What commercial crime covers
A Singapore commercial crime policy responds to loss of money, securities or other property from:
- Employee dishonesty (fidelity guarantee) — theft, embezzlement, fraudulent acts by employees.
- Theft on premises — robbery, burglary, hold-up.
- Theft outside premises — couriers, in-transit cash.
- Computer fraud — unauthorised manipulation of the insured's computer systems to transfer money or property.
- Funds-transfer fraud — fraudulent payment instructions to banks.
- Social engineering (named endorsement) — insured deceived by fraudulent communications into voluntarily transferring funds.
- Forgery of negotiable instruments — cheques, bills of exchange, money orders.
- Counterfeit currency.
- Damage to property in transit — during covered theft.
The social engineering question
Business Email Compromise (BEC) — an employee receives a fraudulent email purporting to be from a vendor or executive instructing a payment, and complies — is now the leading commercial-crime loss category in Singapore SMEs and mid-market businesses.
Commercial crime base wording covers involuntary loss of money (theft, computer fraud where the criminal directly compromises the system). Social engineering involves voluntary transfer by a deceived employee — technically not theft in legal terms — and so requires a named endorsement.
When buying commercial crime, confirm:
- Social engineering coverage is included.
- The sub-limit is adequate for typical wire-payment amounts in your business.
- The conditions (call-back verification, dual-approval, etc) that the insurer requires for cover.
Who needs it most
Highest exposure:
- MAS-licensed PSPs and Major Payment Institutions — handling client funds at scale.
- Banks and financial institutions — significant fidelity exposure from employees with access to client accounts.
- Family offices — wealth management with funds-transfer exposure.
- Charities and NGOs — treasurer exposure; many large grants require commercial crime cover.
- Real estate / property management — deposits and rental trust accounts.
- Professional services with client accounts — law firms, accounting firms, audit firms.
- M&A escrow agents.
Middle exposure: all SMEs handling regular supplier and vendor payments are increasingly buying commercial crime for the social engineering layer alone.
Sum insured guidance
Indicative limits by business profile:
- SME with social engineering only — S$500k to S$2m.
- Mid-market with employee dishonesty + computer fraud + social engineering — S$2m to S$10m.
- MAS-licensed PSP — S$5m to S$25m+ depending on transaction volume.
- Bank — bespoke programme, typically S$25m+.
Consider the worst-case single loss — if a fraudulent funds-transfer instruction to your largest vendor cleared, what would the loss be? Size limits accordingly.
Pairing with cyber liability
Commercial crime and cyber liability are complementary, not duplicate:
- Cyber covers incident response, business interruption from system downtime, data restoration, regulatory defence, third-party privacy claims.
- Crime covers first-party loss of money/property from criminal acts including fraud-driven cyber events.
Ransomware is an edge case — some cyber policies pay ransom (where lawful), some don't. Crime may pay if the ransom is treated as funds-transfer fraud. Discuss with broker at policy inception.
See our cyber liability page for the third-party cover side.