In this article, I suggested the disappointing outcome of the Vatican sexual abuse summit might yet be helpful if:
slow movement by Rome in developing a comprehensive, global approach to dealing with abuse means the Church in the US stops waiting for Rome; and
extends its existing global leadership role in developing abuse prevention mechanisms into developing a truly comprehensive framework to manage abuse risk in all its dimensions.
In a comment to that article, I was asked my thoughts on a meaningful coverage approach to sexual abuse risk. And since, like environmental and employment practices liability before it, Sexual Misconduct Liability (SML) is just now beginning to emerge as a stand-alone insurance from its evolution as one of many GL exposures, now is a good time to think about that.
To answer the question directly, I think there are 4 stages to talk about.
Where SML:
has come from;
is now;
needs to go; and
could go.
Where has SML come from?
SML is still emerging from GL. Most SML is still available as an occurrence-based coverage as part of a GL or broader package approach. Stand-alone SML coverage on the other hand reflects that intermediary stage coverages go through as they are ejected from GL and before their own policy has ‘found itself’. SML therefore currently finds itself in the temporary home of a repurposed E&O policy. Environmental, EPLI and even cyber liability have all followed this well-trodden path before.
Among the issues to consider when buyers look at SML, the following have always – and continue to – require attention:
Distribution
If you really need SML, do you buy a package policy or stand-alone coverage?
Package policies sometimes have low limits but not always, their language is designed to deal with a whole load of unrelated liability exposures, and SML claims handling can be less than expert.
Stand-alone policies tend to have higher limits, though capacity is currently limited. Policy language is better tailored to SML though is currently still far from perfect. Claims handling is also, currently, likely to be more aggressive than expert.
So, the question is: do you really need stand-alone SML? We would argue that anyone responsible directly or indirectly for children or vulnerable adults does because, as far as stand-alone SML policies still need to develop, they already offer more and better protection against increasing settlement demands than package or GL based policies. Where settlement demands used to start at $1m even just a few years ago, Catholic bad press, #metoo, and 9 figure settlements in religious, healthcare, and educational settings mean demands now start at $5m or $10m per victim. And with the increasing frequency of multiple victim/claimant scenarios, limit adequacy is a growing problem in the marketplace.
Coverage trigger
Currently, you can buy either claims made or occurrence SML but which is best? As we argue below, neither claims made nor occurrence is ideal for SML but…
Occurrence is really only available now in GL or package policies and the extent of the SML coverage in these policies is beginning to be restricted. For example, United Educators recently tightened up their prior SML knowledge provisions considerably. Claims made coverage is not yet being offered by sufficient numbers of carriers to fill the gap being created between reducing occurrence coverage and increasing settlement demands.
Occurrence based coverage is extremely effective when used for GL policies because it’s very purpose is to protect organizations from emerging risks no one is thinking about when the policy is written. But as a catch all approach, it’s one size fits all language doesn’t work as well as new risks are identified and as their characteristics become better understood. As is happening now with abuse risk…
Structure
If you have a choice, do you buy per perpetrator or per victim coverage? Per perpetrator coverage aggregates all claims about a single perpetrator into the year the first victim was abused or made a claim, though there are variations on these themes. The intent in most cases is to cap the insurer’s exposure by capturing all claims about a perpetrator into a single policy year. The limits under these policies tend to be low but, if you are buying SML only to comply with a contractual requirement to do so, this is probably a reasonable, and usually the lowest cost, approach.
Per victim coverage means every claim by a victim is treated as a stand-alone claim on the basis that victims make their claims when they are ready to do so, though social media has naturally impacted this aspect of the exposure. SIRs for per victim coverage tend to be higher than per perpetrator coverage but since the per perpetrator limits are often so inadequate (for example $1m and sometimes even less), a higher SIR is the price that has to be paid for an adequate limit.
Limit
Do you want to buy primary or primary and excess coverage? As noted above, an issue of some concern now is how much excess limit can you find. Also, the premium factors insurers use to rate higher layers in an SML program are increasing. You also need to think about how well different insurers work together, in particular in terms of following forms and claims handling.
Given increasing settlement demands and the possibility of more than one victim in almost any scenario, we are coming to the view that $10m is the minimum limit an organization that is responsible for children or vulnerable adults should have.
Retroactivity
Are you happy with little or no retroactive coverage, some, or do you want/need a lot? The premium factors insurers use to calculate SML retro coverage are also increasing.
Coverage
Is your exposure to abuse liability only – the risk you will be held liable for someone committing abuse – or are you required to manage the risk and therefore need to insure risk management liability (for example, failure to observe a mandatory reporting requirement) as well?
Claims handling
How expert are you and how active do you want to be in claims handling? Some insurers leave all claims handling to their insured clients. This works well for the few entities who really know what they are doing because they litigate abuse cases regularly. Most insurers aim to assume control of claims handling but this only works well for those clients who really have no expertise, experience or resources. For everyone else, some form of collaborative approach works better.
Prior knowledge
Do you think you may have to deal with, for example, the unknown victims of a known perpetrator? And how do you deal with – and even, how do you define – a credible allegation? Some policies do not exclude claims by the unknown victims of known perpetrators, as long as the abuse wasn’t committed after the abuser was first known as such. And some policies can be written to recognize the difference between an unfounded and a credible allegation; as forms of continuity, both these issues make a bigger difference the longer coverage is in force.
Where is SML now?
In terms of current coverage trends, now is a scary time for any insurer to be offering SML coverage. More high-profile high settlements, deteriorating public trust, and the resulting increased threat of window legislation mean some insurers are reducing limits, some are adding coverage restrictions and new exclusions, and some are exiting the religious and ‘Higher Ed’ spaces altogether. And of course, some are also increasing premiums. The most important thing is what we are not seeing; in the last 3 or 4 years we have only seen two new entrants into the SML marketplace.
We think there are a few reasons for this.
Reputation risk:
No insurers have so far been brave enough to offer a new policy into a marketplace where all the current publicity around how the risk has been managed in the past, how the risk is managed today, and the exposure this poses to an insurer are irredeemably negative. Notwithstanding high margins and profitability, insurer reluctance is understandable.
Increasing frequency of severity:
Abuse risk is showing signs of both increased frequency and increased severity. The underwriting strategies noted briefly above are designed to deal with these. The bigger problem is that abuse risk is also showing signs of increased frequency of severity – the increasing risk of more, bigger losses. It is this more than any other reason that is causing the abuse risk landscape to change and to cause SML’s ejection from GL coverage.
Windows:
‘Windows’ are fixed periods of time (usually one to three years) when an individual State statute of limitation is ‘lifted’, allowing claimants to bring claims which would otherwise be time barred. So far, 6 States have enacted window legislation.
California offers the clearest example of the threat windows pose. In the California Dioceses we know about, there were over 850 claims, which included a sharp spike in claims for current abuse – which we define as abuse committed in the 5 years before it is discovered – and in claims where the window wasn’t necessary for the claim to be made. Settlement values averaged $1.65m (in 2019 $) for each victim.
We know less about the window for the Archdiocese of Saint Paul and Minneapolis in 2013 but publicly available information points to 450 victims and a settlement of $210m. If Minneapolis was consistent with California, maybe 10% of Minneapolis’s claims would have been for recent abuse.
The result of the threat of windows is that insurers would rather avoid offering SML coverage altogether than try to guess which States to avoid in the near term, where so many States seem to be considering windows and windows can, in insurance terms, open up with relatively little notice.
Where might SML coverage go?
That isn’t an easy question to answer; like so many questions, “it depends…” For example:
It depends whether the question is limited just to the Catholic Church or across religious and other sectors. Though abuse risk is highest in the Church, it is still significant – and appears to be increasing – across all sectors. It also depends if you are talking about long past abuse, abuse cover-ups, or current abuse. Each poses different issues as far as risk management and insurance are concerned.
It depends if your objective is to address abuse that happened 50 years ago, over the last 5 years, or which could happen next week. Or all of them… It also depends if you are in a State where window legislation is being talked about and you are trying to do everything you can to reduce the chance that the window will be opened. It depends if you want to buy an all-encompassing policy or you want coverage tailored to your exposure.
It depends if you are one of the Dioceses that has already been through bankruptcy and so have limited financial exposure to claims for abuse pre-dating your bankruptcy (the financial exposure is of course not the main exposure but it is the exposure insurance deals with most – currently at least).
It depends what you think will happen in the future – most obviously around window legislation. Windows have been discussed most frequently in the context of the Catholic Church but the impact of windows will be felt far further afield. Broadly, we see 3 possible future window scenarios:
1. The current situation persists:
In a continuation of what is happening now, individual States will continue to implement window legislation piecemeal over the course of the next 5 to 10 years.
The threat from this scenario is material because, unless something positive is done to counter it, more windows over an extended period of time will just mean more litigation, more negative press, mounting losses, further deterioration in trust, and more uncertainty – and therefore higher insurance premiums – for many years to come. Further, while this scenario persists, it increases the likelihood of one of the more damaging ‘worst case’ scenarios described below coming to pass.
2. Worst cases:
Either: The ‘Baltimore Letter” (described in this Washington Post article), or something else like it, finally allows plaintiff’s attorneys to pierce the veil between Rome and US Dioceses, leading Rome to call on US Dioceses to fund/contribute significantly to its defence and possible settlements;
Or: The recently instigated Federal investigation into abuse leads to a nationwide window.
A nationwide window implementation is quite unlikely but, for the Church, it would be catastrophic – potentially globally if Rome were somehow brought within its ambit. Many more Dioceses would be forced to declare bankruptcy and Church owned insurers could also be wiped out. Reinsurance and excess capacity might also abandon the Church – or at least become horribly expensive.
It is safe to assume that many skilled plaintiffs’ attorneys are working hard to achieve precisely these objectives.
3. Best case:
All further window legislation is mothballed by specific action taken by institutions managing abuse risk to restore the public’s trust. This outcome cannot happen without some coordinated action, which is not currently evident.
Some effective action is happening – notably in the form of voluntary compensation schemes by Dioceses mainly in the US North East. But impressive as these efforts are, they are limited to the Catholic Church and, even there, don’t go far enough.
So, what do we mean by coordinated action? We think the kind of coordinated action required to have a serious chance of reducing the risk of further window legislation is the broad adoption of risk management practices that are demonstrably best practice. You might reasonably ask why that isn’t already in place…
Currently, abuse risk is predominantly managed using sets of ‘policies and procedures’ and ‘codes of conduct’. This causes 2 problems.
While all policies and procedures require that certain actions are taken, few sets of policies and procedures offer any help in suggesting how, never mind how best, each action should be performed. We have dealt with too many claims where compliance with policies and procedures has been confused with risk management, leading to avoidable abuse and high claim settlements.
Policies and procedures are what risk managers do to treat risks. ‘Treating risks’ is one of (depending on the framework) 4 or up to 8 other stages of a best practice risk management process. As sensible as many policies and procedures are, the most appropriate ones to implement and the best ways to implement them remain unknown in the absence of the context that a full best practice risk management process delivers.
The bottom line is that it is currently not possible to restore trust in abuse risk management because there is no way for an abuse risk manager to identify what they need to do to be worthy of trust. That is where we think abuse risk management should go and we think SML can actively support this objective.
Where we think SML needs to go
Before getting to where SML ‘could’ go, we must first talk about where we think SML needs to go.
We indicated above that stand alone SML coverage started life as a re-purposed E&O, then EPLI policy. This was because of the similarities between the 3 exposures. To consider “a meaningful coverage approach to sexual abuse risk” in the future, we need to look not just at how SML is similar to other risks but how it differs.
1. E&O policies are triggered by claims. This is a problem for SML because so much of the damage suffered by a victim, and therefore the severity of an SML claim, comes from the abuse being compounded by risk management failures which fail to prevent the abuse, to identify the abuse quickly, or to look after the victim fully after the abuse is discovered. Put simply, because abuse (despite the headlines) is rare, few organizations have the resources or experience to deal with it.
We think this means a SML policy trigger must be designed to deliver expert incident investigation and response services when they are most needed – not when a claim is made but when potential abuse is first discovered. Apart from clearly being in the victim’s best interests, it is in the insured and insurer’s best interests too.
2. In view of the above, we don’t think “occurrence” or “claims made” triggers work for sexual abuse risk; neither responds fast enough to events on the ground. The delay is the result is liability insurance’s focus on litigation management as the most effective way of managing severity. But litigation management is a distant fourth in terms of priority when it comes to looking after victims and managing abuse risk severity because prevention, identification and victim response can all prevent abuse, claims, and litigation in the first place.
Note: there are claims that arrive in an insured’s mail with no prior knowledge that abuse has occurred. Claims made coverage is of course necessary for these claims.
3. SML has more, and a different kind of, severity potential than EPLI.
First, a small number of abusers are preferential abusers who abuse multiple victims; 95% of abusers (even at the height of the crisis) were situational abusers (who abuse only once and when the situation allowed). As much as failing to prevent, identify and respond to abuse exponentially compounds both damage and therefore severity, multiple victims compound the impact of risk management failures even more.
Second, victims make claims when they are ready to do so. It is no small act of bravery to come forward and every victim takes their own time to become ready to do so. This means that claims about the same perpetrator can continue to be made over several years and policy periods.
This creates both a severity and a knowledge problem:
Severity – the multiple victims of one perpetrator can bring claims over several years – impacting and/or totalling limits for 2, 3 and in one case we saw, over 4 years.
Knowledge – when buyers look to renew coverage after a new perpetrator has first been identified, they must rely on an insurer’s goodwill to keep renewing which few insurers can be relied on to do absent language compelling them to do so.
What does this mean for coverage? SML policies should be designed to capture all claims by the victims of a single perpetrator under 1 policy so future renewals can be free of the exposure of more claims about the same perpetrator but with sufficient time for victims to come forward and with sufficient limits to settle all the claims from all the victims.
4. For too long, defending sexual abuse claims has been a cottage industry with variable capabilities and little coordination between defense firms – or even between insured, insurer and defense firms. This has led to higher defence costs than necessary, some too high settlements, and unintended precedential consequences.
But it is not just that some defense has been poor; defense firms have often had too little to work with because defensibility has been so compromised. Many defense strategies are limited to trying to excuse or explain away evident risk management failures with little or nothing positive to contrast these with that shows evidence of a systematic and iterative best practice risk management process.
Where we think SML could go…
One of the more frustrating aspects of conversations we have with attorneys in terms of defensibility concerns whether or not it is a good idea for an insured to be told when their risk management is less than ideal. The frustration stems from a fundamentally different world view attorneys have compared to risk managers:
For an attorney, their risk manager client having too much information increases risk because their client cannot be held responsible for failing to respond to something they didn’t know.
For a risk manager, having too little information increases risk because they can’t, for example, repair a control deficiency unless they know about it.
It is our view that, if you are primarily concerned with protecting children, you ought to worry less about defensibility and more about doing everything possible to protect children in the first place. Which itself increases defensibility…
But that is all well and good only if risk managers can get to the information they need to make good decisions about how best to protect children and get the information necessary to implement their well-informed decisions effectively.
Today, risk managers don’t have access to that information.
Which is why, as important as writing SML coverage to acknowledge abuse’s characteristics, not E&O or EPLI’s characteristics, and as important as embedding investigation and response services into SML coverage both are, neither go far enough whether the objective is child protection or risk manager defensibility.
The most important deficiency now is the information risk managers need to identify what they can do to protect children as effectively as possible and so be worthy of the trust that is currently lacking in abuse risk management.
But, because the information risk managers need to manage abuse risk effectively is the same information insurers need to offer meaningful abuse insurance, there is an alignment of interests between the two.
As information development and deployment goes well beyond coverage, we will save the discussion about what information is lacking, why, and how risk manager and insurer interests can be better aligned for our next post.
