The Answer in 60 Seconds
Fidelity Guarantee, Commercial Crime and Cyber Crime cover all respond to money lost through dishonesty or theft, which is exactly why Singapore SMEs assume they are interchangeable. They are not. Fidelity Guarantee is the narrowest: it pays for loss caused by the dishonest or fraudulent acts of your own employees, and nothing else. Commercial Crime is broader: it keeps the Employee Dishonesty cover and adds third-party crime insuring clauses, typically Forgery or Alteration, Theft of Money and Securities, Robbery, Computer Fraud and Funds Transfer Fraud. Cyber Crime is not a separate policy at all, but a set of sections inside a cyber policy, usually Funds Transfer Fraud and Social Engineering Fraud, almost always written to a sub-limit far below the main cyber limit.
The danger is not the overlap. It is the seam between them. The fraud that hurts Singapore SMEs most, a finance staffer deceived by a convincing impersonation into authorising a real payment to a fraudster, can fall outside all three: no employee was dishonest, no system was hacked, and the small social-engineering sub-limit may not stretch to the loss. The offences themselves sit in the Penal Code 1871 (criminal breach of trust, cheating) and the Computer Misuse Act 1993 (unauthorised access and modification), but the criminal law does not pay your loss. Your policy does, if its trigger matches what happened. This is a make-the-call comparison, not a recommendation of any insurer.
The Sourced Detail
The three covers exist because dishonesty arrives by different routes. An employee steals from the inside. A forger or robber attacks from the outside. A fraudster sits between the two, using a screen and a plausible story to make your own staff move the money for them. Each cover was designed around one of those routes, and a loss that does not fit the route the policy was built for goes unpaid even when the dollar outcome looks identical. Below is what each cover responds to, then where the seams open.
Fidelity Guarantee: employee dishonesty only
Fidelity Guarantee responds to direct financial loss caused by the dishonest or fraudulent acts of an insured employee: embezzlement, theft of cash or stock, false invoicing, payroll fraud, asset misappropriation. The trigger is the dishonesty of a person you employ. If the wrongdoer is not your employee, the policy does not respond.
In the Singapore SME market this cover is commonly bundled inside packaged SME policies, where a Fidelity Guarantee section typically protects against direct financial loss caused by the fraudulent or dishonest acts of an insured employee. That is the whole of the cover: real, but narrow. A forged supplier instruction, a robbery at the counter, a phishing-induced wire to a stranger, none of these is employee dishonesty, and none triggers a bare Fidelity Guarantee section.
The mechanics of how a Fidelity claim runs once you discover the theft, evidence preservation, the police report, the proof of loss, are set out in the sibling note on filing a Fidelity Guarantee claim for employee dishonesty.
Commercial Crime: employee dishonesty plus third-party crime
Commercial Crime keeps the Employee Dishonesty insuring clause and adds discrete insuring clauses for crime committed by people who do not work for you. A typical Singapore-issued Commercial Crime wording is built as a set of separate insuring clauses you can read off the schedule:
- Employee Dishonesty, the same trigger as Fidelity Guarantee.
- Forgery or Alteration, for loss from a forged or altered cheque, draft or financial instrument.
- Theft of Money and Securities and Robbery, for physical theft of cash, securities or property.
- Computer Fraud, for loss from a fraudulent entry of, or change to, data or programs in your computer system, typically requiring an actual unauthorised manipulation of the system.
- Funds Transfer Fraud, for loss from a fraudulent instruction to your bank to transfer funds.
The breadth matters because the typical SME crime loss is no longer a hand in the till. It is an instruction. A forged authorisation, a fraudulent payment order, a manipulated vendor master file: these sit in the third-party insuring clauses, not in Employee Dishonesty. An SME that buys bare Fidelity Guarantee and assumes it has crime cover has bought one insuring clause out of six.
How Fidelity Guarantee and Commercial Crime differ on the timing trigger, the Discovery versus Loss-Sustained question that decides whether a multi-year embezzlement discovered today is even claimable, is a separate axis covered in the Loss-Discovered vs Loss-Sustained comparison. Read that alongside this one: trigger architecture and insuring-clause breadth are two different decisions, and you have to get both right.
Cyber Crime: sections inside a cyber policy, usually sub-limited
There is no standalone "Cyber Crime" policy. What SMEs mean by the term is a cluster of financial-loss sections inside a cyber liability policy. A cyber policy's core job is incident response, data restoration, business interruption and liability after a breach. Bolted onto that, most Singapore cyber wordings offer two crime-flavoured sections:
- Funds Transfer Fraud / Cyber Crime, for money stolen through unauthorised electronic access to your systems or accounts.
- Social Engineering Fraud, for money your own staff paid out because they were deceived by a fraudulent communication that impersonated a supplier, a senior manager or a bank.
The structural catch is the sub-limit. These crime sections are almost always written to a sub-limit, often a small fraction of the headline cyber limit. A policy advertised at a S$1m limit may carry a Social Engineering Fraud sub-limit of S$50,000 or S$100,000. The headline figure is for the data breach. The fraud you are most likely to actually suffer is capped far lower. The general pattern of small sub-limits hiding inside a larger policy is the same trap covered in standalone cyber vs a cyber sub-limit under a package policy; here it operates one level deeper, as a sub-limit inside the cyber policy itself.
Where the cover overlaps, and where it gaps
Lay the three side by side against the loss type and the seams appear.
| Loss event | Fidelity Guarantee | Commercial Crime | Cyber Crime sections |
|---|---|---|---|
| Employee embezzles over years | Yes (Employee Dishonesty) | Yes (Employee Dishonesty) | No |
| Forged or altered cheque | No | Yes (Forgery or Alteration) | No |
| Robbery of cash at premises | No | Yes (Robbery) | No |
| Hacker manipulates your system to move funds | No | Often yes (Computer Fraud) | Often yes (Funds Transfer Fraud) |
| Phishing email tricks staff into wiring money to a fraudster | No | Often no | Yes, but only up to the social-engineering sub-limit |
| Deepfake or impersonation call authorises a genuine payment | No | Often no | Yes, if social-engineering section bought, up to sub-limit |
Two columns earn a "yes" against the hacker-manipulation row, which is the real overlap. When an attacker actually breaches the system, both a Commercial Crime Computer Fraud clause and a cyber Funds Transfer Fraud section may respond. That double-touch is not a windfall: the indemnity principle means you recover your loss once, not twice, so the two insurers argue over contribution rather than paying you double. The job at placement is to coordinate them so neither can point at the other and decline.
The dangerous row is the phishing and impersonation one. Social-engineering fraud is the loss where no system is breached and no employee is dishonest. A fraudster impersonates a real supplier or a director, your finance staffer believes the instruction is genuine, and authorises a real payment to the fraudster's account. There was no unauthorised system access, so a Commercial Crime Computer Fraud clause that requires actual manipulation of your system may not respond. There was no employee dishonesty, so Employee Dishonesty does not respond. The only cover built for this exact fact pattern is the Social Engineering Fraud section of a cyber policy, and that is the section most likely to carry a punishing sub-limit, or to have been left off the schedule entirely. This is how SMEs end up uninsured for a loss they were certain something covered.
The most modern version of this gap is the impersonation done with synthetic media, an AI-cloned voice or a deepfake video call. The cover analysis is the same as classic social engineering, because the deception, not the technology, is what the policy turns on. The sibling note on deepfake funds-transfer fraud and where cyber, crime and social-engineering cover sit works through that newer fact pattern in detail.
The criminal-law backdrop
The offences behind all three covers sit in Singapore criminal statute, but the criminal law punishes the wrongdoer; it does not indemnify your loss. Employee embezzlement is criminal breach of trust under sections 405 to 409 of the Penal Code 1871. Deception-based fraud, including most social-engineering loss, is cheating under sections 415 to 420. Where an attacker actually accesses or alters your system, the conduct engages the Computer Misuse Act 1993, which criminalises unauthorised access and unauthorised modification of computer material. A police report to the Singapore Police Force is usually both the right first step and a condition precedent in the policy wording, but it recovers nothing on its own. Whether you are paid back depends on which civil insurance trigger your loss matches, which is the entire point of this comparison.
Common Mistakes
-
Treating Fidelity Guarantee as "crime cover". Fidelity Guarantee is one insuring clause: Employee Dishonesty. Forgery, robbery, computer fraud and funds-transfer fraud are not in it. An SME that needs protection against third-party crime needs Commercial Crime, not bare Fidelity Guarantee.
-
Assuming the cyber policy's headline limit applies to fraud. The data-breach limit and the funds-transfer or social-engineering sub-limit are different numbers. Read the schedule for the sub-limit, because that is the figure that pays out when staff are tricked into a transfer.
-
Leaving social-engineering fraud uncovered. This is the loss that falls between Commercial Crime (no system hack, no dishonest employee) and a cyber policy that did not buy the social-engineering section. It is the single most common uninsured fraud loss for Singapore SMEs.
-
Not coordinating Commercial Crime and cyber on the overlap. Where a genuine system breach moves funds, both policies may respond, and each can try to defer to the other. Without coordination the SME is caught in a contribution dispute at the worst time.
-
Buying the section but under-setting the sub-limit. A S$50,000 social-engineering sub-limit against a credible exposure of several hundred thousand dollars in supplier payments leaves most of the loss uninsured even when the section is in force.
-
Confusing "Computer Fraud" with "Social Engineering Fraud". Computer Fraud usually requires an actual unauthorised manipulation of your system. Social Engineering Fraud responds when staff are deceived into acting and the system was never breached. They are different triggers, and the loss you fear most likely needs the second one.
What This Means for Your Business
Start by naming your real exposures rather than the products. If your largest credible loss is a long-serving finance employee, Employee Dishonesty cover, whether inside Fidelity Guarantee or Commercial Crime, is the priority, and the trigger-architecture decision matters as much as buying the clause. If you make frequent supplier payments by bank transfer, the loss that will actually find you is fraudulent payment instruction, which means Funds Transfer Fraud and, above all, Social Engineering Fraud cover, sized to a sub-limit that reflects your real payment volumes.
Then map the three covers against those exposures and look specifically for the seam. Confirm in writing whether social-engineering fraud is covered, by which policy, and to what sub-limit. Confirm how Commercial Crime Computer Fraud and the cyber Funds Transfer Fraud section coordinate where they overlap, so a genuine breach does not trigger a tug-of-war. The aim is not to buy all three at full breadth. It is to make sure no realistic fraud falls into the gap between them.
If you have already suffered a loss, the operational first moves differ by route. Internal embezzlement has its own day-one workflow and first-24-hours playbook; a fraudulent outbound wire has a separate business email compromise response. The cover that responds is decided long before the loss, by which sections sit on your schedule and at what limit.
Covarage helps with the part that quietly goes wrong: keeping the Fidelity, Commercial Crime and cyber wordings organised in one place so the insuring clauses and sub-limits are visible side by side, with renewal reminders before any of them lapses, and a route to a licensed adviser when you need to compare cover or close a gap.
Questions to Ask Your Adviser
- Are we covered for employee dishonesty only, or for the broader Commercial Crime insuring clauses (forgery, robbery, computer fraud, funds transfer fraud)?
- Is social-engineering fraud covered, by which policy, and what is the sub-limit?
- If our staff are deceived into authorising a genuine payment to a fraudster, with no system breach, which of our policies responds?
- How do our Commercial Crime Computer Fraud clause and our cyber Funds Transfer Fraud section coordinate where they overlap?
- What is the sub-limit on the cyber crime sections, and how does it compare to our actual supplier-payment exposure?
- Does our cover treat an AI-impersonation or deepfake instruction the same way as a classic phishing instruction?
- Are all three wordings documented somewhere we can read the insuring clauses and sub-limits at a glance?
Related Information
- Fidelity Guarantee and Commercial Crime: Loss-Discovered vs Loss-Sustained Trigger Decision Framework
- How to File a Fidelity Guarantee Claim: Employee Dishonesty
- Deepfake Funds-Transfer Fraud: Cyber, Crime, and Social Engineering Insurance
- First 24 Hours After a Major Employee Fraud Discovery: A Singapore SME Crisis Playbook
- Internal Fraud Discovered: The 8-Step Day-One Workflow for Singapore SMEs
- Business Email Compromise / Vendor Email Compromise: Wire Fraud Discovered
- Standalone Cyber Insurance vs Cyber Sub-Limit Under PAR: What's the Difference?
Published 31 May 2026. Source verified 31 May 2026. COVA is an introducer under MAS Notice FAA-N02. We do not recommend insurance products. We provide factual information sourced from primary regulators and route you to a licensed IFA who can match a policy to your specific situation.

