Specialty / FinancialChapter 1920 min read

Crime & Fidelity, employee dishonesty, computer fraud, and the line that overlaps with cyber but rarely defers to it.

Crime is a first-party loss line. It pays the insured for money, securities, and other property stolen by employees or third parties through specific listed perils. Modern crime forms have absorbed computer fraud, funds transfer fraud, and (with the right endorsement) social engineering. The result is a line that sits next to cyber, occasionally overlaps it, and frequently disputes which one pays first.

§ 01

The mental model

Crime insurance pays you back when someone steals from your company. The thief might be an employee or a third party. The theft might be physical or electronic. The form lists specific peril buckets, and a loss has to fit one of them. Coverage is first-party indemnity, not liability.

The line traces back to fidelity bonds, which originated in the 19th century to cover banks and other financial institutions against employee dishonesty. Surety carriers underwrote them, and the structure was an indemnity bond rather than an insurance policy. Over time the coverage broadened to non-financial businesses, the form converted to a more conventional insurance contract, and additional perils (third-party theft, computer fraud) were grafted on. Today most crime is written on either the ISO Commercial Crime Coverage Form (for non-financial commercial insureds) or proprietary financial institution bond forms. The fidelity vocabulary persists in the financial institution market.

Anchor concept

Crime is a first-party form. It pays the insured for the insured's loss. Liability to third parties from a crime event is covered by other lines (D&O, professional liability, cyber). The crime policy reimburses the money or property that left the insured's possession.

§ 02

The two market segments

Crime splits cleanly into commercial crime and financial institution bonds. The forms, the markets, and the underwriters are different.

Commercial crime

For non-financial businesses. Manufacturing, retail, hospitality, professional services, technology, healthcare, nonprofit. Written on ISO Commercial Crime Coverage Forms (CR 00 20 for discovery, CR 00 21 for loss-sustained) or on near-equivalent proprietary forms. Limits typically $1M-$25M, with larger limits available on a layered basis. Premium is modest relative to the limit.

Financial institution bonds

For banks, credit unions, asset managers, broker-dealers, insurance companies, and other financial institutions. Written on specialized forms: Financial Institution Bond Form 24 (Standard Form 24, the dominant bank form), Investment Adviser Bond, Insurance Companies Blanket Bond, Form 14 for credit unions. The exposures are larger, the perils more varied, and the underwriting more granular than commercial crime. Limits often $25M+ on a single bond, with excess layers above.

What's the same

Both segments cover employee dishonesty, premises and in-transit theft of money and securities, forgery, computer fraud, and funds transfer fraud. Both use discovery or loss-sustained triggers. Both wrestle with the social engineering question.

What's different

Financial institution bonds include securities-specific perils (forged securities, transit losses on physical securities) that don't appear on commercial crime. Financial institution bonds also include perils tied to the institution's business model (loans on forged documents for banks, false statements in insurance applications for insurers).

§ 03

Insuring agreements

The standard commercial crime form is structured as a series of insuring agreements. Each is independently triggered, separately limited, and individually rated.

A. Employee theft
Loss of money, securities, or other property resulting from theft committed by an employee. Includes inventory theft, cash skimming, payroll fraud, expense reimbursement fraud, supplier kickback schemes, asset misappropriation. The historical core of the line.
B. Forgery or alteration
Loss from forgery or alteration of checks, drafts, promissory notes, or similar instruments drawn against the insured. Excludes electronic funds transfer (covered separately).
C. Inside the premises (theft of money and securities)
Robbery and burglary on the insured's premises. Less relevant in a cashless economy but still material for retail, hospitality, gaming, financial.
D. Inside the premises (robbery or safe burglary of other property)
Theft of non-money property by violence or by safe burglary on the insured's premises.
E. Outside the premises
Theft of money, securities, or other property in the custody of the insured's messenger or armored motor vehicle company outside the premises.
F. Computer fraud
Loss from the use of a computer to fraudulently cause a transfer of money, securities, or other property from inside the premises or banking premises to a person or place outside.
G. Funds transfer fraud
Loss from a fraudulent instruction directing a financial institution to transfer funds from the insured's account.

Modern forms add several more agreements, most notably social engineering fraud (often as a separately limited endorsement), credit card fraud, and money orders and counterfeit money.

§ 04

Social engineering: the modern fight

Social engineering is the dominant claim category in modern crime. It is also the agreement most often disputed at claim time.

What it is

An impersonator (typically email, increasingly voice and video deepfake) convinces an authorized insured employee to wire funds to a fraudulent destination. The employee initiates the transfer voluntarily, believing the instruction is legitimate. Funds leave the company and are not recoverable.

Why it falls between traditional agreements

The classic computer fraud agreement requires the use of a computer to "fraudulently cause" the transfer. Multiple courts have held that when an authorized employee voluntarily initiates a wire (even based on a fraudulent instruction), the computer was not used to cause the transfer. The funds transfer fraud agreement requires a fraudulent instruction to a financial institution; instructions from an authorized employee are not fraudulent in that narrow sense even if they originate from a fraudulent communication.

The endorsement

Carriers responded by writing a separate social engineering fraud endorsement (sometimes called fraudulently induced transfer, deception fraud, or impostor fraud). It covers loss when an authorized employee transfers funds in response to fraudulent instructions purportedly from a known counterparty (vendor, customer, executive). Sublimits are common, often $250K-$1M, with full limits available on negotiated placements.

Pre-loss controls underwriters care about

  • Out-of-band verification for vendor banking changes.
  • Dual control on outgoing wire transfers above defined thresholds.
  • Restriction of wire instruction approvals to a closed list of named individuals.
  • Mandatory training on impersonation patterns, refreshed at least annually.
  • Email security: anti-spoofing (DMARC, DKIM, SPF), external email banner, attachment quarantining.
The single most disputed coverage point

If the insured does not have an explicit social engineering endorsement, expect coverage disputes on every wire fraud claim. The carrier's first analysis is whether the loss can be denied under the strict reading of computer fraud and funds transfer fraud. The endorsement is essential; the sublimit on it is the actual limit for this exposure.

§ 05

The crime / cyber boundary

Crime and cyber overlap, and the question of which line responds is asked on most cyber-adjacent crime claims.

What crime covers

  • The actual loss of money or property from a fraud event. Wire fraud loss, employee dishonesty loss, electronic theft of funds.
  • First-party indemnity for the dollar amount taken.

What cyber covers

  • Privacy and breach response: notification, credit monitoring, regulatory defense, third-party privacy claims.
  • Business interruption from a cyber event.
  • Ransom payment to restore systems.
  • Data restoration and forensics.

The contested middle

  • Ransomware extortion payment. Cyber extortion is a cyber peril, not a crime peril. Crime forms typically exclude or do not address ransom.
  • Wire fraud after a cyber breach. If a network intrusion led to a wire fraud, both lines may have exposure: cyber for the breach response, crime for the lost funds.
  • Funds transfer fraud through a compromised email account. If the attacker compromised the insured's email, then sent a fraudulent transfer instruction to a bank, both lines can be in play.

Modern brokers approach the placement integratedly. Limits are coordinated, the insuring agreements are reviewed against each other to identify gaps and overlaps, and the broker prepares a coverage roadmap so that the insured knows in advance which line responds to which event. On bankable mid-market and large placements, this is now standard.

§ 06

Discovery vs loss-sustained

Crime forms come in two trigger flavors, and the choice affects every claim.

Discovery form
Coverage applies to losses discovered during the policy period, regardless of when the loss occurred. Includes losses from prior years that were unknown until now. Provides retroactive coverage for old, undiscovered employee dishonesty.
Loss-sustained form
Coverage applies to losses occurring during the policy period and discovered within a defined extended discovery window (typically one year). Does not respond to losses that occurred before the policy period.

Why this matters in renewals and transitions

Discovery forms create an interesting renewal dynamic: coverage attaches at discovery, so the prior years of coverage still matter even after the loss-sustained period would have closed. When an insured switches carriers, the new carrier may be on the hook for a loss that occurred before its policy started, simply because discovery happened during its period. Loss-sustained forms create a cleaner break: each carrier owns its policy period and a defined tail.

Run-off and tail considerations

When a company is acquired or wound down, the run-off arrangement on the crime program matters. Pre-acquisition employee dishonesty losses can surface years later. Discovery period extensions are typically available for an additional premium and are routinely purchased in M&A.

§ 07

Computer fraud and funds transfer fraud

The two electronic agreements deserve their own treatment because the language varies and the case law has shaped what is in and out.

Computer fraud (Insuring Agreement F)

Pays for loss resulting directly from the use of a computer to fraudulently cause a transfer of money, securities, or other property from the insured's premises or banking premises to a person or place outside. Covers hacking-style attacks where an external actor manipulates the insured's computer systems to transfer funds. Does not cover scenarios where an authorized insured employee voluntarily transfers funds based on a fraudulent communication (this is the social engineering issue).

Funds transfer fraud (Insuring Agreement G)

Pays for loss resulting from a fraudulent instruction directing a financial institution to transfer funds from the insured's account. The instruction must purport to come from the insured but actually be issued by a third party without the insured's knowledge or consent. Classic example: an attacker emails the bank with forged credentials directing a wire from the insured's account.

What they jointly do not cover

  • Voluntary transfers by authorized insured employees, even if induced by fraud (social engineering territory).
  • Indirect or consequential loss beyond the actual funds taken.
  • Loss from fraudulent customer transactions where the insured is a financial institution (typically covered under specific FI bond agreements).
§ 08

Underwriting crime

What the crime underwriter looks at, in roughly the order of priority.

Internal controls

  • Segregation of duties: separation of authorization, custody, and recording functions.
  • Bank reconciliations: frequency, who performs them, who reviews them.
  • Wire transfer controls: dual control thresholds, callback verification, named approver lists.
  • Vendor management: master vendor file controls, banking change verification process.
  • Expense reimbursement controls: receipt requirements, approval thresholds.
  • Internal audit function and recent audit findings.

Cyber controls (for the social engineering and computer fraud exposures)

  • Email security: SPF, DKIM, DMARC enforcement, external email banner.
  • MFA on email and banking access.
  • Endpoint detection and response, security awareness training.

Industry and exposure

  • Cash-handling industries (retail, hospitality, gaming, transit) face elevated employee theft frequency.
  • Construction and manufacturing have payroll, materials, and supplier kickback exposures.
  • Nonprofits and small organizations frequently lack segregation of duties and have elevated employee dishonesty severity.
  • Industries with significant outbound wire activity (real estate, M&A advisors, escrow) face elevated social engineering exposure.

Loss history

Five-year crime claims history at minimum, ten years preferred for employee dishonesty given the discovery dynamics. Pattern attention to repeated fraud types and to pre-loss control gaps that may persist.

§ 09

Where IDP earns its keep

Crime submissions arrive with a structured application but the supporting controls documentation is in scattered formats: internal control narratives, SOX walkthroughs, prior loss summaries, vendor management policies, treasury procedures. Demonstrating the difference between adequate and best-in-class controls requires reading several documents that are rarely consistent across submissions.

1
Intake
Application, internal control documentation, treasury procedures, prior losses.
2
Classify
Commercial crime vs financial institution; industry exposure tier; size band.
3
Extract
Wire dual-control thresholds, banking change verification process, MFA posture, prior loss types.
4
Validate
Cross-check stated controls against narrative documentation; flag inconsistencies.
5
Triage
Score against appetite. Flag absence of out-of-band verification, dual control gaps, recent social engineering losses.
6
Underwriter
Pre-built control profile, social engineering exposure flag, suggested sublimit recommendation.
Indico use cases for crime

The most valuable extraction is normalizing internal control attestations from narrative documents. Insureds describe their wire transfer controls in ten different ways across applications, supplementals, and SOX narratives. An extraction agent that reads all of them and produces a single normalized control matrix (dual control thresholds, callback procedures, named approvers, MFA posture, training cadence) is high-leverage. Secondary extractions: prior loss type categorization, industry-specific exposure flags, social engineering control gap detection.

Chapter 19 · Specialty / Financial · 20 min read

Crime & Fidelity — Cheat Sheet

Crime is a first-party loss line. It pays the insured for money, securities, and other property stolen by employees or third parties through specific listed perils. Modern crime forms have absorbed computer fraud, funds transfer fraud, and (with the right endorsement) social engineering. The result is a line that sits next to cyber, occasionally overlaps it, and frequently disputes which one pays first.

The mental model: Crime is a first-party form. It pays the insured for the insured's loss. Liability to third parties from a crime event is covered by other lines (D&O, professional liability, cyber). The crime policy reimburses the money or property that left the insured's possession.

Key terms

ISO CR 00 20 · Discovery form, commercial crime
ISO CR 00 21 · Loss-sustained form, commercial crime
Form 24 · Bank financial institution bond
Social engineering · Impersonation-induced transfer
Computer fraud · Hacking-caused transfer
Funds transfer fraud · Forged instruction to bank
Discovery · Trigger when loss is found

If you remember three things

Crime is a first-party form, not a liability form. The most important exposure today is social engineering, which lives on its own endorsement with its own sublimit and is the actual coverage limit for impersonation-induced wire fraud. The discovery versus loss-sustained choice changes how prior-year losses are handled and matters most at carrier transitions.