Commercial crime insurance covering employee theft wire fraud and social engineering 2026
Insurance

Commercial Crime Insurance 2026: Employee Theft, Wire Fraud, and Social Engineering Explained

Daylongs ·
#commercial crime insurance #employee dishonesty #wire fraud #social engineering #fidelity bond #cyber insurance #business insurance #risk management #embezzlement

What commercial crime insurance really protects against

Commercial crime insurance covers the direct loss your business suffers when money, securities, or property leave the company through dishonesty. Property insurance handles loss from fire. Liability insurance handles harm you cause to others. Commercial crime insurance handles the money that disappears from your accounts through theft, embezzlement, forgery, or fraud.

I have sat across the table from a lot of small business owners, and nearly every one starts with the same line: “Our people would never do that.” The uncomfortable truth is that the losses which sink a company rarely come from a masked stranger. They come from a trusted bookkeeper running fake vendor payments for years, or from a finance clerk who wired six figures overseas because an email looked exactly like it came from the CEO.

This is a practical, US-market buying guide, not an investment note. It walks through what the policy covers, who needs it, how the premium is built, how it differs from a fidelity bond and cyber insurance, and how claims and proof of loss actually work. Understand this product well and you end up doing more than buying a policy. You end up rethinking your internal controls from the ground up.

If you are mapping business risk more broadly, our ocean marine cargo insurance cost guide covers the property-and-transit side of the picture.


Who needs this coverage, and why smaller is riskier

Against intuition, employee fraud risk hits small companies harder than large ones. The reason is simple: there is no segregation of duties.

In a large company, one person requests a payment, another approves it, and a third reconciles the books. In a ten-person shop, a single bookkeeper often enters the invoices, releases the payments, reconciles the bank, and manages petty cash. When one person owns the entire chain, that person can commit fraud and erase the trail at the same time.

The businesses that should treat this coverage as a priority include:

  • Retail, restaurant, and distribution operations where staff handle cash, checks, and inventory
  • Service firms with frequent vendor and payroll transfers
  • Property managers, law firms, and accounting practices that hold client or trust funds
  • Nonprofits that manage donations and grants
  • Startups whose finance function is too small to split duties at all

Nonprofits deserve special mention. They run on trust, controls are loose, and the accounting function is often one or two people deep. When donor money is misappropriated, the organization loses not just the cash but the confidence that keeps it alive.


The core insuring agreements, one by one

A commercial crime policy is a stack of separate insuring agreements. Each can be switched on or off, and each can carry its own limit and sub-limit. Here are the ones that matter.

Insuring agreementLoss it coversReal-world example
Employee Dishonesty (Fidelity)Intentional theft or embezzlement by staffBookkeeper skims payments through a fake vendor for years
Forgery or AlterationForged signatures or altered amounts on your checksStolen check with a forged signature is cashed
Inside the PremisesTheft or damage of cash and securities at your locationSafe burglary, register theft
Outside the PremisesMoney stolen in transit or on the way to the bankDeposit bag robbed en route to the bank
Funds Transfer FraudBank moves your funds on a fraudulent instructionCriminal sends a forged transfer order to your bank
Computer FraudMoney or property moved via system intrusionHacker manipulates payment systems to divert funds
Social Engineering (endorsement)Employee tricked into sending money voluntarilyFinance team wires funds on a fake CEO email

One distinction is essential here. Funds transfer fraud and computer fraud usually exclude the case where an employee was fooled into sending the money themselves. Both agreements assume the criminal moved the funds without your involvement. When an employee believes a fraudulent email and clicks approve, that counts as an authorized transfer and falls out of the base coverage. The social engineering endorsement exists precisely to close that hole.


Social engineering fraud: the most common and most frequently uncovered loss

The loss I see land most often, and slip out of coverage most often, is social engineering fraud. A concrete scenario explains it faster than any definition.

The accounts payable clerk at a manufacturer receives an email from a long-standing supplier contact. “We’ve changed banks. Please send future payments to this new account.” The signature, the logo, the tone all match. The clerk updates the vendor master file without a second thought and sends the next $80,000 payment to the new account. Days later the real supplier calls to ask where their money is. The email was spoofed from a look-alike domain, and the $80,000 has already been withdrawn and gone.

That loss is not employee dishonesty, because your employee was honest and simply deceived. It is not funds transfer fraud, because the bank processed a legitimate instruction. It is not computer fraud, because no system was breached. Only a social engineering endorsement pays it.

The catch is that this endorsement almost always comes with a low sub-limit. Even with a $1 million overall crime limit, the social engineering sub-limit might be capped at $50,000 to $250,000. Because real fraud amounts often exceed that, negotiating the sub-limit up to match your actual exposure is one of the most important decisions in the whole purchase.

Insurers usually attach conditions to this endorsement, and the most common is a callback verification procedure. When a request comes in to change a vendor’s bank details, you confirm it by calling a previously known phone number, not by replying to the email. Document that control and both the underwriting and the rate get friendlier.


How premiums are priced: controls are the rate

The variables that set a commercial crime premium are well defined. Here they are.

FactorEffect on premiumWhy
Annual revenueHigher revenue, higher premiumBaseline measure of cash flow and exposure
Employee countMore employees, higher premiumWider pool of potential dishonesty
Cash and assets handledMore handled, higher premiumLarger amount that can leave at once
IndustryCash-intensive and financial pay moreBanking, payments, retail carry a rate premium
Internal controlsStronger controls, lower premiumDual authorization, callbacks, separation of duties
Coverage limitHigher limit, higher premiumPremium scales with the promise
DeductibleHigher deductible, lower premiumYou self-insure small losses

Qualitatively, a small, office-based firm with modest exposure might start in the low hundreds of dollars a year for base coverage. A cash-heavy business that holds large client balances and layers on high limits plus a social engineering endorsement can run into several thousand a year. The exact number comes from an underwriter reading your financial structure and control environment.

The single most effective way to lower the premium is to strengthen internal controls. Dual control (any transfer above a threshold requires two independent approvals), vendor bank-change callbacks, monthly bank reconciliation, and periodic payroll audits all reduce the probability of loss, and insurers price that in. Controls are both a tool to cut the premium and the root-cause fix that keeps you from ever filing a claim.


How it differs from a fidelity bond and cyber insurance

These three products get conflated constantly. Let me separate them cleanly.

A fidelity bond is the ancestor of commercial crime insurance. Traditionally it covered only loss from employee dishonesty. Today’s commercial crime policy includes that fidelity coverage and extends it with forgery, transfer fraud, computer fraud, and social engineering in a single contract. The exception: if you sponsor a US retirement plan governed by ERISA, the law requires a separate ERISA fidelity bond. That bond exists to protect plan participants, a different purpose from your company’s own crime protection.

Cyber insurance has a different center of gravity. Where commercial crime covers money that left directly, cyber covers breach response costs, customer notification, credit monitoring, system restoration, ransomware, business interruption, and third-party liability. One is about financial loss; the other is about responding to a data and systems event.

The gray zone is a social engineering wire loss, which can be addressed by the social engineering endorsement on the crime policy and by the fraudulent instruction coverage on a cyber policy. If you hold both, put the two wordings side by side and check which responds first, which carries the larger sub-limit, and how a double claim gets adjusted. Placing both with the same carrier or broker makes that coordination far easier.

If you are lining up your broader financial picture, our capital gains tax guide is a useful companion.


Setting limits, deductibles, and endorsements

The starting point for a limit is one question: what is your single largest exposure? The most that could leave in one vendor payment, the highest balance in any single account, or one full payroll run. The largest of those sets the floor. Conservatively, you set the limit high enough that one big fraud would not shake the business financially.

The deductible is your retention. Raise it and the rate falls, but you absorb small losses yourself. Rather than filing a claim for every minor inventory shrink, most businesses are better off taking a reasonable deductible and paying a lower premium.

Among endorsements, social engineering is the clear first priority, for the reasons above: it is easy to leave out of the base coverage and it is the loss you are most likely to actually suffer. Other endorsements worth reviewing:

  • Third-party coverage. Many base policies protect only the company’s own loss. If you want protection for a client or vendor harmed by your employee’s dishonesty, you need an extension.
  • Automatic coverage for acquisitions. A clause that automatically brings a newly acquired subsidiary into the policy up to a size threshold. Without it, the new entity sits exposed.
  • Crypto and digital assets. If you handle digital assets, confirm whether they fall inside the policy’s definition of covered property.

Business owners parking conservative reserves may also weigh cash-equivalent ideas in our multi-year guaranteed annuity guide.


Claims and proof of loss: the clock starts at discovery

The moment you discover the fraud, the clock starts. Here is how a commercial crime claim runs in practice.

First, prompt notice. Report the loss to the insurer within the deadline written into the policy. Late notice can cost you the coverage.

Second, the proof of loss. Within the required window, you submit documents that establish the amount and the dishonest act: accounting records, bank statements, transfer logs, vendor master change history, and internal audit or forensic investigation reports. For a social engineering loss, keep the original fraudulent email, the domain-spoofing evidence, and a record of whether the callback procedure was followed.

Third, the criminal-process link. Where appropriate, a police report supports your proof of loss, though a criminal conviction is generally not a precondition to payment.

The key concept here is the discovery basis. Most commercial crime policies cover a loss based on when it is discovered, not when it occurred. An embezzlement scheme that began three years ago is claimable if you discover it during this year’s policy period. Just confirm how long the discovery period runs after the policy ends. If it is short, a loss that surfaces shortly after cancellation can slip through.


Five coverage gaps businesses miss

Finally, the gaps companies discover too late, at claim time. Make a habit of checking this list at every renewal.

  1. The social engineering sub-limit is too low. Owners look at the overall limit and relax, then the actual fraud exceeds the sub-limit and only part is paid. This is the most common surprise.
  2. Third-party loss is excluded. A client harmed by your employee’s dishonesty is not your own loss and may fall outside base coverage.
  3. New subsidiaries and foreign operations are not automatic. Right after an acquisition, when controls are weakest, the new entity can be completely exposed.
  4. The discovery period is short. A loss surfaces a few months after the policy ends, but the discovery window has already closed.
  5. Owner and partner dishonesty is excluded. Fraud by an equity-holding owner is often carved out. Partnerships and family businesses need to read that definition closely.

Commercial crime insurance is not a buy-it-and-forget-it product. As the company grows, changes how it pays vendors, acquires a new entity, or starts handling larger sums, the exposure moves with it. My standard recommendation is that at every renewal the finance lead and the broker sit down and re-answer two questions: what is our single largest exposure right now, and is that exposure actually defended by the current limit and sub-limits? The habit of asking that question protects a business more reliably than any single policy document.


Keep reading


This article is general information and does not constitute legal, tax, or insurance advice, nor a recommendation to purchase any specific policy. Coverage terms, sub-limits, and exclusions vary by insurer and by policy. Before buying, review the full policy wording and consult a qualified insurance professional. The content reflects general US-market practice as of the writing date.

What does commercial crime insurance actually cover?

It covers direct financial loss from dishonest acts: employee theft and embezzlement, forgery or alteration of your checks, theft of money or securities from inside and outside your premises, funds transfer fraud, computer fraud, and (by separate endorsement) social engineering fraud. The common thread is a direct loss of money, securities, or property caused by a crime, not property damage or liability to others.

Which businesses need commercial crime insurance the most?

Any business where employees handle cash, checks, inventory, or client funds. The highest priority goes to smaller companies where one person controls too much of the payment process, firms that make frequent vendor and payroll transfers, and organizations that hold client money such as property managers, law firms, and nonprofits. Smaller teams often have weaker internal controls, which raises the risk rather than lowering it.

How is commercial crime insurance different from a fidelity bond?

A traditional fidelity bond narrowly covers loss from employee dishonesty. Modern commercial crime insurance includes that fidelity coverage but bundles forgery, funds transfer fraud, computer fraud, and social engineering into a single policy. One exception: companies with ERISA retirement plans are legally required to carry a separate ERISA fidelity bond, which protects plan participants rather than the company itself.

Is social engineering fraud included in the base coverage?

Usually not. When an employee is tricked into sending money voluntarily, the transfer is treated as authorized, so it falls outside the base funds transfer and computer fraud agreements. Social engineering must be added by endorsement, and it typically carries a low sub-limit. Without it, a loss from a fake CEO or vendor payment request may not be reimbursed.

How are commercial crime insurance premiums priced?

Underwriters look at annual revenue, employee count, the amount of cash and assets handled, the industry, the strength of internal controls, and the limit and deductible you choose. Controls like dual authorization, bank callback verification, and separation of duties lower the premium. Cash-intensive and financial businesses pay more; strong controls and a higher deductible bring the rate down.

How do I decide on the right coverage limit?

Start with your single largest exposure: the biggest amount that could leave in one vendor payment, the highest balance in any one account, or a full payroll run. Set the limit high enough that one large fraud would not threaten the business. Remember that the social engineering sub-limit is often far below the overall limit, so negotiate that number up separately.

What is the difference between funds transfer fraud and computer fraud?

Funds transfer fraud covers loss when a criminal sends a fraudulent instruction to your bank to move money out of your account. Computer fraud covers loss when a criminal breaks into your systems to transfer money or property. Both tend to exclude losses where an employee was tricked into sending the money themselves, and that gap is exactly what the social engineering endorsement fills.

How does a commercial crime insurance claim work?

Notify the insurer as soon as you discover the loss, then file a sworn proof of loss within the policy deadline. You prove the amount and the dishonest act with accounting records, bank statements, transfer logs, and internal or forensic investigation reports. Most policies are written on a discovery basis, meaning they cover losses discovered during the policy period even if the scheme began years earlier.

Can commercial crime insurance replace cyber insurance?

No. Commercial crime insurance focuses on the direct loss of money that was fraudulently taken. Cyber insurance handles data breach response costs, customer notification, system restoration, ransomware, business interruption, and third-party liability. Social engineering wire losses can sit in the overlap between the two, so review both policy wordings together to avoid gaps and duplication.

How far does employee dishonesty coverage extend?

It covers loss from theft, embezzlement, or misappropriation committed by an employee with the clear intent to obtain a financial benefit for themselves. It generally does not cover poor performance, bad business judgment, or, in many cases, dishonesty by owners and partners who hold an equity stake. Always check the policy definitions of employee and dishonest act.

What are the most commonly missed coverage gaps?

A social engineering sub-limit set too low, coverage that protects only the company's own loss and not third parties like clients or vendors, newly acquired subsidiaries or foreign operations that are not automatically included, and a short discovery period that misses losses surfacing after the policy ends. Re-checking definitions and sub-limits at every renewal is the fix.

공유하기

관련 글