Commercial Crime Insurance: Employee Theft, Fraud and Funds Transfer Coverage


Commercial crime insurance pays for money, securities and property your business loses to theft and fraud, including theft by your own employees. Most standard forms cover employee theft, forgery or alteration of checks, computer fraud, funds transfer fraud, and theft of money on or off your premises. Social engineering losses, where someone tricks an employee into sending money, usually need a specific endorsement. Your general liability and property policies generally don't cover any of this, and a cyber policy may not either.
Crime coverage is one of the most commonly missing pieces in a small-business business insurance program. Owners assume their property policy covers theft (it covers some theft by outsiders, typically not by employees) or that the cyber policy covers a wire fraud loss (sometimes, often with a low sublimit). This guide explains what each part of a crime policy does, where it overlaps with cyber, and the federal bond requirement if you sponsor a 401(k).
Why employee theft is its own risk
Theft from inside a business is usually slow and quiet: a bookkeeper writing checks to a shell vendor, a manager voiding cash sales, an employee adding a relative to payroll. It often runs for years before anyone notices, and the losses add up over that whole period.
In California there's an additional wrinkle. Labor Code §224 bars wage deductions that aren't authorized in writing or permitted by law. The Labor Commissioner notes that the IWC wage orders allow a deduction for a cash shortage or loss only when the employer can show it was caused by a dishonest or willful act or gross negligence, cautions that this exception may not comply with the Labor Code, and says an employer who takes a deduction does so at its own risk (DIR deductions FAQ). In practice, docking a paycheck is rarely a realistic way to recover a theft loss. A crime policy is.
What commercial crime insurance covers
Crime policies are built from separate insuring agreements. You choose which ones to buy and set a limit for each. ISO's standard crime program and most carrier forms include some version of the following.
Insuring agreement | What it typically covers | Example |
Employee theft (older forms: "employee dishonesty") | Theft of money, securities or other property by an employee, whether or not you can identify which employee | Office manager pays personal credit cards from the operating account over three years |
Forgery or alteration | Loss from forged or altered checks, drafts or promissory notes drawn on your accounts | Someone steals a check from your mail, changes the payee and amount, and cashes it |
Inside the premises: theft of money and securities | Money and securities stolen from inside your premises or a bank premises | Night-time break-in; the cash drawer and safe are emptied |
Inside the premises: robbery or safe burglary of other property | Other property taken in a robbery or safe burglary | Armed robbery of jewelry inventory |
Outside the premises | Money and securities lost while being carried by a messenger or armored car | Employee robbed on the way to the bank with the day's deposit |
Computer fraud | Loss from the fraudulent use of a computer to transfer money or property out of your premises or account | Hacker gets into your accounting system and pushes payments out |
Funds transfer fraud | Loss from fraudulent instructions sent to your bank, purporting to come from you, without your knowledge or consent | Criminal emails your bank, impersonating you, and requests a wire |
Money orders and counterfeit money | Accepting counterfeit currency or money orders that aren't paid | Counterfeit $100 bills taken at the register |
Some editions combine computer fraud and funds transfer fraud into one insuring agreement. The names matter less than the definitions, so read them.
Employee theft: what to check
Who counts as an "employee." Standard forms include current employees and usually leased workers. Many also include people for a short period after termination. Volunteers, directors, trustees and independent contractors are often not included unless added by endorsement. This matters for nonprofits that rely on volunteer treasurers.
Third-party coverage. If your employees work at clients' premises (janitorial, home health, IT services), you may need a "clients' property" endorsement so the policy pays when your employee steals from the client.
Owner exclusion. Theft by you, your partners or LLC members is typically excluded.
Prior knowledge. Most forms end coverage for an employee once you, or a manager not involved in the theft, learn that person has committed a dishonest act. If you discover a problem and keep the person on, you may not be covered for what happens next.
Inventory shortages. Most standard forms exclude losses whose only proof is an inventory count or a profit-and-loss comparison. You need other evidence tying the loss to an employee.
Forgery or alteration
This applies to outgoing instruments, meaning checks you write or that are drawn on your accounts. It doesn't cover bad checks a customer gives you. Positive-pay services from your bank reduce this exposure, and underwriters often ask whether you use them.
Social engineering: the gap most policies leave open
Social engineering fraud is the biggest crime exposure for most small businesses today. A criminal impersonates a vendor, client or executive, usually by email, and convinces your employee to send money or change payment details. The employee authorizes the transfer.
That last fact is why standard insuring agreements often don't respond:
Computer fraud typically requires an unauthorized intrusion or use of a computer to move the money. In a social engineering loss, no one hacked the bank account; an authorized employee sent the wire.
Funds transfer fraud typically requires fraudulent instructions sent to your bank without your knowledge or consent. Here the bank got legitimate instructions from you.
Employee theft requires the employee to intend the theft. Your deceived employee didn't.
The fix is a social engineering fraud (or "fraudulent impersonation" / "fraudulently induced transfer") endorsement or insuring agreement. It's usually written with a lower sublimit than the rest of the policy, and it almost always comes with a verification condition: the policy pays only if your employee confirmed the request through a separate channel, such as calling a known phone number on file, before sending the money. If your staff skipped that step, the claim can be denied.
The FBI's Internet Crime Complaint Center received 24,768 business email compromise complaints in 2025 with more than $3 billion in reported losses, second only to investment fraud among cyber-enabled fraud types (2025 IC3 Annual Report). Those are only reported losses.
Would your policy pay if an employee wired money to a fake vendor tomorrow? TSM is an independent agency — we compare carriers for you. Call (209) 524-6366 (Modesto) or (530) 221-3031 (Redding).
Crime insurance vs cyber insurance: where the gap sits
Crime and cyber liability insurance both respond to "computer" events, but they're built to cover different losses.
| Commercial crime | Cyber |
Core purpose | Your direct loss of money, securities and property to theft or fraud | Costs and liability from a data breach, network attack or system outage |
Employee theft | Yes, the core coverage | Generally no |
Funds stolen by a hacker | Computer fraud / funds transfer fraud | Sometimes, often as a sublimited add-on |
Social engineering wire fraud | Only with a social engineering endorsement | Sometimes, as a sublimited add-on |
Breach notification, forensics, credit monitoring | No | Yes |
Ransomware extortion and data restoration | No | Yes, typically |
Business interruption from a network outage | No | Yes, typically |
Lawsuits from customers whose data was exposed | No | Yes |
The gap: many businesses assume one policy handles a fraudulent wire, and it turns out neither does. The crime policy has no social engineering endorsement, and the cyber policy's "cyber crime" or "funds transfer" sublimit is small or excludes losses the employee voluntarily authorized. Or the opposite: both policies have small sublimits, and "other insurance" clauses send the carriers arguing over which one goes first.
The fix is to decide deliberately where each risk sits. For most businesses that means employee theft and funds-loss coverage on a crime policy with an adequate social engineering limit, and breach response, extortion and liability on cyber. Then confirm the two policies' other-insurance language works together. Our guide to what cyber insurance covers for a California business has the cyber side.
ERISA fidelity bonds for 401(k) plans
If your business sponsors a 401(k) or other retirement plan covered by Title I of ERISA, federal law (ERISA §412) generally requires every person who handles plan funds to be bonded. That's typically you, your CFO or bookkeeper, and anyone with authority over plan money. This is the one crime-type coverage that's legally required for many employers.
According to the Department of Labor's Field Assistance Bulletin 2008-04:
Rule | Requirement |
Amount | At least 10% of the funds handled, measured by the highest amount handled in the preceding plan year |
Minimum | $1,000 per plan |
Maximum required | $500,000 per plan official per plan |
Plans holding employer securities | Maximum required rises to $1,000,000 (plan years beginning on or after January 1, 2008) |
Deductible | Not allowed. The bond must cover from the first dollar of loss |
Who is protected | The plan, not the employer |
What it covers | Loss to the plan from fraud or dishonesty: theft, embezzlement, forgery, misappropriation and similar acts |
Two practical points:
It can ride on your crime policy. The DOL allows the plan to be added to an employer's crime coverage through a rider or endorsement (often called an "ERISA rider"), as long as it meets the bond rules, including the no-deductible requirement. A standalone ERISA bond also works.
It is not fiduciary liability insurance. The bond covers theft from the plan. Fiduciary liability insurance covers claims that plan fiduciaries breached their duties, such as choosing poor investments or charging excessive fees. The DOL is explicit that fiduciary liability insurance is neither required by nor subject to ERISA §412. Many employers carry both.
Fully unfunded plans that pay benefits only from the employer's general assets are generally exempt. Check with your plan administrator.
Discovery vs loss-sustained forms
Crime policies don't use the occurrence or claims-made triggers you see on liability policies (compare claims-made vs occurrence). They use one of two triggers:
Loss-sustained form: covers loss that occurs during the policy period and is discovered during it or within a set period afterward, often one year.
Discovery form: covers loss discovered during the policy period (or a short window after), regardless of when it occurred, subject to any retroactive date.
Because employee theft can run for years, the trigger matters when you switch carriers. Most forms include provisions for loss that started under a prior policy, but they have conditions. Don't let a crime policy lapse between carriers, even for a day.
Crime insurance vs bonds and other policies
[Surety bonds](/resources/surety-bonds-explained-why-your-business-needs-one) (license, contract, permit bonds) protect your customers or a government agency, not you. They're a guarantee you'll perform; the surety can recover from you.
Janitorial or service bonds that you show customers are often a form of third-party crime coverage protecting your clients. Confirm whether yours is a true surety bond or crime coverage.
Your [business owner's policy](/resources/business-owners-policy-bop-california) may include a small employee dishonesty or money-and-securities add-on. Check the limit. It's often too low to matter.
[Directors and officers insurance](/resources/what-d-o-insurance-covers-and-who-actually-needs-it) and [employment practices liability](/resources/employment-practices-liability-insurance-epli-for-businesses) cover lawsuits against management. They don't reimburse stolen money.
How much crime coverage do you need?
There's no single formula. These questions get you to a defensible number:
How much cash and liquid funds could one person reach? Look at the largest amount in your operating accounts at peak season, payroll included.
How long could theft go undetected? If no one reviews bank statements independently each month, assume years, and size the limit for the total.
What's your largest regular wire or ACH payment? Your social engineering limit should cover at least one fraudulent payment of that size.
Do you hold client funds or work in client premises? Add third-party or client property coverage.
Do you sponsor a retirement plan? Add the ERISA bond at the required amount.
Controls that matter to carriers and to you
Underwriters ask about these, and they reduce losses:
Separate duties: the person who writes checks shouldn't reconcile the bank account
Owner or outside accountant reviews bank statements monthly
Dual approval on wires above a set amount
Call-back verification on any change to vendor bank details, using a number already on file
Positive pay on checking accounts
Mandatory vacations for anyone handling money (many schemes come out when the person is away)
If you do find a theft, preserve records, don't confront the employee until you've talked to your agent and an attorney, and report promptly. Crime policies require prompt notice and a sworn proof of loss within a set time. See how to file a business insurance claim for the documentation process, and make crime coverage a line item at your annual insurance review.
FAQs
Does business insurance cover employee theft?
Usually not unless you have commercial crime coverage or an employee dishonesty endorsement. General liability doesn't cover your own lost money, and commercial property forms typically exclude dishonest acts by employees.
What is the difference between crime insurance and cyber insurance?
Crime insurance covers your direct loss of money and property to theft and fraud, including employee theft. Cyber insurance covers breach response, ransomware, network outages and data liability. Fraudulent wire transfers can fall between the two, so check both policies.
Does crime insurance cover social engineering fraud?
Not under most standard insuring agreements, because an employee voluntarily authorized the payment. You typically need a social engineering or fraudulent impersonation endorsement, which often requires call-back verification.
Is an ERISA bond required for a 401(k)?
Generally yes. Each person who handles plan funds must be bonded for at least 10% of the funds handled, with a $1,000 minimum and a $500,000 maximum per plan ($1,000,000 if the plan holds employer securities). The bond can't have a deductible.
Can I deduct stolen money from an employee's paycheck in California?
Generally not without significant risk. Labor Code §224 limits deductions, and the Labor Commissioner says an employer who deducts for a loss does so at its own risk unless it can prove dishonesty, willfulness or gross negligence.






Comments