01
Map the service before naming a policy
Two freelancers with similar revenue can have very different exposure because the work, clients, data, property, advice, locations, and contract promises differ.
General practice
- Service risk: errors, omissions, missed requirements, professional advice, rework, delay, or alleged financial harm.
- Data and cyber risk: personal information, confidential files, credentials, remote access, software, incidents, and notification duties.
- Property and physical risk: business equipment, client property, travel, premises, events, shipping, or bodily injury.
- Contract risk: indemnity, defense, liability limits, insurance clauses, additional insured requests, certificates, and subcontractor obligations.
- People risk: employees, subcontractors, work performed by others, safety, disability, or interruption.
- Location and profession risk: state requirements, local activity, regulated services, and work across jurisdictions.
02
Treat coverage categories as investigation prompts
The SBA lists common business coverage categories, but names, definitions, exclusions, limits, endorsements, and legal requirements vary by policy and location.
U.S. federal orientation
| Category to investigate | Questions it may help frame | Important boundary |
|---|---|---|
| General liability | Third-party bodily injury, property damage, advertising or premises-related allegations. | It may not address professional service errors or every contractual promise. |
| Professional liability or errors and omissions | Claims alleging a professional service error, omission, or failure. | Covered services, claims timing, exclusions, and defense terms matter. |
| Cyber or data coverage | First-party response costs and third-party claims connected to security or privacy events. | Policy triggers, vendor events, social engineering, notification, and security conditions differ. |
| Commercial property or home-business coverage | Equipment, records, inventory, or business property at named locations or in transit. | Personal policies may limit business property or activity; confirm rather than assume. |
| Business owner package | A combined set of common property and liability coverages. | A package does not automatically include every professional or cyber exposure. |
| People-related coverage | Workers' compensation, disability, unemployment, or other employee-related requirements. | Requirements depend on people, classification, work, and jurisdiction. |
03
Separate legal, client, and risk decisions
A policy may be legally required, contractually required by a client, required by a landlord or platform, or voluntarily chosen for a risk. Those are different reasons.
State and local follow-up
| Source | What to verify | Evidence to retain |
|---|---|---|
| Law or regulator | Which rule applies to the location, activity, profession, employees, or vehicles? | Current official page, advice, registration, and policy record. |
| Client contract | Type, limit, duration, territory, additional insured, waiver, notice, or certificate terms. | Accepted contract, endorsement, certificate, and correspondence. |
| Property or service provider | Lease, financing, platform, event, or vendor requirement. | Current terms and proof accepted by the requesting party. |
| Business risk choice | Which losses threaten continuity, assets, clients, or personal finances? | Risk assessment, quote comparison, policy, and review decision. |
04
Look beyond the policy name and premium
Ask a licensed insurance professional to explain how the proposed policy responds to the work and contract you actually have.
General practice
- Named insured, covered people and entities, covered services, locations, territory, and policy period.
- Occurrence-based or claims-made structure, reporting obligations, retroactive dates, and continuing coverage considerations.
- Limits, deductibles or retentions, sublimits, defense costs, duty to defend, and settlement provisions.
- Exclusions for professional services, cyber events, contractual liability, intellectual property, subcontractors, prior knowledge, or specific industries.
- Security, recordkeeping, notice, cooperation, consent, certificate, or risk-control conditions.
- Cancellation, renewal, audit, revenue or payroll estimates, and changes that must be reported.
05
Do not make insurance the only control
Clear scope, secure systems, backups, change control, acceptance criteria, access limits, incident planning, and qualified advice may reduce uncertainty even when insurance applies.
General practice
- Promise only services, results, security practices, and response times the business can support.
- Minimize sensitive data, restrict access, require multi-factor authentication where available, update systems, and test backups.
- Use written scopes, exclusions, client responsibilities, changes, acceptance, liability, ownership, and incident contacts.
- Verify subcontractors, vendors, and client-required systems before giving them data or access.
- Report incidents, circumstances, claims, and material business changes using the policy's actual instructions.
Connect risk questions to the underlying project controls.
- Protecting client information →Apply data minimization, access, sharing, AI, retention, and incident practices.
- Contracts and terms →Review a redacted clause for ambiguity without treating AI as legal or insurance advice.
06
Bring concrete facts to licensed and legal advisers
An adviser can respond more usefully when given the service description, clients, locations, people, systems, data, property, revenue basis, prior events, and relevant contracts.
General practice
- Ask an insurance professional which exposures are included, excluded, limited, or conditioned and how a claim must be reported.
- Ask an attorney to review insurance, indemnity, defense, liability, security, and notice clauses that materially affect the deal.
- Ask a tax or accounting professional how premiums, reimbursements, claims, and business structure interact with the records.
- Revisit the analysis when services, clients, locations, employees, subcontractors, systems, data, or contract promises change.
Source register
Official starting points for this guide
Reviewed September 22, 2026. These are federal starting points, not a substitute for state, local, profession-specific, contract, or current-year review.
- SBA: Launch your business ↗U.S. federal. Supports business structure questions, state registration lookup, licenses and permits, insurance investigation.
- FTC: Cybersecurity for small business ↗U.S. federal. Supports data protection, multi-factor authentication, vendor access, incident response and backups.
- FTC: Start with Security ↗U.S. federal. Supports data minimization, need-to-know access, secure lifecycle, retention and disposal.
Keep going
Connect administration to the actual project
Freelancer pathway
Build a clear freelance process
Connect business administration with service definition, discovery, agreements, delivery, invoicing, and close-out.
Client pathway
Prepare and manage a freelance hire
Connect vendor administration with a usable brief, fair selection, project management, acceptance, and handoff.
Information security
Protect client information
Turn cyber and privacy exposure into concrete collection, access, sharing, retention, and response practices.
Agreements
Work directly with clients
Connect risk allocation with discovery, scope, payment, communication, changes, and close-out.