24h AssistanceClient Area
Financial Institutions
Services and knowledge

Financial Institutions

In a financial entity, the exposure has shifted from the balance sheet to daily operations: to the process that serves the client, the supplier that supports that process, and the resolution that approved continuing in this manner. Each of these three points has its own claimant, and they rarely share a timeline.

Where the claim enters

Operational resilience, third-party risk and board liability

What decides the claim file

The client's claim, the supervisor's file, and the action against the board share a limit.

They rarely share an interlocutor and almost never arrive simultaneously, yet they rely on the same contracted capacity: the order of arrival ultimately determines how much remains for the third. Contracting this capacity in layers, with cover reserved for the director above the general, is what keeps the limit available when the programme already has two open files.

  1. Side A, Side B, and Side C within the same programme

    Side B reimburses the entity for what it advances for its directors, and Side C covers the entity itself, so both consume the limit that also protects the individual. An excess Side A, reserved for the director, maintains available capacity for their defence above that shared by the company and directors.

  2. Operational resilience and critical technology provider

    Regulation (EU) 2022/2554, known as DORA, requires the registration, contracting, and monitoring of essential ICT service providers, and an incident involving one of them opens a file on the entity. The defence before the supervisor is assumed by the regulatory cover of the cyber policy; the loss due to the stoppage is only indemnified when the extension to providers is written.

  3. The claim regarding the suitability of the placed product

    When the complaint is directed at the suitability of what was recommended, and whether the client's profile admitted that product, the matter falls under the professional liability of the entity. The customer service resolves the first stage and records the criteria applied, and this record is what later orders the defence before the supervisor and the court. Documenting the suitability test at the time of sale is what supports both positions.

  4. Social engineering and employee infidelity, two distinct covers

    In social engineering fraud, an employee is deceived into authorising a payment with legitimate credentials and without technical intrusion; the cover usually exists as a sublimit within the cyber policy and almost always requires proof of a dual verification procedure. In infidelity, it is the employee themselves who acts for their benefit, and this scenario corresponds to the fidelity policy or the global bank bond. Each excludes what the other covers, so both wordings are read together before renewal.

Frequently asked questions

Lo que nos preguntan en financial institutions

We already have a directors and officers policy. Why also take out a separate Side A?

Because the ordinary D&O shares the same limit among three destinations: the director's defence, reimbursement to the company that indemnifies them, and the cover of the entity itself. A lengthy procedure can consume that capacity, and the Side A in excess reserves a limit for the director's defence in the event that the company cannot indemnify them.

Does the cyber policy cover a supervisor's sanction?

The defence and regulatory sanctions guarantee assumes the legal management of the file. The response to the incident is ordered by the policy panel and the loss due to the stoppage corresponds to the network interruption guarantee: these are three distinct sub-limits and are considered together, as this is where the expense is concentrated. The sanction itself is covered to the extent that it is legally insurable in the applicable jurisdiction, so the specific wording of the contract is reviewed before considering it included.

What is checked when the service depends on a technology provider?

The DORA regulation requires maintaining the information register of all agreements with ICT service providers, identifying which ones support essential functions, and preserving in each contract rights of access, audit, and orderly exit. The entity is accountable to the client and the supervisor, so the conversation with the insurer starts with that register: who is included, with what classification, and with what recovery time committed in writing.

Let's talk

Get in touch

A specialist reviews your programme and reports back in writing on what would change, what would stay and what each option would cost.

Request an assessmentOr drop by any of our four offices.