Crime insurance is a commercial policy that reimburses a business for money, securities, and other property lost to theft, forgery, fraud, or employee dishonesty. It pays the policyholder directly rather than covering liability to someone else, and it fills a gap most owners don’t notice until a loss happens: general liability and commercial property policies routinely exclude losses from dishonest acts. The FBI’s Internet Crime Complaint Center recorded over $2.77 billion in business email compromise losses alone in 2024, and that figure captures just one slice of the crime that targets businesses.1FBI Internet Crime Complaint Center. 2024 IC3 Annual Report
How the Coverage Is Structured
Most commercial crime policies follow standardized forms developed by ISO (the Insurance Services Office, now part of Verisk), which carriers modify with industry-specific endorsements.2Verisk. ISO Policy Forms The core structure stays consistent across insurers even when the endorsements differ.
Policies are written on one of two bases, and the difference matters. The dominant form is “discovery,” which covers any loss you discover during the policy period regardless of when the crime actually occurred.3ePerils. ISO Commercial Crime Policy – Discovery Form Fraud often hides for months or years, so a discovery policy is the broader protection. When one expires or is canceled, there is usually an extended reporting window of about 60 days to catch losses found shortly afterward.
The alternative, a “loss sustained” form, covers only losses that both happen and are discovered during the policy period or within about a year after it ends. It can pick up losses that occurred under a prior crime policy if you have maintained continuous coverage, but for most buyers the discovery form is the standard choice.
What Crime Insurance Covers
ISO’s program divides coverage into separate insuring agreements. You buy only the ones that match your risks, each with its own limit.
Employee Theft
This is the agreement most buyers come for. It pays for the loss of money, securities, or other property stolen by an employee, whether that employee is identified or not, and whether acting alone or with outsiders.3ePerils. ISO Commercial Crime Policy – Discovery Form Forgery by an employee also falls here rather than under the separate forgery agreement.
One definitional point catches businesses off guard. An “occurrence” for employee theft is all loss caused by one or more employees, whether from a single act or a long series of acts.4The Hartford. Crime Coverage Part If a bookkeeper siphons $10,000 a month for three years, the full $360,000 is one occurrence subject to one limit and one deductible. That can help you (one deductible to meet) or hurt you (if the total blows through the per-occurrence limit).
Forgery or Alteration
This agreement responds to forged or altered checks, drafts, promissory notes, and similar instruments drawn on your accounts or made by someone acting as your agent.3ePerils. ISO Commercial Crime Policy – Discovery Form It also pays reasonable legal costs if you are sued for refusing to honor a forged instrument, provided the insurer consents to the defense. Those defense costs do not count against your limit, which is unusual and genuinely useful. Businesses that process heavy check volume (law firms with trust accounts, real estate agencies holding deposits, retailers taking paper payments) tend to carry higher limits here.
Inside the Premises
Two agreements cover theft at your location. The first pays for loss of money and securities from theft, unexplained disappearance, or destruction, and for damage to the building, safes, vaults, and cash registers from an actual or attempted theft.3ePerils. ISO Commercial Crime Policy – Discovery Form The second covers “other property” (anything that is not money or securities) lost to robbery of a custodian or to safe burglary. Money and other property carry separate limits, so a cash-heavy retailer and a warehouse full of electronics will want very different allocations. Insurers often require alarms, cash safes, and restricted access to sensitive areas, and meeting those benchmarks reduces premiums.
Outside the Premises
This covers money and securities while they are being transported or temporarily held away from your business: bank deposits, armored car runs, and similar transfers. If you move cash or valuable documents between locations, this agreement closes a gap the inside-premises coverage leaves open.
Social Engineering and Impersonation Fraud
Business email compromise is now the most expensive category of crime aimed at businesses. In 2024 the FBI received more than 21,000 complaints involving fraudsters posing as executives, vendors, or clients to trick employees into wiring money.1FBI Internet Crime Complaint Center. 2024 IC3 Annual Report
Standard crime policies handle these losses poorly. Insurers often invoke “voluntary parting”: when an employee is tricked into authorizing a wire, the argument goes, the business voluntarily sent the money rather than having it stolen. The computer fraud and funds transfer fraud agreements generally require an unauthorized system intrusion, not a deceived employee pressing send.
Social engineering coverage is available as a separate endorsement. Chubb, for example, offers one covering vendor, executive, and client impersonation with limits up to $250,000 per occurrence.5Chubb. Social Engineering Fraud Coverage for Crime Insurance Sublimits on these endorsements tend to run well below the main policy limits, so a business with heavy wire-transfer exposure should push for higher amounts during underwriting. The dividing line is simple: if a hacker breaks into your bank portal and moves money without anyone’s approval, that is funds transfer fraud under the standard policy. If a hacker sends a convincing email as the CEO and your controller wires the money voluntarily, you need the social engineering endorsement.
What Crime Insurance Does Not Cover
Exclusions are where most denials start, and several surprise buyers who thought they were fully protected.
- Losses provable only by inventory records. If your sole evidence is that ending inventory does not match the books, the claim gets denied. You need supporting records: transactions, shipping logs, access logs, cameras. This exclusion sinks more claims than any other.
- Indirect and consequential losses. The policy pays for what was taken. Lost revenue, reputational harm, business interruption, and extra expenses from the aftermath are not covered.
- Losses after known dishonesty. Once you know an employee has acted dishonestly, any further loss caused by that employee is excluded. Keeping someone on while you watch and wait voids coverage for whatever they do next.
- Data and intellectual property. Trade secrets, customer lists, and proprietary data fall outside crime insurance; data losses sit with cyber coverage.
- Legal and investigation costs. The cost of building your claim, hiring forensic accountants, or paying attorneys is generally not covered, with the narrow exception of defense costs under the forgery agreement.
- Government seizure. Property confiscated or destroyed by government authorities is excluded even when the seizure stems from criminal activity.
- Salary and compensation fraud. Inflated salaries, unauthorized bonuses, and excessive commissions paid to dishonest employees are typically excluded.
The inventory-records exclusion deserves extra weight because it creates a practical requirement most businesses do not meet. Detailed purchase records, receiving logs, camera footage, and access controls are what separate a payable claim from a denial. If you cannot show how and roughly when the goods disappeared, the insurer will not pay no matter how large the shortfall.
Crime Insurance Compared to Fidelity Bonds and Cyber Policies
A fidelity bond is a narrower product limited to employee dishonesty. It does not cover third-party theft, outsider forgery, or premises robbery. A full commercial crime policy includes employee theft as one of several agreements and goes well beyond it, which makes a standalone fidelity bond redundant for most businesses. The exception is when a law or regulation requires a fidelity bond by name, as ERISA does for employee benefit plans.
Crime and cyber policies overlap awkwardly around phishing attacks that end in fraudulent wire transfers. Both might respond to the same incident, and each insurer may point at the other as primary. The usual division: crime insurance covers the financial theft, cyber insurance covers data breach notification, regulatory fines, and liability to affected third parties. Insider threats can trigger both at once, one for the money and one for the compromised data. Coordinating both policies with your broker before a loss is the safest way to avoid a coverage gap or a finger-pointing dispute later.
If You Run an Employee Benefit Plan
Sponsors of employee benefit plans face a federal bonding mandate that often gets overlooked. Under ERISA, every person who handles plan funds or property must be covered by a fidelity bond equal to at least 10% of the funds they handled in the prior year, with a minimum of $1,000 and a maximum of $500,000. For plans holding employer securities such as an ESOP, the ceiling rises to $1,000,000.6Office of the Law Revision Counsel. 29 USC 1112 – Bonding
The requirement applies to most ERISA-covered retirement plans and funded welfare benefit plans. Unfunded plans, government plans, and church plans are exempt. Banks, insurers, and registered broker-dealers may qualify for exemptions under specific capital and regulatory conditions. The bond must come from a surety listed on the Treasury Department’s approved sureties circular (Circular 570).7U.S. Department of Labor. Protect Your Employee Benefit Plan With an ERISA Fidelity Bond Failing to maintain the required bond is itself an ERISA violation, separate from any theft.
Policy Conditions That Can Sink a Claim
Three conditions deserve attention well before any loss happens.
Notice. Most policies require notification as soon as practicable after discovering a loss, with a hard deadline typically between 30 and 60 days. Missing that window hands the insurer grounds to deny the claim even if the loss is otherwise fully covered. Call the insurer the day you discover the problem and follow with written notice the same day.
Proof of loss. After you report, the insurer will request a sworn proof of loss statement, commonly due 60 days from the request. It requires a detailed accounting supported by bank statements, payroll reports, audit findings, or transaction logs. Incomplete or late submissions are among the most common reasons claims stall or get denied. For any claim of real size, bringing in a forensic accountant to prepare the proof of loss is worth the cost.
Continuous coverage. Because discovery-form policies pay based on when the loss is found, a lapse can leave you with no coverage at all, even for a crime that happened while you were insured. When switching carriers, confirm the new policy picks up losses from under the prior one. A one-day gap can create an uncovered window you cannot repair later.
Filing a Claim
When you discover a covered loss, speed outweighs precision. You can refine the numbers later; you cannot undo late notice.
Call the insurer first, then send written notice. Do not wait to calculate the full loss. Pull together what you have: bank statements, payroll, inventory logs, audit reports, camera footage. For employee theft, assemble the transaction records that show the pattern and identify any accomplices.
The insurer will send a proof of loss form requiring a sworn, itemized accounting. This is the most important document in the file, and insurers scrutinize it closely. Errors or unsupported numbers give adjusters reasons to cut or deny the payout.
The investigation that follows may include employee interviews, forensic accounting, and coordination with law enforcement. Policies require full cooperation, including access to financial records and help with recovery. Some policies require you to pursue legal action against responsible employees as a condition of coverage.
One avoidable mistake sinks otherwise valid claims: reimbursing customers or third parties before filing. If an employee stole from your clients and you repay them out of pocket before submitting the claim, you have eliminated your own covered loss. The insurer will not pay for money you already gave away.
How Payouts Are Calculated
Once a claim is approved, the payout depends on three numbers: your per-occurrence limit, your deductible (called a retention in many crime policies), and any amounts already recovered. The insurer pays the loss above the retention, up to the applicable limit.4The Hartford. Crime Coverage Part If more than one retention could apply to the same loss, only the highest one applies.
Stolen inventory is generally paid at cost rather than at selling price. With strong documentation, forensic accountants typically use an inventory roll-forward: starting from a known inventory level and adjusting for purchases, sales, and normal shrinkage to calculate the missing amount. When records are partial, accountants may compare the claimed loss against figures from historical tax returns as a reasonableness check. How well you kept records before the theft directly determines how much you can prove and recover after.
If law enforcement recovers property or a court orders restitution after the insurer has paid, the insurer has subrogation rights and can recover from the responsible party. Courts generally hold the insurer is entitled to reimbursement out of any recovery up to what it paid.8Office of Justice Programs. Theoretical and Practical Impact of Private Insurance on Restitution Allocation varies by jurisdiction, but expect to repay the insurer for any restitution that overlaps with what the policy already covered.