BlogMergers and AcquisitionsInsurance due diligence in 2026: who pays for tail cover after close?

Insurance due diligence in 2026: who pays for tail cover after close?

16 min read
Marc Seitz

Marc Seitz

Insurance due diligence is the review of a target company's insurance programme and loss history before an acquisition closes. It answers two questions: is the business actually covered for the risks it runs, and what will that cover cost the buyer once the shares change hands?

Quick recap

  • Insurance due diligence examines a target's policies, loss history, retentions, collateral, and contractual insurance obligations, and it is normally run by the buyer's broker rather than by the accountants.
  • A standard review works through 12 policy lines: property, general liability, commercial auto, workers' compensation, umbrella and excess, directors and officers, employment practices, professional liability, cyber, environmental, crime and fidelity, and product liability.
  • Loss runs for the last 5 policy years are the core document request, because premium is priced off claims history rather than off policy wording.
  • Claims-made policies stop responding to past acts the moment they lapse, so a change of control usually requires run-off cover, commonly bought for 6 years on directors and officers liability.
  • Workers' compensation premium is driven by an experience modification rate where 1.00 is the industry average, so a rate of 1.24 means paying roughly a quarter more than an average peer for the same payroll.
  • In an asset purchase, occurrence policies stay with the seller's legal entity, so the buyer can start day one with no historic cover at all.
  • Large-deductible programmes sit behind collateral, usually a letter of credit, and that collateral has to be replaced by the buyer at closing rather than assumed.
  • Customer contracts and leases routinely require additional insured status, waivers of subrogation, and minimum limits, and a target that cannot evidence them is in breach.
  • Representations and warranties insurance covers breaches of the seller's representations; it does not repair an underinsured operating programme.
  • A data room for insurance due diligence gives the broker, the lender, and the underwriter their own scoped links to the same policy and claims files, from €99/month with Papermark.

Insurance is the workstream buyers most often delegate and least often read. The broker reports that the programme is broadly adequate, and nobody notices that the directors and officers policy is claims-made, that the seller has no intention of buying run-off, and that the buyer has just inherited six years of unfunded exposure for acts it had nothing to do with. This guide covers the 12 policy lines, how loss runs and the modification rate set the price, what transfers in an asset deal versus a stock deal, and how to run the review without emailing claims files to five parties.

Insurance diligence is unusually multi-party. The broker, the lender, the seller's risk manager, and often a representations and warranties underwriter all read the same claims history. A data room for insurance due diligence gives each of them one link with its own folder scope. Section 9 covers the setup step by step.

1. What is insurance due diligence?

Insurance due diligence is a structured review of everything a target does to transfer risk to an insurer: the policies it buys, the limits and retentions it carries, the claims it has made, the collateral it has posted, and the insurance obligations it has promised to customers, landlords, and lenders. It is commissioned by the buyer after a letter of intent, performed by a broker or a specialist risk advisory team, and delivered as a report that prices the programme on a go-forward basis and flags gaps.

The workstream sits next to financial and legal diligence but asks a different question. Financial diligence asks what the business earned, legal diligence asks what it owes, and insurance diligence asks what happens when something goes wrong and whether the cost lands on the insurer or on the buyer's income statement. On a labour-heavy target the answer moves the model more than buyers expect, because insurance is often the third or fourth largest operating cost after payroll, materials, and rent.

The review also earns its place because insurance is the mechanism by which many other diligence findings get resolved. An environmental exposure, a product recall risk, or an employment claim found elsewhere in the process usually gets handled with cover rather than with a price adjustment, and the insurance reviewer is the person who can say whether that cover exists and what it costs.

Be precise about one distinction. Insurance due diligence reviews the target's own operational programme. Representations and warranties insurance is a transactional product that pays the buyer if the seller's representations turn out to be untrue. They are often placed by the same broker and they are frequently confused. A policy covering a breach of a compliance representation does nothing about a workers' compensation programme running at a 1.24 experience modification rate.

2. The 12 policy lines a reviewer works through

A complete insurance due diligence review covers 12 lines. Not every target buys all 12, and the absence of a line is itself a finding: a manufacturer with no product liability cover, a professional services firm with no errors and omissions policy, or a business holding payment data with no cyber policy each carries an uninsured exposure the buyer owns from closing.

The reviewer works through each line the same way. What limit is carried, what retention sits underneath it, whether the policy is occurrence or claims-made, what the loss history looks like, and what the go-forward premium will be under new ownership. That last point matters most, because a target inside a group programme buys at rates a standalone business of the same size rarely earns.

#Policy lineWhat the reviewer checksTypical red flag
1PropertyValues declared, valuation basis, business interruption limitValues understated, so coinsurance reduces any claim
2General liabilityLimits, aggregate erosion, additional insured endorsementsAggregate already eroded by open claims
3Commercial autoFleet schedule, driver records, hired and non-owned coverPersonal vehicles used for work with no non-owned cover
4Workers' compensationExperience modification rate, class codes, payroll audit historyModification rate above 1.00 and rising
5Umbrella and excessAttachment points, following-form wording, gaps in the towerA gap between the primary limit and the excess attachment
6Directors and officersClaims-made status, run-off availability, entity coverNo run-off budgeted at closing
7Employment practicesRetention level, open matters, wage-and-hour sublimitWage-and-hour claims excluded or sublimited to a token amount
8Professional liabilityRetroactive date, scope of professional services coveredRetroactive date later than the start of trading
9CyberLimit against record count, ransomware and business interruption coverNo policy at all despite holding customer data
10EnvironmentalSite coverage, historic operations, pollution legal liabilityHistoric operations excluded from a current policy
11Crime and fidelityEmployee dishonesty limit, social engineering endorsementNo social engineering cover on a payments-heavy business
12Product liabilityRecall cover, completed operations, geographic scopeUS exposure excluded on a policy written outside the US

Two lines deserve more attention than they get. Cyber is the most frequently missing, and its limit is meaningless unless set against the number of personal records held or the daily revenue at risk from an outage. Environmental is the line where the exposure predates the policy: a pollution liability policy written in 2024 will not necessarily answer contamination created in 1998.

What the seller has to produce

The list below is also the folder structure a seller should build before the room opens, because it maps to how the broker will work.

DocumentWhy the reviewer wants itTypical countSensitivity
Policy schedules and full wordingsLimits, retentions, endorsements, and exclusions as actually written12 to 25Medium
Loss runs, 5 policy yearsClaims frequency and severity, which drive go-forward premium10 to 20High
Experience modification worksheetsWorkers' compensation pricing and whether it is trending up3 to 5Medium
Open claim files and reservesReserve adequacy and any claim likely to breach a retention5 to 40Very high
Certificates of insurance issued to customersWhat the target has promised contractually20 to 200Low
Collateral and letters of creditWhat the buyer must replace at closing on deductible programmes2 to 6High
Safety programme and loss control reportsWhether the loss trend is being actively managed5 to 15Medium

The sensitivity column is what drives how the room is configured. Open claim files are the most sensitive documents in the set, because they contain employee names, medical detail, litigation strategy, and reserve estimates that the seller would not want a competitor or a departing employee to read. They should not carry the same permissions as the policy schedules.

3. Loss runs and the experience modification rate

Loss runs are the most informative document in insurance due diligence. A loss run is the insurer's own record of every claim made under a policy: date of loss, description, amount paid, amount reserved, and whether the claim is open or closed. Five policy years is the standard request.

What the reviewer looks for is not the total but the shape. High frequency with low severity means an operational problem, usually too many small slips, vehicle incidents, and strains. That is expensive but fixable, and it responds to a safety programme within two or three policy years. Low frequency with high severity means a catastrophic exposure that has already materialised once, and it prices the buyer out of the market for several renewals regardless of operational fixes.

Reserves matter as much as payments. An open claim carries a reserve, the insurer's estimate of what it will ultimately pay, and reserves move. A workers' compensation claim reserved at $40,000 in year one can develop into a $400,000 claim by year four as the medical picture becomes clearer. On a large-deductible programme that development is the buyer's cost, not the insurer's, which is why open claims get their own line in the diligence report rather than being netted into a total.

For workers' compensation specifically, the pricing mechanism is the experience modification rate, which compares a company's actual losses against the expected losses for its industry and payroll size, with 1.00 representing the industry average. A rate of 1.24 means the company pays roughly 24 percent more than an average peer for identical payroll. On a business with a $12M payroll in a hazardous class code, the gap between 1.24 and 0.85 is a six-figure annual cost that flows straight into the deal model. The rate is also forward-looking, because it is calculated on a rolling multi-year window: a rate that was 1.05 three years ago and is 1.24 today will keep climbing even if the safety programme is fixed tomorrow.

4. Claims-made cover and the run-off tail trap

This is the finding that most often surprises a first-time buyer, and it is entirely avoidable. Policies come in two shapes. An occurrence policy responds to events that happened during the policy period whenever the claim is eventually made, which is why a general liability policy from 2019 still answers an injury that occurred in 2019 even if the claim arrives in 2026. A claims-made policy responds only to claims first made while the policy is in force.

Four of the twelve lines are usually written claims-made: directors and officers, employment practices, professional liability, and cyber. On those lines, letting the policy lapse does not just end cover for the future. It ends cover for the past. The moment the seller's directors and officers policy is cancelled at closing, every act and omission of the previous management team becomes uninsured, and the claim that arrives eighteen months later has nowhere to go.

The remedy is run-off cover, also called tail cover or an extended reporting period, which keeps the expiring policy alive for claims arising from acts before closing but reported afterwards. Six years is the market standard on directors and officers cover in a private company sale, chosen to line up with common limitation periods, and brokers commonly quote it at roughly 200 to 300 percent of the expiring annual premium as a single payment at closing.

Link-level permissions restricting the claims folder to the broker in a data room for insurance due diligence

Open claim files go to the broker and the underwriter, not to the lender or the operational reviewers.

Three practical points follow. Run-off is bought once and cannot be bought later, so it belongs in the purchase agreement rather than in a post-closing checklist. Who pays is a negotiation, and the usual outcome is that the seller pays because it protects the seller's own former directors, but a buyer who never raises it will end up paying. And the retroactive date on any replacement claims-made policy should be checked, because a new policy dated at closing offers nothing at all for prior acts.

5. Asset deals, stock deals, and what actually transfers

Deal structure changes the insurance answer completely, and it is worth being explicit because the two cases look nothing alike.

In a stock purchase, the buyer acquires the legal entity and the entity keeps its policies. Occurrence cover for prior years stays where it is, historic claims stay with the same insurers, and the practical work is a change-of-control notice to each carrier plus a decision about whether to keep the programme or move onto the buyer's own policies at renewal. Even here the reviewer checks change-of-control clauses, because a target inside a group programme falls out of that programme at closing.

In an asset purchase, the policies stay with the seller's entity because they belong to that entity. The buyer acquires machines, contracts, and employees, and acquires no insurance at all. That produces two exposures. Cover has to be bound before closing rather than after. And nothing insures the buyer for something that happened before closing, even where the liability transfers with the assets under successor liability principles: a product manufactured last year that injures someone next year is an exposure the buyer may own with no policy responding to it.

Collateral deserves its own note because it is a cash item rather than an expense item. A business running a large-deductible workers' compensation programme has usually posted a letter of credit so the insurer is secured for the deductible layer it pays out and bills back. That collateral is supported by the seller's credit and does not transfer, so the buyer posts replacement collateral at closing. On a mid-sized labour-heavy business that is a seven-figure draw on the buyer's own facility that nobody modelled.

6. Insurance obligations hidden in customer contracts and leases

The last place a reviewer looks is usually where the biggest surprise sits: the target's own contracts. Insurance obligations are written into customer master agreements, subcontracts, property leases, and loan documents, drafted by the counterparty's lawyers rather than by the target's broker, and nobody checks whether the two match until diligence.

Three obligations recur. Minimum limits specify how much cover the target must carry, so a target with a $2M general liability limit that signed contracts requiring $5M is in breach of every one. Additional insured status extends the policy to the customer for liability arising out of the target's work, which needs a specific endorsement and is not automatic. Waiver of subrogation stops the insurer recovering against the customer after paying a claim, and also requires an endorsement.

Contract requirementWhat it obliges the target to doHow it fails in practice
Minimum limitsCarry a stated limit per line for the contract termLimits reduced at a renewal to save premium, contracts never re-read
Additional insuredEndorse the customer onto the policyCertificate says additional insured, no endorsement was ever issued
Waiver of subrogationWaive the insurer's recovery rights against the customerEndorsement missing, insurer sues the customer after paying
Primary and non-contributoryRespond before the customer's own policyWording absent, both insurers argue and the customer escalates
Notice of cancellationGive the customer 30 days notice of any lapsePolicy changed at renewal, notice never sent, customer alleges breach
Landlord and lender interestsName the landlord or lender on property coverProperty sold or refinanced, schedule never updated

There is a documentation trap here as well. A certificate of insurance is evidence, not cover: it is a one-page broker summary that explicitly disclaims conferring rights. A certificate stating the customer is an additional insured proves nothing unless the endorsement exists on the policy. During diligence that means sampling. Pick the five largest customer contracts, read the insurance clause, then find the matching endorsement rather than accepting the certificate.

Dynamic watermarking applied to claims files shared with the broker and the underwriter

Open claim files carry employee names and medical detail, so the folder is view-only and watermarked per viewer.

7. Worked scenario: insuring the acquisition of Kestrel Facilities

A lower middle market private equity fund agrees to acquire Kestrel Facilities Services, a $48M revenue commercial cleaning and building maintenance company with 620 employees across three states. The business is labour-heavy and vehicle-heavy, which means the insurance programme is dominated by workers' compensation and auto, and it is exactly the profile where insurance due diligence changes the model rather than confirming it.

The broker requests five years of loss runs and the current policy schedules on day three. Total insured premium comes to $1.42M a year: workers' compensation $780,000, general liability and commercial auto together $310,000, umbrella and excess $130,000, property $95,000, management liability covering directors and officers plus employment practices $70,000, and cyber $35,000.

Kestrel Facilities: annual insured premium by line at diligence
$1.42Mannual premium
  • Workers' compensation780 · 55%
    $780K, rated at a 1.24 experience modification
  • General liability and auto310 · 22%
    $310K, 140 vehicles on the fleet schedule
  • Umbrella and excess130 · 9%
    $130K, attaching above the primary auto limit
  • Property95 · 7%
    $95K across four leased locations
  • Management liability70 · 5%
    $70K, written claims-made, run-off required
  • Cyber35 · 2%
    $35K, limit set against 620 employee records

Worked scenario. Workers' compensation is 55 percent of the programme, which is why the 1.24 experience modification rate is the finding that matters most.

Three findings emerge. The experience modification rate is 1.24 and was 1.05 three years ago, so the fund models premium at $1.42M rather than the $1.15M the seller allocated internally. The management liability policies are claims-made with no run-off budgeted, so the fund negotiates a six-year run-off into the purchase agreement at the seller's cost. And Kestrel runs a $250,000 per-claim deductible on workers' compensation behind a $1.5M letter of credit posted by the seller, which the fund must replace at closing.

A fourth finding is contractual. Sampling the six largest cleaning contracts shows four require $5M of general liability cover and additional insured status, while Kestrel carries $2M primary with a $5M umbrella and has no endorsement on file for two of them. The remedy costs a few thousand dollars and takes a week, but only because someone read the contracts before closing.

Diligence runs through a room holding 180 documents across nine folders, with the broker, the lender, and the representations and warranties underwriter each on their own link. The open claims folder is view-only and watermarked, because it names 23 injured employees.

8. Common mistakes in insurance due diligence

The most common mistake is starting the insurance review after the model is fixed. Insurance findings are cost findings, and a $270,000 annual premium increase discovered in the last week of exclusivity is very hard to reflect in a price already agreed in principle. The broker should have loss runs in week one, not week five.

The second is accepting certificates of insurance as proof of cover. Sample the largest contracts and verify against the policy endorsements instead. If an additional insured endorsement cannot be produced, it does not exist.

The third is forgetting run-off. Four of the twelve lines are usually claims-made, run-off can only be bought at closing, and the party who benefits most is the seller's own former board. It belongs in the purchase agreement alongside the escrow and the working capital peg. Our guide to the M&A due diligence checklist covers where this sits in the wider process.

The fourth is treating a group-programme target as if it keeps group pricing. Ask the broker to price the programme standalone and put the difference in the model as a permanent cost increase.

The fifth is circulating claims files carelessly. Open claim files name injured employees, describe medical treatment, and set out litigation strategy. Emailing them to a broker, a lender, an underwriter, and two advisors creates a privacy exposure the seller carries even if the deal never completes. The data room checklist covers how to structure this properly.

Manage due diligence with a virtual data room

No credit card required

Page by page analytics
Unlimited documents & folders
Permission management
Dynamic watermarks
NDA collection
Real-time alerts
Custom branding
Audit trail

9. Data room for your insurance due diligence

A data room for insurance due diligence is not the same artifact as the financial room. The financial folder holds commercially sensitive numbers. The claims folder holds employee names, medical detail, and reserve estimates, which are sensitive in a different and more regulated way. That difference should change how the room is built and who gets which link.

Papermark is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available).

Papermark data room for insurance due diligence with folders organised by policy line

An insurance due diligence data room with one folder per policy line, so permissions differ by folder rather than by document.

Why you need a data room for insurance due diligence

Most insurance diligence still runs over email, because the broker asks for loss runs and the seller's risk manager attaches them to a reply. There are four reasons a dedicated data room for insurance due diligence earns its place instead. If you are still choosing a platform, our comparison of the best virtual data rooms covers pricing model, permissions, and compliance across the main providers.

Claims files contain personal and medical data. An open workers' compensation file names an injured employee and describes their treatment. Under GDPR that is special category data, and a breach affecting it triggers a 72-hour notification duty. Emailing those files to four external parties is a processing decision nobody documented, and the seller carries the exposure even if the deal never completes.

Four parties need four different views. The broker needs everything. The lender needs certificates and collateral and nothing else. The representations and warranties underwriter needs loss runs and schedules but has no business reading individual claim files. A shared drive gives you one permission set; a data room for insurance due diligence gives you one per link over the same documents.

Requests arrive in waves. The broker asks for loss runs, then for the three open claim files they reference, then for reserve development on one of those. Across 180 documents and 40 open questions an email thread loses track, and the same question gets asked twice.

The disclosure record matters at claim time. If a representations and warranties claim arises two years after closing, the underwriter asks what was disclosed and when, because anything the buyer knew before binding is excluded. A per-visitor audit log answers that. An inbox does not.

The rest of this section is the practical setup: five steps that handle all four.

Step 1: build the room by policy line, not by document

Create one folder per policy line, plus a claims folder, a collateral folder, and a contracts folder for the certificates and customer insurance clauses. That structure is what makes differentiated access possible later, and it matches how the broker works, which shortens the review.

Upload in bulk by dragging the folder tree straight in. Automatic file indexing on Data Rooms Plus builds and maintains the index as documents arrive, which matters here because loss runs land in waves.

Bulk document upload into a data room for insurance due diligence

Drag the policy and claims folder tree in as a whole; the index builds itself as files arrive.

Step 2: set permissions per reviewer group

This is where an insurance room differs most from a financial one, because one folder is materially more sensitive than the rest.

ReviewerFolders grantedRights
Buyer's insurance brokerAll 12 lines, claims, collateral, contractsView and download
Representations and warranties underwriterPolicy schedules, loss runs, safety reportsView only, watermarked
LenderCertificates, collateral, property schedulesView only
Buyer's operational reviewerSafety programme and loss controlView only

Granular file-level permissions are set per link rather than per user, so each party gets one link carrying its own folder scope, email allowlist, and download rule. Access is link-based, so no reviewer creates an account, which removes the friction that makes a busy broker fall back to email.

Granular folder-level permissions applied per reviewer link in a Papermark data room

Permissions are set per link, so the lender and the underwriter see different folders of the same insurance room.

Step 3: lock down the claims folder

Set the claims folder to view-only and turn on dynamic watermarking, which stamps every page with the viewer's email, IP address, and timestamp as it renders. On files naming individual employees, that is the difference between an untraceable leak and a traceable one. Screenshot protection adds a further deterrent on the open claim files.

State the honest limit: a downloaded file is legally treated as read, and no platform can recall it. That is why download is disabled rather than discouraged on this folder.

Step 4: run the request waves through Q&A, not email

The broker asks about reserve development, the underwriter asks the same question a week later, and the risk manager answers both separately with slightly different numbers.

The Q&A module attaches each question to the document that prompted it, with permissions controlling who sees which threads, so the lender never reads the underwriter's questions. Answers publish to one group or to everyone, and the log exports for the closing file.

Step 5: read the analytics, then freeze the room

Page-level analytics show which reviewer opened which document, when, and for how long. In insurance diligence that is an early warning: a broker who has spent thirty minutes inside one open claim file has found a reserve problem, and you will hear about it a week before the report lands.

Per-visitor analytics across insurance due diligence documents in a Papermark data room

Per-visitor analytics show which policy and claims documents each reviewer opened and for how long.

After closing, data room freeze makes the room immutable and exports it as an archived ZIP with a certificate. If a representations and warranties claim arises two years later, that archive is the record of exactly what was disclosed, to whom, and on what date.

Tyler

Papermark is our #1 VDR provider for M&A transactions right now. In two deals we used custom branding, dynamic watermarking, and granular permissions.

Tyler

Fox Island Group

What it costs

The Data Rooms plan is €99/month with a 7-day free trial and includes 3 team members, unlimited data room visitors, unlimited data rooms, unlimited documents, custom domain, dynamic watermarking, NDA agreements, and granular file-level permissions. Data Rooms Plus at €249/month adds 5 team members, the Q&A module, the audit log, automatic file indexing, and SOC 2 Type II. Data Rooms Premium at €549/month adds 10 team members, AI redaction, full API access, SSO, and whitelabeling. Data Rooms Unlimited at €999/month removes per-seat charges entirely, so teams that add reviewers mid-deal pay one number regardless of headcount, and it carries every Premium capability including AI redaction. For a buyer running several acquisitions a year, unlimited data rooms under one subscription means one insurance room per deal with no per-project fee.

No credit card required.

FAQ

More useful articles from Papermark

Ready to create your deal room?