A business does not need to suffer a fire, hurricane, lawsuit, or physical break-in to experience a devastating financial loss.
Money can disappear through a fraudulent wire transfer. An employee can manipulate vendor records for years. A compromised email account can redirect a legitimate invoice payment. A bookkeeper can create a fictitious vendor. Someone can forge company checks. A trusted employee can steal customer funds. A criminal impersonating the company's CEO can convince Accounts Payable to transfer hundreds of thousands of dollars to the wrong bank account.
These losses create a different insurance problem from ordinary Commercial Property or General Liability.
Commercial Crime Insurance is designed to protect businesses and organizations against specified financial losses caused by covered theft, fraud, forgery, dishonest acts, and other crime exposures.
Modern crime policies can include protection for employee theft, forgery, money and securities, Computer Fraud, Funds Transfer Fraud, Social Engineering Fraud, client property and other exposures depending on the insurer and selected coverage.
The important phrase is: depending on the coverage selected. Crime insurance is not one blanket promise that “fraud is covered.”
Individual insuring agreements, definitions, limits, sublimits, deductibles, discovery provisions, exclusions and endorsements determine what actually happens after a loss.
What Is Commercial Crime Insurance?
Commercial Crime Insurance is generally first-party insurance designed to reimburse an insured organization for certain direct financial losses caused by covered criminal or dishonest acts.
Potential perpetrators can include:
Employees
Former employees in qualifying circumstances
Outside criminals
Hackers
Imposters
Vendors or persons pretending to be vendors
Persons manipulating financial instruments
Other parties defined by the particular insuring agreement
Modern fidelity and crime products commonly offer protection involving Employee Theft, Computer Fraud, Funds Transfer Fraud and Social Engineering Fraud, although the available coverage differs substantially by insurer.
That means the correct question is not:
“Do I have crime insurance?”
It is:
“Which crime insuring agreements do I have, at what limits, and what does each one actually require?”
Why Ordinary Business Insurance Can Leave a Crime Gap
A company may already have:
Commercial Property
General Liability
Businessowners Policy
Commercial Package Policy
Cyber Insurance
and still have a significant crime exposure.
Commercial Property
Property insurance primarily addresses covered physical property losses. Money, securities, fraudulent transfers and employee dishonesty often require specialized treatment.
General Liability
General Liability primarily addresses certain third-party claims for bodily injury, property damage and personal or advertising injury.
It is not designed as reimbursement for money stolen from the insured by an employee or fraudster.
BOP or CPP
A BOP or Commercial Package Policy may contain limited crime coverage or permit crime coverage to be added.
Florida DFS specifically notes that BOPs can include sublimits for crime and employee dishonesty. That does not mean a small embedded limit is equivalent to a full Commercial Crime policy.
Businesses with meaningful financial crime exposure should review whether the limits and insuring agreements inside the package are sufficient.
The Core Commercial Crime Exposures
A modern crime program can involve several distinct insuring agreements. They are related. They are not interchangeable.
Employee Theft
Employee Theft — historically also called Employee Dishonesty coverage — protects against certain theft or dishonest acts committed by covered employees.
Examples can include:
Stealing cash
Diverting deposits
Creating fictitious vendors
Manipulating payroll
Issuing unauthorized checks
Redirecting customer payments
Stealing inventory
Misappropriating company property
Using corporate payment systems dishonestly
Colluding with others to steal company assets
The exposure can be especially significant when one person can both: create a vendor and approve the vendor's payment.
Insurance can provide a financial backstop. It cannot replace internal controls.
Who Counts as an “Employee”?
This is one of the most important questions in a crime policy. Do not assume everyday language controls. The policy definition determines whether a particular person qualifies.
Review treatment of:
Full-time employees
Part-time employees
Temporary workers
Leased workers
Volunteers
Independent contractors
Consultants
Directors
Officers
Partners
LLC members
Owners
Former employees
A business can have a genuine theft and still face a coverage dispute if the person who committed it does not satisfy the applicable definition.
This is especially important for small businesses in which owners, members, independent bookkeepers, contractors or outside service providers may have access to financial systems.
Employee Theft of Client Property
Some companies handle far more than their own assets. Examples include:
Accounting firms
Bookkeepers
Property managers
Law firms
Medical billing companies
Payroll providers
Home health organizations
Nonprofits
Association managers
Businesses holding customer inventory
Professional firms handling client funds
If an employee steals a client's money, securities or property, the financial consequences can be severe.
But ordinary Employee Theft protection for the insured's own property should not automatically be assumed to protect clients.
Some commercial crime programs specifically offer client-theft coverage. Chubb, for example, describes available coverage for employee theft of clients' funds and property in its commercial crime product.
Businesses entrusted with third-party assets should examine this issue explicitly.
Forgery or Alteration
Forgery or Alteration coverage generally addresses certain losses involving financial instruments that are forged or materially altered.
Examples can involve:
Forged signatures
Altered checks
Fraudulent drafts
Changes to payment amounts
Fraudulent instruments created using company banking information
Although businesses increasingly rely on electronic payments, paper checks have not disappeared. Forgery remains a separate exposure from cyber fraud.
Money and Securities
Businesses may hold money and securities:
At the premises
In a cash register
Inside a safe
During transportation
While making a bank deposit
At temporary locations
Crime policies can contain separate protections depending on where the property is located and what caused the loss. This matters because theft, robbery, disappearance and destruction are not necessarily treated identically.
Inside the Premises and Outside the Premises
Traditional crime forms distinguish among different locations and circumstances. Coverage can address qualifying theft or disappearance involving money and securities:
Inside insured premises
Outside the premises
While in transit
While temporarily in the custody of qualifying persons
Policy terminology matters greatly. Do not assume every missing dollar is covered merely because money disappeared.
Robbery, Burglary and Theft Are Not Necessarily the Same Thing
Everyday conversation uses these words loosely. Insurance policies may define them specifically.
For example, robbery can involve taking property from a person through force or threat, while burglary can depend on unlawful entry and particular evidence of forced entry depending on the form.
The operative policy definitions control coverage.
Computer Fraud
Computer Fraud addresses a modern but specific type of loss.
A common concept is the direct loss of money, securities or other covered property resulting from fraudulent or unauthorized computer activity that causes property to be transferred.
Examples can include a criminal:
Gaining unauthorized system access
Manipulating payment instructions
Changing a beneficiary
Causing a digital transfer
Using compromised systems to divert company funds
Chubb describes Computer Systems Fraud as one of the principal insuring clauses available in its commercial crime program, while Travelers similarly illustrates Computer Fraud with unauthorized system activity causing money to be transferred.
But Computer Fraud should not be used as a generic label for every fraud involving an email or computer. That distinction becomes critical with Social Engineering.
Funds Transfer Fraud
Funds Transfer Fraud commonly involves fraudulent instructions delivered to a financial institution that appear to have come from the insured but were not actually authorized.
Consider the difference: Criminal sends fraudulent transfer instructions directly to the bank while impersonating the company.
That may implicate Funds Transfer Fraud. But: Criminal tricks a real company employee into personally authorizing the transfer.
That may instead be a Social Engineering situation.
The exact definitions vary, but the distinction can determine whether a loss reaches the correct insuring agreement.
Travelers specifically distinguishes Funds Transfer Fraud from Social Engineering based on who is deceived and who initiates the transaction.
Social Engineering Fraud
Social Engineering Fraud can be particularly dangerous because the criminal does not necessarily hack the payment system. The criminal hacks human trust.
A fraudster may impersonate:
The CEO
CFO
Vendor
Supplier
Customer
Bank representative
Attorney
Employee
Property owner
Client
and persuade a legitimate employee to voluntarily send money.
Chubb describes Social Engineering coverage as protection for fraud involving impersonation of vendors, executives or clients and offers it as specific crime protection rather than assuming ordinary crime wording automatically handles it.
That matters because the employee may have had full authority to press SEND.
The transaction itself can therefore be “authorized” internally even though the employee was deceived.
Business Email Compromise
Business Email Compromise, or BEC, is one of the clearest examples of Social Engineering risk.
The FBI describes BEC as a sophisticated fraud targeting businesses and individuals who perform legitimate transfers of funds. Criminals can compromise genuine email accounts or use social engineering to create fraudulent transfer instructions.
A typical scenario:
A company regularly pays Vendor A.
A fraudster compromises or convincingly impersonates Vendor A.
Accounts Payable receives an email saying the vendor changed banks.
The email provides new wire instructions.
The company employee changes the payment information.
A legitimate invoice is paid to the criminal.
The real vendor later asks why the invoice remains unpaid.
The business can now face two problems: The stolen payment is gone and the legitimate vendor may still be owed the original invoice.
Whether insurance responds can depend on the policy's Social Engineering, Computer Fraud, Funds Transfer Fraud, Cyber or other wording.
Computer Fraud vs. Funds Transfer Fraud vs. Social Engineering
This is one of the most important distinctions in the entire article.
Scenario | Coverage to Examine |
Hacker manipulates the insured's computer system and causes a transfer | Computer Fraud |
Criminal sends unauthorized transfer instructions directly to the financial institution | Funds Transfer Fraud |
Authorized employee voluntarily transfers funds because an imposter deceived them | Social Engineering Fraud |
Email account is compromised and money is transferred | Crime and Cyber wording must both be reviewed |
Customer or vendor credentials are impersonated | Social Engineering / Cyber / Crime depending on wording |
These are general illustrations. The policy—not the name of the scam—determines coverage.
Crime Insurance vs. Cyber Insurance
Crime and Cyber Insurance increasingly touch the same incidents. They still protect fundamentally different categories of loss.
Commercial Crime may focus on:
Theft of money
Theft of securities
Theft of other covered property
Employee theft
Computer Fraud
Funds Transfer Fraud
Social Engineering
Forgery
Cyber Insurance may focus on:
Data breach response
Privacy liability
Network security liability
Ransomware
Cyber extortion
Digital forensics
Data restoration
Business interruption from network events
Regulatory and notification expenses
Other technology-related losses
Modern Cyber products can themselves include Cyber Crime insuring agreements such as Computer Fraud, Funds Transfer Fraud and Social Engineering, which makes coordination even more important. Travelers, for example, lists these cyber-crime agreements within some CyberRisk products.
The right question is not:
“Is this Crime or Cyber?”
It is:
“Which policy responds to which component of the event, and are there gaps or overlapping limits?”
Voluntary Transfer Is a Critical Issue
One reason Social Engineering deserves its own review is that the insured employee may voluntarily part with the money.
From the employee's perspective, the transfer was intentional. The deception was external.
Traditional policy exclusions or definitions can make that distinction critical, which is why dedicated Social Engineering endorsements exist. Chubb expressly describes its social-engineering product as including a carve-back for voluntary parting in covered circumstances.
When evaluating a crime quote, ask: What happens when our employee knowingly sends the money but unknowingly sends it to a fraudster?
That question is more useful than asking whether the policy “covers email fraud.”
Commercial Crime vs. Fidelity Bonds
The terminology overlaps considerably.
Florida DFS explains that a Fidelity Bond protects an employer against employee theft or dishonest acts involving entrusted property. It distinguishes fidelity from traditional three-party surety bonds.
Commercial Crime Insurance can go substantially beyond employee dishonesty by combining multiple crime insuring agreements.
A business may encounter terms such as:
Fidelity Bond
Employee Dishonesty Bond
Business Services Bond
Commercial Crime Policy
ERISA Fidelity Bond
They should not automatically be treated as equivalent products. For a detailed explanation of fidelity and surety structures, see our Surety & Fidelity Bonds guide.
ERISA Fidelity Bonds: A Completely Different Compliance Issue
Employers sponsoring private employee benefit plans need to understand a special federal requirement.
ERISA generally requires persons who handle plan funds or property to be covered by a fidelity bond protecting the plan against fraud or dishonesty.
The U.S. Department of Labor states that the required amount is generally at least 10% of the funds handled during the previous year, subject generally to a $1,000 minimum and $500,000 maximum, or $1 million for qualifying plans holding employer securities.
An ERISA Fidelity Bond is also not the same as Fiduciary Liability Insurance.
The Department of Labor specifically distinguishes them:
ERISA bonding protects the plan against fraud or dishonesty involving people handling plan assets.
Fiduciary Liability addresses a different exposure involving alleged breaches of fiduciary duties.
This is a compliance issue where businesses should not rely solely on ordinary Commercial Crime coverage without confirming that the statutory requirements are satisfied.
Discovery vs. Loss Sustained Crime Forms
Here is one of the most overlooked technical issues in Crime Insurance. Commercial crime coverage can be written using different coverage triggers.
Discovery Form
A Discovery form generally focuses on a covered loss being discovered during the policy period or applicable extended discovery period, subject to the form's provisions.
Loss Sustained Form
A Loss Sustained form generally focuses on a covered occurrence taking place during the applicable coverage period and being discovered within the timeframe permitted by the form.
IRMI compares these concepts loosely to the distinction between claims-made and occurrence triggers in liability insurance and notes that ISO maintains both Discovery and Loss Sustained commercial crime forms.
This becomes extremely important when:
Changing insurers
Replacing a Crime policy
Moving from Discovery to Loss Sustained
Moving from Loss Sustained to Discovery
Discovering old employee theft years later
Changing limits
Adding a new insuring agreement
Crime losses can remain hidden for years. A bookkeeper might steal small amounts monthly over five years before the owner discovers the scheme. The current policy and prior policies must therefore be reviewed carefully.
When Is a Crime Loss “Discovered”?
Policy wording controls.
Discovery may involve a qualifying insured becoming aware of facts that would cause a reasonable person to assume a covered loss has occurred or may have occurred.
The person whose knowledge matters can also be defined. This means: Suspicion can matter.
The clock does not necessarily begin only when every dollar has been quantified or the employee confesses. Promptly notify the insurer when a potentially covered crime loss is discovered.
Direct Loss vs. Consequential Loss
Crime Insurance frequently centers on direct loss. That distinction matters.
Imagine an employee steals $100,000. The direct theft may be the primary covered loss.
But the business can also suffer:
Lost customers
Reputation damage
Lost future profit
Internal investigation costs
Accounting fees
Legal expenses
Lost management time
Interest
Contract penalties
Those secondary costs should not automatically be assumed to be covered.
Some modern policies provide investigation or related expense extensions, but limits and wording vary. Chubb, for example, identifies investigative expense coverage among features available under its proprietary Commercial Crime product.
One Employee Can Create Multiple Years of Loss
Employee theft frequently does not happen once.
A dishonest employee may repeat a scheme:
Every payroll
Every month
Every invoice cycle
Across multiple customers
Through multiple accounts
The crime policy's definition of occurrence or loss becomes important because a series of related acts may be treated as one loss and subject to one limit. Do not assume that 100 fraudulent transactions automatically produce 100 separate limits.
Limits and Sublimits Matter
A declarations page might show Commercial Crime: $1,000,000 but the important exposures could still have very different limits.
Review each coverage separately:
Employee Theft
Client Theft
Forgery
Money and Securities
Computer Fraud
Funds Transfer Fraud
Social Engineering
Counterfeit Currency
Investigation Expense
Other extensions
Social Engineering in particular may have a lower sublimit than Employee Theft. The headline limit is not enough.
Deductibles
Crime coverage can also use separate deductibles by insuring agreement. A company should understand how much loss it retains before insurance responds. For frequent lower-severity crime losses, the deductible can materially affect practical coverage.
What Commercial Crime Insurance Commonly Does Not Cover
The exact exclusions vary, but areas requiring careful review can include:
Acts by owners, partners or members not meeting the definition of Employee
Known dishonest employees after required knowledge thresholds are met
Inventory shortage proved only by inventory calculations
Accounting or mathematical errors
Voluntary surrender of property without applicable Social Engineering protection
Indirect or consequential loss
Lost income
Certain confidential-information losses
Certain cyber events outside the crime insuring agreements
Prior known losses
Loss discovered outside applicable reporting or discovery provisions
Government seizure
War-related exclusions
Other exclusions contained in the actual form
Never copy an exclusions list from one insurer and assume it applies to another.
Inventory Shortages Are Particularly Tricky
A missing inventory count does not necessarily prove employee theft.
Suppose the accounting system indicates: $75,000 in inventory should exist but the physical count shows: $50,000.
That discrepancy could have resulted from:
Theft
Incorrect receiving
Data-entry error
Damage
Unrecorded sales
Vendor shortage
Misplacement
Crime policies may restrict claims based solely on inventory computation or profit-and-loss calculations. Independent evidence of theft can therefore become important.
Internal Controls Are Part of the Insurance Strategy
Crime Insurance works best when the business also makes crime difficult to commit. Strong controls can include:
Separation of duties
Dual authorization for significant payments
Independent bank reconciliation
Vendor verification
Call-back procedures
Restricted administrator access
Regular audit of vendor-master changes
Regular review of payroll modifications
Employee background screening when appropriate
Inventory controls
Secure check stock
Daily or frequent bank monitoring
Restrictions on wire authority
MFA
Cybersecurity training
Owner-level review of unusual transactions
CISA recommends multifactor authentication, especially for sensitive business accounts, and specifically encourages stronger phishing-resistant MFA where available.
The Payment-Change Verification Rule
One of the simplest controls deserves its own rule:
Never approve new banking instructions using only the communication that requested the banking change.
If an email says:
“We changed banks. Send all future payments here.”
verify the change using a known, independently obtained phone number or another trusted channel.
Do not call the telephone number contained in the suspicious email. The FBI specifically recommends using secondary channels or two-factor verification when account information changes. A 60-second verification call can prevent a six-figure loss.
What to Do After a Suspected Wire or BEC Fraud
Time matters. If the business discovers a fraudulent transfer:
Immediately contact the financial institution.
Request a recall or freeze where possible.
Preserve emails, headers, invoices and payment records.
Notify appropriate internal security or IT personnel.
Notify the insurance agent/carrier promptly.
Avoid destroying or modifying potentially relevant electronic evidence.
Report qualifying internet-enabled fraud to the FBI Internet Crime Complaint Center.
Follow legal, regulatory, customer-notification or contractual requirements that may apply.
The FBI specifically advises victims of fraudulent transfers to contact the financial institution immediately and report BEC incidents to IC3 because rapid action may improve the possibility of freezing funds.
Which Businesses Should Review Crime Coverage?
Virtually any business with money, employees, digital payments or client property has some crime exposure. The need becomes especially important for:
Accounting firms
Bookkeeping companies
Medical practices
Medical billing companies
Law firms
Insurance agencies
Property managers
HOAs and condominium associations
Nonprofits
Churches
Retailers
Restaurants
Contractors
Wholesalers
Distributors
Payroll companies
Professional service firms
Organizations handling donations
Businesses accepting cash
Businesses using ACH or wires
Businesses with valuable inventory
Businesses holding client funds or property
The company does not need thousands of employees. A five-person organization can have enormous crime exposure if one employee controls the bank account.
Common Commercial Crime Mistakes
Assuming a BOP automatically provides enough crime coverage. A small Employee Dishonesty sublimit may be far below the actual exposure.
Buying Employee Theft but ignoring outside fraud.
Treating Computer Fraud, Funds Transfer Fraud and Social Engineering as interchangeable.
Assuming every person working for the company meets the policy definition of Employee.
Forgetting client money or property.
Ignoring the difference between Discovery and Loss Sustained.
Looking only at the largest policy limit instead of each sublimit.
Assuming Cyber Insurance automatically covers every fraudulent payment.
Assuming Commercial Crime automatically satisfies ERISA bonding requirements.
Using email alone to approve changes in banking instructions.
Allowing one employee to create vendors, approve invoices and release payments.
Waiting to notify the insurer until the entire investigation is complete.
Commercial Crime Insurance Review Checklist
Before binding or renewing coverage, determine:
Is Employee Theft included?
Who qualifies as an Employee?
Are temporary and leased workers covered?
Are volunteers covered?
How are directors and officers treated?
How are partners, owners and LLC members treated?
Is employee theft of client property covered?
Is Forgery or Alteration included?
What Money and Securities coverage exists?
Is property covered inside the premises?
Is it covered outside the premises?
Is property in transit covered?
Is Computer Fraud included?
What exactly triggers Computer Fraud?
Is Funds Transfer Fraud included?
Is ACH fraud addressed?
Is wire fraud addressed?
Is Social Engineering included?
What Social Engineering sublimit applies?
Are vendor-impersonation losses included?
Is executive impersonation included?
Are customer-impersonation losses included?
How does the Crime policy coordinate with Cyber?
Is coverage Discovery or Loss Sustained?
What prior-loss provisions apply?
What extended discovery period applies?
What event constitutes Discovery?
What limit applies to Employee Theft?
What limit applies to Computer Fraud?
What limit applies to Funds Transfer Fraud?
What limit applies to Social Engineering?
What deductible applies to each?
How are related acts aggregated?
Are investigation expenses covered?
Are indirect losses excluded?
Does the inventory-shortage exclusion matter?
Does the company sponsor an ERISA plan?
Is the required ERISA Fidelity Bond separately satisfied?
Are internal controls required by underwriting?
Are vendor changes independently verified?
Are significant wires subject to dual approval?
Is MFA enabled for email and financial accounts?
Does the coverage still match current revenue and transaction volume?
Has the company started handling client money or property?
Have new payment platforms or banking systems changed the exposure?
The objective is not simply to buy “Crime Insurance.” It is to make sure the policy matches how money actually moves through the organization.
Crime Insurance Is Financial-System Insurance
The most valuable lesson is that Commercial Crime Insurance should not be viewed only as insurance against dishonest employees. Modern businesses move money through:
Email
ACH
Wire transfer
Cloud accounting
Payroll platforms
Banking portals
Vendor-management systems
Payment processors
Mobile applications
That means crime risk now lives at the intersection of People + Money + Technology + Trust. A modern Crime policy needs to be reviewed the same way.
Speak With a Business Insurance Professional
Commercial Crime losses can be difficult because the difference between a covered and uncovered transaction may depend on exactly who initiated the transfer, who was deceived, what system was accessed, whose property was stolen, when the loss occurred and when it was discovered.
At Capital Edge Firm, we help businesses review Commercial Crime, Employee Theft, Computer Fraud, Funds Transfer Fraud, Social Engineering, client-property exposures and their coordination with BOP, CPP, Fidelity Bond and Cyber coverage.
If your company handles money, inventory, client property or electronic payments, contact Capital Edge Firm to review whether your current insurance program addresses the way crime actually occurs in today's business environment.
Disclaimer: This article is provided for general educational purposes only and does not modify, extend, guarantee or replace any insurance policy or bond. Coverage, definitions, limits, sublimits, exclusions, deductibles, discovery provisions, endorsements and underwriting requirements vary by insurer and policy form. ERISA and other legal requirements should be reviewed with qualified insurance, benefits and legal professionals as appropriate.
