Commercial Crime Insurance: Protecting Assets from Fraud and Financial Theft

Updated 09 July 2026
By Ryan Nevin
Feefo logo

Commercial Crime Insurance protects businesses against direct financial loss caused by dishonest or fraudulent acts, whether committed by employees, criminals, or third parties manipulating payment systems.

Standalone Financial Protection for Dishonest, Fraudulent, or Criminal Acts

Commercial Crime Insurance protects businesses against direct financial loss caused by dishonest, fraudulent, or criminal acts.

Cover can vary significantly between insurers, but a well structured policy will usually address both internal and external fraud exposures, including employee dishonesty, third-party deception, client money theft, and social engineering fraud. 

Commercial Crime policies are built around specific insuring clauses. Each clause responds to a different fraud mechanism, and the breadth of wording can materially affect whether a claim is covered.

Employee Fraud Insurance

Chevron down icon

Employee fraud insurance (also known as fidelity guarantee) provides protection for financial loss, caused by an employee's criminal or fraudulent behaviour.

Employee fraud, often referred to as fidelity insurance, protects against dishonest acts committed by employees, directors or officers. This may include embezzlement, payroll manipulation, false expense claims, inventory theft, fraudulent supplier payments, or the creation of phantom vendor accounts. Because employees often have legitimate access to payment systems, accounting records, stock controls, or client funds, insider fraud can remain hidden for long periods of time, sometimes years.

Fidelity cover helps protect the business against direct financial loss caused by internal dishonesty, subject to policy terms, exclusions, and discovery conditions.

Third-Party Fraud Insurance

Chevron down icon

Third-party fraud insurance protects against losses caused by external criminals who deceive, impersonate, forge, or manipulate payment processes to steal business assets. This may include forged payment instructions, supplier impersonation, funds transfer fraud, invoice redirection, fake procurement requests, or fraudulent changes to banking details. 

Unlike employee dishonesty, the threat comes from outside the business, often through carefully engineered deception designed to bypass normal finance controls. A robust Commercial Crime policy should clearly define how third-party fraud is covered and whether social engineering, authorised push payment fraud, or fraudulent instruction losses are covered.

Client Fraud Insurance

Chevron down icon

Client fraud insurance is specifically important for businesses that handle client money, client assets, escrow accounts, investment funds, deposits, or payment flows on behalf of others. 

Claims may arise where client funds are stolen, misdirected, fraudulently transferred, or dishonestly handled by employees or external criminals. This exposure is particularly relevant for professional services firms, financial services businesses, law firms, property managers, recruitment agencies, payment providers, and any organisation entrusted with third-party assets. 

Cover should be reviewed carefully to ensure the policy responds to loss of client money as well as the company’s own funds.

Social Engineering Fraud Insurance

Chevron down icon

Social engineering fraud insurance protects against losses where employees are manipulated into voluntarily transferring funds or changing payment details based on fraudulent instructions. 

Common examples include CEO impersonation, fake supplier bank detail changes, invoice redirection, mandate fraud, deepfake voice instructions, and urgent confidential payment requests. 

This cover is increasingly important because many frauds do not involve a hacker directly stealing money; instead, criminals persuade an authorised employee to make the payment themselves. Policy wording should be checked carefully, as social engineering fraud is often subject to specific verification conditions, dual-authorisation requirements, and lower sub-limits than the main crime policy.

Commercial Crime vs. Cyber Insurance

One of the most common mistakes is assuming that Cyber Insurance automatically covers all digital fraud. 

Cyber Insurance is primarily designed to respond to incidents involving networks, systems, data, privacy, and digital systems. For example, if hackers encrypt your systems, steal customer data, or compromise your network, Cyber Insurance can fund the response, ransom demand, and recovery.

Commercial Crime Insurance is designed to cover direct financial loss caused by fraudulent or dishonest acts. For example, if a finance employee is tricked into sending £500,000 to a fake supplier account, the relevant cover is likely to sit under Commercial Crime.

The distinction can matter because many modern frauds begin with a cyber deception but end as a direct theft of funds.

AI Impersonation Fraud

Artificial intelligence has materially increased the sophistication of impersonation fraud. Criminals can now use:

  • cloned voices
  • deepfake video calls
  • spoofed executive messages
  • AI-generated supplier emails
  • automated phishing campaigns

This creates a new generation of payment fraud where finance teams are pressured into acting quickly on apparently authentic instructions from senior leaders, clients, or suppliers.

For example, a finance controller may receive an urgent phone or video call appearing to come from the CEO, instructing them to process a confidential acquisition transfer. If the instruction is fake and the money is sent, the business may suffer an immediate financial loss.

Commercial Crime Insurance is increasingly important for protecting against AI-enabled social engineering, provided the policy wording expressly addresses fraudulent instruction, impersonation, and funds transfer scenarios. 

Necessary Verification Controls

Chevron down icon

Businesses should implement verification protocols for payments, supplier changes, and executive instructions. In the AI era, a phone or video call is no longer sufficient proof of authority. 

To secure cover for Social Engineering Fraud, insurers will expect you to implement controls such as dual-authorisation, call-back verification, and segregation of duties. 

Specialist Crime Insurance Broker

Standalone Commercial Crime Insurance is a specialist financial protection product. The wording must be carefully reviewed because small differences in definitions, sub-limits, authorisation requirements, and social engineering extensions can determine whether a major fraud loss is covered.

Often, it is a trusted employee, a convincing email, a cloned voice, or a fraudulent payment instruction that moves money out of the business before anyone realises a crime has occurred.

Sub-limits of Fidelity Employee Theft can be included under a Management Liability package product. Alternatively, lower sub-limits for Social Engineering Fraud cover can be provided under a Cyber Insurance product.

Fraud often exposes systemic weaknesses inside a business. Ensure your leadership team is jointly protected from the subsequent regulatory or shareholder fallout by reviewing our manual on Directors and Officers Insurance.

Meet the Brokers

Simon Taylor (ACII)
Chartered Insurance Broker
A Chartered Insurance Broker with over 25 years experience working within the Management Liability space. Having held senior positions at Willis, QBE and Chubb, he is well placed to advise his clients on obtaining comprehensive and cost-effective commercial crime insurance.
Ryan Nevin
Account Broker
Combining client-focused experience with a keen analytical mindset and attention to detail combined with problem solving skills. He has since continued to build experience, developing a strong understanding of the risks faced by businesses across a range of sectors.