Insuring Agreement
The insuring agreement is the part of an insurance policy where the insurer states what it promises to cover and pay for. It is the section that actually grants coverage, describing the insurer's core promise to the policyholder. What it grants is always read together with the rest of the policy, including definitions, conditions, and exclusions that narrow or qualify that promise.
The insuring agreement is the operative clause of an insurance contract in which the insurer promises to make payment to or on behalf of the insured, defining the scope of coverage granted and the corresponding obligations of both parties. In cyber and related policies it establishes the affirmative grant of coverage that a claim or loss must first fall within before any recovery is possible, and it may be structured as multiple separate insuring agreements addressing distinct first-party exposures (such as business interruption, data restoration, or cyber extortion) and third-party exposures (such as privacy liability or regulatory defense). The insuring agreement does not stand alone: whether a specific loss is ultimately covered is subject to the policy's definitions, conditions, endorsements, exclusions, and applicable retentions and sublimits, and turns on the exact wording of the form and the governing jurisdiction. Identifying which insuring agreement a loss potentially triggers is a distinct step from assessing exclusions that may subsequently remove it from coverage.
Why it matters
The insuring agreement is the starting point of any coverage analysis: before an insurer considers exclusions, conditions, or sublimits, a loss must first fall within the affirmative grant of coverage the insuring agreement provides. If a loss does not fit within any insuring agreement in the policy, there is nothing for the rest of the wording to narrow, and coverage generally fails at the threshold. This makes the insuring agreement the section that defines the outer boundary of what an insured can even hope to recover.
In cyber and related policies, this matters acutely because coverage is frequently organized into multiple distinct insuring agreements, each addressing a different exposure. First-party grants may respond to the insured's own losses such as business interruption, data restoration, or cyber extortion, while third-party grants may respond to liability to others such as privacy claims or regulatory defense. A single incident can implicate several insuring agreements at once, or none at all, depending on how the loss is characterized and how each grant is worded. Risk managers and brokers who assume a policy covers a category of harm without confirming that a specific insuring agreement grants it can be surprised when a claim is declined at the threshold rather than by an exclusion.
Because the insuring agreement is read together with the definitions, conditions, endorsements, exclusions, retentions, and sublimits, its plain-sounding promise is always qualified by the surrounding wording. Identifying which insuring agreement a loss potentially triggers is a distinct analytical step from assessing whether an exclusion later removes it, and conflating the two can lead to poor coverage decisions. Whether any particular loss is ultimately paid turns on the exact form language and the governing jurisdiction.
Who it's relevant to
Inside Insuring Agreement
Common questions
Answers to the questions practitioners most commonly ask about Insuring Agreement.
