Summary. An insurance program is a contract portfolio most companies buy like office supplies and then read only after a loss. This guide treats it as a negotiation: the risk assessment that determines what to buy and how much, the lines of coverage and what each actually does, how brokers are selected and compensated and why that affects the outcome, how to prepare a submission that produces better terms, the provisions worth negotiating and the endorsements worth buying, and how the insurance requirements in leases and vendor agreements must be reconciled with the program that actually exists. It closes with renewal strategy and what to do when a claim arrives.
A 240-employee services company suffers a ransomware attack. Operations are down for eleven days. Direct costs — forensics, legal, notification, credit monitoring, and a ransom the company does not pay — come to $840,000. Lost revenue is roughly $2.1 million.
The company has a cyber policy with a $2 million limit. It recovers $612,000.
The gaps, each of which was a negotiable term:
The business interruption coverage had a 12-hour waiting period and a 10-day maximum indemnity period, so the longest and most expensive part of the outage fell outside the coverage.
"Dependent business interruption" was excluded, and a substantial part of the loss traced to the outage at the company's managed service provider rather than to its own systems.
The policy required notice "as soon as practicable but in no event later than 30 days," and the company's IT team spent two weeks investigating before anyone told the broker. Notice was 19 days after discovery, which was fine — but the company had also failed to notify of an earlier incident that the insurer argued was related.
A sublimit of $250,000 applied to "social engineering and funds transfer fraud," which captured a portion of the loss.
And the "failure to maintain" exclusion applied to a system the company had represented in its application as running multifactor authentication, which it did not on the affected segment — putting the entire claim at risk on a misrepresentation theory before the parties settled.
Every one of those was a term the company could have negotiated, and none of them was priced at more than a few thousand dollars of additional premium. The company did not know to ask.
Insurance is a contract. It is negotiated like one, or it is accepted as written.
Step one: understand the risk
Buying coverage before understanding exposure produces a program that is expensive in the wrong places and absent in the right ones.
Inventory the exposures:
- Property — locations, values, construction, occupancy, protection, and exposure to flood, earthquake, wind, and wildfire, which are frequently excluded or separately sublimited.
- Business interruption — the actual dependency map. Which locations, systems, suppliers, and customers would halt operations, and for how long? Model the loss, do not estimate it.
- Liability to third parties — products, premises, operations, completed operations, advertising, and contractual.
- Professional services — errors in the work product itself, which general liability does not cover.
- Employment — the workforce size, states of operation, turnover, and claims history.
- Management liability — the board, the investors, and any fiduciary responsibility for benefit plans.
- Data — what personal or sensitive information is held, and what a breach would cost.
- Auto — owned, hired, and non-owned exposure, including employees driving personal vehicles on company business, which many companies do not realize is an exposure.
- Crime — employee dishonesty, funds transfer fraud, and social engineering.
- Contractual obligations — every lease, customer contract, and vendor agreement that requires the company to carry specific coverage, name additional insureds, or waive subrogation.
Quantify. For each exposure, estimate frequency and severity. The output determines what to insure, what to retain, and where limits belong. A company with a $60 million balance sheet and $1 million of liability limits is not saving money; it is retaining catastrophic risk unintentionally.
Review the claims history — five years of loss runs from every carrier. They drive underwriting, and they reveal whether the current program is responding.
Step two: the lines
Commercial general liability. Covers bodily injury and property damage caused by an occurrence, personal and advertising injury, and medical payments, on an occurrence basis — meaning it responds to injury occurring during the policy period, whenever the claim is made.
Watch: the professional services exclusion, which removes the very risk a services company faces; the employment-related practices exclusion; the pollution exclusion; the cyber and data exclusions now standard on most forms; the contractual liability exclusion and its insured contract exception, which is what makes indemnity obligations insurable; products-completed operations coverage and its aggregate; and the "your work" and "your product" exclusions, which mean CGL does not pay to fix the insured's own defective work.
Property. Covers direct physical loss to owned and leased property. Negotiate: replacement cost rather than actual cash value; agreed value to avoid coinsurance penalties; the valuation method for inventory and equipment; ordinance or law coverage for the cost of rebuilding to current code; and sublimits for flood, earthquake, and windstorm, which in exposed areas are the whole question.
Business interruption and extra expense. The most misunderstood coverage and frequently the largest exposure. Negotiate: the period of restoration and any extended period of indemnity; the waiting period; contingent business interruption for supplier and customer dependencies; civil authority and ingress/egress coverage; and the worksheet used to establish the limit, because an inadequate limit discovered after a loss cannot be fixed.
Cyber liability. First-party coverage (forensics, notification, credit monitoring, public relations, business interruption, dependent business interruption, data restoration, cyber extortion) and third-party coverage (privacy liability, regulatory defense and fines where insurable, media liability, PCI assessments). Negotiate the items listed in the opening example, and confirm whether the insurer's panel of vendors is mandatory — many policies require the use of approved counsel and forensic firms, which is worth knowing before an incident rather than during one.
Directors and officers. Side A covers individuals when the company cannot indemnify; Side B reimburses the company for indemnification; Side C covers the entity for securities claims (for private companies, frequently broader). Negotiate: the insured versus insured exclusion and its carve-backs, particularly for bankruptcy trustees and derivative suits; the conduct exclusions, which should require a final adjudication in the underlying action and be non-imputable between insureds; severability of the application; Side A difference-in-conditions excess coverage for outside directors; and the treatment of regulatory investigations and pre-claim inquiry costs.
Employment practices liability. Covers discrimination, harassment, retaliation, and wrongful termination. Negotiate: wage and hour defense coverage, which is usually a small sublimit and is the most common claim type; third-party coverage for claims by customers and vendors; the duty to defend and choice of counsel; and the prior acts date.
Professional liability / errors and omissions. Claims-made, which makes the retroactive date and the extended reporting period the two most important terms in the policy. Confirm the definition of professional services matches what the company actually does, and confirm that any technology, cyber, and media exposures are either included or covered elsewhere without a gap.
Umbrella and excess. Sits above the primary layers. Confirm it follows form — that its terms match the underlying — and identify any drop-down provisions, any coverage narrower than the primary, and the maintenance of underlying insurance condition, because a lapse below can leave the excess without an obligation.
Workers' compensation and employers' liability. Statutory, with rates driven by classification codes and the experience modification factor. Audit the classification codes; misclassification is common and expensive in both directions. Confirm coverage in every state of operation, and note monopolistic states where coverage must be purchased from the state fund, leaving employers' liability to be obtained separately.
Other lines by exposure: commercial auto, including hired and non-owned; crime and fidelity, with social engineering coverage specifically requested; fiduciary liability for benefit plans; environmental and pollution legal liability; product recall; representations and warranty insurance for transactions; kidnap and ransom; and trade credit.
Step three: the broker
The broker is the most consequential choice in the program, because the broker prepares the submission, controls market access, and negotiates the terms.
Selection criteria: genuine expertise in the company's industry; access to the relevant markets; the specific team who will service the account rather than the team who pitched; claims advocacy capability, which matters more than placement; and the ability to review contractual insurance requirements.
Understand the compensation. Brokers are paid by commission from the carrier (a percentage of premium, which creates an interest in higher premium), by fee from the client (which aligns interests better and should be considered for larger programs), or both. Contingent commissions based on volume, retention, or loss ratio create an interest in placing business with particular carriers. Ask for full written disclosure of all compensation from all sources, and understand that a broker unwilling to provide it is telling you something.
Broker of record letters. Only one broker may approach a given market on the company's behalf, which prevents multiple brokers from shopping the same account. Assign markets deliberately in a competitive process, or run a formal broker selection and then let the winner approach everyone.
Set expectations in writing: the timeline, the markets to be approached, the coverage specifications, the reporting format for quotes (which should be a comparison of terms, not just premiums), the stewardship report, and the contract review support.
Step four: the submission
Underwriters price uncertainty. A submission that answers their questions before they ask produces better terms than one that requires them to assume the worst.
Assemble, 90 to 120 days before renewal:
- Completed applications for each line — accurate, complete, and reviewed by someone who understands that misrepresentation voids coverage. The cyber application in particular now asks detailed security control questions, and answering them optimistically is the fastest route to a denied claim.
- Five years of loss runs, currently valued, from every carrier.
- A narrative describing the business, its operations, its customers, and its risk management. Most companies skip this, and it is the highest-leverage document in the submission.
- A risk management story — what has changed since last year. New controls, training, safety programs, security improvements, and — crucially — the corrective action taken after any significant claim. Underwriters price the trend, not the history.
- Financial statements.
- Property schedules with values, construction, and protection details.
- The employee census with state distribution and payroll by class code.
- Contractual requirements the program must satisfy.
- A schedule of the coverage specifications the company wants, so quotes are comparable.
Timing matters. Submissions that arrive two weeks before expiration receive whatever the market offers. Submissions that arrive with time for questions, an underwriter meeting, and a site visit receive negotiated terms.
Meet the underwriter for significant lines. A management presentation to an underwriter works the same way it does to an investor, and it is one of the few ways a good risk can distinguish itself from the class it is being rated in.
Step five: negotiating the terms
Read the form, not the summary. Brokers deliver proposals summarizing coverage; the policy is what governs. Ask for specimen policy forms with all endorsements before binding, and have counsel review anything material.
Structural terms:
Occurrence versus claims-made. For claims-made policies, the retroactive date determines how far back covered acts may reach, and it must be maintained through every renewal and every change of carrier. Losing the retroactive date on a switch is one of the most damaging and most common errors in commercial insurance. The extended reporting period (tail) must be purchased on cancellation or non-renewal; negotiate its length and cost at inception, when it is cheap, rather than at cancellation, when it is not.
Defense: within or outside limits. Defense within limits — "eroding" or "wasting" — means defense costs reduce the money available to pay a judgment. On a $2 million policy with $1.4 million of defense costs, $600,000 remains. Negotiate defense outside the limits where available; where it is not, size the limit accordingly.
Duty to defend versus duty to indemnify. A duty-to-defend policy obligates the insurer to defend the entire suit if any claim is potentially covered, which is broad and valuable. An indemnity-only policy reimburses defense costs, usually with rate limits and consent requirements.
Consent to settle and hammer clauses. Many professional and management liability policies require the insured's consent to settle; a hammer clause provides that if the insured refuses a settlement the insurer recommends, the insurer's liability is capped at that amount plus a share of subsequent costs. Negotiate a soft hammer — a 50/50 or 70/30 split of the excess — rather than a full one.
Retentions and deductibles. Higher retentions reduce premium and increase retained risk. Model the tradeoff at actual claim frequency, and understand whether the retention applies per claim or per occurrence, and whether defense costs erode it.
Notice provisions. The most common coverage defense. Understand precisely what triggers notice, to whom it must be given, in what form, and by when — and build an internal process so that a manager who receives a demand letter knows to route it within hours. For claims-made policies, notice of circumstances that may give rise to a claim locks in the current policy year, and it is the most valuable and least used feature of these policies.
Choice of counsel. Insurers select defense counsel under most duty-to-defend policies. Negotiate panel counsel the company is comfortable with, or a right to select from an agreed list, or independent counsel where a conflict exists — which in many states arises automatically when the insurer reserves rights on a coverage issue the defense could affect.
Endorsements worth requesting:
- Additional insured endorsements, in the form the company's contracts require — and note the difference between blanket endorsements triggered by a written contract and scheduled ones naming specific parties.
- Waiver of subrogation, blanket where written contract requires it.
- Primary and non-contributory wording, which contracts routinely demand.
- Notice of cancellation to certificate holders.
- Broadened named insured covering subsidiaries and newly acquired entities, with a reporting period.
- Per-location or per-project aggregate limits, which prevent one project from exhausting the aggregate for all.
- Amendment of the "other insurance" clause where needed.
Exclusions to challenge. Every exclusion is a negotiation. Common candidates for deletion or narrowing: industry-specific exclusions applied by class rather than by underwriting; broad "professional services" exclusions on a CGL where the company's services are incidental; contractual liability exclusions narrower than the insured contract exception; prior acts exclusions on a new claims-made policy; and cyber exclusions on lines where the exposure has not been placed elsewhere.
Reconcile the program to the contracts. Pull every lease, customer agreement, vendor agreement, and construction contract, and build a matrix of required limits, required additional insured status, required waivers, and required notice provisions. Then confirm the program actually satisfies them. A company that promised $5 million of general liability in a lease and carries $2 million has a breach of contract exposure that no insurance covers, and it is discovered at the worst moment.
Step six: alternatives to conventional insurance
Higher retentions with a funded reserve — appropriate where losses are frequent, predictable, and small.
Captive insurance — a wholly owned insurance subsidiary formed in a domicile with a captive statute. Genuine advantages for a company with sufficient scale: access to reinsurance markets, coverage for risks the commercial market prices poorly, retention of underwriting profit, and cash flow benefits. Real requirements: capitalization, a business plan approved by the domiciliary regulator, actuarial support, annual reporting, and enough premium volume to justify the cost — generally at least seven figures. Note that micro-captives electing under 26 U.S.C. § 831(b) have been the subject of sustained IRS enforcement and repeated Tax Court decisions against taxpayers, and are designated reportable transactions; a captive should be justified by risk management economics, not by tax benefits.
Group captives and risk retention groups — for mid-sized companies in similar industries, pooling risk with underwriting discipline.
Fronting arrangements, where a licensed carrier issues the policy and reinsures to the captive, satisfying contractual and regulatory requirements for admitted paper.
Parametric coverage, which pays a fixed amount on a defined trigger — a named storm within a radius, an earthquake above a magnitude — without adjusting the actual loss. Fast, but basis risk is real.
Step seven: renewal and claims
The renewal calendar:
- 120 days out — begin the process; update exposures and values; request loss runs.
- 90 days — submission to the broker; discuss market conditions and strategy; decide whether to market the account or negotiate with incumbents.
- 60 days — submissions to markets; underwriter meetings.
- 45 days — quotes received and compared on terms, not just premium.
- 30 days — negotiate; request specimen forms; legal review.
- Bind before expiration, and confirm binders in writing.
- Post-renewal — review the actual policies against the binders and the proposal within 30 days. Discrepancies are common and are correctable only if found.
Market conditions matter to strategy. In a hard market — rising rates, reduced capacity, tightening terms — the priority is retention of terms and relationships, and marketing the account aggressively can backfire if incumbents decline to quote. In a soft market, competition is worth creating. Ask the broker directly which market the company is in for each line, because the answer differs by line.
When a claim arrives:
- Notice immediately, in the form the policy requires, to every potentially applicable policy — and when in doubt, notice under all of them. Late notice is the most common reason claims fail.
- Preserve evidence and issue a litigation hold.
- Read the reservation of rights letter carefully; it identifies the coverage issues the insurer sees and may trigger a right to independent counsel.
- Tender to others — additional insured status under a vendor's, contractor's, or landlord's policy is frequently available and routinely overlooked. Tender early and in writing.
- Cooperate, as the policy requires, while managing privilege carefully.
- Do not settle or admit liability without the insurer's consent where the policy requires it.
- Document the loss in the format the policy specifies — for business interruption in particular, the proof of loss requirements are demanding and the records must be assembled contemporaneously.
- Escalate coverage disputes to counsel early. Most states impose a duty of good faith and fair dealing on insurers, with bad faith remedies that can exceed policy limits, and the leverage that creates is real but must be developed deliberately.
A short case study
A 400-employee specialty manufacturer with two plants runs a structured renewal for the first time.
Assessment. The dependency map reveals that a single supplier provides a component used in 60 percent of revenue, and that the current property policy has no contingent business interruption coverage. It also reveals that field service technicians drive personal vehicles to customer sites with no hired and non-owned auto coverage.
Contracts. The matrix of contractual requirements finds three customer agreements requiring $10 million of combined limits with additional insured status on a primary and non-contributory basis; the company carries $6 million total.
Submission. Prepared 110 days out, with a narrative describing a new safety program that cut recordable incidents by 40 percent, a documented corrective action following a prior products claim, and a security assessment supporting the cyber application. Two underwriter site visits are arranged.
Negotiation. Results: contingent business interruption added with a $5 million sublimit; hired and non-owned auto added; umbrella increased to $15 million; the cyber policy's waiting period reduced from 12 to 8 hours and the indemnity period extended to 180 days; a soft hammer clause negotiated on the D&O; defense costs moved outside the limits on the professional liability policy; blanket additional insured and waiver of subrogation endorsements added; and the workers' compensation classification audit reclassifies 22 employees, reducing premium.
Net effect. Total premium rises 9 percent. Coverage limits rise 150 percent, three material gaps close, and the contractual requirements are satisfied for the first time.
Eighteen months later, the key supplier suffers a fire. The contingent business interruption coverage pays $2.3 million. It was added at a cost of roughly $14,000 in annual premium.
Conclusion
Three points carry the practical weight.
Start from exposure, not from last year's policy. Most programs are renewals of renewals, tracking a business that no longer exists. The dependency map, the contract requirement matrix, and the claims history are what determine what to buy.
The terms matter more than the premium. Waiting periods, indemnity periods, sublimits, retroactive dates, defense-within-limits, notice provisions, and consent-to-settle clauses each determine what a policy pays. A program that is 10 percent cheaper and materially narrower is not cheaper.
Read the actual policy, and reconcile it to the contracts. The gap between what a company promised its landlord, its customers, and its lenders and what its program actually provides is the most common uninsured exposure in commercial practice — and it is found by reading two stacks of paper against each other, once a year.
Frequently asked questions
How much liability coverage is enough? There is no formula, but three anchors help. The first is the largest amount the company has contractually promised to carry, which is a floor. The second is the value of the enterprise, because a judgment above the limits reaches the balance sheet. The third is the industry's verdict experience, which a broker with real sector expertise can supply. In practice, most companies under-buy umbrella coverage, which is the cheapest limit in the program per dollar of protection.
Is a certificate of insurance proof of coverage? No. A certificate is an informational document that expressly disclaims any amendment of the policy. It tells you a policy existed on the date issued and nothing more. If a contract requires additional insured status, waiver of subrogation, or primary and non-contributory wording, ask for the endorsements, not the certificate.
What is the difference between an additional insured and a certificate holder? A certificate holder simply receives a copy of the certificate. An additional insured has actual rights under the policy. Companies routinely accept certificates naming them as a holder and believe they have coverage; they do not.
Should we use one broker or several? For most companies, one broker with clear market assignments produces better results than several competing brokers approaching the same underwriters, which markets confusion and depresses appetite. Where specialized lines require different expertise — a cyber specialist, a captive manager, an aviation broker — assign those lines explicitly.
Should we market our account every year? No. Underwriters price continuity, and shopping an account annually signals that the relationship has no value. Market the program every three to five years, or when there is a specific problem — a rate increase out of line with the market, a coverage restriction, or a service failure.
What is an experience modification factor? In workers' compensation, a multiplier comparing the company's claims history to its industry class, applied to the manual premium. A modifier below 1.0 is a discount; above 1.0 is a surcharge. It is calculated from data the company can and should audit, and errors in class codes and claim reserves are common and correctable.
Does the insurer have to defend a meritless suit? Under a duty-to-defend policy, yes — the duty is triggered by allegations that are potentially covered, and it is broader than the duty to indemnify. That is why duty-to-defend coverage is more valuable than indemnity-only coverage, and why the "eight corners" comparison of the complaint to the policy is the first analysis in any tender.
What if the insurer denies the claim? Read the denial for the specific policy language relied on, respond in writing with the facts and the language that support coverage, ask for the complete claim file where state law permits, and involve coverage counsel early. Most states impose a duty of good faith on insurers, and the remedies for a bad faith denial can substantially exceed the limits — but that leverage is built with a documented record, not asserted in a phone call.
What is the single most valuable thing we can do this year? Reconcile the insurance requirements in every contract the company has signed against the program it actually carries. It costs a few days of someone's time and it finds gaps that no amount of premium spending would have closed, because nobody knew they existed.
Building the internal function
For a company past roughly a hundred employees, insurance stops being a purchasing decision and becomes a program requiring an owner inside the business.
Assign it to one person. Someone in finance or legal owns the program, the calendar, the claims, and the contract reconciliation. Where nobody owns it, the broker becomes the de facto risk manager — which is a conflict, because the broker is compensated on the placement.
Maintain a coverage summary that a manager can read: what each policy covers, what the limits and retentions are, who to call, and — most importantly — what triggers a notice obligation. Distribute it to every person who could receive a demand letter, a subpoena, an EEOC charge, a customer complaint about the work product, or a report of a security incident. Late notice is the most common coverage failure, and it happens because the person holding the letter did not know it mattered.
Build a claim intake path. One email address, one phone number, and a standing instruction that anything resembling a claim goes there within 24 hours, before anyone investigates or responds. The person who receives an angry letter should not be deciding whether it is serious.
Track the contract requirements continuously, not annually. Every new lease, customer agreement, and vendor contract should be checked against the program at signature, and any requirement the program does not meet should be either negotiated in the contract or added to the program before signing.
Run a stewardship meeting with the broker annually: claims trends, market conditions, program gaps, upcoming exposures, and what changed in the business. Ask for a written stewardship report. Brokers who cannot produce one are not doing the work.
Feed risk management back into underwriting. Safety programs, driver monitoring, security controls, hiring practices, and quality systems all reduce loss and all should appear in next year's submission. Underwriters reward demonstrated improvement, and the discount frequently exceeds the cost of the program that produced it.
A note on growth events. Four things should trigger an immediate program review rather than waiting for renewal: opening in a new state, which affects workers' compensation, auto, and employment practices coverage; acquiring a business, which brings its liabilities and may or may not be covered by the newly acquired entity provision; launching a new product or service line, which can fall outside the definition of covered operations; and taking outside investment or adding independent directors, which changes the D&O analysis entirely. Each of these is cheap to address in advance and expensive to discover during a claim.
And a word about the application. It is a legal document, and in most states a material misrepresentation on it permits the insurer to rescind the policy — retroactively, after the loss. Cyber applications now ask granular questions about multifactor authentication, backup practices, endpoint detection, privileged access, and patching cadence. Answer them from what the environment actually does, verified by the person who runs it, not from what the security policy says should happen. If a control is partially deployed, say so and describe the scope. An accurate answer costs a small amount of premium; an optimistic one can cost the entire claim.
Finally, keep the historical policies. Occurrence-based liability policies respond to injury during their period no matter when the claim arrives, which means a policy from fifteen years ago may be the one that answers a latent products or premises claim today. Archive the complete policies — not certificates, not summaries — permanently, and record the carrier, policy number, period, limits, and retentions in a schedule someone can find.
Related articles
- Business Insurance and Coverage Disputes: CGL, E&O, Cyber, and D&O — how these policies are litigated.
- Insurance Program Review Checklist — the annual review in checklist form.
- Insurance Coverage Toolkit: Placing, Tendering, and Litigating Claims — the full roadmap.
- Handling an Insurance Claim After a Property Loss — the first-party claim process.
- Insurance Producer and Agency Regulation — the broker's side, and the duties they owe.
- Data Breach and Incident Response Toolkit: From Detection to Notification — the incident the cyber policy responds to.
- Commercial Leases for Small Businesses: What to Negotiate Before You Sign — where the insurance requirements come from.
- Preparing a Business Continuity and Crisis Management Plan — the dependency map that sizes business interruption.
- Premises Liability for Property Owners and Businesses — the liability exposure being insured.
- Contract Lifecycle Toolkit: From Term Sheet to Termination — tracking the insurance obligations in every agreement.
This guide is provided for general informational purposes and does not constitute legal or insurance advice. Policy forms, endorsements, and state insurance regulation vary substantially, and coverage depends on the specific language of the policy issued. Consult qualified coverage counsel and a licensed broker before binding or relying on any program.