FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Crime

Social engineering cover conditions: why these claims fail

In short: Social engineering cover — the crime extension that responds when an employee is deceived into transferring money to a fraudster — is usually sold subject to verification conditions: the payment or bank-detail change must have been verified by callback to a known number, or by an equivalent out-of-band check, before release. Many wordings write this as a condition precedent, meaning that if the check was not done, on that occasion, there is no cover — however good the procedures usually are. Claims fail not because the fraud is excluded but because the insured’s real-world process did not match the words on the day it mattered.

What social engineering cover is

Traditional crime insurance grew up around employee dishonesty: the insured’s own people stealing from it. Social engineering fraud — also appearing in wordings as impersonation fraud, fraudulent instruction or payment diversion fraud — is different: an outsider deceives an honest employee into doing the damage themselves. The classic forms are invoice fraud (a supplier’s bank details are “updated” to the fraudster’s account), CEO fraud (an urgent payment instruction appears to come from a senior executive), and conveyancing-style diversion of completion or deal monies. Because the employee acted honestly and the payment was authorised, these losses often fall outside base fidelity cover — hence the specific extension, usually with its own sub-limit, and usually with conditions attached.

The verification condition

The standard condition requires that, before acting on a payment instruction or a change of bank details, the insured verified the request by a means independent of the channel the request arrived through — most commonly a telephone callback to a number already held on file for the payee, not a number given in the request itself. Some wordings extend this to dual authorisation for payments above a threshold, or to specific procedures the insured described in its proposal.

The logic is fair enough: the check is precisely the control that defeats the fraud, and the insurer prices the cover on the assumption it happens. The severity lies in how the requirement is drafted.

Condition precedent: the words that decide claims

Where verification is written as a condition precedent to liability, cover for a given loss exists only if the condition was satisfied for that loss. There is no materiality argument and no proportionality: if the callback was not made on the transaction that went wrong, the claim fails, even if the procedure exists, is documented, and was followed the other fifty-one weeks of the year. The insurer does not need to show the breach caused the loss. This is exactly the scenario in which social engineering claims are declined in practice — and fraudsters engineer that scenario deliberately: the request arrives at 4.45pm on the day before completion, marked urgent and confidential, from someone senior, precisely so the check is skipped.

Milder drafting exists. Some wordings make verification a general condition (where remedies for breach may be more limited), or apply the requirement only above a monetary threshold, or require the insured to have “maintained” procedures rather than to have followed them on each occasion. The differences are worth real money; two policies with the same premium and the same sub-limit can behave oppositely on the same facts.

Why claims actually fail

The recurring patterns: the callback was made to the number in the fraudulent email — which verifies the fraud, not the payee; the change of bank details was processed by a different team from the payments team, and the wording’s condition attached to detail changes, not just payments; the threshold was misread, so a “small” payment below the dual-authorisation limit but above the verification threshold went out unchecked; the proposal form described a procedure more rigorous than the one actually operated, creating both a condition problem and a fair presentation problem under the Insurance Act 2015; or the loss was discovered late and notification conditions compounded the difficulty. Almost none of these are exotic. They are gaps between a written procedure and a Tuesday afternoon.

Making procedure match wording

The work is alignment, in both directions. Read the condition and rewrite the internal procedure so it satisfies the words exactly: callbacks to independently held numbers, applied to bank-detail changes as well as payments, with the evidence (who called, when, what number) recorded where a claims handler can find it. Then read the procedure and negotiate the wording where it demands more than the business can reliably do — a threshold that fits the payment profile, verification duties placed on the teams that actually exist. Train for the exception, not the routine: the fraud is designed for the urgent Friday request, so the procedure must hold precisely then, with no senior-override path. And when the cover is placed, describe the controls accurately — an optimistic proposal form is a declined claim waiting upstream.

How Apex approaches crime placements

We treat the verification condition as the heart of the placement, not boilerplate: which wording’s conditions this client can genuinely satisfy every day, what the sub-limit should be against the realistic worst payment, and whether the fair presentation matches the process on the floor. Social engineering cover that cannot pay is worse than none, because it buys confidence instead of protection.

Frequently asked questions

What is a condition precedent in a crime policy?

A term that must be satisfied before the insurer has any liability for the loss in question. Where verification by callback is a condition precedent and the callback was not made on the transaction concerned, the claim fails on that ground alone — the insurer does not have to show the breach caused the loss.

Does a callback to the number in the email satisfy the condition?

No. The point of the condition is verification through a channel independent of the request. Calling a number supplied in the fraudulent message verifies the fraudster. Wordings typically require a number already held on file or independently obtained, and a callback to anything else is treated as no callback.

Is social engineering fraud covered by standard crime insurance?

Often not by the base employee dishonesty cover, because the employee acted honestly and the payment was authorised. Most insurers offer it as a specific extension with its own sub-limit and verification conditions, and the drafting of those conditions varies widely between wordings.

What should we check before renewal?

Three things: whether the verification requirement is a condition precedent and exactly what it attaches to (payments, detail changes, thresholds); whether your actual day-to-day process — including under time pressure — satisfies it verbatim; and whether the procedures described in your proposal match reality, since the Insurance Act 2015 duty of fair presentation applies to those statements.

Would your cover pay on your worst Friday afternoon?
We will read your crime wording against your real payment process and close the gap in whichever direction it runs. Bristol-based, FCA-regulated, wordings first.
Call 0117 325 0027  info@apexinsurancebrokers.co.uk

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.

Want a broker to look at your commercial cover?
If you have your renewal pack, Statement of Fact or schedule, send it over and we’ll come back with options — no forms to fill in. Arranging cover for the first time? That works too. Or call 0117 325 0027.
Start a commercial quote →
Get a quote →