You signed off the release, so you own what got through
Your job is to catch what shouldn't ship. When a defect makes it past your test cycle and costs the client real money, nobody's asking who wrote the bug. They're asking whether reasonable testing should have caught it. Professional indemnity cover, built for QA and testing work.
Where a QA tester actually gets exposed
Your risk sits with the sign-off, not the bug itself. If a client can argue your testing was negligent or incomplete, and a defect that should have been caught reached production, that's a professional indemnity claim. Standard business cover won't answer it.
The payment bug that passed sign-off
You test and sign off a release for a client's e-commerce platform. A calculation error in the checkout ships to production anyway, undercharging thousands of orders before it's caught.
The client seeks the cost of the shortfall and argues your test cycle should have caught it.
The regression nobody caught
An automated test suite you built and maintain should have flagged a regression introduced late in a release cycle. It doesn't, and the client's release goes out broken.
The client argues the automation gap is on you, and seeks the cost of the outage and the fix.
The production data used in a test environment
To reproduce a hard-to-catch bug, real customer data is copied from production into a test environment you manage. The test environment is less secured, and the data is exposed.
Under the Privacy Act the client has to notify everyone affected, and they say the data never should have left production that way.
Who's going to ask you for it
It's how you get engaged for release sign-off
For QA and testing professionals, cover is often tied to the trust placed in your sign-off:
- Recruitment and consulting agencies won't place QA contractors without a current certificate of currency.
- Enterprise release-management processes require named sign-off with insurance behind it.
- Subcontracts under larger development or consulting firms flow their own insurance requirements down.
The exclusion QA testers assume is covered
"I only test, I don't write the code" doesn't remove the exposure. The claim was never that you caused the bug. It's that reasonable testing would have caught it before it shipped, and that's still a professional indemnity claim.
Separately, scope cuts only defend you if they're documented. An informal decision to skip certain test coverage that was never written down often won't hold up in a dispute.
Common questions
I only test, I don't write the code that failed. Am I really at risk?
Yes. A negligence claim against a tester comes down to whether reasonable testing would have caught the defect before release, not who wrote it. That's exactly the risk professional indemnity cover responds to.
Isn't this just professional indemnity?
PI is the core cover for testing and sign-off negligence. If you also handle production or customer data in test environments, cyber exposure applies too. ICT cover carries both.
What limit should I get?
Take it from your engagement terms or the agency's placement requirement, commonly $1M–$5M. If you're unsure, we'll read it with you before you buy.
An agency needs a certificate of currency before I start, how fast?
Once bound, a certificate is quick to issue. If a placement is waiting on it, tell us and we'll prioritise it.
Does it cover a release I tested before I was insured?
Professional indemnity is claims-made and usually responds to claims first made while you're insured, provided the issue wasn't already known to you. It's best to have cover in place before a dispute surfaces.