Document type: Checklist Practice area: Corporate — Insurance and Risk Jurisdiction: United States Last reviewed: 5 September 2026
Section 1 — D&O structure
- Total programme limit, by layer, with carrier and attachment point mapped
- Dedicated Side A limit — amount, and whether it has difference-in-conditions and drop-down features
- Side B retention amount, and whether defence costs erode it
- Side C entity securities coverage, and whether it shares the limit with Side A
- Scenario test: in a securities class action plus derivative suit plus investigation, how much is realistically available to individuals?
- Insolvency test: if the company cannot indemnify, what responds?
- Limit modelled against the company's own worst case, not only peer benchmarking
Section 2 — Trigger and notice
- Definition of "claim" — does it include written demands, shareholder demand letters, books and records demands, subpoenas, formal orders, Wells notices, tolling requests?
- Notice standard: "as soon as practicable" vs a short fixed period
- Notice address and method for every layer, recorded in one table
- Extended reporting period: available, length, cost, trigger
- Notice of circumstances provision — present, and the standard it applies
- Related claims / interrelated wrongful acts definition, and how far back it can relate
- Prior knowledge and prior notice exclusions, and what they capture
Section 3 — Exclusions and severability
- Conduct exclusion trigger: final non-appealable adjudication in the underlying proceeding — not "final adjudication," not "in fact"
- Severability of exclusions — one insured's conduct not imputed to others
- Side A non-rescindable
- Severability of the application — signatories' knowledge only, not imputed to individuals
- Application incorporation limited to specified documents
- Bodily injury / property damage exclusion, with a carve-back for defence of derivative claims
- Prior and pending litigation date — as early as possible
- Professional services exclusion, and its interaction with any E&O policy
- Regulatory and specific-event exclusions added at renewal
Section 4 — Insured versus insured
- Derivative suits brought without the assistance or participation of an insured person — carved out
- Bankruptcy claimants: trustee, examiner, receiver, liquidator, creditors' committee, debtor in possession — carved out (the most important carve-out in the policy)
- Former officers and directors after a stated period
- Whistleblower and employment claims by insured persons
- Claims brought outside the US by a foreign representative
- Cross-claims and third-party claims within a covered proceeding
- Consider whether the narrower "entity versus insured" formulation is available
Section 5 — Allocation and defence
- Pre-agreed allocation for securities claims — typically 100% to covered loss where entity and individuals are both defendants
- Allocation method stated for non-securities claims
- Interim allocation pending final determination
- Advancement of defence costs during any allocation or coverage dispute
- Duty to defend vs duty to indemnify, and who controls
- Panel counsel requirement, and preferred firms added at placement
- Rate position resolved in writing before fees are incurred
- Litigation guidelines obtained and given to counsel at the outset
- Consent-to-settle standard and the hammer clause
Section 6 — The excess tower
- Provision-by-provision comparison across all layers obtained and read
- Notice provisions and addresses conformed
- Definition of "claim" and "loss" conformed
- Exclusions differing from the primary identified
- Arbitration and choice-of-law clauses identified — choice of law may be the most consequential provision
- Exhaustion language: does it permit exhaustion by payment "by the underlying insurers, by the insureds, or on their behalf"?
- Express statement that a below-limits settlement of an underlying layer does not prejudice attachment if the excess insurer is notified
- Drop-down on underlying insurer insolvency or refusal to pay
- Consent-to-settle requirements at each layer, and the practicality of obtaining all of them
Section 7 — Cyber coverage grants and sublimits
List every grant and its sublimit. The headline limit is usually not the operative number.
- Incident response — sublimit, panel vendors, whether the company's preferred firms are on the panel
- Business interruption — sublimit, waiting period, period of restoration definition
- Contingent business interruption — sublimit, whether providers must be scheduled, and whether the critical ones are
- Data restoration
- Cyber extortion — sublimit, consent process workable in 24 hours, sanctions compliance
- Social engineering / funds transfer fraud — sublimit (usually far too low)
- Bricking
- Reputational harm
- Privacy and network security liability
- Regulatory defence and penalties, "where insurable"
- PCI fines and assessments
- Media liability
- Retroactive date, and prior acts preserved on any change of carrier
Section 8 — Social engineering specifics
- Dedicated grant, not reliance on generic computer fraud or crime coverage
- Sublimit raised toward the full policy limit
- Vendor and client impersonation covered, not only executive impersonation
- Inadvertent disclosure of credentials covered
- Verification condition checked against the actual accounts payable procedure — if they do not match, change one of them
- Coordination with the crime policy; "other insurance" analysed so neither points at the other
- Dual authorization and callback-to-file-number procedures implemented and trained
Section 9 — Cyber exclusions
- War and hostile act: attribution standard requiring more than a government statement; carve-back for collateral damage to a non-target; burden on the insurer
- Infrastructure / utility exclusion aligned with the CBI grant, with a carve-back for failures caused by a covered cyber event
- Widespread event or systemic risk provisions identified and quantified
- Betterment and system upgrade exclusions
- Unencrypted device and failure-to-maintain-controls exclusions — check against actual practice
- Contractual liability exclusion and its effect on customer indemnities
Section 10 — The application
- Signed by the person who actually knows, not by someone relying on a project plan
- Every security control representation verified against reality
- Partial deployments described as partial, with scope stated
- Known circumstances disclosed
- Copies of the application and all supporting materials retained with the policy
- Representations re-verified at each renewal — controls change
Section 11 — Transactions and run-off
- Change of control provisions in every policy identified
- Six-year run-off bound before closing, non-cancellable and fully earned, policy delivered at closing — not merely a covenant to purchase
- Run-off limit sized for six years of claims
- Dedicated Side A within the run-off
- Merger agreement indemnification and insurance covenants reconciled against the actual policy
- On an acquisition: prior acts and subsidiary definitions checked; target's policies, loss history, open claims, and circumstance notices diligenced
- On an IPO: public company D&O placed before pricing; private company run-off considered
Section 12 — Programme coordination
- Annual gap analysis across D&O, cyber, crime, E&O, GL, property, and EPL
- Realistic scenarios mapped to policies: which responds, at what limit, subject to what retention, and where nothing responds
- D&O and cyber both noticed on a breach with shareholder litigation
- Cyber / crime boundary resolved for social engineering
- Physical damage from a cyber event addressed somewhere
- Contingent business interruption addressed in either cyber or property, with providers scheduled
Section 13 — Cash and retentions
- Retention by coverage part, and whether defence costs erode it
- Reimbursement cycle modelled — 90 days invoice to payment is common
- Interim payments requested on undisputed first-party amounts
- Sublimit payments' effect on the aggregate understood
- Working capital requirement in a modelled claim given to finance at placement
Section 14 — The claims runbook
- Trigger list distributed to everyone who might receive a claim
- Notice matrix: carrier, policy number, limit, attachment, address, method, deadline — one table
- Roles assigned: who assesses, drafts, sends, informs the broker, informs the board
- Panel counsel and vendors pre-approved with contacts
- Forensic accountant pre-identified for first-party claims
- Coverage counsel pre-identified with conflicts cleared
- First-party documentation protocol: cost centre, hourly logging, preservation
- Board notification thresholds
- One-page policy summaries current
- Annual tabletop with the broker present
Section 15 — Board reporting
- Tower diagram with layers, carriers, limits, and dedicated Side A called out
- The five terms, quoted: conduct exclusion trigger; insured-versus-insured carve-outs; Side A rescindability and application severability; allocation; exhaustion
- Scenario analysis, including insolvency
- Run-off arrangements on a change of control
- Cyber limits, sublimits, outage cost against payable amount, scheduled providers, waiting period, war exclusion wording, application accuracy
- What changed this year; what was asked for and not obtained
Related documents
- Directors and officers and cyber insurance: towers, triggers, allocation, and the claim you must notice
- Placing and tendering a D&O or cyber claim: a practical guide
- Executive and cyber coverage toolkit: policy comparisons, notice letters, and allocation analyses
- Indemnification and advancement checklist
- Data center agreement review checklist