Coverage Register
Every line of cover · Financial lines

Directors and officers

Defence costs and damages when directors, officers and (under management liability) the company itself are pursued for a wrongful act in managing the business: regulators, shareholders, creditors, employees.

On the schedule

Also calledD&O, management liability, directors liability
FamilyFinancial lines
Responds whenA regulator investigates, a liquidator sues the board, a shareholder alleges misleading disclosure.

Which industries carry it

Usually held byFood manufacturing, General manufacturing, Logistics and warehousing, Construction, Professional services, Software and SaaS, Healthcare provider, Mining and resources, Education, Financial services, Non-profit, Energy and utilities, Transport, Media and marketing, Public sector
Often needed, often lackingRetail, Hospitality, Property owner, Wholesale distribution

Standards this line engages

6 clauses

Clause text quoted from a human-verified compliance corpus under licence. Clauses marked for APRA-regulated buyers or US insurance licensees appear on a register only for those buyers.

ISO 31000 6.5.2 Selection of risk treatment options

Guidance: choosing treatment options balances the benefits for the objectives against the cost, effort and disadvantages of implementing them. Options are not mutually exclusive and not all fit every situation; they include avoiding the risk by not starting or continuing the activity, taking or increasing the risk to pursue an opportunity, removing the risk ...

Evidence an auditor accepts: Treatment option analysis per risk showing the options considered, their cost and benefit, and the one chosen; Insurance schedule, contracts and other risk-sharing arrangements tied to the risks they transfer; Documented retained and residual risk with the decision maker's acceptance
Common gap: Only mitigation considered; avoiding, taking or sharing never on the table
ISO 31000:2018 on compliance.theartofservice.com
ISO 31000 5.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities

Guidance: top management and oversight bodies should ensure that the authorities, responsibilities and accountabilities for every relevant risk management role are assigned and communicated at all levels of the organization. In doing so they should make clear that managing risk is a core responsibility rather than an add-on, and should identify the individua...

Evidence an auditor accepts: Named risk owners for each significant risk; RACI or equivalent assignment of risk management roles and authorities; Role descriptions and delegations that carry risk accountability
Common gap: Risks recorded without an owner, or owned by a committee
ISO 31000:2018 on compliance.theartofservice.com
COSO ERM principle 1 Exercises Board Risk Oversight

The board provides oversight of strategy and carries out governance responsibilities to support management in achieving strategic and business objectives.

Evidence an auditor accepts: Board charter; Risk committee minutes; Annual risk oversight report
Common gap: No documented risk oversight cadence
COSO ERM 2017 on compliance.theartofservice.com
COSO ERM principle 7 Defines Risk Appetite

The organization defines risk appetite in the context of creating, preserving, and realizing value.

Evidence an auditor accepts: Risk appetite statement; Board approval records; Risk tolerance thresholds
Common gap: Qualitative-only appetite
COSO ERM 2017 on compliance.theartofservice.com
COSO ERM principle 13 Implements Risk Responses

The organization identifies and selects risk responses.

Evidence an auditor accepts: Risk treatment plans; Action owner assignments; Cost-benefit analyses
Common gap: Response chosen without analysis
COSO ERM 2017 on compliance.theartofservice.com
ISO 31000 6.3.3 External and internal context

Guidance: the external and internal context is the environment in which the organization defines and pursues its objectives. The context of the risk management process should be established from an understanding of that environment and should reflect the specific environment of the activity the process is applied to, because risk management happens in the co...

Evidence an auditor accepts: Context statement for the assessment, drawing on the external and internal factors of 5.4.1; Link from the assessment context to the organizational context used for the framework
Common gap: Context copied from the enterprise level and not adjusted to the activity
ISO 31000:2018 on compliance.theartofservice.com

Do this for every line on your schedule

Paste the schedule and get this classification for every line at once, with the retained and transferred figures, the rate on line, the loss ratio, the findings and the questions for the broker. Six lines free, no account.

Build my coverage register

Crime and fidelity · Employment practices liability