Do written agreements with third parties contain defense/indemnification + insurance requirements?
When a supplier causes your breach, these clauses decide whether their insurer or yours pays for it.
What the carrier is actually asking
The carrier is asking whether your written agreements with third parties require them to defend and indemnify you, and to carry insurance appropriate to the risk. It usually also looks for breach notification obligations and confidentiality terms.
Why it is underwritten
Subrogation is a material part of the carrier's economics. If a vendor causes a loss and your contract allows recovery from them, the carrier can pursue it. Without those terms, your policy absorbs the loss entirely, which affects both pricing and the carrier's appetite.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This lives in your contract estate, so it is attested. The evidence is coverage across the estate rather than a single well-drafted template.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Contract templates | Standard indemnity, defence, and limitation of liability provisions | A template that carries the terms, as a starting position for negotiation |
| Contract estate | Executed agreements for critical vendors and the terms they actually contain | What was signed after negotiation, which frequently differs from the template |
| Insurance requirements | Required coverage types and limits per vendor tier | Cyber and technology errors and omissions required at limits proportionate to the engagement |
| Certificate tracking | Certificates of insurance collected and current | Certificates on file and renewed, since a requirement with no verification is a drafting exercise |
| Contract estate | Breach notification obligations and timelines | A defined notification period, since your own regulatory clock starts when the vendor tells you |
The clauses survive in agreements with small suppliers who cannot argue and disappear from agreements with the large platforms that hold most of your data, because their terms are non-negotiable. The result is strong contractual protection exactly where the exposure is smallest. It is worth knowing which of your critical vendors you have no recourse against.
What a defensible yes requires
- Standard terms include defence, indemnification, and insurance requirements.
- Insurance requirements name cyber and technology errors and omissions with proportionate limits.
- Certificates are collected and tracked for renewal.
- Breach notification obligations carry a defined and short timeline.
- You know which critical vendors you accepted weaker terms from, and why.
How this answer goes wrong
The answer is yes because the template contains the clauses. A review of executed agreements shows the three vendors holding the most sensitive data all signed their own paper with liability capped at fees paid and no cyber insurance requirement. The template is not the contract estate.
Frequently asked
What limits should we require?
Proportionate to the data and the criticality. A vendor holding your customer database warrants substantially more than one supplying office equipment.
What if a vendor will not accept our terms?
Document the decision, price the residual risk, and make sure your own cover contemplates it. Accepting weaker terms knowingly is a decision; accepting them without noticing is an exposure.
Do we need certificates every year?
Yes, and tracking renewal is the part that lapses. A requirement without verification tells you what the vendor agreed to, not what they carry today.
How does this affect our claim?
It determines whether your carrier can recover from the vendor. Where recovery is possible, your loss history looks different, which matters at the next renewal.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture