Skip to main content
Category: Policy Structure & Terms

Claims-Made Policy

Also known as: claims-made coverage, claims-made form
Simply put

A claims-made policy is a type of insurance whose coverage is triggered by when a claim is first made against the insured, rather than by when the underlying event happened. In many such policies the claim must be made, and often reported, while the policy is active for coverage to apply. This differs from an occurrence-based policy, which responds based on when the wrongful act or incident took place.

Formal definition

A claims-made policy is a coverage form in which the operative trigger is the assertion of a claim against the insured during the policy period, regardless of when the underlying wrongful act occurred, subject to the specific policy wording. Coverage typically depends on the insured being covered at the time the claim is made, and many claims-made forms also require that the claim be reported to the insurer while the policy is in force. Some forms further condition coverage on a retroactive date, so that the wrongful act must have taken place on or after that date; sources vary in emphasis, with some describing coverage as requiring both the incident and the claim to fall within the policy period. Because coverage generally ceases when the policy expires unless extended, the availability of any given loss under a claims-made form is conditional on the precise policy terms, endorsements, reporting requirements, retroactive dates, and any extended reporting provisions. This entry addresses the coverage-trigger structure only and does not by itself specify sublimits, retentions, exclusions, or whether a particular first-party or third-party loss is covered.

Why it matters

The claims-made structure is central to how most cyber liability coverage is written, and misunderstanding it can leave an organization exposed at exactly the moment it needs protection. Because coverage is triggered by when a claim is first made against the insured rather than by when the underlying wrongful act occurred, a data breach or privacy incident that took place while one policy was in force may need to be covered by a policy that is active when the claim actually arrives. That timing distinction matters most at moments of transition: when an insured switches carriers, lets a policy lapse, or winds down operations. In each case, a claim asserted after the policy expires may fall outside coverage unless specific provisions extend the reporting window.

The practical consequences are heightened by two features common to claims-made forms. Many require not only that the claim be made during the policy period but also that it be reported to the insurer while the policy is in force, which places a premium on prompt notice and disciplined claim-handling procedures. Some forms also condition coverage on a retroactive date, meaning wrongful acts before that date are excluded even if the claim itself is timely. For cyber risks, where an intrusion may go undetected for a long time before a claim surfaces, these conditions can determine whether a loss is covered at all.

Because the availability of any given loss under a claims-made form depends on the precise policy wording, reporting requirements, retroactive dates, and extended reporting provisions, risk managers and brokers treat continuity of coverage as a governance issue rather than a routine renewal. The trigger structure described here does not by itself decide whether a particular first-party or third-party loss is covered; that turns on sublimits, retentions, exclusions, and other terms. But if the claims-made trigger is not satisfied, those other provisions never come into play.

Who it's relevant to

Risk Managers
Risk managers must track retroactive dates, reporting deadlines, and any gaps that arise when changing carriers or allowing a policy to expire. Because coverage generally ends when a claims-made policy expires unless extended, maintaining continuity across renewals is a core responsibility, and lapses can leave incidents that predate a new policy uncovered.
Insurance Brokers and Underwriters
Brokers and underwriters need to explain and structure the claims-made trigger accurately, including how retroactive dates and extended reporting provisions interact. Sources differ in how they describe the trigger, so precise attention to the specific policy wording is essential when placing coverage or comparing a claims-made form against an occurrence-based alternative.
Chief Information Security Officers
CISOs whose incidents may surface long after an intrusion should understand that a claims-made policy responds based on when a claim is made and often when it is reported, not when the wrongful act occurred. Prompt internal escalation and timely notice to the insurer can be decisive, since many forms require reporting while the policy is in force.
Legal and Compliance Professionals
Legal and compliance teams advising on coverage disputes and reporting obligations must parse how the trigger, retroactive date, and reporting conditions apply to a given claim. Because whether a loss is covered depends on the precise terms rather than the trigger structure alone, careful reading of the policy wording is necessary before relying on coverage.

Inside Claims-Made Policy

Claims-Made Trigger
A coverage trigger under which the policy responds to claims first made against the insured (and typically reported to the insurer) during the policy period, regardless of when the underlying act or event occurred, subject to the specific wording.
Retroactive Date
A date specified in the policy before which wrongful acts, incidents, or occurrences are not covered. Acts taking place before the retroactive date are generally excluded even if the claim is made during the policy period, depending on the exact wording.
Reporting Requirement / Notification Condition
A condition precedent in many claims-made forms requiring the insured to report claims (and often circumstances that may give rise to a claim) to the insurer within the policy period or a specified window. Failure to comply can jeopardize coverage, subject to jurisdiction and wording.
Extended Reporting Period (ERP) / Tail Coverage
An option or endorsement allowing claims made after the policy expires to be reported, provided the wrongful act occurred during the covered period and after any retroactive date. Relevant when a policy is not renewed or is replaced, subject to the specific terms.
Prior and Pending Litigation / Known Circumstances Provisions
Provisions that typically exclude claims arising from litigation, proceedings, or circumstances known to the insured before inception or a specified date, limiting coverage for matters the insured was already aware of.
Relevance to Cyber Coverage
Many cyber liability (third-party) coverages, such as those responding to privacy claims and regulatory defense, are written on a claims-made basis. Whether a given claim is covered depends on policy wording, the retroactive date, reporting compliance, endorsements, and exclusions.

Common questions

Answers to the questions practitioners most commonly ask about Claims-Made Policy.

Does a claims-made policy cover any incident that happened while it was in force?
Not on its own. A claims-made policy generally responds based on when the claim is first made against the insured (and reported to the insurer), not when the underlying incident or wrongful act occurred. An incident that happened during the policy period but results in a claim after the policy has expired may not be covered unless other provisions apply, such as a retroactive date that reaches back to the incident and an active policy (or extended reporting period) at the time the claim is made. This differs from an occurrence-based approach, which ties coverage to when the event took place. Whether any particular claim is covered depends on the specific policy wording, the retroactive date, reporting conditions, and applicable exclusions.
Is a claims-made policy the same thing as a claims-made-and-reported policy?
They are related but not necessarily identical, and the distinction matters. A claims-made form generally requires that the claim first be made against the insured during the policy period. A claims-made-and-reported form typically adds a further condition: the claim must also be reported to the insurer within the policy period or within a defined window. Under the stricter reported requirement, late notice can defeat coverage even for a claim that was made in time. Because these conditions are treated as important to coverage in many policies, the exact trigger language and reporting requirements should be read carefully rather than assumed.
What is a retroactive date and why does it matter when placing a claims-made policy?
A retroactive date is a date in the policy that generally sets the earliest point from which a covered wrongful act or incident can originate. In many claims-made policies, a claim is only eligible for coverage if the underlying act occurred on or after the retroactive date and the claim is made (and, where required, reported) during the policy period. A retroactive date set later than expected can leave prior acts uncovered. When placing or renewing coverage, the retroactive date should be reviewed so that it aligns with the organization's exposure history, subject to the specific policy wording.
What happens to coverage if we switch insurers or let a claims-made policy lapse?
Switching insurers or allowing a claims-made policy to lapse can create gaps because coverage generally depends on a policy being in force when the claim is made. Two mechanisms commonly address this, subject to the specific wording. An extended reporting period (sometimes called tail coverage) can allow claims made after expiration to be reported, typically for acts before the end of the policy. Prior acts coverage (sometimes via maintaining or matching the retroactive date under a new policy) can allow a successor policy to respond to earlier acts. Whether these apply, and on what terms, depends on the endorsements purchased, the retroactive date continuity, and conditions in each policy.
How should an organization handle notice and reporting obligations under a claims-made policy?
Reporting is often treated as central to coverage under claims-made forms, so it should be managed deliberately. Many policies specify how and when a claim must be reported and may also allow or require notice of circumstances that could give rise to a future claim. Missing a reporting deadline can jeopardize coverage even where the claim was otherwise eligible. Practically, this favors clear internal procedures for recognizing what constitutes a claim, escalating potential matters promptly, and documenting notice. The precise definitions of claim, circumstance, and the applicable deadlines are set by the specific policy wording and any applicable jurisdictional rules.
How does a claims-made structure interact with an organization's broader risk approach?
A claims-made policy is a risk transfer mechanism and does not by itself reduce the likelihood of an incident or constitute resilience. Its trigger structure affects only whether and when financial losses may be indemnified, subject to policy terms, and it is distinct from mitigation controls, business continuity planning, and incident response. In practice, this means continuity of coverage, consistent retroactive dates, timely renewals, and appropriate tail arrangements, should be planned alongside, not in place of, security controls and recovery capabilities. Coverage outcomes remain conditional on the specific wording, endorsements, exclusions, and jurisdiction.

Common misconceptions

A claims-made policy covers any incident that happened while the policy was in force, as long as I report it later.
Coverage under a claims-made form generally depends on the claim being first made (and often reported) during the policy period, not simply on when the incident occurred. Reporting after expiration may require an extended reporting period, subject to the specific wording.
Claims-made and occurrence-based policies are interchangeable ways of describing the same coverage.
They use different triggers. An occurrence form typically responds based on when the event took place, while a claims-made form responds based on when the claim is made and reported. This distinction affects how gaps in coverage can arise when switching insurers or forms.
The retroactive date is a minor administrative detail with little effect on coverage.
The retroactive date can materially limit coverage by excluding wrongful acts that occurred before it, even if the claim arises during the policy period. Maintaining an appropriate retroactive date across renewals is often critical, subject to the specific wording.

Best practices

Confirm the retroactive date at each renewal and when changing insurers to avoid unintended coverage gaps for acts that predate a newly set date.
Understand and calendar the reporting conditions, including whether the form requires notification of circumstances that may give rise to a claim, since these are often conditions precedent to coverage.
Evaluate extended reporting period (tail) options before non-renewing or replacing a claims-made policy, particularly where latent cyber liability exposures may surface after expiration.
Review prior and pending litigation and known-circumstances provisions to identify matters that may be excluded, and disclose known circumstances as required.
When transitioning between insurers or between claims-made and occurrence forms, map the triggers carefully to identify and address potential gaps in continuity of coverage.
Involve brokers and legal or compliance advisors to interpret the specific policy wording, endorsements, and exclusions rather than relying on general assumptions about how claims-made coverage responds.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide