Skip to main content
Category: Policy Exclusions

Fines Uninsurable by Law Exclusion

Also known as: Fines or Penalties Exclusion, Fines and Penalties Exclusion, Insurable by Law Carve-back
Simply put

This is a provision in an insurance policy that removes coverage for fines and penalties that the law itself says cannot be insured. Because different jurisdictions treat the insurability of fines differently, whether a particular fine is covered depends on the local law under which the policy is interpreted. In practice, many regulatory fines may fall outside coverage even when a policy otherwise appears broad.

Formal definition

A policy exclusion that carves out from covered loss any fines or penalties deemed uninsurable under the applicable law governing the policy, commonly framed through wording such that loss does not include fines imposed by law or matters deemed uninsurable under the law pursuant to which the policy is construed. The exclusion is inherently conditional and jurisdiction-dependent: because there is no uniform rule across regimes, its effect turns on the specific policy wording and the governing law, and formulations vary. Under some common formulations only criminal fines are excluded while other fines are covered to the extent they are 'insurable by law,' which shifts the coverage analysis onto the local legal treatment of the specific penalty at issue; in some jurisdictions statutes expressly prohibit insuring certain fines (for example fines imposed on directors and officers), and regulatory penalties under regimes such as GDPR or NIS 2 are commonly asserted to be excluded on this basis. Notably, some sources indicate that for certain policy types (such as representations and warranties insurance) no law may currently prohibit the insurability of fines and penalties and the governing law may be sparse, underscoring that the exclusion's operation cannot be assumed absolute and must be assessed against the specific wording, endorsements, and jurisdiction. This entry addresses the exclusion as an insurance coverage term and does not address the underlying regulatory or resilience obligations that give rise to the fines.

Why it matters

Regulatory fines are among the losses that organizations most want to transfer through insurance, yet they are also among the least reliably covered. The Fines Uninsurable by Law Exclusion exists because public policy in many legal systems treats certain penalties, particularly those meant to punish or deter wrongdoing, as something that should be borne by the wrongdoer rather than shifted to an insurer. For a buyer reading a broad-sounding liability policy, this exclusion can be a decisive gap: a penalty imposed by a regulator may sit outside covered loss even where the policy otherwise responds to the underlying event, defense costs, or related third-party claims.

The practical difficulty is that insurability is not uniform. Whether a specific fine is recoverable turns on the governing law of the policy and the local legal treatment of the particular penalty, and formulations of the exclusion vary. Under some common formulations only criminal fines are excluded and other fines are covered to the extent they are 'insurable by law,' which pushes the entire coverage question onto local law analysis of the specific penalty at issue. Regulatory penalties under regimes such as GDPR or NIS 2 are commonly asserted to fall outside coverage on this basis, and some jurisdictions have statutes that expressly prohibit insuring certain fines, for example, penalties imposed on directors and officers.

At the same time, the exclusion should not be assumed to operate absolutely. Some sources indicate that for certain policy types, such as representations and warranties insurance, no law may currently prohibit insuring fines and penalties and the governing law is sparse. That range of outcomes is precisely why the exclusion matters: two policies with similar wording can yield opposite results depending on jurisdiction and the nature of the penalty, and buyers cannot safely assume either coverage or exclusion without reading the specific wording against the applicable law.

Who it's relevant to

Risk Managers and Insurance Buyers
Risk managers relying on liability coverage to absorb regulatory exposure need to understand that a broad-looking policy may still exclude fines the law deems uninsurable. They should not treat insurance as a substitute for compliance and mitigation, and should identify which of their material fine exposures, for example under data protection or network security regimes, may fall outside coverage under the governing law.
Insurance Brokers and Underwriters
Brokers and underwriters must be precise about which formulation of the exclusion a policy uses, since a clause excluding only criminal fines behaves very differently from one excluding all fines. Because coverage turns on the governing law and the specific penalty, both sides should confirm the applicable jurisdiction and avoid representing coverage for regulatory penalties as certain where local law is unsettled or expressly prohibitive.
Legal and Compliance Professionals
Legal and compliance teams are best positioned to assess whether a particular fine is insurable under the applicable law, including statutes that prohibit insuring penalties against directors and officers, and to flag areas where the law is sparse. They should map the organization's exposure to specific regulatory regimes and coordinate with brokers so that the coverage analysis reflects the actual legal treatment of each penalty type.
Directors and Officers
Directors and officers have a direct stake because some jurisdictions expressly prohibit insuring fines, civil fines, monetary levies, or fines in lieu of indictment imposed on them. Where such prohibitions apply, personal exposure to penalties cannot be transferred to an insurer, making the distinction between insurable and uninsurable fines a matter of individual as well as corporate concern.

Inside Fines Uninsurable by Law Exclusion

Insurability-of-fines carve-out
A policy provision stating that the insurer will not indemnify regulatory fines, penalties, or sanctions to the extent that coverage for such amounts is prohibited by the applicable law or jurisdiction governing the claim. It functions as an exclusion that defers to public policy rather than setting a fixed dollar limit.
Governing-law dependence
Whether a particular fine is insurable turns on the law of the relevant jurisdiction, which varies across regimes. The same category of penalty may be insurable in one jurisdiction and uninsurable in another, so the exclusion's effect is conditional on choice-of-law and where the fine is imposed.
Third-party coverage context
This exclusion typically operates within the liability (third-party) side of a cyber policy, particularly regulatory defense and penalties coverage. It does not concern first-party losses such as business interruption, data restoration, or cyber extortion, which are addressed by separate insuring agreements.
Distinction between defense costs and the fine itself
The exclusion is commonly directed at the fine or penalty amount rather than the associated legal defense or investigation costs. Subject to the specific wording and any sublimits, a policy may still respond to defense expenses even where the underlying penalty is uninsurable.
Interaction with 'most favorable jurisdiction' wording
Some policies include language directing that insurability be assessed under the law most favorable to coverage among the potentially applicable jurisdictions. Whether such wording is present materially affects how the exclusion is applied.
Relationship to other exclusions and conditions
This exclusion sits alongside war, infrastructure, and failure-to-maintain-standards exclusions and applicable conditions precedent. It is one of several provisions that determine whether a regulatory penalty is ultimately indemnified.

Common questions

Answers to the questions practitioners most commonly ask about Fines Uninsurable by Law Exclusion.

Does this exclusion mean my cyber policy never covers regulatory fines or penalties?
No. The exclusion removes coverage only for fines and penalties that are uninsurable as a matter of law in the applicable jurisdiction. Some fines may remain insurable depending on the governing law, the nature of the penalty, and the specific policy wording. Many policies affirmatively grant regulatory defense costs and, where legally permissible, some measure of fines coverage, often subject to a sublimit. Whether any given fine is covered turns on the jurisdiction's public-policy rules and the policy language, not on a blanket bar.
Isn't whether a fine is insurable the same everywhere, so I can rely on one answer?
No. Insurability of fines and penalties is determined jurisdiction by jurisdiction, and treatments differ across regulatory regimes and legal systems. A penalty that public policy renders uninsurable in one jurisdiction may be treated differently in another. Because cyber incidents frequently trigger obligations in multiple jurisdictions at once, the exclusion may apply to some penalties and not others arising from the same event. The determination is fact-specific and legal in nature, and this entry does not substitute for jurisdiction-specific legal advice.
How can I tell whether a particular fine would fall within this exclusion?
Start with the policy's definition of covered fines or penalties and read it against this exclusion, then assess the governing law that determines insurability for the specific penalty at issue. Relevant factors typically include the jurisdiction whose law applies, whether the penalty is characterized as punitive or compensatory, and any conditions precedent or endorsements addressing regulatory exposure. Because the analysis is legal and fact-specific, insureds commonly involve coverage counsel to evaluate a particular penalty against both the policy wording and applicable law.
Where does this exclusion typically sit relative to regulatory defense cost coverage?
Defense costs and the fines themselves are usually treated as distinct. Many policies grant coverage for the costs of responding to or defending a regulatory investigation or proceeding, subject to the specific wording and often a sublimit, even where the underlying fine may be uninsurable by law. The Fines Uninsurable by Law Exclusion generally addresses the payment of the fine or penalty, not the defense expense. Review both the insuring agreement and the exclusion to see how each is handled, since the interaction depends on the form.
What should I check at placement to understand my exposure under this exclusion?
Confirm whether the policy affirmatively offers fines coverage where insurable, whether it is subject to a sublimit or retention, and how the exclusion is worded. Identify the jurisdictions in which your organization operates and holds data, since those drive which penalties may be uninsurable. Ask how the insurer determines insurability and whether that determination is tied to a most-favorable-jurisdiction or similar provision, if the form contains one. All of this is subject to the specific policy language and any endorsements.
Given this exclusion, how should we treat regulatory fine exposure in our risk strategy?
Because some fines may be legally uninsurable, insurance may not be a reliable transfer mechanism for that exposure, which points toward risk mitigation and acceptance rather than transfer alone. Reducing the likelihood and severity of the underlying compliance failures, through controls, governance, and adherence to applicable standards, addresses exposure that insurance cannot. Insurance does not reduce the probability of a regulatory penalty and, where the exclusion applies, may not fund the fine, so the residual exposure is typically managed outside the policy. Treat any insurable portion as a supplement to, not a replacement for, mitigation.

Common misconceptions

All regulatory fines arising from a cyber incident are covered as long as the policy includes regulatory penalties coverage.
Even where a policy offers regulatory penalties coverage, this exclusion removes indemnity for fines that are uninsurable under the applicable law. Whether a given fine is payable depends on the governing jurisdiction and the specific policy wording, not on the mere existence of a penalties insuring agreement.
The exclusion means no regulatory-related amounts are ever recoverable.
The exclusion is typically aimed at the fine or penalty amount itself. Subject to the wording and any applicable sublimits, defense, investigation, and related costs may still be covered even when the penalty is not.
Insurability of a fine is a fixed characteristic that can be determined from the policy alone.
Insurability is conditional and jurisdiction-dependent. The same category of fine may be insurable in one jurisdiction and prohibited in another, so the outcome depends on choice-of-law and the facts of the specific claim rather than the policy in isolation.

Best practices

Review the exact wording of the insurability-of-fines exclusion and check whether it includes 'most favorable jurisdiction' language, which can broaden the circumstances in which a fine is treated as insurable.
Map the regulatory regimes and jurisdictions to which the organization is exposed, and obtain qualified legal input on how each treats the insurability of penalties, rather than assuming a uniform answer.
Confirm whether the policy separates coverage for regulatory defense and investigation costs from coverage for the fine itself, and understand any sublimits or conditions that apply to each.
Coordinate with brokers and coverage counsel early in a regulatory matter to assess how this exclusion interacts with other exclusions and conditions precedent before assuming a penalty will be indemnified.
Do not treat this coverage as a substitute for risk mitigation; insurance does not reduce the likelihood of a regulatory action, and uninsurable fines remain retained by the organization.
Document the choice-of-law and jurisdictional assumptions underlying any coverage expectation so that gaps created by uninsurable fines are identified and managed within the broader risk-financing strategy.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide