You didn't write a line of code, but the workflow is yours
You connect the platforms that quietly run a client's operations, from invoicing and lead handling to fulfilment. When an integration silently stops working, or an automation with broad access exposes data across systems, the platform vendor has no liability to your client. You do. Professional indemnity and cyber cover, built for no-code and automation work.
Where a no-code consultant actually gets exposed
Your risk is real even though you're not writing code. You're assembling systems that touch payments, customer data and core operations. Standard business insurance doesn't cover a failed automation or a misconfigured integration, and neither does the platform you built it on.
The automation that quietly stopped working
You build a workflow linking a client's payment platform to their CRM. A third-party API changes without warning, and the automation silently fails.
Weeks pass before anyone notices invoices haven't been sent and leads haven't been followed up, and the client seeks the cost of the missed revenue.
The integration with too much access
An automation you configured connects a client's email, CRM and payment platform with broader access scopes than the workflow actually needs. A misconfiguration leaks customer data across the connected systems.
Under the Privacy Act the client has to notify everyone affected, and they say your configuration was the cause.
The workflow nobody could untangle
An undocumented chain of automations you built breaks when one step is edited by someone else on the client's team. Their operations stall while the whole workflow is unpicked and rebuilt.
The client seeks the cost of the disruption and holds you responsible for how the workflow was designed.
Who's going to ask you for it
A smaller but growing requirement
No-code and automation consulting is a newer market, so formal insurance requirements are less common than for traditional development, but they still show up:
- Direct SME clients rarely mandate cover contractually, but the exposure is just as real when a workflow runs their invoicing or fulfilment.
- Agencies subcontracting automation work increasingly flow their own PI requirements down.
- Clients with existing compliance obligations (handling health, financial or other sensitive data) may require proof of cover before connecting their systems to yours.
The exclusion no-code consultants assume is covered
The most common trap is assuming "I didn't write any code, so I'm not really a tech risk" and skipping cover altogether. The platform vendor has zero liability to your client for how you configured their tool. That responsibility sits with you, the consultant who designed and connected the workflow.
A silent failure you were already warned about and hadn't fixed is also typically excluded.
Common questions
I don't write code, do I really need this?
Yes. The tools you connect have no liability to your client for how you configured them, so all of the responsibility for a failed or misconfigured workflow sits with you, the same as it would for a developer.
Isn't this just professional indemnity?
PI is the core, but no-code automations typically connect multiple systems through broad access scopes, so cyber exposure can be larger than for a single app. ICT cover combines professional indemnity with cyber so there isn't a gap between policies.
What limit should I get?
For most direct client work, $1M–$2M is typical. If you're subcontracted under an agency or working with a client that has compliance obligations, check their requirement before you buy.
Does it cover a workflow I built before I was insured?
Professional indemnity is claims-made and usually responds to claims first made while you're insured, provided the issue wasn't already known to you. It's best to have cover in place before a dispute surfaces.
An agency needs a certificate of currency, how fast can I get one?
Once bound, a certificate is quick to issue. If a project is waiting on it, tell us and we'll prioritise it.