3 min read

Asia's tightening regulatory landscape: the impact on D&O claims

Read more

By Ross Risby & Andrew Robinson

|

Published 28 September 2026

Overview

As regulatory frameworks across Asia tighten and the cyber security landscape becomes increasingly under scrutiny, we continue to see a rise in D&O claims as a result. Although capacity remains available and pricing may still be favourable in parts of the market, directors and officers are operating against a backdrop of less forgiving regulatory enforcement, geopolitical instability, economic uncertainty, and fast-moving technology risk. A corporate incident can now move quickly from an operational issue to a regulatory investigation, shareholder action or allegation of personal liability. 

In Hong Kong, China, Singapore, and across Southeast Asia, the regional focus on safe, credible and well-regulated markets remains central and regulators continue to place greater emphasis on enforcement, governance, and individual accountability. Recent regional commentary points to a higher level of regulatory examination particularly in financial services, digital assets, artificial intelligence, cybersecurity, market conduct, and corporate governance. 

In Hong Kong, regulatory developments and disciplinary action continue to highlight that directors and officers may face scrutiny where internal controls, disclosure or reporting processes fail. Across the wider region, regulatory updates have also placed renewed emphasis on governance, consumer protection, operational resilience, data protection, and technology risk.

In Singapore, recent changes introducing higher penalties for breaches of directors’ duties and strengthening the focus on board-level cybersecurity oversight illustrate the move towards greater personal responsibility for directors and officers.

As regulatory frameworks tighten, investigations are placing greater focus not only on the conduct of the company, but also the decision-making of senior management. Directors and officers may be required to respond to regulatory inquiries, produce documents, attend interviews, and defend allegations of misconduct. The cost of that process can be significant, particularly where the investigation becomes the platform for subsequent shareholder or derivative claims. 

Similarly, a significant cyber event can lead to business interruption, loss of customer or investor confidence, damage to the company’s public profile and, for listed companies, share price volatility. These consequences can prompt scrutiny of the board’s decisions, preparedness, internal controls, disclosure framework, and response to the incident. Where regulators investigate the company’s approach, or shareholders allege failings by directors, the incident may give rise to a D&O claim. While not every cyber incident will result in a D&O claim, the prospect of shareholder, regulatory or other third-party action may be enough to constitute a circumstance under the policy. 

In response to regulatory development, boards across the region are also assessing the adequacy of their insurance cover. Companies are more closely reviewing internal processes to ensure compliance with regulatory requirements to reduce the risk of claims. Many insureds are using favourable market conditions not only to reduce pricing, but also to improve the certainty and breadth of cover available to them. Particular attention is being given to regulatory language, the coordination of D&O, FI and PI cover, broader investigation costs protection, entity investigation extensions, separate limits for investigations, and automatic reinstatement provisions after a significant investigation. 

Underwriters are conducting more detailed enquiries into the quality of an insured’s risk management strategy at inception and renewal, with a greater focus on how a company prepares for and responds to regulatory investigations and cyber incidents. Insurers are likely to continue to focus on governance structures, the allocation of responsibility for technology and data risk at board or senior management level, incident response planning, board reporting, escalation procedures, disclosure protocols, and the extent to which previous incidents or regulatory issues have been addressed. 

Regulatory investigations and cyber incidents therefore remain significant sources of D&O exposure in Asia. For insurers, a rise in investigations and cyber-related incidents is likely to create more complex coverage issues and increase claims costs, particularly where an incident results in regulatory scrutiny, shareholder litigation or both. In that environment, underwriting discipline, careful assessment of governance and cyber resilience, and clear policy language are likely to assume even greater importance. 

Authors