Document type: Checklist Practice area: Corporate — Insurance and Risk Jurisdiction: United States Last reviewed: 5 September 2026


Section 1 — D&O structure

  • Total programme limit, by layer, with carrier and attachment point mapped
  • Dedicated Side A limit — amount, and whether it has difference-in-conditions and drop-down features
  • Side B retention amount, and whether defence costs erode it
  • Side C entity securities coverage, and whether it shares the limit with Side A
  • Scenario test: in a securities class action plus derivative suit plus investigation, how much is realistically available to individuals?
  • Insolvency test: if the company cannot indemnify, what responds?
  • Limit modelled against the company's own worst case, not only peer benchmarking

Section 2 — Trigger and notice

  • Definition of "claim" — does it include written demands, shareholder demand letters, books and records demands, subpoenas, formal orders, Wells notices, tolling requests?
  • Notice standard: "as soon as practicable" vs a short fixed period
  • Notice address and method for every layer, recorded in one table
  • Extended reporting period: available, length, cost, trigger
  • Notice of circumstances provision — present, and the standard it applies
  • Related claims / interrelated wrongful acts definition, and how far back it can relate
  • Prior knowledge and prior notice exclusions, and what they capture

Section 3 — Exclusions and severability

  • Conduct exclusion trigger: final non-appealable adjudication in the underlying proceeding — not "final adjudication," not "in fact"
  • Severability of exclusions — one insured's conduct not imputed to others
  • Side A non-rescindable
  • Severability of the application — signatories' knowledge only, not imputed to individuals
  • Application incorporation limited to specified documents
  • Bodily injury / property damage exclusion, with a carve-back for defence of derivative claims
  • Prior and pending litigation date — as early as possible
  • Professional services exclusion, and its interaction with any E&O policy
  • Regulatory and specific-event exclusions added at renewal

Section 4 — Insured versus insured

  • Derivative suits brought without the assistance or participation of an insured person — carved out
  • Bankruptcy claimants: trustee, examiner, receiver, liquidator, creditors' committee, debtor in possession — carved out (the most important carve-out in the policy)
  • Former officers and directors after a stated period
  • Whistleblower and employment claims by insured persons
  • Claims brought outside the US by a foreign representative
  • Cross-claims and third-party claims within a covered proceeding
  • Consider whether the narrower "entity versus insured" formulation is available

Section 5 — Allocation and defence

  • Pre-agreed allocation for securities claims — typically 100% to covered loss where entity and individuals are both defendants
  • Allocation method stated for non-securities claims
  • Interim allocation pending final determination
  • Advancement of defence costs during any allocation or coverage dispute
  • Duty to defend vs duty to indemnify, and who controls
  • Panel counsel requirement, and preferred firms added at placement
  • Rate position resolved in writing before fees are incurred
  • Litigation guidelines obtained and given to counsel at the outset
  • Consent-to-settle standard and the hammer clause

Section 6 — The excess tower

  • Provision-by-provision comparison across all layers obtained and read
  • Notice provisions and addresses conformed
  • Definition of "claim" and "loss" conformed
  • Exclusions differing from the primary identified
  • Arbitration and choice-of-law clauses identified — choice of law may be the most consequential provision
  • Exhaustion language: does it permit exhaustion by payment "by the underlying insurers, by the insureds, or on their behalf"?
  • Express statement that a below-limits settlement of an underlying layer does not prejudice attachment if the excess insurer is notified
  • Drop-down on underlying insurer insolvency or refusal to pay
  • Consent-to-settle requirements at each layer, and the practicality of obtaining all of them

Section 7 — Cyber coverage grants and sublimits

List every grant and its sublimit. The headline limit is usually not the operative number.

  • Incident response — sublimit, panel vendors, whether the company's preferred firms are on the panel
  • Business interruption — sublimit, waiting period, period of restoration definition
  • Contingent business interruption — sublimit, whether providers must be scheduled, and whether the critical ones are
  • Data restoration
  • Cyber extortion — sublimit, consent process workable in 24 hours, sanctions compliance
  • Social engineering / funds transfer fraud — sublimit (usually far too low)
  • Bricking
  • Reputational harm
  • Privacy and network security liability
  • Regulatory defence and penalties, "where insurable"
  • PCI fines and assessments
  • Media liability
  • Retroactive date, and prior acts preserved on any change of carrier

Section 8 — Social engineering specifics

  • Dedicated grant, not reliance on generic computer fraud or crime coverage
  • Sublimit raised toward the full policy limit
  • Vendor and client impersonation covered, not only executive impersonation
  • Inadvertent disclosure of credentials covered
  • Verification condition checked against the actual accounts payable procedure — if they do not match, change one of them
  • Coordination with the crime policy; "other insurance" analysed so neither points at the other
  • Dual authorization and callback-to-file-number procedures implemented and trained

Section 9 — Cyber exclusions

  • War and hostile act: attribution standard requiring more than a government statement; carve-back for collateral damage to a non-target; burden on the insurer
  • Infrastructure / utility exclusion aligned with the CBI grant, with a carve-back for failures caused by a covered cyber event
  • Widespread event or systemic risk provisions identified and quantified
  • Betterment and system upgrade exclusions
  • Unencrypted device and failure-to-maintain-controls exclusions — check against actual practice
  • Contractual liability exclusion and its effect on customer indemnities

Section 10 — The application

  • Signed by the person who actually knows, not by someone relying on a project plan
  • Every security control representation verified against reality
  • Partial deployments described as partial, with scope stated
  • Known circumstances disclosed
  • Copies of the application and all supporting materials retained with the policy
  • Representations re-verified at each renewal — controls change

Section 11 — Transactions and run-off

  • Change of control provisions in every policy identified
  • Six-year run-off bound before closing, non-cancellable and fully earned, policy delivered at closing — not merely a covenant to purchase
  • Run-off limit sized for six years of claims
  • Dedicated Side A within the run-off
  • Merger agreement indemnification and insurance covenants reconciled against the actual policy
  • On an acquisition: prior acts and subsidiary definitions checked; target's policies, loss history, open claims, and circumstance notices diligenced
  • On an IPO: public company D&O placed before pricing; private company run-off considered

Section 12 — Programme coordination

  • Annual gap analysis across D&O, cyber, crime, E&O, GL, property, and EPL
  • Realistic scenarios mapped to policies: which responds, at what limit, subject to what retention, and where nothing responds
  • D&O and cyber both noticed on a breach with shareholder litigation
  • Cyber / crime boundary resolved for social engineering
  • Physical damage from a cyber event addressed somewhere
  • Contingent business interruption addressed in either cyber or property, with providers scheduled

Section 13 — Cash and retentions

  • Retention by coverage part, and whether defence costs erode it
  • Reimbursement cycle modelled — 90 days invoice to payment is common
  • Interim payments requested on undisputed first-party amounts
  • Sublimit payments' effect on the aggregate understood
  • Working capital requirement in a modelled claim given to finance at placement

Section 14 — The claims runbook

  • Trigger list distributed to everyone who might receive a claim
  • Notice matrix: carrier, policy number, limit, attachment, address, method, deadline — one table
  • Roles assigned: who assesses, drafts, sends, informs the broker, informs the board
  • Panel counsel and vendors pre-approved with contacts
  • Forensic accountant pre-identified for first-party claims
  • Coverage counsel pre-identified with conflicts cleared
  • First-party documentation protocol: cost centre, hourly logging, preservation
  • Board notification thresholds
  • One-page policy summaries current
  • Annual tabletop with the broker present

Section 15 — Board reporting

  • Tower diagram with layers, carriers, limits, and dedicated Side A called out
  • The five terms, quoted: conduct exclusion trigger; insured-versus-insured carve-outs; Side A rescindability and application severability; allocation; exhaustion
  • Scenario analysis, including insolvency
  • Run-off arrangements on a change of control
  • Cyber limits, sublimits, outage cost against payable amount, scheduled providers, waiting period, war exclusion wording, application accuracy
  • What changed this year; what was asked for and not obtained

Related documents