Employee Dishonesty Coverage
Employee dishonesty coverage can protect a business against specified direct loss of money, securities, or other property caused by an employee’s theft.
- The claim must fit a selected crime-policy agreement and its definitions, causal wording, exclusions, limit, and conditions.
- A bookkeeping mistake, imprudent purchase, vendor scam, unexplained shortage, or employee’s negligent act is not automatically covered.
On this page12 sections
- Identify the employee under the form
- What counts as dishonest theft
- Prove a direct loss
- Discovery and employee knowledge
- Inventory shortage and proof
- A dishonest payment diversion
- A deceived employee and fraudulent wire
- Customer property and plan assets
- Quantifying and reporting a loss
- A claim file that can prove employee dishonesty
- Frequently asked questions
- Prepare for the Texas P&C exam
Employee dishonesty coverage can protect a business against specified direct loss of money, securities, or other property caused by an employee’s theft. The claim must fit a selected crime-policy agreement and its definitions, causal wording, exclusions, limit, and conditions. A bookkeeping mistake, imprudent purchase, vendor scam, unexplained shortage, or employee’s negligent act is not automatically covered.
Employee dishonesty coverage is a crime-policy agreement that can reimburse an insured business for specified direct loss of money, securities, or other property caused by an employee’s dishonest act. The claim must fit the selected insuring agreement and the policy’s definitions, causal language, exclusions, limit, and conditions. The phrase does not mean every mistake, bad decision, contract breach, or dishonest act by anyone connected to the business is insured.
Identify the employee under the form
The first task is identifying who qualifies as an employee under the form. Commercial crime forms may define employee by status, service, compensation, or duties and may address temporary workers, leased workers, managers, directors, trustees, volunteers, or people furnished under a staffing agreement differently. A person called a contractor on payroll records could still fit a policy definition, or might be excluded. Do not import the workers’ compensation or tax definition into a crime policy.
The next question is whose property was lost. A business may own cash, inventory, equipment, or securities; it may also hold a client’s property, employee benefit plan assets, or funds in trust. Standard employee-theft wording may cover property of the insured, while separate language may be needed for client property or an ERISA plan. A firm should list the assets employees can access and check whether each is within the form’s covered-property grant.
What counts as dishonest theft
The policy often requires that theft be committed by an employee with the intent to cause the insured a loss and obtain an improper financial benefit for the employee or another person. Specific definitions vary. An employee who diverts customer money to a personal account presents a classic fact pattern. A bookkeeper who incorrectly posts a payment, forgets a deposit, or makes an unwise purchase may have caused a loss without committing covered theft.
The causal wording matters. A form may cover loss resulting directly from employee theft. The insured should trace the act to the property loss and separate it from later business consequences, such as lost profits, investigation costs, customer lawsuits, penalties, or remediation expenses. Some policies offer limited extra coverage for these consequences; they do not necessarily fall under the employee-theft agreement itself.
Employee theft can involve collusion. A dishonest employee may act alone, cooperate with another employee, or enlist a third party. Some forms expressly cover collusion; others contain limitations or separate definitions. A business should not assume that outside help defeats coverage or that all related losses can be aggregated without limit. Determine who committed each act, the dates, property, and any aggregation provision.
Prove a direct loss
Policy knowledge and discovery provisions matter. A form can end coverage for a particular employee once a specified person learns of that employee’s dishonest act, and a discovery form may assign losses by when they are discovered. Prior acts, prior insurance, multiple policies, reporting extensions, and known circumstances can affect response. This is separate from deciding whether the underlying conduct meets the employee-theft agreement; see the distinct discovery-versus-loss-sustained article for timing analysis.
Common exclusions may address indirect loss, inventory shortage without evidence of theft, loss discovered outside permitted timing, dishonest acts by certain owners or principals, voluntary transfers, consequential loss, or property not within the grant. Exact terms vary. An exclusion should be read with exceptions and endorsements; do not rely on a generic list as a policy-specific coverage decision.
Discovery and employee knowledge
Inventory shortage is a recurring challenge. A business may discover that 80 laptops are missing, but that count alone does not identify theft or the actor. The cause could be shrinkage, record error, spoilage, misdelivery, or unauthorized removal. A claim is stronger when access logs, inventory scans, shipping records, surveillance, receipts, or admissions establish a dishonest act and resulting direct loss. A policy may treat unexplained disappearance differently from proven employee theft.
Consider an accounts-payable clerk who creates a false vendor and routes company payments to a personal account over several months. The analysis asks whether the clerk is an employee under the form, whether money or property was covered, whether the act meets the theft definition, what direct loss occurred, when management learned of it, and which limit applies. The business should preserve payment approvals, bank statements, vendor files, emails, accounting-system audit logs, and device records.
Inventory shortage and proof
Now consider a legitimate employee who approves a real vendor invoice after receiving a convincing email that changes the vendor’s bank account. The employee may have been deceived but did not steal from the company. The loss may require a funds-transfer, computer-fraud, or social-engineering agreement rather than employee theft. Employee dishonesty coverage should not be stretched to encompass every fraudulent payment just because staff participated in the process.
A dishonest payment diversion
Client-property coverage matters to businesses that hold assets for others. A property manager collects rent, a law firm holds settlement proceeds, and a payroll processor transfers employee funds. If an employee steals those funds, the insured may suffer a legal liability or direct property loss. Verify that the policy extends to customers’ property and that the named insured’s interest and contractual responsibility fit the form. A client’s own fidelity policy may also apply, but coordination must be reviewed.
ERISA plans have separate fidelity-bond requirements for people who handle plan funds. A general employee-theft limit may not satisfy the plan’s rules. Confirm the plan and covered officials, the required amount, policy form, deductible, aggregate, and whether the bond protects the plan itself. An endorsement that covers employee dishonesty for the company does not automatically satisfy every ERISA condition.
A deceived employee and fraudulent wire
Loss quantification should start with the direct property taken, not a broad estimate of the company’s total financial harm. Reconcile bank statements, checks, receivables, physical inventory, and recovered property. Deduct salvage or restitution as the policy requires. Separate the principal theft amount from fees, interest, legal expenses, lost customers, and investigation costs, then determine whether any endorsement covers additional categories.
Internal controls help prevent and detect loss, but they do not replace insurance terms. Segregate vendor setup, invoice approval, and payment release; require independent call-back verification for bank changes; reconcile accounts promptly; limit privileged system access; and review inventory variances. Insurers may ask about controls at underwriting, and policy conditions can impose specific duties. Follow the issued wording and document compliance.
Customer property and plan assets
When reporting a suspected theft, notify the insurer as soon as required, preserve evidence, cooperate with the investigation, and consider law-enforcement reporting if the form requires it or the insurer recommends it. Avoid destroying devices, altering ledgers, or confronting suspects in a way that compromises evidence. Ask the carrier for a written list of proof needed, including employee status, chronology, property valuation, and discovery date.
Quantifying and reporting a loss
Build a chronology before deciding which policy period may respond. Record when the dishonest act began, when it ended, when the insured first discovered facts that would cause a reasonable person to suspect employee dishonesty, and when the insurer received notice. A discovery form and a loss-sustained form may use different timing rules. Renewals, retroactive dates, prior insurance, and any extended reporting or discovery period can affect which contract is implicated. Use the actual form’s trigger rather than assuming the date the accountant finished an audit controls.
For example, a bookkeeper may divert small amounts over several years, while a new controller discovers an unexplained account in November. The relevant questions include whether the covered insured discovered the loss during the current policy period, whether the wording aggregates related acts, whether a prior carrier received notice, and whether a discovery extension applies after cancellation. A suspicion may count differently from proof of the final total, so report the circumstances promptly instead of waiting until every transaction has been traced.
Keep records that show both what was known and when it became known: audit emails, bank alerts, interview notes, internal reports, board minutes, and insurer notices. Separate a preliminary indication of theft from later quantification. Give the carrier updates as the loss develops and follow any proof-of-loss deadline in the policy. If a business changes forms or carriers, ask how prior acts, known circumstances, and discovered losses are treated; a renewal does not automatically reset or extend coverage for an old theft.
Common errors include assuming every employee act is theft; treating an employee’s tax or HR classification as conclusive; assuming customer property and ERISA funds are covered; ignoring when management first learned of the act; treating a fake-invoice wire as employee theft; and adding business interruption or reputation costs to a direct-loss claim without policy support.
| Claim fact | Coverage question |
|---|---|
| Employee diverts cash to own account | Does the employee definition and theft grant apply, and can the business prove direct loss? |
| Employee approves fake vendor wire | Was this theft by an employee, computer fraud, funds-transfer fraud, or social engineering? |
| Inventory records show unexplained shrinkage | Is there evidence of theft, or could it be error, spoilage, or misdelivery? |
| Employee steals client funds | Does the form extend to customer property, and what is the insured’s property or legal interest? |
| Company discovers old theft after renewal | Which policy period applies under discovery/loss-sustained wording and prior insurance terms? |
A claim file that can prove employee dishonesty
A strong proof file connects the suspected employee to the act, the act to the property, and the property to a measurable direct loss. Preserve access logs, approval histories, check images, bank transfer records, accounting-system audit trails, vendor master changes, inventory records, and messages. Keep original exports when available and note who collected each item and when. The goal is to show a reliable chain of records, not just a suspicious balance or a manager’s conclusion that money is missing.
Interview witnesses separately and document dates, amounts, authority, and the employee’s access. Reconcile the books to independent bank statements, customer receipts, and physical counts. Identify which transactions the employee personally caused and which could have resulted from duplicate entries, coding errors, returned goods, or another worker. If the suspected employee had shared credentials, explain what controls existed and what evidence links the person to the activity. These facts can determine whether the loss fits the form’s requirement that an employee commit a dishonest act with the required intent.
Report the claim under the policy’s notice and proof requirements even if the investigation is unfinished. State what is known, distinguish estimates from confirmed amounts, and update the insurer as evidence develops. The policy may require a sworn proof of loss within a specified time after request, examination under oath, records access, or cooperation with recovery efforts. Give the carrier requested records promptly, but keep a copy of every submission and seek clarification when a demand is too broad or a deadline is unclear.
Frequently asked questions
Does employee dishonesty cover every dishonest employee act?
No. It covers only acts and property within the purchased agreement and its definitions, exclusions, timing, and limit.
Is an independent contractor an employee under the policy?
The crime form’s definition controls. Do not assume its answer matches tax or workers’ compensation status.
Does employee theft cover a customer’s money?
Only if the policy’s covered-property wording or an extension reaches client property and the insured has the required interest.
Is a fake supplier wire covered as employee theft?
Not automatically. If the employee authorized a transfer after deception, funds-transfer or social-engineering wording may be more relevant.
Prepare for the Texas P&C exam
The Texas Property and Casualty exam course helps you separate employee theft from other crime agreements and apply each policy definition to the facts.
Common questions
Does employee dishonesty cover every dishonest employee act?
No. It covers only acts and property within the purchased agreement and its definitions, exclusions, timing, and limit.
Is an independent contractor an employee under the policy?
The crime form’s definition controls. Do not assume its answer matches tax or workers’ compensation status.
Does employee theft cover a customer’s money?
Only if the policy’s covered-property wording or an extension reaches client property and the insured has the required interest.
Is a fake supplier wire covered as employee theft?
Not automatically. If the employee authorized a transfer after deception, funds-transfer or social-engineering wording may be more relevant.