Risk Profile

Office Building

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

Risk profile for an office and administrative building (single or multi-tenant): the risk attributes typically assessed in underwriting and the resulting commercial insurance programme architecture.

Risk picture

Office and administrative buildings are comparatively low-hazard occupancies dominated by ordinary combustibles (furniture, fit-out, paper, IT equipment) rather than industrial process risk, so loss frequency and severity are typically driven by building age and construction, electrical installations, water damage from pipework, and visitor/tenant liability exposures in common areas, lobbies, lifts and car parks. Multi-tenant buildings add landlord liability and business interruption complexity because a single incident (fire, water damage, power loss) can force evacuation or closure across several unrelated occupiers. Networked building management systems and office IT infrastructure also expose the property owner and its tenants to a growing cyber and data protection dimension.

Risk attributes to capture

The table below is generated from this profile’s linked risk attributes and grouped by category; see the individual attribute pages for underwriting logic, evidence requirements and mitigation measures.

Coverage architecture

Employee accident cover is compulsory in Switzerland (UVG) wherever staff are employed, and general/building owner’s liability covers third-party bodily injury and property damage claims arising from the building and its common areas. Property all risks forms the core of the programme, covering the building fabric, fixed installations and, where applicable, tenant improvements. Business interruption becomes relevant wherever rental income or the insured’s own administrative operations depend on continued use of the premises, and cyber cover is increasingly warranted given networked access control, building management and office IT systems that process personal and business data.

Prevention

Loss prevention priorities are sound electrical installation maintenance and inspection, access control and video surveillance covering entrances, car parks and sensitive areas (server rooms, records storage), and a documented backup strategy with multi-factor authentication for IT systems and building management platforms. Water damage prevention (pipe condition, leak detection in risers and plant rooms) and clear evacuation and fire safety management for a multi-occupancy environment round out the core measures.

Kind
Object

Risk attributes to capture

Building

  • Building Floor Area — Building floor area records the footprint and total gross floor area of a building, and is queried in property proposal forms to size fire compartments, accumulation and probable maximum loss.
  • Construction Class — Construction class categorises a building by the combustibility and fire resistance of its structural materials, and is queried in property proposal forms to gauge fire severity potential and set base rates.
  • Number of Storeys — Number of storeys records the vertical extent of a building above and below ground, and is queried in property proposal forms because it affects fire and smoke behaviour, evacuation and firefighting access.

Security

  • Access Control System — Access control system records the method by which entry to a location or to sensitive areas within it (server rooms, cash offices, hazardous storage) is restricted and logged, as queried in property and cyber insurance proposal forms to assess unauthorised-access exposure.
  • Video Surveillance Coverage — Video surveillance coverage records the extent to which a location's perimeter, entrances and vulnerable areas are monitored by a CCTV system, as queried in property insurance proposal forms to assess deterrence and post-loss investigation capability.

IT/Cyber

  • Backup Strategy and Offline Copy — Backup strategy and offline copy records how frequently an organisation backs up critical data and whether at least one copy is kept offline, air-gapped or immutable, a decisive control against ransomware queried in cyber proposal forms.
  • Multi-Factor Authentication — Multi-factor authentication records whether privileged, remote and email access to an organisation's systems requires more than one independent authentication factor, a baseline control queried in virtually every cyber insurance proposal form.

Coverage architecture