D&O Renewal 2026: Governance Evidence Underwriters Want

Fintech, crypto, and VC-backed buyers often pay 2-3x mainstream D&O rates (Price Forbes 2025). Renewal questionnaires probe AI, cyber, and ESG governance. A versioned glossary is one artifact to show.

In brief. Price Forbes' 2025 D&O market update reports that fintech, crypto, and VC-backed buyers "often pay two to three times higher rates than mainstream peers". WTW and Allianz Commercial separately flag AI, cyber, and ESG governance as live pricing themes for 2025-2026 placements. Renewal questionnaires probe governance evidence, not just policy existence. A four-eyes-approved, version-controlled terminology record is one concrete artifact a CFO can cite.

Why the questionnaire changed

D&O underwriting used to be a balance-sheet conversation. In 2025-2026 it is increasingly a governance conversation. WTW's Directors and Officers Liability: A Look Ahead to 2025 identifies crypto and AI-exposed organizations among the more challenged classes, and underwriters increasingly expect boards to describe how they oversee those exposures, not just acknowledge them. Allianz Commercial's Directors and Officers Insurance Insights 2025 names AI washing and litigation funding among the active themes shaping the market.

For a CFO at a fintech, crypto, or VC-backed company, the stakes show up in basis points. Price Forbes' 2025 D&O market update states that these risk classes "often pay two to three times higher rates than mainstream peers". The rate is set by the market, but the file is set by the buyer. Underwriters compare submissions, and the files that read as defensible win better outcomes on both rate and capacity.

What underwriters actually ask

Read any recent D&O renewal questionnaire and the same themes recur. On AI: how does the board understand the company's AI use, and what governance exists over the claims made in disclosures. On cyber: who owns incident definitions and how quickly the organization can produce a consistent record of what was disclosed when. On ESG: how the company keeps its external statements aligned with internal definitions of scope, materiality, and progress. On directors' duty of oversight: evidence of active, documented involvement, not acknowledgement.

The shift shows up in the source material: Allianz Commercial's 2025 D&O briefing singles out AI washing and third-party litigation funding as active themes, and underwriters increasingly treat documented governance evidence as a differentiator in renewal discussions rather than a nice-to-have.

The CFO's stake

D&O renewal is not a procurement item. It is the instrument that sits between the CFO's personal assets and a shareholder or regulator action. When capacity tightens or retentions widen, the CFO's protection narrows. When a questionnaire answer is thin, capacity goes first and price follows. The 2-3x premium differential Price Forbes reports for fintech, crypto, and VC-backed buyers is a revenue-and-margin problem before it is a governance problem, and it lands on the CFO's P&L and, ultimately, on the CFO's personal balance sheet.

The audit-committee version of the same story is that directors increasingly expect to see the CFO bring artifacts, not assertions, into the renewal meeting. A questionnaire answer that points to a live, version-controlled system of record travels better than one that references an undated policy document.

Where terminology governance fits

Compliance Glossary does not replace a governance program, a cyber control framework, or an ESG reporting function. It is narrower and more concrete. It is a Confluence-native record of how the organization defines regulated terms, who approved each definition, and when they changed. For the parts of a D&O questionnaire that ask about AI governance, cyber definitions, and ESG language, a single artifact covers multiple answers.

  • Four-eyes approval. Every term definition requires a second approver who is not the submitter, producing the dual-control evidence underwriters associate with mature governance.
  • Version history. Every change to a regulated term is preserved, so the CFO can show exactly how the company defined "high-risk AI system", "material cyber incident", or "Scope 3 emissions" at any point in time.
  • Audit trail with timestamps. Who changed what, when, and why is attributable at the individual level, aligned with the ALCOA+ principles the company would apply in a regulated-data context.
  • Compliance scanner. Detects where deprecated or unapproved terms still appear across Confluence spaces, so external disclosures draft from internal ground truth.
  • CSV export with full version history (PDF audit-package export on the 2026 roadmap). Produces a clean, timestamped record to attach to the renewal questionnaire or to share directly with the broker.

For current pricing, see the Atlassian Marketplace.

This is a partial-fit product. We are honest about that. An audit-trailed glossary is not a substitute for a cyber program, for AI model risk management, or for ESG assurance. It is a governance artifact that answers specific terminology-and-disclosure questions in the questionnaire without forcing the CFO to fabricate process where none exists.

Frequently asked questions

Why do fintech, crypto, and VC-backed companies pay 2-3x more for D&O?

Price Forbes' 2025 D&O market update states that fintech, crypto, and VC-backed buyers often pay two to three times higher rates than mainstream peers, driven by risk-class, regulatory scrutiny, and litigation exposure. WTW separately identifies crypto and AI-exposed organizations among the most challenged classes heading into 2025, and underwriters increasingly require documented governance evidence to justify rate or capacity.

What kind of governance evidence do D&O underwriters ask for?

Renewal questionnaires request evidence that the board and management oversee AI use, cyber risk, and ESG disclosure. Underwriters look for documented policies, named approvers, version history, and audit trails for how the company defines and controls regulated terminology in disclosures, not just the existence of a policy document.

Can Compliance Glossary reduce our D&O premium?

No vendor can promise a rate reduction. Compliance Glossary provides a concrete, auditable artifact a CFO can cite in the governance-evidence section of a D&O questionnaire: four-eyes approval on every definition, full version history, and timestamped audit trail across AI, cyber, and other regulated terminology your team loads. Underwriters reward evidence, not assertions. Any rate outcome still depends on the underwriter's full view of the submission, not a single artifact.

How does the pricing compare to a D&O premium increase?

For current pricing, see the Atlassian Marketplace.

Bring an artifact to your next renewal

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading