window.dataLayer = window.dataLayer || [];function gtag(){dataLayer.push(arguments);}gtag('js', new Date());gtag('config', 'G-FQXKQJYQM1');
Schneiderman Insurance Agency
Schneiderman Insurance Agency

Commercial Crime Insurance

Commercial Crime Insurance2026-09-16T21:54:52-07:00

What is commercial crime insurance?

Commercial crime insurance is first-party coverage that responds to a business’s own loss of money, securities, and property. It may cover employee theft, forgery, robbery and burglary, funds-transfer fraud, and social-engineering fraud, where an employee is deceived into sending money, exposures that general liability and property policies do not address.

Theft does not always come from a stranger. A lot of the loss businesses experience traces back to their own operations, from a dishonest employee to a spoofed email that redirects a payment. We help California businesses figure out which crime exposures matter most for how they handle funds.

Commercial Crime Insurance

What does crime insurance cover?

What does Commercial Crime Insurance cover?

  • Employee dishonesty and theft.
  • Forgery or alteration of checks and financial instruments.
  • Theft of money and securities, inside and outside the premises.
  • Robbery and burglary of business property.
  • Funds-transfer fraud, where a transfer is made without your knowledge.
  • Social engineering fraud, where an employee is deceived into authorizing a payment. This is a separate insuring agreement on most forms, usually sublimited, because computer fraud and funds transfer fraud do not reach an authorized payment.

Why does it matter in California?

California businesses move a large volume of electronic payments, and social-engineering scams targeting accounts payable have become common statewide. Coverage for these deception-based losses often sits in a specific insuring agreement with its own limit.

Which businesses need it?

Businesses that handle cash, checks, or wire transfers; companies with employees who can access accounts or approve payments; and nonprofits, professional offices, and retail operations.

How do we build the crime coverage?

We look at how money moves through your business, who touches it, and where a single point of failure could create a loss. Then we help you size limits and confirm the policy addresses newer exposures like social-engineering fraud, which is not always included by default.

Fidelity bonds, extortion and social engineering, explained

What is the difference between a fidelity bond and a commercial crime policy?

A commercial crime policy is a two-party contract that pays your business for its own loss, while a bond is a three-party promise in which a surety answers for someone else’s conduct. California keeps the two apart. A surety who pays a claim is entitled to reimbursement from the principal, the person whose conduct was guaranteed, under Civil Code section 2847. California also classifies fidelity products as surety insurance in Insurance Code section 105, which reaches the guaranteeing of behavior and loss from forgery or alteration. In practice a modern employee dishonesty bond is written by a casualty insurer and bought to protect the employer, so the labels blur. What matters is which instrument your contract or your plan actually calls for.

Who has to carry an ERISA fidelity bond, and for how much?

Every fiduciary of an employee benefit plan, and every person who handles plan funds or other property, must be bonded under 29 U.S.C. section 1112. The bond must be at least ten percent of the funds handled. It can never be less than $1,000, and never more than $500,000 per plan official per plan. That ceiling rises to $1,000,000 where the plan holds employer securities. The amount is fixed at the start of the plan’s reporting year, using the most funds that person handled in the prior year. Department of Labor guidance in Field Assistance Bulletin 2008-04 adds two conditions that are easy to miss. The required portion carries no deductible, and the plan itself must be named on the bond.

Is an ERISA fidelity bond the same as fiduciary liability insurance?

No. The bond covers loss to the plan from fraud or dishonesty by the people who handle its money. Fiduciary liability insurance responds to breaches of fiduciary duty, such as imprudent investment decisions or administrative errors. The same Department of Labor guidance states plainly that it is neither required by nor subject to section 412 of ERISA. One consequence follows and is worth stating: the protected party under the bond is the plan, not the employer that sponsors it. A business that buys the bond and assumes it is covered for its own losses has bought the wrong instrument.

What is a business service bond, and which California companies buy one?

A business service bond responds when your own employee steals a customer’s property while working at the customer’s location. It answers a dishonest act, not a careless one. Damage caused by employee negligence is a general liability question instead, and confusing the two is the most common error we see on this coverage. Cleaning companies, home-service trades and in-home care providers are asked for these most often, usually because a client contract requires one. Volunteers and temporary staff are not automatically included. The policy’s definition of employee has to be extended first, which is an endorsement rather than an assumption.

Why might a crime policy not pay when an employee is tricked into wiring money?

Because the standard computer fraud and funds transfer fraud agreements have been read to require an unauthorized transfer, and an employee who approves a wire has authorized it. Applying California law in 2016, the Ninth Circuit held that reading those words more broadly would turn a crime policy into a general fraud policy. In an unpublished 2017 decision the same court found no coverage where a business management firm wired roughly $200,000 on spoofed client emails. Cover for deception-induced payments usually requires a separate social engineering or fraudulent instruction agreement. It is often written at a sublimit below the policy limit, and it commonly conditions payment on callback verification of any request to change payment details.

What does extortion coverage on a commercial crime policy cover?

Extortion is not part of the crime policy by default. It is added by optional endorsement, or bought through a separate kidnap, ransom and extortion form, and the two are not written to the same scope. The crime program’s version was built around threats of bodily harm to people connected with the business, and threatened damage to premises or property. California defines extortion in Penal Code section 518 as obtaining property from another through the wrongful use of force or fear. The policy conditions normally require notice to the insurer, consent before any payment, and a report to law enforcement. Those conditions come first, and the coverage follows them.

Is a ransomware demand covered by crime insurance or by cyber insurance?

A ransomware demand normally sits under a cyber policy’s cyber extortion agreement, not under the crime policy’s extortion endorsement, which was written around physical threats. California treats the conduct as extortion in Penal Code section 523, which makes introducing ransomware punishable as though the demand had been paid. That settles the criminal question, not the coverage question. Two further duties attach whichever policy responds. A payment that reaches a sanctioned party can draw civil penalties on a strict liability basis, set out in Treasury’s updated ransomware advisory. A breach of personal information also triggers the notification duty in Civil Code section 1798.82, which since January 2026 runs on a 30-day clock.

What has to happen before a crime or extortion claim can be paid in California?

The loss has to be discovered and reported inside the policy’s discovery conditions, and then documented. Crime forms come in two structures, and which one you hold changes the answer. A discovery form responds to loss found during the policy period even where the theft began earlier. A loss sustained form looks instead to when the loss occurred. Embezzlement is defined in Penal Code section 503 as the fraudulent appropriation of property by a person it was entrusted to, which is why a long-running theft is usually treated as one course of conduct. Once proof of claim is received, title 10 CCR section 2695.7 gives the insurer 40 days to accept or deny it.

Ready to look at it? Start a business insurance quote and tell us how money moves through the business. We will want to know who can approve a payment, who can change a vendor’s bank details, and whether a second person verifies that change by phone. Add your headcount, whether you sponsor a retirement plan, and the largest amount of plan funds any one person handled last year. Tell us whether a client contract asks you for a business service bond, whether you hold personal information about California residents, and whether you carry a cyber policy today. Some accounts we can write directly and quickly. Others go to underwriting for approval, or need a wholesale market, and those take longer. Either way you know before you decide.

Statutory references current as of September 2026 and specific to California, including the January 2026 amendment to Civil Code section 1798.82. Bonding figures are those set by 29 U.S.C. section 1112. Coverage descriptions are general; the policy form controls.

Common questions about Commercial Crime Insurance

Answering the most frequently asked questions about Commercial Crime Insurance.

Do small businesses need this?2026-08-10T13:44:28-07:00

Often yes, because smaller teams may have fewer checks on who handles money.

Is social-engineering fraud automatically covered?2026-08-10T13:44:28-07:00

Not always. It often requires a specific insuring agreement, which we can help you review.

Does it cover cyber losses?2026-08-10T13:44:29-07:00

There is overlap, but crime and cyber address different things. Many businesses carry both. We can explain how they may work together.

How is crime insurance different from a bond?2026-08-10T13:44:30-07:00

Crime is first-party insurance that pays your business for its own loss. A surety bond is a three-party guarantee that protects someone else. A fidelity bond specifically covers employee theft.

What should I do when a crime loss is discovered?2026-08-22T09:19:22-07:00

Report it immediately, because crime policies run on discovery rather than on when the loss happened. Tell us as soon as you suspect it, before the internal investigation is finished. File a police report, preserve the records, bank statements, and email trail, and involve your bank within its own deadlines, which are often measured in days for a fraudulent transfer. Do not confront an employee before you have secured the records. A long-running theft can be covered even when it began under an earlier policy, provided the discovery conditions are met.

Am I covered if someone tricks my staff into sending money?2026-09-07T11:02:25-07:00

Often not under the agreements businesses assume cover it. Computer fraud generally requires an unauthorised entry into your system, and funds transfer fraud generally requires a transfer instruction your bank acted on without your knowledge. A convincing email that persuades your own employee to authorize a payment fits neither, because the transfer was authorized. That gap is filled by a social engineering or fraudulent instruction agreement, usually with a sublimit well below the policy limit and a callback verification condition attached. Ask which of the three you hold.

What are the insuring agreements inside a crime policy?2026-09-07T11:02:27-07:00

A crime policy is a menu, not a single coverage. The common agreements are employee theft, forgery or alteration of your instruments, and theft of money and securities inside the premises. Then the same outside the premises or in transit, computer fraud, funds transfer fraud, and money orders and counterfeit currency. Social engineering, meaning a payment you were deceived into authorizing, is usually its own agreement with a lower sublimit. Each carries its own limit and deductible, and an agreement you did not buy simply is not there.

Is any crime coverage required by law?2026-09-07T11:02:29-07:00

One is, and it catches employers by surprise. Federal law requires that every person who handles funds or other property of an employee benefit plan be bonded. Under ERISA section 412 the bond must be at least 10 percent of the funds handled, with a minimum of $1,000 and a maximum of $500,000, rising to $1,000,000 for a plan holding employer securities. That is a fidelity bond, not a surety bond and not a license bond. Beyond that, contracts and landlords drive most crime requirements. Current as of August 2026.

What does commercial crime insurance not cover?2026-08-22T09:19:08-07:00

Losses you cannot document, and losses that belong to another policy. Property damage and bodily injury are elsewhere, and a data breach is cyber. Inventory shortages proven only by a physical count are commonly excluded, since a discrepancy is not the same as a theft. Loss discovered long after an employee left may fall outside the discovery period. Above all, a crime policy pays only on the insuring agreements you actually bought, so the schedule is what decides the answer rather than the policy title.

Start Your Commercial Crime Insurance Quote

Schneiderman Insurance Agency makes the process of finding Commercial Crime Insurance convenient for you. Tell us about your situation, we review your risks and options with you, we help you put the right coverage in place, and we stay with you at renewal.

Crime coverage and cyber liability divide social engineering and funds transfer fraud between them, and which form responds depends on how the loss occurred. The wider program is on our business insurance page.