← All posts

Insurance Due Diligence in M&A: What Acquirers Miss in the First 90 Days

Insurance due diligence is one of the most underweighted workstreams in any deal. Acquirers miss named insured changes, missing D&O, E&O, and cyber tail coverage, lines the target never carried, and integration-driven exposures. Here is what to review before close and how continuous monitoring protects the first 90 days after it.

Insurance Due Diligence in M&A: What Acquirers Miss in the First 90 Days

Quick answer: Insurance due diligence in M&A is the review of a target company's commercial insurance program to find coverage gaps, uninsured liabilities, and claims-made policies that need tail coverage before a deal closes. Acquirers most often miss four things in the first 90 days: named insured changes that invalidate claims, missing D&O, E&O, or cyber tail (runoff) coverage for pre-close acts, coverage lines the target never carried, and new exposures created by integration. A thorough review plus continuous, year-round monitoring after close catches these before they become claims.

Most M&A deals close with a signed purchase agreement and a sense of relief. The insurance due diligence? It gets a folder in the data room, a quick scan from outside counsel, and a note that says "looks fine." Sixty days later, the acquirer finds a coverage gap that predates the close, a lapsed policy, or a D&O tail that nobody ordered. That is when "looks fine" gets expensive.

Insurance due diligence is one of the most consistently underweighted workstreams in any deal process. It does not show up in the headline valuation model, but it surfaces liabilities that the financial statements never will, and it determines whether the coverage you think you acquired actually protects the combined entity once the ink dries.

This guide covers what acquirers most often miss in the first 90 days, why those gaps are so predictable, and how to build a process that catches them before they cost you. For a broader overview of how coverage transfers at close, see the companion guide on what happens to your insurance when you acquire a company.


Why Insurance Gets Treated as a Checkbox

Standard M&A due diligence devotes serious attention to financials, IP ownership, employment contracts, and regulatory compliance. Insurance typically lands near the bottom, treated as an administrative confirmation rather than a substantive risk review.

A few reasons explain this. Most deal teams do not include an insurance specialist. Outside counsel reviews declarations pages for limits and named insureds but rarely digs into exclusions, sublimits, or retroactive dates. And the target's management team, eager to close, is not going to volunteer that their cyber policy has a $250,000 sublimit on social engineering losses.

The result is a pattern that repeats across deals of every size: the acquirer inherits the target's coverage as it stands, assumes it is adequate, and only discovers the gaps when a claim arrives.


The Coverage Lines That Create the Most Surprises

Not every policy carries equal risk in an M&A context. Some lines are straightforward to evaluate. Others have structural features, especially the claims-made trigger, that make them genuinely dangerous to inherit without scrutiny.

Directors and Officers Liability

D&O is one of the first places to look in any acquisition. The target's existing policy covers the pre-close period, but once the deal closes, that coverage needs to be extended through a tail policy, also called a runoff policy, to protect the acquired company's former directors and officers from claims tied to pre-close acts.

If no one orders the tail, the window closes. A shareholder dispute, a regulatory inquiry, or an employment claim rooted in decisions made before close can arrive years later with nothing to respond to it. Understanding how D&O insurance works for directors and officers before you reach the closing table is not optional, it is foundational to the deal structure. Where D&O, EPLI, and fiduciary coverage sit together, a management liability review is the fastest way to see the whole picture.

Tail periods typically run three to six years. The cost is negotiated as part of the deal, but it has to be negotiated. It does not happen automatically.

Cyber Liability

Cyber policies are claims-made, which means the claim must be reported during the active policy period. If the target experienced a breach or security incident before close that was never reported, and the policy lapses or gets replaced at close, the acquirer may have no coverage for that incident.

This matters more than most deal teams realize. A target's cyber posture is not visible in the financial statements. You need to review the policy retroactive date, confirm whether any incidents were reported during the policy period, and assess whether the limits and sublimits are appropriate for the combined entity's actual risk profile.

Acquirers in tech, SaaS, and financial services are especially exposed here. The target's customer data, API integrations, and third-party vendor relationships all become the acquirer's problem at close.

Errors and Omissions

E&O policies cover professional services delivered before the acquisition. If the target provided software, consulting, or any professional service to clients, those past engagements carry ongoing liability. A client who was unhappy with work done 18 months ago can file a claim after close.

Like D&O, E&O is claims-made. The retroactive date on the policy determines how far back coverage reaches. If the target switched carriers at any point without maintaining a prior acts endorsement, there may be a gap covering older work, and no one will know until a claim surfaces. This is the prior acts gap, and the retroactive date is exactly where it lives.

Commercial Property and Builders Risk

If the target owns or leases physical space, or has any active construction or renovation projects, those assets need a separate review. Property schedules can be outdated, values understated, and active projects may be covered under a builders risk policy that terminates at project completion or at a change in ownership.

An acquirer who does not update the property schedule and named insured after close may find that a loss to the acquired facility is only partially covered, or not covered at all.


The First 90 Days: Where the Gaps Appear

The period immediately after close is when insurance problems become visible. Here is where they tend to surface.

Days 1 to 30: The Named Insured Problem

Every commercial policy lists a named insured. After an acquisition, the legal entity structure changes. If the policies are not updated to reflect the new ownership, the acquirer may not have standing to file a claim.

This sounds like a paperwork issue. It is not. Carriers can and do deny claims on the basis that the named insured no longer matches the entity that suffered the loss. The fix is straightforward, notify all carriers of the ownership change and update the named insured on every active policy, but it requires someone to own the task in the first 30 days. The same review should confirm any additional insured requirements in the target's contracts are still met after the entity change.

Days 30 to 60: Discovering What Was Never There

The second wave of surprises comes when the combined entity starts operating and finds coverage the target simply never had.

Common examples: no employment practices liability insurance despite a headcount of 60 people, no umbrella policy sitting above the general liability, or a workers' compensation policy that does not cover all states where employees actually work. These are not exotic lines. They are standard for a business of any size, and their absence is a gap the acquirer now owns. Mid-market targets are especially prone to a missing EPLI program and to workers' compensation that was never extended to every operating state.

This is also when hidden gaps in commercial insurance policies that were invisible before close become real liabilities. Sublimits, exclusions, and endorsements that looked acceptable in isolation may be wholly inadequate for the combined entity's actual risk profile.

Days 60 to 90: Integration Triggers New Exposures

By the time integration is underway, the acquired business's risk profile has often changed materially. New employees, new systems, new contracts, new vendor relationships, each one can create exposures the existing policies were never designed to cover.

A common scenario: the acquirer adds the target's employees to its payroll system, migrates to a new HR platform, and signs enterprise contracts on behalf of the combined entity. The target's original policies were priced and scoped for a different business. The acquirer's policies may not yet include the acquired entity. For a stretch of time, neither policy fully covers the combined operation.


What a Proper Insurance Due Diligence Review Covers

A thorough insurance due diligence review goes well beyond confirming that policies exist. Use this as an insurance due diligence checklist.

Policy inventory and verification

Collect every active policy, including declarations pages, full policy forms, and all endorsements. Verify that each policy is in force and that premiums are current. Confirm the retroactive dates on all claims-made policies.

Named insured and additional insured review

Confirm who is listed as the named insured on each policy. Identify any contracts requiring the target to carry specific limits or name specific parties as additional insureds. Check whether those requirements are currently met.

Limits and sublimit analysis

The headline limit on the declarations page is not the whole story. Sublimits for specific loss types, such as ransomware, social engineering, or bodily injury in specific contexts, can be a fraction of the stated limit. Evaluate whether the limits are appropriate for the combined entity's size and risk profile.

Claims history review

Request five years of loss runs. Frequent small claims can signal systemic risk management problems. Open claims at close are particularly important, they may not be covered by the acquirer's policies and could exhaust the target's limits before the acquirer even realizes it. Here is how to get loss runs and read them.

Tail and runoff requirements

Identify every claims-made policy that will need a tail. Calculate the cost. Determine who pays for it as part of the deal negotiation.

Coverage gap analysis

Compare the target's coverage program against what a business of its size, industry, and risk profile would typically carry. Identify lines that are missing entirely, limits that are below market, and exclusions that create material exposure.


Key Person Risk: The Coverage Nobody Asks About

One area that gets almost no attention in M&A due diligence is key person insurance. If the target's business depends substantially on one or two individuals, a founder, a lead engineer, a key account manager, losing that person after close can materially affect the value of what was acquired.

Key person insurance is not always in place at the target, and even when it is, the acquirer needs to evaluate whether the coverage amount and structure still make sense post-close. It is a straightforward review that is almost always skipped.


A Comparison: What Most Reviews Cover vs. What They Should

Review AreaTypical Deal Team ReviewThorough Insurance Due Diligence
Policy existenceConfirms policies are in placeVerifies in-force status and premium currency
LimitsNotes headline limitsAnalyzes sublimits and adequacy for combined entity
Claims-made retroactive datesOften missedReviewed for every claims-made policy
Tail/runoff requirementsIdentified if flagged by counselSystematically identified and costed
Named insured accuracyNot reviewedVerified with an update plan created for close
Coverage gapsNot assessedCompared against industry benchmarks
Key person coverageRarely reviewedEvaluated for post-close dependency risk
Claims historySometimes requestedFive years of loss runs reviewed and analyzed
Cyber postureNot assessedEvaluated against threat intelligence and policy terms

How Continuous Risk Monitoring Changes the Post-Close Period

One structural problem with M&A insurance due diligence is that it is a point-in-time review. The deal team looks at policies as they exist on a specific date. But the acquired business's risk profile keeps changing after close, sometimes rapidly.

This is where continuous, year-round risk monitoring makes a real difference. Rather than waiting until the next renewal to discover that the combined entity's cyber posture has shifted, or that a new contract has created an exposure the existing policies do not cover, ongoing monitoring flags those changes as they happen.

Aiden's AI risk engine analyzes 140+ signals, including CVE databases, active cyber threat feeds, public filings, breach history, and industry peer benchmarks, to build a real-time risk profile for a business. A licensed broker reviews the output, runs a coverage gap analysis, and places coverage across a panel of 100+ carriers, then flags exposure changes between renewals rather than only at the annual renewal date. For an acquirer managing a post-close integration, that ongoing visibility is far more useful than a point-in-time review that is already outdated by the time the deal closes.

If you are managing a deal or a post-close integration and want to understand what the combined entity's coverage program actually looks like, you can get a quote and start the process at aidenrisk.com.


Key Takeaways

  • Request loss runs early. Five years of claims history tells you more about a target's risk profile than the policy declarations ever will.
  • Map every claims-made policy. D&O, E&O, and cyber are all claims-made. Every one needs a retroactive date review and a tail assessment.
  • Update named insureds at close. This is the most commonly skipped post-close task, and one of the most consequential.
  • Run a coverage gap analysis before binding. Compare the target's program against what a business of its size and industry should actually carry.
  • Plan for integration-triggered exposures. New employees, new systems, and new contracts create new risks. The existing policies were not priced for them.
  • Do not skip key person coverage. If deal value is tied to specific individuals, evaluate whether that dependency is insured.
  • Build in continuous monitoring post-close. A point-in-time review at close does not protect you from exposures that emerge during integration.

FAQs

What does insurance due diligence in an acquisition actually involve?

It means collecting and reviewing every active commercial policy held by the target, verifying that each is in force, analyzing limits and sublimits for adequacy, identifying claims-made policies that require tail coverage, reviewing five years of loss runs, and comparing the target's program against what a business of its size and industry would typically carry. The goal is to find gaps and liabilities before close, not after a claim.

Who is responsible for insurance due diligence in an M&A deal?

Responsibility is often unclear, which is a big part of why gaps persist. Outside counsel may review declarations pages, but a thorough review requires an insurance specialist who understands commercial coverage lines, claims-made versus occurrence policies, and the specific exposures relevant to the target's industry. Assigning this workstream explicitly, rather than assuming it is covered, is the first step.

What is a tail policy and when is it required in an acquisition?

A tail policy, also called a runoff policy, extends coverage under a claims-made policy, typically D&O or E&O, for claims that arise after the policy period ends but relate to acts that occurred before close. It is required any time a claims-made policy will lapse or be replaced as part of the deal. Without it, the acquired company's former directors, officers, or professional service providers have no coverage for pre-close acts once the original policy is gone.

How far back should you request loss runs for a target company?

Five years is the standard. Loss runs show the full claims history for each policy, including open and closed claims, reserves, and payments. Frequent claims, large reserves on open matters, or claims in lines that seem unusual for the business can all point to risk management problems that affect the post-close picture.

What happens to the target's cyber policy after an acquisition closes?

The target's cyber policy may lapse, be replaced, or be absorbed into the acquirer's program. Because cyber policies are claims-made, any incident that occurred before close but was never reported during the active policy period may have no coverage if the policy is no longer in force. The acquirer should review the retroactive date, confirm that no unreported incidents exist, and ensure continuity of coverage through the transition.

What coverage gaps are most common in mid-market acquisition targets?

The most common gaps include missing EPLI despite meaningful headcount, no umbrella policy above general liability, cyber limits too low for the actual data exposure, workers' compensation that does not cover all operating states, and E&O retroactive dates that leave older work unprotected. These are not unusual gaps, they reflect the reality that many growing businesses buy the minimum required coverage and never revisit it.

Is representations and warranties insurance part of insurance due diligence?

Representations and warranties (R&W) insurance is a separate, specialty transactional product that protects against breaches of the seller's representations in the purchase agreement. It is not a substitute for reviewing the target's operational insurance program. Insurance due diligence focuses on the commercial lines the combined entity will rely on day to day, such as D&O, E&O, cyber, general liability, property, and workers' compensation.

Should insurance due diligence happen before or after the deal closes?

Both. The core review belongs before close, so tail costs, coverage gaps, and named insured changes can be negotiated into the deal. After close, continuous monitoring tracks how the combined entity's risk profile evolves during integration and flags new exposures the existing policies were not designed to cover.

How does post-close risk monitoring differ from the initial due diligence review?

The due diligence review is a point-in-time assessment of the target's coverage as it exists at close. Post-close monitoring tracks how the combined entity's risk profile evolves during integration, including new employees, new contracts, new systems, and new vendor relationships, and flags exposures the existing policies were not designed to cover. Without ongoing monitoring, an acquirer may not discover a new gap until the next renewal cycle, or worse, until a claim arrives.

Want a risk assessment for your business?

Aiden's AI risk engine analyzes 140+ data vectors to surface coverage gaps before a claim forces the question.

Analyze Your Risk →