Step 14 / 18

Six years to commit it, one day to discover it

8 min of reading

This field has already presented two ways of dating a loss: the occurrence basis, which takes the date of the fault, and the claims-made basis, which takes the date of the letter. Fraud introduces a third, and it must be named clearly because it resembles neither: the discovery basis. The policy responds to losses DISCOVERED while it runs, whatever the date the acts were committed, subject to a retroactive date.

The reason for that choice belongs to the risk and is convincing. A well-run fraud is invisible by construction: the person diverting funds works precisely so that nothing shows, and the average time between the first diversion and its discovery is counted in years. A policy taking the date of commission would require each entry to be attached to the year it was made, mobilizing five successive contracts for one fraud, with five deductibles and five limits. The discovery basis avoids this by treating the fraud as a single event, located on the day it stops being invisible.

One must therefore know what discovery means in the contract, since it is not certainty. Wordings target the moment the insured becomes aware of facts that would lead a reasonable person to suspect a covered loss, even if the amount, the perpetrator and the details remain unknown. That threshold is low, deliberately, and it produces a consequence insureds grasp badly: a documented suspicion starts the clock. A finance director noting an anomaly in a reconciliation, without yet knowing what to make of it, may already have discovered.

The second consequence is symmetrical with the first and harsher. Since discovery fixes the date, the policy in force that day is the one that responds, and a single limit applies to a fraud that ran for six years. An insured that suffered 610,000 euros of diversion spread over four financial years does not have four annual limits: it has the one from the year it understood. The amount of cover must therefore be sized not on what a fraudster can take in a year, but on what one can take before being discovered, which is an entirely different calculation.

The retroactive date plays the role here that it plays on a claims-made basis, with a difference of vocabulary that misleads. It does not say how long one may claim, it says how far back the acts committed may be covered. A policy with unlimited retroactive cover picks up a fraud begun before the insured was even this insurer's client; a policy with none covers only acts after inception, which, on a risk whose concealment runs for years, empties much of the cover.

The case of a change of insurer must be added, since it produces here the same gap as in professional indemnity and by a neighboring route. The old policy no longer covers discoveries after its end; the new one does not cover acts before its retroactive date. A fraud committed under the old contract and discovered under the new therefore falls into the interval, unless the new one's retroactive date reaches far enough back. Most contracts in this market provide a continuity clause repairing this, and it is verified in one reading.

The discipline comes to three steps, two of which are taken before any loss. Check the retroactive date and compare it with the length of service of the people who handle funds, since that duration is what bounds the real risk. Size the limit on a long fraud and not on a financial year. And, the day a suspicion arises, date it in writing and notify, without waiting to know how much or by whom: late notification is this line's leading ground of refusal, and it almost always happens while a director, in good faith, tries to understand before troubling the insurer.

The worked case

A utilities services company changes crime insurer on January 1, 2025. The old contract had run since 2016 with unlimited retroactive cover; the new one carries a retroactive date of January 1, 2025, the insurer having refused to go further for want of a recent internal control audit. On February 14, 2025 the management controller emails the finance director that three suppliers share the same bank details, and writes that he does not understand it. The finance director asks for a check, which drags. An external audit concludes on September 30, 2025 that 480,000 euros were misappropriated between 2019 and 2024 by a buyer, using fictitious suppliers. Notification is made on October 6, 2025. Who responds?

The analysis

The file turns on a date, and it is neither the audit's nor the notification's. The new contract must first be ruled out, which takes no hesitation: its retroactive date is January 1, 2025 and the acts are all earlier, committed between 2019 and 2024; it answers for nothing, and the insurer's refusal to go further for want of an internal control audit takes on its full retrospective meaning here. That leaves the old contract, which had unlimited retroactive cover and would therefore pick up the acts without difficulty, on one condition: that discovery occurred while it ran, that is, before December 31, 2024. Yet the audit concluded on September 30, 2025 and notification is dated October 6, 2025, both later. Taken that way, the file is lost on both sides. It is the February 14, 2025 email that decides, and it must be read for what it is: three suppliers sharing bank details, reported in writing, are facts that would lead a reasonable person to suspect a covered loss, even without knowing the amount or the perpetrator. The discovery threshold is low and is probably crossed that day. But that date too is after December 31, 2024, and so falls within the new contract, which does not cover acts before its retroactive date. The honest conclusion is that the loss risks being covered by nobody, and that this should be said early rather than left as a hope. Two lessons emerge, and the second is the only actionable one. The continuity clause most contracts in this market provide exists for exactly this case and was missing here: it would have made the new insurer answer for acts covered by the old. And the refusal of retroactive cover, given for want of a recent internal control audit, was not an underwriting formality: it was the decision that created the gap, and it should have been put to the board as such rather than treated as a condition of price.

What to remember
  • 01A third way of dating a loss, after occurrence and claims-made: DISCOVERY, because a successful fraud is invisible by construction.
  • 02To discover is not to know: the threshold is the suspicion a reasonable person would form, without knowing the amount or the perpetrator.
  • 03One limit for a six-year fraud: size it on what a fraudster takes BEFORE being discovered, not on a financial year.
  • 04The retroactive date does not say how long you may claim, it says how far back committed acts are covered.
  • 05Late notification is this line's leading ground of refusal, and it comes from a director in good faith trying to understand before troubling anyone.
The notions in this module