Commercial crime

Commercial crime insurance: social-engineering and payment-fraud terms

A forged invoice and an employee’s theft are different loss patterns. The finance workflow should be described before comparing crime options.

Clothing, bags and accessories displayed on open shelving and rails in a small shop.
By Zara HashmiCyber and financial controls8 min read

The way money leaves matters

Commercial crime insurance should be compared against the business’s actual authorization path. A technology startup may pay cloud vendors by wire, a property owner may process rent and maintenance invoices, and a retailer may hold cash and stock. For each, identify who can request, approve and release money. A fraudulent instruction that an employee follows can be treated differently from unauthorized access to a system or theft by an employee.

A retailer may receive a vendor email changing bank instructions, an employee may divert receipts, or someone may access the accounting system without permission. Each involves a different actor and authorization path. “Fraud coverage” on a quote is too broad a phrase to answer how a specific payment was approved.

The FTC recommends clear purchase and invoice approval procedures and close checks of invoices. Describe those controls honestly in the application; they also help reconstruct what happened if a suspicious payment is discovered.

Map the payment process and records

Document the payment chain from invoice receipt to bank confirmation. Include vendor-master changes, email and phone verification, dual approval, transaction thresholds and audit logs. If a supplier changes its bank details, record the independent number used to verify the change. The insurer’s social-engineering wording may refer to specific verification steps, so a process that exists only on a policy manual’s page is not enough to describe the actual operation.

List who can create vendors, change bank details, approve invoices and release a transfer. Gather dual-approval rules, callback practices, banking agreements, transaction limits and audit logs. Identify cash handling, point-of-sale access, inventory custody and the employees or contractors involved.

For a suspected loss, preserve the original message, headers, approval trail, bank instructions and timeline. Promptly contact the bank and use the reporting instructions on the policy. The insurance review should not delay immediate operational steps to try to recover funds.

Compare distinct crime grants

Put employee theft, forgery, computer fraud, funds-transfer fraud and social-engineering endorsements in separate rows. For each, note its defined loss, insured property, limit, sublimit, deductible, discovery condition and notice deadline. An employee who knowingly diverts a payment, a hacker who initiates an unauthorized transfer and a fake vendor who persuades a real approver are not one event type. Ask which grant the proposed form is intended to address in each scenario.

Check employee theft, forgery, computer fraud, funds-transfer fraud and any social-engineering endorsement separately. Read definitions of employee, direct loss, authorized transfer and fraudulent instruction. Compare limits and sublimits, deductibles, discovery periods, reporting conditions and any requirement for a verification callback.

The California insurance department describes crime as a property line with options for forgery, embezzlement and other losses. Modern payment schemes may be handled differently by specific endorsements. Do not infer that an employee who willingly follows a fraudulent instruction is covered under a computer-fraud provision.

Follow an altered invoice through approval

An altered vendor invoice is a useful tabletop test for social-engineering terms. Start with the email, then trace the bank-detail change, callback, second approval and final transfer. If a step was skipped, document why. Compare the sequence with the form’s definition of fraudulent instruction and any required verification control. The exercise also shows which records the finance team could preserve quickly after discovering a suspicious transfer.

Suppose a familiar supplier’s email account is compromised and sends new bank details. Record who received the message, whether a callback used a known number, who approved the change and how the bank instruction reached the payment system. A policy comparison needs that sequence because social-engineering, computer-fraud and funds-transfer definitions can turn on who initiated or authorized the transfer.

The FTC advises businesses to verify invoices and train staff to recognize fake requests. Make the procedure practical: a second approver, independent phone confirmation for banking changes and a log of the verified contact. Describe the existing process to the market without implying a proposed control was already in operation.

Distinguish internal theft from external deception

The employee definition can matter where a property manager uses temporary staff or a retailer uses contractors for stock handling. Ask whether those workers are included and what evidence of their duties is required. For external deception, focus on who actually authorized the transfer and whether the instruction was verified. These factual distinctions belong in the submission and the incident file; neither the label “crime” nor a bank’s refusal to reverse funds decides coverage.

Employee theft may involve someone with ordinary access taking cash or inventory. An external actor may instead persuade an employee to make an authorized payment. Check whether the form defines employee to include temporary workers or contractors and how it handles inventory, money and securities. The two events should not be collapsed into “crime.”

Use job duties and access records to describe who can handle refunds, cash, vendor setup and banking. If the business has multiple stores, compare whether a limit is per location, per occurrence or shared across the policy. Keep loss history and control changes available for the submission.

Check discovery and response duties

Crime policies can use a defined discovery moment and a notice deadline. Set an escalation route from a store manager, bookkeeper or property manager to the person who can contact the bank and the policy reporting channel. Preserve the original invoice, bank record and system log. A delayed internal investigation should not silently consume a reporting period; the issued wording dictates the notice question.

A suspicious transfer may be found immediately, while a pattern of diverted receipts may emerge at reconciliation months later. Ask when the policy says a loss is discovered, who must receive notice and what proof-of-loss documentation is required. Preserve records before changing accounts or employee access, subject to the business’s security and legal advice.

Contact the bank promptly for a payment that may be recoverable and follow the policy’s reporting instructions. A crime claim and a cyber incident may involve different reporting contacts. Document the timeline and expenses accurately; the available grant and limit cannot be determined from the fact that a fraud occurred.

Reconcile controls with each quoted condition

A social-engineering endorsement may ask for a callback or dual authorization before a changed payment is sent. Put each condition beside the business’s real payment procedure and ask who performs it. If the quoted condition is impractical for small payments or after-hours approvals, raise that mismatch before choosing the option; an attractive sublimit does not replace the process it requires.

Review bank permissions, vendor-master edits and employee access after a role change. Separate preventive controls from the policy’s discovery and reporting requirements. A callback is good practice, but an insurer’s form can still define a covered loss narrowly. The comparison should note the grant, sublimit, retention, verification condition and reporting address for each proposed crime part.

A retailer with cash drawers and online supplier payments has more than one workflow. Test employee theft with inventory and cash records, then test a fraudulent wire with invoice and bank logs. Those examples will expose different documentation needs. Keep the review grounded in the business’s own controls rather than borrowing a checklist from a large company that has a separate treasury department.

Make controls and coverage review repeatable

Save the workflow narrative and the comparison of each quoted grant. Train staff to use a known phone number to verify changed payment instructions and review bank permissions when roles change. Revisit policy terms when online payment volume or vendor access grows.

The policy wording, declarations and endorsements control. This guide does not determine whether a particular transfer is insured; facts about deception, authorization and notice have to be tested against the issued terms.

Payment-fraud review questions

  • Who can alter vendor banking information and who verifies it?
  • Is social engineering separately offered and subject to a sublimit?
  • How do employee theft and computer fraud define their triggers?
  • What discovery and notice deadlines apply?
  • Can the business preserve an approval and transaction trail?

Sources

These sources provide general context. Policy wording, declarations and endorsements control the terms of any particular insurance contract.

Concerned about changed payment instructions?

Book a call with your payment workflow and current crime terms. We can compare each fraud grant with how your business actually moves money.

Book a call