Teplov CPA Complimentary Review

Insurance Claims, Deductibles, and Business Records

A cyber or E&O insurance claim creates its own record-keeping and tax questions, separate from the premium deductibility already on file.

Read time
~ 5 min

Deductibility of insurance premiums, covered in insurance, E&O, cyber coverage, and deductibility, is usually the easy part. What is less routine, because most consultancies only encounter it occasionally, is what happens on the books once an actual claim is made: a deductible payment, a settlement, or a payout that needs its own tax treatment and its own records, separate from the annual premium.

The Deductible Is a Business Expense, With Its Own Documentation Trail

When a covered incident occurs, a data breach, a client dispute triggering an E&O claim, or a cyber liability event, the policy deductible or any uncovered portion of the response cost is generally deductible to the corporation on the same basis as any other business expense, provided the underlying incident relates to the business.

Where this differs from an ordinary expense is the documentation expected to support it. A routine software subscription needs a receipt and a brief note of business purpose. A deductible paid following an insurance claim benefits from a fuller record because it sits at the intersection of an insurance event and a tax deduction, and either the insurer or CRA may ask for the full picture:

  • the incident report or notification that triggered the claim
  • the insurer’s claim number and the policy it was filed under
  • correspondence confirming what the policy covered, what it excluded, and the deductible amount applied
  • the invoice or cost record for the deductible payment or any expense the insurer did not cover
  • the final settlement or claim-closure statement

Keeping these together, rather than filing the deductible payment as a standalone expense disconnected from the claim it relates to, is what makes the expense defensible as a genuine insured-event cost rather than an unexplained one-off charge.

What Happens to a Payout

The tax treatment of money received from an insurer depends entirely on what the payout is compensating for, not on the fact that it came from an insurance company.

Reimbursement of a deducted expense. If the corporation already deducted a breach-response cost, forensic investigation, client notification, credit monitoring, and the insurer later reimburses some or all of it, the reimbursement is generally included in income when received. The net effect across the two transactions, the deduction and the later reimbursement, is roughly neutral, but both sides need to be recorded. Booking only the deduction and never recording the reimbursement as income when it arrives understates income in the period the payout lands.

Compensation for business interruption or lost income. A payout under a business interruption component of a cyber policy, compensating for revenue lost while systems were down, is generally taxable as income, the same as the revenue it is standing in for would have been.

Compensation for damaged capital property. A payout for a damaged or destroyed asset, hardware lost or destroyed as part of an incident, generally reduces the cost of replacement property or is treated as proceeds of disposition under the capital cost allowance rules, rather than being taxed directly as ordinary income. This ties back to the technology equipment and CCA treatment of the asset itself.

Treating every insurance payout the same way, as either automatically tax-free or automatically fully taxable, is the error that shows up most often. The correct treatment depends on identifying which of these three categories, or combination of them, the specific payout falls into.

Insurance settlements themselves are generally outside the scope of GST/HST, since an insurance payout is not consideration for a taxable supply. Where GST/HST does come into play is on the underlying goods or services purchased as part of the claim response, replacement equipment, third-party incident response services, or legal fees, which are taxed normally as purchases and generate input tax credits in the ordinary course, independent of how the insurer ultimately reimburses the cost.

Booking the Claim Across a Fiscal Year End

Claims involving a data breach or a liability dispute frequently take months to resolve, and it is common for the underlying cost to be incurred in one fiscal year while the insurer’s decision and payout land in the next. Both halves of the transaction should still be tracked as connected even when they fall on either side of a year-end:

  • the deductible or uncovered cost is recorded as an expense in the period it is incurred, regardless of when the claim is expected to settle
  • a claim in progress at year-end, with a reasonably expected recovery, may warrant a receivable if the recovery is virtually certain, a determination worth confirming with a CPA rather than assuming by default
  • the reimbursement, once received, is recorded as income in the period it is actually received or becomes receivable, not backdated to the period the original expense was incurred

Splitting a single claim’s expense and reimbursement across two different tax years without a clear paper trail connecting them is a common source of confusion when a return is reviewed later, since the two entries can look unrelated without the underlying claim documentation to tie them together.

Scope of This Guide

This guide covers the tax treatment and record-keeping for insurance deductibles and payouts once an actual claim is made by a Canadian cybersecurity consultancy. It does not cover:

  • Policy selection, coverage limits, or claim negotiation, which are insurance and legal questions
  • Personal insurance claims unrelated to the business
  • QST-specific treatment for Quebec-based claims, which generally mirrors the federal GST treatment but should be confirmed separately

This is general information, not advice for a specific claim. A CPA reviewing your actual claim and settlement documents can confirm the correct tax treatment for your file.

Alex Teplov, CPA · Last updated: August 2026

Alex Teplov is a CPA registered with CPA Ontario. This article is for general informational purposes only and does not constitute professional accounting, tax, or legal advice. It does not create an accountant-client relationship. A professional engagement with Teplov CPA is established only through a signed engagement letter. Tax law, CRA administrative positions, and provincial rules change frequently. Information in this article may not reflect the most recent developments. Do not make financial or tax decisions based solely on this content. Consult a qualified CPA for advice specific to your situation.

Alex Teplov, CPA
About the author
Alex Teplov, CPA

Teplov CPA helps Canadian IT professionals with tax, bookkeeping, and compliance. You’ll communicate directly with me. I remain your primary contact throughout the engagement, so you can bring questions, changes, and decisions to someone who understands your file.

About Alex
Browse the library

All Resources

Guides on tax, GST/HST, incorporation, and CRA compliance for Canadian IT contractors.

View all guides
Get professional advice

Work with Teplov CPA

Guides cover general rules. Your file involves details that general guidance cannot address.

Talk to a CPA

Want a second opinion?

Complimentary Tax and Compliance Review for Canadian IT Professionals

If you’re a Canadian IT professional, you can request a complimentary review of your most recent tax and compliance position.

Request a Complimentary Review
Get started

Questions about your tax position?

Teplov CPA works with Canadian IT contractors on tax planning, CRA compliance, and incorporation.

Book a 15-minute introduction