Insurance Requirements Clause Explained (2026)
An insurance requirements clause tells both parties exactly what coverage to carry, at what limits, and how to prove it. Learn the three-layer system that makes it work.
Generate a services agreement in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What an Insurance Requirements Clause Actually Does
An insurance requirements clause is a contract provision that names which party must carry insurance, identifies the required policy types and dollar limits, and defines how proof must be delivered. It is not redundant with an indemnification clause — it is the financial backstop that makes an indemnification clause enforceable. Without it, a counterparty's promise to compensate you is worth exactly as much as their bank balance the day disaster strikes.
Key takeaways
- An insurance requirements clause allocates risk by ensuring the party creating exposure actually has money to cover it — the indemnification clause only shifts liability; insurance produces the cash.
- Three elements must align for the clause to protect you: the contract language, the ACORD 25 certificate of insurance, and the carrier-issued policy endorsements — a gap in any layer can void the protection.
- Commercial general liability (CGL) policies are typically written on an occurrence basis; professional liability and cyber policies are almost always written on a claims-made basis — a fact most insurance clauses leave unspecified at their peril.
- Being listed as a "certificate holder" on an ACORD 25 confers zero coverage rights; only a carrier-issued additional insured endorsement does.
- Coverage minimums are negotiable, but a service provider who agrees to carry insurance they cannot actually obtain has breached the contract before the ink is dry.
The Three-Layer Stack: Why the Clause Alone Is Never Enough
Every piece of content about insurance clauses treats the clause as if it operates alone. It does not. A contract insurance requirement only functions when three layers are all correctly assembled:
Layer 1 — The Contract Clause. This is the written obligation: which policies, what limits, what endorsements, and how long coverage must stay in force. A clause that specifies "general liability, $1 million per occurrence" but omits the policy trigger type (occurrence vs. claims-made), the requirement for an additional insured endorsement, and a waiver of subrogation is legally in force but commercially fragile.
Layer 2 — The Certificate of Insurance (ACORD 25). The ACORD 25 (currently edition 2025/12 per ACORD's latest revision) is the industry-standard one-page summary that confirms policies exist. The standard disclaimer printed on every ACORD 25 reads: "This certificate is issued as a matter of information only and confers no rights upon the certificate holder. This certificate does not affirmatively or negatively amend, extend or alter the coverage afforded by the policies." Read that carefully. Being named as the "certificate holder" on an ACORD 25 gives you notification rights — not coverage rights.
Layer 3 — The Policy Endorsements. The endorsement is the only document that creates legally enforceable rights beyond the named insured's own coverage. Additional insured status requires a carrier-issued endorsement, typically ISO form CG 20 10 (ongoing operations) combined with CG 20 37 (completed operations) for general liability. A waiver of subrogation also requires an endorsement — standard CGL forms (Insurance Services Office standard CGL form CG 00 01) permit waivers of subrogation made in writing before a loss occurs, but individual carrier policies may require an additional endorsement and premium. A notation in the ACORD 25's "Description of Operations" box acknowledging these provisions is not the same as the endorsement itself.
The compliance failure that creates real losses: a vendor submits an ACORD 25 on day one of the contract, someone files it, and nobody checks again. The certificate reflected accurate coverage at the moment of issuance — not at the moment of the claim.
Which Coverage Types Belong in Which Contracts?
Not every policy type belongs in every agreement. Using this table, match the contract scope to the required coverage:
| Contract type | CGL | Professional liability (E&O) | Workers' comp | Cyber liability | Commercial auto | Umbrella |
|---|---|---|---|---|---|---|
| IT managed services / SaaS | ✓ | ✓ | ✓ | ✓ | — | ✓ if >$500K |
| Construction / trade work | ✓ | If design involved | ✓ | — | ✓ | ✓ |
| Consulting / advisory | ✓ | ✓ | ✓ if employees | Recommend | — | Optional |
| Staffing / agency | ✓ | — | ✓ | — | If transport | ✓ if large |
| Physical goods / distribution | ✓ incl. products | — | ✓ | — | ✓ | ✓ |
| Commercial lease (tenant) | ✓ | — | — | — | — | Landlord decides |
| Healthcare / HIPAA-covered | ✓ | ✓ medical mal. | ✓ | ✓ (HIPAA exposure) | — | ✓ |
A pure services contract does not need product liability coverage. A remote consulting engagement with no vehicle use does not need commercial auto. Requiring blanket, maximalist coverage of every possible policy type — a pattern common in large-enterprise boilerplate — forces vendors to pay premiums for policies that have no logical connection to the scope of work, which drives up pricing without reducing actual risk.
The Claims-Made Trap: A Fully Worked Example
This is the coverage gap that causes the most real-world losses, and almost no insurance clause addresses it directly.
Scenario: A SaaS development agency completes a custom platform build under a 12-month statement of work. The contract requires "professional liability insurance, $1 million per claim." The agency carries a claims-made E&O policy during the engagement and cancels it immediately after project delivery to cut costs.
Eight months after delivery, the client discovers a data-leakage flaw in the code. The flaw existed at launch. The client files a claim.
Result: The agency's claims-made policy is gone. The claim is filed after policy cancellation. No coverage. The contract's insurance clause required the coverage only "during the term" — it said nothing about a post-termination tail period. The client's only recourse is a direct lawsuit against the agency's assets, which may be minimal if the agency is a small LLC.
How to prevent it: Draft the insurance clause to specify that professional liability and cyber liability must be maintained on either (a) an occurrence basis, or (b) a claims-made basis with a retroactive date no later than the contract start date and an extended reporting period (tail) of at least two years after contract termination. Many clients require three to five years of tail coverage for high-value software or professional services engagements. This single clause addition costs the vendor little — tail coverage for a one-year E&O policy typically runs 100–200% of the annual premium — but protects both parties from latent defect claims.
Per-occurrence vs. aggregate limits also matter here: a claims-made policy that includes defense costs within the declared limit can be eroded significantly by a single contested claim before any settlement occurs, leaving insufficient coverage for subsequent claims in the same policy year.
How to Draft and Negotiate an Insurance Requirements Clause
Follow these steps when building or reviewing the clause:
-
Define the scope first. List the work, the people performing it, and the property or data involved. The scope dictates which policy types are logically necessary — start there, not from someone else's boilerplate.
-
Specify policy types by name. Write "commercial general liability (CGL), occurrence form" — not just "liability insurance." Write "professional liability, claims-made form, with retroactive date no later than [contract date]" — not just "errors and omissions."
-
Set limits tied to contract value and risk. A common baseline is $1 million per occurrence / $2 million aggregate for CGL, plus statutory workers' compensation limits. For technology contracts handling personal data, most enterprise clients now require separate cyber liability of $1–5 million. Umbrella or excess limits of $1–10 million appear on contracts over $500,000 in value. These numbers are negotiable and should scale with actual exposure, not status anxiety.
-
Require additional insured status on the face of the clause. Name exactly who must be added (the contracting entity, its affiliates, officers, directors, and agents). Specify the ISO endorsement form numbers if your business routinely handles this: CG 20 10 for ongoing operations, CG 20 37 for completed operations.
-
Include waiver of subrogation and primary/non-contributory language. Primary and non-contributory language means the vendor's policy pays first before any policy held by the client is triggered — this is standard in construction contracts and most commercial services agreements.
-
Require proof delivery before work starts. The clause should state that the vendor must deliver a certificate of insurance and copies of all required endorsements before performing any work. Certificates submitted after project start create retroactive exposure gaps.
-
Address post-termination tail periods. For professional liability and cyber coverage, specify the number of years the vendor must maintain either the active claims-made policy or an extended reporting period after the agreement ends.
-
Include a cure or termination right. If the vendor's coverage lapses mid-contract, the client needs the right to either terminate immediately or to purchase the coverage itself and charge the cost back. Many government contracts model this: the contracting party may "obtain such insurance and charge an insurance fee" if the vendor fails to maintain required coverage.
You can generate a services agreement with a structured insurance clause using Pactlio's AI drafting tools, or create an independent contractor agreement that includes scoped coverage requirements appropriate for 1099 workers. For multi-engagement relationships, an MSA is the right vehicle for establishing insurance baselines that flow through to individual statements of work.
For more on the clause's relationship to financial accountability, see our guide to indemnification clauses and our breakdown of limitation of liability provisions, which must be read alongside the insurance clause to understand total risk exposure. When reviewing a counterparty's draft, our contract review guide walks through the sequence of clauses most worth scrutinizing first.
Jurisdiction Notes
Insurance requirements are governed primarily by the underlying insurance law of the state where the risk is located — not where the contract is signed. Key differences:
| Jurisdiction | Notable rule |
|---|---|
| California | Workers' compensation is mandatory for any employee; independent contractors may still trigger WC obligations under ABC test (Cal. Labor Code § 3353) |
| New York | Requires specific ACORD 25 form compliance; using unapproved or outdated COI forms can carry penalties of $1,000–$2,500 per violation |
| Texas | Unique workers' compensation structure — Texas does not require most private employers to carry WC, making the contract clause the primary mechanism for requiring it |
| Florida | Anti-indemnity statute (Fla. Stat. § 725.06) limits how broadly a construction contract can shift liability, which directly affects how the insurance clause must be drafted to remain enforceable |
| Federal contracts | FAR Part 28 governs insurance requirements for federal contractors and sets specific coverage minimums by contract type |
For contracts spanning multiple states, specify that coverage must satisfy the requirements of each state where work is performed — not just the state of the governing law clause.
Common Mistakes to Avoid
- Confusing certificate holder status with additional insured status. They are legally distinct. A certificate holder gets cancellation notices. An additional insured gets coverage. Only a policy endorsement creates the latter.
- Failing to specify occurrence vs. claims-made. Leaving this out means the vendor can satisfy the clause with whichever policy type is cheaper — which may leave you with no coverage for latent defects discovered after project completion.
- Setting limits without checking the vendor's actual capacity. A vendor who agrees to carry $5 million in coverage but whose insurer will only write $1 million has breached the clause before the first deliverable. Verify AM Best rating (ideally A- / VII or better) and confirm the carrier is admitted in the state of performance.
- Requiring coverage irrelevant to the scope. Product liability in a pure services contract, or commercial auto for a fully remote engagement, adds premium cost with no risk reduction — and signals to the vendor that you are not reading your own contracts.
- Accepting a COI without the endorsement documents. A notation in the ACORD 25 "Description of Operations" box acknowledging additional insured status is not the endorsement. Request and review the actual CG 20 10 and CG 20 37 endorsements.
- Not specifying the duration of tail coverage. For any claims-made policy, post-termination tail requirements belong in the clause — not in a side email after the contract expires.
For a broader look at overlooked clause risks, see red flags in contracts and our guide to independent contractor agreements, which addresses insurance obligations specific to 1099 relationships.
Sources
- Insurance Services Office CGL Form CG 00 01: https://www.iso.com/products/commercial-general-liability.html
- ISO Additional Insured Endorsements CG 20 10 and CG 20 37: https://www.iso.com/products/commercial-general-liability.html
- ACORD 25 (2025/12) Certificate of Liability Insurance — ACORD Corporation: https://www.acord.org/standards-architecture/acord-forms/Property-Casualty-Forms
- Taft Law — Insurance Issues in Commercial Contracts: A Checklist for Dealmakers: https://www.taftlaw.com/news-events/law-bulletins/insurance-issues-in-commercial-contracts-a-checklist-for-dealmakers/
- ContractNerds — How to Assess Common Insurance Requirements in Contracts: https://contractnerds.com/how-to-assess-common-insurance-requirements-in-contracts/
- Insurance Training Center — Occurrence vs. Claims-Made Policies Explained: https://insurancetrainingcenter.com/resource/occurrence-vs-claims-made-policies-explained/
- AIA Contract Documents — Claims-Made vs. Occurrence-Based Construction Insurance: https://learn.aiacontracts.com/articles/how-to-manage-risk-using-construction-insurance-bonds-part-9-claims-made-versus-occurrence-based-policies/
- Florida Anti-Indemnity Statute — Fla. Stat. § 725.06: https://www.flsenate.gov/Laws/Statutes/2024/725.06
- California Labor Code § 3353 — Independent Contractor Definition: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=LAB§ionNum=3353
- FAR Part 28 — Bonds and Insurance (Federal Acquisition Regulation): https://www.acquisition.gov/far/part-28
- Outside GC — A Closer Look at Insurance Coverage Requirements in Commercial Contracts: https://outsidegc.com/blog/a-closer-look-at-insurance-coverage-requirements-in-commercial-contracts/
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
What is an insurance requirements clause in a contract?▾
An insurance requirements clause is a contract provision specifying which party must carry insurance, what policy types are required (such as general liability or professional liability), the minimum dollar limits, and how proof of coverage must be provided. It functions as a risk-allocation tool that ensures money is available to cover losses if something goes wrong.
What types of insurance are typically required in a services contract?▾
Most services contracts require commercial general liability (CGL), professional liability (errors and omissions), and workers' compensation. Technology or data-handling contracts increasingly add cyber liability. Contracts involving vehicles require commercial auto liability. The scope of work determines which types are relevant — not every policy type belongs in every agreement.
What is an additional insured endorsement and why does it matter?▾
An additional insured endorsement is a formal amendment attached to the named party's insurance policy that extends liability coverage to a second party. It matters because being listed as a 'certificate holder' on an ACORD 25 form does not grant you any coverage rights — only a carrier-issued endorsement, typically ISO form CG 20 10, actually does that.
What is the difference between occurrence and claims-made coverage in a contract?▾
An occurrence policy covers any incident that happened during the policy period, regardless of when the claim is filed — even years later. A claims-made policy only covers claims filed while the policy is active. For service providers whose work may surface defects months after project completion, the policy type is a critical contract detail that many insurance clauses fail to specify.
Does a certificate of insurance (COI) prove I'm covered under a contract?▾
No. An ACORD 25 certificate of insurance is informational only. The standard disclaimer on every ACORD 25 states that it 'does not affirmatively or negatively amend, extend or alter the coverage afforded by the policies.' Only the underlying policy and its endorsements determine actual coverage rights. Reviewing a COI without reviewing the endorsements is incomplete compliance.
What is a waiver of subrogation in an insurance clause?▾
A waiver of subrogation stops the insurer of one party from suing the other party after paying a claim. For example, if a contractor's negligence damages your property and your insurer pays the claim, a waiver of subrogation prevents your insurer from then suing the contractor. Standard CGL forms permit written pre-loss waivers, but specific carriers may require an endorsement.
How much insurance should I require in a commercial contract?▾
A starting baseline for most commercial service contracts is $1 million per occurrence and $2 million aggregate for general liability, plus statutory workers' compensation. As contract value or data sensitivity increases, many clients require $2 million per occurrence, $4 million aggregate, and separate cyber liability of $1–5 million. Umbrella limits of $1–10 million are common on larger engagements.
Can I negotiate insurance requirements in a commercial contract?▾
Yes. Minimum coverage limits are nearly always negotiable. A vendor can request that coverages inapplicable to their scope be removed (for example, product liability in a pure services deal), that limits be scaled to contract value, or that waiver-of-subrogation requirements be modified if their carrier charges additional premium. Negotiation is expected — but never agree to carry coverage you cannot actually obtain.