Verifying an offshore development vendor's insurance means checking three things independently: the certificate of insurance itself, the exclusions buried in the policy wording, and whether the coverage limits match the actual financial exposure of the engagement. Most procurement teams stop at step one. They ask for a certificate, file it, and move on. That is the gap this article addresses.
A certificate confirms a policy exists on the date it was issued. It says nothing about whether that policy would pay out for the specific failure mode your contract is exposed to, which is a different question and the one that actually matters when something goes wrong.
TL;DR
A certificate of insurance is proof of existence, not proof of adequate coverage. You need the policy schedule and exclusions page, not just the certificate.
Professional Indemnity (Technology E&O) and Cyber Liability are separate policies covering separate failure modes. A vendor can hold one without the other, and standard contracts rarely force both.
Minimum cyber liability coverage in technology services generally sits between $1 million and $2 million per occurrence, covering first-party costs (data recovery, extortion) and third-party liability (breach response, network security failures).
Common exclusions, fraud, known prior defects, assumed contractual liability, are the clauses that determine whether a claim actually gets paid, and standard vendor contracts almost never ask a vendor to disclose them.
If your financial entity operates in the EU, DORA now requires you to specify insurance obligations for ICT third-party providers directly in the contract, not just assume them.
About the Author
This article is written from 724SOFTWARE's experience as a long-term technology partner for regulated clients in Fintech, digital healthcare, and enterprise software, where insurance verification is a standard part of vendor onboarding. The company holds ISO 27001:2022 and SOC 2 Type II certifications and works through these exact due diligence conversations with clients evaluating offshore engineering teams.
What Is Professional Indemnity Insurance for a Software Vendor?
Professional Indemnity insurance, often labeled Technology Errors and Omissions insurance in the US market, covers legal costs and damages when a vendor's professional service causes a client financial loss through an error, omission, or failure to deliver as specified. This is distinct from general liability, which covers physical injury or property damage. For a software vendor, the exposure is almost entirely financial: a bug that corrupts a client's production database, a missed deadline that breaches a downstream contract, an integration that silently drops transactions for three weeks before anyone notices.
Coverage limits should scale with the financial risk of the project, not with the vendor's day rate. A $2 million professional indemnity policy sounds substantial until you're running a trading platform where a pricing bug could generate losses well past that figure in a single trading session. The policy exists to transfer that risk, so the limit needs to reflect the exposure, not the contract value.
What most procurement checklists miss is the exclusions list. Standard exclusions include fraud, dishonesty, known prior defects (meaning a bug the vendor already knew about before the policy incepted), liability the vendor contractually assumed beyond what the law would otherwise impose, and non-professional risks like bodily injury. That third exclusion, assumed liability, is the one that catches clients off guard. If your master service agreement includes an indemnification clause that goes further than standard negligence liability, the vendor's professional indemnity policy may not cover it at all. You would be relying on a contractual promise with no insurance behind it.
How Is Cyber Liability Different From Professional Indemnity, and Why Do You Need Both?
Cyber liability insurance covers costs arising from a data breach or cyberattack, separate from the professional error that caused it. Professional indemnity asks "did the vendor's work cause you a financial loss?" Cyber liability asks "did a security incident expose data or disrupt systems?" A vendor can fail one test without failing the other. A developer who ships a bug that miscalculates interest payments has a professional indemnity problem. A vendor whose laptop gets compromised and leaks client source code and customer PII has a cyber liability problem. The failure modes, the claims process, and often the insurers are different.
Industry standards for technology service providers handling client data typically call for minimum cyber liability coverage of $1 million to $2 million per occurrence.
That coverage should include two categories:
First-party costs: data recovery, business interruption, and cyber extortion payments if the vendor itself is the direct victim.
Third-party liability: network security liability and data breach response costs when the incident affects your customers' or partners' data, not just the vendor's own systems.
The 2026 renewal cycle for cyber insurance has tightened noticeably. Carriers are no longer accepting attestations at face value; they're requiring documented proof of multi-factor authentication deployment, active endpoint detection and response monitoring, and tested backup restoration. This matters to you as a client because if your offshore vendor's own cyber policy lapses or gets denied at renewal due to insufficient controls, you inherit that gap silently. A vendor whose insurer is now demanding phishing-resistant MFA and 24/7 monitored EDR before renewing coverage is a vendor who is under real pressure to tighten security operations, which is exactly the posture you want from anyone handling your codebase and data.
What Do Standard Vendor Contracts Typically Miss?
Standard vendor contracts miss the connection between the insurance clause and the actual scope of work. Most master service agreements include a boilerplate line requiring "commercially reasonable insurance," without specifying policy type, coverage limit, or exclusion tolerance. This leaves three gaps unaddressed:
No distinction between policy types. A contract that says "the vendor shall maintain insurance" without naming professional indemnity and cyber liability separately allows a vendor to satisfy the clause with only one of the two.
No mechanism to verify exclusions. Certificates of insurance list coverage type and limit; they do not list exclusions. You need the policy declarations page or a broker letter to see what is actually carved out.
No requirement tied to certification. ISO 27001 certification does not itself mandate insurance, but it has become a practical prerequisite for underwriting. Insurers increasingly require organizations to demonstrate ISO 27001 controls, such as documented incident response and MFA enforcement, as a baseline before issuing or renewing cyber liability coverage. A vendor holding ISO 27001 is one whose security posture has already been audited to a standard insurers recognize, which should factor into how much scrutiny you apply to their coverage claims.
What Do Regulators Actually Require for Offshore Vendor Insurance?
This varies sharply by jurisdiction, and treating it as one uniform rule is where compliance teams get exposed. In the EU, the Digital Operational Resilience Act (DORA) requires financial entities to specify, in the contract itself, whether ICT third-party providers must hold mandatory insurance and at what coverage level.
This is a direct, contract-level obligation, not a general best-practice recommendation. In the US and UK, there is no equivalent statutory mandate forcing offshore vendors to carry specific insurance. Instead, financial regulators require the client institution to run third-party risk management, which in practice pushes the insurance requirement into the vendor contract anyway, just via a different regulatory path.
The practical takeaway: if you operate under DORA, your contract template needs an insurance clause with named limits, not a general reference. If you operate under US or UK financial regulation, the obligation sits with your third-party risk program, and your vendor contract is the tool you use to discharge it.
How Should You Compare Professional Indemnity Coverage Across Vendors?
A professional indemnity insurance comparison across vendors should look past the headline limit and check three things: the retroactive date (does the policy cover work already delivered, or only work performed after the policy start date), the aggregate versus per-claim limit (a $2 million aggregate limit can be exhausted by one claim, leaving nothing for a second), and the exclusion list against your specific contract terms. Two vendors quoting the same $2 million limit can have materially different real-world protection once you check those three variables.
Frequently Asked Questions
Does a certificate of insurance guarantee the vendor is covered for my specific project?
No. A certificate confirms a policy exists and states the limit and type. It does not confirm the exclusions, the retroactive date, or whether your specific engagement falls within the covered scope.
What is Technology Errors and Omissions insurance?
Technology E&O is another name for professional indemnity insurance as applied to software and IT service providers, covering financial loss caused by errors, omissions, or failure to perform professional duties.
Is $1 million in cyber liability coverage enough for a mid-sized SaaS vendor?
Industry minimums for technology service providers typically start at $1 million to $2 million per occurrence, but the right figure depends on the volume and sensitivity of data the vendor processes on your behalf.
Does ISO 27001 certification replace the need for cyber insurance?
No. ISO 27001 is a security management certification, not an insurance product. It does, however, increasingly function as a baseline insurers expect before underwriting or renewing cyber liability coverage.
Can a vendor's professional indemnity policy cover a data breach?
Generally not directly. Professional indemnity covers errors in professional service delivery; a data breach is typically a cyber liability matter, which is why both policies are needed rather than one substituting for the other.
What should a vendor insurance clause specify in a contract?
Name the policy types (professional indemnity and cyber liability separately), state minimum per-occurrence limits, require annual proof of renewal, and where operating under DORA, state the requirement explicitly rather than relying on general language.
Are offshore vendors held to different insurance standards than local ones?
The insurance products themselves are the same categories globally. What differs is the regulatory pressure to require them contractually, which is stronger and more explicit under frameworks like DORA than under general US or UK third-party risk guidance.
About 724SOFTWARE
724SOFTWARE is a Vietnam-based technology partner delivering application development, dedicated engineering teams, and offshore development centers for clients in Fintech, digital healthcare, and enterprise software. The company operates GDPR-compliant delivery processes, the same security baseline that underpins the insurance verification standards discussed above. With 200+ professionals, 58% at senior-level expertise, and a follow-the-sun support model with <10 minute incident response, 724SOFTWARE works with clients as a long-term technology partner rather than a one-off contractor, which is precisely the relationship where insurance and compliance verification should be built into onboarding from day one.
If you're evaluating an offshore engineering partner and want to see how insurance, certification, and contract terms fit together in practice, visit 724SOFTWARE.
