The two previous courses dealt with faults: an error of advice, a management decision. This one deals with intentional acts committed to take money, which changes everything, beginning with who is insured. A crime policy does not cover the insured's liability towards a third party, it covers the loss the insured suffers in its own assets. It is therefore not liability insurance, it is first-party insurance, and that characterization decides most of the questions that follow.
The product's origin explains its shape, and is worth knowing. It grew from what was called fidelity cover, by which an employer protected itself against theft committed by its own employees. The trust a company necessarily places in those who handle its funds is a risk, and no other line covers it: not liability, since the insured is liable to nobody for its own loss, and not property, since nothing is physically damaged. Internal fraud is therefore the historic family, and it remains the product's core.
The second family came later and is today the larger by volume: external fraud. A third party obtains a payment by deception, diverts a transfer, forges a payment instrument, or impersonates a director to have an instruction executed. The difference from the first is not only the identity of the fraudster, it is evidential: in internal fraud one looks for who inside the company took; in external fraud one often knows the money left and will never know where it ended up.
One must see that the two families are not underwritten on the same conditions, and that the reason is economic rather than moral. Internal fraud presupposes a failure of the insured's internal control, which the insurer examines before underwriting: segregation of duties, dual signature, rotation of functions, bank reconciliations. External fraud presupposes deception from outside, where the insured's controls still count but where the attacker's sophistication counts more. Proposal forms therefore ask about different things.
A third category deserves isolating because it is the most disputed: collusion. An employee and a supplier agreeing to over-invoice produce a loss that is neither wholly internal nor wholly external, and many wordings address it expressly. The point to check is whether the cover requires the employee's act to be established, or whether it suffices to establish the loss and a third party's participation, since in collusion it is precisely the employee's part that is hardest to prove.
What a crime policy almost never covers must be added, and insureds hope to find it there. The fall in value of an asset following a dishonest decision, which belongs to directors' liability. Lost profit and reputational harm, which are not diverted funds. The costs of reconstructing the accounts, sometimes covered by a named extension and never by the main cover. And fraud committed by a director for its own benefit, which belongs to a separate discussion since that person is both the perpetrator and an organ of the insured.
The useful reading therefore comes to three questions to put to any policy in this family. Who can be the fraudster within the meaning of the contract, and is collusion named. Which acts are covered, bearing in mind that wordings enumerate more than they define, and that an act absent from the list is outside. And what proof is required, a question that decides more files than the first two and that has a whole lesson to itself later in this course.
A building materials trader, 240 employees, discovers three separate losses during one audit in March 2026. First loss: the chief accountant issued transfers to a personal account over four years using adjustment entries, 610,000 euros. Second loss: in November 2025 a third party impersonating the chairman obtained from an assistant the execution of a 180,000 euro transfer to a foreign account, on the basis of emails imitating the director's address. Third loss: a buyer and a supplier had agreed for two years to inflate prices by 8 percent, the excess being shared, around 340,000 euros. The crime policy covers "the misappropriation of funds or securities committed by an employee, and fraud committed by a third party by means of a contrivance". What does it cover?
The three losses belong to three different families, and it is the third that raises the real question. The first is internal fraud in its historic form: an employee misappropriated the company's funds for her own benefit, the act is expressly covered, and the argument will bear on proof and quantum rather than principle. One timing point the facts make salient must be checked, the four elapsed years, since these policies most often trigger on discovery rather than on commission, which is the subject of the next lesson. The second is external fraud: a third party obtained a payment by a contrivance, which the wording also covers. The contested point will not be the fraudster's identity but the fact that the assistant executed the transfer voluntarily, believing she was obeying a proper instruction: some wordings require a fraudulent act bearing on a system or on a document, and a company that pays willingly because it was deceived does not always cross that threshold. The third is collusion, and it is the hardest of the three for a reason worth seeing: the wording quoted covers misappropriation by an employee and fraud by a third party, taken separately, and collusion is named nowhere. The supplier misappropriated no funds strictly speaking, it invoiced and was paid on invoices the company approved; the buyer took no money from the till, he approved prices. The loss is real, 340,000 euros, and it risks falling between the two limbs of the definition. Three steps follow. Notify the three losses separately, characterizing each, rather than as one set discovered at the same audit. On the collusion, look in the contract for an endorsement addressing it, and failing that build the file on the employee's part, which is the hardest to prove and the only limb the quoted wording allows. And check when each loss arose against the policy's trigger, which will decide the first as much as its characterization.
- 01This is not liability insurance but first-party cover: it covers the loss the insured suffers in its own assets.
- 02Two families, two evidential logics: in internal fraud one looks for who took, in external one knows the money left and rarely where it ended.
- 03They are not underwritten alike: internal control for the first, the attacker's sophistication for the second.
- 04Collusion is neither internal nor external, and a wording that does not name it lets the loss fall between the two limbs of its definition.
- 05Wordings enumerate more than they define: an act absent from the list is outside, however much it resembles those that are in it.