Coverage Register
Every line of cover · Liability

Umbrella and excess liability

A further layer of liability limit that sits above the primary public, products, motor or employers liability policies and responds once those limits are used up.

On the schedule

Also calledumbrella liability, excess liability, excess layer
FamilyLiability
Responds whenA liability claim is large enough to exhaust the primary policy limit.

Which industries carry it

Usually held bynone of the twenty classes as a usual line; bought for a specific exposure
Often needed, often lackingnot on any watch list

Standards this line engages

6 clauses

Clause text quoted from a human-verified compliance corpus under licence. Clauses marked for APRA-regulated buyers or US insurance licensees appear on a register only for those buyers.

ISO 31000 6.5.2 Selection of risk treatment options

Guidance: choosing treatment options balances the benefits for the objectives against the cost, effort and disadvantages of implementing them. Options are not mutually exclusive and not all fit every situation; they include avoiding the risk by not starting or continuing the activity, taking or increasing the risk to pursue an opportunity, removing the risk ...

Evidence an auditor accepts: Treatment option analysis per risk showing the options considered, their cost and benefit, and the one chosen; Insurance schedule, contracts and other risk-sharing arrangements tied to the risks they transfer; Documented retained and residual risk with the decision maker's acceptance
Common gap: Only mitigation considered; avoiding, taking or sharing never on the table
ISO 31000:2018 on compliance.theartofservice.com
ISO 31000 6.4.4 Risk evaluation

Guidance: risk evaluation supports decisions by comparing the results of analysis with the risk criteria to determine where further action is needed. The comparison can lead to doing nothing further, considering treatment options, analysing further to understand the risk better, maintaining existing controls, or reconsidering the objectives themselves. Decis...

Evidence an auditor accepts: Evaluation outcome per risk against the criteria, with the decision taken (treat, tolerate, analyse further, maintain controls, revisit objectives); Sign-off of evaluation outcomes at the appropriate level; Communication of outcomes to affected stakeholders
Common gap: Evaluation reduced to a colour on a heat map with no decision attached
ISO 31000:2018 on compliance.theartofservice.com
COSO ERM principle 11 Assesses Severity of Risk

The organization assesses the severity of risk.

Evidence an auditor accepts: Likelihood-impact matrix; Inherent vs residual risk ratings; Scenario analysis
Common gap: Subjective scoring only
COSO ERM 2017 on compliance.theartofservice.com
ISO 31000 6.4.3 Risk analysis

Guidance: risk analysis builds an understanding of the nature and characteristics of a risk, including its level where appropriate, by considering in detail uncertainties, sources, consequences, likelihood, events, scenarios, controls and how effective they are; one event can have several causes and consequences and touch several objectives. Analysis can be ...

Evidence an auditor accepts: Analysis record per risk: likelihood, consequence, existing controls and their effectiveness, level of risk; Statement of assumptions, exclusions, information quality and confidence attached to the analysis; Choice of qualitative or quantitative technique and the reason
Common gap: Control effectiveness assumed rather than assessed
ISO 31000:2018 on compliance.theartofservice.com
ISO 31000 6.3.4 Defining risk criteria

Guidance: the organization should specify the amount and type of risk it may or may not take relative to its objectives, and should define criteria for judging the significance of risk and supporting decisions. Risk criteria should align with the framework and be customized to the purpose and scope of the activity; they should reflect the organization's valu...

Evidence an auditor accepts: Documented risk criteria: consequence and likelihood scales, how level of risk is derived, time horizons, treatment of combined risks; Risk appetite or tolerance statement the criteria derive from; Review record showing criteria revisited when context changed
Common gap: A five-by-five matrix with no definition of what a consequence level means
ISO 31000:2018 on compliance.theartofservice.com
COSO ERM principle 13 Implements Risk Responses

The organization identifies and selects risk responses.

Evidence an auditor accepts: Risk treatment plans; Action owner assignments; Cost-benefit analyses
Common gap: Response chosen without analysis
COSO ERM 2017 on compliance.theartofservice.com

Do this for every line on your schedule

Paste the schedule and get this classification for every line at once, with the retained and transferred figures, the rate on line, the loss ratio, the findings and the questions for the broker. Six lines free, no account.

Build my coverage register

Technology errors and omissions · Business interruption