Home/Questions/Services and contracts/Liability limitation clauses
Services and contracts

Do the Applicant's client contracts contain limitation of liability clauses benefiting the Applicant?

The liability cap is the single most consequential commercial term in a professional services contract, and the carve-outs are where it stops applying.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether your client contracts contain limitation of liability clauses that benefit you, typically capping liability at fees paid or a multiple of them.

Why it is underwritten

The cap sets the ceiling on what a client can recover, which is the ceiling on the carrier's exposure per relationship. Contracts without caps, or with caps carved out for data breach, expose the full limit and beyond. Carriers price the contractual position because it determines their maximum loss per client.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is a contract estate question, and the executed terms matter rather than the template.

PlatformWhere the setting livesWhat has to be true
TemplatesStandard limitation clause and its cap basisA cap expressed in a way that scales sensibly, such as fees paid in the preceding twelve months. Attested
Contract estateWhat was actually agreed after negotiation with major clientsExecuted caps, which frequently differ from the template
Carve-outsExceptions to the capData breach, confidentiality, and indemnity carve-outs, which are where the cap stops applying
UncappedContracts with no cap or an uncapped data liabilityIdentified and quantified against your policy limit
EnforceabilityWhether caps are enforceable in the governing jurisdictionsLegal review, since some jurisdictions restrict limitation clauses
Data breach carve-outs are the standard ask

Enterprise clients routinely negotiate the cap away for data breach specifically, which is exactly the loss your cyber policy is meant to cover. That carve-out converts a bounded exposure into an unbounded one for the loss most likely to occur.

What a defensible yes requires

  • Standard terms include a liability cap on a defensible basis.
  • Executed contracts with major clients have been reviewed for what was actually agreed.
  • Carve-outs are inventoried, particularly for data breach.
  • Uncapped exposure is quantified and compared against the policy limit.
  • Enforceability has been checked in the governing jurisdictions.

How this answer goes wrong

The template caps liability at fees paid, and the three largest clients negotiated an uncapped data liability. Those three contracts represent most of the revenue and effectively all of the exposure, and nobody compared them against the limit.

Frequently asked

What cap level is normal?

Fees paid in the preceding twelve months is the common baseline, with multiples negotiated upward for larger engagements. It varies widely by sector.

What if a client demands unlimited data liability?

Price it, quantify it against your limit, and take the decision deliberately. Some organisations accept it commercially; the mistake is accepting it without noticing.

Are caps always enforceable?

Not everywhere and not for every category. Some jurisdictions restrict limitation for certain conduct, so local advice matters.

Does the cyber policy respond above the cap?

The cap limits what the client can recover from you. Where it is carved out, your exposure runs to the policy limit and beyond it.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture