Employee dishonesty coverage pays when your own people steal from you. Social engineering coverage pays when an outsider deceives your people into sending money willingly. Cyber coverage pays when your systems are breached. The same missing dollars can implicate all three — and which policy actually responds depends on exactly how the money left the building.
When a business discovers a six-figure hole in its accounts, the first question is never “which insuring agreement applies?” — but it becomes the only question that matters. A bookkeeper skimming for three years, a hacker inside the payment system, and a controller tricked by a convincing email produce the same wire out the door and three completely different coverage answers. Crime policies, social engineering endorsements, and cyber policies were each built for a different version of the loss, they carry very different limits, and the gaps between them are where businesses get burned. This article walks through what a commercial crime policy actually covers, why computer fraud coverage usually does not pay for a deception loss, what social engineering coverage adds, and where crime and cyber overlap — and where a loss can fall between them.

- What does a commercial crime policy actually cover?
- What counts as employee dishonesty — and what has to be proven?
- Why doesn’t computer fraud coverage pay for social engineering?
- What does social engineering fraud coverage actually do?
- Where do crime and cyber overlap — and where does a loss fall between them?
- What do underwriters expect before offering full limits?
- How does Avanti Group structure crime and cyber together?
What does a commercial crime policy actually cover?
A commercial crime policy is a package of separate insuring agreements — employee theft, forgery or alteration, theft of money and securities inside and outside the premises, computer fraud, and funds transfer fraud — each with its own trigger and often its own limit. It is the modern descendant of the fidelity bond, and it answers the oldest version of the question every commercial insurance program exists to answer: what happens when the money is simply gone? Two structural details matter more than buyers expect. First, crime coverage is written on either a discovery basis or a loss-sustained basis — the difference determines whether a theft that ran quietly for years before anyone noticed is covered by the policy in force when it happened or the one in force when it was found. Second, the insuring agreements are not interchangeable: a loss that fails the definition in one agreement does not get to borrow coverage from another. That is why the crime policy belongs in the same management-liability conversation as EPLI and the rest of the executive lines — all of them are policies where the definitions, not the limit on the declarations page, decide the claim.
What counts as employee dishonesty — and what has to be proven?
The employee theft insuring agreement covers loss of money, securities, or other property resulting directly from theft committed by an employee — and most forms require that the employee acted with manifest intent to cause the loss and obtain a benefit. That intent standard is the underwriting heart of the coverage: poor judgment, sloppy controls, and unauthorized-but-well-meaning transactions are not employee theft, no matter how much money they cost. The classic covered loss is the long embezzlement — the trusted bookkeeper, the fictitious vendor, the payroll ghost — discovered years in, which is exactly why the discovery and loss-sustained distinction above matters. Employees are already the source businesses underestimate most; the same pattern that drives EPLI claim frequency — exposure concentrated in the people closest to the operation — drives dishonesty losses too. One version of this protection is not even optional: federal law (ERISA section 412) requires fidelity bonding for people who handle employee benefit plan funds, generally ten percent of the funds handled, capped at $500,000 for most plans. The company’s own operating accounts enjoy no such mandate — that protection only exists if someone deliberately built it.
Why doesn’t computer fraud coverage pay for social engineering?
Because of one word: *voluntary*. The computer fraud and funds transfer fraud insuring agreements were written for an outsider who takes — a hacker who penetrates the system and moves money out, or a fraudster who sends the bank instructions the insured never authorized. In a social engineering loss, nobody takes anything. A controller receives an email that appears to come from the CEO, or a vendor’s compromised account sends new banking instructions on a real invoice, and an authorized employee willingly, deliberately sends the wire. The transfer itself is legitimate; only the instruction behind it is false. Carriers have long argued — and many courts have agreed, though decisions have gone both ways — that a voluntary payment is not a “direct” loss from computer fraud, because the fraud happened to a person, not to a system. The result is the signature coverage failure of this whole subject: a business holding a seven-figure crime limit discovers that the loss it actually suffered runs through the one insuring agreement it never bought. Coverage that looked fine on paper and failed when it actually mattered.
What does social engineering fraud coverage actually do?
Social engineering fraud coverage — sometimes labeled fraudulent instruction or deception fraud coverage — is a distinct insuring agreement, usually added by endorsement, that covers the voluntary transfer of funds by an employee who was intentionally deceived by an impostor. It exists precisely to fill the gap the computer fraud agreement leaves. It is also where the numbers deserve a hard look: social engineering coverage is routinely sublimited to a small fraction of the crime policy’s headline limit — commonly six figures or less on programs whose employee theft limit is seven. The FBI’s Internet Crime Complaint Center has for years reported business email compromise among the costliest fraud categories it tracks, with reported losses running into the billions of dollars annually — which makes social engineering one of the few exposures where the most likely modern loss meets the smallest limit on the policy. A sublimit is not a technicality; sublimits, exclusions, and conditions are the policy, and this endorsement usually carries all three — including, on many forms, a condition requiring the insured to have followed its own verification procedures before the transfer. The business decides what risk it is keeping and what risk it is transferring; a $100,000 sublimit under a $1 million crime limit is a keep decision, whether or not anyone made it on purpose.
Where do crime and cyber overlap — and where does a loss fall between them?
The overlap is real and so is the gap. A modern cyber policy responds when the insured’s systems are compromised — and many now offer their own cybercrime or funds transfer fraud endorsements, also sublimited, that shingle over the crime policy’s territory. A business email compromise that starts with an intrusion into the insured’s own network can plausibly trigger both policies, at which point “other insurance” clauses and claim strategy decide which carrier leads. But consider the loss that touches neither trigger cleanly: the *vendor’s* email is compromised, not yours; the fraudulent banking instructions arrive on a genuine invoice; your employee follows them. No breach of your systems — so the cyber policy’s core agreements are quiet. A voluntary transfer — so computer fraud is quiet. Unless a social engineering endorsement sits on one policy or the other, a six-figure loss has just landed in the seam between two policies that each looked complete. It is the same lesson dependent business interruption teaches on the property side: your dependence on other people’s systems is your exposure, whether or not your own systems ever fail. And because a pure funds-transfer loss usually exposes no personal information, it may not even trigger a breach-notification duty under Iowa’s security breach statute (Iowa Code chapter 715C) — the money is gone, and the legal system’s cyber machinery never switches on.
What do underwriters expect before offering full limits?
Verification controls — and they are not negotiable theater. Carriers offering meaningful social engineering limits want to see callback verification to a known number (not one supplied in the request) for any new or changed payment instructions, dual authorization above a dollar threshold, and out-of-band confirmation for executive-initiated transfers. Some forms make those controls a condition of coverage, which means a business that skips its own callback procedure on a Friday afternoon may have skipped its insurance along with it. There is a market-timing point here too: the cyber market has softened substantially — Avanti Group’s read as of mid-2026 is that nearly every buyer should be remarketed, because better coverage at the same or better rate is the norm rather than the exception right now. Businesses that put verification controls in writing and hold to them are exactly the accounts carriers are competing for — on both the crime and cyber side of the house.
How does Avanti Group structure crime and cyber together?
Crime, social engineering, and cyber coverage answer three versions of the same event, and Avanti Group structures them as one system rather than quoting each in a vacuum. That starts with a Business Risk Diagnostic™ — who can move money, what the payment-change procedure actually is (not what the manual says), which vendors can redirect funds with an email, and where the current crime and executive-lines program leaves the seams described above. Then the limits get built deliberately: employee theft sized to the real embezzlement exposure, social engineering limits negotiated up from the token sublimit, cyber’s fraud endorsements coordinated with the crime form so the two policies interlock instead of pointing at each other. A fast quote answers none of those questions; most agents will hand you one anyway. A business that knows exactly how its money can leave — by hand, by hack, or by ask — is the one whose insurance program is built for the loss it will actually have.
Frequently Asked Questions
Is social engineering fraud covered under a standard crime policy?
Usually not without an endorsement. The computer fraud and funds transfer fraud insuring agreements are built for unauthorized takings; a social engineering loss is a voluntary transfer by a deceived employee, and carriers have often denied those claims — with courts split on the question. Dedicated social engineering (fraudulent instruction) coverage exists specifically to close that gap, and it is typically sublimited well below the policy’s headline limit.
What is the difference between computer fraud and funds transfer fraud coverage?
Computer fraud covers loss from an outsider using a computer to fraudulently transfer property from inside your premises or bank — a hacking-style taking. Funds transfer fraud covers fraudulent instructions sent to your financial institution purporting to be from you, without your knowledge. In both, the insured never authorizes the movement. The moment an authorized employee willingly sends the money, you have left both agreements and entered social engineering territory.
Should business email compromise be insured under crime or cyber?
Potentially both, deliberately. Many cyber policies now offer cybercrime endorsements that overlap the crime policy’s fraud agreements, and a BEC event that involves intrusion into your own systems can trigger each. The structure to avoid is accidental: two sublimited endorsements with conflicting conditions and “other insurance” clauses pointing at each other. The two forms should be placed and coordinated together so one of them clearly leads.
What does a discovery form versus a loss-sustained form mean?
A loss-sustained form covers theft that occurs during the policy period; a discovery form covers theft discovered during the policy period, whenever it occurred. Because embezzlement schemes commonly run for years before detection, the choice — and the continuity between old and new forms when switching carriers — determines whether a long-running theft is covered at all. It is one of the most consequential and least-discussed items in a crime placement.
Do verification procedures really affect coverage?
On many forms, yes. Some social engineering endorsements condition coverage on the insured having followed its stated verification procedures — callback to a known number for changed payment instructions, dual approval over a threshold. Underwriters also price and limit the coverage based on those controls. A written procedure that is actually followed does double duty: it prevents the loss and preserves the coverage if prevention fails.
Related reading
Other articles in the Commercial Foundations series:
- Ransomware Coverage Gaps: Sublimits, Coinsurance, and Exclusions — Most cyber policies do not pay ransomware losses up to the headline limit — a ransomware sublimit typically aggregates the extortion payment, negotiator, forensics, restoration, and sometimes the downtime loss under one reduced cap; cyber coinsurance shares every covered loss with the insured no matter how much limit was purchased (unlike the property-side penalty mechanism); and the exclusion families that surface in real claims — security-maintenance conditions tied to the application’s answers, end-of-life software, and state-sponsored-actor language — can shrink or erase recovery, while the softened mid-2026 market means businesses with MFA, EDR, and tested offline backups can frequently buy full limits without coinsurance if the account is positioned to today’s market instead of auto-renewing the hard-market form. Opens the Cyber Liability cluster.
- Social Engineering and Wire Fraud: Why Most Cyber Policies Sublimit It — Social engineering losses leave through channels that look legitimate — an authorized wire, an approved vendor, a routine payment run — which is why cyber policies cap them at a sublimit far below the headline limit and make verification procedures a condition of coverage; UCC Article 4A (Iowa Code ch. 554) allocates fraudulent-wire losses to the business rather than the bank, and the controls that persuade underwriters to raise the cap — callback verification, dual authorization, banking-change waiting periods — are the same ones that prevent the loss. Second article in the Cyber Liability cluster.
- Business Email Compromise: Anatomy of a Six-Figure Loss — A BEC loss is an authorized payment procured by deception — assembled from weeks of reconnaissance inside a compromised vendor mailbox, executed through a routine payment run where every indicator reads normal — and the coverage analysis turns on deception and verification rather than network intrusion: cyber social engineering sublimits, crime endorsements, breach-response coverage when a mailbox is compromised (including Iowa Code chapter 715C notification duties), and the verification controls that both prevent the loss and preserve the coverage. Third article in the Cyber Liability cluster.
