What is the difference between computer fraud, funds transfer fraud, and social engineering coverage?
The three coverages are separated by who moved the money and how, and only one responds when your own employee sends the wire willingly. Computer fraud covers loss caused by someone hacking into your systems and using that access to transfer money or property, so there is a real intrusion behind it and no one at your company authorized anything.
Funds transfer fraud covers loss when a criminal sends a fraudulent instruction directly to your bank, impersonating you, and the bank moves money without your knowledge. Social engineering, sometimes called fraudulent instruction or deception fraud, is the one that covers the wire your employee sent on purpose after being tricked. It is the most common loss by a wide margin and the most narrowly covered.
- Computer fraud requires an unauthorized intrusion into your systems, not just a convincing email
- Funds transfer fraud involves your bank acting on a forged instruction you never gave
- Social engineering covers a transfer your own authorized employee made after being deceived
Why is social engineering coverage almost always a sublimit instead of a full policy limit?
Carriers sublimit social engineering because the loss depends on human judgment rather than on technology they can verify, and because these claims are frequent, fast and hard to prevent with controls alone. A carrier can audit whether you use multifactor authentication. It cannot audit whether a stressed accounts payable clerk will pause on a Friday afternoon.
The practical result is that a policy with a $5,000,000 aggregate limit may carry only $100,000 for social engineering. Typical sublimits run $25,000 to $250,000 for small and midsize businesses, with $500,000 to $1,000,000 available to companies that document strong payment controls. Retentions apply separately, commonly $5,000 to $50,000, and some carriers add coinsurance requiring you to bear a percentage of the loss above the retention.
- Social engineering sublimits commonly run $25,000 to $250,000 even on multimillion dollar cyber policies
- Size the sublimit against your largest routine wire or vendor payment, not your average one
- Watch for coinsurance language that leaves you funding a percentage of the loss above the retention
What is the voluntary parting problem, and why does it decide claims?
Voluntary parting is the principle that traditional crime and computer fraud coverage does not pay when you willingly handed over the money, even if you were deceived into doing so. It is the reason social engineering had to be created as a separate coverage grant in the first place.
Under a standard computer fraud agreement, the loss must result directly from the fraudulent use of a computer to cause a transfer. When a person reads an email, decides to act and approves the payment, the chain of causation runs through a human decision, and carriers take the position that this breaks the direct link the coverage requires.
Do not assume a computer fraud clause covers a deception loss. If the words "social engineering," "fraudulent instruction" or "deception fraud" appear nowhere in your policy, you very likely have no coverage for the most common way money leaves a business today.
What is a callback verification warranty, and can failing it void your coverage?
A callback verification warranty is a condition in the policy requiring you to confirm any payment instruction or bank detail change by voice, using a phone number you already had on file, and failing to do it can void the claim entirely. This is the most common reason an otherwise valid social engineering claim is denied.
The wording matters. Some carriers write verification as a condition precedent to coverage, meaning no verification means no payment. Others write it as a warranty that applies only above a dollar threshold, such as payments over $25,000. A few treat it as a premium credit rather than a requirement.
Read the condition, then build your process to match it word for word. If the policy says you must call a previously established number, calling the number printed on the new invoice does not satisfy it, and that is exactly the number the criminal supplied.
- Verify by phone using a number from your existing vendor file, never one on the new invoice or email
- Confirm whether your verification requirement applies to all payments or only above a stated threshold
- Document each callback with the date, the person reached and the number dialed
- Require dual authorization on wires above a set amount, commonly $10,000 to $50,000
How do invoice manipulation and vendor impersonation losses actually happen?
Most of these losses begin inside a vendor's email system rather than yours, so your own security controls do not prevent them. A criminal gains access to a supplier's mailbox, reads the billing thread for weeks, learns the amounts and the tone, then sends a real invoice with altered banking details just as a payment is due.
Invoice manipulation coverage addresses the mirror image of that loss. If attackers compromise your systems and send fraudulent invoices to your own customers, your customers pay the criminal, and you are left trying to collect twice from a client who believes they already paid. That receivable loss is not covered by standard social engineering wording and needs its own grant.
- Vendor email compromise means the fraudulent message often comes from a genuine, unaltered address
- Invoice manipulation coverage protects lost receivables when your customers are defrauded through your systems
- Set a written policy that bank detail changes are confirmed with a known contact before any payment
Should a wire fraud claim go to your crime policy or your cyber policy?
Either can respond, and the danger is not that both refuse but that each points at the other while your claim sits unpaid. Commercial crime policies have covered employee theft and forgery for decades and now often add a social engineering endorsement. Cyber policies added the same coverage from the other direction, and many businesses end up with two partial answers.
Overlap creates two problems. Definitions rarely match, so a loss that fits your crime wording may fall outside your cyber wording. Other insurance clauses in both may each declare themselves excess to the other, which delays payment while the carriers argue.
The clean approach is to decide in advance which policy is the intended home for money-out losses, make that one the larger limit, and confirm the other sits genuinely excess.
- Compare the social engineering wording in both policies side by side, not just the limits
- Check the other insurance clause in each policy to see which claims to be excess
- Note that crime policies often exclude losses arising from a network breach, and cyber policies often exclude employee dishonesty
What do underwriters want before raising a social engineering sublimit?
Underwriters raise social engineering sublimits when you can show documented, enforced payment controls, because the exposure is procedural rather than technical. The application questions are predictable, and answering them well is often worth more than security spending.
Expect to describe your out-of-band verification process, your dual authorization threshold, how vendor bank changes are approved and by whom, whether multifactor authentication protects email, and how often staff receive phishing training. Carriers also look at segregation of duties, meaning the person who sets up a vendor is not the person who releases the payment.
Written procedures matter more than intentions. A one page wire transfer policy, signed by finance staff and attached to your submission, frequently moves a sublimit from $100,000 to $500,000 at little or no additional premium.
- Document out-of-band callback verification as a written, signed procedure
- Enforce dual authorization and segregation of duties on vendor setup and payment release
- Require multifactor authentication on all email accounts, including executives and remote staff
Frequently Asked Questions
This article is for general information and is not a substitute for policy language or professional advice.
