The Coverage Memo

Insurance Due Diligence in Startup Fundraising

Investors now require D&O insurance before closing seed and Series A rounds.

Senior Writer · · 9 min read
Cover illustration for “Insurance Due Diligence in Startup Fundraising”
Funding Milestones · October 2, 2026 · 9 min read · 1,939 words

Insurance has moved from a background administrative task to a closing condition in venture financing, and the reason is structural rather than bureaucratic. Investors know this, and they will not absorb that exposure on faith. Without a D&O policy in place, a fund faces three options going into a round: walk away from the deal, ask the startup to personally indemnify its board designee (a promise most early-stage companies cannot financially back), or decline to take the board seat at all. Each of those outcomes stalls or kills a financing. That is why Dealroom's 2026 due diligence guide treats insurance and risk not as a standalone workstream but as a recurring sub-item woven through financial, legal, commercial, operational, HR, IT, tax, environmental, and strategic-fit review, nine formal workstreams in total. Insurance is checked throughout the process because its absence touches every part of a company's risk profile, and 4Degrees' 2026 checklist confirms the same pattern, listing policy types, coverage adequacy, and claims history as standard items investors check before capital moves.

The coverage stack by funding stage

The coverage a founder needs is not a fixed checklist bought once and forgotten. It expands in scope and in dollar limits with each financing round, moving from a single narrow policy at the earliest stage to a full management-liability program by the time a company reaches Series A. At pre-seed, the only coverage that applies broadly is cyber insurance, and even that depends on whether the company handles personally identifiable information; there is no formal D&O expectation yet. At seed, D&O, cyber, and Technology E&O form the baseline, with D&O the most common investor requirement before wiring seed funds, and most institutional investors require it at this stage. At Series A, the stack grows again to include D&O at higher limits, Employment Practices Liability (EPL), cyber, Tech E&O, crime/fidelity, and commercial general liability, the full set investors and newly seated board members expect to see. From Series B onward, that same stack carries forward, but scrutiny intensifies: by Series C and growth stage, cybersecurity posture, ESG practices, regulatory compliance, and quality of earnings all become first-class diligence concerns alongside mandatory insurance review. The sections that follow unpack what each of these stages demands and why.

Diagram: The Coverage Stack by Funding Stage. Visualizes: Show how startup insurance requirements expand across four funding stages.

Seed-stage review: D&O as the non-negotiable first policy

D&O insurance is usually the first formal policy a founder encounters as a hard investor requirement, and understanding its structure affects whether directors and officers are actually protected when a claim arises, not just whether a box gets checked. The policy is built around three distinct coverage parts, with Side C providing entity coverage for the company itself, most commonly tied to securities-related allegations, though not every startup needs this in equal measure at seed. Side A protects individual directors and officers personally when the company cannot or will not indemnify them. Side B reimburses the company itself when it does step in to indemnify its directors and officers.

The detail that trips up founders most often involves the claims-made structure that governs D&O policies, which creates a retroactive-date trap. A claim is covered only if the underlying act occurred on or after the policy's retroactive date, typically the first date of continuous coverage. Heffernan Insurance Brokers lays out the mechanics: a founder who buys a D&O policy on January 1, 2026, and then receives notice of a claim in February 2027 has no coverage if the conduct in question took place in December 2025, before that retroactive date began. Timing matters: buy D&O before fundraising conversations start, not after a term sheet lands on the table.

D&O also has limits that founders frequently misunderstand. It does not cover product performance failures, which fall under Tech E&O; it does not cover data breaches or cyber incidents, which fall under Cyber Liability; it does not cover bodily injury, which falls under commercial general liability; and it does not cover wage-and-hour claims, which typically require EPLI. Founders who treat D&O as a catch-all create gaps that investors will find during diligence. That matters especially at seed, where the most common claims at sub-100-person companies come from employment disputes rather than securities allegations. Some seed-stage investors also ask about EPL alongside D&O even before Series A.

Diagram: The Retroactive-Date Trap. Visualizes: Illustrate a single claims-made timing failure using the exact example from the article: a founder buys D&O on January 1, 2026; the conduct at issue occurred in December 2025 (before the retroactive…

The policy exclusion problem: why having insurance is not the same as having coverage

Owning a policy and owning protection are not the same thing. A policy that technically exists but excludes a startup's core line of business gives investors nothing real to rely on, and investor legal teams reviewing Series A deals know exactly where to look for this gap. The research brief's cautionary example involves a data analytics startup whose Professional Indemnity policy, reviewed deep in Series A diligence, turned out to exclude claims arising from "financial modelling advice," which happened to be the company's core product feature. The exclusion rendered the policy functionally worthless despite its existence on paper.

AI adds a newer version of the same problem. Whether a Tech E&O policy actually covers AI hallucinations comes down to whether the policy affirmatively includes AI coverage or simply fails to exclude algorithmic output, and most off-the-shelf policies address neither. A second structural risk sits in the distinction between claims-made and occurrence-based D&O coverage: if a company that's been acquired or merged never purchased run-off (tail) coverage, and the acquiring party doesn't catch this during diligence, the acquirer inherits years of unfunded liability for conduct it had no part in. The fix is straightforward in principle even if it's skipped in practice: read the endorsements and exclusions, not just the limits and deductibles, and confirm that what actually triggers a claim under the policy matches what the business actually does.

Series A review: higher limits, broader stack, and the EPL addition

Series A changes the nature of the review itself. At seed, investors mostly confirm that a D&O policy exists. At Series A, investors and incoming board members shift to confirming that the entire stack is sized correctly and reviewing it as a condition of closing. Series A term sheets routinely require D&O limits of $2M–$5M, often with a requirement to raise those limits further within a set window after close. The stack itself widens to include D&O, Employment Practices Liability, cyber, Technology E&O, crime/fidelity, and commercial general liability.

EPL's arrival as a formal requirement at this stage is not arbitrary. Governance weaknesses compound this risk directly: a startup that has accumulated employment-related claims, repeated equity compensation disputes, unusually high turnover, or inconsistent documentation may discover that coverage purchased reactively, after those problems surface, is already too late to be useful from a claims standpoint. Series A diligence reflects this by going deeper than a yes/no check. Investors routinely request Certificates of Insurance and may ask for loss run reports or claims history outright, particularly when a company has pivoted its business model or scaled headcount quickly. 4Degrees' checklist confirms the same scope at this stage: policy types, adequacy of limits and terms, and any outstanding claims history, reviewed as standard practice rather than exception.

How governance history affects insurability

Buying insurance proactively preserves the ability to get good coverage. Underwriters flag a specific set of warning signs when they assess a startup's D&O application: accumulated employment-related claims or lawsuits, repeated disputes over equity compensation, unusually high employee turnover, and inconsistent documentation practices. Any of these can lead to higher premiums, narrower coverage, or outright denial. A founder who waits until a term sheet demands D&O coverage may arrive at the underwriter's desk with a governance record that has already limited what's available to buy.

The procurement process itself does useful work beyond producing a policy. The underwriting questions required to bind D&O coverage force a company to answer questions about board composition, officer authority, cap table complexity, and documentation practices, the same conversations that are far more useful to have early than at the moment a funding round is trying to close. Heffernan Insurance Brokers frames this as a matter of alignment: placing D&O coverage at or before institutional funding keeps the policy aligned with actual board composition and authority, protects both the company and its individual decision-makers, and reveals governance gaps during underwriting while they're still fixable. The objection that small, early-stage startups carry too little governance exposure to bother insuring against doesn't hold up once outside capital and equity compensation enter the picture; disputes over both tend to arise faster than founders expect.

The procurement timeline problem

Even founders who understand what to buy have historically run into a timing problem. Getting a startup insurance program in place through a traditional broker has typically taken two to four weeks, a pace that doesn't fit the final, compressed days of a fundraise. The most common and most avoidable cause of a delayed closing is a founder opening a due diligence checklist and discovering, late, that coverage is missing, inadequate, or poorly documented, which then triggers a scramble no one planned for.

A newer generation of insurance carriers has emerged specifically to remove that friction. These AI-native platforms now offer instant quotes and same-day Certificates of Insurance, letting founders put a full insurance program in place quickly without going through a traditional broker relationship at all. Corgi, founded in San Francisco in 2024, is the clearest example of this shift: the company raised $108M to launch as a full-stack carrier built specifically for startups, using that capital to scale operations, expand its coverage offerings, and develop AI systems for underwriting, claims, and policy management. Corgi went on to raise further capital at a valuation exceeding a billion dollars and reached tens of millions of dollars in annual recurring revenue within two years of beginning carrier operations. The pattern isn't limited to one company. Vouch has raised hundreds of millions of dollars in total funding, and Embroker has secured substantial backing of its own, evidence of a crowded, well-capitalized market responding to real founder demand rather than a single outlier succeeding alone. None of this is a ranking exercise between platforms; the broader point is that the procurement delay that used to threaten closings is now a solvable problem, not an unavoidable one.

New exposures investors are beginning to scrutinize: AI liability and coverage gaps in standard policies

The next frontier in insurance due diligence involves exposure that standard policies were never written to address. Due diligence checklists and off-the-shelf coverage have not caught up with AI-specific liability, and sophisticated investors are starting to probe exactly where that gap sits.

Whether a Tech E&O policy covers AI hallucinations or discriminatory algorithmic outputs depends on whether it includes affirmative AI coverage or lacks active exclusions for algorithmic output, and most standard policies do not address this. Purpose-built "AI Coverage" products have started to appear in the market specifically to address risks, like data leaks and discriminatory outputs, that major carriers actively write out of their standard policies. Many startups building AI products learn that these exclusions exist only when a diligence process reveals them, often well into a funding round. The exposure doesn't shrink as a company grows; it becomes harder to ignore. By Series C and growth stage, cybersecurity posture and regulatory compliance sit alongside standard insurance review as first-class diligence concerns, so the AI liability gap gets more visible rather than less as a company scales. The governance framework around all of this is still moving: the NVCA's model document update on October 2, 2025 reflected recent legal and market developments across national security compliance, tranched financing mechanics, and corporate governance, a sign that the formal rules investors rely on are still catching up to the risks founders are already carrying.

Sources

  1. 2026 Venture Capital Due Diligence Checklist - 4Degrees
  2. What Founders Need to Know About Insurance Before They Fundraise
  3. D&O Insurance for Startups
  4. Startups Due Diligence: Guide for Founders + Checklist

More in Funding Milestones