What an E&O limit is actually protecting
Professional liability, written as errors and omissions in the United States and professional indemnity elsewhere, responds when your work causes a client financial loss. The distinguishing feature is that the damages bear no fixed relationship to what you were paid. A structural engineer earning $80,000 on a design can cause a rebuild costing several million. A benefits consultant earning $40,000 can misadvise on a plan election and create a liability an order of magnitude larger. This is why sizing the limit against revenue — the most common approach — produces numbers that are unrelated to the exposure.
Size it instead against the engagement that could produce the largest claim, and apply a multiplier that reflects what going wrong on that engagement would cost the client. The multiplier is the judgement in this calculation and it belongs to your profession, not to a table: in design and construction it is driven by the cost of rework; in accounting and tax it is driven by the size of the position taken; in technology it is driven by the client's downstream revenue. Whatever multiplier you use, define it against contract fees, because that is the denominator this calculator applies it to. A multiplier remembered from a peer conversation quoted against project value instead of fees will size your limit wrongly by the ratio of the two.
Two other things are always true of an E&O claim and both are in the arithmetic here. You will incur defence costs whether or not you are liable, and defending a claim you eventually win is a normal and expensive outcome. And the claims that arrive tend to arrive together, because the market conditions or the internal process failure that produced one usually produced several.
Why defence inside the limit is the most expensive line on the form
Most E&O policies are written with defence costs inside the limit, meaning every dollar spent on lawyers reduces what is left to settle with. General liability, by contrast, traditionally pays defence in addition to the limit. Buyers compare an E&O limit against a general liability limit as if they were the same currency, and they are not.
The arithmetic is unforgiving. A $1,000,000 per-claim limit with $150,000 of defence cost gives you $850,000 of settlement capacity, not $1,000,000. Against a $1,500,000 indemnity exposure the gap is $650,000. Move defence outside the limit and the same policy leaves a $500,000 gap — $150,000 better, exactly the defence cost, because defence is then paid in addition. The relationship is exact rather than approximate: switching defence from inside to outside improves the settlement capacity by precisely the defence cost, no more.
That also means the effect is largest on small limits. On a $250,000 limit, a $150,000 defence bill consumes 60% of it and leaves $100,000 to settle a claim. On a $5,000,000 limit the same defence consumes 3%. Firms buying modest limits are the ones for whom defence erosion matters most, and they are also the ones least likely to be offered a defence-outside option.
The second structural feature is the aggregate. A policy with $1,000,000 per claim and $2,000,000 aggregate can pay two full-limit claims and nothing more, whatever arrives in the rest of the period. Modelling claim counts as Poisson with mean λ, the chance of two or more in a year is 1 − e−λ(1 + λ). At λ = 0.15 that is 1.02% — small in any one year, but roughly one year in a hundred, and the year it happens is the year the aggregate decides your outcome.
Worked example: a consultancy with a $500,000 engagement
A consultancy's largest live contract is worth $500,000 in fees. It judges that a serious error on that engagement would cost the client about three times the fee. Defence on a contested claim runs $150,000. The policy is $1,000,000 per claim, $2,000,000 aggregate, defence inside the limit. Historical frequency across the firm is 0.15 claims a year.
- Indemnity exposure. $500,000 × 3 = $1,500,000.
- Single-claim exposure. $1,500,000 + $150,000 defence = $1,650,000.
- Settlement capacity. Defence is inside, so $1,000,000 − $150,000 = $850,000.
- Uninsured gap. $1,500,000 − $850,000 = $650,000, which the firm pays from its own balance sheet.
- Recommended limit. The exposure to cover is $1,650,000, so the next standard market tier is $2,000,000.
- Aggregate test. Two claims at $1,650,000 each need $3,300,000. The $2,000,000 aggregate is $2,000,000 ÷ $3,300,000 = 60.6% of that.
- Probability of two claims. 1 − e−0.15 × 1.15 = 1 − 0.98981 = 1.02%.
The firm's exposure is 65% larger than the limit it carries, and its aggregate would run out on the second claim. Both problems come from the same decision: the limit was bought at $1,000,000 because that is what everybody buys, without anyone multiplying the largest contract by anything.
How to read the result
Look at the uninsured gap first, and read it as a balance-sheet number rather than an insurance number. It is the amount the firm pays out of retained earnings if the modelled claim happens. If the gap exceeds what the business could absorb without failing, the limit is wrong regardless of what peers buy.
Then read the settlement capacity against the per-claim limit. The difference between them is the defence cost, and if it is a large fraction of the limit you are effectively buying a much smaller policy than the declarations page suggests. Ask your broker whether a defence-outside or a defence-in-addition option is available and what it costs; on smaller limits it is frequently better value than the same premium spent on more limit, because it delivers its benefit on every claim rather than only on the large ones.
Aggregate adequacy below 100% means the policy cannot absorb the number of claims you asked it to size for. That is not automatically a problem — buying an aggregate for four simultaneous full-limit claims is expensive and usually unnecessary — but it should be a decision rather than an accident. Where frequency is genuinely material, an aggregate reinstatement or a higher aggregate is the right purchase, not a higher per-claim limit.
Finally, treat the recommended limit as a floor for the discussion. It covers the largest engagement you have today. Firms grow into larger contracts between renewals, and the limit is fixed at inception, so a firm whose largest engagement doubles mid-year is underinsured for the second half of the period with no signal that anything has changed.
Standard market limits and what they leave uncovered
| Per-claim limit | Capacity if defence is inside | Gap if defence is inside | Gap if defence is outside |
|---|---|---|---|
| $250,000 | $100,000 | $1,400,000 | $1,250,000 |
| $500,000 | $350,000 | $1,150,000 | $1,000,000 |
| $1,000,000 | $850,000 | $650,000 | $500,000 |
| $2,000,000 | $1,850,000 | $0 | $0 |
| $3,000,000 | $2,850,000 | $0 | $0 |
| $5,000,000 | $4,850,000 | $0 | $0 |
The two gap columns differ by exactly the $150,000 defence cost until the limit is large enough that both reach zero. That constant difference is the value of moving defence outside the limit, and it is worth the same on every claim regardless of the claim's size.
Claims-made means the date that matters is not the date you made the mistake
Almost all professional liability is written on a claims-made basis: the policy that responds is the one in force when the claim is first made against you and reported, not the one in force when you did the work. Three consequences follow. A retroactive date on the policy excludes work performed before it, so changing carriers without preserving the retroactive date can delete years of past work from coverage. Letting a policy lapse leaves every past engagement uninsured, because no future policy will pick them up. And when you stop practising you need extended reporting period cover — tail cover — to report claims arising from work already done, priced as a multiple of the expiring premium. None of these is modelled by the limit arithmetic on this page, and all of them can matter more than the limit.
Assumptions and limits of this model
- One claim from one engagement. Real claims can arise from a systemic error repeated across many clients, in which case the exposure is the aggregate of every affected engagement, not the largest one.
- The multiplier is judgement. No table can tell you what damages a failure on your work produces. Use your own claims history, your professional body's guidance, or the largest consequential loss written into your client contracts.
- Contractual limitation of liability is ignored. Many engagement letters cap liability at fees, or at a multiple of fees. Where that cap is enforceable in your jurisdiction it is the cheapest risk control available and it changes the multiplier directly.
- Poisson assumes independent claims. Professional liability claims cluster, because one bad process or one market downturn generates several at once. The probability of two or more claims is therefore a lower bound.
- No sublimits or coverage extensions. Regulatory investigation costs, disciplinary proceedings and loss of documents are commonly written at sublimits, and none of them is included here.
- No allowance for the deductible. The retention comes off each claim and is not modelled; with several small claims in a year the retentions alone can be a material cost.
Where this sits alongside the rest of the programme
Professional liability overlaps two adjacent covers, and the overlap is where gaps live. A technology or services firm whose failure exposed client data faces a cyber loss and an E&O claim from the same facts, and which policy responds turns on the wording rather than on what happened; size that side with the cyber liability coverage limit calculator and check for an other-insurance clause that could leave a strip uninsured between the two. General liability, meanwhile, excludes professional services almost universally, which is precisely why E&O exists as a separate purchase.
For a firm large enough that claims are predictable rather than exceptional, the more useful question stops being what limit to buy and becomes how much of the layer to retain. A higher deductible on an E&O programme behaves like any other retention decision and can be evaluated with the self-insured retention break-even calculator: expected retained loss plus the premium at that retention, against the volatility a bad year produces.
Review the limit whenever the largest engagement changes rather than only at renewal. That single input drives everything on this page, and it is the one that moves without anyone in the insurance conversation being told. Firms that also carry business interruption exposure should read this alongside the business interruption coverage calculator, since both are sized from operational facts that change faster than policies do.
