Call Centre and Contact Centre Insurance
A contact centre is a simple business with one concentrated risk: a large number of people in one building, handling other people's customers and other people's data.
Volume Is The Risk
The property side is unremarkable. The exposure that matters is that you are processing personal information at volume, frequently including payment details, for clients whose own regulators and customers will ask questions if it goes wrong. A single misconfigured recording system or one compromised account reaches thousands of records rather than one.
The second feature is continuity. A centre that cannot take calls is not inconvenienced, it has stopped trading, and so has the part of the client's business that depends on it. Contracts frequently contain service levels that treat an outage as your failure regardless of cause.
What Call Centre Insurance Covers
Cyber and data breach, at volume
The core exposure. You process personal data and frequently card details for many thousands of individuals who are your client's customers rather than yours, and the cost of a breach scales with the number of records.
Professional indemnity
Where your handling of a client's customers caused them loss: wrong advice given on a call, a complaint mishandled, a regulated script departed from. Mechanics on our professional indemnity page.
Business interruption
Arguably more important than the property cover. A centre that cannot take calls has stopped, and so has part of the client's operation. The indemnity period should reflect re-establishing a floor and a telephony platform rather than drying out a building.
Contents, telephony and IT
Workstations, headsets, servers and the platform, which is frequently the most valuable and least replaceable thing in the building.
Employers' liability
Compulsory at a £5 million statutory minimum. A large workforce in one building, with upper limb and voice disorders, stress and display screen exposures rather than physical hazards.
Employment practices liability
High headcount, high turnover and performance management at scale make tribunal claims a frequency exposure rather than an occasional one.
Public liability
Visitors and client audits on site, and modest beside the rest, though clients frequently require evidence of it before awarding work.
Where The Cover Stops
Wordings differ between insurers, so treat these as the usual position rather than as universal fact. Where one of them matters to you, it is worth checking on your own schedule before you need to.
Breach costs scale with records
Notification, credit monitoring, forensic investigation and legal costs are driven by the number of individuals affected, not by the size of your business. A modest cyber limit on a centre holding millions of records is nominal.
Card data and PCI exposure
Taking payments over the phone brings card industry obligations, and fines or assessments following a breach are frequently treated differently from other costs or excluded.
Service level penalties
Contractual penalties for missed answer times or availability are commercial terms rather than insured losses, even where the cause was an insured event.
Regulated activity for clients
Handling calls for financial services, insurance or utilities clients can bring their regulatory regime into your operation, including script compliance and vulnerable customer handling.
Homeworking agents
Data and security exposures move into employees' homes, and a policy written around a single secure building may not contemplate that.
Call recordings
Recordings are personal data, often include card details spoken aloud, and are retained in volume. They are frequently the most sensitive thing the business holds.
The Breach Is Priced By Record Count
The thing that makes a contact centre an unusual insurance risk is that the size of a loss has almost no relationship to the size of the business.
A centre with two hundred seats might hold records for several million individuals across its client base. If a system is misconfigured, an account is compromised or an employee exports a database, the cost is notification, forensic investigation, legal advice, credit monitoring where appropriate, regulatory engagement and the client's own losses, and all of it scales with the number of people affected rather than with your turnover.
So the cyber limit needs to be set against the record count rather than against the balance sheet, which is counter-intuitive and frequently resisted. It is also worth separating the elements: first party response costs, third party liability to the individuals and to your client, and any cover for the client's own consequential loss, because a contract may make you responsible for the last of those in full.
Card Details Spoken Out Loud
Any centre taking payments over the phone carries an exposure that is partly technical and partly cultural, and recordings are where the two meet.
Card numbers read aloud by a customer end up in a call recording unless the system pauses or suppresses them, and a recording archive containing card data is a payment card industry problem rather than merely a data protection one. The obligations are specific, the assessments following a breach are substantial, and policies treat card industry fines differently from other breach costs or exclude them.
Practically there are established answers: pause and resume on recordings, agent-assisted payment where the agent never hears or sees the number, tokenisation, and a clear desk and no-phones policy on the floor. What matters for insurance is being able to describe which of those you have, because an underwriter asking about card handling is deciding whether the record count is the exposure or whether the card data is.
Business Interruption Is The Contract Risk
A fire in a contact centre is not primarily a property loss. It is an inability to answer the phone, and the contracts usually say what that costs.
Service levels on answer times, abandonment rates and availability are standard in outsourcing agreements, frequently with penalties or service credits attached, and they generally do not care why the service failed. Meanwhile your own loss is the revenue from a contract you cannot service and the real possibility that the work moves permanently to another provider during the outage.
Which makes two things worth attention. The indemnity period, set against re-establishing a floor, a telephony platform and trained agents rather than against drying out a building, which is considerably longer than it sounds. And whether you have a tested continuity arrangement, meaning a second site or a genuine homeworking fallback, because clients increasingly ask for it and insurers price it. A centre that moved a floor to homeworking in a day once already can say so.
People Risk At Scale
The employers' liability and employment exposures in a contact centre are not dramatic and they are high frequency, which is a different problem.
The physical claims are upper limb disorders, voice problems, hearing complaints from headset use and display screen issues, all of which develop over time and arrive long after the employee has left. The employment claims come from scale and turnover: performance management across hundreds of agents, absence procedures, shift changes, and occasionally a collective issue rather than an individual one.
So the controls are ordinary and the documentation is everything: workstation assessments, headset and volume management, break structures, documented performance processes applied consistently, and a complaints route. Employment practices liability is worth having rather than optional here, because the frequency is what drives cost and a run of tribunal matters is a management load as much as a financial one.
How To Choose A Broker For A Contact Centre
One number matters more than the rest and it is not your turnover. We are an FCA regulated broker and will not tell you we are the best choice. These are the questions that decide it.
Is the cyber limit set against record count rather than turnover?
Breach costs scale with the number of individuals affected. A modest limit on a centre holding millions of records is nominal, and that is counter-intuitive enough that it gets missed.
How is card data treated?
If you take payments by phone, card industry fines and assessments are frequently excluded or treated separately from other breach costs. Ask directly.
Is the interruption period realistic?
Re-establishing a floor, a telephony platform and trained agents takes considerably longer than drying out a building, and the work may move permanently in the meantime.
Does cover follow homeworking agents?
Data and security exposure moves into employees' homes. A policy written around one secure building may not contemplate it.
Is employment practices liability included?
High headcount and turnover make tribunal claims a frequency exposure rather than an occasional one.
Does the policy reflect regulated work you do for clients?
Handling calls for financial services, insurance or utilities clients brings their regulatory regime into your operation, including script compliance and vulnerable customer handling.
Factually, here is what we do against those questions. We set the cyber limit against the number of records you hold rather than scaling it from turnover, we establish how card data and payment card industry costs are treated before you need to know, we set the interruption period against re-establishing a floor and a platform rather than a building, and we declare homeworking agents rather than leaving the policy written around one site. We are a broker, so it goes to several insurers rather than one.
We also place cyber for professional firms and agencies holding client data, so volume data exposure is familiar ground here rather than an adjacent sector.
What Moves The Price
Every policy is priced on the business behind it. These are the things that move the premium:
- The number of individual records you hold and process
- Whether card payments are taken by phone, and how they are handled
- Seat count and whether agents work from home
- The business interruption indemnity period and gross profit
- Whether you handle regulated activity for clients
- Telephony and IT platform values
- Headcount, turnover and employment claims history
- Continuity arrangements, including a second site
We are a broker, so we take it to several insurers rather than quoting one. Call 02382 000820 for a quote.
What We Need To Quote
- Seat count, and the split between office and homeworking
- The approximate number of individual records held
- Whether card payments are taken, and how recordings handle them
- The sectors your clients operate in, and any regulated work
- Telephony and IT platform replacement values
- Gross profit and a realistic indemnity period
- Continuity arrangements and whether they have been tested
- Any data incidents, claims or tribunal matters in five years
Cover that often goes with this
The gaps we most often find sitting next to this policy.
- Cyber insuranceVolume data, card details and recordings.
- Business interruptionA floor and a platform, not a building.
- Recruitment agenciesWhere the agents come from, and the same employment exposures.
- IT consultantsThe systems and telephony behind the operation.
- Employers' liabilityUpper limb, voice and display screen claims at scale.
- Talk to a brokerTell us how many records you hold, not your turnover.
Common questions
What insurance does a call centre need?+
Cyber and data breach cover first, at a limit set against the number of records you hold rather than your turnover, because breach costs scale with the number of individuals affected. Business interruption with an indemnity period reflecting re-establishing a floor, a telephony platform and trained agents. Contents, telephony and IT. Employers' liability at a £5 million statutory minimum, with upper limb, voice and display screen exposures rather than physical hazards. Then employment practices liability, since headcount and turnover make tribunal claims a frequency exposure, and professional indemnity where your handling caused a client loss.
How much cyber cover does a contact centre need?+
More than the size of the business suggests, which is the counter-intuitive part. A centre with a couple of hundred seats might hold records for several million individuals across its client base, and if a system is misconfigured or an account compromised the cost is notification, forensic investigation, legal advice, regulatory engagement and the client's own losses, all scaling with the number of people affected rather than with your revenue. Set the limit against the record count, and separate the elements: your own response costs, liability to individuals and to your client, and whether the client's consequential loss falls to you under contract.
What happens to card details taken over the phone?+
They end up in your call recordings unless the system pauses or suppresses them, and a recording archive containing card data is a payment card industry problem as well as a data protection one. The obligations are specific and the assessments following a breach are substantial, and policies frequently exclude card industry fines or treat them differently from other breach costs, so ask directly. The established answers are pause and resume on recordings, agent-assisted payment where the agent never hears the number, tokenisation, and a clear desk policy. Be able to describe which you have, because an underwriter will ask.
Are service level penalties covered if we cannot take calls?+
Generally not. Service credits and penalties for missed answer times or availability are commercial terms in your outsourcing contract rather than insured losses, and they usually do not care why the service failed. What insurance addresses is your own loss: the revenue from a contract you cannot service while the centre is out, which is what business interruption is for. The risk beyond that is commercial rather than insurable, because work moved to another provider during an outage may not come back, which is why a tested continuity arrangement matters more here than in most sectors.
Does our insurance cover agents working from home?+
Only if it was declared, and this catches centres that moved to hybrid and never told the insurer. Homeworking moves the data and security exposure into employees' homes: unsecured networks, household members in earshot of calls containing personal or card data, devices outside your physical control, and paper where there should be none. A policy written around a single secure building may not contemplate any of it. Declare the split and describe the controls, because a centre that can explain its homeworking security presents very differently from one that has simply sent people home.
Who insures call and contact centres in the UK?+
It is placed as a combined office and cyber risk, and the market is reasonably available, though appetite narrows where card data is handled at volume or where clients operate in regulated sectors. What separates placements is whether the cyber limit reflects record count rather than turnover, how card industry costs are treated, whether the interruption period reflects rebuilding an operation rather than a building, and whether homeworking has been declared. Price rarely decides whether a breach claim is adequately covered.
More food, drink and leisure we cover
What our customers say on Google
5.0average from 169 Google reviews
