Ask owners about theft and they picture a smashed window. The claims files tell a different story: the costliest business theft is committed by someone with keys, over years, in amounts small enough to miss. The bookkeeper running a second payables file. The manager voiding sales after cash-out. The warehouse lead with a side channel for inventory. Association studies of occupational fraud have estimated organizations lose a meaningful percentage of revenue to it annually — and the median scheme runs for over a year before discovery.
This is the exposure commercial crime coverage exists for, and it's among the least-understood policies a business can carry. Here's what it does, what it doesn't, and the controls that matter more than either.
What crime coverage actually pays
The core insuring agreement is employee dishonesty: theft of money, securities, or property by your own people, discovered during (or within a discovery window after) the policy period. Around it sit the related agreements — theft of money on premises or in transit, forgery and cheque fraud, computer and funds-transfer fraud, and increasingly social-engineering fraud, where an employee is deceived into sending money to a criminal.
Two structural points matter. Crime policies are discovery-based: what triggers coverage is when you find the loss, which suits schemes that run silently for years. And client-property extensions cover theft by your employees from customers' premises — the reason cleaning, janitorial, and in-home service businesses are asked to be 'bonded': that bond is a crime coverage.
The fraud triangle runs through your accounting
Fraud examiners describe a triangle — pressure, opportunity, rationalization — and a business only controls one corner: opportunity. Opportunity lives in concentration. The same person who sets up vendors also pays them; the person who handles deposits also reconciles the bank; nobody else ever opens the statements. Small businesses are structurally exposed because small teams concentrate duties by default.
The countermeasures are procedural and nearly free: bank statements delivered to (and actually opened by) the owner; dual approval on payments above a threshold; vendor-file changes verified by phone; mandatory vacations, because schemes need daily tending; surprise counts on cash and high-value stock. None of this accuses anyone. It removes the opportunity corner for everyone — which honest employees, incidentally, tend to appreciate.
Where crime meets cyber
The modern fraud loss is a hybrid: an email account is compromised (cyber territory), a fake invoice with new banking details follows (social engineering), and an employee authorizes the transfer (crime territory). Whether your cyber policy or your crime policy responds depends on wordings that differ between insurers — and the worst place to learn the answer is mid-claim.
Our standing advice: carry both coverages, confirm explicitly which one owns fraudulent-transfer losses, and check the social-engineering sub-limit — it's often a fraction of the main limit and frequently needs to be selected rather than assumed. Then install the control that beats the whole category: any change to payment instructions gets verified by phone, on a number you already had.
Sizing and claims reality
Size the limit to plausible worst cases, not averages: what could the most-trusted person in your business move over three undetected years? For a business processing meaningful payables, six figures is not exotic. At claim time, expect the insurer to require a proof of loss and often a police report; expect the forensic reconstruction to lean entirely on your records. Clean books don't just deter fraud — they're what makes the claim payable.
What crime coverage costs, and how limits get sized
Crime coverage is among the cheaper additions to a commercial program relative to its severity protection: small businesses commonly add employee-dishonesty and money coverages for a few hundred dollars a year at $25,000–$100,000 limits, with six-figure limits well within reach for businesses whose exposure justifies them. Pricing follows the controls story — insurers ask about segregation of duties, bank reconciliation practices, and countersignature rules, and the applications are refreshingly blunt about it.
Sizing is where owners under-shoot. The instinct is to size to petty theft — a float, a deposit bag. The actuarially honest question is the one from earlier: what could your most trusted person move over three undetected years? A bookkeeper processing $2 million of annual payables with weak oversight is a six-figure exposure, full stop. Median occupational-fraud losses across studies sit in the low-to-mid six figures for schemes of meaningful duration, and small organizations consistently suffer disproportionately because controls are thinner. Size to the scheme, not the float.
Watch two structural details while buying: the discovery period (how long after policy expiry a discovered loss can still be claimed — longer is better in a coverage built for slow-burning schemes), and whether coverage is per-loss or per-employee aggregated. Your broker should walk both; they're checkbox differences between markets that decide real claims.
A scheme anatomy: eighteen months of small invoices
The classic file, composited: a construction firm's office manager — trusted, tenured, never takes vacation — creates a supplier in the accounting system: 'GTA Site Services Inc.', an entity she controls. Invoices begin: $1,800, $2,400, amounts precisely calibrated below the owner's $2,500 review threshold, one or two a month, coded across active jobs where materials costs hide easily. Eighteen months later a bank-side duplicate-payment query surfaces one invoice; the owner pulls the vendor file and finds forty-three more totalling just under $80,000.
The claim proceeds on the crime policy's employee-dishonesty agreement: police report filed (most policies require it), forensic accountant engaged, the loss reconstructed invoice by invoice from records that — fortunately — existed. Settlement lands near the documented total, minus deductible. The postscript writes itself: vendor-creation now requires second-person approval, the owner's review threshold caught its own weakness, and mandatory vacation entered the employee handbook — because the scheme's tending was daily, and two consecutive weeks away would have surfaced it a year earlier.
Every element of that story is ordinary: the trusted employee, the sub-threshold amounts, the discovery by accident rather than audit. Which is precisely the argument — the coverage pays the reconstruction, but the controls decide whether the number has one comma or two.
The controls checklist, sized for a business without a CFO
Enterprise fraud frameworks assume staff you don't have, so here's the ten-person version, cost near zero. Banking: statements delivered to the owner unopened (digital counts — owner-only portal access), reviewed monthly line-by-line for ten minutes; dual approval on payments above a threshold you set; no shared banking credentials, ever. Vendors: new-vendor creation requires a second person; any change to vendor banking details verified by phone on a previously known number — the single rule that defeats both internal schemes and external social engineering.
People: mandatory consecutive vacation for anyone touching money, cross-training so absence coverage exists (and schemes lose their tending), and reference checks that actually call the references. Physical: cash counted by two, deposits varied, high-value stock counted on surprise cadence. Each control is boring; together they remove the opportunity corner of the fraud triangle for everyone, which honest staff — the overwhelming majority — experience as protection, not suspicion. Frame it exactly that way when you roll it out.
Write the six rules on one page, date it, and revisit annually. That page is simultaneously your best fraud prevention, your best premium argument, and — should a scheme beat it anyway — exhibit one in a clean, payable claim.
When you suspect something: the first seventy-two hours
Discovery moments are volatile, and the instinctive moves are frequently the wrong ones. Don't confront immediately: alerted schemers destroy records, and destroyed records shrink both prosecutions and claims. Don't announce broadly. Do preserve: secure the accounting data, the emails, the vendor files — quietly, with access logged. Do call, in short order: your lawyer (employment law has opinions about what happens next), your insurer's claims line (crime policies have notice requirements, and early notice protects the claim), and, when the file is stable, police — remembering that most policies require the report.
Then let professionals reconstruct: forensic accountants exist for exactly this, their costs are often covered within the claim, and their product — a documented loss quantum — is what both the insurer and any prosecution will work from. The emotional pull is to treat it as a betrayal to be confronted; the effective frame is an incident to be processed, with the confrontation happening on counsel's schedule, evidence in hand.
And afterward, resist the quiet-settlement temptation — letting the person repay and resign without report. It forfeits the insurance claim (undisclosed, unreported losses aren't covered), it exports the problem to their next employer, and repayment promises from discovered fraudsters have a documented tendency toward fiction. The uncomfortable process exists because it's the one that ends with the money back.
The bottom line
Trust is a working necessity; unchecked trust is a system design flaw. Split the duties you can, verify payment changes always, and let crime coverage stand behind the controls for the scheme that gets through anyway.
If your current program has no crime section — common in older small-business packages — it's a quick addition to quote. Ask us to price it alongside your renewal, or start here.