Our Process

The Avanti Group Process

Most business owners don’t find out their insurance is wrong until a claim happens. By then, it’s too late.

We work with high performing business owners who understand that fast quotes and cheap policies don’t protect wealth. Before we quote anything, we run a Business Risk Diagnostic™—a pre-quote due-diligence process that identifies hidden exposure, stress-tests coverage against real operations, and surfaces gaps most agents never look for.

Business Risk Diagnostic™ includes:

Step 1
Risk Mapping: entity structure, operations, vehicles, payroll/class codes, subcontractors, contracts, locations, real estate, and ownership/lease exposure

Step 2
Coverage Stress Test: audit current policies against actual risk scenarios to find gaps, overlaps, and “looks fine on paper” failures

Step 3
Market Positioning: ensure the account is being represented correctly to carriers and priced for your true risk profile—not assumptions

The result is clarity: what you’re actually exposed to, what your current coverage does (or doesn’t) protect, and whether moving forward even makes sense—before anyone wastes time on quotes that don’t matter.

For many of my business clients, risk doesn’t stop at the company. The largest uninsured exposures we see often live on the personal balance sheet—homes, liability, collections, and lifestyle risk. That’s why we also run a Residential Risk Audit™ for clients whose personal assets require the same level of scrutiny as their businesses.

We don’t lead with carriers, quick quotes, or generic bundles. We lead with risk.

If you’re looking for the cheapest option, we’re probably not the right fit. If you value clarity, strategy, and protection that actually holds up when something goes wrong—we should talk.

What we look for in a Business Risk Diagnostic

Several of the line items the Business Risk Diagnostic examines are covered in depth on the Avanti Group blog. These articles map to the specific exposures, policy lines, and renewal-strategy questions we review during a Diagnostic:

  • Total Cost of Risk: The Number That Should Replace Your Premium — The number that includes premium, retention, claims cost, and the cash trapped in collateral.
  • Loss Runs Explained: What Underwriters See That Owners Often Don’t — Five years of loss data, read the way an underwriter reads it.
  • How to Read a Commercial Insurance Declarations Page Without Missing the Sublimits — What’s actually on the dec page—and the lines that decide what gets paid.
  • Coinsurance Penalties on Commercial Property: The Clause That Quietly Cuts Claim Checks — How the coinsurance formula trims a claim check when valuation drifts.
  • Additional Insured Status on Commercial Liability Policies: What It Actually Buys You — What CG 20 10 / 20 37 actually grants—and what it doesn’t.
  • Why the Cheapest Commercial Quote Is Usually the Most Expensive Policy — Three Iowa-style scenarios where the lowest premium hid the largest gap.
  • Captive vs Guaranteed Cost vs Large Deductible: Risk Financing Compared — Three risk financing structures side by side—when each one fits and when it stops making sense.
  • Policy Language That Quietly Limits Your Coverage: Sublimits, Exclusions, and Conditions — Three places a commercial policy quietly limits coverage—sublimits, named exclusions, and conditions.
  • What General Liability Insurance Actually Covers and What It Doesn’t — The three coverage parts of a CGL, the named exclusions, and how per-occurrence and aggregate limits cap what gets paid.
  • Per-Occurrence vs Aggregate Limits: Why the Math Matters — Two stacked limits on every CGL — per-occurrence caps a single event, the aggregate caps the policy year, and the math is where renewals get decided.
  • Products and Completed Operations Coverage: The Long-Tail Risk Every Manufacturer and Contractor Faces — A separate coverage trigger with its own aggregate, a tail that runs years past the job — and the Iowa statute of repose that finally closes it.
  • The Purpose of a Subcontractor Agreement: Risk Transfer Beyond the Certificate — Indemnification, additional insured, waiver of subrogation, and primary/non-contributory — the four operating clauses that turn a contract into real risk transfer.
  • How to Demand and Verify Certificates of Insurance from Subcontractors — A COI is a snapshot, not a contract — three endorsements turn it from paperwork into protection.
  • How Landlords Use Certificates of Insurance to Manage Tenant Risk — Lease, endorsement, certificate — the three-document system that decides whether tenant risk transfer actually holds.
  • General Liability vs Professional Liability: When You Need Both — Two non-overlapping commercial coverages, two triggers, two standards of care — and the professional services exclusion that decides which policy actually pays.
  • Damage to Property in Your Care, Custody, or Control: The Coverage Most GL Policies Exclude — The CCC exclusion strips coverage for property of others in the insured’s possession — and the fix is an inland marine placement, not another GL extension.
  • Iowa Workers Compensation Requirements Every Employer Should Know — Iowa Code Chapter 85 makes WC mandatory for nearly every employer — here is what the law requires, who is exempt, and what happens to an Iowa business that goes without.
  • Action Over Claims: When an Injured Worker Sues a Third Party Who Then Sues You — The exclusive remedy bars the employee from suing the employer — but not the third party who then sues the employer for the same injury. Part Two Employers’ Liability and CGL contractual liability are how the program actually responds.
  • Workers Comp Class Code Mistakes That Quietly Raise Your Premium — NCCI class codes route every payroll dollar into an injury-risk pool; misclassification quietly raises premium, and the annual audit is where the cost arrives.
  • Return-to-Work Programs That Actually Lower Your E-Mod — Modified duty converts lost-time claims into medical-only claims and shortens indemnity duration — the most direct operational lever a business has on its own experience modifier.
  • Workers Comp for Contractors Who Hire Seasonal Help — Seasonal crew is covered payroll, not an exception — here is how to estimate, classify, and document seasonal labor before the workers comp audit reconciles the year.
  • D&O for Private Companies: Why It’s Not Just a Public Company Product — Directors and officers insurance is not a public company product: private company owners, officers, and board members are sued personally by employees, customers, co-owners, creditors, and regulators over the decisions they make running the business, and neither the corporate structure nor a general liability policy protects their personal assets when that happens — the claims land in the gap GL was never designed to fill, and Side A, Side B, and Side C divide the protection between the individuals and the entity. First article in the Management Liability cluster.
  • D&O Side A, Side B, and Side C Explained — A directors and officers policy is three coverage agreements stacked inside one form: Side A pays individual directors and officers directly when the company cannot or will not indemnify them, Side B reimburses the company for indemnifying its people (how most claims actually pay), and Side C covers claims against the entity itself — and because the three sides usually share one policy limit, order-of-payments provisions and a dedicated Side A DIC layer exist to keep entity defense costs from eroding the protection of the individuals. Second article in the Management Liability cluster.
  • EPLI Claims Trends: Wage and Hour, Retaliation, Harassment — The employment claims hitting businesses hardest fall into three categories: retaliation, the most common basis in EEOC charges every year since 2009 and now appearing in more than half of all charges filed; harassment, which carries the largest settlements and reputational cost; and wage and hour, the coverage trap — excluded from most EPLI forms or covered under a small defense-costs-only sublimit — with Iowa’s Civil Rights Act reaching employers at just four employees, far below Title VII’s fifteen. Third article in the Management Liability cluster, first on the EPLI sub-hub.
  • EEOC Charges: The First 30 Days — An EEOC charge is an administrative complaint, not a lawsuit — but it is the mandatory first step toward one, and the first thirty days set the trajectory: preserve every relevant record under a litigation hold, notify the EPLI carrier before spending a dollar on lawyers (the charge itself, not the eventual suit, is the claims-made trigger), work with carrier-appointed panel counsel, and treat the position statement as a document that follows the case for years — with Iowa’s parallel ICRC track reaching employers at just four employees and a 300-day filing window. Fourth article in the Management Liability cluster, second on the EPLI sub-hub.
  • EPLI for Restaurants: The Highest-Frequency Sector — Restaurants generate more employment practices claims, more often, than almost any other class of business — a young, hourly, high-turnover, tipped workforce managed by supervisors promoted off the line — and tipped wages are the most dangerous exposure on the menu: tip-credit notice failures, side-work disputes, and manager participation in tip pools scale a single payroll error into a collective action, while standard EPLI forms exclude wage-and-hour claims entirely or cap them at a modest defense-only sublimit; third-party coverage for customer harassment and Iowa’s $4.35 tipped minimum and four-employee ICRA threshold round out what a restaurant placement must answer. Fifth article in the Management Liability cluster, third on the EPLI sub-hub.
  • Indemnification Basics for Officers and Board Members — Indemnification is the company’s promise to cover its directors and officers for the costs of claims arising from their service — but under Iowa Code chapter 490 most of it is permissive rather than mandatory (only a wholly successful defense must be reimbursed), bylaws can be rewritten by whoever controls the board next, and the promise fails outright at insolvency, refusal, or legal prohibition; a bilateral indemnification agreement with mandatory advancement locks the promise in, and Side A D&O coverage — including dedicated Side A DIC limits — is the backstop for non-indemnifiable loss. Sixth article in the Management Liability cluster, third on the D&O sub-hub.
  • Crime, Employee Dishonesty, and Social Engineering: Three Policies, One Loss — Employee dishonesty coverage pays when your own people steal; social engineering coverage pays when an outsider deceives an authorized employee into sending funds willingly; cyber pays when systems are breached — the same missing dollars can implicate all three, and which policy responds turns on exactly how the money left: the crime form’s separate insuring agreements and the discovery vs loss-sustained trigger, the manifest-intent standard for employee theft, the voluntary-transfer gap that keeps computer fraud coverage from paying deception losses, the routinely sublimited social engineering endorsement with its verification-procedure conditions, and the vendor-email-compromise seam where crime and cyber can both stay quiet. Seventh article in the Management Liability cluster, fourth on the EPLI sub-hub.
  • Fiduciary Liability for Businesses That Sponsor a Retirement Plan — Fiduciary liability insurance covers the owners, officers, and committee members who run a company’s retirement plan against personal liability for how it is managed — imprudent investment selection, unmonitored fees, administrative errors — exposure the federally required ERISA bond does nothing to insure (the bond protects the plan against theft and pays the plan, never the fiduciaries), standard D&O excludes, and ERISA’s anti-exculpation rule keeps corporate indemnification from fully answering; excessive-fee litigation has moved steadily down-market, ERISA preempts any small-employer carve-out, and even a pooled employer plan leaves the sponsor the duty of selecting and monitoring the provider. Eighth article in the Management Liability cluster, fourth on the D&O sub-hub — closes the cluster.
  • Ransomware Coverage Gaps: Sublimits, Coinsurance, and Exclusions — Most cyber policies do not pay ransomware losses up to the headline limit — a ransomware sublimit typically aggregates the extortion payment, negotiator, forensics, restoration, and sometimes the downtime loss under one reduced cap; cyber coinsurance shares every covered loss with the insured no matter how much limit was purchased (unlike the property-side penalty mechanism); and the exclusion families that surface in real claims — security-maintenance conditions tied to the application’s answers, end-of-life software, and state-sponsored-actor language — can shrink or erase recovery, while the softened mid-2026 market means businesses with MFA, EDR, and tested offline backups can frequently buy full limits without coinsurance if the account is positioned to today’s market instead of auto-renewing the hard-market form. Opens the Cyber Liability cluster.
  • Social Engineering and Wire Fraud: Why Most Cyber Policies Sublimit It — Social engineering losses leave through channels that look legitimate — an authorized wire, an approved vendor, a routine payment run — which is why cyber policies cap them at a sublimit far below the headline limit and make verification procedures a condition of coverage; UCC Article 4A (Iowa Code ch. 554) allocates fraudulent-wire losses to the business rather than the bank, and the controls that persuade underwriters to raise the cap — callback verification, dual authorization, banking-change waiting periods — are the same ones that prevent the loss. Second article in the Cyber Liability cluster.
  • Business Email Compromise: Anatomy of a Six-Figure Loss — A BEC loss is an authorized payment procured by deception — assembled from weeks of reconnaissance inside a compromised vendor mailbox, executed through a routine payment run where every indicator reads normal — and the coverage analysis turns on deception and verification rather than network intrusion: cyber social engineering sublimits, crime endorsements, breach-response coverage when a mailbox is compromised (including Iowa Code chapter 715C notification duties), and the verification controls that both prevent the loss and preserve the coverage. Third article in the Cyber Liability cluster.
  • Cyber Insurance for Healthcare: HIPAA-Aligned Policy Structure — Healthcare cyber coverage has to be engineered around HIPAA’s fixed obligations from the start: the Breach Notification Rule’s 60-day machinery mapped to specific insuring agreements, regulatory proceedings coverage for OCR investigations and the insurability of fines, business associate agreement (BAA) vendor exposure and Iowa Code chapter 715C’s parallel state notification track, and the patient-harm seam between cyber and medical malpractice coverage. Fourth article in the Cyber Liability cluster, first vertical piece (healthcare).
  • Cyber Insurance for Manufacturers: OT, IoT, and Downtime — A manufacturer’s cyber loss lands on the production floor, not the front office: operational technology (PLCs, SCADA, industrial control systems) that the eroding ‘air gap’ no longer protects, cyber business interruption terms — waiting period, period of restoration, how lost production is measured — that decide whether a stopped line is actually covered, bricking coverage for equipment rendered functionally dead, and the physical-damage seam where cyber policies exclude tangible property and property policies never contemplated an electronic cause of loss. Fifth article in the Cyber Liability cluster, second vertical piece (manufacturing).
  • Cyber for SaaS and Tech Companies: What Underwriters Expect — Cyber underwriters read a SaaS company’s controls before its revenue — a tech E&O and cyber program structured as one placement (one carrier, one form, one set of definitions) so a single outage can’t be split into two partial denials; customer-contract data promises and indemnities read against the policy’s contractual liability language; and documented controls — MFA on email, remote access, and privileged accounts, tested segregated backups, EDR, and a rehearsed incident response plan — that now move terms, retentions, sublimits, and insurability itself, while a SOC 2 report corroborates the underwriting file without replacing it, and the softened mid-2026 cyber market rewards exactly the documentation discipline the hard market demanded. Sixth article in the Cyber Liability cluster — the cluster’s underwriter-expectations piece.
  • What Most Insurance Reviews Miss — Four-part framework most agents skip — the gap between a 15-minute renewal stamp and a real diagnostic.
  • 3 Questions to Ask Your Current Agent at Renewal — The three questions that force any agent to prove they’ve been paying attention — or reveal where they haven’t.
  • The 12 Months Between Renewals: When to Call Your Agent — Most insurance gaps form in the 363 days between renewals. The short list of life and business changes that should prompt a call now.
  • Why We Wrote Your Quote the Way We Did — Two insurance quotes on the same risk are rarely the same coverage. The philosophy behind a diagnostic-first quote.

Begin Your Business Risk Diagnostic™

Click the button below to head to our quotes page where you can enter some basic information to have our team help with your insurance!

Ready to get started?

Start Your Quotes Today

Enter some basic information below to get the process started.

Service Options