Commercial crime insurance for growing businesses
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
Most founders think about insurance in terms of the obvious risks: someone gets hurt, a client sues, a product fails. Crime is the one that catches scaling companies off guard, because the exposure grows quietly. As you hire a finance team, move more money, and add layers between the person approving a payment and the person who founded the company, the opportunity for loss — whether through a rogue insider or an external fraudster impersonating one — grows with you. This page explains what commercial crime cover actually does, why it tends to come up around Series B, and how it fits alongside the cyber policy you may already have.
What does commercial crime insurance actually cover?
At its core, a commercial crime policy covers your business against direct financial loss caused by criminal acts. It is not about a broken laptop or a defamation claim — it is about money and assets leaving your business dishonestly. The classic trigger is employee theft or fraud: a member of staff who diverts funds, falsifies invoices, sets up a fake supplier, or manipulates payroll. But modern crime policies have broadened well beyond the insider.
Depending on how the wording is structured, cover commonly extends to include:
- Employee dishonesty and theft — the traditional fidelity element, covering loss caused by an employee acting dishonestly for personal gain.
- Third-party fraud — loss caused by an external party, such as forged instruments or fraudulent alteration of documents.
- Social engineering and payment fraud — where an employee is deceived into transferring funds, for example by a spoofed email appearing to come from a supplier or a senior colleague changing bank details. This is often offered as a specific insuring clause, sometimes with its own sub-limit.
- Funds transfer fraud — the unauthorised electronic transfer of your money from your account by a fraudster.
- Loss of money and securities — theft of physical cash or negotiable instruments, on premises or in transit.
The exact scope varies significantly between insurers and wordings, which matters more here than in almost any other class. Two policies that both say "crime" on the schedule can respond very differently to a social-engineering loss in particular — some treat it as a headline cover, others bury it under a low sub-limit or attach conditions around callback verification. It is worth having someone read the wording against how your business actually moves money.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Approaching a round, or just added a finance hire? We'll map where your money moves and pressure-test what a crime policy would actually pay on — before you sign anything.
Get a tailored quote →Why does the risk grow as we scale?
When you are five people around a table, the founder often still signs off every payment and knows every supplier by name. Fraud is hard to hide because there is almost no distance between the money and the person who cares most about it. That intimacy is exactly what you lose as you grow, and losing it is what creates the exposure.
Several things change at once as a company scales:
- Payment volumes rise. More suppliers, more contractors, more frequent payment runs — a fraudulent invoice or a diverted payment is far easier to lose in the noise.
- The finance function grows and specialises. You hire people who can create, approve and reconcile payments. Controls help, but any process involving humans and money can be gamed, and a trusted, capable insider is precisely the person best placed to do it.
- Founders step back from the detail. The people approving payments increasingly are not the people who own the company, which weakens the instinctive "that doesn't look right" check.
- You become a more attractive target. A funded, growing company with real cash in the bank and a public profile is a more appealing mark for external fraudsters running social-engineering campaigns.
None of this means your team is untrustworthy. The overwhelming majority of finance hires are exactly who they appear to be. But insurance exists for the low-probability, high-impact event — and a well-placed fraud, discovered months later, can remove a meaningful chunk of the capital you just raised. That is the scenario crime cover is built for.
Why does crime insurance often come up around Series B?
There is no rule that says crime cover belongs at a particular stage — but in practice it tends to surface around Series B, and the reasons are structural rather than arbitrary. By Series B most companies have crossed a threshold on all the factors above at once: the finance team is a proper function rather than one person, monthly outgoings are substantial, and the amount of cash sitting in the business is large enough that a single fraud could be genuinely painful.
It also reflects how a founder's insurance programme matures. Earlier rounds tend to prioritise the covers that come up first: directors' and officers' (D&O) insurance, which investors commonly require as part of a term sheet from around Series A; employers' liability, which is a legal requirement in the UK once you employ staff; and often cyber. Crime is the next layer — the cover you add once the business is complex enough that internal controls alone no longer feel like enough of a backstop. If you are thinking about how these fit together across a funding journey, our stage-by-stage insurance guide walks through what tends to matter when.
The honest position is that the right time is when your exposure justifies it, not when a slide deck tells you to buy. For some businesses — a fintech, a marketplace, anyone handling client money or high transaction volumes — that point can arrive much earlier. This is a good conversation to have with a broker rather than to guess at.
How is this different from cyber insurance?
This is the question we get asked most, and it is a fair one, because the two genuinely overlap in places. The cleanest way to think about it: cyber insurance is primarily about your systems and data; crime insurance is primarily about your money.
A cyber policy typically responds to events like a network breach, a ransomware attack, a data privacy incident, or business interruption caused by your systems going down. It funds the response — forensics, legal, notification, restoring systems — and covers your liability to others when their data is compromised. Its centre of gravity is the technology and the data.
A crime policy responds when money or assets are taken from you dishonestly, whether the method is digital or not. Its centre of gravity is the financial loss itself.
The overlap that causes the most confusion is social-engineering and payment fraud — the spoofed email that persuades an employee to change a supplier's bank details and send a payment to a criminal. That loss can look like both a "cyber" event and a "crime" event, and the frustrating reality is that it may be covered under either, both, or neither, depending on how each policy is worded and where the insuring clauses sit. Some cyber policies include a modest social-engineering extension; some crime policies treat it as a core cover; some exclude it unless specific verification controls were followed. This is exactly where a gap can open up quietly — you assume the cyber policy has it, the cyber policy assumes it is a crime exposure, and you find out which is true only after a loss.
Well-structured, the two policies complement each other cleanly: cyber handles the breach and the data fallout, crime handles the theft of your funds. Poorly structured, you can end up double-insured on one scenario and exposed on another. Getting them to sit together properly is one of the more valuable things a broker does for a scaling company, and it is a big part of why we treat cyber and crime as a joined-up conversation rather than two separate quotes. Our cyber insurance guide covers the other side of that pairing in more detail.
What drives the cost and the scope of cover?
We won't quote you a figure on a web page — anyone who does is guessing — but it is useful to understand what an insurer looks at when pricing and structuring a crime policy, because those same factors are within your control and often lower both your risk and your premium. Underwriters tend to focus on:
- Your headcount and the size of your finance function — more people with access to payments generally means more exposure.
- Transaction volumes and values — how much money moves through the business, and how often.
- Your internal controls — segregation of duties, dual authorisation on payments, supplier verification and callback procedures on bank-detail changes. Strong controls are the single biggest thing you can influence, and they matter both to your risk and to how an insurer views you.
- Sector and business model — handling client money, operating a marketplace, or high-value B2B payments all shift the risk profile.
- The limit and structure you choose — the overall limit of indemnity, and any specific sub-limits for social engineering, are the main scope levers. Limits are usually offered as illustrative options — for example £1m, £5m or £10m — and the right choice depends on your cash exposure, not on a standard number.
The strength of your payment controls is worth dwelling on, because it does double duty: it makes a fraud far less likely to succeed in the first place, and it presents you to insurers as a well-run risk. Dual authorisation and a firm callback rule on any change of supplier bank details are two of the highest-value habits a scaling finance team can build, insurance or no insurance.
Do we really need it, or are our controls enough?
Good controls genuinely reduce the frequency of loss — and you should invest in them regardless. But controls reduce probability; they do not eliminate it, and they do nothing to reimburse you when something slips through anyway. The frauds that reach insurers are usually the ones that defeated the controls: the trusted senior employee who understood exactly how to work around the process, or the social-engineering attack sophisticated enough to survive a rushed callback on a busy Friday.
So the honest answer depends on your exposure. If you are moving meaningful sums, have a growing finance team, and hold enough cash that a single well-executed fraud would hurt, crime cover starts to earn its place. If you are still very small with one person handling every payment, it may sensibly wait — though even then, the social-engineering risk is real. There is no universal trigger, which is precisely why this is a conversation worth having with someone who will look at your specific setup rather than sell you a template.
Insurance for a scaling company should be one joined-up programme — crime, cyber, D&O and the rest sitting together with no quiet gaps. That's the part we're built for. Talk to an Apex specialist and we'll hand-hold you through it, round by round.
Get a tailored quote →Commercial crime cover rarely makes the headline list of "startup insurance" — it lives in the second wave, alongside the covers you add once the business is real, complex and worth defrauding. That is exactly why it gets overlooked, and exactly why the loss lands so hard when it does. If you want to understand whether it belongs in your programme yet, and how to make it fit cleanly with your cyber cover rather than overlap or clash with it, speak to an Apex specialist — we'll give you a straight read on your specific exposure.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
