
August 19, 2026
ExplainersHOA Fidelity Bond Requirements: How to Size the Bond in 2026
How HOA fidelity bond requirements are set by Fannie Mae, Freddie Mac, FHA, and state law, plus how to calculate the right coverage amount.
10 min read


Manage your risk with Coverwatch
Get a free coverage review and find out where you are over or under insured.
Business email compromise cost victims $3.05 billion in losses reported to the FBI in 2025. HOA social engineering fraud insurance pays when an impostor tricks your manager into wiring money, if the crime policy lists that insuring agreement (the clause naming one covered loss). Fidelity and computer fraud wording usually won't respond, so we cover which agreement applies, whose account paid, and which steps keep the claim payable.
Only if the policy includes social engineering or fraudulent impersonation coverage. A fake vendor email that convinces an authorized person to send a wire produces a voluntary payment. Standard crime wording places that payment outside both employee theft and computer fraud. So check the declarations page, the summary sheet listing each coverage and its limit, because the deciding line is either printed there or missing.
The numbers explain why insurers split this risk out. The FBI's Internet Crime Complaint Center (IC3) logged 24,768 business email compromise complaints in its 2025 annual report, second only to investment fraud by dollar loss.
An association's crime policy usually starts with fidelity coverage for insider theft. Our fidelity guide explains who requires a fidelity bond and at what limit. Outsider fraud sits in other insuring agreements, and HOA wire fraud coverage exists only where the policy lists one by name.
The funds transfer fraud vs social engineering split turns on who gave the instruction. Funds transfer fraud coverage answers a fake instruction sent straight to your bank by someone outside the association, without anyone inside knowing. Social engineering covers your own person being tricked. A spoofed board-president email to your manager belongs there.
| Insuring agreement | Who moves the money | Fits a spoofed-president wire? |
|---|---|---|
| Computer fraud | A fraudulent entry or change in a computer system causes the transfer | Rarely; courts split when an employee sends the wire |
| Funds transfer fraud | Your bank, acting on an instruction that only appears to come from you | Rarely under ISO wording; your own person sent the instruction |
| Fraudulent impersonation or social engineering | Your own person, acting in good faith on an impostor's instruction | Yes, up to its own limit and conditions |
The 2015 crime forms from the Insurance Services Office (ISO) define a "fraudulent instruction" as one "fraudulently issued by someone else without your knowledge or consent" and pay funds transfer claims only for that kind. The government edition then adds an exclusion to its combined computer and funds transfer agreement. It removes loss from an "employee" acting upon any instruction that "proves to be fraudulent" unless the funds transfer provision covers it. Ohio's state risk office publishes the government edition of this ISO crime form with the same language.
The premises and in-transit theft agreements carry the voluntary parting exclusion. It removes loss when anyone acting for you is "induced by any dishonest act to voluntarily part with" property. Social engineering coverage exists to pay that loss back, which is why it's sold separately.
Courts have read older computer fraud and funds transfer wording both ways. In the 2016 Apache case, the Fifth Circuit called a fraudulent email "merely incidental" to an authorized payment and denied coverage. Six years later the Ninth Circuit revived a management company's computer fraud and funds transfer fraud claims on spoofed-email wires in the Ernst & Haas decision. Waiting out an appeal is a poor plan, so buy the named agreement.
Only up to its own limit, which can sit far below the crime limit your lender sees. Each insuring agreement carries a separate limit on the declarations page. A social engineering line can be written as a sublimit, a smaller cap inside the overall policy limit.
| Coverage | How the limit is set | What to check |
|---|---|---|
| Fidelity (employee theft) | The main crime limit, sized to lender or statute formulas | Matches the funds in custody |
| Computer and funds transfer fraud | Its own line on the declarations | A dollar limit appears on that line |
| Fraudulent impersonation or social engineering | Optional, with its own limit line | Limit, deductible, and verification condition |
| Cyber policy add-on | Separate cyber limit, which may apply excess over crime | Which policy pays first |
ISO's 2022 forms turned fraudulent impersonation into an optional insuring agreement inside the crime form, according to the International Risk Management Institute (IRMI). That agreement replaced the 2015-era endorsement (a form that adds or changes coverage). Some insurers still sell it as a social engineering fraud endorsement. Cyber policies offer versions too, and IRMI's glossary says those are "typically limited to $100,000" and apply only as excess over any commercial crime policy.
The Fannie Mae fidelity limit calculation sizes protection against people who handle funds. Surprisingly, it says nothing about impostors, so a board can satisfy its lender and still carry a thin limit for this loss.
For example, take a 150-unit association with a $500,000 crime limit, a $50,000 social engineering sublimit, and a $5,000 deductible. A spoofed "president" email asks the manager to wire a $120,000 roofing deposit to a new account. If the claim meets every condition, the policy would pay $50,000, leaving $70,000 that the association must cover from operating funds or reserves.
When management firm staff send a social engineering wire, the association's crime policy might not respond. ISO's employee definition leaves out independent contractors, and its funds transfer fraud agreement reaches only a "transfer account" the insured maintains. Look at the firm's crime policy first.
ISO defines a transfer account as "an account maintained by you at a 'financial institution'" that you can transfer from. Its employee definition excludes "any agent, independent contractor or representative of the same general character" not specified. A management company is an outside firm, though ISO's designated agents endorsement (CR 25 02) can treat its staff as employees for employee theft. That doesn't by itself extend social engineering coverage to them.
Whose account sent the wire matters. When the association's own account pays, its policy can respond if the impostor fooled someone the policy covers. A firm trust account may point the claim at the manager's policy. In Ernst & Haas, the management company claimed on its own crime policy after its clerk wired $200,000 on spoofed emails.
Put the answer in the management agreement. It should say which party carries social engineering coverage, who verifies payment changes, and who repays a loss. For the policy side, read about naming the management company as an insured, and see insurance for community association managers for the firm's own program.
Verify every new payment request or bank-detail change by calling a number already on file, never one in the email, and record that call before money moves. ISO's fraudulent impersonation wording requires a reasonable attempt to verify the request. Some insurers add stricter written conditions, so don't assume a quick reply email counts.
An IC3 public service announcement tells businesses to use "previously known numbers, not the numbers provided in the e-mail request" when they confirm transfers by phone. Apache shows the cost of skipping that step. Its staff called the number printed on the fraudulent letter and reached the criminals.
The written procedure should match the policy's verification condition word for word, because an adjuster will compare the two after a loss. Coverwatch compares the verification condition on the crime form with the manager's payment procedure and flags gaps before renewal, along with the rest of the HOA insurance program.
After an HOA social engineering wire fraud loss, call the bank and request a recall, file at ic3.gov with full transaction details, and give the crime insurer written notice. Hours count here. In 2025 the IC3's Financial Fraud Kill Chain froze $679 million across 3,900 incidents, a 58% success rate, according to the same report.
"If you discover a fraudulent transfer, time is of the essence," the report warns. It also tells victims to file a complaint "regardless of the amount lost" with the IC3. ISO crime forms also require notice to the insurer as soon as possible and a sworn proof of loss within 120 days.
Owners may later question the board's controls, and that complaint can become a breach of fiduciary duty claim. Directors and officers (D&O) coverage handles that claim, not the crime policy.
The master property and general liability policies are not built for it. The crime policy can respond, but only through the agreement that matches how the money left. A wire your manager sent on a spoofed request needs <strong>fraudulent impersonation</strong> or social engineering coverage. A transfer your bank made on an instruction nobody at the association gave falls under funds transfer fraud.
It's a crime insuring agreement or endorsement that pays when someone acting for the association is deceived into sending money to an impostor. It writes back the loss that the voluntary parting exclusion and fraudulent instruction wording remove. It usually carries its own limit and a condition requiring verification before the transfer.
Sometimes, by endorsement. The International Risk Management Institute (IRMI) describes cyber social engineering endorsements as typically limited to $100,000 and applying only as excess over any commercial crime policy. If the association carries both, ask which policy pays first so the two limits work together.
Usually not. Under <a href="https://www.law.cornell.edu/ucc/4A/4A-202">Uniform Commercial Code (UCC) Section 4A-202</a>, a payment order is the customer's authorized order if the customer authorized it or is bound by it under agency law. A recall request can still recover money that has not left the receiving account, which is why the first call to the bank matters.

August 19, 2026
ExplainersHow HOA fidelity bond requirements are set by Fannie Mae, Freddie Mac, FHA, and state law, plus how to calculate the right coverage amount.
10 min read

October 7, 2026
How-ToHow to calculate the fidelity limit Fannie Mae, Freddie Mac, and FHA require, with the controls exception, reserves, and a worked 140-unit example.
8 min read

July 11, 2026
ExplainersWhat fidelity and crime coverage an HOA needs, how much under the Fannie and state formulas, who must be covered, and how a claim pays.
10 min read

October 7, 2026
ExplainersFannie Mae condo reserve requirements rise from 10% to 15% of assessment income for 2027 loan applications. The math, the dates, and the insurance angle.
7 min read
Fill out the form and a Coverwatch advisor will get back to you within the next hour.
Your quote