Resources

White Paper - Hidden Risk Series Part 1

Why annual insurance renewal should be treated as a strategic review, not an administrative event

A Quality Care Group White Paper

Simon van Os

Executive summary

Every year, organisations make one of their largest risk-financing decisions through a process that can become almost automatic.

Renewal documents arrive.

Values are checked against last year’s schedule.

A few questions are answered.

The premium is considered.

The policy is renewed.

The organisation moves on.

The comforting assumption is that little has changed.

In adult social care, that assumption is rarely true.

Care organisations evolve continuously. Buildings are extended and adapted. Residential services begin supporting people with more complex needs. Digital care records replace paper systems. New vehicles, equipment and technologies are introduced. Staff structures change. Revenue grows. Contracts become more demanding. Providers acquire services, open new locations and diversify into supported living, homecare, training, consultancy or specialist provision.

These developments may happen gradually, but their cumulative effect can transform the organisation’s risk profile.

Insurance does not automatically understand that transformation.

A policy renewed using historic information may still produce a certificate of insurance, but the certificate itself does not confirm that the organisation remains adequately protected. It only confirms that a contract exists on the terms, values, limits, conditions and assumptions recorded within it.

The consequences of a mismatch may remain invisible until a major loss, claim, regulatory investigation or prolonged interruption exposes the gap.

This white paper examines eight connected risks:

  1. Why organisations evolve more quietly than leaders realise.
  2. How familiarity and administrative convenience can turn renewal into routine.
  3. The operational changes most likely to alter a care provider’s exposure.
  4. Why inflation and rebuilding costs can make historic property values unreliable.
  5. How digital transformation creates both operational benefits and new dependencies.
  6. Why business interruption periods are frequently based on optimistic recovery assumptions.
  7. The responsibilities of boards, directors and trustees.
  8. A practical framework for conducting a meaningful annual risk and insurance review.

Its central argument is simple:

Insurance renewal should not ask whether anything has changed. It should uncover everything that has.

1. Why organisations evolve quietly

Organisational change is often imagined as a visible event.

A merger.

An acquisition.

A new building.

A major contract.

A strategic transformation programme.

Yet most operational change is less dramatic.  It arrives through dozens of small decisions.  

A room is repurposed.

A service accepts people with more complex needs.

A provider introduces electronic medication records.

A member of staff begins undertaking a new clinical task.

A garden building becomes an activity space.

An additional vehicle is acquired.

A vacant office becomes temporary accommodation.

A new subcontractor is appointed.

A service starts delivering training to external organisations.

None of these decisions may seem transformational in isolation.

Together, however, they may create an organisation that is materially different from the one described at the previous insurance renewal.

Change by accumulation

A residential care home may still describe itself as a residential care home, even though:

  • residents now have significantly higher acuity;
  • staff administer more complex medication;
  • additional equipment is used;
  • the premises have been altered;
  • digital systems have become essential;
  • staffing levels and payroll have increased;
  • income has grown;
  • new contractual obligations have been accepted.

The organisation’s name may be unchanged.

Its regulatory registration may be unchanged.

Its address may be unchanged.

Its underlying exposure may be entirely different.

This is particularly relevant in social care because services frequently adapt around people. That adaptability is one of the sector’s strengths, but it can also cause a gradual drift between the activities being undertaken and those originally described to insurers.

The problem with the phrase “business as usual”

“Business as usual” does not mean the business is static.

It often means change has become normalised.

A newly introduced process may feel significant in its first month. By renewal, it is simply how the organisation works.

The same can happen with:

  • digital care planning;
  • remote monitoring;
  • electronic medication administration;
  • delegated healthcare tasks;
  • higher dependency levels;
  • agency staffing;
  • overseas recruitment;
  • leased equipment;
  • consultancy services;
  • transport provision;
  • external training;
  • property improvement programmes.

If these developments are not deliberately captured, they may never reach the person completing the insurance declaration.

Why leaders may not see the whole picture

Senior leaders may approve major expenditure but not see every operational adaptation.

Finance may know that revenue increased.

Operations may know that service delivery changed.

Estates may know that a building was altered.

Human resources may know that employee numbers and roles changed.

IT may know that essential systems migrated to the cloud.

The registered manager may know that people’s needs became more complex.

The broker or insurer may receive only fragments of this information.

The first challenge at renewal is therefore not calculating a premium.

It is assembling an accurate picture of the organisation.

The greatest renewal risk is not necessarily providing incorrect information. It is providing information that was once correct but is no longer complete.

2. The psychology of auto-renewal

Insurance renewal can become routine for understandable reasons.

Care organisations operate under intense pressure. Leaders are managing workforce shortages, safeguarding, inspections, commissioning, occupancy, referrals, payroll, funding and service quality.

Insurance may feel distant from immediate care delivery, particularly when no significant claim has occurred.

The renewal therefore arrives as another deadline in an already crowded calendar.

Familiarity creates reassurance

When an organisation has renewed with the same insurer or broker for several years, familiarity can produce confidence.

The policy renewed last year.

No major concern was raised.

The insurer accepted the risk.

The certificates were issued.

This can create an implicit belief that the insurance programme remains suitable.

However, insurers can assess only the information made available to them. Renewal is not an independent audit of every activity, asset, contract or operational dependency within the organisation.

The presence of continuing cover should not be confused with confirmation that every declared value, limit and assumption remains accurate.

The status quo feels safer

Behavioural decision-making research has long recognised a tendency to favour existing arrangements, particularly when changing them involves effort, uncertainty or perceived risk.

In an insurance context, this can appear as:

renewing because the existing programme is familiar;

focusing primarily on the movement in premium;

accepting historic sums insured;

using last year’s turnover or wage roll as the starting point;

assuming index-linking has solved rebuilding-cost exposure;

avoiding broader review because renewal time is limited;

treating unanswered questions as evidence that nothing changed.

The ease of repeating last year’s information can overpower the harder task of reconstructing the organisation’s present-day exposure.

Renewal can become a price conversation

A further danger is that the annual process becomes dominated by premium.

Price matters.

Care providers operate within severe financial constraints, and boards rightly scrutinise expenditure.

But a cheaper policy may represent poor value if:

  • the buildings sum insured is inadequate;
  • the business interruption indemnity period is too short;
  • the description of activities is incomplete;
  • cyber cover excludes key dependencies;
  • liability limits do not reflect contractual requirements;
  • new entities or locations are missing;
  • conditions precedent cannot be met;
  • excesses have increased beyond the organisation’s risk appetite.

The real renewal question is not simply: “What will the insurance cost?”

It is:

“What financial and operational consequences are we asking the insurance programme to absorb?”

Consumer auto-renewal rules do not remove commercial responsibility

The Financial Conduct Authority requires firms to explain automatic renewal to consumers and provide accessible cancellation arrangements. Its renewal rules are designed in part to help consumers check that cover remains appropriate and compare alternatives. These protections should not be interpreted as a substitute for a commercial organisation’s own review of risk.

For a care organisation, automatic renewal should therefore be viewed as an administrative mechanism, not a risk-management conclusion.

3. Hidden operational change

The most important insurance changes are often operational rather than explicitly financial.  A provider does not need to buy another company or open a major new site for its exposure to alter materially.

3.1 Changes to people’s needs

A service may gradually support people with:

  • greater mobility needs
  • more complex medication
  • behaviours that challenge
  • acquired brain injuries
  • complex mental-health needs
  • respiratory support
  • enteral feeding
  • diabetes
  • epilepsy
  • advanced dementia
  • palliative or end-of-life needs

This evolution may affect:

  • staffing requirements
  • clinical responsibilities
  • professional liability
  • training
  • equipments
  • safeguarding exposure
  • evacuation planning
  • business continuity

the description of activities given to insurers.

The service may still use the same broad label, but the nature of the work may have changed substantially.

3.2 Changes to buildings

Care properties rarely remain untouched.

Changes may include:

  • extensions
  • conservatories
  • lifts
  • wet rooms/specialist baths
  • sensory rooms
  • commercial kitchens
  • nurse-call systems
  • garden buildings
  • solar panels
  • battery storage/charging points
  • upgraded fire systems
  • air-conditioning equipment
  • security systems
  • conversion of bedrooms or communal areas
  • changes to listed or heritage features

A project may increase the physical value of the premises, alter the fire or security risk, introduce specialist equipment or affect the cost and complexity of reinstatement.

Some alterations may also require planning, building-control or landlord consent. If those requirements are not properly documented, they can create complications well beyond the original building project.

3.3 Changes to services

A provider may begin with one core activity and gradually add others.

Examples include:

  • residential care
  • nursing care
  • domiciliary care
  • supported living
  • outreach
  • respite
  • day services
  • transport
  • training
  • consultancy
  • therapy
  • complex-care packages
  • agency staffing
  • property management
  • technology-enabled care

Each additional activity may introduce different contractual, professional, motor, property, cyber and liability exposures.

The most dangerous phrase may be: “It is only a small part of what we do.”

A small revenue stream can still generate a large claim.

3.4 Changes to the workforce

Insurance declarations frequently rely on payroll, employee numbers and role classifications.

These may change through:

  • recruitment growth
  • restructuring
  • new clinical roles
  • volunteers
  • apprentices
  • agency workers contractors
  • self-employed consultants
  • overseas recruitment
  • secondments
  • remote workers
  • employees working across multiple sites

Incorrect categorisation can affect employers’ liability, professional indemnity, personal accident, travel, motor and employment-related exposures.

3.5 Changes to contracts

Care providers operate within increasingly detailed contractual environments.

New contracts may require:

  • specified liability limits
  • cyber insurance
  • professional indemnity
  • indemnities in favour of commissioners
  • extended notification obligations
  • subcontractor controls
  • data-security standards
  • business-continuity commitments
  • access to particular systems
  • specific staffing or training requirements

Insurance should not be reviewed in isolation from these commitments.

A policy may be technically valid but insufficient to meet a contractual obligation accepted elsewhere in the organisation.

3.6 Changes to revenue and values

Insurance calculations may rely on:

  • turnover
  • gross profit
  • payroll
  • replacement values
  • stock
  • equipment
  • rental income
  • fee income
  • number of service users
  • number of beds
  • vehicle values

Growth can render historic figures inaccurate.

A percentage-based uplift may not be adequate where growth has been uneven, acquisition-led or concentrated in a new service line.

4. Inflation and rebuilding costs

One of the clearest examples of hidden insurance drift is the gap between a building’s insured value and its true reinstatement cost.

Market value is not rebuilding cost

Commercial property should generally be insured according to the cost of rebuilding, rather than sale price or market value. The Association of British Insurers specifically distinguishes rebuilding cost from market value and notes that the relevant figure includes labour and materials.

For care properties, reinstatement may involve much more than reconstructing walls and a roof.

The calculation may need to include:

  • demolition
  • debris removal
  • professional fees
  • surveyors
  • architects
  • engineers
  • planning requirements
  • building-control requirements
  • accessibility standards
  • fire-safety requirements
  • specialist mechanical and electrical systems
  • lifts
  • commercial kitchens
  • nurse-call systems
  • specialist bathrooms
  • external works
  • landscaping
  • site constraints
  • inflation during the rebuilding period
  • VAT where applicable

RICS guidance on reinstatement cost assessment explains that current building-cost evidence may come from sources such as BCIS, price books and comparable projects. A proper assessment is a specialist exercise, not simply an estimate of the property’s sale value.

Why historic valuations become unreliable

A valuation may become outdated because of:

  • construction-cost inflation
  • labour shortages
  • material-price changes
  • regulatory change
  • alterations to the building
  • extensions
  • increased professional fees
  • new safety standards
  • site-access difficulties
  • planning conditions
  • rebuilding inflation following a loss

Even where a policy contains index-linking, that mechanism may not correct an inaccurate starting figure or account fully for unreported alterations.

Underinsurance may affect more than the total-loss scenario

Some organisations assume the sum insured matters only if a property is completely destroyed.

That may be incorrect.

Depending on policy wording, an insurer may apply an average or proportional settlement where declared values are lower than the true value at risk.

For example, if a property is insured for substantially less than its true reinstatement value, the insurer may treat the organisation as having retained part of the risk itself.

The precise effect will depend on the wording, basis of settlement and insurer, but the underlying principle is clear:

A partial claim does not necessarily escape the consequences of underinsurance.

The ABI’s 2026 SME underinsurance report emphasised the need for realistic, declared values and indemnity periods and warned that underinsurance can lead to severe claim outcomes.

Care buildings create additional recovery challenges

A damaged office can sometimes relocate relatively quickly.

A damaged care service may need:

  • suitable alternative accommodation
  • local-authority and commissioner involvement
  • regulatory approval
  • specialist adaptations
  • safe transfer of residents
  • medication continuity
  • staffing continuity
  • family communication
  • preservation of routines
  • compatibility with people’s complex needs

Rebuilding the physical structure is only one part of the recovery.

Restoring the regulated service may take considerably longer.

A practical approach to property values

Boards should ask:

  • When was the last professional reinstatement-cost assessment?
  • Has the building been extended, altered or upgraded since then?
  • Are specialist fixtures and systems included?
  • Are external works included?
  • Does the figure reflect current construction costs?
  • Is day-one uplift or index-linking correctly applied?
  • Are professional fees and debris removal included?
  • Have heritage, planning or site constraints been considered?
  • Is the business interruption period aligned with the likely rebuilding and regulatory timeline?

A property value should be treated as a living risk assumption, not a number inherited indefinitely from an old schedule.

5. Technology and cyber evolution

Digital transformation has changed adult social care.

Electronic care records, medication systems, rostering, payroll, cloud storage, remote monitoring, communications platforms and digital reporting can improve quality, consistency and access to information.

Government guidance describes digital technology as potentially transformative when embedded effectively into care and support. CQC also recognises the growing role of digital record systems in improving quality and safety.

However, every efficiency can create a dependency.

The risk is not only data theft

Cyber risk is often imagined as an external hacker stealing personal data.

That remains important, but the operational consequences can be broader.

A care organisation may lose access to:

  • care records
  • medication information
  • staffing rotas
  • payroll
  • contact details
  • incident records
  • financial systems
  • email
  • telephony
  • remote monitoring
  • supplier information
  • commissioner portals
  • building-access systems

Official social-care cyber guidance asks providers to consider what they would do if they could not access digital care records or staff rostering systems and whether usable backups exist.

Cyber resilience is therefore not merely an IT responsibility.

It is a care-continuity responsibility.

Technology evolves faster than annual declarations

Between one renewal and the next, an organisation may:

  • move systems to the cloud
  • adopt a new software provider
  • connect additional devices
  • enable remote access
  • introduce artificial intelligence
  • use biometric data
  • change payment systems
  • outsource IT
  • connect with NHS or commissioner systems
  • deploy sensors or monitoring devices
  • increase homeworking
  • use personal devices

These developments can affect:

  • data volumes
  • regulatory exposure
  • system dependency
  • supplier dependency
  • contractual obligations
  • recovery costs
  • notification obligations
  • cyber-insurance underwriting
Third-party dependency

Care organisations increasingly rely on external technology suppliers.

A provider may believe data and systems are protected because they are hosted by a reputable third party.  Yet outsourcing a system does not outsource every consequence of failure.

A supplier outage or breach can still cause:

  • service disruption
  • loss of access
  • reputational damage
  • regulatory investigation
  • contractual disputes
  • family concerns
  • additional staffing costs
  • manual workarounds
  • notification costs

The annual review should therefore examine not only the organisation’s own technology but the resilience of critical suppliers.

Regulatory and contractual expectations

The Data Security and Protection Toolkit is used across health and social care to assess how personal information is handled. Local-government guidance describes it as an annual self-assessment and notes that commissioners may require providers to complete and publish it at the appropriate standard.

The toolkit is also transitioning towards the National Cyber Security Centre’s Cyber Assessment Framework, reflecting a broader emphasis on cyber resilience rather than narrow compliance.  Insurance is not a replacement for these controls.

Cyber insurers may expect evidence of:

  • multifactor authentication
  • backups
  • patching
  • access controls
  • staff training
  • incident-response planning
  • endpoint protection
  • email security
  • tested recovery arrangements

The NCSC provides guidance for organisations on backing up data, securing devices, protecting email and preparing for incidents.

The annual technology review

The renewal process should establish:

  • Which systems are essential to safe care?
  • What information is stored?
  • Where is it stored?
  • Who can access it?
  • Which suppliers are critical?
  • What would happen if each system failed?
  • Are backups segregated and tested?
  • Can services operate manually?
  • Has the incident plan been rehearsed?
  • Do declared revenues and data volumes remain accurate?
  • Have insurer security requirements been reviewed?
  • Are contractual cyber limits sufficient?

The most important cyber question may not be: “Could we be attacked?”

It is: “Could we continue delivering safe care while the attack is being resolved?”

6. Why business interruption is often underestimated

Buildings and equipment are tangible.

Interruption is harder to visualise.

For that reason, business interruption insurance can be based on assumptions that are optimistic, incomplete or inherited from previous years.

The ABI describes business interruption cover as protection against lost income when an organisation cannot operate normally following an unexpected event, with the aim of restoring the business to the financial position it would have occupied without the incident.

The difficulty lies in determining how much protection is needed and for how long.

Recovery begins long before rebuilding

A major property loss may trigger:

  • emergency response
  • evacuation
  • temporary relocation
  • insurer investigation
  • site stabilisation
  • demolition or clearance
  • surveys
  • design
  • planning
  • tendering
  • contractor appointment
  • procurement
  • rebuilding
  • fitting out
  • inspection
  • regulatory approval
  • recruitment
  • referrals
  • gradual return to normal occupancy

A twelve-month indemnity period may sound substantial.

For a complex care property, it may be consumed before the organisation has fully recovered.

Physical reinstatement is not commercial recovery

Even when a building is ready, the service may not immediately return to its previous financial position.

It may take time to:

  • rebuild occupancy
  • recruit staff
  • restore referral relationships
  • reassure commissioners
  • rebuild reputation
  • replace lost contracts
  • regain operational momentum
  • support people to return
  • achieve regulatory approval

The business interruption period should therefore reflect the time required to restore trading performance, not merely complete building works.

Gross profit terminology can mislead

Insurance definitions of gross profit may differ from accounting definitions.

A provider may submit a figure based on its accounts without appreciating that the policy calculation requires a specific adjustment for uninsured working expenses.

This can create material underinsurance even where turnover is accurate.

The calculation should be completed with appropriate financial and insurance advice rather than assumed from headline accounting figures.

Increased cost of working

Care organisations may incur significant additional costs while maintaining services, including:

  • temporary premises
  • transport
  • agency staff
  • overtime
  • temporary technology
  • equipment hire
  • professional fees
  • communications
  • relocation
  • security
  • additional management time

Some costs may be economically sensible even if they exceed the immediate reduction in insured income, because they protect residents, contracts, reputation and continuity.

The policy’s treatment of increased cost of working should be understood before a loss.

Dependencies beyond the insured premises

An organisation may be interrupted by damage at:

  • a key supplier
  • a laundry
  • a catering supplier
  • a pharmacy
  • an IT provider
  • a utility provider
  • a commissioner’s facility
  • a transport provider
  • an access road
  • a nearby property causing denial of access

Not every dependency is automatically covered.

The annual review should identify which external organisations could materially disrupt care delivery and whether the policy responds.

Business continuity and insurance must agree

A business-continuity plan may assume:

immediate access to another building;

  • rapid transfer of residents
  • availability of agency staff
  • access to paper records
  • functioning telecommunications
  • commissioner support
  • short rebuilding times

The insurance programme may make different assumptions.

The plan and policy should be tested together.

A continuity plan without adequate financial protection may be unaffordable.

Insurance without a workable continuity plan may be too slow to protect people and services.

Business interruption is not simply about replacing lost income. It is about financing survival while the organisation reconstructs its ability to operate.

7. Governance and board responsibility

Insurance is sometimes delegated to finance, procurement or an external broker.

The administration may be delegated.  Responsibility for organisational risk cannot be.

Directors

Section 172 of the Companies Act 2006 requires a director to act in the way they consider, in good faith, most likely to promote the success of the company while having regard to matters including long-term consequences, employees, business relationships, community impact and reputation.

Insurance adequacy is not named as a standalone statutory duty.

Nevertheless, decisions about risk financing, asset protection, service continuity and organisational resilience sit naturally within responsible governance.

A board does not need to become expert in insurance wording.

It should be capable of demonstrating that it:

  • understands major risks
  • receives reliable information
  • challenges material assumptions
  • seeks specialist advice where necessary
  • records decisions
  • monitors agreed actions
CQC governance expectations

CQC’s Regulation 17 guidance requires providers to maintain effective governance, assurance and auditing systems that assess, monitor and improve quality and safety.

Insurance alone does not satisfy that requirement.

However, inadequate protection can amplify the consequences of weaknesses in:

  • governance
  • risk management
  • records
  • cyber security
  • business continuity
  • property management
  • incident response

A meaningful renewal review should therefore connect with the provider’s wider governance system rather than remain an isolated purchasing exercise.

Trustees

Many social-care organisations are charities.

Charity Commission guidance states that trustees should identify major risks, decide how to respond and maintain an appropriate risk-management framework. Trustees must avoid exposing the charity to undue risk and take reasonable steps to manage risks to activities, beneficiaries, property and reputation.

All trustees remain responsible for financial management and internal controls even where detailed work is delegated.

For a charitable provider, an uninsured or underinsured loss can affect not only the organisation but:

  • beneficiaries
  • continuity of care
  • restricted funds
  • reserves
  • fundraising
  • reputation
  • trustee confidence
  • future viability
The board’s role at renewal

The board should not necessarily review every policy clause.

It should receive assurance on the matters capable of threatening continuity.

A proportionate annual report might include:

  • major operational changes
  • acquisitions and disposals
  • property valuations
  • material claims
  • emerging risks
  • changes in services
  • cyber maturity
  • indemnity periods
  • uninsured exposures
  • policy limitations
  • significant conditions
  • insurer risk-improvement requirements
  • management recommendations
Questions boards should ask
  1. What has changed since the last renewal?
  2. Who was consulted when answering that question?
  3. Which values are estimates, and how were they calculated?
  4. When were properties professionally assessed?
  5. Do our declared activities describe everything we now do?
  6. Which systems and suppliers are operationally critical?
  7. How long would full recovery realistically take?
  8. What risks have we consciously chosen to retain?
  9. Which exclusions or conditions could materially affect a claim?
  10. What evidence supports the recommendation to renew?

A renewal decision should be traceable.

Not because every claim can be predicted.

Because the board should be able to demonstrate that material assumptions were examined rather than inherited.

8. A practical annual review framework

The following framework is designed for care providers of different sizes and structures.  It is not a substitute for professional insurance, legal, property, cyber or financial advice.  Its purpose is to improve the quality of the annual conversation.

The CHANGE Framework

C: Context

Begin with the organisation, not the policy.

Ask:

  • ‍
  • What services do we currently provide?
  • Who do we support?
  • Where do we operate?
  • What has changed strategically?
  • What are the organisation’s objectives for the next year?
  • Are acquisitions, disposals or developments planned?
  • Which risks could prevent those objectives?

Required evidence

  • current organisation chart
  • group structure
  • service list
  • location schedule
  • strategic plan
  • risk register
  • acquisition or development plans
H: How the organisation operates

Map practical delivery.

Review:

  • activities
  • staffing
  • contractors
  • clinical responsibilities
  • transport
  • outsourced services
  • safeguarding
  • volunteers
  • training
  • consultancy
  • homeworking
  • overseas activity
  • events
  • fundraising where relevant

Key question

Does the description given to insurers match what staff actually do?

A: Assets and amounts

Review every value that drives insurance adequacy.

This includes:

  • buildings
  • tenants’ improvements
  • contents
  • specialist equipment
  • vehicles
  • computers
  • stock
  • revenue
  • gross profit
  • payroll
  • fees
  • rental income
  • cash
  • engineering plant

Required actions

  • commission professional property assessments where appropriate
  • update asset registers
  • reconcile turnover and payroll projections
  • identify new equipment
  • confirm ownership and lease responsibilities
  • examine inflation assumptions

Key question

Could every material asset be replaced using the values declared?

N: New dependencies and new risks

Identify what has appeared or become more important.

Review:

  • cyber
  • digital care records
  • cloud providers
  • AI
  • remote monitoring
  • critical suppliers
  • utilities
  • commissioners
  • transport
  • key people
  • regulatory changes
  • new contracts
  • environmental risks
  • reputational exposure

Key question

What can stop the organisation today that could not have stopped it five years ago?

G: Governance and gaps

Examine assurance rather than paperwork alone.

Review:

  • board oversight;
  • ownership of risk;
  • claims trends;
  • outstanding risk improvements;
  • policy conditions;
  • warranties;
  • exclusions;
  • excesses;
  • uninsured risks;
  • conflicts between contracts and cover;
  • broker recommendations;
  • insurer requirements.

Required evidence

  • documented review;
  • named action owners;
  • board or committee approval;
  • rationale for retained risks;
  • completion dates.

Key question

Which gaps have been accepted deliberately, and which exist only because nobody noticed them?

E: Emergency, interruption and recovery

Test the organisation’s survival assumptions.

Review:

  • emergency response
  • evacuation
  • alternative premises
  • resident relocation
  • communications
  • manual systems
  • backups
  • supplier failure
  • cash flow
  • reputational recovery
  • regulatory approval
  • rebuilding time
  • return to occupancy
  • indemnity period

Practical exercise

Run a tabletop scenario:

At 2am, the organisation’s largest service is made unusable by fire. Digital systems are unavailable, residents must be relocated and the building may require complete reconstruction.

Ask:

  • Who makes the first decision?
  • Where do people go?
  • How are families contacted?
  • How are medicines managed?
  • What information remains accessible?
  • What costs begin immediately?
  • How long before the service can reopen?
  • How long before income returns to its former level?
  • Which part of the insurance programme responds? Which costs are not covered?

Key question

Would the continuity plan still work if recovery took twice as long and cost twice as much as expected?

The annual review timetable

A high-quality renewal should begin well before the policy expiry date.

Six months before renewal

  • review claims
  • update risk register
  • identify acquisitions, developments and changes
  • commission property assessments where required
  • begin cyber and continuity review

Four months before renewal

  • gather turnover, payroll and asset data
  • confirm locations and entities
  • review contracts
  • consult operations, finance, HR, estates, IT and clinical leadership
  • update business interruption calculations

Three months before renewal

agree market strategy;

  • identify risk improvements
  • prepare underwriting narrative
  • review major policy limitations
  • resolve missing information

Six to eight weeks before renewal

  • assess insurer proposals
  • compare cover, conditions and service, not only premium
  • escalate major gaps
  • document options

Before binding cover

  • confirm all material changes
  • approve declared values
  • confirm entities and locations
  • review conditions
  • record governance decision
  • allocate post-renewal actions

Within one month after renewal

  • circulate policy summaries
  • brief relevant managers
  • diarise conditions and inspections
  • update claims procedures
  • store policies and contact information securely
  • plan mid-term review

Mid-term review

Annual review alone may be insufficient.  A mid-term review should be triggered by:

  • acquisition
  • disposal
  • major refurbishment
  • new site
  • new service
  • material increase in complexity
  • regulatory change
  • significant contract
  • major claim
  • cyber incident
  • substantial revenue growth
  • restructuring;
  • change of ownership
  • change in occupancy or building use

The insurance programme should follow the organisation’s change cycle rather than wait for its renewal date.

Board assurance checklist

Before approving renewal, the board should be able to answer yes to the following:

  • We have reviewed operational change across the organisation.
  • All entities and locations have been confirmed.
  • Services and activities are accurately described.
  • Property values have a defensible basis.
  • Major alterations and equipment are included.
  • Turnover, payroll and financial values are current.
  • Business interruption assumptions have been tested.
  • Cyber dependencies and controls have been reviewed.
  • Key contracts and indemnity requirements have been examined.
  • Major exclusions and conditions have been explained.
  • Claims experience has informed the renewal strategy.
  • Uninsured risks have been identified.
  • Decisions and actions have been documented.
  • The recommendation reflects more than price.
  • A mid-term review process is in place.
Conclusion

The phrase “nothing has changed” is rarely a statement of fact.

More often, it means change has not yet been gathered, examined and translated into the language of risk.

Care organisations evolve because they respond to people, communities, commissioners, regulation, technology and opportunity.

That evolution should be celebrated.

It should also be understood.

The danger is not renewal itself.

The danger is allowing renewal to become a substitute for review.

A policy can renew successfully while the organisation becomes progressively less aligned with the protection it holds.

Buildings may be worth more.

Services may be more complex.

Recovery may take longer.

Technology may be more critical.

Contracts may impose greater obligations.

People may depend on the organisation in entirely new ways.

The annual insurance process should therefore be treated as a strategic checkpoint.

A moment to stop. To look again. To ask what the organisation has become.

And to decide whether its protection has kept pace.

The cost of reviewing change can be measured in time and professional advice.

The cost of assuming nothing has changed may only be discovered when there is no longer time to correct it.

The board question

If our organisation had to recover from a major loss tomorrow, would our insurance protect the organisation we operate today, or the one we described several renewals ago?