Steve Hourigan is founder and CEO of HeardSafe, Inc., which builds governance signal infrastructure, and has served on more than twenty boards. Full bio at the end of the article.
Editor’s note: This article uses terminology from the specialist world of professional-liability insurance. For readers who do not work in insurance, the following definitions may help.
Captive insurer: An insurance company established or controlled by a Big Four firm or network to cover part of its own professional-liability risk.
Retention: The portion of a claim that the firm or its captive must absorb before external insurance kicks in.
Reinsurance: Insurance bought by the captive from outside insurers to transfer part of its risk.
Excess tower: Layers of external insurance that cover progressively larger losses above the captive’s retained amount.
Soft pricing: A market in which professional-liability insurance remains relatively inexpensive despite the potential for very large claims.
Network firewall: The legal separation between individual Big Four member firms and the international coordinating entity.
Key Takeaways
Big Four captives may face rising exposure as professional-liability claims become more severe.
The article argues that firms often identify warning signs before claims emerge, but fail to escalate them quickly enough.
As captives retain more risk, earlier intervention becomes more financially valuable.
The proposed solution is to treat internal warnings as underwriting intelligence and measure how quickly they reach people with authority to act.
The Big Four’s captive insurers are carrying a severity problem that the headline insurance market is not yet pricing. When it is priced, the captives will hold more of the loss, and the cheapest place to reduce that loss is before the incident, not after it.
Each firm’s professional liability programme runs through its own in-house insurer, typically domiciled in Bermuda or the US, which retains the first layers and cedes the rest to reinsurers. That structure works well when claims are frequent and modest. It works less well when a single claim can run into billions, when the global network itself is now arguably in the dock, and when reinsurers start asking why the same pattern of missed warnings keeps appearing in the evidence.
The severity record
Three recent matters show how large the claims have become, and how often they turn on warnings that existed but were not acted on.
The provisions tell the same story. EY UK set aside a record £188m for fines and legal claims in its latest accounts. The firm, like its peers, relies on an in-house insurer that passes part of the risk to external providers.
The phrase that recurs in the pleadings is “red flags.” The allegation is rarely that nobody could have known. It is that the signal was there and did not travel.
The ceiling question
Historically, auditor settlements have landed at a small fraction of the claims. NMC’s £105.5m was roughly 5% of the £2bn pleaded. The largest public outcomes top out at a few hundred million dollars per matter, and the biggest cases settle mid-trial on confidential terms.
It is tempting to credit the network firewall for that gap. It is not the main reason. In NMC, Colonial, MF Global and Carillion, the defendant was the auditing member firm itself. Three other forces did most of the work.
What is collectible. A member firm is a partnership with limited capital and a finite insurance tower. One former Arthur Andersen in-house lawyer estimated PwC US could absorb about $3bn in payouts over a short period (Mullin Hoard Brown). In MF Global, it was unclear whether PwC could pay even a fraction of the $2bn in losses attributed to it (Forbes).
Defenses. Auditors argue that management fraud bars or reduces recovery. PwC argued in Taylor Bean that the executives’ illegal conduct left the trust unable to collect under Florida law.
Opening numbers. Claims are pleaded high, and even judgments are discounted. Colonial’s $625m award settled for $335m to avoid an appeal.
This is why Evergrande matters. The firewall does not suppress claims; it caps the pool a claimant can reach at one national partnership’s capital and insurance. If the Hong Kong court finds that the global entity owes a duty of care, that ceiling moves to the network, and settlements could be sized against network-wide resources.
The global coordinating entities are themselves companies limited by guarantee with little capital of their own. So, the practical question becomes what insurance sits behind the network. How each firm’s captive is structured is not public, but captive boards should be asking whether a network-level duty would land on programs priced around member-firm risk.
Soft pricing is hiding a severity problem
On the surface, the professional indemnity market is benign. Brokers report rate reductions of 5–10% for claims-free firms in 2026 (Bellrock). But claim frequency is stable while severity keeps rising, so loss costs can outpace renewal pricing, especially on long-tail claims (Mordor Intelligence).
That gap is where a captive gets hurt. Bermuda markets are already deploying capacity selectively, with typical lines of $5–10m (AmWINS). A single billion-dollar claim, or a finding that a global network entity owes a duty of care, can prompt reinsurers to reprice the excess tower or ask the captive to retain more.
Either way the captive’s retention rises. When it does, every dollar of loss avoided in the retained layer is a dollar the firm keeps. The economics of prevention change sharply once the firm is effectively insuring itself.
Every claim begins as an internal warning
Claims departments see a matter when it is notified. By then the loss is largely fixed. The more useful moment is earlier: when an audit senior first doubts a client’s figures, a manager questions a partner’s judgment, or a staff member sees something that does not sit right.
Big4News readers have watched this pattern play out. At KPMG Australia, a whistleblower’s disclosure was first handled as a personnel matter, then passed through an internal investigation and external reviews before the firm accepted in July 2026 that a central allegation was substantiated. The escalation to KPMG International was declined on the basis of the legal separation between the global organization and the member firm. At Wirecard, as Pav Gill told this publication, the warnings existed inside the company years before the collapse.
In each case the information existed. What failed was routing: how the warning was classified, who controlled its path, and how long it took to reach someone with the independence and authority to act. That interval is measurable, and it is where captive losses are made or avoided.
What a pre-incident early warning system requires
A hotline is not an early warning system. It waits for someone to decide to become a whistleblower, and most people who notice a problem never make that choice. A system that protects a captive’s retained layer needs five features.
Solicited signal. It asks engagement teams, on a regular schedule, about the specific risks that drive claims: pressure from clients, unresolved audit differences, doubts about evidence. It does not wait for a report.
Independence at intake. The signal is received and synthesized outside the reporting line of the partners it may concern, ideally through outside counsel so the synthesis can be protected by privilege.
Delivery to both sides. Findings reach firm leadership and the board, or the captive’s risk committee, at the same time, so management is informed rather than bypassed.
Measured latency. Every signal carries a clock: when it first appeared, when it was escalated, when it was closed. The interval is the metric.
Pattern, not person. The value lies in patterns across engagements and member firms, which is exactly what a network entity cannot see today and may now be asked about in discovery.
For a captive, the output is underwriting intelligence it currently lacks: a forward-looking view of where the next notification is likely to come from.
What captive boards and reinsurers should ask now
Captive directors and the reinsurers behind them do not need to wait for the next billion-dollar claim to test this. Four questions will show where a programme stands.
When an engagement team member doubts a client’s figures, how long does it take for that doubt to reach someone who can stop the audit opinion?
Who decides how an internal warning is classified, and can that classification be downgraded by people it implicates?
Can the network entity see patterns of warnings across member firms, and if not, what will it say when discovery asks what it knew?
Does the captive receive any pre-notification signal at all, or does its view of risk begin at the claim?
If the answers are unclear, the captive is pricing its retention on history alone. In a market where severity is rising faster than premiums, that is the most expensive place to be.
The firms that shorten the distance between the first warning and the first action will carry lower retentions, negotiate better excess terms, and spend less on reputational repair. The rest will keep finding their red flags in the pleadings.
Sources
Hong Kong High Court judgment / case text
Bloomberg Tax — NMC Health v EY
The Irish Times — Carillion v KPMG
The Guardian — Carillion settlement
Global Legal Post — MF Global v PwC
Going Concern — Colonial Bank settlement
SEC — Avis Budget 2007 Form 10-K
Mullin Hoard Brown — PwC/Colonial Bank analysis
Forbes — MF Global/PwC settlement
Bellrock Advisory — July 2026 PI market update
Mordor Intelligence — Professional Indemnity Insurance Market
AmWINS — State of the Market 2026 Outlook
This article is part of the Big4News Investigations & Analysis series, which examines the structural forces shaping Deloitte, PwC, EY and KPMG.
It is also highly relevant to the PwC Evergrande case and the $8.4 billion lawsuit.
About Steve Hourigan
Steve Hourigan is founder and CEO of HeardSafe, Inc., which builds governance signal infrastructure, including systems of the kind described in this article. He has served on more than twenty boards.
His book in progress, The Trust Record, examines 13 governance failures through the lens of signal latency: the time between when an organization first knows something and when someone with authority acts on it. Using a timed framework (T0–T5), it traces how each warning travelled, stalled or was reclassified on its way up, and argues that most failures come from routing rather than malice or ignorance. One chapter is devoted to KPMG Australia.
Firms need a timed record of their own warnings because every regulator, court and liquidator eventually asks the same question: what did you know, and when? Most firms can only answer after the event, reconstructed under pressure; The Trust Record shows how to measure the answer while there is still time to act on it.









