Social engineering cover conditions: why these claims fail
What social engineering cover is
Traditional crime insurance grew up around employee dishonesty: the insured’s own people stealing from it. Social engineering fraud — also appearing in wordings as impersonation fraud, fraudulent instruction or payment diversion fraud — is different: an outsider deceives an honest employee into doing the damage themselves. The classic forms are invoice fraud (a supplier’s bank details are “updated” to the fraudster’s account), CEO fraud (an urgent payment instruction appears to come from a senior executive), and conveyancing-style diversion of completion or deal monies. Because the employee acted honestly and the payment was authorised, these losses often fall outside base fidelity cover — hence the specific extension, usually with its own sub-limit, and usually with conditions attached.
The verification condition
The standard condition requires that, before acting on a payment instruction or a change of bank details, the insured verified the request by a means independent of the channel the request arrived through — most commonly a telephone callback to a number already held on file for the payee, not a number given in the request itself. Some wordings extend this to dual authorisation for payments above a threshold, or to specific procedures the insured described in its proposal.
The logic is fair enough: the check is precisely the control that defeats the fraud, and the insurer prices the cover on the assumption it happens. The severity lies in how the requirement is drafted.
Condition precedent: the words that decide claims
Where verification is written as a condition precedent to liability, cover for a given loss exists only if the condition was satisfied for that loss. There is no materiality argument and no proportionality: if the callback was not made on the transaction that went wrong, the claim fails, even if the procedure exists, is documented, and was followed the other fifty-one weeks of the year. The insurer does not need to show the breach caused the loss. This is exactly the scenario in which social engineering claims are declined in practice — and fraudsters engineer that scenario deliberately: the request arrives at 4.45pm on the day before completion, marked urgent and confidential, from someone senior, precisely so the check is skipped.
Milder drafting exists. Some wordings make verification a general condition (where remedies for breach may be more limited), or apply the requirement only above a monetary threshold, or require the insured to have “maintained” procedures rather than to have followed them on each occasion. The differences are worth real money; two policies with the same premium and the same sub-limit can behave oppositely on the same facts.
Why claims actually fail
The recurring patterns: the callback was made to the number in the fraudulent email — which verifies the fraud, not the payee; the change of bank details was processed by a different team from the payments team, and the wording’s condition attached to detail changes, not just payments; the threshold was misread, so a “small” payment below the dual-authorisation limit but above the verification threshold went out unchecked; the proposal form described a procedure more rigorous than the one actually operated, creating both a condition problem and a fair presentation problem under the Insurance Act 2015; or the loss was discovered late and notification conditions compounded the difficulty. Almost none of these are exotic. They are gaps between a written procedure and a Tuesday afternoon.
Making procedure match wording
The work is alignment, in both directions. Read the condition and rewrite the internal procedure so it satisfies the words exactly: callbacks to independently held numbers, applied to bank-detail changes as well as payments, with the evidence (who called, when, what number) recorded where a claims handler can find it. Then read the procedure and negotiate the wording where it demands more than the business can reliably do — a threshold that fits the payment profile, verification duties placed on the teams that actually exist. Train for the exception, not the routine: the fraud is designed for the urgent Friday request, so the procedure must hold precisely then, with no senior-override path. And when the cover is placed, describe the controls accurately — an optimistic proposal form is a declined claim waiting upstream.
How Apex approaches crime placements
We treat the verification condition as the heart of the placement, not boilerplate: which wording’s conditions this client can genuinely satisfy every day, what the sub-limit should be against the realistic worst payment, and whether the fair presentation matches the process on the floor. Social engineering cover that cannot pay is worse than none, because it buys confidence instead of protection.
Frequently asked questions
What is a condition precedent in a crime policy?
A term that must be satisfied before the insurer has any liability for the loss in question. Where verification by callback is a condition precedent and the callback was not made on the transaction concerned, the claim fails on that ground alone — the insurer does not have to show the breach caused the loss.
Does a callback to the number in the email satisfy the condition?
No. The point of the condition is verification through a channel independent of the request. Calling a number supplied in the fraudulent message verifies the fraudster. Wordings typically require a number already held on file or independently obtained, and a callback to anything else is treated as no callback.
Is social engineering fraud covered by standard crime insurance?
Often not by the base employee dishonesty cover, because the employee acted honestly and the payment was authorised. Most insurers offer it as a specific extension with its own sub-limit and verification conditions, and the drafting of those conditions varies widely between wordings.
What should we check before renewal?
Three things: whether the verification requirement is a condition precedent and exactly what it attaches to (payments, detail changes, thresholds); whether your actual day-to-day process — including under time pressure — satisfies it verbatim; and whether the procedures described in your proposal match reality, since the Insurance Act 2015 duty of fair presentation applies to those statements.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
