The mental model
Crime insurance pays you back when someone steals from your company. The thief might be an employee or a third party. The theft might be physical or electronic. The form lists specific peril buckets, and a loss has to fit one of them. Coverage is first-party indemnity, not liability.
The line traces back to fidelity bonds, which originated in the 19th century to cover banks and other financial institutions against employee dishonesty. Surety carriers underwrote them, and the structure was an indemnity bond rather than an insurance policy. Over time the coverage broadened to non-financial businesses, the form converted to a more conventional insurance contract, and additional perils (third-party theft, computer fraud) were grafted on. Today most crime is written on either the ISO Commercial Crime Coverage Form (for non-financial commercial insureds) or proprietary financial institution bond forms. The fidelity vocabulary persists in the financial institution market.
Crime is a first-party form. It pays the insured for the insured's loss. Liability to third parties from a crime event is covered by other lines (D&O, professional liability, cyber). The crime policy reimburses the money or property that left the insured's possession.
The two market segments
Crime splits cleanly into commercial crime and financial institution bonds. The forms, the markets, and the underwriters are different.
Commercial crime
For non-financial businesses. Manufacturing, retail, hospitality, professional services, technology, healthcare, nonprofit. Written on ISO Commercial Crime Coverage Forms (CR 00 20 for discovery, CR 00 21 for loss-sustained) or on near-equivalent proprietary forms. Limits typically $1M-$25M, with larger limits available on a layered basis. Premium is modest relative to the limit.
Financial institution bonds
For banks, credit unions, asset managers, broker-dealers, insurance companies, and other financial institutions. Written on specialized forms: Financial Institution Bond Form 24 (Standard Form 24, the dominant bank form), Investment Adviser Bond, Insurance Companies Blanket Bond, Form 14 for credit unions. The exposures are larger, the perils more varied, and the underwriting more granular than commercial crime. Limits often $25M+ on a single bond, with excess layers above.
What's the same
Both segments cover employee dishonesty, premises and in-transit theft of money and securities, forgery, computer fraud, and funds transfer fraud. Both use discovery or loss-sustained triggers. Both wrestle with the social engineering question.
What's different
Financial institution bonds include securities-specific perils (forged securities, transit losses on physical securities) that don't appear on commercial crime. Financial institution bonds also include perils tied to the institution's business model (loans on forged documents for banks, false statements in insurance applications for insurers).
Insuring agreements
The standard commercial crime form is structured as a series of insuring agreements. Each is independently triggered, separately limited, and individually rated.
Modern forms add several more agreements, most notably social engineering fraud (often as a separately limited endorsement), credit card fraud, and money orders and counterfeit money.
Social engineering: the modern fight
Social engineering is the dominant claim category in modern crime. It is also the agreement most often disputed at claim time.
What it is
An impersonator (typically email, increasingly voice and video deepfake) convinces an authorized insured employee to wire funds to a fraudulent destination. The employee initiates the transfer voluntarily, believing the instruction is legitimate. Funds leave the company and are not recoverable.
Why it falls between traditional agreements
The classic computer fraud agreement requires the use of a computer to "fraudulently cause" the transfer. Multiple courts have held that when an authorized employee voluntarily initiates a wire (even based on a fraudulent instruction), the computer was not used to cause the transfer. The funds transfer fraud agreement requires a fraudulent instruction to a financial institution; instructions from an authorized employee are not fraudulent in that narrow sense even if they originate from a fraudulent communication.
The endorsement
Carriers responded by writing a separate social engineering fraud endorsement (sometimes called fraudulently induced transfer, deception fraud, or impostor fraud). It covers loss when an authorized employee transfers funds in response to fraudulent instructions purportedly from a known counterparty (vendor, customer, executive). Sublimits are common, often $250K-$1M, with full limits available on negotiated placements.
Pre-loss controls underwriters care about
- Out-of-band verification for vendor banking changes.
- Dual control on outgoing wire transfers above defined thresholds.
- Restriction of wire instruction approvals to a closed list of named individuals.
- Mandatory training on impersonation patterns, refreshed at least annually.
- Email security: anti-spoofing (DMARC, DKIM, SPF), external email banner, attachment quarantining.
If the insured does not have an explicit social engineering endorsement, expect coverage disputes on every wire fraud claim. The carrier's first analysis is whether the loss can be denied under the strict reading of computer fraud and funds transfer fraud. The endorsement is essential; the sublimit on it is the actual limit for this exposure.
The crime / cyber boundary
Crime and cyber overlap, and the question of which line responds is asked on most cyber-adjacent crime claims.
What crime covers
- The actual loss of money or property from a fraud event. Wire fraud loss, employee dishonesty loss, electronic theft of funds.
- First-party indemnity for the dollar amount taken.
What cyber covers
- Privacy and breach response: notification, credit monitoring, regulatory defense, third-party privacy claims.
- Business interruption from a cyber event.
- Ransom payment to restore systems.
- Data restoration and forensics.
The contested middle
- Ransomware extortion payment. Cyber extortion is a cyber peril, not a crime peril. Crime forms typically exclude or do not address ransom.
- Wire fraud after a cyber breach. If a network intrusion led to a wire fraud, both lines may have exposure: cyber for the breach response, crime for the lost funds.
- Funds transfer fraud through a compromised email account. If the attacker compromised the insured's email, then sent a fraudulent transfer instruction to a bank, both lines can be in play.
Modern brokers approach the placement integratedly. Limits are coordinated, the insuring agreements are reviewed against each other to identify gaps and overlaps, and the broker prepares a coverage roadmap so that the insured knows in advance which line responds to which event. On bankable mid-market and large placements, this is now standard.
Discovery vs loss-sustained
Crime forms come in two trigger flavors, and the choice affects every claim.
Why this matters in renewals and transitions
Discovery forms create an interesting renewal dynamic: coverage attaches at discovery, so the prior years of coverage still matter even after the loss-sustained period would have closed. When an insured switches carriers, the new carrier may be on the hook for a loss that occurred before its policy started, simply because discovery happened during its period. Loss-sustained forms create a cleaner break: each carrier owns its policy period and a defined tail.
Run-off and tail considerations
When a company is acquired or wound down, the run-off arrangement on the crime program matters. Pre-acquisition employee dishonesty losses can surface years later. Discovery period extensions are typically available for an additional premium and are routinely purchased in M&A.
Computer fraud and funds transfer fraud
The two electronic agreements deserve their own treatment because the language varies and the case law has shaped what is in and out.
Computer fraud (Insuring Agreement F)
Pays for loss resulting directly from the use of a computer to fraudulently cause a transfer of money, securities, or other property from the insured's premises or banking premises to a person or place outside. Covers hacking-style attacks where an external actor manipulates the insured's computer systems to transfer funds. Does not cover scenarios where an authorized insured employee voluntarily transfers funds based on a fraudulent communication (this is the social engineering issue).
Funds transfer fraud (Insuring Agreement G)
Pays for loss resulting from a fraudulent instruction directing a financial institution to transfer funds from the insured's account. The instruction must purport to come from the insured but actually be issued by a third party without the insured's knowledge or consent. Classic example: an attacker emails the bank with forged credentials directing a wire from the insured's account.
What they jointly do not cover
- Voluntary transfers by authorized insured employees, even if induced by fraud (social engineering territory).
- Indirect or consequential loss beyond the actual funds taken.
- Loss from fraudulent customer transactions where the insured is a financial institution (typically covered under specific FI bond agreements).
Underwriting crime
What the crime underwriter looks at, in roughly the order of priority.
Internal controls
- Segregation of duties: separation of authorization, custody, and recording functions.
- Bank reconciliations: frequency, who performs them, who reviews them.
- Wire transfer controls: dual control thresholds, callback verification, named approver lists.
- Vendor management: master vendor file controls, banking change verification process.
- Expense reimbursement controls: receipt requirements, approval thresholds.
- Internal audit function and recent audit findings.
Cyber controls (for the social engineering and computer fraud exposures)
- Email security: SPF, DKIM, DMARC enforcement, external email banner.
- MFA on email and banking access.
- Endpoint detection and response, security awareness training.
Industry and exposure
- Cash-handling industries (retail, hospitality, gaming, transit) face elevated employee theft frequency.
- Construction and manufacturing have payroll, materials, and supplier kickback exposures.
- Nonprofits and small organizations frequently lack segregation of duties and have elevated employee dishonesty severity.
- Industries with significant outbound wire activity (real estate, M&A advisors, escrow) face elevated social engineering exposure.
Loss history
Five-year crime claims history at minimum, ten years preferred for employee dishonesty given the discovery dynamics. Pattern attention to repeated fraud types and to pre-loss control gaps that may persist.
Where IDP earns its keep
Crime submissions arrive with a structured application but the supporting controls documentation is in scattered formats: internal control narratives, SOX walkthroughs, prior loss summaries, vendor management policies, treasury procedures. Demonstrating the difference between adequate and best-in-class controls requires reading several documents that are rarely consistent across submissions.
The most valuable extraction is normalizing internal control attestations from narrative documents. Insureds describe their wire transfer controls in ten different ways across applications, supplementals, and SOX narratives. An extraction agent that reads all of them and produces a single normalized control matrix (dual control thresholds, callback procedures, named approvers, MFA posture, training cadence) is high-leverage. Secondary extractions: prior loss type categorization, industry-specific exposure flags, social engineering control gap detection.