Home  /  Insights  /  Crime & Fidelity Insurance
Claims & Coverage

Crime & Fidelity Insurance: Employee Theft, Social Engineering, and the Sublimits That Decide Your Claim

Crime and fidelity insurance protects the one thing most liability policies do not: your own money. It covers losses from employee theft and from outside criminals, forgers, fraudsters, and the social engineers who trick a member of your team into wiring funds away. The catch in 2026 is that the fastest-growing loss, social engineering fraud, is usually the most narrowly covered part of the policy, and the number that decides your claim is a sublimit buried in an endorsement.

Short answer: Crime and fidelity insurance reimburses a business for money, securities, and property lost to dishonest acts. The fidelity side covers theft by your own employees; the crime side covers third-party acts like forgery, computer fraud, funds transfer fraud, and social engineering. The most important detail is the social engineering sublimit, often just $25,000 to $100,000 even on a $1M policy, which is where most modern claims are won or lost.

Below: what crime and fidelity insurance is, what it covers, why social engineering fraud is the coverage gap, the sublimits and controls to check, what it costs, and who needs it.

What is crime and fidelity insurance?

Crime and fidelity insurance is commercial coverage that reimburses your business for the direct loss of money, securities, and other property to dishonest acts. It is a first-party coverage, meaning it pays you for your own loss, which is what separates it from liability lines like directors and officers or cyber and technology E&O that defend you against claims others bring. The fidelity element, historically sold as a fidelity bond, protects against theft or fraud committed by your own employees. The crime element extends that protection to acts committed by people outside the company. Most businesses buy the two together as a single commercial crime policy.

What does crime and fidelity insurance cover?

A commercial crime policy is built from separate insuring agreements. You can think of them as covering two directions of risk: the threat from inside, and the threat from outside.

Insuring agreementWhat it protects
Employee theft (fidelity)Loss of money, securities, or property caused by dishonest acts of your own employees.
Forgery or alterationLoss from forged or altered checks, drafts, and similar written instruments.
On-premises & in-transitRobbery, burglary, or theft of money and securities at your location or while being transported.
Computer fraudLoss from a third party fraudulently using a computer to transfer your money or property.
Funds transfer fraudLoss when a criminal fraudulently instructs your bank to transfer funds without your knowledge.
Social engineeringLoss when an employee is deceived into voluntarily sending funds to a criminal. Usually added by endorsement and sublimited.
Client / third-party coverageTheft of a client's money or property by your employees, often required by professional-services contracts.

For third-party cyber events and service failures, crime coverage sits alongside cyber / technology E&O; for the underlying coverage overview, see crime and fidelity bonds.

Why social engineering fraud is the coverage gap

The threat has shifted from the safe and the ledger to the inbox, and the policies have not fully caught up. Social engineering fraud, where an attacker impersonates a vendor, executive, or client and convinces an employee to wire money, is now the dominant crime loss. The FBI reports that business email compromise losses have run into the billions of dollars a year, and the mechanism is almost always a deceived but authorized employee, not a hacked system.

That distinction is exactly where claims are denied. Many crime forms were written for an earlier era and may not extend to social engineering losses, leaving policyholders both defrauded and uninsured. Because the employee authorized the transfer, insurers argue it was not the kind of unauthorized computer or funds transfer fraud the base policy covers. The fix is an affirmative social engineering endorsement, but it typically carries a sublimit far below the policy limit.

The sublimit is the number that matters

On most mid-market crime policies, the overall limit might be $1 million or more, while the social engineering endorsement is sublimited to a fraction of that, commonly $25,000 to $100,000. If your business routinely wires sums larger than the sublimit, a single successful fraud can exceed your coverage by an order of magnitude. Two things determine whether that sublimit is adequate and whether the claim pays:

The pattern is the same one we see across every line we place: the exclusion or sublimit is discovered at claim time, when the wording is already fixed. A broker who reads the crime form for the social engineering sublimit and control warranties before binding is the difference between a paid claim and a denied one.

How much does crime and fidelity insurance cost?

There is no flat rate. Pricing is built from the limit and sublimits selected, employee count, the volume and method of your funds transfers, your internal controls, industry, revenue, and loss history. Documented verification controls, dual authorization on wires, callback verification on any change to payment instructions, and separation of duties in finance, meaningfully improve both price and terms. As with every line, the decisive question is not the premium but the coverage design: a low-priced policy with a $25,000 social engineering sublimit is the expensive one if your typical wire is $250,000.

Who needs crime and fidelity insurance?

Almost every business that handles money, moves funds, or holds client assets. It is especially important for companies that process vendor payments and payroll, finance teams and startups that wire large sums, professional-services firms holding client funds, and digital asset and crypto businesses, which face elevated theft and fraud exposure. Investors and enterprise customers sometimes require it, and it is a standard component of a complete management liability program alongside D&O and employment practices liability.


The bottom line

Crime and fidelity insurance guards your balance sheet against dishonesty from inside and outside the company. In 2026 the exposure that grows fastest, social engineering fraud, is the one standard policies handle worst, and the single most important number on the placement is the social engineering sublimit. Size it to your real wire exposure, put the verification controls in place that carriers now expect, and have the crime form read for sublimits and warranties before you bind. That is what turns a policy you own into a claim that pays.

Check your crime policy's social engineering sublimit

Alton Risk places crime and fidelity coverage for startups, finance teams, professional-services firms, and digital asset companies. Every prospective client gets a coverage review: our brokers read your crime form for the social engineering sublimit and control warranties, benchmark the limit against your real wire exposure, and negotiate the gaps closed before you bind.

Get covered →

Related reading: Crime / Fidelity Bonds · Cyber / Technology E&O · Directors & Officers · Glossary: Social Engineering Fraud

Frequently asked questions

What is crime and fidelity insurance?

+

Crime and fidelity insurance is commercial coverage that reimburses a business for money, securities, and property lost to dishonest acts. The fidelity part covers theft or fraud by your own employees (historically written as a fidelity bond); the crime part covers third-party acts such as forgery, robbery, computer fraud, funds transfer fraud, and social engineering. It protects the balance sheet against loss of assets, which is different from liability insurance that covers claims brought against you by others.

Does crime insurance cover social engineering fraud and business email compromise?

+

Often only partially, and only if the policy is written for it. Social engineering fraud, where an employee is deceived into wiring funds to a criminal (the mechanism behind most business email compromise), is frequently added by endorsement and carries a much lower sublimit than the rest of the policy, commonly $25,000 to $100,000 even when the overall crime limit is $1 million or more. Many standard crime forms were written before this risk was common, and claims are denied when the loss involves a voluntary transfer authorized by a deceived employee. Confirming that social engineering is affirmatively covered, and negotiating the sublimit up, is the single most important step in placing a modern crime policy.

What is the difference between a fidelity bond and crime insurance?

+

A fidelity bond is the older term for coverage against employee dishonesty. Modern commercial crime insurance includes fidelity (employee theft) as one insuring agreement and adds several third-party crime coverages, forgery or alteration, on-premises and in-transit theft, computer fraud, funds transfer fraud, and, by endorsement, social engineering. In practice the two terms are used together, and most businesses buy a single crime and fidelity policy rather than a standalone bond.

How much does crime and fidelity insurance cost?

+

There is no flat rate. Pricing is driven by the limit and sublimits selected, the number of employees, the volume and method of funds transfers, internal controls such as dual authorization and callback verification, industry, revenue, and loss history. Because weak verification controls cause the majority of social engineering losses, insurers reward documented controls with better terms. The most important cost decision is not the premium but whether the social engineering sublimit is large enough to cover a realistic wire loss.

Who needs crime and fidelity insurance?

+

Any business that handles money, moves funds, or holds client assets, which is almost every company. It is especially important for firms that process vendor payments or payroll, startups and finance teams that wire large sums, professional services firms holding client funds, and digital asset companies, which face elevated theft and fraud exposure. Investors and enterprise customers sometimes require it, and it is a standard part of a complete management liability program.

Can't find an answer to your questions? Reach out to our team →

Sources: Gallagher, "The Coming of Age of Crime Insurance: Social Engineering"; National Law Review, "Social Engineering Fraud and Your Crime Policy"; Ward and Smith, "Social Engineering Fraud and Your Crime Policy"; WTW, "Insurance Marketplace Realities, Fidelity/Crime". This article is general information, not legal, financial, or insurance advice.