Running a practice

The clause that makes a tech E&O policy worthless

A professional liability policy can look correct on every limit and still exclude the only thing a data engineering firm actually needs it for. Here is the wording, and the question to ask before you bind.

Start a conversation
All posts

A professional liability quote arrives. The limits look right. One million per claim, one million aggregate, a reasonable deductible, blanket additional insured included, and an endorsement specifically naming technology services and IT consulting. Everything a client would ask for on a certificate.

Then you read the policy specimen rather than the quote summary, and you find this:

Errors and omissions in programming, processing, or storing data, including any mistakes in design, installation, testing, or maintenance of computer systems.

Excluded.

That sentence is a complete description of what a data engineering firm does. Every migration, every schema change, every pipeline, every index rebuild. If the policy excludes errors in programming, processing and storing data, it does not cover the profession it was sold for.

Why it is easy to miss

The exclusion is frequently absent from the quote document. An eight page quote can set out coverage, offered upgrades, claims examples, limits and deductibles, and a two page schedule of endorsement codes, without ever stating the exclusion in words. It lives in the underlying specimen, which nobody sends unless asked.

The claims examples make it harder still. One general liability illustration describes an IT professional damaging a client server, the client’s electronic data being destroyed, and the carrier covering the loss. Reasonable to assume the scenario is covered. Then the limits table sets the electronic data liability sublimit to zero.

What a data engineering claim actually looks like

This matters because the likely claim is not a breach.

You are migrating a production database. Something goes wrong. Data is corrupted or lost. There is no hacker, no ransomware, no unauthorised access. Just a mistake made in the course of professional work.

That is a negligent professional act, which is the core insuring agreement of a professional liability policy. It is not a cyber event, so the cyber policy does not respond either. Cyber data recovery generally requires a breach, extortion, or a security failure to trigger it.

So the scenario most likely to end a small data firm can fall between two policies that were both purchased to prevent exactly that.

The question to ask every carrier

Before limits, before price, before anything:

Does your technology errors and omissions form exclude errors or omissions in programming, processing, or storing data?

Ask it first. It sorts carriers faster than any other question, and a broker who cannot answer it is the wrong broker for this class of business.

Then ask for these

  • The policy specimen, not the quote. The quote is a summary written to sell. The specimen is the contract.
  • A concrete scenario in writing. Describe a migration going wrong with no breach involved, and ask which policy responds.
  • The electronic data liability sublimit. If it is zero, know that before you rely on it.
  • Whether the policy is claims made, and the retroactive date. Work performed before that date is never covered, no matter when you buy.

Two practical notes

General liability limits are often free to raise. A quote arriving at 500,000 per occurrence and 600,000 aggregate may go to 1 million and 2 million at no additional premium, because the underwriter set a default rather than priced a risk. Federal subcontracts and most commercial master agreements require the higher figures, so ask for them from the start.

Ordering cannot be corrected later. Because professional liability is written claims made, coverage has to be in force before work begins rather than before revenue arrives. Those two events are close together, but only one of them can be fixed after the fact.

The general point

A policy summary is a marketing document. The specimen is the contract. For any firm whose core risk is a specific professional act, the only reliable approach is to name that act out loud and make the carrier tell you, in writing, whether it is covered.

It takes one phone call. It is considerably cheaper than finding out during a claim.

This is a note on procurement practice, not insurance advice. Fortis is not an insurance broker. Talk to one who understands technology errors and omissions.

Working through something like this?

If any of the above matches a problem in front of you, the fastest way in is a fixed-scope assessment. Two to three weeks, written findings, yours to keep either way.

See assessments Start a conversation