A risk that lives on someone else's premises
Most of the risk profiles in this series are about factories: a building, plant, stock and a fire load an insurer can survey. A facility management (FM) or private-security firm is a different animal, and the difference is that it barely owns the assets its risk attaches to. Its people, housekeeping staff, technicians, guards, work inside its clients' buildings, using the clients' equipment, alongside the clients' visitors and employees. The firm's own balance sheet is mostly people, contracts and a modest fleet.
That inverts the underwriting question. For an FM or security company the property programme is small; the real exposures are liability, employee dishonesty, workforce compensation and contractual risk assumed under client agreements. A cleaner floods a data centre, a technician's maintenance lapse trips a client's cold room, a deployed guard is accused of colluding in a theft, a worker is injured at a site the firm does not control, and each of those lands on the services firm, not on the client whose premises it happened at.
This is a large sector, integrated FM providers, standalone housekeeping and security agencies, and manpower-supply firms, and it is under-represented in the manufacturing-heavy risk libraries brokers usually reach for. This profile maps its exposures in the order that matters for a services firm: liability at the client's premises, employee dishonesty, the contractual indemnities the client's Master Service Agreement (MSA) imposes, the distributed workforce, the fleet, and the professional-indemnity tail that integrated FM adds. The recurring theme is that the firm's contracts create as much of its risk as its operations do.
Liability at the client's premises
The core operational exposure is third-party and property-damage liability arising from the firm's activities on the client's site. A housekeeping team damages the client's flooring or a lift; a guard's negligence lets a visitor be injured; a pressure-washing job floods a floor below; a technician leaves a wet surface that a client's employee slips on. In each case a third party (the client, the client's staff, a visitor, a neighbour) has a claim against the FM firm for the loss its people caused.
This sits under a public liability or third-party-liability cover, and the wording detail matters more than the headline limit. The policy must respond to liability arising at premises the insured does not own or occupy, which is the whole point of the business, and it must not carry an exclusion that quietly limits cover to the firm's own premises. Damage to the client's property in the firm's care, custody or control is the recurring friction point, because many general liability wordings exclude property in the insured's custody, and an FM firm is constantly handling and working on client property.
The limit should be set against the value of the sites the firm works in, not a nominal figure. An FM contractor servicing a grade-A office tower, a hospital or a data centre can cause damage and consequential loss far larger than its own annual revenue, so the liability limit is driven by the client portfolio, not the firm's size.
Employee dishonesty and theft allegations
A firm that places staff and guards inside client premises carries an exposure most manufacturers do not: its own employees may steal from, or be accused of stealing from, the client. A guard colludes in the removal of client assets, a housekeeping worker takes property, or a theft occurs on a guarded site and suspicion falls on the deployed staff. The client's loss becomes the firm's problem, because the client engaged the firm precisely to protect or service those assets.
Fidelity guarantee cover is the instrument here. A fidelity-guarantee policy indemnifies the employer against loss caused by the dishonesty or fraud of named or unnamed employees, and for a security or FM firm it is close to a core cover rather than an optional one, because employee dishonesty is a foreseeable and recurring loss on the very service the firm sells. Clients frequently require it in the contract, and the sum insured should reflect the value of assets the firm's staff have access to across its sites.
The theft-allegation dimension is subtler. Even where the firm's staff did not cause a loss, a theft on a guarded site can trigger a contractual claim or dispute with the client, and the firm's ability to investigate and defend depends on its own records: guard logs, deployment records, background verification of the staff placed. A security agency operating under the Private Security Agencies (Regulation) Act, 2005 (PSARA) is already required to verify and train its guards, and that verification discipline is both a licensing obligation and a defence against the allegation. The broker should read the fidelity cover against the client contracts, because the loss the firm actually faces is a blend of genuine employee dishonesty and contractual exposure to alleged theft, and a fidelity policy alone may not answer the contractual side.
Contractual risk transfer: the MSA and the certificate demands
For an FM or security firm, the contract is a risk instrument in its own right. Client Master Service Agreements routinely impose indemnities that shift a large amount of risk onto the service provider: hold-harmless clauses, obligations to indemnify the client for any act or omission of the firm's staff, and sometimes indemnities broad enough to cover the client's own consequential loss. The firm signs these to win the contract, and in doing so it assumes liabilities that its off-the-shelf insurance may or may not cover.
Two mismatches recur. The first is that a broad contractual indemnity can exceed what the firm's public-liability policy responds to, because liability policies cover the firm's legal liability in tort, not every obligation it has contractually assumed. Contractual liability assumed under an MSA needs to be read against the policy's contractual-liability position, and where the firm has agreed to indemnify a client for consequential or business-interruption loss, that may sit outside a standard public-liability grant entirely.
The second is the insurance-specification clause. Clients increasingly require the firm to carry defined covers at defined limits, to name the client as an additional insured, to waive subrogation against the client, and to produce a certificate-of-insurance evidencing all of it before work starts. Meeting these is administrative until it is not: a firm that agrees to a waiver of subrogation its insurer has not accepted, or names an additional insured the policy does not permit, has a gap between what it promised and what it holds.
A distributed workforce: EC Act, group PA and PSARA
An FM or security firm's largest single exposure by headcount is its own workforce, deployed across many client sites the firm does not control. The Employees' Compensation Act, 1923 (and the Employees' State Insurance scheme where applicable) makes the firm liable to compensate its workers for injury, disablement or death arising out of and in the course of employment, and that liability follows the worker to whichever client site they are posted at. A guard injured on a client's premises, a technician hurt on a maintenance job, a housekeeping worker in a fall, all are the firm's compensation liability even though the incident happened on a third party's site.
An employers-liability cover, usually written as a workers'-compensation policy, responds to this, and for a distributed workforce the declaration and headcount basis matters, because the policy has to cover a workforce that moves between sites and changes with contract wins and losses. A group personal accident cover providing defined accidental-death and disablement benefits typically sits alongside it, and is often required by clients for the staff deployed on their premises.
For security agencies specifically, PSARA adds a regulatory layer that intersects with the workforce cover. The Act governs the licensing of private security agencies and sets requirements for the verification, training and conditions of guards, and compliance with it is both a licence condition and a factor an underwriter weighs, because a well-run agency that verifies and trains its guards presents a lower liability and fidelity risk than one that does not. The aggregation point applies here too: a firm with thousands of workers across hundreds of sites can face multiple compensation and PA claims from a single event, such as a fire or building incident at a large site, so the limits should be tested against that concentration rather than set per head.
The motor fleet and the logistics tail
FM and security firms run vehicles, and the fleet is a real exposure even though it is not the centre of the business. Security agencies operate patrol vehicles and response cars; FM providers run vehicles for material movement, staff transport, waste removal and equipment logistics across their client sites. Each vehicle carries the standard motor exposure: third-party liability for injury and property damage, which is compulsory under the Motor Vehicles Act, and own-damage cover for the fleet.
The fleet risk scales with the number of vehicles and the driving intensity, and for a firm running patrol and logistics vehicles around the clock the third-party liability exposure is the one to size carefully, because a serious road accident produces a liability claim independent of the firm's other covers. A motor-insurance fleet placement, rated on the vehicle mix and claims experience, is the right structure, and the firm's driver-management, vehicle-maintenance and telematics discipline feed the terms.
The practical point for the risk manager is to keep the fleet cover coordinated with the liability and workforce programme, because a single vehicle incident can involve the driver (a compensation claim), the third party (a motor-liability claim) and, if client property was aboard, a custody exposure, and the three covers should join up rather than leave a seam between them.
Professional indemnity for integrated FM
The FM firms that have moved up the value chain, from housekeeping and manned guarding into integrated FM with technical services, add an exposure that pure manpower providers do not carry: professional liability for the technical work itself. When a firm takes on the operation and maintenance of a client's heating, ventilation and air-conditioning (HVAC), electrical and mechanical (M&E) systems, fire systems, or building-management systems, a failure of that service can cause the client a loss that goes far beyond damaged property.
The scenario that concentrates this is a maintenance failure that causes client business interruption. An HVAC failure that takes down a data centre's cooling, a chilled-water lapse that spoils a pharmaceutical or food client's stored product, or a fire-system maintenance error discovered after a loss, each can produce a claim for the client's consequential loss rather than just physical damage. That is professional-indemnity territory: cover for the firm's liability arising from a negligent act, error or omission in the professional services it provides, and it responds to the financial consequences of a service failure that a public-liability policy, focused on third-party bodily injury and property damage, does not.
Match the professional-indemnity limit to the criticality of the systems the firm maintains, not to the value of the maintenance contract. An FM firm maintaining the cooling on a data centre or the cold chain of a pharmaceutical warehouse can trigger a client business-interruption loss many times its own fee, and the professional-indemnity limit should be sized against that downstream loss, with the client's own contractual expectations read into the placement.
For an integrated FM provider the professional-indemnity, public-liability and contractual-liability positions overlap, and the boundaries between them decide which policy responds to a technical-service failure. Reading them together, against the MSA, is where the programme is made coherent rather than left with a gap between the liability that arises in tort and the liability the firm assumed by contract.
Structuring the programme, and reading the wordings with Sarvada
A defensible programme for an FM or security firm is built around liability, dishonesty and workforce rather than property. The liability spine is a public-liability cover written to respond off the insured's own premises and with the care-custody-control exposure addressed, at a limit driven by the client portfolio. Fidelity guarantee sits alongside it for employee dishonesty, sized to the assets the firm's staff can reach. The workforce layer is the employer's-liability and group-PA cover for a distributed, changing headcount, and the fleet layer is the motor programme. Integrated FM providers add professional indemnity for the technical services, sized to the client business-interruption they can cause. Over all of it sits the contractual question: whether the covers actually deliver the indemnities and insurance terms the client MSAs demand.
The features that earn better terms are operational and contractual: guard and staff verification and training (a PSARA obligation for security agencies), documented deployment and incident records, driver and fleet management, and a disciplined approach to reading MSA indemnity and insurance clauses before signing.
What decides whether each cover pays sits in the wording: whether the public-liability grant reaches off-premises and custody exposures, how the fidelity cover defines employee dishonesty and proof of loss, how contractual liability is treated, and where the professional-indemnity and liability boundaries fall. Those grants and exclusions differ across insurers and rarely line up with the indemnities a client contract imposes. Sarvada gives brokers and risk managers searchable access to insurer policy-wording, so an FM or security firm's liability, fidelity, workforce and professional-indemnity exposures can be matched to the wordings that actually respond, and read against the client contracts that create much of the risk. If you place or advise on facility-management and private-security risk, Request Access to compare the clauses that decide these claims.