Step 15 / 18

Nobody broke in, and the money left

8 min of reading

The commonest configuration in this line is also the one most often declined, and the paradox is explained in one sentence: the company paid voluntarily. Nobody entered its systems, no document was forged inside it, no employee took money. An authorized person executed a transfer they believed to be proper, because they had been deceived. The question the contract must settle is whether a payment consented to under deception is fraud within the meaning of the cover.

The mechanism must be described first, because its banality is what makes it effective. A third party observes the company, learns the names, the vocabulary, the timetable of a transaction under way, then writes to the right person at the right moment imitating a known address. The instruction is plausible, urgent and confidential, and it asks for a light departure from the ordinary procedure. The employee who executes it is neither careless nor complicit: they are doing their job in a context manufactured for it, which is why the best-run companies fall for it too.

The contractual difficulty is that many wordings describe fraud by its means rather than by its result. A cover targeting the forgery of a document, the alteration of a system or fraudulent entry into a data process describes acts that did not occur here. A cover targeting the obtaining of funds by a fraudulent contrivance describes exactly what happened. Two policies from the same market, two opposite outcomes on the same facts, and the difference lies in a few words nobody reads before the loss.

One must then know the two conditions these covers almost always attach, since they decide files more often than the definition does. The first is a procedural requirement: the policy asks that the company verify through an independent channel before any payment above a threshold, a call back on a known number and not the one given in the message. The second is a requirement of compliant execution: the payment must have been made by an authorized person, through the prescribed circuit. A departure allowed out of kindness or urgency can therefore cost the cover.

That second condition deserves dwelling on, because it produces a counter-intuitive effect. The fraudster succeeds precisely by obtaining a departure from the procedure; and the policy requires the procedure to have been followed. In other words, the cover withdraws at the very moment the risk materializes, and this is not a trap but an accepted consequence: the insurer covers deception, not a loosening of control. An honest underwriter says so to the client beforehand, and an informed client puts the independent call-back beyond the reach of any individual departure.

The boundary with the cyber policy must be added, since it produces the most frequent passing of files by volume. Where no intrusion occurred, the cyber policy objects that no system was breached; where an employee paid voluntarily, the crime policy objects that the circuit was not followed. The file can thus sit for months between two of the same insured's insurers. The answer is not found in the loss, it is prepared at placement, by putting both covers with the same carrier or by having it written down which responds first.

The useful step therefore comes to three readings done together and never after the event. How does my policy define fraud, by the means employed or by the result obtained. What procedural conditions does it impose, above what threshold, and are those conditions actually applied here rather than described in a binder. And what happens if my cyber insurer and my crime insurer pass the file between them. A professional with those three answers knows what the policy covers; one without them has bought a heading.

The worked case

A 90-employee industrial SME is acquiring a competitor, an operation known to a few people. On May 22 the sole bookkeeper receives an email from the chairman, traveling, asking her to execute a confidential deposit of 240,000 euros to a lawyer's account abroad, noting that the dual authorization procedure would slow the deal and that the finance director is on a plane. The sender's address differs by one character. The bookkeeper executes the transfer alone at 5:40 pm. The fraud is discovered on May 26. The policy covers "fraud committed by a third party having obtained funds by means of a contrivance", subject to "verification through an independent channel for any payment above 50,000 euros" and "execution in accordance with the authorization circuit in force". What happens?

The analysis

The definition favors the insured and the conditions do not, which is this lesson's exact configuration. On the definition there is no argument: the policy targets the obtaining of funds by a contrivance, that is, the result and not the means, and an email imitating the chairman's address to obtain a transfer is precisely that. A wording targeting the forgery of a document or the alteration of a system would by contrast have closed the file at once, since nothing of the kind occurred. On the conditions, both are breached and they should be distinguished rather than added together. Verification through an independent channel above 50,000 euros did not happen: no call back on a known number, on an amount almost five times the threshold. Execution in accordance with the circuit did not happen either: dual authorization was set aside, and it was set aside on the request contained in the fraudulent message itself. This is where the lesson holds most harshly: the fraudster succeeded by obtaining the departure, and that same departure withdraws the cover. The insurer covers deception, not a loosening of control, and it will very probably raise both breaches. Three observations for what follows, and the first is a question of fact not to be prejudged. It must be checked what the authorization circuit actually provided for a sole bookkeeper in the finance director's absence: a circuit with no designated deputy is a circuit that cannot be followed, and a condition impossible to meet is arguable. Next, the company should pursue its bank and recovery, the fraud having been discovered within four days, which leaves a chance of freezing the funds. Finally, and this is the only transferable lesson, the structural weakness was not the bookkeeper: it was an organization where one person alone can execute a 240,000 euro payment because two others are unavailable.

What to remember
  • 01The company paid voluntarily, and that is what makes this loss hard: nobody entered, nothing was forged, an employee did their job.
  • 02A policy defining fraud by its MEANS closes the file; one defining it by its RESULT opens it. A few words separate them.
  • 03Two conditions decide more often than the definition: verification through an independent channel, and execution in accordance with the circuit.
  • 04The fraudster succeeds by obtaining a departure, and that departure withdraws the cover: the insurer covers deception, not slackness.
  • 05A circuit with no designated deputy is a circuit that cannot be followed, and a condition impossible to meet is arguable.
The notions in this module