Third parties and vendors

Do written agreements with third parties contain defense/indemnification + insurance requirements?

When a supplier causes your breach, these clauses decide whether their insurer or yours pays for it.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether your written agreements with third parties require them to defend and indemnify you, and to carry insurance appropriate to the risk. It usually also looks for breach notification obligations and confidentiality terms.

Why it is underwritten

Subrogation is a material part of the carrier's economics. If a vendor causes a loss and your contract allows recovery from them, the carrier can pursue it. Without those terms, your policy absorbs the loss entirely, which affects both pricing and the carrier's appetite.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This lives in your contract estate, so it is attested. The evidence is coverage across the estate rather than a single well-drafted template.

PlatformWhere the setting livesWhat has to be true
Contract templatesStandard indemnity, defence, and limitation of liability provisionsA template that carries the terms, as a starting position for negotiation
Contract estateExecuted agreements for critical vendors and the terms they actually containWhat was signed after negotiation, which frequently differs from the template
Insurance requirementsRequired coverage types and limits per vendor tierCyber and technology errors and omissions required at limits proportionate to the engagement
Certificate trackingCertificates of insurance collected and currentCertificates on file and renewed, since a requirement with no verification is a drafting exercise
Contract estateBreach notification obligations and timelinesA defined notification period, since your own regulatory clock starts when the vendor tells you
Large vendors negotiate these terms away

The clauses survive in agreements with small suppliers who cannot argue and disappear from agreements with the large platforms that hold most of your data, because their terms are non-negotiable. The result is strong contractual protection exactly where the exposure is smallest. It is worth knowing which of your critical vendors you have no recourse against.

What a defensible yes requires

  • Standard terms include defence, indemnification, and insurance requirements.
  • Insurance requirements name cyber and technology errors and omissions with proportionate limits.
  • Certificates are collected and tracked for renewal.
  • Breach notification obligations carry a defined and short timeline.
  • You know which critical vendors you accepted weaker terms from, and why.

How this answer goes wrong

The answer is yes because the template contains the clauses. A review of executed agreements shows the three vendors holding the most sensitive data all signed their own paper with liability capped at fees paid and no cyber insurance requirement. The template is not the contract estate.

Frequently asked

What limits should we require?

Proportionate to the data and the criticality. A vendor holding your customer database warrants substantially more than one supplying office equipment.

What if a vendor will not accept our terms?

Document the decision, price the residual risk, and make sure your own cover contemplates it. Accepting weaker terms knowingly is a decision; accepting them without noticing is an exposure.

Do we need certificates every year?

Yes, and tracking renewal is the part that lapses. A requirement without verification tells you what the vendor agreed to, not what they carry today.

How does this affect our claim?

It determines whether your carrier can recover from the vendor. Where recovery is possible, your loss history looks different, which matters at the next renewal.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture