Fidelity bond and commercial crime insurance cost guide 2026
Insurance

Fidelity Bond and Crime Insurance Cost 2026: Protect Your Business From Employee Theft

Daylongs ·
#Fidelity Bond #Crime Insurance #Employee Dishonesty #ERISA #Business Insurance #Internal Controls #Fraud Prevention

Why Your Most Trusted Employee Is Exactly Who This Insurance Is For

Here’s the uncomfortable truth: fidelity bond and crime insurance exist precisely because trust and access travel together. The bookkeeper you’d never suspect is usually the one with the login credentials, the check-signing authority, and the years of unquestioned tenure that make sustained embezzlement possible. Studies from the Association of Certified Fraud Examiners have repeatedly found that occupational fraud schemes run for well over a year on average before detection, and small organizations — those with fewer than 100 employees — tend to suffer disproportionately large losses relative to their size, largely because they can’t afford the layered internal controls that bigger companies take for granted.

My take: if your business moves money — payroll, vendor payments, client trust accounts, retirement plan contributions — you need this coverage regardless of how well you know your team. This isn’t about distrust. It’s about the fact that one person with unchecked access to funds represents a single point of failure that no amount of goodwill fixes.

This guide breaks down what fidelity bonds and commercial crime insurance actually cover, realistic cost ranges, the underwriting factors that move your premium, the ERISA fidelity bond requirement that trips up plan sponsors, how to set a defensible coverage limit, and the mistakes that show up again and again in claims files.


Fidelity Bond vs. Commercial Crime Insurance: What’s the Real Difference?

The terms get used interchangeably in casual conversation, but they have distinct histories and, in one important context, distinct legal meanings.

Fidelity bond is the older term, rooted in surety-adjacent products banks and financial institutions used to guarantee employee honesty. It historically covers one thing: losses caused by dishonest or fraudulent acts of employees. It’s still the term of art used in ERISA compliance, where the law specifically requires a “fidelity bond” for anyone handling retirement plan assets.

Commercial crime insurance is the modern, broader package most brokers actually quote today. It bundles employee dishonesty coverage with additional insuring agreements — forgery, computer fraud, funds transfer fraud, and increasingly social engineering fraud — into a single policy with separate limits for each peril.

In practice: if you’re setting up a 401(k) or pension plan, you need to satisfy the specific ERISA fidelity bond requirement. If you’re protecting the business generally against fraud and theft, you’re buying a commercial crime policy, and the ERISA bond can often be issued as a rider or standalone piece of that same relationship with your carrier.

👉 If your company also carries a buy-sell agreement funded by life insurance, read our buy-sell agreement life insurance guide — both products exist to protect the business from the financial shock of losing a key person, just through different mechanisms.


What Does It Actually Cover? Employee Dishonesty to Social Engineering

Crime policies are built from modular insuring agreements. Which ones you need depends on how money actually moves through your organization.

Coverage moduleWhat it protects againstReal-world example
Employee DishonestyDirect loss from theft, embezzlement, or fraudulent use of company property by an employeeA controller quietly redirects vendor payments to a shell account over several years
Forgery or AlterationForged or altered checks and financial instrumentsSomeone forges the company’s signature on a check and cashes it
Computer FraudUnauthorized use of a computer system to fraudulently transfer money or propertyA hacker breaches accounting software and initiates outbound wires
Funds Transfer FraudLosses when a financial institution transfers funds based on fraudulent instructionsCriminals impersonate a company officer to instruct the bank to wire funds
Social Engineering FraudLosses when an employee is deceived into voluntarily transferring fundsA fake “CEO” email convinces an employee to wire funds to a fraudulent account
Third-Party / ERISA FidelityExtends coverage to outsourced staff or retirement plan assetsA third-party payroll vendor’s employee misappropriates plan contributions

The module businesses most often assume they already have is social engineering fraud — and it’s the one most likely to be excluded from a base policy. Underwriters draw a legal distinction: in the first five categories, someone deceived a system or forged a document. In social engineering, the employee made a conscious, if manipulated, decision to send the money. That distinction is exactly why carriers treat it as a separate, often lower-limit endorsement.


How Much Does Fidelity Bond and Crime Insurance Cost?

No broker can quote you a firm number without underwriting your specific business, but the market shows consistent qualitative patterns worth knowing before you get on the phone.

Business profileTypical limit rangeQualitative annual premium range
Small business, under 20 employees, simple money flow$50,000–$250,000Low, often starting in the low hundreds of dollars
Mid-size company, 50–200 employees$250,000–$1,000,000Moderate, varies widely with internal controls
Financial services, property management, or funds handlers$1,000,000+High, underwriting is stricter and pricing rises sharply
ERISA fidelity bond (statutory minimum)10% of plan assets, subject to a federal capRelatively low, standardized products are common
Social engineering fraud endorsementOften written as a sub-limit of the base policyAdds incremental cost on top of the base premium

Treat this table as directional, not a quote. The real driver of cost isn’t a single number on a rate card — it’s how your specific combination of headcount, limit, industry, and controls interacts with the underwriter’s risk model. Two companies with identical revenue can land in very different premium bands depending on who actually has check-signing authority.


What Actually Drives Your Premium?

Underwriters look at a narrower, more specific set of factors than most business owners expect.

How many employees can actually move money — not total headcount. A 200-person company where only three people touch the bank account looks very different to an underwriter than a 30-person company where a dozen staff have wire authority.

The limit you’re requesting. Premium doesn’t scale linearly with limit. Once you cross roughly the $1 million mark, pricing often jumps because it starts interacting with reinsurance capacity, not just the primary carrier’s risk appetite.

Industry. Financial institutions, investment advisors, property managers, and any business regularly holding client or third-party funds in trust get underwritten far more conservatively than a business whose money flow is simple and internal.

Internal controls. Dual authorization on large transfers, segregation of duties between who approves and who executes payments, and regular independent audits are the single biggest levers you control. Carriers price these companies more favorably because the controls genuinely lower loss frequency.

Prior claims history. A business with a clean claims record is a much easier sell than one that has already filed an employee dishonesty claim, even years ago.

Deductible selection. As with most commercial lines, choosing a higher deductible lowers your premium — the standard trade-off applies here too.


Why Is an ERISA Fidelity Bond Not Optional?

This is where a lot of plan sponsors get caught off guard. ERISA — the federal law governing employer-sponsored retirement plans — requires that every person who “handles” plan funds or other plan property be covered by a fidelity bond. That includes trustees, plan administrators, and any staff member with authority to move plan assets, regardless of title.

A few things every plan sponsor should confirm:

  • Who counts as “handling” plan assets. It’s a functional test, not a job-title test — anyone with practical access or authority over plan funds can trigger the requirement.
  • The statutory minimum limit. Generally set as a percentage of the plan’s assets at the start of the plan year, subject to a federal cap that Congress periodically adjusts.
  • Who the bond actually protects. This is the detail most business owners miss: the ERISA fidelity bond protects the plan and its participants, not the company itself. The beneficiary of a claim is the plan, structurally distinct from your general commercial crime policy.
  • The consequence of noncompliance. A DOL audit that finds an unbonded or underbonded plan can trigger corrective action requirements and puts the plan fiduciaries’ personal liability on the table.

A common and costly assumption: that a general commercial crime policy automatically satisfies the ERISA requirement. It doesn’t, unless the bond explicitly names the plan as an insured and meets ERISA’s specific form requirements. If your company sponsors a 401(k), confirm the ERISA fidelity bond separately from whatever crime insurance protects the business’s own balance sheet.

👉 For a broader look at protecting income if a key person becomes unable to work, our business overhead expense insurance guide covers a related but distinct kind of business continuity risk.


How Do You Set the Right Coverage Limit?

Following “what everyone else in my industry buys” is a weak strategy. Here’s a more defensible process.

  1. Calculate your maximum single-event exposure. Add up your largest bank balance, the highest approval authority any one person holds, and the ceiling on your funds-transfer systems. That’s your worst realistic loss in one incident.
  2. Check contractual minimums. Loan agreements, major client contracts, and investor agreements frequently specify a minimum crime insurance limit as a condition of the relationship — that number is often your real floor, not a guideline.
  3. Use industry benchmarks as a sanity check, not a target. Benchmarks tell you what’s typical; your own money-flow structure tells you what’s adequate.
  4. Revisit annually as the business grows. A limit set at $100,000 during your first year of operation may be badly outdated once revenue and headcount triple.
  5. Look specifically at the social engineering sub-limit. It’s common for this sub-limit to sit well below the base employee dishonesty limit — confirm it’s actually sufficient given how much your team wires in a typical month.

What Does the Application Process Look Like?

  1. Map your risk internally first. Document who has funds access, what your current segregation of duties looks like, and your largest realistic exposure before you talk to a broker.
  2. Work with a broker who specializes in crime and fidelity coverage. Get multiple quotes, and if you need an ERISA fidelity bond, say so explicitly — it’s a distinct product line even within the same brokerage.
  3. Prepare underwriting documents. Financial statements, an org chart showing who approves payments, and a written description of your internal controls speed up the process and often improve pricing.
  4. Select your insuring agreements individually. Don’t assume the base package covers everything — add forgery, computer fraud, funds transfer, and social engineering as needed.
  5. Finalize limits and deductibles against your exposure calculation and budget.
  6. Reassess every year at renewal. Headcount, revenue, and money-movement patterns change, and your limit should move with them.

The Mistakes That Show Up Again and Again

Mistake 1: Assuming social engineering fraud is automatically covered. This is the single most expensive and most common gap. Business email compromise scams targeting wire transfers remain a persistent threat, and businesses routinely discover — only after filing a claim — that their base policy excludes exactly this scenario.

Mistake 2: Confusing the ERISA fidelity bond with general crime insurance. Plan sponsors buy a commercial crime policy to protect the company and assume it also satisfies their ERISA obligation. It usually doesn’t, and the gap only surfaces during a DOL audit or, worse, an actual plan-asset loss.

Mistake 3: Setting a limit once and never revisiting it. A limit that made sense at 15 employees rarely makes sense at 150. Growing businesses routinely carry coverage that’s years out of date relative to their actual cash exposure.

Mistake 4: Forgetting outsourced staff and contractors. If your bookkeeping or payroll runs through an outside firm with access to company funds, a standard employee-only policy leaves that access point uninsured unless you add a third-party fidelity endorsement.

Mistake 5: Treating insurance as a substitute for controls. A policy reimburses you after a loss; it doesn’t prevent one. Skipping dual authorization and segregation of duties because “we’re insured” both raises your premium and does nothing to reduce the odds of the loss happening in the first place.



This article is general educational information about how fidelity bonds and commercial crime insurance work in the United States. It is not legal, insurance, or financial advice. Coverage terms, exclusions, limits, and ERISA compliance requirements vary by carrier and plan — consult a licensed insurance broker and a qualified ERISA attorney or CPA before making any coverage decisions.

What is a fidelity bond, exactly?

A fidelity bond is a type of insurance that reimburses a business for direct financial losses caused by dishonest acts of its own employees — theft, embezzlement, forgery, or fraudulent manipulation of company funds. Despite the word 'bond,' it functions as first-party insurance, not a surety obligation owed to a third party.

Is a fidelity bond the same thing as commercial crime insurance?

They overlap but are not identical. Fidelity bond traditionally refers narrowly to employee dishonesty coverage, while commercial crime insurance is the broader modern package that can also include forgery, computer fraud, funds transfer fraud, and social engineering fraud as separate insuring agreements within one policy.

Why is an ERISA fidelity bond legally required?

Under ERISA (the Employee Retirement Income Security Act of 1974), anyone who handles funds or property of a retirement plan — trustees, plan administrators, staff with signing authority — must be covered by a fidelity bond. This protects plan participants' retirement savings, and the Department of Labor can flag noncompliance during a plan audit.

How much does fidelity bond and crime insurance cost for a small business?

Pricing varies by carrier, industry, and limit, but qualitatively, a small business carrying a modest limit (say $100,000–$250,000) often starts in the low hundreds of dollars per year. Costs rise, sometimes sharply, once a business needs limits above $1 million, operates in a regulated financial industry, or handles large volumes of third-party funds.

Does crime insurance automatically cover social engineering fraud?

Usually not. Social engineering fraud — where an employee is tricked by a fake email or phone call into voluntarily wiring money — is frequently excluded from the base employee dishonesty and computer fraud insuring agreements. Most carriers require a separate endorsement, often with its own lower sub-limit.

How do I decide how much coverage limit to buy?

Start with your maximum single-incident exposure: the largest amount that could realistically move out of the company in one fraudulent event, given your banking setup and approval authority. Then check whether lenders, landlords, or major clients contractually require a minimum limit, and revisit the number annually as revenue and headcount grow.

Do contractors and outsourced staff count as 'employees' under a crime policy?

Not automatically. Standard fidelity coverage is usually written around W-2 employees. If your bookkeeping, payroll, or accounting is outsourced to a third-party firm or staffing agency with access to company funds, you typically need a specific third-party fidelity endorsement to close that gap.

What's the biggest mistake businesses make when buying this coverage?

Assuming the base policy already covers social engineering fraud, and never revisiting the coverage limit as the business grows. Both mistakes are discovered only after a loss, when it's too late to fix.

Can a fidelity bond replace internal controls like dual authorization?

No. A fidelity bond reimburses losses after the fact; it does not prevent theft. Underwriters price policies more favorably for businesses with segregation of duties, dual approval on large transfers, and regular audits, because those controls actually reduce the probability of a loss occurring.

Is this article legal or insurance advice?

No. This is general educational information about how fidelity bonds and commercial crime insurance work in the US. Coverage terms, limits, and ERISA compliance requirements vary by policy and plan, so consult a licensed insurance broker and an ERISA attorney or CPA before making coverage decisions.

공유하기

관련 글