A cyber policy can look reassuring but leave a small firm exposed to misdirected client money and authorised push fraud. It can also miss chargebacks, reconciliation errors and API outages. One event can cause refund demands, contract claims, FCA scrutiny and cash-flow pressure. Protection depends on permissions, activities and contracts, not product labels.
Which covers does a small payment firm need?
A firm needs insurance that matches its regulated role. It must also match money access and promises to merchants, partners and customers.
Cyber insurance can pay for incident response, forensic work, data restoration and privacy claims. It can also cover business interruption after a covered cyber event. Professional indemnity, or PI, can respond when poor payment, technology or compliance services cause customer loss. Crime insurance can address staff dishonesty and some fraud.
A policy called “cyber insurance” does not prove that payment losses, merchant claims or client-money shortfalls are insured.
The policy name matters far less than its wording.
Cyber cover is not payment-loss cover
Cyber cover usually responds to a hack, ransomware attack or data breach. It may not cover an operational payment failure. Payment card data creates PCI DSS risk, so check the policy wording.
Ask if it covers forensic checks, contract charges, regulatory defence costs and privacy liability. The ICO may investigate a serious breach. Insurance does not replace UK GDPR duties.
Permissions change the insurance answer
A PISP or AISP may need PI insurance or a similar guarantee. The Payment Services Regulations 2017 set this requirement. FCA permissions, services and transaction volumes shape the amount needed.
An EMI that holds safeguarded customer money faces different risks. These include safeguarding, settlement, crime and reconciliation risks. A software supplier with only an API faces a different set of risks.
Match payment risks to cover before buying
Match each realistic loss to a named insuring clause before comparing premiums. Also check each exclusion, excess and sublimit. An excess is the amount your firm pays first.
| Payment event | Likely cover | Frequent gap | Ask for in writing |
|---|
| Ransomware exposes card data | Cyber insurance | PCI DSS or contract costs excluded | PCI DSS and privacy-liability wording |
| Cloud API outage stops payments | Cyber business interruption | Supplier outage excluded | Dependent supplier cover |
| Reconciliation error delays settlement | Professional indemnity | Pure financial loss excluded | Processing and settlement errors |
| Employee diverts client money | Crime insurance | Client funds excluded | Employee dishonesty wording |
| Chargeback dispute | PI, if caused by an error | Treated as a trading loss | Merchant-services liability |
Chargebacks are often trading losses
Chargebacks, reserve deductions and cardholder disputes are often normal trading costs. Insurers may not treat them as covered losses. Cover is more likely if your careless processing error caused the merchant’s claim.
Read the merchant agreement beside the policy. Focus on clauses that require repayment even when your firm was not at fault.
Cloud outages need contingent cover
A cloud host, open-banking link or fraud-screening supplier can fail. Merchants may then be unable to take payments, even when your systems work. Dependent business interruption can address this risk.
Check waiting periods, named-supplier rules and lost-profit calculations. The NCSC gives relevant UK guidance on resilience.
Supplier failure can stop revenue without breaching your own systems.
Protect client money, fraud and settlement gaps
Safeguarding customer funds is a regulatory process, not insurance. It will not always refill an account after theft, an accounting error or insolvency.
The Financial Services Compensation Scheme does not automatically protect payment institution or EMI balances. Eligible bank deposits receive different protection. Choose limits from the largest realistic single loss.
Then test fraud, privacy, supplier-outage and defence-cost sublimits. Check that enough cover remains after each sublimit applies. Model a failed settlement day and a merchant claim. Also model 24 to 72 hours of lost payment income.
Large headline limits can hide small fraud limits.
Safeguarding is not an insurance policy
A reconciliation error means your records do not match money actually held. Failed refunds, duplicate files and timing faults can cause this mismatch. Think of it as two cashbooks that no longer show the same balance.
PI may respond to a third-party claim for careless work. It may exclude fixing your own books or replacing client money. Ask for a processing-error or settlement extension.
Fraud wording can fail at the claim
Funds-transfer fraud sends money to the wrong person through deception or unauthorised instructions. Social engineering is when a criminal tricks a person into approving that payment. These losses can happen without a system hack.
Insurers often require dual approval, call-back checks and multi-factor authentication. They also require prompt notice. Fraud sections often have lower sublimits than the policy’s headline limit.
The most frequent error is trusting the headline limit. The relevant fraud sublimit may be far lower.
Insurance decision path:
1. List every service: acquiring, e-money, payment initiation, account data, software or settlement.
2. List where customer money, card data and API dependencies sit.
3. Test each loss against the policy trigger, excess, sublimit and exclusion.
4. Ask the insurer to confirm the agreed activity description and extensions in writing.
Prepare transaction volumes, countries served and your largest merchant exposure before seeking terms. Also prepare cloud suppliers, prior claims, fraud controls and contract limits.
This approach does not apply in the same way to a shop using an external payment provider. That shop must not itself provide regulated payment services. This approach also does not replace regulatory, legal or insurance advice. Seek advice on FCA permissions, safeguarding, merchant contracts and a specific policy. A large group with an international programme and risk team needs a different review.
Bring your risk list, FCA permissions and key merchant contracts to a regulated insurance adviser. Test the wording, not just the quote.
Questions & answers
Do fintech companies need professional indemnity
Yes, if payment, technology, compliance or advisory services could cause client financial loss. PI may be compulsory for some FCA-regulated activities. This includes certain PISP and AISP arrangements, depending on permissions and activities.
What insurance does a payment firm need in the UK?
Payment firms often need cyber, PI and crime cover. They may also need funds-in-transit or management liability cover. An EMI holding safeguarded funds needs a broader review than a software-only supplier without payment-instruction access.
Does cyber insurance cover authorised push payment fraud?
Sometimes, if the policy includes social-engineering or funds-transfer-fraud wording. These sections often have lower sublimits. They may require dual approval, call-backs, multi-factor authentication and short notice deadlines.
Are chargebacks covered by cyber insurance?
Usually not, if the chargeback is a normal merchant trading loss or cardholder dispute. Cover may apply if a covered cyber event caused the merchant’s claim. It may also apply if a careless processing error directly caused that claim.
Do PISPs and AISPs need FCA-approved PI cover?
PISPs and AISPs should check current FCA rules on PI insurance or a similar guarantee. The Payment Services Regulations 2017 set the relevant rules. Required scope can depend on transaction volumes, territory and services provided.
How should a small firm choose its insurance
Test the largest credible single event, including legal costs, customer claims and lost income. Test lost income over 24 to 72 hours. Then check sublimits and excesses.
A £1 million headline limit may not apply to fraud or supplier outage.
Further reading
If you want to learn more about this topic, these sources may interest you: