The 2026 Demand Signal: Fraud Numbers Are Moving Crime Cover Into the Budget
Commercial crime and fidelity insurance sat at the edge of most Indian corporate insurance programmes for years, bought reflexively at a low limit or skipped entirely in favour of cyber and directors and officers cover. That is changing through 2026, and the reason is empirical. TransUnion's 2026 analysis put India's suspected digital-fraud rate at 7.1 per cent, close to double the global figure of 3.8 per cent, with the highest concentrations in logistics, telecom and insurance. When roughly one in fourteen digital transactions carries a fraud signal, the finance function stops treating internal and third-party crime as a tail risk and starts treating it as a recurring cost of doing business.
The demand is being driven from three directions at once. Corporates with large vendor-payment and payroll flows are worried about employee dishonesty and diverted funds. NBFCs and fintechs, running high-volume disbursement and collection systems, face both insider fraud and organised external attacks on their payment rails. Platform businesses, where cash and inventory move through a distributed workforce that is often not on the payroll in the traditional sense, are discovering that their fidelity guarantee wordings were written for a factory, not a marketplace.
The regulatory backdrop reinforces the mood. The IRDAI Insurance Fraud Monitoring Framework Guidelines 2025, effective 1 April 2026, require insurers to run structured anti-fraud machinery, which raises the visibility of fraud across the whole market and, indirectly, tightens the questions underwriters ask commercial buyers at renewal. The result is a market where crime and fidelity submissions are up, limits are being revisited, and brokers are being asked a question they were rarely asked before: does our current wording actually respond to the way we lose money today?
This post is a demand-side read for that question. It maps what commercial crime and fidelity cover, where the gaps against cyber sit, who is buying and why, and how the IRDAI framework reshapes the conversation.
What Commercial Crime and Fidelity Guarantee Actually Cover
The two products overlap but are not the same, and buyers often conflate them. Fidelity guarantee insurance is the older, narrower cover. It indemnifies the insured for direct financial loss caused by the dishonest or fraudulent acts of its own employees, written on a named-employee, position or blanket (all-employees-by-class) basis. It is the standard answer to embezzlement, cash misappropriation, inventory diversion and payroll fraud committed by staff.
Commercial crime insurance is the broader, more modern wording, usually adapted from international crime forms and now offered by insurers including ICICI Lombard, TATA AIG, HDFC Ergo and Bajaj Allianz. A typical Indian crime policy bundles several insuring clauses: employee dishonesty (the fidelity element), loss of money and securities on premises and in transit, forgery or alteration of negotiable instruments, computer fraud, funds transfer fraud, and, increasingly, a separate social-engineering fraud clause. It responds to both first-party loss (the insured's own money) and, under some sections, loss of third-party property in the insured's care.
Several structural features define how these covers behave, and brokers should walk buyers through each. Crime and fidelity policies almost always operate on a discovery basis, responding to losses discovered during the policy period regardless of when the act was committed, subject to a retroactive date. Proof of loss provisions require documentary evidence linking an identified dishonest act to a quantified loss, which is why weak internal records defeat otherwise valid claims. A prior knowledge exclusion removes cover where the insured or its senior management already knew of the dishonest conduct.
Recovery against perpetrators runs through the criminal law. Under the Bharatiya Nyaya Sanhita, 2023, criminal breach of trust falls under Section 316 and cheating under Section 318, the successors to the old Indian Penal Code provisions. Insurers pursuing subrogation rely on these filings, so the quality of the insured's incident response feeds directly into how much of a paid claim is ever clawed back.
The Social-Engineering Gap: Where Crime Cover Stops and Cyber Begins
The fastest-growing loss type is also the one most likely to fall between two policies. Social-engineering fraud, where a finance employee is tricked into authorising a genuine-looking but fraudulent payment, sits awkwardly on the boundary between crime and cyber insurance, and the coverage outcome depends on wording detail that few buyers examine before a loss.
The common patterns are business email compromise, where an attacker impersonates a vendor and changes bank account details on an invoice, and CEO or executive impersonation, where a spoofed instruction pressures a junior staffer into an urgent transfer. There is no system breach in the technical sense. The employee has authority, the payment mechanism works as designed, and the money leaves through a legitimate channel to a fraudulent destination. That is precisely why a standard computer fraud clause, which typically requires an unauthorised entry into or alteration of a computer system, often does not respond. The system was never hacked. A person was.
Cyber insurance does not reliably fill the gap either. Many Indian cyber wordings treat funds-transfer and social-engineering loss as an optional extension rather than a core insuring clause, and where both a crime and a cyber policy respond, the buyer faces overlapping conditions, different sub-limits and potential double-proof requirements. The practical answer is coordination at placement. Brokers should map, in writing, which policy is primary for a fraudulent-instruction loss, align the sub-limits so the buyer is not left with a token limit on the exposure that is actually growing, and confirm the verification warranties are operationally achievable by the client's real payments team rather than an idealised one.
Who Is Buying and Why: NBFCs, Fintechs, Platform Businesses and Listed Corporates
Demand in 2026 is not uniform. Four buyer segments are driving most of the new crime and fidelity submissions, each for a distinct reason.
NBFCs and fintechs are the sharpest buyers. Running large disbursement, collection and settlement flows, often through agents and third-party service providers, they carry concentrated insider-fraud and funds-diversion exposure. RBI supervisory attention on digital lending and outsourcing has raised board-level sensitivity to operational and fraud risk, and many are now buying crime cover alongside, or as a complement to, a bankers indemnity or blanket bond structure. For these firms, funds transfer fraud and forgery clauses matter as much as the fidelity element.
Platform and marketplace businesses are buying because their workforce model outran their old wordings. Cash on delivery, distributed inventory and gig or contractor staff mean the people handling money and goods may not be employees in the strict legal sense that a traditional fidelity guarantee wording assumes. These buyers are negotiating worker definitions that capture contractual personnel under the insured's direction and control, so the cover follows the actual exposure rather than the employment paperwork.
Listed and large unlisted corporates are revisiting limits that have not moved in years. A treasury or procurement fraud at a mid-cap can run into crores before detection, and audit committees, more attentive after several public governance episodes, are asking whether a legacy fidelity limit set a decade ago is still credible. Here crime cover is increasingly discussed alongside directors and officers liability, because a large internal fraud can trigger both a first-party crime loss and a shareholder governance claim.
Manufacturing and logistics groups round out the demand, driven by inventory diversion, in-transit money loss and vendor-collusion schemes. TransUnion flagged logistics as one of the highest-fraud sectors in India, and that finding is showing up directly in submission volumes.
The IRDAI Insurance Fraud Monitoring Framework, Effective 1 April 2026
The IRDAI Insurance Fraud Monitoring Framework Guidelines 2025 came into effect on 1 April 2026 and refresh the regulator's decade-old anti-fraud architecture. The framework is directed at insurers rather than at commercial buyers, so it is important to be precise about what it does and does not require, because the marketing around it can overstate the point.
What the framework does is oblige every insurer to run structured anti-fraud machinery. That includes a board-approved anti-fraud policy, a Fraud Monitoring Committee or equivalent governance body, dedicated fraud monitoring units, and defined processes for detecting, investigating and reporting fraud across the recognised fraud classes, spanning policyholder and claims fraud, intermediary fraud and internal fraud. Insurers are expected to deploy early-warning analytics and to report fraud data to the regulator on a defined cadence.
What the framework does not do is compel any company to buy commercial crime or fidelity cover. There is no mandate here for the corporate buyer. The relevance is indirect but real. As insurers build out fraud analytics and tighten claims scrutiny under the framework, commercial buyers should expect sharper underwriting questions at renewal, more attention to internal-control representations in the proposal form, and closer investigation of crime and fidelity claims when they are filed. A proposal that overstates the maturity of a client's payment controls is a materiality problem waiting to surface at claim stage.
Read correctly, the framework is a demand signal, not a mandate. It confirms that the regulator now treats fraud as a systemic issue, and that confirmation is part of why crime and fidelity cover is moving up the buying agenda.
Structuring the Programme: Limits, Sub-limits and Broker Checkpoints
Turning rising demand into a defensible programme comes down to a handful of structuring decisions that separate a wording that pays from one that disappoints.
Limit adequacy is the first. The single largest plausible loss for most buyers is a senior-employee or organised-collusion fraud that runs undetected for months, not a one-off cash theft. Limits should be sized against that scenario, informed by the value flowing through the most exposed processes (treasury, procurement, payroll, disbursement) rather than against turnover as a crude proxy. A limit that looks generous against revenue can be trivial against a single diverted vendor-payment run.
Sub-limit calibration is the second, and social-engineering fraud is where buyers get caught. If the fraudulent-instruction clause carries a sub-limit a fraction of the main crime limit while it represents the fastest-growing loss type, the programme is mis-shaped. Brokers should push for the social-engineering sub-limit to reflect real payment run sizes and negotiate the verification warranty into a form the client can actually meet.
Definitions and exclusions are the third. The employee or covered-worker definition should capture the people who actually handle money and stock, including contractors and outsourced staff where relevant. The prior-knowledge and prior-loss exclusions, the retroactive date, and the proof-of-loss provisions should all be read against the client's real record-keeping. A wording that demands transaction-level proof the client's systems cannot produce is a claim denial in waiting.
Buyers should also settle coordination with adjacent covers before binding, not after a loss. Crime, cyber, bankers indemnity and directors and officers policies can all touch a large fraud event, and the priority of response should be agreed in writing. For a working reference on how employee-dishonesty claims are proven and quantified in the Indian market, see Fidelity Guarantee Claims in India. Deductibles, discovery periods and reinstatement of limit after a paid claim complete the checklist.
Reading the Wordings Before You Buy
The 2026 demand story is straightforward. Fraud in India is measurably high, the regulator has formalised its anti-fraud expectations of insurers, and buyers across NBFCs, fintechs, platforms and corporates are re-examining crime and fidelity cover they long treated as boilerplate. The harder problem is that the value of this cover lives in wording detail: the employee definition, the social-engineering sub-limit and its verification warranty, the discovery basis, the prior-knowledge exclusion, and how cleanly the policy coordinates with cyber and bankers indemnity forms.
Those details vary materially from one insurer to the next, and they are exactly where a submission built on last year's assumptions goes wrong. A buyer comparing three crime quotes on limit and premium alone, without reading how each defines a covered fraudulent instruction, is comparing prices for different products.
This is the work that a searchable, structured view of insurer policy wordings is built to support. Comparing crime and fidelity forms manually means opening a dozen PDFs and hunting for the clause that decides whether a fraudulent-instruction loss is paid or declined, and that is slow, error-prone work at exactly the point where accuracy matters most. Sarvada lets brokers and risk teams compare crime, fidelity, cyber and bankers indemnity wordings across the Indian market clause by clause, so social-engineering sub-limits, worker definitions, verification warranties and coordination language sit side by side rather than buried in separate documents. If you are placing or reviewing commercial crime and fidelity programmes in 2026, Request Access to see how wording-level intelligence sharpens the comparison before you bind.