Commercial crime insurance has long sat in the background of a company's program, but a shift in how fraud is committed is pulling it forward, with brokers increasingly asking for higher limits on coverage that used to be an afterthought, according to Lesley Rowe (pictured), vice-president of executive solutions at Trisura, which writes this cover primarily in the small and mid-market space.
The driver, Rowe said, is social engineering fraud. Historically, it was handled as a small sublimit, a modest aggregated amount tacked onto a policy. That is changing. "We're seeing brokers now ask for higher limits on that," she said, as more companies become exposed to the fraud, and more become aware of it once it happens. Funds-transfer fraud and impersonation are part of the same wave, she said, and the two often overlap – the impersonation that makes social engineering work is frequently the mechanism behind a fraudulent transfer.
That fraud can sit on more than one policy, which is part of why it confuses buyers. Social engineering and funds-transfer coverage can be found on cyber policies as well as crime policies, Rowe said. Her guidance is to avoid duplicating it. "It's probably better to have it in one," she said, rather than paying for the same protection in two places.
Underneath the newer fraud, though, the core of crime insurance remains what it has always been: protection against loss from within. Crime cover is a first-party coverage, Rowe said, protecting a company's own assets, and employee theft is the main insuring agreement most buyers are after. The scale of that underlying exposure is steady and substantial. Rowe pointed to the Association of Certified Fraud Examiners, which publishes its Report to the Nations every two years, and to one figure she called consistent: that around 5% of revenue is typically lost to occupational fraud – employee theft, misappropriation and the various forms of internal fraud.
What makes employee theft distinct from other insured losses, Rowe said, is the emotional weight that comes with it. A crime claim is not a straightforward filing, because it usually means confronting a betrayal. There is reputational hesitation – whether to pursue the employee, involve the police, or quietly handle it – and there is something harder to name. "There's also some shame involved with that, too," Rowe said. The affected company has, in her words, been hoodwinked by someone it trusted.
That trust is precisely what makes the schemes work, and why they run so long. It is often the most trusted employee who turns out to be responsible, Rowe said – the one who never takes vacation and never seems to get sick, because stepping away would expose the scheme. The schemes tend to surface only when circumstance forces the books open – when the trusted employee finally takes a vacation or falls ill and someone else picks up the work, or when a business is being sold and a buyer's review of the accounts turns up something that does not add up. Those schemes, she noted, can run for many years, and the longer they run, the more is taken. Underneath it all, seniority tracks with loss. "Higher positions steal more," she said, because they have easier access and more room to conceal it.
The coverage is built to respond when a company's controls are overcome, Rowe said, not to stand in for them. "It's not meant to replace controls. It's sort of meant to be a backup," she said. Where a company's controls are strong, she said, it works as intended. There are boundaries to what it will do, though, and she flagged one brokers ask about: social engineering cover responds to a voluntary parting with money or securities – where a bad actor convinces someone to transfer funds – but not to goods shipped to a fraudster. Rowe framed that as a design boundary rather than a flaw, since a company would pass through more checkpoints before shipping product than before moving money.
The larger problem, in her telling, is that many companies assume the risk cannot touch them. Property policies often carry a small crime sublimit (she cited $50,000) which can create a false sense of security. The mindset she hears is familiar: my employees would never steal from me, we are a small company, we are all family. "You might have that sort of false sense of security," Rowe said, treating a modest just-in-case limit as adequate when it is not. A dedicated commercial crime policy, with larger limits and more insuring agreements, or crime enhancements added to a cyber policy, provides the layer those sublimits do not.
Where the real protection lies, she said, is in the controls the coverage is meant to back up. Segregation of duties is central: more eyes on transactions make it harder for an employee to, for instance, create a fake vendor and funnel money out. Callback provisions verify payment-change requests before money moves, defending against the social-engineering fraud coming from outside. And the single most effective measure, she said, is a way for problems to be reported. "One of the best controls you can have is actually a whistleblower hotline," Rowe said, because the goal is not only to prevent fraud but to detect it quickly – the sooner a long-running scheme is caught, the less it takes.
For smaller companies without a dedicated risk manager, Rowe said, the broker often fills that role, and the insurance application itself can do some of the work. Crime and cyber applications are long, but they ask about the controls a well-run company would already have, which prompts first-time applicants to recognise the gaps. The conditions under which people steal, she said, are opportunity and ease.
"The harder you make it," Rowe said, "the less likely they are to steal."