Guide · 2026

The Three Reasons a Business Buys Insurance

Executive summary

Almost every commercial-insurance purchase reduces to one of three reasons, and conflating them is the most common and most expensive mistake a buyer makes. The law requires some coverage; the people you need — customers, landlords, investors, platforms — require more; and a few lines nobody demands are still prudent given your exposure. This guide is the decision framework every other playbook on this site refers to: how to tell which reason applies to each line, and why the answer decides whether you can avoid it, what limit to carry, and whether to negotiate.

Almost every commercial-insurance purchase reduces to one of three reasons. Read the insurance stack of almost any small business and you can sort each line into exactly one of three buckets — and which bucket a line sits in decides whether you can avoid it, what limit to carry, and whether negotiating is even an option. Buyers who cannot tell the three apart spend too much on lines they could have negotiated, miss lines the law actually forces on them, and resent the ones they chose freely.

Here is the framework, and why the distinction matters.

Reason one: the law requires it

A statute or regulation makes you carry the coverage, sets the trigger, and attaches a penalty for noncompliance. This is the smallest of the three buckets. In commercial insurance it is almost entirely workers’ compensation: your state’s employee threshold switches the duty on, and the enforcement is a regulator, a fine, and in some states a stop-work order or criminal exposure. California requires it with a single employee under Labor Code 3700; other states set the line elsewhere.

The signature of a legal mandate is that the “or else” is the government, not a customer. You cannot negotiate a statute. The only decision the law leaves you is how to satisfy it — buy the policy, self-insure where a state permits, or file an owner-officer exemption where one applies. General liability, professional liability, D&O, and cyber are not in this bucket anywhere in the United States, which surprises founders who assume “required” means “by law.” It almost never does.

Reason two: someone you need requires it

A counterparty conditions a deal you want on proof of coverage. Your customer’s master services agreement demands technology E&O and cyber at named limits. Your lease demands general liability and names the landlord additional insured. Your investor’s term sheet asks for D&O. A platform — Amazon, a payment processor, a marketplace — sets an insurance threshold for sellers. A lender writes coverage covenants into a loan.

This is the largest bucket for most businesses, and its signature is that the “or else” is the loss of a deal: you do not sign the customer, take the keys, close the round, keep the listing. The requirement lives in a contract or a condition, not a statute, and it is enforced by a certificate of insurance plus the endorsements the clause names. The limit it specifies is a real number someone will check, not a suggestion — and it is usually negotiable in a way a statute is not. A contract demanding $1 million per occurrence of general liability is standard and cheap to satisfy; a demand for specialty coverage unrelated to your scope is worth a redline before you bind anything. The mechanics of reading that clause are on the sister library.

Reason three: nobody requires it, but your exposure makes it prudent

No law and no contract demand the line. You buy it because a realistic adverse outcome would threaten the business, and the policy is how you transfer that risk. This is the only bucket that is genuinely a risk decision — and for that reason it is the one most often skipped.

EPLI is the clearest example. No statute, customer, or landlord requires it. Yet the exposure begins at your first hire, because every termination and pay decision is a claim none of your other policies will answer, and retaliation is the most frequently alleged basis of discrimination. Cyber for a company that holds sensitive data but has no enterprise customer demanding it sits in this bucket too. The signature of a prudence line is silence: nothing on paper forces it, so the “requirement” is your own read of your exposure. That makes it easy to defer and easy to regret.

Why conflating the three is expensive

The damage is not theoretical. A founder who treats a customer’s E&O demand as if it were a legal requirement overbuys instead of negotiating the limit to fit the work. A founder who assumes workers’ comp is “just a good idea” discovers, at an audit or an injury, that it was a mandate with a penalty attached. A founder who carries cyber only because a contract said so drops it the day that contract ends — and loses coverage for a breach that traces to work done while the policy was in force, because most cyber is claims-made and the continuity was never the buyer’s to break.

A decision frame for any line you carry

For each coverage on your schedule — and each one a counterparty has handed you — ask the same three questions, in order:

QuestionIf yesIf no
Does a statute require it?Satisfy it exactly; the limit is the statute’s, not yoursGo to the next question
Does a deal you need require it?Match the clause; negotiate anything beyond your scopeGo to the next question
Would a realistic loss threaten the firm?Buy it on your own analysis; size to your worst single eventYou can defensibly go without

One line can sit in different buckets for different buyers — workers’ comp is reason one for an employer and reason two for the general contractor whose subcontract agreement demands it. The point is to know which bucket you are in, because that is what decides whether the line is optional, what number to carry, and whether the conversation about it is with a broker or with a counterparty.


Sources are linked below. The framework is editorial; the mandate, contract, and prudence examples each link to the question page that sources them.

Sources

  1. Primary source: NAIC — Insurance topics for small businesses — Regulator-association overview distinguishing state-required coverage (workers' compensation) from coverage driven by contracts and by the business's own exposure.
  2. Primary source: New York Department of Financial Services — Small businesses — State regulator overview separating the statutory layer (workers' comp and disability) from the elective, contract-driven, and prudence-driven layers.
  3. Primary source: California DIR, Division of Workers' Compensation — Employer FAQ — Example of a legal mandate with a threshold and a penalty: California requires workers' comp with even one employee (Labor Code 3700).
  4. Primary source: U.S. Equal Employment Opportunity Commission — Retaliation — Example of a prudence-driven line: EPLI, because retaliation is the most frequently alleged basis of discrimination, yet no law or contract requires the coverage.
  5. Primary source: California Civil Code § 2772 — Defines indemnity as protection against the legal consequences of another person's conduct — the contractual mechanism behind most counterparty insurance demands.