Commercial Crime Coverage Triggers
A commercial crime claim must fit the purchased insuring agreement, including its definitions, covered property, causal wording, limits, and reporting conditions.
- Employee theft, forgery, premises theft, transit loss, computer fraud, and funds-transfer fraud are distinct grants.
- Dishonesty alone does not establish coverage; the wording and timing rule control.
On this page9 sections
A commercial crime claim must fit the specific insuring agreement purchased and the form’s definitions, covered property, causal wording, limits, and reporting conditions. Employee theft, forgery, premises theft, transit loss, computer fraud, and funds-transfer fraud are different coverage grants. A bank-transfer scam or missing inventory is not automatically covered just because dishonesty was involved. The issued policy’s wording controls, and discovery-versus-loss-sustained timing is a separate question.
The agreement is the starting point
A commercial crime policy is a set of selected coverage grants rather than a general promise to reimburse every loss involving dishonesty. The declarations or schedule should identify each selected insuring agreement and limit. Each grant has its own definitions, exclusions, causal language, covered property, and conditions. Begin a claim analysis by describing what disappeared, who caused it, how the transfer or taking happened, and what the insured knew and when.
The Texas P&C exam outline includes crime as a policy form and identifies burglary, robbery, theft, and mysterious disappearance as insurance terms. Those labels help describe the event, but they do not alone prove coverage. A policy might define theft, require direct loss, exclude an unexplained shortage, or offer a special limit for particular property. Read the selected agreement rather than relying on the everyday meaning of “crime insurance.”
Employee Theft generally addresses direct loss of money, securities, or other covered property resulting from theft by an employee, subject to the policy’s definition of employee and theft. A form may extend to unidentified employees or collusion, but the wording controls. The agreement is not the same as a liability policy that pays a customer injured by negligent supervision; it concerns the insured’s loss of property as described in the contract.
Forgery or Alteration may address loss resulting directly from a forged or altered check, draft, or other covered instrument. A forged check drawn on the company account differs from a customer disputing a card transaction or a vendor submitting a false invoice. Some forms exclude instruments signed or endorsed by an authorized person or require that the forgery be legally valid. Identify the instrument, signature, account, payment, and causal chain.
Premises theft and money-and-securities coverage examine where the property was located and who had custody. A cash drawer stolen from a locked shop after a break-in is not the same as a cashier robbed while carrying a deposit to the bank. Forms may define premises, safe, financial institution, employee custody, and transit. The insured should preserve alarm records, deposit slips, camera footage, receipts, and incident reports.
Electronic fraud requires careful classification
Computer-fraud coverage generally turns on a specified fraudulent computer act and a direct causal connection to the loss. The actual form might require unauthorized entry, alteration, destruction, or use of a computer system. A criminal email that merely persuades a bookkeeper to send a valid payment instruction can raise a different question from malware that alters account data or causes a bank transfer without the insured’s knowledge.
Funds-transfer fraud agreements often focus on fraudulent instructions to a financial institution directing a transfer from an insured account without the insured’s knowledge or consent. That fact pattern differs from one where an employee knowingly sends the bank a valid instruction after being deceived by someone impersonating a vendor. Read the policy definition of a fraudulent instruction and its requirements for authorization, authentication, and verification.
Social-engineering or fraudulent-impersonation coverage may be offered by endorsement for payments an employee authorizes after a criminal poses as a trusted person. It can have a sublimit, verification condition, waiting period, or exclusions for voluntary parting with property. Do not assume a computer-fraud grant covers social engineering. The endorsement’s coverage grant and any fraud-prevention conditions determine the answer.
Use the payment path to classify an electronic loss. Ask who created the payment instruction, who received it, who authorized it, whether the bank followed it, and whether the insured’s system was accessed or manipulated. If a criminal impersonated the CEO, did the employee send an otherwise authorized transfer? If the criminal hacked credentials and sent the bank an instruction without employee approval, was the bank’s action unauthorized under the form? These differences can decide which agreement to examine.
Client property and employee plans
Some forms cover customer money, securities, or other property entrusted to the insured when an employee steals it. That is not automatically the same grant as theft of the insured’s own property. A warehouse, property manager, payroll processor, or law firm should determine whether it had custody, a contractual duty, and an insurable interest, and whether client-property coverage was selected.
Employee-benefit plans raise a separate fidelity question. ERISA generally requires a bond for people who handle plan funds, subject to statutory details and exceptions. A standard company employee-theft agreement may not satisfy the plan’s separate bonding requirement. Verify the covered plan, officials, required amount, qualifying instrument, policy period, and who is insured under the bond or crime form.
A fidelity bond is often marketed alongside commercial crime insurance, but the relationship and protected interest differ from a surety bond. In a fidelity policy, the business or plan may be insured against specified dishonest acts. In a conventional surety bond, the principal’s duty to the obligee is guaranteed and the surety often seeks reimbursement. Read the parties and grant rather than assuming the word “bond” tells you the coverage.
Direct loss and valuation
Crime forms commonly require direct loss of covered property. A business should separate stolen funds from consequential costs such as lost future sales, reputational harm, customer goodwill, or the cost of upgrading controls. Some products offer limited investigation expenses or restoration costs, while others do not. Business-income coverage or cyber insurance may be relevant to other consequences, but one policy’s grant does not silently add coverage to another.
An unexplained inventory variance does not automatically establish theft. A stock count can be wrong because of spoilage, waste, recording errors, unrecorded sales, damaged goods, or misdelivery. The insured should reconcile purchase records, point-of-sale transactions, invoices, return logs, access records, and physical counts. If evidence identifies a dishonest act, document the actor’s status and how the loss occurred.
Ownership is not always straightforward. A company can hold customer funds in trust, possess leased equipment, or store goods for another party. Whether an interest is insured depends on the policy and the insured’s legal responsibility. Identify who owned the property, who had custody, whether the insured was contractually liable, and whether the schedule extends to property of others. Quantify the direct loss using reliable records and policy valuation provisions.
Timing is a separate trigger question
Commercial crime forms may be written on a discovery or loss-sustained basis. The timing wording can affect whether a loss that began in one period but came to light in another is assigned to a particular policy. A separate inventory page compares those structures. For this topic, remember that timing does not replace agreement selection: a timely discovered event still must fit a purchased insuring agreement and satisfy its definitions and exclusions.
The sample Discovery Form CR 00 22 11 15 cited below ties coverage to loss resulting directly from an occurrence that is discovered during the policy period or a specified extended period. It is a form example, not a universal rule. The policy may also address prior insurance, known circumstances, multiple acts, aggregation, and reporting. When switching insurers, coordinate prior-loss disclosures and retroactive or discovery provisions instead of assuming a renewal creates a clean slate.
Notice, proof, and cooperation conditions matter after an event. Preserve original emails, wire confirmations, checks, bank statements, server logs, payroll exports, and access-control records. Notify the carrier according to the policy, report crime to law enforcement if required or useful, and avoid altering evidence. Ask what proof is needed before deleting a mailbox or resetting devices. These steps do not establish coverage, but they preserve information needed to evaluate it.
A repeatable claim analysis
First name the insured and property owner. Confirm that the claimant is insured for the agreement and that the business had an ownership or covered legal interest in the lost item. Next describe the act without assuming its legal label: employee diversion, forged instrument, robbery, unauthorized bank instruction, voluntary payment after deception, or unexplained shortage. Then identify the coverage agreement that directly addresses those facts.
After locating the grant, check definitions such as employee, money, securities, other property, premises, computer system, financial institution, and occurrence. Trace the actual causal chain and custody. Review the selected limit, deductible, sublimit, exclusions, notice duties, proof-of-loss requirements, and discovery or loss-sustained structure. A limit shown on a declarations page cannot create a coverage grant that was never purchased.
For example, an employee steals customer checks and deposits them into a personal account. The analyst should identify whose funds were stolen, whether the employee fits the policy definition, whether the loss was direct, and whether the insured bought employee theft or client-property coverage. A payment bond or CGL form does not automatically answer that first-party crime question.
For a fake supplier wire, preserve the original email and headers, payment request, call-back records, bank instructions, account details, and approval trail. Determine whether the employee authorized the payment, whether the computer system was manipulated, and whether a fraudulent instruction reached the bank. Then test each selected crime agreement separately. A business that skipped its written payment-verification protocol may face a condition or exclusion issue if the form contains one.
| Loss scenario | Agreement to review | Question that separates it |
|---|---|---|
| Employee diverts a customer payment | Employee theft or client-property wording | Who owned the money, and was the actor an employee? |
| A forged check is paid | Forgery or alteration | Was the instrument covered and did forgery directly cause the loss? |
| Cash disappears on a bank run | Money and securities in transit | Who had custody and was the route/carrier within the wording? |
| A fake email leads to a wire | Funds-transfer or social-engineering endorsement | Was the transfer unauthorized at the bank or authorized by a deceived employee? |
| Inventory is short after a count | Employee theft only if evidence supports it | Is there evidence of a dishonest act, rather than error or shrinkage? |
Common coverage traps
- Assuming one crime grant covers every employee and third-party theft.
- Treating a forged invoice as automatically covered under forgery coverage.
- Equating an employee-authorized but deceived wire with a transfer the bank made without the insured’s knowledge.
- Assuming computer fraud and social engineering are interchangeable.
- Treating unexplained inventory shrinkage as proof of theft.
- Assuming client assets, ERISA plans, investigation costs, business interruption, or extortion are included.
- Believing correct timing alone establishes a covered cause of loss.
Frequently asked questions
Does commercial crime cover all fraud?
No. The loss must fit a selected agreement and its definitions, causal wording, exclusions, limit, and conditions.
Is computer fraud the same as social engineering?
Not necessarily. A computer grant may require an unauthorized computer act; social engineering often concerns an employee deceived into authorizing a transfer.
Does property insurance cover employee theft?
Some package forms offer limited crime coverage, but employee theft may be excluded or restricted under property coverage. Check the actual policy.
Does discovery wording cover any old loss found now?
No. Timing provisions do not remove the requirement that the loss fit an insured agreement and satisfy conditions.
Prepare for the Texas P&C exam
The Texas Property and Casualty exam course helps you map each crime loss to its insuring agreement, covered property, and policy trigger.
Common questions
Does commercial crime cover all fraud?
No. The loss must fit a selected agreement and its definitions, causal wording, exclusions, limit, and conditions.
Is computer fraud the same as social engineering?
Not necessarily. A computer grant may require an unauthorized computer act; social engineering often concerns an employee deceived into authorizing a transfer.
Does property insurance cover employee theft?
Some package forms offer limited crime coverage, but employee theft may be excluded or restricted under property coverage. Check the actual policy.
Does discovery wording cover any old loss found now?
No. Timing provisions do not remove the requirement that the loss fit an insured agreement and satisfy conditions.