Small Businesses
Tech Companies
Motor & Fleet
Insurance Basics

Investment manager indemnity insurance: PI, D&O and cyber explained

July 20, 2026
a list item
8 Mins Read
Investment manager indemnity insurance: PI, D&O and cyber explained

Investment manager indemnity insurance may combine Professional Indemnity (PI) and management-liability sections for fund businesses, while cyber may be arranged separately or alongside the program. Each section has a different trigger. A coordinated program should match the defined services, fund entities, management roles and payment controls rather than assuming one section covers every event.

PI may address claims about how the fund was managed. Directors and Officers (D&O) covers claims about how the business was governed. Crime addresses defined direct financial loss from fraud or theft. Cyber handles data, systems and privacy risks. And regulatory cover may fund approved legal costs for insured inquiries. Understanding what each does helps spot gaps before a claim arrives.

For a full overview, see what is investment manager indemnity insurance. For who should consider it, see what insurance do investment managers need.

At a glance

  • PI may respond to claims from defined fund or advisory services
  • D&O may respond to wrongful-act claims against insured directors or officers
  • Crime may address defined direct loss from dishonesty or fraud
  • Regulatory cover may fund approved legal costs for insured inquiries
  • Cyber isn't automatically part of every IMI policy
  • One event can trigger PI, D&O and crime at the same time
  • Cyber cover should be confirmed, not assumed

PI, D&O, crime and cyber: key differences

Cover Main trigger Who or what it may protect Example
PI Alleged error or breach in fund services Manager, fund or insured service entity Investor alleges unsuitable strategy
D&O Alleged management wrongful act Directors, officers, insured entity where applicable Director accused of weak compliance oversight
Crime Defined direct loss from dishonesty or fraud Manager or fund where insured Employee diverts money
Regulatory Insured official inquiry Insured entity or person ASIC requests documents and interviews
Cyber (often separate) Cyber incident or data/privacy event Systems, data, business and third-party liabilities Investor records exposed in breach

Swipe left or right to see the full table.

How professional indemnity works for investment managers

The PI section may respond where a party alleges that an error, omission or breach in providing defined fund services caused a financial loss. Claims may involve failure to follow a mandate, inaccurate reporting, net asset value (NAV) errors or undisclosed conflicts.

Cover may include approved defence costs and, where the claim is covered, settlements or damages. The scope depends entirely on how "investment services" is defined in the wording. That definition is the gatekeeper. If it's too narrow. for example, if it lists "portfolio management" but the claim is about research advice. A legitimate claim may fall outside cover.

Market loss versus PI trigger. Poor fund performance caused by market movement alone isn't a PI trigger. The claim needs to allege an error in how the fund was managed, not just that it didn't perform. A fund losing 25% in a broad downturn isn't a PI claim. A fund losing 25% because the manager ignored the mandate's risk limits is a different matter. The distinction is between an investment result and alleged wrongful conduct.

Defence costs: inside or outside the limit? This is one of the most important structural questions in any IMI policy. If defence costs sit inside the limit, a long case can eat through the cover before it settles. A $5 million limit with $2 million in legal fees leaves only $3 million for the settlement. ASIC favours costs in addition to the limit for retail-facing licensees.

Scenario: investors allege negligent NAV calculation

A fund manager miscalculates the NAV, causing investors to buy units at an inflated price. When corrected, values drop. Investors allege negligence. The PI section may assess approved defence costs and any covered settlement. The key questions: was the NAV service within the defined services, and was the error notified in time under the claims-made rules?

How D&O insurance works for investment managers

D&O may respond to claims that a director, officer, trustee or committee member committed a wrongful act while managing the business or fund. It primarily addresses claims against insured people acting in management capacities. This is personal cover for the individuals, though some policies also include entity cover (where the company itself is sued) and company reimbursement (where the company indemnifies the director).

Common claim triggers. Claims may concern breach of duties, weak governance, misleading disclosure approved by the board or failure to manage conflicts. Unitholders, investors and ASIC may all bring claims against insured directors of a responsible entity (RE). The claims don't need to involve the investment advice itself. They target how the business was run.

Who's covered matters. Check whether the insured-persons definition includes directors, officers, compliance committee members and investment committee members. If the manager holds board seats on portfolio companies (common in PE), that board-level exposure should be addressed too. A gap in the insured-persons list means a gap in cover.

The PI/D&O boundary. A claim that the manager gave poor investment advice is a PI issue. A claim that the director failed to supervise the team giving the advice is a D&O issue. The line between them isn't always clear. That ambiguity is one of the main reasons the bundled IMI approach exists. One insurer assesses both, rather than two insurers arguing about which policy should respond.

Scenario: director faces personal claim for PDS misrepresentation

An RE issues a Product Disclosure Statement (PDS) with return projections. The fund underperforms. Investors allege the director approved misleading projections. D&O may cover the director's personal defence costs. PI may also need to assess the claim against the RE itself, depending on who is sued and in what capacity.

Crime insurance versus cyber insurance

These two are often confused. They address different losses.

Crime may address defined direct financial loss suffered by the manager or an insured fund from dishonest or fraudulent conduct. This may include employee theft, forgery and specified transfer-fraud events where included. Crime commonly covers first-party loss. the insured entity's own money.
Not third-party claims. If an employee creates false invoices and diverts fund assets, that's a crime claim.

Cyber may address data breaches, privacy liability, ransomware, system interruption and third-party claims from a cyber event. Fund managers hold sensitive client data: names, tax file numbers, bank details and investment positions. A breach triggers obligations under the Privacy Act and may trigger client claims. Cyber is not automatically part of every IMI policy. The upcover IMI product page highlights PI, D&O, regulatory, crime and Employment Practices Liability (EPL) as the core sections. Cyber should be checked separately.

The grey area. A fraudulent electronic transfer caused by a hacking attack may fall under cyber. The same transfer caused by a dishonest employee may fall under crime. A social-engineering email that tricks an employee into making a payment may fall under either, neither or both depending on the wording. This overlap is one of the trickiest areas in fund-management insurance. The specific event must be expressly included in the relevant section.

How regulatory cover works

Regulatory cover may fund approved legal and representation costs when ASIC, APRA or another body conducts an insured inquiry into the business or its people.

When the trigger starts. This varies between policies. Some respond from the first information request or notice. Others only respond once a formal investigation is declared. That distinction matters because early-stage costs. Responding to information requests, attending interviews, producing documents can be substantial. A policy that only triggers at the formal stage may leave those early costs unfunded.

Who's covered. The insured persons and entities should match the regulatory section's scope. Directors, officers and the management entity are commonly included. But authorised representatives, compliance officers and the fund itself may or may not be covered. Check.

Common misconceptions

What people assume What's more accurate
"D&O covers all regulatory fines" Depends on the wording, investigation stage and whether the fine is legally insurable
"PI covers poor fund performance" The trigger is alleged negligence or breach, not market movement alone
"One limit means each section has the same capacity" A shared limit may be eroded by one large claim, leaving less for other sections
"The manager's policy covers every fund" Funds and entities must fall within the insured-entity definition or schedule
"Defence costs are always extra" Some policies pay defence costs from inside the limit, not in addition to it
"D&O and PI never overlap" A single event can trigger both. The bundled IMI approach helps manage that boundary.

One event, three sections: why the bundle matters

This is the scenario that explains why coordinated cover exists.

An employee fabricates trades and triggers investor losses. A senior trader at a fund manager creates fictitious trades to hide losses over several months. When the fraud is discovered, three things happen at once.

Crime responds to the direct loss. The employee's fraud caused a direct financial loss to the fund. The crime section may cover that loss, subject to the policy's definitions, discovery period and notification rules. This is a first-party claim - the fund lost its own money.

PI responds to the investor claim. Investors don't just accept the loss. They allege the manager was negligent in supervising the trader and that the fund suffered losses it shouldn't have. The PI section may cover approved defence costs and any covered settlement. The claim isn't about the fraud itself - it's about how the fund was managed.

D&O responds to the regulatory action. ASIC investigates the directors for failing to maintain adequate compliance and supervision systems. The D&O section (or the regulatory section) may cover approved legal and representation costs for the insured directors. The directors face personal exposure for how they ran the business.

Why this matters. With separate policies from different insurers, the crime insurer might say the investor loss is a PI issue. The PI insurer might say it's a crime issue. The D&O insurer might say it's both. The manager ends up in a three-way coverage dispute while trying to defend the actual claims. The IMI bundle puts one insurer across all sections, which may reduce that boundary-dispute risk.

Shared limits versus separate D&O capacity

This is a structural decision that affects how much cover is available when it matters most.

Shared limit. One limit covers PI, D&O and crime. If a large PI claim uses $3 million of a $5 million limit, only $2 million remains for D&O and crime. The sections compete for the same pool. A fund manager dealing with a major investor claim and a simultaneous ASIC investigation may find the limit stretched across both.

Separate D&O tower. D&O gets its own dedicated limit. A large PI claim doesn't reduce the D&O cover. Separate D&O capacity may remain available where the PI limit has been eroded, subject to its own terms.

When separate capacity may make sense. Listed REs, managers with large FUM, managers with multiple funds, or boards with independent directors who require personal protection as a condition of serving. Whether separate capacity is appropriate depends on the governance exposure and the directors' personal risk profile.

Practical checks before arranging cover

Are all funds and entities insured? Every fund, sub-fund, manager, RE, trustee and special-purpose vehicle should be checked against the schedule. An unlisted entity may not be covered when a claim arises.

Are the defined services accurate? The PI section only responds to claims within the defined fund or advisory services. If the definition says "portfolio management" but the business also gives research advice or structures products, those services may fall outside cover.

Does crime include the right events? Employee theft is usually covered. But fraudulent payment instructions and external fraud events may need to be expressly included. Don't assume they're in.

Is cyber included or separate? If the IMI doesn't include cyber, arrange it alongside the program. Fund managers hold sensitive data that creates Privacy Act obligations.

Are limits shared or separate? If one limit covers PI, D&O and crime, a large claim in one section can erode cover for the others. Directors may want a separate D&O tower.

Are defence costs inside or outside the limit? Inside means legal fees reduce what's left for the settlement. Outside means the full limit stays available for damages. This one structural detail can make a material difference in a large claim.

When does regulatory cover start? First information request? Formal investigation? The trigger determines whether early-stage legal costs are funded.

Are portfolio-company board roles covered? PE managers who hold board seats face D&O exposure at both the fund-manager level and the portfolio-company level. Both should be addressed.

How upcover can help

upcover arranges investment manager indemnity insurance for eligible Australian businesses. Options can be compared using consistent funds under management (FUM), fund structures, entities and services so wording differences are easier to spot.

  • 70,000+ businesses covered across Australia
  • 4.9/5 customer rating
  • 80+ insurance partners

Get an IMI insurance quote through upcover

upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078.

Frequently asked questions

Is cyber included in IMI?

Not always. Some policies include cyber by extension, but it's often arranged separately. The upcover IMI product highlights PI, D&O, regulatory, crime and EPL as core sections. Cyber should be checked.

What is the difference between PI and D&O in IMI?

PI may respond to claims about how the fund was managed (service errors, mandate breaches). D&O may respond to claims about how the business was governed (director duties, oversight). The triggers differ even when the same event is involved.

Does D&O cover ASIC investigations?

It may where the regulatory section is included and the inquiry meets the policy trigger. The stage, insured person, sub-limit and wording all matter. Some policies respond from the first notice. Others only respond once a formal investigation starts.

Does crime cover social-engineering fraud?

Not necessarily. Social-engineering attacks may fall under crime, cyber or neither depending on the wording. The specific event must be expressly included. Don't assume it's covered.

Can PI and D&O respond to the same event?

They may assess different allegations arising from the same event. An investor may allege manager negligence (PI) while ASIC investigates the directors for oversight failures (D&O).

Does one IMI policy cover the fund and the manager?

Only where both fall within the insured-entity definition or schedule. A fund that isn't listed may not be covered. Check every relevant entity including sub-funds and special-purpose vehicles.

The information in this article has been prepared without taking into account your individual needs, objectives or financial situation. It should not be relied upon as personal advice. All insurance products arranged through upcover are subject to the terms, conditions, limits and exclusions contained in the relevant policy wording and Product Disclosure Statement. Before deciding whether a particular insurance product is right for you, please read the relevant PDS and consider your personal circumstances. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078. upcover arranges insurance products with selected insurers and underwriters and does not compare all general insurers or insurance products available in the market.

We are digitising commercial insurance and risk management for small, mid-market and technology businesses. We work with a global network of underwriters, challenging legacy brokers and delivering market leading coverage to our customers.