Does the organization send and/or receive wire transfers?
A yes here opens the funds transfer fraud conversation, including the conditions that cover usually carries.
What the carrier is actually asking
The carrier is asking whether the organisation sends or receives wire transfers, and often the volume and typical value. It determines whether funds transfer fraud cover is relevant and how it should be structured.
Why it is underwritten
Funds transfer fraud is the highest-frequency cyber claim. Carriers price the cover against transfer activity and commonly condition it on verification procedures, which is why this question and the dual authorisation question are read together.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Transfer activity comes from finance records, and the controls around it are what the carrier is really assessing.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Finance | Transfer volume and typical and maximum values | Figures that support an appropriate sub-limit. Attested |
| Finance | Authorisation controls in the banking platform | Dual authorisation enforced by the platform above a threshold |
| Finance | Callback verification procedure for new or changed details | Verification to a number already on file, applied without exception |
| Banking | Access to banking platforms and its authentication | Multi-factor on every banking credential, ideally on a dedicated device |
| Microsoft 365 | Protection of finance mailboxes | Forwarding blocked, impersonation protection configured, and external tagging enabled |
Funds transfer fraud cover frequently requires that verification procedures were followed. A loss that occurred because someone skipped the callback under time pressure may fall outside cover. That makes the procedure both a control and a coverage condition, which is worth telling the finance team explicitly.
What a defensible yes requires
- Transfer activity is quantified so the sub-limit is appropriate.
- Dual authorisation is enforced by the banking platform.
- Callback verification is unconditional.
- Banking access requires strong multi-factor, ideally from a dedicated device.
- Finance mailboxes are hardened against forwarding and impersonation.
How this answer goes wrong
The answer is yes and the procedures described are policy rather than platform-enforced, so a determined social engineering attempt under urgency succeeds. The subsequent claim then turns on whether the verification condition in the policy was met.
Frequently asked
Is funds transfer fraud covered automatically?
Usually as a sub-limited extension rather than at the full policy limit, and frequently with conditions. Read the sub-limit against your typical transfer value.
What sub-limit should we buy?
At least the largest single transfer you would make, and preferably more. The common shortfall is a sub-limit far below the transfer sizes the business routinely handles.
Does this cover client funds?
Depends on the wording. If you hold or move client money, raise it explicitly, because the cover may not extend there.
What if we only receive transfers?
Lower exposure and not zero. Attackers impersonate you to redirect incoming payments, which harms your customers and your relationship with them.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture