- 01Employees and access to money or property
- Job duties, approval authority, system permissions, and access to inventory or accounts help define where an internal theft could occur. Describe access by role rather than title alone.
- 02Transaction volume and payment methods
- Wire transfers, ACH payments, checks, credit cards, and cash each create different fraud paths. Include typical and maximum transaction amounts when selecting useful limits.
- 03Financial and technology controls
- Dual approval, independent callbacks, multifactor authentication, bank alerts, and reconciliations can prevent or identify fraud. Written controls should match what employees follow in practice.
- 04Money, securities, and property values
- Limits should reflect the largest credible amount at risk in one event, not only an annual average. Consider cash, checks, securities, inventory, and other covered property separately.
- 05Client funds and property
- Handling a client's funds, keys, inventory, or other property can create a loss that differs from theft of the business's own assets. Contracts may also require a bond or specified third-party protection.
- 06Prior theft or fraud losses
- Earlier losses help show how an event occurred and whether similar weaknesses remain. Include changes to access, approval, reconciliation, or vendor-verification procedures made afterward.
- 07Selected coverage parts and limits
- Employee theft, computer fraud, funds-transfer fraud, social engineering, and money or securities coverage are separate. Review each limit, deductible, territory, and verification condition.