The through-line of everything above is that technology professional indemnity rewards precision. The label on the policy tells you little; the wording, the covered perils, the retroactive date and the limit tell you almost everything. A firm that ships software and services needs a wording built for that reality, not an advice-only template borrowed from another profession — and it needs to sit sensibly alongside cyber and the rest of the programme rather than leaving a seam between them.

That is the work we do for IT and technology businesses at Apex: reading the contract you have been handed, translating what the client is really asking for, and placing a policy that responds when it matters. If you would rather talk it through than fill in a form, speak to an Apex specialist and we will start from what your business actually does.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →