Business and financial profile

Does the organization send and/or receive wire transfers?

A yes here opens the funds transfer fraud conversation, including the conditions that cover usually carries.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether the organisation sends or receives wire transfers, and often the volume and typical value. It determines whether funds transfer fraud cover is relevant and how it should be structured.

Why it is underwritten

Funds transfer fraud is the highest-frequency cyber claim. Carriers price the cover against transfer activity and commonly condition it on verification procedures, which is why this question and the dual authorisation question are read together.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Transfer activity comes from finance records, and the controls around it are what the carrier is really assessing.

PlatformWhere the setting livesWhat has to be true
FinanceTransfer volume and typical and maximum valuesFigures that support an appropriate sub-limit. Attested
FinanceAuthorisation controls in the banking platformDual authorisation enforced by the platform above a threshold
FinanceCallback verification procedure for new or changed detailsVerification to a number already on file, applied without exception
BankingAccess to banking platforms and its authenticationMulti-factor on every banking credential, ideally on a dedicated device
Microsoft 365Protection of finance mailboxesForwarding blocked, impersonation protection configured, and external tagging enabled
Cover is often conditioned on the procedure

Funds transfer fraud cover frequently requires that verification procedures were followed. A loss that occurred because someone skipped the callback under time pressure may fall outside cover. That makes the procedure both a control and a coverage condition, which is worth telling the finance team explicitly.

What a defensible yes requires

  • Transfer activity is quantified so the sub-limit is appropriate.
  • Dual authorisation is enforced by the banking platform.
  • Callback verification is unconditional.
  • Banking access requires strong multi-factor, ideally from a dedicated device.
  • Finance mailboxes are hardened against forwarding and impersonation.

How this answer goes wrong

The answer is yes and the procedures described are policy rather than platform-enforced, so a determined social engineering attempt under urgency succeeds. The subsequent claim then turns on whether the verification condition in the policy was met.

Frequently asked

Is funds transfer fraud covered automatically?

Usually as a sub-limited extension rather than at the full policy limit, and frequently with conditions. Read the sub-limit against your typical transfer value.

What sub-limit should we buy?

At least the largest single transfer you would make, and preferably more. The common shortfall is a sub-limit far below the transfer sizes the business routinely handles.

Does this cover client funds?

Depends on the wording. If you hold or move client money, raise it explicitly, because the cover may not extend there.

What if we only receive transfers?

Lower exposure and not zero. Attackers impersonate you to redirect incoming payments, which harms your customers and your relationship with them.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture