Insurance for Startups & New Economy

Building a Run-Off Programme for a Real-Money Gaming Company That No Longer Trades

The Supreme Court upheld the online money-gaming ban in late August 2026, and one of the largest operators completed its pivot away from real-money play within days. A shut-down platform still carries D&O, employment, cyber and crime exposures for years, and the run-off programme has to be bought while the company still exists to buy it.

Sarvada Editorial TeamInsurance Intelligence
11 min read

Listen to this article

Audio version • 11 min read

run-offD&Oextended reporting periodonline gamingcyber liability

Last reviewed: September 2026

A Ban Upheld, and the Liabilities That Outlast the Business

The Promotion and Regulation of Online Gaming Act, 2025 received Presidential assent on 22 August 2025 and its prohibition on online money games has since been brought into force. An online money game is one where a user pays a fee or stakes money expecting monetary winnings, whether the game turns on skill, chance, or both. Offering such a service is a cognizable and non-bailable offence carrying up to three years of imprisonment and a fine of up to one crore rupees.

The constitutional challenge closed in late August 2026. LawStreet Journal reported the outcome on 26 August 2026 under the headline "Every Mobile Phone a Virtual Gambling House: SC Upholds Online Betting Ban". The commercial response was immediate: Outlook Respawn reported on 23 August 2026 that Dream11 had ended its ad-free subscription product amid the crackdown, and the Economic Times reported on 27 August 2026 that the company had completed its pivot and was no longer a gaming app.

For an insurance buyer, this is where most programmes go wrong. Revenue stops, distributions get planned, and the renewal is treated as a cost that serves no purpose. Almost everything a real-money gaming operator bought was claims-made, and such a policy protects the period in which a claim is made, not the period in which the conduct happened. Stop renewing and the trading years become uninsured on the day the last policy expires.

Why a Claims-Made Tower Collapses at Shutdown

Directors-and-officers liability, employment practices liability, technology errors and omissions, professional indemnity and most cyber wordings sold in India are claims-made. The trigger is the written demand received during the policy period, or a circumstance notified during it, whenever the alleged wrongful act occurred, provided it falls after the retroactive date.

That works while the company keeps renewing, because each renewal picks up the prior years through the retroactive date. It fails at wind-down. A player group action filed in 2028 over contest outcomes in 2024, a regulatory proceeding started in 2029, or a former employee's claim over an ESOP cancellation in the shutdown week all arrive after the last policy expired.

Extended reporting period versus a standalone run-off policy

  • An extended reporting period (ERP), also called a discovery period or tail endorsement, is bought on the expiring policy. It extends the time in which claims can be notified, but only for wrongful acts before expiry, and the limit, retention, exclusions and retroactive date stay exactly as they were.
  • A run-off policy is a new contract, written for a multi-year period in a single placement, covering claims made in that period for wrongful acts before a stated run-off date. Its terms can be negotiated, which matters when the expiring wording has a gap the buyer now knows about.

Tail length should be set against the periods in which claims realistically arrive. The default limitation for suits founded on contract or tort under the Limitation Act, 1963 is three years, but tax proceedings and prosecutions under the 2025 Act do not follow that clock. Indian placements are commonly written for three, five or six years, and six is the usual ask where the activity has been prohibited outright.

Pricing, Fully Earned Premium and a Limit That Never Reinstates

Run-off cover is priced as a multiple of the expiring annual premium, charged once, and treated as fully earned and non-refundable from inception. A six-year tail costs a substantial multiple of the last annual premium rather than a small add-on, and it cannot be cancelled later to recover cash for distribution.

The structural point that gets missed is the limit. An annual policy gives a fresh limit every year. A six-year run-off gives one limit for six years, and every claim, defence cost and investigation expense over the tail erodes the same tower. A limit that looked adequate against one trading year can be thin against six years of claims arising from a prohibited activity, an unresolved tax position, and a mass exit of staff.

Three wording points earn their keep at placement:

  1. Side A difference-in-conditions cover for the individuals. Once the company is dissolved or has distributed its assets, there is no indemnifier left. Side A responds directly to a former director where the company cannot or will not indemnify, usually on a separate limit that company-reimbursement claims cannot exhaust.
  2. Full severability of the proposal and the conduct exclusions. One officer's alleged dishonesty should not void cover for a colleague who knew nothing, and the conduct exclusion should bite only on final adjudication rather than on allegation.
  3. Named-insured continuity. The run-off should follow the entity through name changes, mergers and the pivot itself, and cover subsidiaries sold or struck off during the wind-down. Where control has already changed, check whether the expiring policy's change-in-control clause converted it into run-off on a date the buyer did not choose.

Once a policy lapses without an ERP election, the window closes, and no market will write a tail over an expired programme for a prohibited business. Our note on how directors-and-officers claims are actually defended sets out what that limit ends up paying for.

Dormant KYC Data Is Still a Live Exposure

A real-money gaming operator held identity documents, PAN details, bank and UPI handles, transaction histories and behavioural records for tens of millions of paying users. Shutting the app deletes none of it, and a dormant database is a harder security problem than a live one because nobody is monitoring it, patching it, or noticing that a credential still works.

Retention pulls in two directions. The Digital Personal Data Protection Act, 2023 requires a data fiduciary to erase personal data once the purpose for processing is served, unless retention is required by law. Online gaming operators were brought within the reporting-entity framework of the Prevention of Money Laundering Act, 2002 by notification in March 2023, and PMLA record-keeping obligations run for five years. The answer is a documented retention schedule that keeps what the law requires and erases the rest, with the retained archive moved out of production into encrypted cold storage and every application and vendor credential that touched it revoked.

Cyber cover needs its own tail, read for what the run-off form actually pays. Incident response, forensics and notification to affected principals are usually available, while business interruption cover is worthless to an entity with no revenue. Regulatory defence cost is the line that matters, because the Data Protection Board can proceed against a fiduciary for a breach of security safeguards with penalties running to INR 250 crore under the Act's Schedule, and the insurability of the penalty itself is doubtful even where the defence cost is covered.

Unclaimed Player Balances and Crime Risk in a Thinning Team

Player wallets are the operational problem that will not close cleanly. A platform winding down real-money play has to refund deposits and settled winnings to millions of accounts, and a residue always remains: stale KYC, closed bank mandates, users who never respond, and balances too small for anyone to chase. That residue sits on the balance sheet as a liability to identified individuals for years, in an account that fewer and fewer people are watching.

Crime and fidelity exposure rises during a wind-down rather than falling. The finance and engineering staff who understand the payout systems are serving notice or already gone, segregation of duties breaks when three approvers become one, access reviews stop, and vendor credentials stay live long after anyone needs them. Each of those is a documented precursor to insider loss.

Commercial crime and fidelity policies are typically written on a loss-discovered basis, which needs its own extension rather than a claims-made tail. A discovery period extension keeps cover in place for losses that occurred during the policy period but come to light after it ends, which is the pattern for wind-down fraud found at a final audit. Confirm three things: that former employees remain insured persons for acts committed while employed, that the discovery extension covers the audit cycle after closure, and that insider and outsider collusion is covered rather than falling between the crime and cyber policies.

Three controls do most of the work. Revoke system credentials on the last working day, not at the end of notice, and run an access review after the final technical departure. Move the residual player float into a single account with dual authorisation and no operational payment rights. Document the unclaimed-balance position at closure so a later claim can be tested against a fixed record.

These are the exposures set out in our earlier piece on liability and operational insurance for real-money gaming platforms, except that no one is now paid to manage them.

GST Demands and Proceedings That Name Former Directors

The 28 percent GST on the full face value of deposits or entry amounts, effective from October 2023, and the retrospective demands raised for earlier periods, produced the largest numbers the sector ever faced. Those demands do not disappear when trading stops. They follow the entity through the wind-down, and sometimes the people who ran it.

Tax and duty payable by the company are excluded from D&O cover. No management liability policy pays a GST demand, the interest, or the penalty attached to it. What the policy can pay is the defence cost of a covered individual in a proceeding brought against that person, subject to the regulatory investigation sublimit and the conduct exclusions. Section 89 of the CGST Act, 2017 permits recovery of a private company's unpaid tax from its directors where recovery from the company fails, unless the director shows the non-recovery was not attributable to gross neglect, misfeasance or breach of duty. Defending that allegation is a personal legal cost, and it is what a Side A run-off tower exists to fund.

The 2025 Act adds a second track. Because offering an online money game is a cognizable, non-bailable offence carrying up to three years of imprisonment, complaints can name individual officers over conduct during the trading period. Criminal defence costs are commonly advanced under Indian D&O wordings, with the conduct exclusion applying only on final adjudication. Confirm that defence costs are advanced as incurred rather than reimbursed at the end, and that the definition of insured person covers officers who resigned or were removed before the run-off date.

The run-off programme funds the defence and protects individual net worth. It does not touch the tax number itself, which is a matter for legal strategy, provisioning and disclosure.

The Employment Tail After a Mass Exit

A shutdown of this kind ends hundreds or thousands of employment relationships within weeks, and employment claims arrive late. Employment practices liability is claims-made like the rest of the tower, so the exposure peaks when the policy is most likely to be dropped.

The claims that follow a wind-down are predictable: disputes over notice pay and final settlement, allegations that selection for retrenchment was discriminatory, claims tied to accrued but unpaid variable pay, and grievances raised on the way out that surface months later.

ESOP treatment straddles two policies. A claim that unvested options were cancelled, or that a liquidity event disadvantaged option holders, can be pleaded as an employment claim, as breach of contract, or as a claim against the board. Where it targets board conduct it belongs on the D&O tower; where it targets the employment relationship it belongs on EPL. Buy both tails for the same period, ideally from the same insurer, so the allocation argument stays internal to one carrier.

Sequencing the Purchase Before the Entity Goes Quiet

Run-off is a sequencing problem more than a coverage problem. Almost every failure traces back to a decision taken in the wrong order.

  1. Inventory every claims-made policy and its expiry date. D&O, EPL, tech E&O, professional indemnity, cyber, and any crime policy with a discovery clause. Record the retroactive date and the ERP election window for each, since those windows are often thirty or sixty days after expiry.
  2. Notify circumstances before the last policy expires. Regulatory correspondence, player complaints in progress, tax show-cause notices naming individuals and employee grievances should go in as circumstances under the expiring policy. A properly notified circumstance is deemed a claim under it, which puts the matter on a live tower rather than into the tail.
  3. Negotiate the tail before non-renewal. The incumbent insurer is the realistic market. Start at least ninety days before expiry with a wind-down narrative, the refund plan for player balances, the retention schedule, and the status of every known proceeding.
  4. Set tail length per policy. Six years is defensible for D&O where a prohibited activity and open tax proceedings are in play. Employment and cyber tails are often shorter, but never shorter than the realistic notification window for the exposures they cover.
  5. Fund the premium before distributions. It is a single fully earned payment and has to be provisioned ahead of any return of capital, because it cannot be bought once the cash has left.
  6. Appoint a custodian and a notice address that survive the closure. One named person holds the policy documents, the service address, the data inventory and the broker relationship for the whole tail, and the insurer is told in writing. Notices sent to a dead office or a lapsed email domain undo tails that were fully paid for.
  7. Preserve the evidence the defence will need. Contest logs, payout records, KYC and AML files, board minutes and the tax file, in a controlled archive with an access log.

The entity is the last constraint. A run-off policy is a contract, and after strike-off there is no company left to be the named insured or to receive a notice. If dissolution is on the timetable, the tail must be placed and paid for while the company still exists, with the individuals secured through Side A cover that survives it. For what this sector was insuring before the ban, see our analysis of platform liability, cyber and regulatory risk after the gaming law.

Frequently Asked Questions

Why does a company that has stopped trading still need directors-and-officers cover?
Because D&O is claims-made. The policy responds to claims first made during its period, not to the period when the conduct occurred. Claims against a real-money gaming operator's former board can arrive years after the platform closes: tax recovery proceedings naming directors personally, prosecutions under the Promotion and Regulation of Online Gaming Act, 2025, shareholder or investor actions over the wind-down, and player or creditor claims. If the company simply stops renewing, the last policy expires and there is no contract in force to accept notice of any of those claims. The former directors are then defending at their own cost, against a company that may no longer have assets to indemnify them.
What is the difference between an extended reporting period and a run-off policy?
An extended reporting period, also called a discovery period or tail endorsement, is bought on the expiring policy and extends only the time in which claims can be reported. The limit, retention, exclusions and retroactive date all remain exactly as they were, and the limit is whatever is left of the expiring tower. A run-off policy is a fresh contract placed for a multi-year period, covering claims made in that period for wrongful acts before a stated run-off date. Because it is a new placement, terms and limit can be negotiated, which is useful when the buyer has identified a gap in the expiring wording or needs a larger limit to carry several years of exposure. Both are typically paid as a single fully earned premium that cannot be cancelled or refunded.
How long should the run-off period be for a shut-down gaming platform?
Indian placements are commonly written for three, five or six years, and six is the usual ask where the underlying activity has been prohibited outright. The default limitation for suits on contract or tort under the Limitation Act, 1963 is three years, but tax proceedings, criminal complaints under the 2025 Act, and regulatory investigations do not follow that clock, which is why a three-year tail often ends before the exposure does. Tail length can differ by policy: D&O usually takes the longest period, while employment and cyber tails are sometimes set shorter, though never shorter than the realistic notification window for the exposures they cover.
Can insurance cover the GST demands raised against a gaming operator?
No. Tax and duty payable by the company are excluded from D&O and from every other management liability wording. The policy can pay the cost of defending a covered individual in a proceeding brought against that person, including recovery action under Section 89 of the CGST Act, 2017, which allows a private company's unpaid tax to be recovered from its directors where recovery from the company fails, subject to the regulatory investigation sublimit and the conduct exclusions. The tax number itself is a balance-sheet and legal-strategy problem, and a programme bought on the assumption that insurance will absorb it will be sized against the wrong risk.
What happens to the dormant player database after the platform closes?
It stays a live exposure. The DPDP Act 2023 requires erasure once the purpose for processing is served, unless retention is required by law, while PMLA record-keeping obligations run five years and pending tax or player proceedings carry their own preservation needs. The workable position is a documented retention schedule that separates records the law requires from records kept out of inertia, with the retained archive moved out of production into encrypted cold storage and every application and vendor credential revoked. Cyber run-off should then be read for what it actually funds after closure: incident response, forensics, notification and regulatory defence costs, since business interruption cover is meaningless for an entity with no revenue.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform