Fraud that targets a business rarely looks like a break-in anymore. It looks like an invoice email from a "supplier" with a new bank account, or a call from someone who sounds exactly like the company's CFO asking for an urgent wire. Understanding what crime insurance and social engineering fraud coverage actually address, and where the two overlap, matters before a business assumes either one is automatically part of its policy.
This article covers what a commercial crime policy typically includes, why social engineering fraud is often treated as a separate add-on rather than a built-in feature, and where the coverage gap tends to show up for Canadian businesses.
What Is Crime Insurance?
Crime insurance is a commercial policy, or an endorsement added to a business owner's package, designed to address financial losses caused by dishonest acts such as employee theft, forgery, and counterfeit money. It is typically written as a set of separate insuring agreements inside one policy, so a business can carry some crime coverages and not others depending on what applies to its operation.
A base crime form commonly bundles several distinct agreements, including:
- Employee theft: money, securities, or property an employee unlawfully takes from the business.
- Forgery or alteration: losses from a forged signature on a cheque or similar financial instrument.
- Money and securities: loss of cash or securities on the premises or in transit.
- Computer fraud: a loss resulting from an unauthorized intrusion into the business's computer system.
- Counterfeit currency: a loss caused by accepting fake money or a fraudulent money order.
Each insuring agreement carries its own limit, so a business with high cash handling and a business with mostly digital payments often end up with very different crime coverage priorities.
Why Social Engineering Fraud Needs Its Own Coverage
Social engineering fraud is where a criminal impersonates a vendor, client, executive, or employee to convince someone inside the business to voluntarily send money or change payment details. Trade coverage of the Canadian market has described this pattern as impersonation fraud rising to become one of the more common sources of crime claims, alongside employee theft.
The reason it sits outside standard crime and cyber wordings comes down to one word: voluntary. A computer fraud agreement is generally meant to respond to an unauthorized break-in to a computer system, and most base crime forms specifically exclude a loss that happens because the insured's own employee willingly transferred the funds, even under a false pretense. Because a wire sent after a convincing fake email was authorized by a real employee, it typically falls outside both agreements unless the policy names it specifically.
Insurers in Canada began introducing dedicated social engineering fraud coverage in the mid-2010s to close that gap, usually structured one of two ways:
- As an endorsement added to a commercial crime policy, extending the crime form to cover fraudulent-instruction losses.
- As a sub-limit inside a cyber liability policy, often set lower than the policy's main limit.
Neither structure is automatic. A business carrying crime insurance or cyber insurance without confirming this endorsement or sub-limit exists may still have no coverage for a social engineering loss.
How These Losses Typically Happen
The mechanics behind most social engineering fraud claims follow a similar pattern: a fraudster gathers enough detail about a business, often from a hacked email account or public information, to send a request that looks routine. Common versions include a fake invoice from a regular supplier with updated banking details, a spoofed email that appears to come from a company executive requesting an urgent payment, or a call impersonating IT support asking for remote access or login credentials.
According to the Canadian Anti-Fraud Centre (2025), spear phishing and business email compromise schemes were reported to have caused close to $68 million in losses across Canada that year, and the centre estimates that only 5 to 10 percent of fraud victims ever file a report. That likely means the real national figure is considerably higher than what gets recorded.
Common Exclusions and Coverage Gaps
Even with social engineering fraud coverage in place, most policies carry conditions worth knowing about. A callback or verification requirement is common, where the insurer expects the business to have confirmed a payment change through a second channel before the transfer went out. Many endorsements also apply a sub-limit well below the base crime or cyber limit, so a large fraudulent transfer might only be partly addressed. Coverage generally excludes losses the business could have avoided through basic internal controls, and it typically does not extend to a loss the business simply cannot substantiate with records.
Coverage details vary meaningfully by insurer and by the specific wording purchased, so only a policy's actual terms and a licensed broker can confirm what applies to a given business.
Benefits of Crime Insurance and Social Engineering Fraud Coverage
Carrying this coverage means a business has a place to turn when a trusted employee is deceived rather than negligent, which is a scenario general liability and standard property coverage were never built to address. It also gives a business a documented incentive to put basic controls in place, since insurers often ask about payment-verification practices during underwriting. For a business that processes vendor payments, payroll, or client funds regularly, having this coverage in the commercial package is information worth having on hand before, rather than after, a fraudulent request lands in an inbox.
Where You'll Come Across Crime Insurance and Social Engineering Fraud Coverage
These coverages typically come up when a business first assembles its commercial insurance package, during a renewal conversation where a broker reviews what limits and endorsements are in place, or after a vendor, landlord, or contract requires proof of crime coverage as a condition of doing business. They also tend to surface after a business reads about a fraud case in the news and asks whether its own crime or cyber coverage would extend to something similar. Businesses that changed how they handle vendor payments, added remote staff, or grew their accounts payable team since their last renewal are often good candidates to revisit what their crime and cyber coverage actually includes.
Talk to a Licensed Broker About Crime Coverage
Crime insurance and social engineering fraud coverage sit at the intersection of a business's business insurance package and its cyber exposure, and the two rarely line up automatically. A broker who works across technology companies' cyber and crime coverage or a standard commercial package can walk through what a specific business's crime and cyber policies currently include and where a fraudulent-transfer gap might still exist, alongside options like the coverage many online businesses and Amazon sellers carry for similar exposures. Get a commercial insurance quote to start that review.
Coverage details vary by insurer and by policy, and only the wording of an actual policy and a licensed broker can confirm what applies to a specific situation.