The mental model
Terrorism, as an insured peril, has three layers. The TRIA federal backstop sits behind everything — covering certified acts of terrorism above a deductible and within a program-wide cap. The standard commercial property and casualty market provides primary terrorism coverage when buyers accept the TRIA disclosure and pay the modest additional premium. Stand-alone terrorism markets — concentrated in London and Bermuda — provide higher limits, broader perils, and non-certified coverage for buyers who need more than the TRIA-supported primary market will provide.
The line is unusual because it is structurally subsidized. Without TRIA, the actuarial science of terrorism (low frequency, catastrophic severity, undefined attacker behavior) makes it economically impossible to write at sustainable rates. With TRIA, primary carriers can offer terrorism coverage on commercial accounts at a small markup, and the stand-alone market fills the gaps. The two markets coexist because they cover different things — TRIA-supported coverage is broader on certified events; stand-alone covers what TRIA does not.
TRIA is a federal reinsurance program, not an insurance program. It does not pay buyers directly. It reimburses primary insurers for a portion of their certified terrorism losses, which lets primary insurers offer terrorism coverage on commercial policies at viable rates. Without TRIA, the primary terrorism market would not exist at any meaningful scale.
A short history
Before September 2001, terrorism was largely silent in commercial property and casualty policies — neither specifically covered nor specifically excluded. The 9/11 attacks produced approximately $40 billion in insured losses across property, business interruption, life, liability, and workers compensation, the largest insured loss event in history at the time.
The immediate post-9/11 response was capacity withdrawal. Reinsurers exited terrorism almost entirely. Primary carriers introduced terrorism exclusions on commercial property and added terrorism endorsements that excluded coverage by default. Major commercial real estate financings stalled because lenders required terrorism coverage that no carrier would write.
The legislative response
Congress enacted the Terrorism Risk Insurance Act in November 2002. The original act was a three-year program covering certified acts of foreign terrorism above carrier deductibles, with the federal government reimbursing 90% of insured losses above the deductible up to a program-wide cap of $100 billion. The intent was temporary — a bridge until the private market could reabsorb the risk. The private market never did. The program has been reauthorized four times: TRIEA in 2005, TRIPRA in 2007, again in 2015, and most recently in 2019, extending coverage through December 31, 2027.
What has changed across reauthorizations
- Trigger. Originally $5M in insured losses; raised to $50M and then $200M.
- Insurer deductible. Originally 7% of prior-year direct earned premium; now 20%.
- Federal share. Originally 90% above deductible; now 80%.
- Domestic terrorism. Originally only foreign acts qualified; since 2007, both foreign and domestic acts are eligible for certification.
- Cyber inclusion. Cyber terrorism is explicitly within scope of the modern program.
How TRIA actually works
TRIA is layered. The buyer experience and the federal mechanics are different worlds connected only at the claim-payment moment.
From the buyer's perspective
- The carrier offers terrorism coverage in conformance with TRIA. This offer must be made on every commercial property and casualty policy subject to TRIA.
- The buyer either accepts the coverage (typically for an additional premium of 1–5% of base premium) or rejects it in writing. Rejection requires a signed disclosure.
- If accepted, terrorism is included in the policy. If a certified act of terrorism occurs, claims are paid like any other covered loss.
- The buyer never deals with the federal government. The reimbursement happens between the carrier and Treasury, invisibly to the policyholder.
From the federal mechanics
- The Secretary of the Treasury, in consultation with the Attorney General and Secretary of Homeland Security, certifies whether a specific act qualifies as an "act of terrorism" under TRIA. This is a discrete event-level decision.
- Once certified, the program activates if aggregate insured losses across the industry exceed the program trigger ($200M).
- Each participating insurer pays losses up to its individual deductible (20% of prior-year direct earned premium in covered lines).
- For losses above each insurer's deductible, the federal government reimburses 80% of those losses. The insurer absorbs the remaining 20%.
- The program-wide cap is $100 billion. If aggregate certified losses exceed this cap, neither insurers nor the federal government is liable for the excess — losses simply go unpaid.
The mechanics matter because they shape carrier behavior. A carrier with $10B in direct earned premium in covered lines has a $2B individual deductible. If a terrorism event causes $5B in losses to that carrier, the carrier eats the first $2B, the federal government reimburses 80% of the next $3B ($2.4B), and the carrier ultimately bears $2.6B of the $5B loss. The deductible is large enough that carriers care meaningfully about their terrorism exposure — TRIA is a backstop, not a giveaway.
Certified vs non-certified
The distinction between certified and non-certified terrorism is one of the most consequential — and least understood — features of the TRIA architecture.
What "certified" means
An act of terrorism is "certified" under TRIA when the Secretary of the Treasury formally certifies it. The certification requires that the act be committed by individuals as part of an effort to coerce the US civilian population or government, and that aggregate property and casualty losses exceed $5 million (a separate threshold from the program trigger). To date, no event has ever been formally certified — not 9/11 (which predated TRIA), not the Boston Marathon bombing, not the Pulse nightclub shooting, not the Las Vegas shooting. The certification has remained theoretical for two decades.
What "non-certified terrorism" means
Non-certified terrorism is an act that has terrorism characteristics but has not been (or cannot be) certified by Treasury. The Boston Marathon bombing is the canonical example — a clear terrorist act in everyday language, but never certified because total insured losses were below the certification threshold.
Why this matters for coverage
- TRIA-supported coverage responds only to certified events. If an event is not certified, the federal reimbursement does not apply and the carrier's coverage may not respond either, depending on policy wording.
- Most modern policies cover both. When carriers offer terrorism coverage, they typically include both certified and non-certified events in the coverage grant, even though only certified events qualify for federal reimbursement. The carrier absorbs the non-certified portion.
- Some sublimits differ. Some policies provide higher limits for certified events (because TRIA backs the layer) and lower limits for non-certified (because the carrier is on its own).
Coverage language varies meaningfully. Some terrorism endorsements cover only certified events. Others cover both. The certificate of insurance does not usually clarify. Reading the actual endorsement matters when an event occurs — particularly an event with terrorism characteristics that the federal government has not certified.
The opt-in mechanic
TRIA requires carriers to offer terrorism coverage. It does not require buyers to accept it. The offer-and-rejection mechanic creates a small but persistent stream of disclosure paperwork on every commercial renewal.
Required disclosures
- At quote. The carrier must disclose the premium charge for terrorism coverage and the existence of the federal backstop.
- At bind. If the buyer accepts coverage, the disclosure is repeated. If the buyer rejects, a signed rejection form is required.
- At renewal. The disclosure and offer must be repeated annually. Prior-year rejection does not roll forward automatically.
- On certificates of insurance. The certificate must indicate whether terrorism coverage is in place.
Take-up rates
Take-up rates vary by line and by buyer profile. Workers compensation has effectively 100% take-up because terrorism cannot be excluded from workers compensation — the coverage is statutory regardless of TRIA. Commercial property take-up averages 60–70%, with higher take-up among real-estate-heavy industries and lender-financed properties (because lenders require it). Casualty take-up is lower, around 50%, because the actual exposure to terrorism on a casualty policy is less obvious than on a property policy in a major city.
Stand-alone terrorism
The TRIA-supported primary market does not solve every terrorism coverage need. Stand-alone terrorism markets — based primarily in London, Bermuda, and a handful of specialty US carriers — provide an alternative for buyers with specific gaps.
What stand-alone covers that primary does not
- Non-certified events. Primary terrorism coverage may exclude non-certified acts; stand-alone typically covers both.
- Higher limits. Stand-alone markets routinely offer $500M to $1B+ in terrorism limits, well in excess of typical primary capacity.
- Specific perils. Some stand-alone forms cover NBCR (nuclear, biological, chemical, radiological) terrorism, which TRIA-supported primary almost always excludes.
- Active assailant. Stand-alone markets pioneered active assailant / active shooter coverage well before mainstream carriers entered the space.
- Sabotage. Damage from sabotage by individuals who do not meet the certification threshold for "terrorism" is often covered by stand-alone but not primary.
Who buys stand-alone
- Trophy real estate in target cities (NYC, DC, LA, London) where the primary terrorism market does not provide adequate limits.
- Critical infrastructure (utilities, ports, transportation hubs) with exposures that exceed primary capacity.
- Hotel chains, casinos, and entertainment venues with high foot-traffic exposures.
- Multinationals with foreign operations not covered by the US TRIA program.
- Government contractors and defense suppliers.
How the placement works
Stand-alone terrorism is wholesale-placed business. The retail broker engages a wholesale broker, who slips the risk to London, Bermuda, or US specialty markets. Pricing is bespoke — there is no published rate. Major placements may take weeks to fill the layer, and lead underwriters set terms that following markets adopt without significant variation. The Lloyd's terrorism syndicates (Hiscox, Beazley, Talbot, Lancashire, and others) are the historical core of the market.
NBCR and the exclusions
NBCR — nuclear, biological, chemical, radiological — represents the catastrophic tail that almost no insurance program covers. The losses from a major NBCR event would dwarf the entire global insurance industry's surplus. Insurance does not pretend otherwise; the exclusions are explicit and broad.
The standard exclusions
- Nuclear exclusion. Damage caused by nuclear reaction, radiation, or radioactive contamination is excluded from virtually every commercial property and casualty policy, with or without terrorism context. The exclusion predates TRIA by decades.
- Biological / chemical exclusion. Most terrorism endorsements explicitly exclude biological and chemical agents. Some specialty markets buy back portions of this exclusion for specific buyers (large pharmaceutical companies, hospitals).
- Radiological exclusion. Distinct from nuclear; covers dirty bombs and other dispersed radioactive materials. Also broadly excluded.
- Cyber-physical. A grey area. A cyber attack that causes physical damage may or may not be covered depending on the policy form and the specific cause of loss exclusions.
Why the exclusions persist
The math is straightforward. A major NBCR event would produce losses in the hundreds of billions to trillions of dollars. The global property and casualty industry's total surplus is approximately $1 trillion. Insuring such an event would not transfer risk — it would simply move the certain bankruptcy of every participating carrier to the moment of the event. The exclusions exist because the alternative is industry collapse.
The TRIA-NBCR question
TRIA does not require carriers to cover NBCR. It also does not require carriers to exclude it. In practice, carriers exclude NBCR even when they offer terrorism coverage, and TRIA reimbursement applies only to the perils the carrier actually wrote. The federal backstop is not a backdoor to NBCR coverage.
Adjacent perils: cyber, active assailant
The terrorism category does not have hard edges. Two adjacent peril categories overlap with terrorism in ways that matter operationally.
Cyber terrorism
TRIA explicitly includes cyber as a potentially certifiable act of terrorism. A state-sponsored cyber attack causing significant insured losses could, in principle, be certified by Treasury. None has been. Cyber insurance policies typically include their own terrorism language — usually covering acts of cyber terrorism but excluding war (the distinction matters for state-sponsored attacks). The NotPetya attribution to Russia and the resulting war-exclusion litigation (Merck v. ACE) is the canonical example of the boundary problem.
Active assailant / active shooter
Mass-casualty events involving firearms or vehicles are typically not certified as terrorism (the certification threshold is high, the political bar for attribution is high), so they fall outside the TRIA architecture. Active assailant coverage emerged as a distinct line in the mid-2010s, pioneered by Lloyd's and now offered by US specialty markets. The coverage typically includes property damage, business interruption, victim counseling, crisis management, and certain types of third-party liability arising from the event. Common buyers: schools, hospitals, faith-based organizations, retail, hospitality, large employers in target geographies.
Civil disorder and riot
Distinct from terrorism but often confused with it. Riots, civil commotion, and looting are standard insured perils under most commercial property policies (unlike terrorism, which historically required affirmative buy-in). The 2020 civil unrest produced approximately $2B in insured losses across major US cities — meaningful but absorbed by the standard market without TRIA involvement.
Where IDP earns its keep
Terrorism is a small slice of any individual commercial submission, but it is universal — every commercial property and casualty submission generates terrorism disclosures, offers, acceptances or rejections, and certificates. The volume of compliance paperwork is significant and most of it is structurally identical across submissions.
Indico use cases
- Disclosure audit. Validate that every TRIA-eligible policy in a portfolio has a signed acceptance or rejection on file and that the disclosure was made at quote, bind, and renewal as required.
- Endorsement-variant matching. Identify which terrorism endorsement (certified-only, certified + non-certified, NBCR carve-back) is attached to each policy and flag mismatches between policy and certificate.
- Stand-alone slip extraction. Pull the structured data from London terrorism slips into the carrier's internal record so the stand-alone layer is reconciled against the primary policy.
- Concentration mapping. Aggregate terrorism-exposed property values by geocoded location to identify accumulation in target cities, target buildings, or proximity zones.
For a portfolio underwriter or compliance team, the per-submission terrorism workflow is low-stakes but high-frequency. Automating the disclosure audit and endorsement-variant matching eliminates a recurring source of compliance findings without consuming underwriter time. The accumulation modeling is the higher-value play — when a portfolio underwriter can see terrorism-exposed TIV by location in seconds rather than days, the underwriting conversation changes.