Commercial crime insurance exists for a simple, uncomfortable reason: businesses are stolen from, most often by people they trust or people impersonating those they trust. The policy covers direct financial loss from defined fraud events. The historic core is employee dishonesty — the bookkeeper writing themselves supplier payments, the warehouse manager running a parallel stock operation, the long-serving employee whose fraud survives precisely because they are trusted and never take holiday. Around that core, modern wordings add third-party fraud: forgery and fraudulent alteration of instruments, funds transfer fraud, where a bank is induced to move your money on fraudulent instructions, and social engineering fraud, where your own staff are deceived into sending it — the impersonated supplier with new bank details, the urgent transfer instruction from a spoofed director email.
What crime cover pays is the money (or stock, or securities) itself — the direct loss — rather than liability to others. That distinction shapes everything else about the product.
Crime policies are written on a discovery basis: the policy that responds is the one in force when the loss is discovered, not the one in force when the dishonest acts were committed. The logic is practical — employee fraud characteristically runs for years before surfacing, and no one can notify a loss they do not know about.
The consequence that matters is continuity. When you switch crime insurers, the new policy typically covers losses discovered during its period, but wordings commonly limit or exclude losses from acts committed before a retroactive date, and the old policy has stopped responding to new discoveries. Switch carelessly and a fraud committed in year one and discovered in year four can find both insurers pointing at each other. The remedies are wording work: retroactive cover for prior acts, continuity recognised from the original inception, and clean disclosure at each renewal. It is the same discipline claims-made covers require, applied to a different trigger — and it is a good example of why we treat switching as a wordings exercise, not a price exercise.
Social engineering fraud — deceiving an authorised employee into making a genuine payment to a fraudulent destination — is the loss most businesses now actually fear, and insurers know it. The market’s response has two features to understand before you buy.
First, the sub-limit: social engineering cover usually carries a lower inner limit than the main employee dishonesty insuring clause. If your realistic exposure is a redirected six-figure supplier payment, the sub-limit is the number to negotiate, not the headline limit.
Second, the verification conditions. Policies commonly require that changes to payment details and non-routine payment instructions are verified out-of-band — classically, a callback to a number already on file, not one supplied in the requesting email — before funds move. These are conditions of cover: skip the callback and the claim can be reduced or declined. The right response is to treat the condition as free risk management. Write a callback procedure your finance team can genuinely operate, apply it without exception — especially to urgent requests apparently from senior people, because urgency and seniority are the fraudster’s standard tools — and the procedure both prevents most losses and preserves cover for the ones it does not.
The tidy version: crime cover pays when money is stolen; cyber cover responds when systems and data are compromised. A ransomware event that halts trading is cyber. An employee embezzling by manipulating the ledger is crime. The untidy middle is where a systems compromise is the route to a money theft — a mailbox intrusion that studies your supplier correspondence for weeks, then times a convincing payment redirect. Is that a cyber incident or a crime loss? Under some wording pairs, both respond in part; under others, each policy’s fraud or crime exclusions push the loss towards the other, and a poorly matched pair can leave invoice fraud sitting in the seam between them.
The answer is not to buy one and hope. It is to hold the two policies’ wordings up against each other — the cyber policy’s crime and funds-transfer exclusions against the crime policy’s social engineering clause — and establish before any loss which policy carries which scenario. We cover this mapping in detail in our cyber-crime overlap guide; the point here is that it is a solvable wordings problem, and solving it is part of placing either policy properly.
Every business that pays supplier invoices has social engineering exposure, which in practice means every business. But the exposure concentrates in recognisable places: finance and accounting functions moving money daily; businesses with high payment volumes or high-value single payments — property transactions, wholesale, import and export; cash-handling operations; businesses where one trusted person controls a whole financial process end to end, which is the classic fraud environment; and growing firms whose controls have not kept pace with their payment volumes. Underwriters will ask about segregation of duties, dual authorisation and reconciliation frequency — and, as with every line we place, the businesses that describe their controls accurately get wordings that fit and claims that pay. Describe the risk properly; structure the cover around how the money actually moves. That is the whole method.
Employee dishonesty cover typically extends to dishonest acts by directors and officers acting as employees, but wordings differ on senior individuals, and dishonesty by a sole controlling shareholder-director is generally not insurable — the company cannot insure against its own controlling mind. Where ownership and management are concentrated, the definitions need particular attention.
Fidelity guarantee is the traditional, narrower form: employee dishonesty only. Commercial crime is the broader modern product, typically adding third-party fraud, forgery, funds transfer fraud and social engineering cover. Many management liability packages include a crime section along fidelity lines, so the question to ask of any existing policy is which fraud routes it actually covers, not just whether the word crime appears.
Usually not to the full policy limit. Most insurers apply a sub-limit to social engineering fraud and impose verification conditions — typically that payment details and instructions are verified by callback to a known number before transfer. If the procedure was not followed, cover can be reduced or lost. The practical advice is to agree procedures you can actually operate, then operate them every time, including when the request is urgent and appears to come from the top. Urgency and seniority are precisely the levers fraudsters pull.
They answer different questions. Cyber responds to incidents affecting systems and data — breach response, business interruption from an attack, ransomware. Crime responds to money being stolen, by employees or outsiders, with or without a computer involved. Some losses touch both, and invoice fraud in particular can fall between standard wordings. The clean approach is to hold both covers and have the social engineering and funds transfer position mapped across the pair, so the answer to “which policy pays?” exists before the money leaves.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.