Do the Applicant's client contracts contain limitation of liability clauses benefiting the Applicant?
The liability cap is the single most consequential commercial term in a professional services contract, and the carve-outs are where it stops applying.
What the carrier is actually asking
The carrier is asking whether your client contracts contain limitation of liability clauses that benefit you, typically capping liability at fees paid or a multiple of them.
Why it is underwritten
The cap sets the ceiling on what a client can recover, which is the ceiling on the carrier's exposure per relationship. Contracts without caps, or with caps carved out for data breach, expose the full limit and beyond. Carriers price the contractual position because it determines their maximum loss per client.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is a contract estate question, and the executed terms matter rather than the template.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Templates | Standard limitation clause and its cap basis | A cap expressed in a way that scales sensibly, such as fees paid in the preceding twelve months. Attested |
| Contract estate | What was actually agreed after negotiation with major clients | Executed caps, which frequently differ from the template |
| Carve-outs | Exceptions to the cap | Data breach, confidentiality, and indemnity carve-outs, which are where the cap stops applying |
| Uncapped | Contracts with no cap or an uncapped data liability | Identified and quantified against your policy limit |
| Enforceability | Whether caps are enforceable in the governing jurisdictions | Legal review, since some jurisdictions restrict limitation clauses |
Enterprise clients routinely negotiate the cap away for data breach specifically, which is exactly the loss your cyber policy is meant to cover. That carve-out converts a bounded exposure into an unbounded one for the loss most likely to occur.
What a defensible yes requires
- Standard terms include a liability cap on a defensible basis.
- Executed contracts with major clients have been reviewed for what was actually agreed.
- Carve-outs are inventoried, particularly for data breach.
- Uncapped exposure is quantified and compared against the policy limit.
- Enforceability has been checked in the governing jurisdictions.
How this answer goes wrong
The template caps liability at fees paid, and the three largest clients negotiated an uncapped data liability. Those three contracts represent most of the revenue and effectively all of the exposure, and nobody compared them against the limit.
Frequently asked
What cap level is normal?
Fees paid in the preceding twelve months is the common baseline, with multiples negotiated upward for larger engagements. It varies widely by sector.
What if a client demands unlimited data liability?
Price it, quantify it against your limit, and take the decision deliberately. Some organisations accept it commercially; the mistake is accepting it without noticing.
Are caps always enforceable?
Not everywhere and not for every category. Some jurisdictions restrict limitation for certain conduct, so local advice matters.
Does the cyber policy respond above the cap?
The cap limits what the client can recover from you. Where it is carved out, your exposure runs to the policy limit and beyond it.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture