Business insurance. Personal attention.

Technology, software and digital services

Software Developer Insurance
Perth, Sydney, Melbourne, Brisbane & Canberra

A practical guide to the risks, cover considerations and questions that matter to your business.

General information. Cover is subject to policy terms and underwriting.

Business owner discussing insurance documents with an adviser
BAU Risk Services — insurance brokerage

At a glance

Understand the risk.
Ask the right questions.

Software Developer Insurance starts with a clear picture of the work you perform, the responsibilities you accept and the events that could interrupt your business. This guide brings together common risks, insurance categories, practical documents and questions to discuss with your broker. Your business may need a different combination of covers or extensions from another business in the same industry.

Use the sections below to prepare for an insurance conversation in Perth, Sydney, Melbourne, Brisbane, Canberra or elsewhere in Australia. These examples are general information, not a recommendation that a particular policy is suitable for you. Your activities, locations, contracts and the applicable policy wording need to be considered together.

General information only. This does not take into account your objectives, financial situation or needs. Before acting, consider whether the information is appropriate for you. Cover is subject to insurer acceptance and the policy terms, conditions, limits and exclusions. Read the Financial Services Guide and the relevant PDS (where applicable) and/or policy wording before deciding.

01 / Understand your exposure

Common risks to consider.

02 / Connect risks with cover

Insurance commonly considered.

No single package suits every business. The descriptions below identify possible cover categories; each is subject to its own wording and underwriting.

may respond to covered allegations that professional services, advice, designs or omissions caused financial loss, subject to the insured services, retroactive date and claims-made notification requirements.

may assist with specified cyber incidents, privacy events, response costs and business interruption, depending on the event, security controls, sub-limits and exclusions.

may cover specified buildings, contents, stock and equipment following insured events, subject to declared values, exclusions and settlement terms.

may respond to certain directors and officers, employment-practices, statutory-liability or crime exposures where included, subject to policy terms and legal insurability.

The detail makes the difference.

A policy name does not establish that an activity or incident is insured. Review the insured business description, trigger, conditions, limits, excess and exclusions with your broker.

Business owners reviewing risk documents and a tablet
BAU Risk Services — insurance brokerage

03 / A closer look at your business

Details worth discussing.

A software developer should explain what is built, how it is delivered and what client systems depend on it. Custom applications, subscription platforms, embedded software and integration work can involve very different consequences if something fails. Identify whether the business only writes code or also hosts, deploys, monitors and supports the product. Explain access to production environments and the authority to change client data. A small development fee can relate to a system processing substantial transactions or supporting critical operations, so project value alone may not describe the potential exposure arising from the work.

Include the development model and the people contributing to it. Subcontractors, offshore teams and open-source components can form part of a product supplied under your contract. Describe the review, testing and release process as it operates in practice. Explain whether clients approve deployment and who maintains the software after handover. If the business changes from project work to a hosted service, the ongoing responsibilities may need fresh consideration. Professional indemnity, technology liability, cyber and property arrangements can address different issues, and none should be assumed to include every failure or allegation simply because the loss involves software.

Statements of work should identify the agreed functions, assumptions, dependencies and acceptance process. Record changes in scope and the effect on timing or cost. A request made in a chat channel can become a material change even if the formal document is never updated. Keep evidence of tests, approvals and the version released. These records help explain what the developer was instructed to deliver and what the client accepted. They do not establish that every defect is covered or eliminate the need to assess an allegation against the insured services and policy wording.

Review service levels, warranties, indemnities and liability caps before signing a significant contract. A guarantee of uninterrupted performance or responsibility for all consequential loss may exceed the insurer’s accepted liability. Ask about the treatment of intellectual property allegations, loss of data, security failures and costs to correct your own work. Open-source and third-party licence obligations should be considered through appropriate legal and technical review. If the developer hosts the product, explain dependencies on cloud providers and external services. A provider’s service credit or resilience claim does not establish that the developer’s own customer liabilities and interruption costs are insured.

After a failure, retain the relevant logs, deployment history, configuration information and communications. Record when the problem was detected, which functions were affected and what changed before it began. Avoid overwriting useful evidence during rollback or repair where it can be preserved safely. A security event may call for a different response from an ordinary code defect, so identify the appropriate technical and insurance contacts. Check incident response and consent provisions before engaging outside services on the assumption that their costs will be reimbursed. The immediate recovery work should remain coordinated with the applicable reporting arrangements.

Before renewal, review larger deployments, new industries, overseas clients and changes in hosting or support responsibilities. Explain any move into software used for more consequential decisions or operations. Consider how the business would maintain service if a key developer, repository or build system became unavailable. Access management and recoverable project records are relevant to that planning. Keep unresolved complaints, threatened claims and significant failures available for the submission. The insurance review should follow the full software lifecycle, from agreed requirements to continuing maintenance, so the selected arrangements can be discussed against the actual responsibilities accepted by the development business.

04 / Put it in context

What an incident might look like.

Hypothetical examples only. These are not BAU client stories or predictions of a claim outcome.

Scenario 02

A deployment, code defect or integration issue causes a client’s system or website to fail. The affected party seeks compensation, defence costs or rectification expenses. Whether any policy responds would depend on the allegations, insured activities, policy trigger, exclusions, excess and limit.

Scenario 03

A vulnerability or credential compromise leads to unauthorised access or data loss. The event also interrupts normal trading or creates additional expense. Property, liability, professional, cyber or interruption cover may be relevant only where the facts satisfy the applicable wording.

A few minutes. A different perspective.

Put your thinking
into practice.

Three situations for software developer businesses. Choose a practical next step, then explore why the details matter.

A learning activity with hypothetical situations. It is not a risk assessment, personal advice or a prediction of insurance cover.

3 industry scenariosSoftware Developer Insurance

What would you do next?

Work through the facts, the records and the questions you would take to your broker. There is no time limit.

Business owner and adviser reviewing policy documents with a calculator
BAU Risk Services — insurance brokerage

05 / Prepare for the conversation

Bring the details.
Make the discussion useful.

Documents and contracts

  • Are all products and services—development, hosting, support, data processing, consulting and managed services—listed?
  • What uptime commitments, warranties, indemnities and liability caps appear in customer contracts?
  • Does cyber cover include incident response, privacy liability, business interruption and social-engineering losses?
  • How are open-source software, subcontractors, cloud providers and offshore development teams treated?
  • Do the policy territory and jurisdiction match where customers, users and data are located?

06 / Know the limitations

What may not be covered.

The following are examples only, not a complete exclusion list. Product terms vary, and the applicable PDS and/or policy wording must be checked.

07 / Questions, explained

Frequently asked questions.

Depending on their activities, assets, staff and contracts, software developers and development firms may consider Professional indemnity insurance, Cyber insurance, Public and products liability insurance. Other policies or extensions may also be relevant. No single list is suitable for every business, and availability is subject to insurer appetite and underwriting.

Not automatically. A claim outcome depends on the actual facts, the policy period, insured activities, definitions, exclusions, conditions, excesses, sub-limits and notification requirements. The relevant wording should be reviewed before relying on cover.

Insurers commonly request turnover or revenue, payroll, staff and contractor numbers, locations, claims or complaints history, and the exact activities to be insured, plus services provided, contract limits, data volumes, security controls, hosting arrangements and overseas customers. Complete and accurate disclosure helps the insurer assess the risk, but it does not guarantee that cover will be offered or that a future claim will be accepted.

Local understanding. National reach.

Across Australia.
Connected to your business.

Based in Osborne Park, Western Australia, and supporting businesses nationally. These are service areas, not separate BAU offices. State and territory requirements can differ.

WAWestern Australia

Perth, Bunbury, Mandurah, Rockingham and Kalgoorlie.

NSWNew South Wales

Sydney, Newcastle, Central Coast, Wollongong and Maitland.

VICVictoria

Melbourne, Geelong, Ballarat, Bendigo and Shepparton.

QLDQueensland

Brisbane, Gold Coast, Sunshine Coast, Townsville and Cairns.

SASouth Australia

Adelaide, Mount Gambier, Whyalla, Gawler and Port Pirie.

TASTasmania

Hobart, Launceston, Devonport, Burnie and Ulverstone.

ACTAustralian Capital Territory

Canberra, Gungahlin, Tuggeranong, Belconnen and Woden Valley.

NTNorthern Territory

Darwin, Palmerston, Alice Springs, Katherine and Nhulunbuy.

Let’s start with your business

A clearer conversation
about your insurance.

Tell us what you do, what has changed and what you need to understand.

Speak with BAU Risk

Request a callback.

Tell us about your business and the cover questions you would like to discuss.

Before sharing personal information, read our privacy information.

This field is for validation purposes and should be left unchanged.
Name(Required)
What would you like to discuss? Please leave out sensitive personal or payment information.