Insurance & Risk Management

Coverage types, contract requirements, policy exclusions, claims and incident response, and reducing operational risk.

Find a section

Home / For CRAs / Insurance & Risk Management

CRAs face potential liability and financial exposure from inaccurate reporting, FCRA violations, data security incidents, contractual obligations, and other business risks. Under FCRA § 1681n, a consumer may recover actual damages or statutory damages of $100 to $1,000 for willful noncompliance, along with punitive damages and attorney fees. Under FCRA § 1681o, a consumer may recover actual damages and attorney fees for negligent noncompliance.

Insurance and risk management address that exposure from two directions. Insurance responds after a claim is made. Risk management reduces the number of claims that arise.

Coverage Types

Different policies respond to different events, and a CRA’s exposures rarely fall under a single one.

  • Errors and omissions. Also called professional liability, this coverage generally responds to claims arising from errors or negligence in the CRA’s professional services, including inaccurate reports, missed records, and other reporting errors.
  • Cyber liability. This coverage generally responds to data breaches and other security incidents. Depending on the policy, coverage may include breach notification costs, forensic investigation, credit monitoring, legal expenses, and regulatory response.
  • General liability. This coverage generally responds to bodily injury and property damage claims arising from business operations. It does not respond to claims about the accuracy of a report.
  • Employment practices liability. This coverage generally responds to claims brought by the CRA’s own employees, separate from anything involving consumer reports.
  • Directors and officers. This coverage generally responds to claims against individual officers and directors arising from management decisions.

Worth Knowing: Errors and omissions coverage is often called professional liability insurance. It generally addresses claims arising from errors or negligence in the CRA’s professional services, while cyber liability addresses data breaches and other security incidents. The names and coverage vary by policy, so CRAs should confirm what each policy actually covers and where gaps may remain.

Contract Requirements

Insurance obligations flow in both directions. Clients impose requirements on the CRA, and the CRA imposes requirements on its vendors.

  • Review client insurance requirements before signing. Service agreements frequently specify coverage types, minimum limits, and additional insured status. Confirm that existing policies satisfy them rather than assuming they do.
  • Understand additional insured requirements. Some client agreements require the client to be named as an additional insured. Confirm with the carrier whether the requested status is available and what coverage it provides before agreeing to the requirement.
  • Impose requirements on vendors. Court researchers, data providers, and other vendors should carry coverage appropriate to the work they perform, stated in the vendor agreement.
  • Collect certificates of insurance and track expiration. Obtain updated certificates periodically to confirm that required vendor coverage remains current.
  • Compare indemnification obligations with coverage. Contractual indemnification requirements may extend beyond what an insurance policy covers, leaving the CRA responsible for uninsured exposure.

See Vendor Management for the insurance provisions in a vendor agreement.

Policy Exclusions

Coverage depends not only on what the policy includes, but also on its exclusions, definitions, limits, and conditions.

  • Review statutory and regulatory exclusions. Some professional liability policies exclude claims arising under specific statutes. A policy that excludes FCRA claims provides limited protection to a CRA.
  • Check how statutory damages are treated. Coverage for statutory damages, fines, penalties, and punitive damages may be limited or excluded depending on the policy and applicable law.
  • Identify prior acts and retroactive dates. Claims made policies generally respond only to claims arising from work performed after a stated retroactive date. Changing carriers can create a gap covering earlier work.
  • Claims made vs. occurrence coverage. A claims made policy generally responds to claims reported during the policy period. An occurrence policy responds to events that happened during the policy period, regardless of when the claim is reported. CRAs should understand the applicable reporting requirements, retroactive dates, and other conditions of their coverage.
  • Confirm defense cost treatment. Determine whether defense costs are paid in addition to the limit or reduce it. FCRA defense costs can be substantial even when a claim is resolved without payment.
  • Review intentional acts and knowledge exclusions. Coverage may not respond to conduct the CRA knew about before the policy incepted.

Good Practice: Review the actual policy language rather than the summary of coverage. Exclusions, definitions, and the retroactive date appear in the policy form and its endorsements, and those are the terms that determine whether a claim is paid.

Claims and Incident Response

Prompt handling of claims and incidents can affect both the outcome of the matter and the availability of insurance coverage.

  • Report claims and potential claims promptly. Claims made policies typically require notice within the policy period and within a specified time after the CRA becomes aware of the matter. Late notice is a common basis for denial.
  • Know what triggers a notice obligation. Depending on the policy, a demand letter, lawsuit, regulatory inquiry, or circumstance that could reasonably lead to a claim may require notice to the carrier.
  • Suspend routine destruction of related records. When litigation or a regulatory inquiry becomes reasonably foreseeable, disposal of related records should stop until the matter is resolved.
  • Coordinate the response when appropriate. Significant claims, regulatory matters, and security incidents may require coordination with the insurance carrier, broker, legal counsel, or other appropriate professionals.
  • Preserve the file as it existed. The report as furnished, the research documentation, and the identity match determination all establish what was done at the time.
  • Follow the breach response process for security incidents. Notification timing is governed by state law, and cyber policies frequently require the carrier to be involved in selecting forensic and legal resources.

Worth Knowing: Claims where a procedure affected many consumers in the same way may be brought as a class action. If willful noncompliance is established, statutory damages may significantly increase the potential exposure (FCRA § 1681n). This makes identifying and correcting systemic compliance problems particularly important.

See the Risk Management and Employment Law directories for providers serving CRAs.

Operational Risk Management

Insurance is only one part of managing risk. Strong procedures can reduce the errors, security incidents, compliance failures, and operational problems that lead to claims.

  • Identify common sources of exposure. Inaccurate reports, incorrect identity matches, reporting information beyond an applicable limit, public record notice issues, and mishandled disputes can all create significant FCRA risk.
  • Pay particular attention to systemic errors. A problem in a procedure or system may affect multiple reports, making it important to identify the scope of the issue and correct the underlying cause.
  • Use dispute data to find weaknesses. Disputes categorized by cause identify which procedures are failing before a claim is filed.
  • Address concentration risk. A CRA that depends on one client, one vendor, or one data source for a large share of its work is exposed if that relationship ends or that source fails.
  • Plan for business interruption. Consider how operations will continue after a system outage, facility loss, vendor disruption, or unexpected loss of key personnel.
  • Review exposures on a schedule. New services, new jurisdictions, and new data sources each introduce risks the existing program was not built for.

See Quality Control Standards for identifying procedural weaknesses before they produce claims.

Records to Keep on File

Insurance records document what coverage was in force, when, and what has been reported under it.

Maintain, as applicable:

  • Current policies, including all endorsements
  • Expired policies, retained for the period during which a claim may still be brought
  • Certificates of insurance issued to clients
  • Certificates of insurance received from vendors, with expiration dates tracked
  • Retroactive dates and prior acts coverage for each policy
  • Claims and incidents reported, with dates of notice
  • Correspondence with carriers and brokers
  • Risk assessments and the actions taken in response

Expired policies should be retained along with current policies. Prior policy terms, retroactive dates, reporting provisions, and endorsements may become important when determining which coverage applies to a later claim.

See Records & Documentation for retention schedules and secure storage.

Worth Knowing: Insurance can help protect a CRA from the financial impact of a claim, but it does not replace strong compliance and operational procedures. The best risk management program combines appropriate coverage with practices designed to prevent problems before they occur.

Download the Insurance and Risk Review Checklist

What coverage to review, what exclusions to check, and what to keep on file.

Download PDF