cuttleflow
Commons
Meridian Commons · Technology Liability

Comprehensive Technology Liability Insurance

Combined technology professional and product liability, with cyber and general-liability layers.

About This Policy

This policy is designed to cover technology companies for the three main liability risks they face: professional liability for technology products and services, cyber and data security risks, and public and products liability. We have combined these into one policy because technology risks don't fit neatly into separate boxes — a single event can trigger all three.

Status of this document: this is a DRAFT wording, subject to legal review by Cuttleflow's Wording Partner. It must not be issued, bound, quoted from, or relied upon as a policy of insurance until that review is complete and the DRAFT marking is removed.

Distribution posture: this wording is drafted on the assumption of wholesale distribution to business insureds through an authorised intermediary. Where a prospective insured meets the retail client test in section 761G of the Corporations Act 2001 (Cth) and regulation 7.1.11, the issuing agency must prepare and provide a Product Disclosure Statement and Target Market Determination before use, and must not rely on this wording's wholesale-distribution drafting assumption.

Notice under section 40(1) of the Insurance Contracts Act 1984 (Cth): Sections 1 and 2 of this policy are issued on a claims-made basis — they cover claims first made against you and notified to us during the policy period. Section 40(3) of the Act provides that, where you become aware of facts that might give rise to a claim and give us written notice of those facts as soon as reasonably practicable and before this policy expires, we may not refuse to pay a later claim arising from those facts only because it is made after the policy has ended. You should be aware that this policy may not cover a claim first made after it expires unless that notification has been given.

This policy has three operative sections. Your schedule shows which sections apply to you:

Section What it covers Trigger
Section 1 — Technology Professional Liability Claims arising from your technology products and services Claims-made
Section 2 — Cyber Protection Data breaches, cyber attacks, business interruption, extortion, regulatory proceedings Claims-made / Discovery
Section 3 — Public and Products Liability Bodily injury and property damage from your business operations and technology products Occurrence

If "Not Included" is shown in the schedule against any section, that section and all references to it are deleted.

This policy, together with your schedule and any endorsements, forms your contract of insurance. Words shown in bold have special meanings — see the Definitions. Your schedule also states, among other things, your retroactive date, continuity date, limits of liability, retentions, sub-limits, waiting periods, indemnity periods and extended reporting period, and the other schedule variables this wording refers to.

Definitions

Core Definitions (All Sections)

Business The provision of technology products and technology services and includes: (a) ownership, tenancy, maintenance, and repair of real property; (b) the giving of first aid or emergency assistance by you or your workers; (c) fire and security services for the protection of your own premises.
Claim (a) any writ, summons, cross-claim, or other legal proceeding issued against you; (b) any written demand for compensation; (c) with respect to Section 2 only, any regulatory proceeding against you.
Client A person or organisation that has contracted with you to purchase, distribute, or use technology products or technology services. Client does not include any contractor or sub-contractor.
Computer system Any computer, hardware, software, communications system, electronic device, server, cloud platform, or microcontroller — including any configuration of these and any operational technology, input/output devices, data storage, networking equipment, or backup facilities.
Continuity date means the date shown in the schedule from which you have been continuously and without interruption insured for the risk covered by this policy, whether by us or, where the schedule shows a predecessor insurer, by that insurer. Continuity date is distinct from Retroactive date and performs a different function: retroactive date fixes how far back covered acts, errors, omissions or events may reach; continuity date evidences unbroken prior cover for the purposes of the Continuous Cover extension (Section 4.3) and the Prior or Pending exclusion (Section 5.25). The schedule contains separate fields for each. Continuity date is relevant wherever Section 4.3 applies — Sections 1 and 2 and the Cyber Liability Extension of Section 3.
Cyber loss means any amount we pay, or agree to pay, under Section 2, including business interruption loss, breach response costs, extortion payments, data restoration costs, hardware replacement costs, loss under the Reputational Harm extension, and reimbursement under the Cyber Crime extension (Section 2.9). Cyber loss arises only under Section 2. For the avoidance of doubt, an amount payable under the Cyber Liability Extension of Section 3 (3.3) for personal injury or property damage is loss, not cyber loss, because that extension responds under Section 3's occurrence trigger. Cyber loss is referred to in the exclusions (Section 05), the notification condition (Section 6.1), the aggregation condition (Section 6.4), and the limits and retention provisions (Section 7.1, Section 7.3) — each of which applies to Section 2 only in respect of cyber loss.
Damages (a) any amount you are legally liable to pay to a third party as compensation arising from a judgment, including awards of the third party's legal costs; or (b) any reasonable settlement paid to a third party with our consent.
Defence costs The reasonable legal costs and expenses incurred with our prior written consent in investigating, defending, settling, or appealing a claim. Defence costs do not include your overheads or any salaries, wages, or benefits of insured persons.
Employee (a) any natural person employed under a contract of service with you; (b) any contractor or consultant acting under a written contract for the provision of technology products or technology services solely for and on behalf of you.
Executive officer Any partner, principal, director, CEO, CFO, COO, CIO, CISO, general counsel, or equivalent position.
Final adjudication means: (a) a judgment, verdict, or determination of a court or tribunal of competent jurisdiction in respect of which all rights of appeal have been exhausted, or the time to appeal has expired without an appeal being filed; or (b) a formal written admission, or a consent order or settlement in which the insured person concerned admits, the conduct described in Section 5.8. Final adjudication is relevant to all sections, wherever conduct described in Section 5.8 is in issue.
Insured (a) you and any subsidiary; and (b) any insured person.
Insured person Any executive officer or employee.
Joint venture means any incorporated or unincorporated arrangement, however structured, between you and one or more other parties to jointly carry on a business activity, in which you hold a stated percentage interest, share of profits or losses, or degree of control. Joint venture is relevant wherever the term is used in this policy (currently Section 4.8, all sections).
Limit of liability The amount shown for each section in the schedule.
Loss (a) damages; (b) defence costs; (c) court attendance costs; (d) inquiry costs; (e) regulatory penalties (where specifically covered under an extension or insuring agreement); (f) claim prevention costs. Loss does not include: (a) taxes; (b) costs under a merchant services agreement; (c) restitution, disgorgement, or unjust enrichment; (d) punitive, aggravated, exemplary, or liquidated damages; (e) costs of complying with injunctive or non-monetary relief; (f) your overheads, staff time, or internal costs; (g) your fees or commissions; (h) amounts uninsurable under the law governing this policy. Loss does not include cyber loss (as defined), which is a separate, Section 2-specific concept.
Named insured The entity shown as such in the schedule.
Operational technology Hardware, software, or equipment used to control physical devices and processes (including SCADA systems) — but not the physical devices or processes being controlled.
Policy period The period shown in the schedule.
Regulatory penalty Any civil penalty or fine imposed by a government or regulatory body that is insurable by law.
Regulatory proceeding A formal investigation, hearing, or proceeding — or a compulsory request, notice, or demand for information, documents, or attendance — commenced or issued by an Australian government or regulatory body acting in its regulatory capacity in relation to privacy, cyber security, or data protection, including under the Privacy Act 1988 (Cth) or the Competition and Consumer Act 2010 (Cth), or by the Office of the Australian Information Commissioner, the Australian Competition and Consumer Commission, or the Australian Securities and Investments Commission.
Retention The amount shown in the schedule that you must bear first.
Retroactive date means the date shown in the schedule. See also Continuity date, a distinct, separately scheduled concept.
Schedule The document issued with this policy showing your specific details.
Subsidiary Any entity of which you: (a) are the sole owner; (b) control the board; (c) control more than half the voting power; or (d) hold more than half the issued share capital — as at the start of the policy period.
Technology product Computer or telecommunications hardware, software, or related electronic components that you create, design, manufacture, distribute, license, lease, or sell — including software updates, service packs, and maintenance releases.
Technology service Any computer, cloud computing, or electronic technology service, including: (a) data processing, SaaS, PaaS, IaaS, NaaS, IoT solutions, AI and machine learning services, blockchain services, API services, data analytics, and business intelligence; (b) data and application hosting, systems analysis, technology consulting, and training; (c) custom software development, systems installation and integration, DevOps and MLOps consulting; (d) management, repair, maintenance, network design, and internet services.
Third party Any entity or person other than: (a) an insured; or (b) any entity or person with a financial interest or executive role in you.
We / us / our The insurer named in the schedule.
You / your (a) the named insured and any subsidiary; and (b) any insured person.

Drafting note (not operative text): the definition of "Approved product" carried in v1.1.0 was an orphan — defined but never used in any operative clause — and has been deleted in this version (see change register, N1). No cover position changes as a result.

Cyber-Specific Definitions (Section 2)

Business interruption loss (a) loss of gross profit; (b) increased costs of working — reasonable and necessary costs incurred, beyond normal operating expenses, to mitigate or reduce the interruption; and (c) forensic expenses — but not third-party liability, legal costs, loss from unfavourable business conditions, or loss of market share.
Control group means your executive officers, together with any person responsible for information security, privacy, or risk management functions within your business or, where you have no formally designated control group, your most senior officer. Control group is relevant to Section 2 only (Section 6.1(b)).
Cyber security breach (a) unauthorised access (as defined) to or use of your computer system; (b) a denial-of-service attack on your computer system; (c) infection of your computer system with malicious code; or (d) transmission of malicious code from your computer system to a third party's systems.
Data breach The theft, loss, unauthorised access, or unauthorised disclosure of any personal information or third-party information in your care, custody, or control.
Extortion threat A credible threat to carry out a cyber security breach or data breach against your computer system unless a ransom demand is met.
Personal information Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not true and whether or not recorded in a material form; this has the same meaning as in section 6 of the Privacy Act 1988 (Cth).
System failure An unintentional and unplanned interruption of your computer system that renders it incapable of carrying out its normal function. System failure does not include any interruption resulting from a cyber security breach.
Technology provider A third party that provides technology services to you under a written contract for hosted application services, or for processing, storing, or hosting your data. Technology provider does not include providers of utilities, telecommunications infrastructure, financial securities, stock exchanges, or clearing houses.
Third-party information Any trade secret, confidential data, or proprietary information of a third party that is not available to the general public.
Unauthorised access means access to, or use of, your computer system that is not permitted by you, and includes access or use that exceeds the scope of access or use you have permitted — whether or not the person accessing or using the system holds valid credentials to do so. This addresses an employee or other person who holds legitimate credentials but exceeds their authorised scope. Unauthorised access is relevant to Section 2 only.
Waiting period The time period stated in the schedule. A business interruption must last longer than the waiting period before any business interruption loss is payable. Once the interruption exceeds the waiting period, business interruption loss is measured from the start of the interruption.

Public Liability Definitions (Section 3)

Occurrence An event that results in personal injury or property damage that you did not expect or intend. Continued or repeated exposure to substantially the same harmful conditions is treated as a single occurrence, taken to happen when that exposure first begins.
Personal injury (a) death, physical injury, sickness, disease or disability; (b) shock, emotional distress or mental anguish; (c) false arrest, wrongful detention or false imprisonment; (d) malicious prosecution; (e) wrongful entry onto, or eviction from, premises; or (f) assault or battery, unless committed by you or with your consent or at your direction.
Property damage (a) physical damage to, or destruction of, tangible property, together with any loss of use of that property; or (b) loss of use of tangible property that has not itself been physically damaged, where that loss of use is caused by physical damage to other tangible property. Property damage does not include loss of, or damage to, data or personal information.
Product injury Personal injury or property damage arising out of a technology product or technology service.

01 Technology Professional Liability

This section operates on a claims-made and notified basis.

1.1 Insuring Agreement

If a claim is first made against you during the policy period and arises solely from the provision of technology products or technology services, we will pay your loss.

1.2 Insuring Agreement Clarifications

Without limiting the insuring agreement, we confirm that cover includes claims arising from:

Artificial intelligence: The use of any artificial intelligence or machine learning software in the provision of technology products or technology services — including claims arising from AI model output errors, algorithmic bias, autonomous decision-making, and training data used in connection with your services.

Consumer protection legislation: Claims under the Australian Consumer Law, the Competition and Consumer Act 2010 (Cth), or equivalent state/territory legislation.

Loss of documents: Unintentional destruction, damage, misplacement, deletion, or loss of documents in your custody or control.

Vicarious liability: Claims arising from technology products or services provided by another person on your behalf.

Former subsidiaries: Claims arising from technology products or services provided by a subsidiary before its acquisition by another entity.

1.3 Extensions — Section 1 Only

Outstanding Fees: Notwithstanding the fees exclusion, we will pay your contractually agreed fees (excluding profit and GST) that a client refuses to pay — provided: (a) there is written evidence of the client's refusal and intention to make a claim; (b) you have made all reasonable efforts to recover; (c) you will cease recovery efforts; (d) payment is reasonably likely to resolve any existing or potential claim. Sub-limit: as shown in the schedule.

Refund of Fees: Notwithstanding the fees exclusion, we will pay any refund-of-fees component of damages.

Mitigation Costs: We will pay claim prevention costs — reasonable direct costs to prevent, rectify, or mitigate a potential claim you first become aware of during the policy period. You must obtain our written consent first, unless delay would jeopardise mitigation. Sub-limit: as shown in the schedule.

Patents: Notwithstanding the media liability exclusion, we will cover claims for unintentional breach of any patent arising from your technology products or technology services — but only patents registered outside the USA and Canada. Sub-limit: as shown in the schedule.

Regulatory Penalties: We will pay insurable regulatory penalties arising from a claim or inquiry in connection with your technology products or technology services. Sub-limit: as shown in the schedule.

02 Cyber Protection

This section operates on a claims-made / discovery basis.

2.1 Breach Response and Notification

We will pay reasonable and necessary breach response costs you incur following first discovery of an actual or suspected data breach or cyber security breach during the policy period, including: (a) forensic investigation; (b) legal advice on notification obligations; (c) notification to affected individuals and regulators; (d) credit monitoring for up to 12 months; (e) call centre; (f) crisis management.

You may appoint the incident response panel shown in the schedule and incur costs without our prior consent for up to 72 hours following first discovery.

2.2 Data Restoration

We will pay reasonable costs to determine whether damaged or destroyed software or personal information or other data can be restored, and to restore it to substantially the same state as immediately before a cyber security breach.

2.3 Business Interruption

We will reimburse business interruption loss you incur within the indemnity period shown in the schedule (or, if not shown, 180 days maximum) as a result of: (a) a cyber security breach; or (b) a dependent security breach (an attack on your technology provider's systems). Sub-limit for (b): as shown in the schedule.

Waiting period — threshold basis. The waiting period operates as a qualifying threshold, not a deduction. If the interruption lasts longer than the waiting period, business interruption loss is measured from the start of the interruption. If the interruption does not exceed the waiting period, no payment is made.

2.4 System Failure Business Interruption

We will reimburse business interruption loss from: (a) a system failure (your own systems); or (b) a dependent system failure (your technology provider's systems) — subject to the same indemnity period and waiting period (threshold basis) as Section 2.3. Sub-limit for (b): as shown in the schedule.

2.5 Cyber Extortion

We will reimburse reasonable costs to deal with, contain, mitigate, or pay a ransom demand in connection with an extortion threat first discovered during the policy period.

2.6 Data and System Security Liability

We will pay your loss from a claim arising from: (a) a data breach; or (b) a cyber security breach.

2.7 Regulatory Defence and Fines

We will pay your defence costs and any insurable regulatory penalty arising from a regulatory proceeding first brought against you during the policy period in connection with a data breach.

2.8 PCI DSS Liability

We will pay PCI DSS fines you are liable to pay and reasonable legal costs in dealing with a PCI DSS investigation arising from a data breach.

2.9 Extensions — Section 2 Only

Hardware Replacement: Reasonable costs to replace hardware that cannot function due to corruption or destruction of software/firmware from a cyber security breach. Does not include operational technology. Sub-limit: as shown in the schedule.

Reputational Harm: Loss of gross profit within the indemnity period resulting from reputational damage caused by a public allegation that you failed to prevent a cyber security breach or data breach. Sub-limit: as shown in the schedule.

Cyber Crime: Reimbursement for direct financial loss from: (a) unauthorised electronic funds transfer; (b) unauthorised invoice manipulation; (c) impersonation-based requests for transfer of money, securities, data, or property. Sub-limit: as shown in the schedule.

Underwriting note (not operative text): funds-transfer fraud and impersonation-based cover of this kind is conventionally sub-limited well below the Section 2 aggregate limit across the Australian cyber market. The schedule default for the Cyber Crime sub-limit should reflect that market practice; setting the actual figure is an underwriting decision outside the scope of this remediation (see change register, M5).

03 Public and Products Liability

This section operates on an occurrence basis.

3.1 Public Liability

We will pay your loss from a claim for personal injury or property damage (excluding product injury) that first happens during the policy period and is caused by an occurrence in connection with your business.

3.2 Products Liability

We will pay your loss from a claim for product injury that first happens during the policy period and is caused by an occurrence in connection with your business.

3.3 Extensions — Section 3 Only

Product Recall Expenses: Notwithstanding the product recall exclusion, we will pay reasonable recall costs where technology products have caused or are reasonably likely to cause personal injury or property damage due to: (a) the accidental omission of a component during manufacture; (b) the accidental inclusion of a harmful or contaminating substance; (c) an accidental labelling error; or (d) any other defect arising in design or manufacture. Sub-limit: as shown in the schedule.

Third-Party Indemnities: We will indemnify parties to whom you provide technology products/services, lessors of equipment or premises, and vendors — where you have contractually agreed to indemnify them, and we would have been liable if the same claim had been made against you.

Physical and Legal Control: Notwithstanding the property-in-control exclusion, we cover property damage to: (a) premises you lease or rent, and their contents; (b) premises you temporarily occupy to carry out work; (c) the personal property of your insured persons; (d) vehicles left in a car park you operate, other than a car park you run for a fee; or (e) other property temporarily in your physical control, sub-limited as shown in the schedule.

Harm Response Expenses: Reasonable costs for first aid, making property safe, communications to prevent further injury/damage, and additional staff costs — incurred during the policy period as a result of a covered occurrence.

Cross Liability: Each insured is treated as a separate entity. Does not increase the limit of liability.

Cyber Liability: Notwithstanding the cyber exclusion, we cover personal injury or property damage caused by an occurrence arising from: (a) a cyber security breach; (b) your technology products transmitting malicious code. Sub-limit: as shown in the schedule.

This extension ensures physical harm from a cyber event is covered under the occurrence-based liability section, not the claims-made cyber section — the correct trigger for bodily injury claims. Amounts payable under this extension are loss (Section 3), not cyber loss — see the Cyber loss definition.

04 Extensions Applicable to All Sections

4.1 Advancement of Defence Costs

If you notify us of a claim or inquiry, we will advance defence costs (after erosion of the retention) before we determine whether the policy responds — provided you use a lawyer on our legal panel. You must repay any defence costs later determined, by final adjudication (as defined) or otherwise, not to be covered. Sub-limit: as shown in the schedule.

4.2 Claims Preparation

We will pay the reasonable costs of qualified professionals you retain to produce and certify information supporting your loss claim. Sub-limit: as shown in the schedule.

4.3 Continuous Cover

Applies to Sections 1 and 2 and the Cyber Liability Extension of Section 3 only.

Notwithstanding the prior/pending exclusion, we will cover a claim arising from facts or circumstances that should have been notified before this policy period but were not — provided: (a) you have been continuously insured by us since the facts arose, or you first became aware of them after the continuity date (as defined); (b) your failure to notify was not deliberate or fraudulent; (c) the claim is subject to the terms in force when you first became aware, and our liability is capped at the lower of: (i) the limit of liability in force when you first became aware of the facts or circumstances; and (ii) the limit of liability in force under this policy at the time the claim is made; (d) our liability is reduced to the extent of any prejudice from late notification.

4.4 Contractual Liability

Notwithstanding the contractual liability exclusion, we will cover your liability arising from:

(a) Liquidated damages — provided they are a fair and reasonable estimate of damages at law;

(b) Client indemnities — any indemnity or hold harmless directly relating to your technology products or technology services;

(c) Common law liability — any guarantee, warranty, or liability you would have had without the contract;

(d) Fitness for purpose — any implied warranty or statutory term requiring your products/services to be fit for purpose and meet a standard of quality, safety, or fitness;

(e) PCI DSS — (Section 2 only) liability from a data breach or cyber security breach under a PCI DSS agreement;

(f) Lease agreements — (Section 3 only) provisions in a lease for real or personal property.

Items (a) to (c) require the agreement to be in a written contract signed before the claim was made. Item (d) is not subject to that requirement — the fitness-for-purpose write-back is deliberately excluded from the written-contract proviso because the underlying consumer guarantees are non-excludable by contract form under the Australian Consumer Law / Competition and Consumer Act 2010 (Cth); preserved on remediation.

WORKED EXAMPLE — CONTRACTUAL LIABILITY. You provide cloud hosting services to a client. Your contract includes a service level agreement (SLA) with a 99.9% uptime guarantee and liquidated damages of $5,000 per hour of downtime exceeding the SLA threshold. Your systems suffer an unplanned outage of 48 hours due to a software bug. The client claims $240,000 in liquidated damages under the SLA. This policy covers the liquidated damages claim under extension 4.4(a) — provided the $5,000/hour rate was a fair and reasonable estimate of the client's likely loss when the contract was signed. If the rate was a genuine pre-estimate (not a penalty), it's covered. If it was punitive, it's not.

4.5 Court Attendance Costs

We will pay the amounts shown in the schedule per day for each insured person who attends court as a witness in a covered claim or inquiry. No retention applies.

4.6 Extended Reporting Period

Applies to Sections 1 and 2 only.

If this policy expires without being renewed or replaced, or is cancelled by you or by us, we will automatically cover claims first made within the automatic extended reporting period shown in the schedule (or, if not shown, 90 days) after the date of expiry or cancellation — provided the claim arises from acts before that date. This benefit ceases if you obtain replacement cover. A longer extended reporting period may be purchased by endorsement, for the period and additional premium shown in the schedule.

4.7 Inquiry Costs

We will pay your reasonable legal costs to respond to or attend any inquiry (investigation, examination, or inquiry by a body with legal authority) where you are first served during the policy period. Does not include routine supervision, compliance audits, or industry-wide inquiries. Sub-limit: as shown in the schedule.

4.8 Joint Venture Liability

We will cover claims arising from your participation in a joint venture (as defined) that provides the same technology products or technology services as you — provided the joint venture was disclosed to us before inception. Cover is limited to your stated percentage interest or share of the joint venture. No cover for joint venture partners.

4.9 Media and Advertising Liability

Notwithstanding the media liability exclusion, we will cover claims for unintentional: (a) defamation; (b) plagiarism; (c) copyright infringement or trademark dilution; (d) improper deep-linking, framing, or web scraping; (e) violation of privacy rights — arising from your technology products, technology services, advertising, a data breach, or a cyber security breach. Sub-limit: as shown in the schedule.

4.10 Newly Created or Acquired Subsidiaries

We will cover new subsidiaries created or acquired during the policy period — provided their revenue does not exceed 15% of yours. Retroactive date is the date of acquisition. Must provide the same technology products/services as you.

4.11 Public Relations Expenses

Reasonable costs of a PR consultant to protect your reputation following a covered claim or an allegation likely to result in a covered claim. Sub-limit: as shown in the schedule.

4.12 Run-Off

Applies to Sections 1 and 2 only.

If you cease to exist, operate, or are acquired, this policy continues to expiry — but only for claims arising from technology products/services provided before the cessation or acquisition. This extension is subject to, and does not limit, Section 7.6 (Mergers and Consolidations); where the same event triggers both provisions, Section 7.6 governs the scope of continued cover for Sections 1 and 2.

4.13 Severability / Non-Imputation / Innocent Non-Disclosure

Where one insured person failed to disclose or made a misrepresentation, this does not prejudice any other insured person who was not aware of the failure. The conduct of any executive officer is imputed to the entity.

05 What Is Not Covered

Exclusion Applicability Matrix

Not all exclusions apply to all sections. Use this table to check which exclusions apply to your sections. "Yes" means the exclusion applies; "No" means it does not. Numbered notes appear below the table.

Exclusion S1 (PI) S2 (Cyber) S3 (GL)
5.1 Advertising liability Yes Yes Yes
5.2 Aircraft and watercraft Yes Yes Yes
5.3 Asbestos and silica Yes Yes Yes
5.4 Anti-competitive conduct Yes Yes (1) Yes
5.5 Betterment No Yes Yes (2)
5.6 Commercial decisions Yes No No
5.7 Communicable disease No No Yes
5.8 Conduct (fraud/dishonesty) Yes Yes Yes
5.9 Construction No No Yes
5.10 Contractual liability Yes (3) Yes (3) Yes (3)
5.11 Cyber and data No No Yes (4)
5.12 Directors and officers Yes Yes No
5.13 Employers liability Yes Yes Yes
5.14 Fees or charges Yes (5) Yes Yes
5.15 Fines and penalties Yes (6) Yes (6) Yes
5.16 Force majeure Yes Yes No
5.17 Infrastructure failure No Yes No
5.18 Jurisdictional limits (US/Canada) Yes Yes Yes
5.19 Known defect Yes No Yes
5.20 Media liability Yes (7) Yes (7) Yes (7)
5.21 Nuclear Yes Yes Yes
5.22 Personal injury and property damage Yes Yes No
5.23 Planned outages No Yes Yes (2)
5.24 Pollution Yes Yes Yes
5.25 Prior or pending Yes Yes Yes
5.26 Product defect/recall/repair Yes Yes Yes
5.27 Property in your control No No Yes
5.28 Related entities Yes Yes Yes
5.29 Retroactive date Yes Yes No
5.30 Sanctions Yes Yes Yes
5.31 Securities law Yes Yes Yes
5.32 Terrorism Yes No Yes
5.33 Trading debts Yes Yes Yes
5.34 Unsolicited communications Yes Yes Yes
5.35 Vehicles No No Yes
5.36 War and state cyber operations Yes Yes Yes
5.37 Wear and tear No Yes Yes (2)
5.38 Wrongful data collection Yes Yes Yes (2)

Notes to the matrix:

(1) Does not apply to consumer privacy laws covered under Section 2.6 (Data and System Security Liability).

(2) Cyber Liability Extension of Section 3 only.

(3) Subject to the Contractual Liability Extension write-back (Section 4.4).

(4) Subject to the Cyber Liability Extension write-back (Section 3.3).

(5) Subject to the Outstanding Fees and Refund of Fees write-backs (Section 1.3).

(6) Subject to the Regulatory Penalties Extension (Section 1.3) and Regulatory Defence and Fines (Section 2.7) write-backs.

(7) Subject to the Patents Extension (Section 1.3) and Media and Advertising Liability Extension (Section 4.9) write-backs.

The Exclusions

We do not cover any claim, loss, cyber loss, or liability:

5.1 Advertising Liability

Arising from your advertising activities and involving: (a) a breach of contract, except a breach of an implied contract to use another party’s advertising idea; (b) an incorrect statement of the price, or of the description or quality, of goods or services; (c) a failure of goods or services to conform with any quality or performance you advertised; (d) the infringement of a registered trade mark or service mark, except where the mark is used only as a trading name, product name or slogan; or (e) goods or services whose intended function is itself advertising.

5.2 Aircraft and Watercraft

Arising from ownership, maintenance, or operation of any aircraft or watercraft, or technology products/services that affect aircraft or watercraft safety, flight controls, or sailing controls.

5.3 Asbestos and Silica

Arising from the presence or release of asbestos, asbestos-containing materials, or silica in any form.

5.4 Anti-Competitive Conduct

Arising from restraint of trade, anti-competitive practices, price fixing, or tortious interference — including under any competition, consumer, or fair trading legislation. Does not apply to consumer privacy laws covered under Section 2.6 (Data and System Security Liability).

5.5 Betterment

(Section 2 and Cyber Liability Extension only.) Any claim or cyber loss that puts you in a better financial position as a result of a covered event. However, following a covered cyber security breach, we will pay up to the percentage shown in the schedule (or, if not shown, 25%) of the repair/replacement cost toward installing a more secure version of the affected computer system (excluding operational technology).

5.6 Commercial Decisions

(Section 1 only.) Failure to provide technology products/services because you did not have (and could not source) the required technical, logistical, or financial resources when you agreed to provide them.

5.7 Communicable Disease

(Section 3 only.) Highly pathogenic animal influenza in humans, cholera, rabies, any WHO-declared pandemic or epidemic, or any disease listed under the Biosecurity Act 2015 (Cth).

5.8 Conduct (Fraud and Dishonesty)

Arising from any criminal, dishonest, fraudulent, malicious, or deliberately reckless act, or deliberate breach of contract, professional duty, or any law. However, this exclusion only applies once established by final adjudication (as defined); until then, defence costs are advanced under Section 4.1. The conduct of one insured person is not imputed to any other (except executive officers, whose conduct is imputed to the entity — see Section 4.13, which this exclusion is drafted consistently with). If conduct is later established by final adjudication, you must repay all amounts we paid in connection with that conduct.

5.9 Construction

(Section 3 only.) Personal injury or property damage from land development, erection, demolition, alteration, or addition to buildings, structures, or engineering works.

5.10 Contractual Liability

Arising from any liability assumed under a contract, agreement, guarantee, indemnity, or warranty. Subject to the Contractual Liability Extension (Section 4.4) which writes back substantial cover.

5.11 Cyber and Data

(Section 3 only.) Arising from any cyber security breach or data breach. Subject to the Cyber Liability Extension (Section 3.3) which writes back cover for bodily injury and property damage caused by cyber events.

5.12 Directors and Officers

Arising from acting as a director or officer of any entity or as a superannuation trustee. Does not apply to Section 3.

5.13 Employers Liability

Arising from: (a) injury to any insured person under workers' compensation or similar legislation; (b) damage to insured person property in the course of employment; (c) breach of employment practices (unless arising from a data breach or cyber security breach covered under Section 2).

5.14 Fees or Charges

Unpaid fees or refund of professional fees, charges, commissions, or other remuneration. Subject to the Outstanding Fees and Refund of Fees Extensions (Section 1.3).

5.15 Fines and Penalties

Punitive, aggravated, or exemplary damages, fines, penalties, or service credits, to the extent uninsurable at law. Subject to the Regulatory Penalties Extension (Section 1.3) and Regulatory Defence and Fines (Section 2.7).

5.16 Natural Perils and Physical Events

(Sections 1 and 2 only.) Fire, smoke, explosion, solar flare, lightning, wind, water, flood, earthquake, volcanic eruption, tsunami, landslide, tornado, hail, or any other natural physical event.

5.17 Infrastructure Failure

(Section 2 only.) Failure of financial securities, stock exchanges, utilities, telecommunications, internet, satellite, or mechanical infrastructure not under your operational control.

5.18 Jurisdictional Limits

Any claim or inquiry brought within, or to enforce a judgment from, the United States or Canada (including territories).

5.19 Known Defect

(Sections 1 and 3 only.) Providing technology products/services where you knew or should have known of a defect, deficiency, or inability to fulfil the intended purpose.

5.20 Media Liability

Arising from: (a) breach of any patent; (b) breach of any trade secret (Sections 1 and 3 only); (c) any media liability. Subject to the Patents Extension (Section 1.3) and Media and Advertising Liability Extension (Section 4.9).

IP BOUNDARY AT A GLANCE (guidance only — not operative text; the operative positions are in the clauses cross-referenced below and are unchanged by this note). Patents: excluded, written back for non-US/Canada registrations only (Section 1.3, Patents). Trade secrets: excluded for Sections 1 and 3 (Section 5.20(b)); not excluded for Section 2, so effectively covered there through the Data breach definition. Copyright infringement and trademark dilution: excluded as media liability, written back (Section 4.9). Trademark infringement (other than dilution): excluded (Section 5.1(d)), no write-back. This consolidated statement is provided per audit finding N6; no substantive IP position changes.

5.21 Nuclear

Arising, directly or indirectly, from ionising radiation, or from radioactive contamination originating in nuclear fuel or nuclear waste.

5.22 Personal Injury and Property Damage

(Sections 1 and 2 only.) Personal injury and/or property damage. However, this does not apply to: (a) property damage to your computer system under Section 2; (b) hardware replacement under Section 2.9; (c) emotional distress arising from media liability under the Media and Advertising Liability Extension (Section 4.9).

5.23 Planned Outages

(Section 2 and Cyber Liability Extension only.) Arising from planned or scheduled downtime of your systems or your technology provider's systems. However, this does not apply where you deliberately took systems offline to manage a cyber security breach.

5.24 Pollution

Arising from the discharge, release, or escape of any pollutant, or any remediation thereof. However, in Section 3, this does not apply to sudden, unexpected, and unintended pollution during the policy period.

5.25 Prior or Pending

Arising from: (a) matters disclosed or threatened before the policy period; (b) facts or circumstances previously notified or which you knew might give rise to a claim. Subject to the Continuous Cover Extension (Section 4.3).

5.26 Product Defect, Recall, Repair, and Replacement

(a) Property damage to your own product from a defect; (b) cost of correcting or improving your work; (c) withdrawal, recall, inspection, repair, replacement, or refund of any technology product/service. Subject to the Product Recall Expenses Extension (Section 3.3).

5.27 Property in Your Control

(Section 3 only.) Property damage to property owned by or in your control. Subject to the Physical and Legal Control Extension (Section 3.3).

5.28 Related Entities

Any claim brought by an insured, a parent, successor, or any entity in which an insured or executive officer has an executive or controlling interest.

5.29 Retroactive Date

(Sections 1 and 2 only.) Any act, event, error, or omission before the retroactive date in the schedule.

5.30 Sanctions

Any claim, loss, or cyber loss, to the extent that making a payment or providing a benefit would breach, or expose us to enforcement action under: (a) the Autonomous Sanctions Act 2011 (Cth) or the Charter of the United Nations Act 1945 (Cth); or (b) as a deliberate additional scope choice, any trade or economic sanctions law of the United Nations, the European Union, the United Kingdom, the United States, or Australia.

5.31 Securities Law

Any actual or alleged breach of a law regulating the offering, issue, purchase, or sale of securities, including Chapters 6D (fundraising) and 6CA (continuous disclosure) of the Corporations Act 2001 (Cth), or any comparable law of another jurisdiction.

5.32 Terrorism

(Sections 1 and 3 only.) Any act of terrorism, including any action to control, prevent, or suppress terrorism. Where property damage under Section 3 arises from an incident declared a terrorist incident under the Terrorism Insurance Act 2003 (Cth), that Act's provisions may override this exclusion to the extent it applies to eligible property; this exclusion does not purport to limit the operation of that Act.

5.33 Trading Debts

(a) Trading losses or liabilities; (b) lost electronic fund transfers; (c) face value of over-redeemed coupons/vouchers; (d) theft of money, securities, or cryptocurrency; (e) value of transferred funds or cryptocurrency. Subject to the Cyber Crime Extension (Section 2.9) for Section 2.

5.34 Unsolicited Communications

Breach of the Spam Act 2003 (Cth) or equivalent anti-spam legislation.

5.35 Vehicles

(Section 3 only.) Personal injury or property damage from ownership, maintenance, or use of registered vehicles or vehicles requiring compulsory insurance. However, this does not apply to injury/damage from loading or unloading.

5.36 War and State Cyber Operations

Arising, directly or indirectly, from: (a) war, whether or not war has been declared; (b) the use of a computer system, by or on behalf of a state, to cause harm in the course of war or in its immediate lead-up; or (c) the use of a computer system, by or on behalf of a state, that has a major disabling effect on the essential functions of another state — for example its financial system, its energy or water supply, or its public-health or security capability. Paragraph (c) does not apply, for Section 2 and the Cyber Liability Extension of Section 3, to the direct or indirect effect of such use on your computer system or your technology provider’s systems, provided those systems are not physically located in the state whose essential functions are affected.

What this means in practice: if a state-backed group targets your business specifically, you remain covered — even if the attack is attributed to a government — unless it escalates into a state-level attack on another country’s essential services, or your systems sit in the country under attack.

5.37 Wear and Tear

(Section 2 and Cyber Liability Extension only.) Gradual deterioration or failure of electronic equipment in normal use.

5.38 Wrongful Data Collection

(Sections 1, 2, and Cyber Liability Extension only.) Unauthorised or wrongful collection, storage, transfer, or sharing of personal information, including internet search history and browsing habits.

06 Claims Conditions

6.1 Notification

(a) Section 1 (claims-made): tell us in writing as soon as you become aware of a claim or inquiry. You may also notify us in writing, during the policy period, of specific facts or circumstances that may give rise to a claim, giving full particulars known to you. A notification under this paragraph is a notification of facts under section 40(3) of the Insurance Contracts Act 1984 (Cth).

(b) Section 2 (claims-made / discovery): if any member of your control group (as defined) becomes aware of a claim, cyber loss, or any circumstance that may give rise to a claim or cyber loss, you must notify: (i) the incident response panel shown in the schedule; and (ii) us — as soon as reasonably practicable during the policy period. A notification of circumstances under this paragraph is also a notification of facts under section 40(3) of the Act.

(c) Section 3 (occurrence): tell us in writing as soon as you become aware of a claim, inquiry, or loss.

6.2 Defence and Settlement

We may: (a) instruct you to conduct the defence if we believe the claim will not exceed the retention; (b) take over and conduct the defence or settlement of any claim at any time.

You must not negotiate, settle, admit liability, or incur defence costs without our written consent (which we will not unreasonably withhold).

6.3 Allocation

Where a claim involves both covered and uncovered matters, we will work with you to agree a fair and proper allocation. If we cannot agree, the matter is referred to Senior Counsel (mutually agreed or appointed by the relevant Law Society president) whose opinion is binding. Senior Counsel's costs are treated as defence costs.

6.4 Related Claims and Aggregation

Sections 1 and 2 (claims): All claims arising from the same, similar, or related act, error, or omission (or a series of related acts, errors, or omissions) are deemed one claim, made at the time the earliest of them was first made. A claim arising from a circumstance notified under Section 6.1 is deemed to have been made at the time of that notification.

Section 2 (cyber loss): All cyber loss arising from the same, similar, or related act, event, or originating cause is deemed one cyber loss, occurring when first discovered. Where related events span more than one policy period, the entire series is treated as occurring in, and is subject to the limit of liability, retention, and terms of, the policy period in which it was first discovered.

Section 3: All personal injury and property damage from continuous or repeated exposure to the same conditions is deemed one occurrence.

6.5 Senior Counsel Clause

We will not require you to contest any claim unless Senior Counsel advises that the claim should be contested, taking into account the likely damages, defence costs, and prospects of success. Senior Counsel's costs are part of defence costs.

6.6 Right to Contest

If we recommend a settlement and you disagree, you may contest the claim — but our liability is then limited to the amount for which the claim could have been settled, plus defence costs to the date of your election, less the retention.

07 General Conditions

Threading note: in this Section 07, a reference to a claim includes, for Section 2, a reference to a cyber loss (as defined), except where this wording expressly distinguishes between them. This ensures the limits, non-accumulation and retention machinery below reaches Section 2's first-party payments, not only its claims.

7.1 Limits of Liability

Section 1: The limit of liability is the most we will pay for any single claim. The aggregate limit is the most we will pay in the policy period.

Section 2: The limit of liability applies to each insuring agreement, to each claim and to each cyber loss. The aggregate limit is the most we will pay in the policy period for all claims and all cyber loss under Section 2 combined.

Sections 1 and 2 combined: The aggregate limit shown in the schedule for Sections 1 and 2 combined is the most we will pay across both sections.

Section 3: Public liability — limit of liability per claim, no aggregate. Products liability — limit of liability per claim, aggregate limit in the policy period. Defence costs are in addition to the limit (Section 3 only).

All sections: All sub-limits are part of (not in addition to) the relevant limit. The inclusion of more than one insured does not increase the total payable.

7.2 Non-Accumulation

If a claim (or, for Section 2, a cyber loss) could be indemnified under more than one section: (a) you are entitled to indemnity under one section only per claim or cyber loss; (b) the maximum liability across all sections is the highest single section limit; (c) limits do not accumulate across sections; (d) where more than one retention would apply, the highest applies.

WORKED EXAMPLE — NON-ACCUMULATION. You have Section 1 (PI) with a $5M limit, Section 2 (Cyber) with a $5M limit, and Section 3 (GL) with a $10M limit. A claim could potentially fall under both Section 1 and Section 2. The maximum we will pay for that claim across all sections is $10M (the highest single section limit) — not $20M. If the claim is allocated to Section 1, the most we pay is $5M.

7.3 Retention

The retention is borne by you and must remain uninsured. We only pay amounts exceeding the retention, whether the amount is a claim or (for Section 2) a cyber loss. Where a claim or cyber loss could fall under more than one insuring agreement or extension, only one retention applies (the highest), and the aggregation rule in Section 6.4 determines what counts as one claim or one cyber loss for this purpose.

For Section 2 business interruption: the waiting period operates as a qualifying threshold (see the waiting period definition and Sections 2.3 and 2.4). Once the interruption exceeds the waiting period, business interruption loss is measured from the start of the interruption, and any monetary retention then applies to that loss.

7.4 Other Insurance

(a) Scope. This clause applies only to other insurance of the same class, or responding to the same subject matter, as the section or extension under which you are claiming. It does not apply to insurance you are required by law to hold, and it does not affect the Excess Layer endorsement (E04) or any other insurance expressly written as specific excess over this policy.

(b) General position. To the extent permitted by law, where you have other valid and collectible insurance of that same class responding to the same claim or cyber loss, we will pay only our proportion of the loss, calculated by reference to the respective limits of liability available under each policy — unless the other insurance is written as specific excess over this policy, in which case this policy responds first.

(c) Priority at the Section 2 / standalone cyber policy boundary. Where you hold both Section 2 of this policy and a standalone cyber insurance policy (including the Meridian Cyber wording) that could respond to the same cyber loss, this policy's Section 2 responds first for cyber loss arising from or in connection with your provision of technology products or technology services (i.e., professional-liability-triggered cyber events); a standalone cyber policy is intended to respond first for cyber loss unconnected with your provision of technology products or technology services.

(d) Contribution tie-break. If, after applying paragraphs (b) and (c), it remains unclear which policy is primary, or both insurers dispute priority, each insurer contributes rateably in the proportion its own applicable limit of liability bears to the total of the applicable limits of liability of both policies, pending resolution.

(e) Section 45. Nothing in this clause limits your rights, or affects our obligations, under the Insurance Contracts Act 1984 (Cth), including section 45 (which voids a provision that purports to relieve an insurer from liability by reason of other insurance, except where a policy is expressed to be excess of a specified underlying policy). This clause is drafted, and is to be read, consistently with section 45.

7.5 Cancellation

By you: cancel at any time by written notice to us. Proportional refund of premium applies. Cancellation under this paragraph does not affect any claim, inquiry, loss, or notified circumstance arising before the cancellation date, which continues to be dealt with under this policy.

By us: in any circumstances permitted by law, by giving you 30 days' written notice. Proportional refund.

7.6 Mergers and Consolidations

If you merge with, are acquired by, or sell 50%+ of your assets to another entity during the policy period, this policy continues to expiry — but only for claims arising from products/services provided before the event. No cover for post-event activity unless we agree in writing. See also Section 4.12 (Run-Off), which applies only to Sections 1 and 2 and does not limit this clause.

7.7 Reinstatement

Section 1 only.

If the aggregate limit exceeds the limit of liability, and the limit is exhausted, we will reinstate it for subsequent unrelated claims — until the aggregate is exhausted.

7.8 Insurance Contracts Act Protections

This policy is subject to the Insurance Contracts Act 1984 (Cth) (the Act). Nothing in this policy excludes, restricts, or modifies the operation of the Act; where this policy is inconsistent with the Act, the Act prevails.

(a) Utmost good faith: We will act towards you with the utmost good faith, as required by sections 13 and 14 of the Act.

(b) Section 54 — acts and omissions: We will not refuse to pay a claim solely because of your failure to comply with a term or condition of this policy, unless that failure caused or contributed to the loss, or prejudiced our interests. Where we have been prejudiced, we may reduce our liability to the extent of that prejudice.

(c) Non-avoidance: We will not avoid this policy for non-disclosure or misrepresentation unless the non-disclosure or misrepresentation was fraudulent. Where it was not fraudulent, we may reduce our liability under section 28(3) of the Act to the amount that would place us in the position we would have been in had the disclosure been made or the representation not been made. For this class, we do not extend the section 28(3) reduction waiver that applies for innocent insureds under the financial-lines suite's multi-individual covers, reflecting that this class is predominantly a single-named-insured business cover rather than a cover for multiple individuals.

(d) Innocent insured: Where this policy excludes loss caused by dishonest, fraudulent, or criminal conduct, that exclusion does not apply to an insured who did not commit, participate in, or know about the conduct.

(e) Section 40(3) — notification of circumstances: Where you give us notice of facts that might give rise to a claim during the policy period, in accordance with Section 6.1, we cannot later refuse to cover a claim arising from those facts on the ground only that it was made after the policy period, as provided by section 40(3) of the Act.

7.9 GST

Amounts payable under this policy are calculated without regard to any input tax credit to which you are, or would be, entitled under A New Tax System (Goods and Services Tax) Act 1999 (Cth) (the GST Act), unless this policy or the schedule states otherwise. Where GST is payable on a supply made in connection with a claim or cyber loss, the amount we pay is adjusted (grossed up or down) in accordance with the GST Act so that you are placed in the same net position as if no GST applied.

7.10 Version Control

The version of this wording that applies to your policy is the version in force at the start of the policy period. Later updates to the Cuttleflow open wording library do not apply to your policy unless we agree in writing.

7.11 Governing Law and Jurisdiction

(a) Governing law: This policy is governed by the laws of the Australian state or territory in which this policy is issued, as shown in the schedule.

(b) Jurisdiction: The parties submit to the non-exclusive jurisdiction of the courts of that state or territory, and courts of appeal from them.

7.12 Disputes and Complaints

If you have a complaint, contact us first using the details in the schedule. We will acknowledge your complaint promptly and deal with it through our internal dispute resolution process within the timeframes required by ASIC Regulatory Guide 271 (ordinarily 30 calendar days, or such shorter period as the law requires). If you are not satisfied with our response, or if that period has passed without a response, you may refer your complaint to the Australian Financial Complaints Authority (AFCA) — www.afca.org.au | 1800 931 678.

Endorsement Library

The following endorsements are available and may be attached as shown in the schedule. The full operative text of each endorsement is set out in the companion Endorsement Library document (Doc Ref 2026/TL/0002). That document is not remediated by this draft; required amendments to it are recorded in the change register (to be published) as deferred library actions, including updating the compatibility statement to a version range and drafting a new systemic/widespread cyber-event aggregation endorsement (see change register, M6/P1).

E01 US/Canada jurisdiction extension
E02 Defence costs in addition to the limit (Sections 1 and 2)
E03 Increased sub-limits
E04 Excess layer
E05 IoT/embedded systems extension
E06 AI governance and model liability extension
E07 Open source software licence compliance
E08 Cryptocurrency and digital asset services
E09 Managed security services provider (MSSP) extension
E10 Government and defence contractor extension
E11 Non-IT dependent business interruption (named suppliers)
E12 Customer business interruption (named customers)
E13 Missed bid income loss (bids not submitted due to a cyber security breach or system failure)
E14

Emergency continuity costs (temporary workaround costs to remain operational during an interruption)

Changes From v1.2.0

Provenance and Australianisation remediation ahead of Commons publication (registers CMN-RDR-TL-001 v0.2, PROV-CMN-001, CMN-AUS-TL-001). Drafting-only: no coverage position is changed; effect preserved for every clause. Six coverage-position questions (W1–W6) are reserved for the Wording Partner and remain open.

• Provenance — redrafted the ISO/broadform/NMA/LMA-derived passages into original house wording, effect preserved: advertising-liability exclusion (5.1); Occurrence, Personal injury and Property damage definitions (Section 3); Business definition limb (b); Product Recall and Physical & Legal Control extensions (3.3); Nuclear (5.21); Sanctions (5.30, now the house-standard clause); and the War and State Cyber Operations exclusion (5.36, LMA-attribution sentence removed).

• Australianisation — replaced the US term (civil investigative demand) in the Regulatory proceeding definition with Australian regulators’ compulsory-notice powers (OAIC, ACCC, ASIC).

• Australianisation — renamed the defined term to Personal information and aligned it to section 6 of the Privacy Act 1988 (Cth).

• Australianisation — added the section 40(1) pre-contract notice to About This Policy; retitled 5.16 to Natural Perils and Physical Events (catch-all preserved); anchored 5.31 Securities Law to the Corporations Act 2001 (Cth).

• Open for Wording Partner (W1–W6): statutory-penalty insurability inline citations (5.15); coverage position on the statutory tort of serious invasion of privacy and the 4.9(e) unintentional gate; cyber-extortion payment-approval mechanic; the 5.36 reinsurance-conformity confirmation; and the two pre-existing WP-review items at 7.4 and 7.8(c).

Changes From v1.1.0

Recorded in accordance with the Cuttleflow open wording library versioning requirements. This is a MINOR-to-structural remediation release; see the companion change register (to be published) for the finding-by-finding mapping.

Critical — Cyber loss defined (Definitions, Core; threaded into Section 05 intro, Section 6.1, Section 6.4, Section 7.1, Section 7.3).

Critical — Continuity date defined, distinguished from Retroactive date, and threaded into Section 4.3 (Definitions, Core).

Critical — Other Insurance (7.4) rewritten: scoped to same-class insurance, priority rule at the Section 2 / standalone cyber policy boundary ( tagged), proportional-contribution tie-break, and an express section 45 savings statement.

Critical — DRAFT marking added to the header and footer of every page, and to the About This Policy section.

Major — Section 40(3) circumstance-notification machinery added for Section 1 (Section 6.1(a)), cited in Section 7.8(e); deemed-claim-date rule in Section 6.4 extended to circumstances notified under 6.1.

Major — Continuous Cover (4.3) capped at the lower of the current and prior limits of liability.

Major — Extended Reporting Period (4.6) now triggers on cancellation as well as non-renewal; automatic period increased to the Meridian 90-day default (schedule-overridable); purchasable extension via endorsement retained.

Major — First-party aggregation for cyber loss added (Section 6.4): same/similar/related-cause test and a cross-period rule.

Major — Sub-limit language added to the Hardware Replacement, Reputational Harm, and Cyber Crime extensions (Section 2.9).

Major — Dependent business interruption (2.3(b), 2.4(b)) sub-limited, resolving the inconsistency with endorsement E11; a systemic/widespread-event endorsement is recorded as a deferred library action.

Major — Jurisdiction clause added (Section 7.11(b)), alongside the existing governing law clause.

Major — Insured's cancellation right (7.5) made unconditional (the "provided no claims paid or reported" gate removed).

Major — Undefined gating terms defined: Final adjudication, Joint venture (Core Definitions); Unauthorised access, Control group (Cyber-Specific Definitions); each threaded into its operative clause (5.8, 4.1, 4.8, Cyber security breach definition, 6.1(b)).

Major — Distribution posture statement added to About This Policy, with a tag on the PDS/TMD wrapper question.

Minor — Orphan definition "Approved product" deleted (never used in operative text).

Minor — Sanctions exclusion (5.30) now cites the Autonomous Sanctions Act 2011 (Cth) and the Charter of the United Nations Act 1945 (Cth).

Minor — GST general condition added (new Section 7.9), citing A New Tax System (Goods and Services Tax) Act 1999 (Cth).

Minor — Hard-coded constants moved to schedule defaults: betterment percentage (5.5), extended reporting period (4.6), business interruption indemnity period (2.3, 2.4) — each now "as shown in the schedule, or [default] if not shown".

Minor — Run-Off (4.12) and Mergers and Consolidations (7.6) cross-referenced, with 7.6 stated to govern where the two overlap.

Minor — Consolidated IP boundary explanatory note added near Section 5.20 (guidance only; no substantive IP position changed).

Minor — Section 28(3) position recorded expressly in Section 7.8(c) rather than left silent.

Polish — Endorsement library compatibility statement: recorded as a required library action to move from a single hard-coded version to a range (deferred; not amended in this document).

Polish — AFCA/IDR clause (now 7.12) expanded to describe internal dispute resolution and RG 271 timeframes before naming AFCA.

Polish — Terrorism exclusion (5.32) now acknowledges the Terrorism Insurance Act 2003 (Cth).

• General Conditions renumbered from 7.9 onward to accommodate the new GST clause and the split Governing Law / Jurisdiction clause: former 7.9 (Version Control) is now 7.10; former 7.10 (Governing Law) is now 7.11(a), with new 7.11(b) (Jurisdiction); former 7.11 (Disputes and Complaints) is now 7.12. No other clause numbers changed; all endorsement library anchors (5.18, 6.3, 1.2/1.3, 5.20, 5.33, 4.4/4.4(a), 2.3(b), 4.2, and the Business interruption loss definition) are unaffected.

Cuttleflow Systems — Open Source Insurance Wording · Licence: CC BY 4.0 (wording text only — see licence boundary note below)

2026/TL/0001 · v1.3.0-DRAFT · July 2026 · © 2026 Cuttleflow Pty Ltd t/a Cuttleflow Systems

Lloyd's risk codes: PC (technology professional liability) · CY (cyber) · GL (public liability) · PR (products liability)

This wording is prepared for adoption, adaptation, and redistribution under the terms of the licence once Wording Partner sign-off is complete. The CC BY 4.0 licence applies to the wording text only; it does not extend to the Cuttleflow Systems name, the Meridian brand, the bearing mark, or other brand assets. Adopters must obtain their own legal advice and their capacity provider's approval before use; the Wording Partner's review letter runs to Cuttleflow Systems only. It is designed for the Australian market and assumes the application of the Insurance Contracts Act 1984 (Cth). Users are responsible for their own legal review, regulatory compliance, and reinsurance alignment.

DRAFT — SUBJECT TO LEGAL REVIEW — NOT FOR USE

33°53′S · 151°16′E · SYDNEY · CUTTLEFLOW PTY LTD T/A CUTTLEFLOW SYSTEMS

Comments on this wording

The rest of the libraryComment where it’s quiet