An excess of loss layer says nothing until you have defined what it calls a loss. The same program, on the same portfolio, on the same facts, produces recoveries differing tenfold depending on whether the attachment applies to each risk hit or to everything one event destroyed. It is the definition of a loss, not the size of the attachment, that decides what the cedant really carries.
In a per-risk layer, every policy hit is a loss in its own right. The attachment applies as many times as there are risks affected. A windstorm damaging two hundred separately insured houses produces two hundred losses, each compared to the attachment, and if that attachment is 500,000 euros while the damage runs around 20,000, none of them reaches it: the layer pays nothing although the cedant has lost 4 million. A per-risk layer protects against one large individual loss, never against an event that makes many small ones.
In a per-event layer, all losses arising from the same event are added together first, and the attachment applies once to that total. On the same facts and the same 500,000 attachment, the aggregated 4 million pierces the layer comfortably. That is the structure bought against windstorm, flood and earthquake, and it is the one commonly called catastrophe cover.
What remains is the hard question, and it is entirely a matter of drafting: what is one and the same event? Is a storm sweeping a country for three days one event or three? A series of aftershocks spread over a week? The answer is not deduced from meteorology, it is read in the treaty, and the instrument that gives it is the hours clause. It sets a window, often seventy-two hours for windstorm and one hundred and sixty-eight for other perils, inside which all losses from the named peril are deemed to arise from a single event.
The hours clause almost always gives the cedant the right to choose when the window starts, and that right is the most concrete lever it holds. Over a ninety-hour episode, no seventy-two hour window contains everything: the cedant therefore decides where to place its own, and it places it where it captures the most damage. What falls outside the window is not lost for that, it forms a second event, with a second attachment to pierce and a limit to reinstate.
That ability to slice cuts both ways, and the arithmetic is done before notifying. Two events mean two attachments paid by the cedant, but also twice the limit available, if reinstatements allow. A single event means one attachment only, but one limit only, and possible exhaustion. On an episode that runs well past the top of the program, the cedant is often better off with two events; on a middling episode, almost always with one. So one does not notify in the order of the days, one notifies after running both calculations.
That choice is not discretionary for all that, and two guardrails bound it. The window does not move after the fact as developments arrive: it is anchored on dated facts, and a reinsurer watching a window drift along with the estimates would have every reason to dispute it. And one loss cannot fall inside two windows, which forbids counting the convenient damage twice. The hours clause is an instrument of qualification, not of optimization, and its anchoring date is the whole difference between the two.
From January 8 to 11, 2026, a depression crosses a region and costs an insurer 6.4 million euros of damage, spread as follows: 1.1 million on the 8th between 2 p.m. and midnight, 3.6 million on the 9th and 10th, 1.7 million on the 11th up to 6 p.m. The insurer carries a layer of "5 million excess of 2 million" per event, with a seventy-two hour clause at the cedant's election and one reinstatement. There is no layer above. How should the window be placed?
The episode spans roughly one hundred hours, so no seventy-two hour window can contain all of it and a choice must be made. The first option is a single window opened on the 8th at 2 p.m., running to the 11th at 2 p.m. and capturing 1.1 plus 3.6 plus the part of the 11th falling before 2 p.m. Assuming the 1.7 million of the 11th spread evenly to 6 p.m., that brings about 6 million inside the window. One event of 6 million, attachment of 2, the layer pays 4 million and the cedant keeps 2 million plus the 0.4 million left outside, that is 2.4 million net. The second option is to split into two events, say the 8th alone and then the 9th to the 11th. The first event weighs 1.1 million and does not even reach the 2 million attachment: it falls entirely on the cedant. The second weighs 5.3 million, the layer pays 3.3 million, and the cedant keeps 2 million. In total it would have recovered 3.3 million and retained 3.1 million, plus the cost of a reinstatement called for nothing. The first option is therefore clearly better here, and the reason is general: splitting only becomes attractive when each piece pierces the attachment AND the program exhausts on a single event. Neither holds here, the episode staying below the 7 million top of the layer.
- 01The definition of a loss, not the size of the attachment, decides what a layer really pays.
- 02Per risk, the attachment applies to every policy hit: a per-risk layer never protects against an event that makes many small losses.
- 03Per event, all losses from one event are added together before the attachment applies once.
- 04The hours clause says what one event is: a window of fixed length, often seventy-two hours, starting when the cedant elects.
- 05Two events mean two attachments but two limits; one event means one attachment but possible exhaustion. The arithmetic comes before the notification.
- 06The window is anchored on dated facts and does not move afterwards, and one loss never falls inside two windows.