FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE

Crime and social engineering coverage for complex businesses

A commercial crime program should match each way money or property can be stolen to the policy's specific insuring agreement, limit, sublimit, conditions, and ownership wording. Employee theft, unauthorized computer entry, fraudulent bank instructions, and an employee deceived into voluntarily sending money are not interchangeable events. Client money, verification procedures, policy form, and cyber overlap can determine which policy is relevant before the headline limit matters.

Who this page is for

Commercial crime coverage should reflect how money and property actually move through the business. Payroll, vendor payments, wires, client funds, escrow or trust accounts, card activity, and administrator access can each create a different theft or fraud scenario, with different policy definitions and sublimits.

A senior broker review distinguishes employee theft from computer fraud, funds-transfer fraud, and a deceptive voluntary transfer. It also tests verification conditions, ownership of money, discovery dates, prior dishonesty, and overlap with cyber coverage rather than assuming one crime limit applies to every event.

Discuss your crime and social engineering program with a senior broker

Start with a conversation. No application or documents required.

Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.

No insurance application or document upload required.

How do four common crime insuring agreements differ?

Employee dishonesty or employee theft addresses specified direct loss caused by theft or dishonest acts of an employee, as the policy defines that term. The review should determine whether temporary workers, leased employees, directors, owners, and administrators qualify, and whether one employee's acts over time are treated as one occurrence. Inventory shortage or unexplained disappearance may not prove employee theft under the form.

Computer fraud generally concerns unauthorized entry into or use of a computer system that directly causes a transfer of money, securities, or property. Funds-transfer fraud instead generally concerns a fraudulent electronic, telegraphic, or similar instruction transmitted to a financial institution without the insured's knowledge or consent. Definitions differ, and neither label should be applied solely because email or a computer appeared somewhere in the sequence.

Social engineering or deceptive voluntary transfer involves an authorized employee being deceived into sending money, often by an impostor posing as an executive, vendor, or trusted counterparty. Because the employee intentionally executes the transfer, traditional computer- or funds-transfer-fraud wording may not fit. This exposure is commonly addressed by a separate insuring agreement or endorsement with a lower sublimit and specific verification conditions.

Whose money or property is insured?

A standard crime form may cover money, securities, or other property the insured owns, leases, holds, or is legally liable for, but the exact ownership provision controls. A loss from the company's operating account is not automatically treated the same as a loss from an escrow account, client trust account, tenant account, or customer payment flow. The schedule and application should identify each account, owner, custodian, balance, and transfer authority.

Businesses handling client money should examine client property coverage and any third-party or “clients” coverage endorsement. Those terms can address different relationships and may require the client to be identified, the dishonest actor to meet a definition, or the loss to occur while the insured provides stated services. Contractual responsibility for client funds does not itself prove the policy covers them.

Escrow and trust funds need operational detail: who can initiate and approve a wire, whose credentials are used, whether funds are commingled, how balances peak, and who bears a shortfall. A $1M company-money crime limit does not establish a $1M client-funds limit. The proposal should state each applicable limit and sublimit separately.

When is verification a condition of coverage?

A social engineering endorsement may require call-back verification to a known telephone number or another out-of-band method before a transfer. Out-of-band means using a communication channel independent of the request, such as calling a previously validated number rather than replying to the same email. The policy can make compliance a condition precedent—something that must occur before coverage is available—rather than merely a recommended control.

The review should read who must be contacted, which number or system may be used, the transfer threshold, required documentation, and whether exceptions exist. If an employee skips the required procedure, the insurer may deny coverage under that insuring agreement even when the request was fraudulent. The policy wording and facts control; a well-written internal procedure does not cure failure to satisfy a policy condition.

Controls and insurance should align. Dual approval, vendor-change validation, role-based payment authority, bank alerts, and escalation for urgent requests can reduce risk, while records of verification can support claim presentation. The FBI's business email compromise guidance also emphasizes independently verifying payment and account changes. Insurance does not replace those procedures.

How should crime limits follow the way money moves?

Start with peak values, not average balances: the largest payroll file, vendor-payment run, wire, client-fund balance, and amount one employee can release before another approval. Then map each scenario to employee theft, computer fraud, funds-transfer fraud, or social engineering. A common aggregate or occurrence definition can join repeated acts and reduce what remains for a later event.

The sample amounts below are limits or sublimits being evaluated, not recommendations or guaranteed options. Individually evaluated higher-limit brokerage options are subject to actual placement availability. A smaller social engineering sublimit can control a deceptive transfer even when the declarations show a larger commercial crime limit.

Each number measures the stated crime limit or social engineering sublimit for a defined occurrence; it is not annual revenue, an account balance guarantee, or a limit for every fraud event.

Limit being evaluatedWhat to investigateWhat the number does not establish
$250,000 social engineering sublimit per occurrenceLargest vendor or executive-requested transfer, verification condition, retention, related acts, and annual aggregateThat computer fraud, funds-transfer fraud, or client-money loss uses the same $250,000 sublimit
$1M employee theft limit per occurrencePeak accessible company and client property, employee definition, collusion, repeated acts, discovery, and ownership wordingThat unexplained inventory loss is covered or each dishonest act receives a new $1M limit
$2M computer and funds-transfer fraud limits per occurrenceSystem and bank instruction definitions, direct-loss wording, wire volume, authentication, sublimits, and policy coordinationThat a voluntary deceptive transfer receives $2M or that cyber and crime limits can be added together

Why do discovery and loss-sustained forms differ?

A discovery form generally responds to covered loss discovered during the policy period, subject to its retroactive or prior-loss provisions and reporting deadline. A loss-sustained form generally requires the loss to be sustained during the policy period and discovered within a stated period after it ends. The date dishonest acts began, when loss occurred, when facts were discovered, and when notice was given can therefore determine which policy period is implicated.

Discovery is usually defined by when an authorized person first becomes aware of facts that would cause a reasonable person to assume a covered loss has occurred, not necessarily when the final amount is known. A review should preserve prior policies, applications, audit findings, bank correspondence, and notice records rather than assuming the current policy handles a scheme that developed over several years.

Prior dishonesty exclusions can remove an individual from the employee-theft grant once specified management or the insured learns of dishonest conduct, even if that conduct did not produce the current loss. Hiring, disciplinary, and investigation records therefore matter. The broker should flag the wording and reporting process without deciding whether a particular employee's conduct meets the exclusion.

How do ERISA bonds and cyber policies fit?

An ERISA fidelity bond is a distinct requirement intended to protect an employee benefit plan against loss from fraud or dishonesty by persons who handle plan funds. It is not the same as commercial crime coverage for the company, fiduciary liability for allegations about plan administration, or EPLI. The plan, bonded persons, required amount, and bond terms should be reviewed separately with qualified advisers.

Many cyber forms include a cybercrime or funds-transfer part with its own sublimit, retention, and definitions. The same payment event may be reported under cyber and crime, but the business cannot assume both limits stack. Direct-loss wording, voluntary-transfer treatment, insured accounts, verification conditions, and causation language may differ even when both policies use similar labels.

Other-insurance clauses state how a policy responds when another policy may cover the same loss. One may say it is excess, another may also claim excess status, or a form may be primary only for a specified event. The review should identify the intended primary policy, align notices, and ask how deductibles or retentions and recovery will be allocated without predicting the insurers' final coverage positions.

What should a commercial crime review produce?

Build a funds-flow map covering payroll, accounts payable, executive wires, card payments, client and tenant funds, escrow or trust accounts, bank portals, payment processors, and third-party administrators. For each flow, record peak amount, initiator, approver, credentials, verification method, legal owner of funds, and contractual responsibility. Compare that map with insured entities, covered property, territory, and employee definitions.

The policy comparison should show each insuring agreement, per-occurrence limit, annual aggregate, sublimit, retention, related-acts wording, verification condition, discovery trigger, reporting period, prior-loss treatment, exclusions, and other-insurance clause. It should also identify whether investigative expense, claim preparation, or recovery expense has a separate amount rather than silently treating every cost as part of the crime limit.

$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage.

What your senior broker should examine

  • What are the peak payroll, vendor-payment, wire, client-fund, escrow, and trust-account amounts, and who can release each payment?
  • How does the form distinguish employee theft, computer fraud, funds-transfer fraud, and deceptive voluntary transfer?
  • Does ownership wording cover company money, client property, and funds the business holds or is legally liable for?
  • Which call-back or out-of-band verification steps are conditions precedent, and what are the consequences if a step is skipped?
  • Is the policy discovery or loss sustained, and how are earlier acts, discovery, notice, and prior dishonesty treated?
  • What ERISA fidelity bond is maintained separately for benefit-plan funds and persons who handle them?
  • Which cyber and crime insuring agreements could apply to the same event, which is intended to be primary, and how do other-insurance clauses interact?

Questions businesses ask

Is social engineering the same as funds-transfer fraud?

Not usually. Social engineering commonly involves an authorized employee voluntarily sending money after deception, while funds-transfer fraud generally involves an unauthorized fraudulent instruction to the bank. Definitions vary, so the specific sequence and policy wording control.

What happens if an employee skips the required call-back?

If call-back or out-of-band verification is a condition precedent, failure to complete it may prevent coverage under the social engineering insuring agreement. The exact condition, any exceptions, and the facts should be reviewed; an internal policy alone does not change the insurance contract.

Does a crime policy cover money held for clients?

It may, but company money and client money should not be assumed to receive identical treatment. Ownership wording, client property or clients endorsements, account structure, legal liability, limits, and exclusions determine the analysis.

Can we add the cybercrime and commercial crime limits together?

Not automatically. The policies may cover different events, share sublimits, or contain other-insurance clauses that determine priority. The same loss cannot be treated as two independent pools without reading both forms.

Is an ERISA fidelity bond the same as employee theft insurance?

No. The bond is a distinct requirement protecting an employee benefit plan from specified fraud or dishonesty by persons handling plan funds. Commercial crime and fiduciary liability serve different purposes and should be reviewed separately.

Sources

Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.