What is commercial crime insurance?
Commercial crime insurance is first-party coverage that responds to a business’s own loss of money, securities, and property. It may cover employee theft, forgery, robbery and burglary, funds-transfer fraud, and social-engineering fraud, where an employee is deceived into sending money, exposures that general liability and property policies do not address.
Theft does not always come from a stranger. A lot of the loss businesses experience traces back to their own operations, from a dishonest employee to a spoofed email that redirects a payment. We help California businesses figure out which crime exposures matter most for how they handle funds.

What does crime insurance cover?
What does Commercial Crime Insurance cover?
- Employee dishonesty and theft.
- Forgery or alteration of checks and financial instruments.
- Theft of money and securities, inside and outside the premises.
- Robbery and burglary of business property.
- Funds-transfer fraud, where a transfer is made without your knowledge.
- Social engineering fraud, where an employee is deceived into authorizing a payment. This is a separate insuring agreement on most forms, usually sublimited, because computer fraud and funds transfer fraud do not reach an authorized payment.
Why does it matter in California?
California businesses move a large volume of electronic payments, and social-engineering scams targeting accounts payable have become common statewide. Coverage for these deception-based losses often sits in a specific insuring agreement with its own limit.
Which businesses need it?
Businesses that handle cash, checks, or wire transfers; companies with employees who can access accounts or approve payments; and nonprofits, professional offices, and retail operations.
How do we build the crime coverage?
We look at how money moves through your business, who touches it, and where a single point of failure could create a loss. Then we help you size limits and confirm the policy addresses newer exposures like social-engineering fraud, which is not always included by default.
Fidelity bonds, extortion and social engineering, explained
What is the difference between a fidelity bond and a commercial crime policy?
A commercial crime policy is a two-party contract that pays your business for its own loss, while a bond is a three-party promise in which a surety answers for someone else’s conduct. California keeps the two apart. A surety who pays a claim is entitled to reimbursement from the principal, the person whose conduct was guaranteed, under Civil Code section 2847. California also classifies fidelity products as surety insurance in Insurance Code section 105, which reaches the guaranteeing of behavior and loss from forgery or alteration. In practice a modern employee dishonesty bond is written by a casualty insurer and bought to protect the employer, so the labels blur. What matters is which instrument your contract or your plan actually calls for.
Who has to carry an ERISA fidelity bond, and for how much?
Every fiduciary of an employee benefit plan, and every person who handles plan funds or other property, must be bonded under 29 U.S.C. section 1112. The bond must be at least ten percent of the funds handled. It can never be less than $1,000, and never more than $500,000 per plan official per plan. That ceiling rises to $1,000,000 where the plan holds employer securities. The amount is fixed at the start of the plan’s reporting year, using the most funds that person handled in the prior year. Department of Labor guidance in Field Assistance Bulletin 2008-04 adds two conditions that are easy to miss. The required portion carries no deductible, and the plan itself must be named on the bond.
Is an ERISA fidelity bond the same as fiduciary liability insurance?
No. The bond covers loss to the plan from fraud or dishonesty by the people who handle its money. Fiduciary liability insurance responds to breaches of fiduciary duty, such as imprudent investment decisions or administrative errors. The same Department of Labor guidance states plainly that it is neither required by nor subject to section 412 of ERISA. One consequence follows and is worth stating: the protected party under the bond is the plan, not the employer that sponsors it. A business that buys the bond and assumes it is covered for its own losses has bought the wrong instrument.
What is a business service bond, and which California companies buy one?
A business service bond responds when your own employee steals a customer’s property while working at the customer’s location. It answers a dishonest act, not a careless one. Damage caused by employee negligence is a general liability question instead, and confusing the two is the most common error we see on this coverage. Cleaning companies, home-service trades and in-home care providers are asked for these most often, usually because a client contract requires one. Volunteers and temporary staff are not automatically included. The policy’s definition of employee has to be extended first, which is an endorsement rather than an assumption.
Why might a crime policy not pay when an employee is tricked into wiring money?
Because the standard computer fraud and funds transfer fraud agreements have been read to require an unauthorized transfer, and an employee who approves a wire has authorized it. Applying California law in 2016, the Ninth Circuit held that reading those words more broadly would turn a crime policy into a general fraud policy. In an unpublished 2017 decision the same court found no coverage where a business management firm wired roughly $200,000 on spoofed client emails. Cover for deception-induced payments usually requires a separate social engineering or fraudulent instruction agreement. It is often written at a sublimit below the policy limit, and it commonly conditions payment on callback verification of any request to change payment details.
What does extortion coverage on a commercial crime policy cover?
Extortion is not part of the crime policy by default. It is added by optional endorsement, or bought through a separate kidnap, ransom and extortion form, and the two are not written to the same scope. The crime program’s version was built around threats of bodily harm to people connected with the business, and threatened damage to premises or property. California defines extortion in Penal Code section 518 as obtaining property from another through the wrongful use of force or fear. The policy conditions normally require notice to the insurer, consent before any payment, and a report to law enforcement. Those conditions come first, and the coverage follows them.
Is a ransomware demand covered by crime insurance or by cyber insurance?
A ransomware demand normally sits under a cyber policy’s cyber extortion agreement, not under the crime policy’s extortion endorsement, which was written around physical threats. California treats the conduct as extortion in Penal Code section 523, which makes introducing ransomware punishable as though the demand had been paid. That settles the criminal question, not the coverage question. Two further duties attach whichever policy responds. A payment that reaches a sanctioned party can draw civil penalties on a strict liability basis, set out in Treasury’s updated ransomware advisory. A breach of personal information also triggers the notification duty in Civil Code section 1798.82, which since January 2026 runs on a 30-day clock.
What has to happen before a crime or extortion claim can be paid in California?
The loss has to be discovered and reported inside the policy’s discovery conditions, and then documented. Crime forms come in two structures, and which one you hold changes the answer. A discovery form responds to loss found during the policy period even where the theft began earlier. A loss sustained form looks instead to when the loss occurred. Embezzlement is defined in Penal Code section 503 as the fraudulent appropriation of property by a person it was entrusted to, which is why a long-running theft is usually treated as one course of conduct. Once proof of claim is received, title 10 CCR section 2695.7 gives the insurer 40 days to accept or deny it.
Ready to look at it? Start a business insurance quote and tell us how money moves through the business. We will want to know who can approve a payment, who can change a vendor’s bank details, and whether a second person verifies that change by phone. Add your headcount, whether you sponsor a retirement plan, and the largest amount of plan funds any one person handled last year. Tell us whether a client contract asks you for a business service bond, whether you hold personal information about California residents, and whether you carry a cyber policy today. Some accounts we can write directly and quickly. Others go to underwriting for approval, or need a wholesale market, and those take longer. Either way you know before you decide.
Statutory references current as of September 2026 and specific to California, including the January 2026 amendment to Civil Code section 1798.82. Bonding figures are those set by 29 U.S.C. section 1112. Coverage descriptions are general; the policy form controls.
Common questions about Commercial Crime Insurance
Answering the most frequently asked questions about Commercial Crime Insurance.
Start Your Commercial Crime Insurance Quote
Schneiderman Insurance Agency makes the process of finding Commercial Crime Insurance convenient for you. Tell us about your situation, we review your risks and options with you, we help you put the right coverage in place, and we stay with you at renewal.
Crime coverage and cyber liability divide social engineering and funds transfer fraud between them, and which form responds depends on how the loss occurred. The wider program is on our business insurance page.





