Insurance Topic

Scheduled Vendor Endorsement

A scheduled vendor endorsement is a cyber insurance policy amendment that identifies specified third-party vendors or service providers for purposes of defined dependent business interruption coverage.

Definition

A scheduled vendor endorsement is an amendment to a cyber insurance policy that identifies one or more third-party vendors, service providers, suppliers, technology platforms, or other external dependencies whose qualifying technology disruption may satisfy the policy’s requirements for dependent or contingent business interruption coverage. The endorsement establishes a defined relationship between the listed third party and the insured’s dependent-loss provisions.

The scheduling mechanism narrows the relevant third-party dependency to specifically identified organizations rather than automatically treating every external vendor as a covered dependency. Whether a loss associated with a scheduled vendor qualifies remains subject to the applicable policy definitions, covered-event requirements, limits, waiting periods, retentions, exclusions, and causation provisions.

Structural Components

  • Scheduled vendor: A specifically identified third-party organization on which the insured depends for goods, services, technology, infrastructure, processing, or another defined operational function.
  • Dependent coverage provision: The underlying policy language establishing the circumstances under which interruption originating at a third party may produce a covered dependent loss.
  • Qualifying event: The policy-defined security failure, system failure, cyber event, or other specified occurrence that must affect the scheduled vendor.
  • Dependent interruption: The resulting impairment or interruption of the insured’s operations caused by the qualifying event affecting the scheduled vendor.
  • Coverage limit or sublimit: The maximum amount applicable to covered loss associated with the scheduled vendor or dependent business interruption provision.
  • Waiting period or retention: The contractual threshold that may apply before covered dependent interruption loss is measured or payable.

Parameters & Conditions

Application of a scheduled vendor endorsement depends on both the identity of the affected third party and the nature of the event affecting that third party. Scheduling a vendor generally establishes that the vendor is recognized for purposes of the applicable dependent coverage provision, but it does not independently establish that every interruption involving that vendor satisfies the policy’s coverage trigger.

The policy may distinguish between interruptions caused by malicious security events and interruptions caused by non-malicious system failures. It may also establish different limits, sublimits, waiting periods, or other conditions according to the type of event or the particular vendor listed in the schedule.

Scheduling may occur by individual organization name, by a specifically described provider, or through another designation permitted by the insurer’s form. The operative wording determines whether coverage applies only to scheduled dependencies or whether scheduled vendors receive treatment different from other third-party providers.

Topic Relationships

Exceptions, Limitations & Boundaries

A scheduled vendor endorsement does not necessarily provide blanket coverage for every outage, cyber incident, or operational disruption involving a listed vendor. The event must satisfy the applicable policy definitions and other conditions governing dependent coverage.

The endorsement is distinct from an additional insured endorsement. Scheduling a vendor for purposes of dependent business interruption identifies an external dependency relevant to the insured’s own loss and does not, by itself, grant insured status to that vendor.

The endorsement is also distinct from insurance carried by the vendor itself. Listing a vendor does not transfer the vendor’s own liabilities to the insured’s policy and does not establish the scope of insurance maintained by the vendor.

Policy structures vary. Some cyber policies provide dependent coverage for broadly defined classes of third parties without requiring individual scheduling, while others restrict some or all dependent coverage to specifically identified providers. The applicable contract controls the classification and scope.

Scheduled Vendor Endorsement: Definitional FAQ

What is a scheduled vendor endorsement?
A scheduled vendor endorsement is a cyber insurance policy amendment identifying specified third-party vendors or service providers for purposes of defined dependent business interruption coverage.
What does it mean for a vendor to be scheduled?
A scheduled vendor is specifically identified within the applicable endorsement or policy schedule as a third-party dependency recognized under the corresponding coverage provisions.
Does scheduling a vendor mean every outage involving that vendor is covered?
No. Scheduling establishes the vendor’s specified status under the policy, while coverage for a particular interruption remains dependent on the defined event, causation requirements, limits, waiting periods, exclusions, and other contractual conditions.
Is a scheduled vendor endorsement the same as an additional insured endorsement?
No. A scheduled vendor endorsement in the dependent-business-interruption context identifies a third-party operational dependency, while an additional insured endorsement grants specified insured status to another person or organization under defined policy provisions.
Do all cyber policies require vendors to be scheduled?
No. Policy structures differ; some dependent coverage provisions recognize broadly defined third-party providers, while others restrict coverage or particular limits to specifically scheduled vendors.
Scroll to Top