Insurance Due Diligence in M&A (2026): The Collateral Trap + Loss-Run Playbook
Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.
Last updated: August 2026
I'm Sean Yu, co-founder of Peony, a virtual data room company. Before Peony I spent my career on the deal side, and the insurance review is the workstream I most often watch get outsourced to a single line item in the legal folder — right up until the moment a posted letter of credit or a missing directors-and-officers tail turns into a real cash cost at close. Insurance due diligence is its own workstream, and the tell is who runs it: an insurance broker or risk-advisory team, not the accountants running quality of earnings and not the lawyers running the legal review. Reading a loss run, benchmarking an experience modification rate, and pricing a D&O run-off are specialist skills, and a deal that treats insurance as a checkbox tends to discover the bill after signing.
The named trap in this post is the collateral trap: a target that runs a high-deductible workers'-compensation program has almost certainly posted collateral — a letter of credit, a surety bond, or cash in trust — to secure the losses it self-insures, and that collateral does not just transfer at close. The buyer often has to stand up replacement collateral, which is real cash or borrowing capacity tied up on day one, and it is the kind of line a light insurance review misses entirely. I run Peony, a data room company used by 6,800+ customers across M&A and diligence, and this guide maps the insurance-program review the way a buy-side broker actually runs it — organized by the decisions the buyer has to make, with every load-bearing number attributed or explicitly framed as a market norm, and the tooling described honestly, including where a specialist actuary or an enterprise platform is the better call than us.
Quick answer: Insurance due diligence is the buy-side review of the target's own insurance program — run by the broker, not the accountants. Organize it by four decisions: continuity (does coverage survive the change of control — occurrence policies generally do, claims-made lines like D&O/EPL/E&O/cyber turn on a retroactive date and often need a tail), cost/adequacy (are limits and retentions right, or did thin coverage prop up EBITDA), inherited liability (open claims, loss reserves, IBNR, and posted collateral), and deal-required cover (the D&O six-year run-off the merger agreement requires, replacement collateral, prior-acts continuity). Pull five years of currently-valued loss runs per line. And keep it distinct from RWI — insurance DD reviews the target's operating insurance; RWI insures the deal's reps. They are different products with different budgets.

Why is insurance due diligence its own workstream?
Insurance due diligence is its own workstream because it protects the buyer from a category of risk that the financial and legal reviews are not built to catch — and because the person qualified to run it is neither the accountant nor the lawyer. A quality-of-earnings team tests whether the earnings are real. A legal review reads the contracts and the corporate record. Neither one benchmarks an experience modification rate against a class average, reads five years of loss runs for a developing reserve, or prices a directors-and-officers run-off policy — those are broker and risk-advisory skills. When insurance gets folded into the legal folder as a single line, the deal team tends to confirm that policies exist and stop there, which is exactly how the expensive items hide.
What the workstream protects the buyer from is concrete. A target can look profitable partly because it has been under-insured — carrying limits too low for its risk, or self-insuring through a high deductible without funding the tail of claims — so the earnings the buyer is paying for are propped up by risk the buyer inherits. A target can carry inherited liability in the form of open claims and loss reserves, plus incurred-but-not-reported exposure the buyer assumes in a stock deal. And the deal itself forces new coverage: the pre-close board needs a tail, the high-deductible program needs replacement collateral, and the claims-made lines need continuity — costs that land on the buyer at close whether or not anyone modeled them.
The cleanest way to run the review is not to march down a list of a dozen policy lines. It is to organize around the four decisions the buyer actually has to make — continuity, cost, inherited liability, and deal-required cover — and let the policy lines fall under whichever decision they inform. The rest of this guide is built that way: what the review covers, what the loss runs and the EMR reveal, how the claims-made lines and tail cover work, what transfers in an asset versus a stock deal, the insurance obligations buried in the target's own contracts, the collateral trap, the boundary with RWI, and how to run the file in the room.
What is insurance due diligence?
Insurance due diligence is the structured pre-acquisition review of a target's insurance and risk-financing program — the policies it buys, the losses it has suffered, the collateral it has posted, and the coverage the transaction will require — conducted so the buyer can decide whether the program is adequate, what liability transfers, and what new cover must be bound to close.
The plain-English framing is that this workstream answers a different question than the one the financial review asks. Financial diligence asks whether the numbers are real; insurance diligence asks whether the risk behind the numbers is properly covered and priced, and whether the buyer is about to inherit an uncovered liability or an unbudgeted cost at close. It is a workstream inside the broader buy-side due diligence process — one lane among several running against the same clock — and it plugs into the M&A due diligence process the way the other specialist reviews do: its findings translate into a price, a protection, or a plan.
One scope note up front, because it is the single most common confusion in this area. Insurance due diligence reviews the target's operating insurance. Representations and warranties insurance (RWI) insures the deal's reps. This post is about the former. RWI gets a dedicated boundary section below, and the mechanics of RWI pricing and adoption live in the due diligence report and what-is-due-diligence guides — I do not re-derive them here, and I do not contradict them.
What does an insurance due-diligence review cover?
An insurance due-diligence review covers the target's whole risk-financing picture, and the most useful way to structure it is by the four decisions the buyer must make rather than by an arbitrary enumeration of policy lines. The table maps the common lines to the decision each one informs; the sections after it go deep on the pieces that most often move money — the loss runs and EMR, the tail on claims-made lines, and the collateral trap.
| Buyer decision | What you verify | The lines and evidence that inform it |
|---|---|---|
| Continuity — does coverage survive the deal | Whether occurrence policies keep covering pre-close events, and whether claims-made lines keep their prior-acts position through the change of control | General liability, property, auto, workers' comp (occurrence); D&O, EPL, E&O/professional, cyber (claims-made); change-of-control and anti-assignment provisions |
| Cost & adequacy — is the program right-sized | Whether limits, deductibles, and self-insured retentions fit the risk, or thin coverage flattered earnings | Full policy schedule with limits and retentions; premium history; benchmarking against the risk profile |
| Inherited liability — what the buyer assumes | Open claims, loss reserves, IBNR exposure, and any posted collateral the buyer takes on | Five years of currently-valued loss runs per line; reserve and IBNR analysis; collateral instruments (LOC, surety, trust) |
| Deal-required cover — what the deal forces you to buy | The new coverage the transaction itself requires to close cleanly | D&O run-off (tail); replacement collateral; new or continued claims-made programs with prior-acts continuity |
Two things to read off this table. First, the same document set answers several decisions at once — the policy schedule feeds both continuity and adequacy, and the loss runs feed both inherited liability and the forward-cost view — so the reviewer reads across, not down. Second, the decisions are not independent: a claims-made line that will not keep its prior-acts position (a continuity problem) becomes a deal-required-cover problem (buy a tail), and a high-deductible program (a cost choice) becomes an inherited-liability problem (assume the reserves) and a deal-required-cover problem (replace the collateral) all at once. That cross-referencing is why the buy-side room has to let the broker, the underwriter, and counsel each work their slice while keeping the shared contract set visible.
What do five years of loss runs tell a buyer?
Five years of loss runs tell a buyer where the target's real risk lives and whether its insurance costs are about to rise — and reading them correctly is the technical heart of the workstream. A loss run is the carrier's record of claims against a policy: the date of each claim, the amount paid, the reserve still held open, and a description of the event. The market norm is to pull about five years of history per line, because one bad year is noise and a five-year trend is signal.
Three things a disciplined reviewer insists on. First, currently-valued runs — valued within roughly the last 60-90 days — because a run valued a year ago understates claims that have developed since, and a developing reserve is exactly the kind of liability the buyer would assume. Second, the trend, not the total: a workers'-comp frequency climbing year over year, a professional-liability severity stepping up, or a property book carrying a large open reserve each tells a different story than a flat five-year history, and each points to a different forward-premium and reserve-adequacy conclusion. Third, the piece a naive read misses — incurred-but-not-reported (IBNR) exposure. Paid losses plus case reserves plus IBNR is the estimate of ultimate losses, and IBNR is the claims that have happened but have not yet been reported. On long-tail lines like workers' compensation and general liability, IBNR can be material and can surface years after the event, which is why the reserve question is not answered by the paid-loss column alone. Sizing IBNR and reserve adequacy is where a specialist — a broker's analytics team or an actuary — earns the fee; the room's job is to get them the loss runs cleanly, not to do the analysis.
A rising loss trend is not automatically a reason to walk. It is a repricing lever and a reserve question: the buyer's broker sizes the forward-cost impact and the reserve adequacy, and the finding translates into a purchase-price adjustment, an escrow, or a specific indemnity, the same way any material red flag does. What is not negotiable is the handling: because loss runs and the claim files behind them can carry injury and health detail — special-category data under privacy law — they belong behind a gated, watermarked folder, a point the data-room section returns to.
Does the experience modification rate transfer in an acquisition?
The experience modification rate can follow the acquired operations for years, which is why a rising EMR is a diligence red flag rather than a curiosity. The EMR — the e-mod or x-mod — is the workers'-compensation premium multiplier that the National Council on Compensation Insurance (NCCI) or a state rating bureau calculates from about three years of an employer's claims history against the average for its class code. The baseline is 1.00 by design: 1.00 means the employer's losses match the class average, 0.80 means it pays roughly 20% below baseline, and 1.30 means roughly 30% above. Because the multiplier applies to the whole workers'-comp premium, a step change in the EMR is a direct, compounding cost — and a rising EMR is a leading indicator of both a deteriorating safety record and higher forward premiums.
The deal mechanics matter. In a change of ownership, the buyer generally must report the transaction to the rating bureau — for NCCI states, on the ERM-14 form, typically within about 90 days — and the prior experience frequently follows the acquired operations rather than resetting to 1.00. Whether the two entities' experience actually combines is governed by ownership and the bureau's combinability rules: a large acquirer absorbing a small target may see little change, while two similar-sized companies with very different loss records can see a material swing in the combined rate. The practitioner read for a buyer is to pull the EMR worksheet, understand the direction of travel, and price the forward workers'-comp cost into the model — not to assume the seller's rate carries over unchanged. This is one of the cleaner examples of an insurance finding that quietly changes the forward P&L the operational review is trying to protect.
Who pays for D&O tail coverage, and when is it negotiated?
D&O tail coverage is a negotiated closing mechanic, and getting the quote late is a classic way to delay a signing. A directors-and-officers (D&O) tail — also called run-off coverage — extends the window to report claims against the target's pre-close directors and officers for wrongful acts that occurred before the deal, after the change of control has put the underlying claims-made policy into run-off. It exists because D&O is written claims-made: a change-of-control provision typically stops coverage for post-close wrongful acts and freezes the pre-close program, so without a tail the departing board is exposed to pre-close claims that surface later.
The norms, with the sourcing honest about what is doctrine and what is market convention. The run-off period is customarily six years, and it is standard for the merger agreement to require the tail to be bound for the benefit of the target's directors and officers — the American Bar Association's Business Law Today notes the six-year norm and that these terms are heavily negotiable, while cautioning that change-of-control provisions operate in ways worth pinning down precisely. Who pays — buyer, seller, or a split, often funded out of transaction expenses — is a deal point, not a default, and it belongs in the agreement rather than the diligence memo. On cost, brokers commonly quote a six-year tail at roughly 200-300% of the expiring annual premium as a one-time, non-refundable payment; the real number turns on the risk and the market, so I state that as a directional norm, not a fixed price. The buyer's diligence actions: confirm the expiring D&O program and its limits, get a real tail quote early because it gates the close, and make sure the run-off obligation is written into the deal.
The same claims-made logic extends past D&O. The target's employment-practices (EPL), errors-and-omissions / professional, and cyber policies are typically claims-made too, and each turns on a retroactive date and a prior-acts position. In a deal, continuity on these lines is preserved either by a tail from the incumbent carrier or by a new policy that grants prior-acts coverage back to the original retroactive date — and a lapse or a new retroactive date set at inception silently strips coverage for pre-close events. A reviewer checks the retroactive date on every claims-made line and confirms the plan to keep continuity, because a broken prior-acts chain is an uninsured gap hiding in plain sight.
What happens to a target's insurance in an asset deal versus a stock deal?
Deal structure changes what happens to the insurance, and the asset-versus-stock distinction is the fork. In a stock (or equity) deal, the target entity survives with its policies in place, subject to any change-of-control provision the carrier can invoke — so occurrence policies continue to cover pre-close events for the entity, and the buyer's task is to confirm the carriers do not walk and to handle the claims-made lines with tails or prior-acts continuity as above.
In an asset deal, the buyer generally does not inherit the seller's policies. Commercial insurance contracts contain anti-assignment conditions barring transfer of the policy to another party without the insurer's written consent, so the buyer usually cannot simply take over the program and must bind its own coverage effective at close. There is a nuance the case law recognizes and a good agreement uses: while the policy itself cannot be assigned without consent, most courts hold that the right to claim proceeds for a loss that already occurred before the sale can be assigned, because that right is a fixed claim rather than a new risk to the insurer. So a well-drafted asset purchase agreement expressly assigns the right to insurance proceeds for pre-closing occurrences as a named asset — all past occurrence policies, not just the current one — and, where useful, names the buyer as an additional insured on the seller's occurrence policies for pre-close events.
The practical diligence output is a two-column map: which coverage disappears at close (so the buyer binds replacement cover in time and there is no day-one gap) and which pre-close claim rights the buyer wants preserved in the purchase agreement. Because this sits on the seam between the insurance and legal workstreams — the same change-of-control and consent analysis the lawyers are running on the contract base — the broker and counsel work it together rather than in separate silos.
Is a certificate of insurance enough to rely on?
No — a certificate of insurance proves coverage existed on the day it was issued and nothing more, and treating it as proof of current, adequate cover is a recurring diligence mistake. A certificate of insurance (COI), typically an ACORD 25 form, carries its own disclaimer in capital letters: it "is issued as a matter of information only and confers no rights upon the certificate holder" and "does not affirmatively or negatively amend, extend or alter the coverage afforded by the policies." The independent-agent bar's guidance on certificates collects the case law: a certificate is not a contract between the holder and the insurer and creates no coverage — it merely informs a third party that insurance was in force at issuance.
For diligence, that doctrine has teeth. A stack of COIs the target collected from its vendors, or issued to its own customers and landlords, tells the reviewer a policy was in force at a moment in time. It does not confirm that the limits are adequate today, that the policy has not since been cancelled or eroded by paid claims, that the additional-insured or waiver-of-subrogation status a contract required was actually endorsed onto the policy, or that the coverage responds the way the holder assumes. So the reviewer uses COIs as a starting index and then verifies against the actual policies, endorsements, and declarations pages, and specifically confirms that the additional-insured and waiver-of-subrogation obligations the target owes under its customer contracts and leases are genuinely reflected on the underlying policies — which leads directly to the next section.
Are there insurance obligations hidden in customer contracts and leases?
Yes — some of the most consequential insurance findings are not in the insurance file at all; they are in the target's customer contracts, supplier agreements, and commercial leases. These agreements routinely impose insurance requirements on the target: a duty to name the customer or landlord as an additional insured, a waiver of subrogation in the counterparty's favor, and minimum coverage limits by line. As practitioners note, additional-insured and waiver-of-subrogation terms appear in virtually every commercial contract of meaningful value, usually as the price of winning the work or signing the lease — and a waiver of subrogation is a real transfer of risk, not boilerplate.
These obligations bite in two directions. First, non-compliance is a breach: if the target promised additional-insured status and a specified umbrella limit to its largest customer but never endorsed it onto the policy, the target is in breach — and in the worst case the customer holds a termination right the buyer inherits. Second, the obligations shape the post-close program: the combined entity must keep meeting every additional-insured and minimum-limit requirement across the assumed contract base, which can force higher limits or specific endorsements the buyer had not budgeted. The review therefore pulls the insurance clauses from the material contracts and leases and cross-checks them against the endorsements actually on the target's policies, flagging every gap. This is the clearest example of why the insurance and legal reviews coordinate: the change-of-control read and the insurance-clause read are two passes over the same contract set.
What is the collateral trap on high-deductible programs?
The collateral trap is the insurance finding most likely to surprise a buyer with a real cash cost at close, and it is the named hook of this guide. Here is the mechanic. A target that runs a high-deductible (large-deductible) workers'-compensation program — or a similar self-insured casualty program — self-insures losses up to a deductible, and the carrier, which is the first payer on all losses, requires the target to post collateral to secure the deductible it has promised to reimburse. As Milliman explains, that collateral takes the form of a letter of credit (LOC), a surety bond, or cash held in trust, and it is the carrier's view of the remaining self-insured liability. Because workers'-comp claims pay out over many years, the collateral does not release at close — it ramps up toward an equilibrium as new policy-year losses are offset by old ones running off, and it can tie up a large portion of the company's cash or revolving credit for years.
Now the deal problem. That collateral usually cannot simply transfer to the buyer. When ownership changes, the buyer generally has to replace the collateral — post its own letter of credit, surety bond, or cash — for the assumed program, and until it does, the seller's instrument may stay on the hook. Replacement collateral is not an accounting entry; it is real cash or borrowing capacity committed on day one, and it is precisely the line a light insurance review misses because it is not a premium and it does not appear as a "claim." A buyer that has not scoped it can find, late in the process, that closing requires posting several months of forward-losses' worth of collateral it never modeled.
Here is a hypothetical to make the mechanic concrete (illustrative figures, not a real deal). Suppose a target runs a $500,000-per-claim deductible workers'-comp program and has a $3 million letter of credit posted to its carrier as collateral against developing losses. On a change of control, the buyer is asked to replace that LOC with its own — $3 million of the buyer's bank facility now encumbered, plus fees, from close. The buyer does not necessarily walk; it prices the finding. It might treat the required collateral as debt-like in the purchase-price bridge, negotiate who funds the replacement, or — where a surety bond is acceptable to the carrier — use a bond that costs less than an LOC and frees up the credit line, since insurers increasingly accept surety in place of letters of credit. What always happens is that the collateral obligation gets surfaced, sized, and allocated in writing — the opposite of discovering it at signing. This is the single strongest reason insurance belongs on the diligence critical path rather than in a footnote.
How is insurance due diligence different from RWI?
Insurance due diligence and representations and warranties insurance (RWI) are two different products, and conflating them is the most common category error in this workstream. Insurance due diligence reviews the target's own operating insurance — the policies it carries to run the business, its loss history, its collateral, its EMR. RWI (also written R&W insurance) is a transactional policy placed on the deal itself: it backstops the seller's representations in the purchase agreement, so if a rep proves untrue, the insured recovers from the RWI policy rather than clawing back from the seller.
The mechanics and budgets are separate. Insurance DD is a review cost — broker or advisory time. RWI is a placed policy with a premium (the market convention prices it as a percentage of the policy limit) and a retention the insured absorbs before coverage responds. I do not re-derive the RWI pricing, retention norms, or 2026 adoption rates here, because our due diligence report guide already covers them in depth and I will not risk contradicting that canon — that is the reference for how RWI is priced and how often it is used.
The two products interact, which is the part worth getting right. An RWI underwriter reads the diligence reports to price the policy and will exclude from coverage anything the buyer already knew — so a gap the insurance-DD review surfaces and the buyer chooses to accept is not something RWI will later pay for. Known issues get handled through purchase-price adjustments, escrows, or specific indemnities, not through the RWI policy. Put simply: insurance DD tells you what you are buying; RWI protects the promises the seller made about it. For the RWI mechanics and adoption data, see the due diligence report and what-is-due-diligence guides; this post stays on the operating-program side of that line.
What does insurance due diligence cost and how long does it take?
Insurance due diligence is one of the lower-cost diligence workstreams in absolute terms — it is broker or risk-advisory time, not a multi-week accounting engagement — and it usually runs in parallel rather than on the long pole. The exact figure varies too widely by deal size, the number of policy lines, and the complexity of the collateral and claims picture to publish a single reliable number, so I frame it as a range that scales with the program rather than inventing precision: a clean, single-line program on a small deal is a light review; a target with multiple deductible programs, posted collateral, a messy five-year loss history, and a large assumed-contract base with embedded insurance obligations is a heavier one. For where this sits against the other workstreams, our due diligence cost breakdown has the cross-deal benchmarks.
On timeline, two items are the ones that actually cause delay if they start late. Pulling five years of currently-valued loss runs from the carriers can take weeks — which is why a prepared seller requests them at the outset — and a D&O tail quote is a closing mechanic that should be obtained before it holds up the signing. Neither is hard; both are slow if left to the end. The overall deal arc is what the insurance review has to fit inside: across 334 M&A transactions on the Peony platform, blended time-to-close reached about 8.6 months in Q2 2026 (State of M&A Data Rooms, Q2 2026), and the insurance workstream sits comfortably within that as long as the loss runs and tail quotes are started on time. The single biggest lever on both cost and speed is whether the insurance file was assembled before the buyer's broker started asking. For the index of first-party Peony datasets behind these numbers, see Peony Research.
How do you run the insurance workstream in the data room?
You run the insurance workstream in a few steps built around two facts: the file is contract-heavy and it is privacy-sensitive. The goal is a room where the broker, the underwriter, and counsel each work independently, the loss runs and claim files stay gated and traceable, and nothing sensitive walks out.
1. Give the workstream its own structure. Inside the broader diligence room, the insurance file gets its own folder tree: the policy schedule and declarations, five years of loss runs by line and year, the collateral instruments (LOC, surety, trust), the certificates of insurance sitting next to the policies they reference, and a pull of the insurance clauses from the material customer contracts and leases. Organizing certificates next to policies and clauses next to endorsements is what makes the verification in the COI and contractual-obligations sections fast instead of a scavenger hunt. AI auto-indexing sorts a bulk upload into that structure in minutes.
2. Wall the reviewers into their slice. The broker and the underwriter get a granular-permission view scoped to the insurance folder; counsel sees the insurance clauses alongside the legal folder; the quality-of-earnings team never needs the claim files. When several bidders are in the process, one room per bidder means no bidder learns another is at the table.
3. Gate and watermark the claims folder specifically. Loss runs and the claim files behind them can contain injury and health detail — special-category personal data, and a data-protection incident carries its own clock: GDPR Article 33 requires notifying the supervisory authority of a personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware. So the claims folder signs behind an NDA before it opens, carries per-viewer dynamic watermarking so any screenshot traces to one party, and turns on screenshot protection. Keeping this material in a gated, logged room rather than an email thread is the difference between a controlled disclosure and a reportable breach.
4. Track engagement. Page-level analytics show which reviewer is working which part of the file and where they are stuck — useful for managing a multi-party insurance review and for reading which bidders are serious.
The honest scope of the room. The data room is the exchange and evidence layer, not the analysis tool. The loss-run read, the reserve-and-IBNR adequacy work, and the EMR benchmarking are run by your broker or actuary; the room gives them a walled, watermarked, logged view of exactly the loss runs and schedules they need. And for a mega-cap process with millions of pages and a staffed, managed Q&A desk, an enterprise VDR is the right tool, and I would say so — that is a different job than the operator-run and mid-market deal this workstream usually lives in. Peony runs that mid-market room on the Data Room plan at $52 per admin per month (billed annually) with unlimited documents and rooms, dynamic watermarking, granular permissions, and an exportable audit trail; a seller can even assemble and pressure-test the insurance file on the free plan first, then present a Simple NDA on Business at $30 or Advanced NDA with countersigning on Data Room. Viewers are always unlimited and free, so a broker, an underwriter, and their analysts reviewing the file add nothing to the bill. This is the model behind Peony serving 6,800+ customers across M&A and diligence.
What are the common mistakes in insurance due diligence?
The common mistakes in insurance due diligence cluster around treating it as a checkbox — confirming policies exist without reading what they mean, and discovering the deal-required costs after signing instead of during diligence. Each is avoidable, and each recurs.
- Treating a certificate of insurance as proof of coverage. A COI confers no rights and only shows insurance was in force at issuance; relying on the certificate instead of verifying the actual policy, endorsements, and current limits is the classic light-review error.
- Missing the collateral trap. Failing to scope the collateral behind a high-deductible workers'-comp or casualty program leaves the buyer to discover, at close, that it must post replacement collateral — real cash or credit committed on day one.
- Forgetting the D&O tail until it delays the close. The six-year run-off is a negotiated closing mechanic; getting the quote late, or leaving the run-off obligation out of the merger agreement, holds up the signing.
- Breaking prior-acts continuity on the claims-made lines. Letting a D&O, EPL, E&O, or cyber policy lapse or accept a new retroactive date at inception silently strips coverage for pre-close events.
- Assuming the EMR resets. Treating the target's workers'-comp experience modification rate as if it disappears at close, when it frequently follows the acquired operations for years and can raise the combined entity's premiums.
- Ignoring the insurance obligations in customer contracts and leases. Skipping the cross-check of additional-insured, waiver-of-subrogation, and minimum-limit clauses against the actual policy endorsements, so a breach — and a possible customer termination right — rides along uninspected.
- Mishandling the claims file. Putting loss runs and claim files with injury or health detail into an ungated email thread rather than a gated, watermarked room, turning a routine disclosure into a privacy exposure.
The unifying lesson is that insurance diligence rewards reading the program rather than counting the policies, and using the room to keep the contract-heavy, privacy-sensitive file organized, gated, and auditable — so the review confirms what the buyer is really assuming rather than surfacing an unbudgeted cost the week of close.
Related Resources
- What Is Due Diligence? — the definitional root of the DD cluster and the seven types, including where RWI sits
- M&A Due Diligence Process Guide — the six-phase, eight-workstream framework this insurance review plugs into
- Buy-Side Due Diligence — the buy-side process and the seven workstreams sequenced against the exclusivity clock
- Due Diligence Report — the IC-ready synthesis, and the deepest coverage of RWI pricing, retention, and 2026 adoption
- Legal Due Diligence — the change-of-control consent map behind policy assignability and the insurance-clause read of the contract base
- Operational Due Diligence — the eight-system operational audit where insurance adequacy is one sub-element
- Financial Due Diligence — add-backs, the working-capital peg, and where under-insurance flatters earnings
- Quality of Earnings — the QoE that reads the insurance finding as an input to earnings quality
- HR Due Diligence — employee benefits, workers'-comp exposure, and the people-side risk that overlaps the insurance file
- Cybersecurity Due Diligence — the cyber-policy and breach-liability review that runs alongside the insurance workstream
- Due Diligence Cost Breakdown — comparative diligence costs across deal sizes and workstreams
- Due Diligence Red Flags — the cross-workstream red-flag library, including insurance and reserve signals
- Best Insurance M&A Advisors — a different intent: the advisors who run the sale of an insurance agency or brokerage, not the program review
- Buy-Side M&A Data Room — the acquirer's room architecture that houses every diligence workstream
For insurance due diligence specifically, Peony's data room — used by 6,800+ customers — gives the insurance workstream its own permissioned folder so the broker, underwriter, and counsel work independently in one room; dynamic watermarking and screenshot protection on the loss runs and claim files that carry special-category data; NDA gating before the claims folder opens; AI auto-indexing that sorts policy schedules, loss runs, and certificates into structure in under five minutes; and an exportable audit trail that records who reviewed which loss run and when. Try Peony free for 14 days — no credit card required.
About the author: Sean Yu is the co-founder of Peony, the data room platform used by 6,800+ customers across M&A, fundraising, and diligence workflows. Before Peony, Sean spent his career on the deal side — M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries at Target Global — running and supporting buy-side and sell-side processes across software, industrials, and services in North America and Europe. He studied Biomedical Engineering at Imperial College London on a full scholarship before dropping out to build companies. Contact: sean@peony.ink • LinkedIn.
Sources
- NCCI — Experience Rating and the ERM-14 Change in Ownership form (combinability; ~90-day reporting) — https://www.ncci.com/Articles/Documents/UW_ERM14Instructions.pdf
- Prescient National — Mergers & Acquisitions and Combinability in Workers' Compensation — https://www.prescientnational.com/mas-and-combinability-in-workers-compensation/
- Insureon — Experience Modification Rating (1.00 baseline; below 1.0 = credit, above = debit) — https://www.insureon.com/insurance-glossary/experience-modification-rating
- ABA Business Law Today — Coverage Cutoffs in M&A: Five Things to Know About D&O 'Tail' Coverage (six-year run-off; change-of-control; heavily negotiable), Dec 22 2025 — https://businesslawtoday.org/2025/12/coverage-cutoffs-in-ma-transactions-five-things-to-know-about-do-insurance-tail-coverage/
- LegalClarity — D&O tail policy: six-year term at ~200-300% of annual premium, non-refundable (market norm) — https://legalclarity.org/what-is-a-do-tail-policy-and-when-do-you-need-one/
- IIABA (Independent Insurance Agents & Brokers of America) — Certificates of Insurance: Issues and Answers (ACORD 25 confers no rights; case law) — https://www.independentagent.com/wp-content/uploads/2024/04/IIABACOI.pdf
- National Law Review — Assigning Insurance Policies Can Get Tricky (assignment must be explicit; the Premcor lesson) — https://natlawreview.com/article/assigning-insurance-policies-can-get-tricky
- Barnes & Thornburg — Transferring Insurance Rights in Corporate Transactions — https://btlaw.com/insights/blogs/policyholder-protection/2020/transferring-insurance-rights-in-corporate-transactions
- Embroker — Prior Acts Coverage and the retroactive date (claims-made continuity) — https://www.embroker.com/blog/prior-acts-coverage
- Milliman — Large Deductible Programs: Demystifying Collateral (LOC / surety / cash-trust; multi-year equilibrium) — https://www.milliman.com/en/insight/large-deductible-programs-demystifying-collateral
- Business Insurance — Comp insurers ease collateral requirements for high-deductible policies (surety in place of LOC) — https://www.businessinsurance.com/Comp-insurers-ease-collateral-requirements-for-high-deductible-policies/
- Reed Smith — Navigating Additional Insured Requirements in Commercial Contracts — https://www.reedsmith.com/articles/navigating-additional-insured-requirements-in-commercial-contracts-a-practical-guide-for-businesses/
- Higginbotham — What is a Waiver of Subrogation in Business Insurance? — https://www.higginbotham.com/blog/waiver-of-subrogation/
- IRMI — Loss Run (currently valued loss-history report; definition) — https://www.irmi.com/term/insurance-definitions/loss-run
- IRMI — Incurred But Not Reported (IBNR) — https://www.irmi.com/term/insurance-definitions/incurred-but-not-reported
- GDPR — Article 33, Notification of a personal data breach to the supervisory authority (72-hour clock) — https://gdpr-info.eu/art-33-gdpr/
- Peony — State of M&A Data Rooms, Q2 2026 (334 transactions; ~8.6 months blended time-to-close) — https://www.peony.ink/blog/state-of-ma-data-rooms
- Peony Research — first-party dataset index — https://www.peony.ink/research
You might also like
May 11, 2026
AI Due Diligence (2026): 5-Layer Audit + EU AI Act Map + 12 Deals
Aug 21, 2026
ESG Due Diligence (2026): The Post-Omnibus Scope Reset + the Scope 3 Evidence Test
Aug 19, 2026
Manufacturing Due Diligence (2026): The Certification, Capex, and Tariff Checks That Price the Deal

