Commercial Insurance Program Design: CPP, Specialty Lines, and Coverage Gaps

Updated October 1, 2026.

Direct answer: A complete commercial insurance program stacks a Business Owner’s Policy (BOP) or Commercial Package Policy (CPP) for property and liability, workers’ compensation, umbrella or excess liability, and specialty lines where standard forms exclude the exposure. Design starts with an exposure inventory, maps each loss scenario to a policy form, then stress-tests limits and exclusions so gaps show up before a claim—not after.

A commercial insurance program is not a single policy. It is a portfolio of policies that collectively address the organization’s identified risk exposures. For small businesses, a BOP plus workers’ compensation may provide adequate starting coverage. For mid-market and large commercial accounts, the program typically includes a CPP covering property, general liability, and auto; a workers’ compensation policy; a commercial umbrella or excess liability tower; and one or more specialty lines policies covering management liability, cyber, professional liability, and other exposures that standard commercial forms explicitly exclude. Designing this program systematically—starting from an inventory of actual exposures and working toward coverage structures that address each one—produces better outcomes than assembling policies reactively at renewal or after a loss.

Exposure Inventory Before Policy Names

Program design fails when it starts with “what did we buy last year?” instead of “what can go wrong?” Walk premises, contracts, payroll, fleet, products, data flows, and balance-sheet dependencies. For each exposure, note whether standard ISO commercial forms cover it, cover it only with endorsements, or exclude it entirely. That matrix drives CPP part selection, specialty placements, and tower limits.

Commercial Package Policy (CPP) Structure

The Commercial Package Policy is the ISO framework for assembling multiple commercial coverage parts into a single policy. A CPP consists of a common policy declarations page, common policy conditions (IL 00 17), and two or more coverage part declarations and forms selected from the ISO commercial lines portfolio.

Commercial Package Policy (CPP): A modular commercial insurance structure combining two or more ISO commercial coverage parts under common declarations and conditions. Unlike a BOP (pre-packaged for eligible small businesses), the CPP has no eligibility restrictions and can accommodate any combination of property, liability, auto, crime, inland marine, and other commercial coverage parts needed for the specific account.

Key CPP coverage parts include Commercial Property (ISO CP 00 10 building and personal property; CP 00 30 business income and extra expense; causes-of-loss forms CP 10 10 Basic, CP 10 20 Broad, or CP 10 30 Special/Open perils); Commercial General Liability (ISO CG 00 01 occurrence or CG 00 02 claims-made); Commercial Auto (CA 00 01 business auto and related forms); Commercial Crime (CR 00 20—employee theft, forgery, computer fraud, funds transfer fraud, money and securities); and Commercial Inland Marine (equipment floaters, contractor’s equipment, installation floater, electronic data processing, accounts receivable, valuable papers).

The CPP framework allows customization a BOP cannot match: replacement cost valuation with an agreed value provision (eliminating coinsurance on covered property); business income with extended period of indemnity; blanket limits across locations; completed operations for contractors; and endorsements tied to how the business actually operates. Mid-market accounts (roughly $50,000–$500,000 in annual premium) are typical CPP users; smaller eligible accounts often stay on BOPs; larger accounts may negotiate manuscript primary forms while still layering excess and specialty lines consistently.

Specialty Lines Outside Standard Commercial Forms

Standard commercial forms (CGL, commercial property, commercial auto, workers’ compensation) contain explicit exclusions for risks that require standalone specialty policies. The most commercially significant specialty lines for mid-market accounts:

Professional liability (E&O)

Covers claims alleging financial loss from an error, omission, or negligent act in professional services. The CGL professional services exclusion removes this from GL; a standalone professional liability policy is required for any fee-for-service professional work—architects, engineers, IT firms, consultants, real estate agents, insurance agents and brokers, accountants, and attorneys. Policies are typically claims-made with retroactive dates; tail or extended reporting period coverage matters when coverage ends or the firm closes.

Management liability (D&O, EPLI, fiduciary)

Directors and Officers liability protects individuals and the entity from wrongful acts in management—investor misrepresentation, breach of fiduciary duty, oversight failures, antitrust, securities claims. Private companies see D&O exposure in M&A, shareholder disputes, regulatory investigations, and bankruptcy. Employment Practices Liability covers discrimination, harassment, wrongful termination, failure to accommodate, and retaliation—excluded from CGL and the most frequent management-liability claim category for employers of all sizes. Fiduciary liability covers plan-participant claims alleging ERISA violations in benefits administration.

Cyber liability

First-party coverages include incident response (forensics, legal, notification, credit monitoring), data restoration, business interruption from system outage, ransomware response, and crisis management. Third-party coverages include privacy liability, regulatory defense and fines where insurable, and payment card industry assessments. Underwriting in 2026 still centers on MFA, endpoint detection and response, segmented backups, and patch cadence; carriers also scrutinize social-engineering and funds-transfer fraud driven by AI-generated impersonation—see cyber insurance market evolution: AI-driven threats, deepfake fraud, and emerging coverage models. Stand-alone cyber policies—not thin BOP endorsements—are appropriate when customer data, payments, or operational technology matter to revenue.

Commercial crime and ERISA fidelity

Covers dishonest employee acts including theft, embezzlement, computer fraud, and funds transfer fraud. CGL and standard property forms exclude employee dishonesty; ISO CR 00 20 or equivalent fills the gap. ERISA §412 fidelity bonding is separately required for employee benefit plans—generally 10% of plan assets, capped at $500,000 ($1,000,000 if the plan holds employer securities).

Coverage Gaps and Systematic Review

A coverage gap is an exposure with no paying policy, a sublimit too low for realistic loss scenarios, or an exclusion that removes the peril you actually face. Common mid-market gaps include: flood and earthquake (standard property exclusions—NFIP or private flood and difference-in-conditions endorsements where warranted); cyber and social engineering (assumed “covered somewhere” but excluded or capped on GL and property); hired and non-owned auto when employees use personal vehicles; pollution and mold on older GL schedules; uninsured/underinsured limits on auto in litigious venues; and management liability absent despite boards, investors, or growing headcount.

Run gap analysis at least annually and after material changes—new locations, acquisitions, contract templates, cloud migrations, or capital raises. Compare each exposure line to declarations limits, endorsements, and exclusions; reconcile umbrella underlying schedules so no primary policy is missing from the tower; verify workers’ compensation class codes and experience mod inputs with your payroll reality. Record decisions in a simple coverage matrix owners and risk managers can audit.

Record cat-bond issuance (~$18 billion in 83 deals in the first half of 2026, per Artemis; ~$65.6 billion outstanding mid-year) does not replace your primary property policy, but it shows where peak peril capital is flowing. Coastal and convective-storm buyers should still expect tight terms, higher deductibles, and facultative scrutiny on large schedules.

Coverage Tower Construction

A coverage tower is the layered structure of primary and excess policies that collectively provide total liability limit for a line. Primary policies (CGL, commercial auto, D&O, professional liability) sit at the base with stated per-occurrence and aggregate limits. The umbrella or excess liability policy attaches above underlying primaries and may provide drop-down coverage or self-insured retentions where underlying policies do not respond. Higher excess layers follow form of the layer below.

Illustrative mid-market sizing: CGL often starts at $1 million per occurrence / $2 million aggregate; umbrella commonly $5 million–$10 million for typical accounts and $25 million+ where products, premises, or professional exposure is significant; professional liability often $1 million / $2 million minimum, $5 million+ for larger service organizations; private-company D&O often $2 million–$10 million by revenue, assets, and outside capital, scaling sharply pre-IPO or public; cyber limits track data volume and revenue—roughly $1 million–$5 million for smaller accounts and $10 million–$25 million for mid-market firms with material data or operational technology dependence. Workers’ compensation sits outside the liability tower but belongs in the same program review because payroll growth and classification errors change total cost of risk.

Frequently Asked Questions

What is a Commercial Package Policy (CPP) and how does it differ from a BOP?

A Commercial Package Policy (CPP) combines two or more ISO commercial coverage parts under one common declarations and conditions framework—property, general liability, auto, crime, inland marine, and others—with no BOP-style eligibility cap. A Business Owner’s Policy is a pre-packaged product for eligible smaller businesses with fixed coverage combinations. Mid-market and larger accounts that outgrow BOP eligibility or need endorsements BOPs cannot carry should structure on a CPP.

What is management liability insurance and what coverages does it include?

Management liability is a package of lines protecting directors, officers, managers, and often the entity from claims alleging wrongful management acts. Typical components are Directors and Officers (Side A individual, Side B company reimbursement, Side C entity securities where applicable), Employment Practices Liability (discrimination, harassment, wrongful termination, retaliation), and Fiduciary Liability (ERISA benefit plan administration). These exposures are excluded from standard CGL; any company with a board, outside investors, or employees should evaluate limits annually.

What does cyber liability insurance cover in 2026?

Cyber policies address first-party costs—forensics, legal, notification, credit monitoring, data restoration, business interruption, ransomware response, and crisis management—and third-party claims such as privacy liability, regulatory actions where insurable, and PCI assessments. Carriers expect MFA, EDR, offline or immutable backups, and documented incident plans; many now underwrite AI-enabled impersonation and fraudulent payment instruction separately from classic network intrusion. Limits often run $500,000–$5 million for smaller firms, $5 million–$25 million mid-market, and layered towers above that for enterprises.

How do I find coverage gaps before a loss?

List exposures by location, product, contract, people, and data; map each to a specific policy form and limit; then read exclusions and endorsements on those forms—not just declarations summaries. Test catastrophic scenarios (fire plus business income, auto liability in excess of primary, ransomware plus BI, D&O in a transaction, flood on a leased site). Gaps appear where no form responds, aggregates exhaust, or exclusions remove the peril. Fix with endorsements, specialty policies, or tower increases, and document the rationale.

When does a commercial account need umbrella or excess liability?

Umbrella or excess liability is appropriate when plausible third-party injury or property damage judgments could exceed primary CGL or auto limits, when contracts require higher limits, or when products/completed operations or fleet exposure concentrates severity. Umbrellas also help when underlying policies have mismatched retentions or brief coverage holes if drop-down provisions apply. Match underlying schedules exactly—an unlisted primary policy can void excess attachment when you need it most.

Scroll to Top