Insurance Clause Outsourcing
Definition
Insurance Clause Outsourcing
An insurance clause requires a provider to hold named policies at stated limits for the whole life of the contract, and to prove each year that it does. Insurance funds the promise that indemnities and liability caps merely allocate on paper.
The clause exists because a promise is only as good as the balance sheet behind it — a mid-sized provider facing a large claim may simply be unable to pay it.
Four policies cover most outsourcing arrangements: professional indemnity, cyber, public liability and employer’s liability. Regulated work often adds crime cover and specific fidelity bonds.
Limits should be set against modelled exposure rather than copied from a template — a cyber policy sized for a small office is meaningless when the provider handles millions of records.
Key takeaways
- Insurance funds the exposures that indemnity and liability clauses allocate.
- Professional indemnity and cyber are the two policies that matter most in services.
- Limits should follow a modelled worst case, not a standard template figure.
- Certificates must be renewed annually, and the clause should require proof.
How it works
A workable clause names each policy, the minimum limit, whether cover is per claim or in aggregate, how long it must survive the contract, and what evidence the buyer receives each year.
Public buyers set explicit floors. Federal rules require bodily injury liability cover of “at least $500,000 per occurrence”, with employer’s liability cover of at least $100,000 where occupational disease statutes do not apply.
| Policy | What it answers | Typical outsourcing trigger |
|---|---|---|
| Professional indemnity | Negligent advice or service | Processing errors, bad output |
| Cyber | Breach response and liability | Incident affecting buyer data |
| Public liability | Injury or damage to others | Visitors and buyer premises |
| Employer’s liability | Claims by the provider’s staff | Workplace injury or illness |
| Crime or fidelity | Dishonesty by staff | Payment fraud, data theft |
The per-claim versus aggregate distinction is the one to press — an aggregate limit shared across every client the provider serves can be exhausted by someone else’s incident before yours arrives.
Cover must also outlive the contract. Professional indemnity is written on a claims-made basis, so a run-off period of six years after exit is a standard and reasonable demand.
Not every risk should be insured. UK guidance notes that in most cases “the optimal approach will be through self-insurance” for public buyers, with performance bonds reserved for particular sectors.
Examples
Insurance clauses are checked at signature and then forgotten, which is where the problems start. The four cases below show the clause working and failing in outsourcing arrangements.
A processing error at a claims provider triggers a professional indemnity claim. The insurance outsourcing contract required cover sized to annual premium volume, so the policy absorbs it.
A buyer discovers at renewal that the provider’s cyber limit is an aggregate figure shared across 40 clients. The clause is amended to require a dedicated per-claim limit.
A regulated financial buyer requires crime cover after mapping payment-handling exposure. The addition costs little and closes the only gap the risk outsourcing review identified.
A contract ends and no run-off cover was required. A claim arrives 18 months later with no policy responding, and the indemnity is worth only what the provider can pay.
Related terms
Insurance is the funding layer beneath several other clauses, and it is easy to confuse with them. The entries below separate allocating a loss from actually paying for it.
- Business risk: the exposures a buyer carries whether or not a provider is insured.
- Business continuity clause: reduces the loss before any policy is called on.
- Disaster recovery clause: restores systems, while insurance funds the consequences of not restoring them fast enough.
- Compliance outsourcing: a service line where regulators often mandate specific minimum cover.
- Banking, financial services and insurance: the sector with the most prescriptive cover requirements.
FAQ
Which policies should an outsourcing contract require?
Professional indemnity and cyber in almost every case, plus public and employer’s liability wherever people or premises are involved. Regulated work usually adds crime cover.
What limits are appropriate?
Whatever a modelled worst case suggests, not a template figure. A useful starting test is whether the limit exceeds the contract’s liability cap.
What does claims-made mean?
The policy responds to claims notified while it is in force, regardless of when the incident happened. That is why run-off cover after exit matters so much.
Per claim or in aggregate?
Per claim is far stronger. An aggregate limit is shared across all claims in the period, including those from the provider’s other clients.
How should cover be evidenced?
By an annual certificate from the insurer or broker, naming the policy, the limit and the period. A copy of a schedule from three years ago proves nothing.
Does insurance replace an indemnity?
No. The indemnity creates the obligation to pay, insurance provides the money behind it, and a contract needs both to be worth relying on.
Providers can publish their cover and credentials at the Outsource Accelerator hubs.







Independent




