Few questions reach a fidelity underwriting desk as often as this one: “Is a commercial crime policy the same thing as a fidelity bond?” The question arrives from controllers who have been told by a lender to “get bonded,” from plan sponsors confusing their statutory ERISA bond with the coverage their operating company needs, from broker dealers who carry a Form 14 and assume it protects the firm’s own accounts, and from insurance buyers who have simply noticed that their carrier renewed a “fidelity bond” under a declarations page titled “commercial crime.” The answer is a qualified yes, and the qualification is worth an essay, because the vocabulary of fidelity has drifted over a century while the instrument itself has broadened without changing its essential character. This piece traces the lineage, explains why the fidelity bond vs commercial crime policy distinction is largely one of nomenclature, identifies the statutory instruments that remain genuinely distinct, and closes with the practical consequences for an organization deciding what to buy.
The fidelity bond defined
A fidelity bond is an insurance policy that indemnifies an employer for loss caused by the dishonest or fraudulent acts of its employees. The Surety & Fidelity Association of America, the standards and advisory organization that has served the surety and fidelity industry since 1908, defines the instrument in exactly those terms and adds that a fidelity bond “typically covers the insured against” forgery or alteration, loss inside the premises caused by theft, disappearance, destruction, robbery and safe burglary, and loss outside the premises caused by robbery of a messenger.1 The SFAA then makes the point that this essay exists to elaborate: “These coverages sometimes are referred to as Crime Coverage.”1
The instrument is old. Fidelity guarantees appear in English commercial practice by the eighteenth century, first as personal suretyship in which a third party pledged to answer for a clerk’s honesty, then as corporate suretyship once joint stock companies began to write guarantees for premium.2 The American market followed, and by the early twentieth century the fidelity bond was a standard product of the corporate surety, written on a schedule basis naming individual employees or on a blanket basis covering all of them.2 Because sureties wrote it, the product carried the vocabulary of suretyship: it was a “bond,” the employer was the “obligee,” the employee was in effect the “principal,” and the document promised indemnity rather than defense.
That vocabulary is the first source of confusion. A fidelity bond has never been a true surety bond in the tripartite sense. The dishonest employee does not sign it, does not pay for it, and owes no indemnity to the surety in the way a construction contractor indemnifies a performance bond surety. A fidelity bond is, functionally, first-party insurance. The employer pays the premium, the employer suffers the loss, and the employer collects. Courts and commentators have recognized this for decades, and the modern forms say so explicitly.3 The word “bond” survives as an artifact of who sold it, not what it does, and much of the fidelity bond vs commercial crime policy confusion begins with that surviving word.
How the fidelity bond became the commercial crime policy
The second source of confusion is the broadening of the form. Over several decades in the middle and late twentieth century, the SFAA, working with the major national carriers engaged in fidelity bonding, significantly expanded the coverages carried under the basic fidelity bond. The employee dishonesty promise remained the core insuring agreement, but the standardized forms added forgery or alteration of instruments drawn on the insured’s accounts, multiple perils inside the premises, and specified losses outside the premises. Later revisions, keeping pace with how money actually moves, added computer fraud and funds transfer fraud.4 With the coverage no longer limited to the dishonesty of employees, “fidelity bond” had become an underinclusive label for a multi-peril form, and the broad form fidelity bond was renamed commercial crime.
The renamed forms are the ones in use today. Insurance Services Office publishes the Commercial Crime Coverage Form in a discovery version and a loss sustained version, each organized around the same family of insuring agreements: employee theft, forgery or alteration, inside the premises, outside the premises, computer fraud, funds transfer fraud, and money orders and counterfeit money.5 The SFAA publishes parallel standard forms for mercantile and governmental risks and, separately, the financial institution bonds discussed below.1 The standardized forms are accepted by insurance commissioners in every United States jurisdiction as fidelity bonds. That acceptance matters in practice: when a statute, a lender, a franchisor, a grantor or a contract requires an organization to carry a “fidelity bond,” a commercial crime policy issued on the standard forms satisfies the requirement, because regulators treat the two names as the same instrument.
So the honest answer to the fidelity bond vs commercial crime policy question is that the commercial crime policy is the fidelity bond, broadened by the industry’s own standards body and issued under a name that describes the full scope of what it now covers. Surety One has said as much publicly for more than a decade. A January 2013 note on the firm’s blog put it plainly: fidelity bonds, “more recently referred to as commercial crime policies,” are an excellent way to cover a business for losses due to the dishonest acts of employees, and demand for broader coverage has produced endorsements and third-party products that extend “far beyond internal theft.”6
What the modern form actually promises
The fidelity bond vs commercial crime policy comparison is easiest to see when the modern insuring agreements are laid side by side with the classic bond.
The employee theft insuring agreement is the classic fidelity bond. It pays for loss of money, securities and other property resulting directly from theft committed by an employee, whether identified or not, acting alone or in collusion with others.5 Everything the schedule and blanket fidelity bonds of 1930 promised lives here.
Forgery or alteration pays for loss resulting from the forgery or alteration of checks, drafts, promissory notes and similar instruments drawn on the insured’s accounts, and typically extends to the cost of defending a suit brought over the insured’s refusal to honor a forged instrument.5 This agreement is the first of the broadenings.
Inside the premises covers theft, disappearance or destruction of money and securities inside the insured’s premises or a banking premises, together with robbery of a custodian and safe burglary of other property, and damage to the premises or a safe from an actual or attempted theft. Outside the premises covers money, securities and other property in the care of a messenger or an armored motor vehicle company.5 These are the multiple peril and messenger robbery coverages the SFAA definition names.
Computer fraud and funds transfer fraud are the late additions. The first pays for loss resulting directly from the use of a computer to fraudulently transfer money, securities or property from inside the premises or a banking premises to a person or place outside. The second pays for loss of funds from the insured’s transfer account caused by fraudulent instructions to a financial institution, acted upon without the insured’s knowledge or consent.5
Social engineering, or fraudulent impersonation, deserves its own paragraph because it is the exposure that has generated the most litigation in the past decade and the most confusion among buyers. When an employee is deceived by a criminal impersonating a vendor, a client or an executive into voluntarily transferring funds, the loss does not fit comfortably within computer fraud or funds transfer fraud as the standard forms define them, and the federal courts of appeals have divided on the question. The Fifth Circuit denied coverage where a spoofed vendor email led to a changed payment instruction, reasoning that the computer use was incidental to a loss caused by the insured’s own authorized transfer.7 The Second and Sixth Circuits found coverage on facts that were not identical but were close.8 The industry’s response was the social engineering endorsement, generally written with a sublimit and a callback verification condition, and a careful buyer asks for it by name. It is a fidelity coverage in every sense, but it is not automatically part of the form.
Two features of the modern form decide whether a loss is paid at all, and both descend directly from the classic bond. The first is the trigger. A discovery form covers loss discovered during the policy period regardless of when it occurred, subject to any retroactive date; a loss sustained form covers only loss that both occurs and is discovered during the policy period or an extended discovery period, with a prior insurance provision that may reach back to a predecessor policy.5 The second is termination as to any employee. The moment the insured, or a partner, officer or manager not in collusion, learns of a dishonest act committed by an employee, coverage as to that employee ends.5 Both provisions are why fidelity underwriters ask about prior knowledge with such insistence, and why the answer to that question on an application is treated as a condition of coverage rather than an idle inquiry.
The instruments that remain genuinely distinct
If the fidelity bond vs commercial crime policy distinction is one of nomenclature, why does the market still sell things called fidelity bonds? Because a handful of statutory and contractual instruments are prescribed by law or by an obligee, written on their own forms, and protect a party other than the buyer. These are the qualifications in the qualified yes.
The ERISA fidelity bond is the most widely required of them. Section 412 of the Employee Retirement Income Security Act requires every fiduciary of an employee benefit plan and every person who handles plan funds or other property to be bonded, generally in an amount of ten percent of the funds handled, with a minimum of $1,000 and a maximum of $500,000 per plan, or $1,000,000 where the plan holds employer securities.9 The Department of Labor’s regulations govern the bond’s form and the sureties that may write it.10 The ERISA bond protects the plan and its participants against loss caused by fraud or dishonesty on the part of the persons bonded. It does not protect the sponsoring employer’s own treasury, and the sponsoring employer’s commercial crime policy does not satisfy section 412. An organization that sponsors a plan and has employees who touch money needs both. Surety One, Inc. issues the statutory bond, often the same business day, at ERISA-Bonds.com.
The FINRA fidelity bond is the second. FINRA Rule 4360 requires every member firm that is required to join the Securities Investor Protection Corporation to maintain blanket fidelity bond coverage with specified insuring agreements and minimum limits keyed to the firm’s net capital requirement.11 The bond is written on the Brokers Blanket Bond, Standard Form No. 14, promulgated by the SFAA, which is why practitioners call it the Form 14.12. It is a fidelity bond in the fullest sense and a financial institution bond in form, and it is distinct from a commercial crime policy in the way a financial institution bond has always been distinct from a mercantile crime form. Surety One issues it at BrokerDealerBond.com.
The business services bond, sometimes called a dishonesty bond or a third party fidelity bond, is the third. It reverses the direction of the promise. Rather than indemnifying the employer for theft by its employees, it indemnifies the employer’s clients for theft of the client’s property by the employer’s employees while performing services on the client’s premises. Janitorial contractors, home care agencies, pet sitters, movers, handyman services, and similar businesses carry it, often in amounts between $5,000 and $250,000, so that they may advertise as bonded and so that a property manager or a household will accept the engagement. Many carry a small business services bond and a commercial crime policy at once, one for the client’s property and one for their own. Surety One, Inc. describes the product and offers it at CommercialCrimePolicy.com.
Mortgage banker bonds, public official bonds, and the financial institution bonds written for banks, insurers and investment advisers each carry fidelity elements as well, and each is prescribed by a regulator or an investor rather than chosen by the insured. The unifying principle is simple. When a law or an obligee tells you which form to buy, you are buying a distinct instrument that happens to be a fidelity bond. When you are protecting your own balance sheet from your own people and from outside criminals, you are buying the commercial crime policy, and calling it a fidelity bond is not an error.
The distinction matters to the buyer. Settling the fidelity bond vs commercial crime policy question has three practical consequences for the buyer.
The coverage gap most organizations carry is not a gap between fidelity and crime; it is the gap between crime coverage and everything else. Commercial property forms exclude dishonest acts by employees. Commercial general liability responds to third-party bodily injury and property damage claims and has nothing to say about the theft of the insured’s own funds. Cyber liability forms frequently exclude or sublimit the transfer of money, and where they respond to social engineering at all they do so through their own sublimited endorsements.13 The commercial crime policy is the form the industry built for the disappearance of the insured’s own money, and an organization that has employees handling cash, deposits, payables, payroll, inventory or wire instructions and does not carry it is uninsured for the exposure the Association of Certified Fraud Examiners estimates costs the typical organization five percent of annual revenue, with a median loss per case of $145,000 and a median duration of twelve months before detection.14
In any fidelity bond vs commercial crime policy comparison, the name on the declarations page is not the test of adequacy; the insuring agreements are. A buyer who is told to obtain a fidelity bond should read the requirement for the amount and, if the requirement is statutory, for the form. If the requirement comes from ERISA or FINRA, the buyer needs the statutory instrument on its own form. If the requirement comes from a lender, a franchisor, a grantor or a contract, a commercial crime policy on the standard forms satisfies it, and the buyer should then select the insuring agreements and the trigger that fit how money moves through the organization. Employee theft is nearly universal; funds transfer fraud and the social engineering endorsement are essential for any organization that pays vendors electronically; inside and outside the premises coverage matters for cash businesses; forgery matters for any organization that writes checks. The FBI’s Internet Crime Complaint Center reported business email compromise losses approaching three billion dollars in 2023 alone, which is reason enough to treat the social engineering endorsement as a default rather than an option.15
Fidelity underwriting turns on controls, and it always has. The classic surety asked about the bookkeeper’s references; the modern underwriter asks whether someone other than the person who reconciles the bank accounts makes the deposits, makes the withdrawals and signs the checks, whether countersignature is required above a threshold, whether payment instruction changes are verified by callback to a known number, whether an outside accountant audits or reviews the books, and whether inventory is counted by someone other than its custodian. An applicant that cannot demonstrate a clear separation of duties does not meet the internal control standard for fidelity coverage, and a company of one cannot be bonded for the dishonesty of employees it does not have. Those rules are not carrier caprice; they are the underwriting logic of a product that insures against the trusted insider, and they are the same whether the declarations page says fidelity bond or commercial crime.
Parting Thoughts
The fidelity bond vs commercial crime policy question dissolves once the history is understood. The fidelity bond is the instrument; commercial crime is the name the industry gave it after the Surety & Fidelity Association of America and the national carriers broadened the form to cover forgery, premises and transit perils, computer fraud and funds transfer fraud. Insurance commissioners in every jurisdiction accept the standardized forms as fidelity bonds. The instruments that remain distinct, the ERISA bond, the FINRA Form 14, the business services bond and the various statutory and financial institution bonds, are distinct because law or an obligee prescribes their form and because they protect someone other than the buyer, not because they are a different species of coverage. An organization that keeps those three ideas in view will buy the right instrument for the right beneficiary, and will spend its attention where fidelity underwriting has always spent it, on the controls that separate the honest handling of money from the opportunity to steal it.
Surety One, Inc. underwrites fidelity bonds and commercial crime coverage in all fifty states, Puerto Rico and the U.S. Virgin Islands, and maintains dedicated platforms for the commercial crime policy, the ERISA fidelity bond and the FINRA Form 14. The author is the founder of Surety One, Inc. and the author of The Contractor’s Guide to Surety Bonds.
~ C. Constantin Poindexter, MA, JD, CPCU, AFSB, ASLI, ARe, AINS, AIS, CPLP
Notes
- The Surety & Fidelity Association of America, “About Fidelity,” https://www.surety.org/ (defining a fidelity bond as “a bond which indemnifies the insured for loss caused by the dishonest and fraudulent acts of its covered employees,” listing the additional coverages typically carried, and noting that “these coverages sometimes are referred to as Crime Coverage”). The SFAA has served the industry since 1908 and develops the standard fidelity and crime forms for financial institutions and for mercantile and governmental entities. ↩ ↩2 ↩3
- See generally Edward C. Lunt, Surety Bonds: Nature, Functions, Underwriting Requirements (1922), and Willis Park Rokes, Human Relations in Handling Insurance Claims (rev. ed. 1981), on the development of corporate fidelity guarantees from personal suretyship; see also Robert F. Cushman & George L. Blick, eds., Handling Fidelity, Surety and Financial Risk Claims (2d ed. 1990), chapter 1, on the schedule and blanket forms. ↩ ↩2
- The modern ISO and SFAA forms describe themselves as insurance policies issued to the insured and pay the insured directly. On the character of fidelity coverage as first-party insurance rather than suretyship, see, e.g., Auto Lenders Acceptance Corp. v. Gentilini Ford, Inc., 181 N.J. 245, 854 A.2d 378 (2004) (analyzing an employee dishonesty policy under first-party insurance principles). ↩
- The evolution of the standard forms from employee dishonesty coverage to multi-peril crime coverage, including the addition of forgery, premises, transit, computer fraud and funds transfer fraud agreements, is traced in the SFAA’s and ISO’s form histories and in Cushman & Blick, note 2 above. The SFAA and the major carriers standardized the broadened mercantile form and renamed it commercial crime; the standardized forms are accepted by all United States insurance commissioners as fidelity bonds. ↩
- Insurance Services Office, Commercial Crime Coverage Form (Discovery Form), CR 00 20, and Commercial Crime Coverage Form (Loss Sustained Form), CR 00 21, Section A (Insuring Agreements), Section D (Conditions, including “Termination As To Any Employee” and, in the loss sustained form, “Loss Sustained During Prior Insurance”). Edition dates vary by state; the 2013 and later editions are current in most jurisdictions. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
- C. Constantin Poindexter, “Fidelity bond, commercial crime policy, dishonesty bond, . . . one in the same!,” Surety One, Inc. blog, January 4, 2013. ↩
- Apache Corp. v. Great American Insurance Co., 662 F. App’x 252 (5th Cir. 2016) (no coverage under computer fraud insuring agreement where a fraudulent email prompted the insured to change vendor payment instructions). ↩
- Medidata Solutions, Inc. v. Federal Insurance Co., 729 F. App’x 117 (2d Cir. 2018) (coverage under computer fraud agreement for spoofed email scheme); American Tooling Center, Inc. v. Travelers Casualty & Surety Co. of America, 895 F.3d 455 (6th Cir. 2018) (loss “directly” caused by computer fraud despite intervening employee actions). ↩
- Employee Retirement Income Security Act of 1974 § 412, 29 U.S.C. § 1112. ↩
- 29 C.F.R. Part 2580 (Temporary Bonding Rules), including §§ 2580.412-1 through 2580.412-36; see also U.S. Department of Labor, Employee Benefits Security Administration, Protect Your Employee Benefit Plan With An ERISA Fidelity Bond (Field Assistance Bulletin 2008-04 and related guidance). ↩
- FINRA Rule 4360 (Fidelity Bonds), requiring covered members to maintain blanket fidelity bond coverage with specified insuring agreements and minimum coverage tied to net capital. ↩
- The Surety & Fidelity Association of America, Brokers Blanket Bond, Standard Form No. 14; see also Financial Institution Bond, Standard Form No. 24, the banking counterpart. ↩
- On the interaction of crime and cyber forms and the placement of social engineering coverage, see the discussion of the Fifth, Second and Sixth Circuit decisions in notes 7 and 8 above, and the endorsements subsequently promulgated by ISO and by individual carriers to address fraudulent impersonation. ↩
- Association of Certified Fraud Examiners, Occupational Fraud 2024: A Report to the Nations (2024) (estimating that organizations lose five percent of revenue to fraud annually, reporting a median loss of $145,000 per case, and a median duration of twelve months before detection). ↩
- Federal Bureau of Investigation, Internet Crime Complaint Center, 2023 Internet Crime Report (2024) (reporting business email compromise complaints and adjusted losses exceeding $2.9 billion). ↩