The importance of D&O insurance for directors and officers

In an environment of increasing regulation and public scrutiny, organizations and their leaders must have protection against the legal risks inherent to senior management.

Center for Corporate Governance

In today’s corporate landscape, the responsibilities of directors and officers have grown exponentially, as they face a multitude of risks that can impact both their decisions and personal assets. This is where D&O (Directors & Officers) insurance becomes an essential tool to protect both the individuals in these roles and the organization itself.

Understanding the importance of D&O insurance today is therefore a strategic priority for any board of directors.

To help business administrators gain a clear understanding of the responsibilities they may face in their roles, Esade’s Center for Corporate Governance, along with Marsh and Mercer, has developed a practical guide for directors on D&O insurance. In addition to analyzing the risk environment for directors and officers, the document presents the main coverage options available to them. 

What is D&O insurance?

D&O insurance is a liability policy that provides coverage to directors and officers against potential legal claims arising from their decisions or actions in the course of their duties. This policy not only protects the personal assets of the insured but also shields the company from claims linked to the actions of its directors and officers. 

Events that may trigger this coverage can range from accusations of negligence in management to issues stemming from regulatory non-compliance, discrimination, or privacy violations. One of the most critical aspects of D&O insurance is its retroactive clause, which protects directors and officers even after they have left the organization or the board. Decisions made during their tenure can lead to litigation years later.

Who does D&O insurance protect and what does it cover?

D&O insurance is primarily designed to protect an organisation's directors and officers, both executive and non-executive, against claims arising from decisions made in the course of their duties. However, depending on the type of policy taken out, coverage may also extend to the company itself.

Many executives ask: is D&O insurance necessary if the company already has general liability coverage? The answer is yes, general liability does not protect personal assets.

In general terms, this insurance covers situations such as: errors or omissions in strategic decision-making, regulatory breaches, shareholder lawsuits, regulatory sanctions, cybersecurity incidents and claims related to ESG governance. It is important to note that coverage is maintained even after the director or board member has left their position, thanks to the retroactive clause that characterises these policies.

Do I need D&O insurance? Understanding the purpose

The short answer is yes, and here's why. Lawsuits against executives are rising, driven by shareholder activism, tighter regulation, and growing public accountability demands. The digital environment has compounded this risk: cybersecurity failures and data privacy breaches are now significant sources of D&O claims, capable of triggering major investigations and fines.

Without adequate coverage, directors and officers are personally exposed. D&O insurance removes that barrier, allowing leaders to make bold, strategic decisions without the constant threat of personal financial ruin.

D&O insurance in Spain: a growing market

In Spain, the D&O insurance market has experienced sustained growth in recent years, driven by an increase in corporate litigation and growing regulatory requirements on corporate governance bodies. Legal frameworks such as the Capital Companies Act, CNMV regulations and the recent European regulation on sustainability reporting (CSRD) have significantly expanded the scope of liability for executives and directors.
This reality makes D&O insurance an increasingly relevant tool for Spanish boards of directors, which must face not only traditional management risks, but also new requirements related to governance, transparency, and sustainability. 

Functionality and coverage of D&O insurance

The guide published by Esade’s Center for Corporate Governance delves into the factors to consider when purchasing D&O insurance. In summary, there are three types of coverage known as Side A, Side B, and Side C: 

  • Side A Coverage: This coverage directly protects the personal assets of directors and officers. It activates when the company cannot or will not indemnify them. For instance, if a director is sued for an error in an investment decision and the company cannot cover their legal costs, this coverage safeguards their personal assets.
  • Side B Coverage: This mode reimburses the company when it has indemnified its directors and officers under indemnity obligations. In other words, if the company covers a director's defense costs, Side B coverage reimburses those expenses to the organization.
  • Side C Coverage: This coverage protects the company itself against claims related to securities, such as those that may arise from stock value fluctuations. This type of coverage is essential for publicly traded companies, which are exposed to shareholder class-action lawsuits.

Risk factors and trends in D&O claims

The main trends in D&O insurance claims reflect a shift toward greater scrutiny in areas such as ESG (environmental, social, and governance), cybersecurity, and sustainability. Specifically, failure to meet stakeholder expectations regarding sustainability and business ethics can lead to accusations of greenwashing or fraud. These risks are increasingly present on the agenda of institutional investors, who demand clear accountability regarding the management of these issues. 

Another area of growing importance is cybersecurity. The inability to protect corporate and personal data not only damages corporate reputation but can also lead to costly fines and lawsuits from affected parties. In this context, the recently published Good Governance Code on Cybersecurity by the Spanish National Securities Market Commission (CNMV) emphasizes the principles that should govern cybersecurity strategy, organization, daily management, and oversight.

What to review before taking out D&O insurance

Additionally, the guide provides a list of aspects board members should pay close attention to when contracting D&O insurance: 

  • Reviewing any indemnity granted by the company (e.g., indemnity agreements) and its interaction with the D&O policy.
  • Comparing indemnity limits to ensure adequate protection.
  • Verifying coverage applicable in cases of insolvency or bankruptcy.
  • Considering a dedicated Side A coverage, reserving indemnity limits exclusively for individuals.
  • Checking coverage for formal investigations against directors and officers.
  • Assessing the need for a multinational program with local policies to comply with various jurisdictions.
  • Reviewing exclusions and their scope.
  • Coverage for civil and criminal bail bonds.
  • Choosing insurers based on their technical proposal, experience, solvency, and claims management.
  • Ensuring D&O coverage for cybersecurity events.

D&O insurance, an instrument of good governance

In an environment of increasing risks and challenges, having appropriate D&O insurance is essential to manage the risks inherent to senior management and allows leaders to focus on making strategic decisions without fear of unforeseen legal complications that may arise at any time, even years after they have left the organization.

The benefits of D&O insurance lie precisely in this dual dimension: protecting the people who govern organisations and, at the same time, strengthening the culture of accountability that stakeholders, shareholders, regulators and investors demand from companies both in Spain and in the other jurisdictions where their executives operate.

The purpose of D&O insurance goes beyond legal defense, it underpins a culture of accountability that shareholders, regulators, and investors increasingly demand.

All written content is licensed under a Creative Commons Attribution 4.0 International license.