The excitement of a successful closing often masks a less glamorous financial reality: buying a company also means buying its past mistakes. For a CFO or a scale-up leader, an external growth operation is a powerful development lever, yet it introduces a dangerous permeability. If the target has poorly managed its risks or undersized its coverages, the entire acquiring group can find itself exposed to old claims or sudden operational failures. The objective is not just to verify the existence of insurance contracts, but to ensure that these will not become unforeseen cost centers that eat away at the deal’s profitability.
The Trap of the Classic Financial Audit
During the due diligence phase (the deep examination of accounts and legal status before purchase), attention naturally gravitates toward EBITDA columns, asset quality, and the solidity of client contracts. Insurance is too often relegated to a simple line of general expenses in the profit and loss statement. This approach is risky because it ignores the very nature of latent liability. A company can present healthy accounts while carrying a ticking time bomb in the form of inadequate professional indemnity insurance (the insurance that covers your liability if a client blames you for an error in your service).
We regularly observe acquirers who settle for checking that premiums are paid. However, the real issue lies in the alignment between the target’s actual business activity and the guarantees purchased. If a software company has pivoted from a consulting model to a SaaS (software as a service) model without updating its guarantees, it is simply not covered for its current activity. By integrating it into the group, you import this legal vacuum. A relevant analysis requires a change of perspective: instead of looking at the insurance contract, we start by analyzing the specific risks of the target's business model to see if the existing contract can actually address them.
Contamination by Historical Liabilities
The most insidious risk in an acquisition is "contamination." This happens when an incident occurring before the takeover is only discovered after the integration. In most liability contracts, it is the date of the claim that triggers the guarantee. If the target had insufficient coverage or if it changes insurers at the time of the merger, certain claims (the covered incidents) can fall into a blind spot. You could find yourself forced to compensate a client using the group's equity because the target's contract was terminated too quickly or poorly negotiated.
You must be particularly vigilant regarding the insurance that protects your personal assets if a shareholder or an employee holds you personally liable (Directors and Officers liability, or D&O). During a takeover, the former leaders of the target often exit the equation, but their past decisions can still lead to legal action. Without a "discovery period" or "run-off" clause (an extension of coverage that handles future claims for past events), the acquiring group is left to manage disputes that do not concern it directly but impact its balance sheet and its reputation.
"External growth is not just about adding up revenue figures; it is a merger of liabilities where the weakest link defines the security level of the entire group."
Auditing to Rebuild Rather Than Just Validate
At Lesto, we reason in reverse compared to the market: we start with the risks, then we find or build appropriate coverage. For a company in the middle of an integration, this approach is the only viable protection. The audit of the target must focus on three operational pillars. The first is contractual compliance. This involves checking whether the commitments made by the target to its clients (in terms of compensation limits or service restoration times) are actually covered by its insurance. A gap between a contractual promise and the reality of the insurance is a hidden debt.
The second pillar concerns the structure of deductibles (the portion you pay out of pocket in case of a problem). A target may display very low insurance premiums simply because it has accepted disproportionate deductibles. For the acquiring group, this means that every small operational incident will be paid out of pocket, directly impacting post-integration cash flow. Finally, the third pillar is the claims history. Beyond the reimbursed amounts, it is the frequency and nature of incidents that reveal the maturity of the target's internal processes. A high number of small incidents related to cybersecurity is often the sign of a fragile technical infrastructure that will need to be rebuilt at great expense.
Merging Programs Without Creating Blind Spots
Once the acquisition is finalized, there is a strong temptation to immediately switch all the target’s assets to the parent company’s insurance program to simplify management. While this consolidation often allows for economies of scale and increases the overall level of guarantees, it must be handled with caution. A sudden transfer can lead to a break in coverage for past activities. The recommended method is to maintain the target's policies in force during a transition phase while negotiating automatic inclusion clauses in the group contract.
You must also pay close attention to the limits of guarantee (the maximum amount the insurer will reimburse). By adding a new entity, the group’s revenue and overall exposure increase. If your limits remain the same, you mechanically reduce your relative protection. A group that generated 50 million euros in revenue with a 5 million limit is better protected than a consolidated group of 100 million keeping that same limit. The merger is the ideal time to reassess the needs for guarantee limits based on the new critical size of the organization.
Integration as an Opportunity for Rationalization
Despite the risks, the integration phase is a unique opportunity to improve the risk culture within the new group. By auditing the target, you often highlight areas of fragility that also exist within the acquirer. This is the time to standardize contract management processes and impose common security standards, particularly in terms of cyber-protection. The insurance program then becomes a management tool that reflects the growth strategy rather than just an administrative constraint.
The success of a merger from a risk perspective depends on the finance department's ability to not delegate insurance to a simple executing broker. You need a partner capable of understanding the technical specificities of the business to anticipate points of friction. Balance sheet protection is not played out when the incident occurs, but months earlier, during the integration negotiations. By treating insurance as a strategic asset rather than an expense, you ensure that the value created by the acquisition does not evaporate at the first sign of litigation.
If you are preparing an external growth operation and want to secure the integration of your future target, we can support you in auditing its operational risks.
Tags
- #M&A
- #acquisition
- #risk-management
- #integration
- #group-insurance

Julien Falémé
Co-founder
Julien Falémé is the co-founder of Lesto, the next-generation insurance broker for SMEs. After several years in B2B tech sales (Riot, Theodo Group), he founded Lesto with the conviction that SME founders deserve the same level of risk analysis as large corporations.
LinkedIn →