Community Bank Insurance: The Program Is a Bond, Not a Package

By Winfield Lee, Licensed Independent Insurance Agent · Serving Georgia & the Southeast · Updated 2026

Short answer

Nearly every business in a Southeast small town buys the same architecture: a package policy, a workers' comp policy, an auto policy, an umbrella. A community bank does not. Its program is built around a financial institution bond, with a management liability tower and a technology tower bolted to it, and property is almost an afterthought until a hurricane makes it one.

That structural difference is why bank insurance goes wrong in a specific way. The losses do not usually fall inside a policy that failed. They fall in the seams between three separate towers that were bought at different times, from different carriers, on different renewal dates, by different people.

The one-line version: A bank's largest realistic uninsured loss is not a robbery. It is a wire that an authorized employee sent because a convincing email told him to, or a claim against former directors that an insured-versus-insured exclusion removed. Both are form-reading problems, not price problems.

Why this page exists

The Southeast still has real community banks — single-charter institutions in Claxton, Statesboro, Vidalia, Waynesboro, Dublin, Evans, and a hundred towns like them, holding local deposits and lending against local dirt. They are small enough that the insurance program is often handled alongside everything else and large enough that a single coverage gap is a board-level event.

They also sit at an awkward size for the market. Too specialized for a generalist agent, too small to command a dedicated financial-institutions team at a national broker. The result is a program that renews on autopilot, with limits set years ago and a bond schedule nobody has re-read since the last examination.

The program: what answers for what

CoverageWhat it answers forCharacteristic failure
Financial institution bondThe bank's own money and securities — employee dishonesty, in-transit, forgery, counterfeitInsuring agreements left off the schedule years ago and never revisited
Directors & officers liabilityClaims against the board and management, including by regulators and shareholdersInsured-vs-insured exclusion with no receiver carve-back
Bankers professional liabilityCustomer claims arising from lending, deposit and account servicesRetro date reset at a carrier change, erasing prior years
Cyber & privacyBreach response, network interruption, regulatory defense, extortionBought as a small endorsement, sized for a dentist's office
Social engineering / fraudulent instructionThe authorized-but-deceived wire transferSublimit far below the exposure — or the grant is simply absent
Employment practices liabilityWrongful termination, discrimination, harassment claimsThird-party (customer) coverage missing at a public-facing business
Fiduciary & trust E&OThe bank's own benefit plans; separately, trust administration for customersThe two are confused; trust activity assumed to sit in the professional form
Property, BI & equipment breakdownBranches, ATMs, vault, operations center, alternate-site operating costPercentage named-storm deductible nobody has translated into dollars

The bond, read properly

This is the section worth the page.

A financial institution bond is not a surety bond despite the name, and there is no third party guaranteeing anything. It is first-party insurance on the institution's own money and securities. The nearest general-business equivalent is a commercial crime policy, but the bank form is built around perils an ordinary crime form either treats differently or never contemplated: in-transit and armored carrier loss, forged and altered instruments, counterfeit securities and currency, and in some forms loan loss arising from employee dishonesty.

Four mechanics decide what it actually does:

D&O and the two exclusions that decide it

If you read one endorsement in the whole program, read the exclusions on the directors and officers form.

Financial institution D&O commonly carries a regulatory exclusion and an insured-versus-insured exclusion. The second one was written for a sensible reason — to stop collusive suits between a company and its own officers. But when a regulator or receiver steps into the institution's shoes and sues former directors, a broadly worded insured-versus-insured exclusion can be read to remove precisely the claim the directors most needed covered.

Three questions, on the form as issued:

  1. Is there a regulatory or receiver exclusion — and if so, is there a carve-back?
  2. Does the insured-versus-insured exclusion carve out claims brought by a receiver, conservator, liquidator or regulator acting in the institution's name?
  3. Is there Side A difference-in-conditions coverage protecting individual directors when the institution cannot or will not indemnify them — which is exactly the condition a troubled institution creates?
Why directors ask about Side A specifically. Ordinary D&O reimburses the institution for indemnifying its directors. If the institution is insolvent, under an agreement, or simply refuses, that reimbursement path is worth nothing to the individual. Side A DIC pays the director directly and typically cannot be exhausted by the entity's own claims. On a small board of local business owners with personal balance sheets, that distinction is the entire reason anyone agrees to serve.

Bankers professional liability — and why the bond does not cover it

The bond covers your money. Bankers professional liability covers claims made against you by customers arising out of banking services: lending and loan servicing, deposit account administration, wire and payment services, escrow, and customer account handling generally.

Lender liability is the subset that produces most community bank claims — allegations around loan commitments, workout conduct, foreclosure handling, collateral treatment, and breach of an alleged duty of good faith. It arrives most often in the same season the loan portfolio does badly, which is also the season the D&O tower gets tested. Those two events correlate, and a program built as though they are independent is under-limited.

These forms are almost always claims-made. Three consequences follow, and they are the same ones that catch every claims-made buyer:

Confirm also whether trust activity is inside the professional form or needs separate trust E&O. If the bank exercises trust powers, this is not a detail. And keep it distinct from fiduciary liability, which protects the bank as sponsor of its own retirement plan — a completely different exposure that shares a confusing vocabulary. The general structure of professional forms is covered on our E&O page.

The wire that was authorized

Here is the loss shape that has hurt community institutions most in recent years, and the reason it is hard to insure.

Traditional bond and crime language responds to computer fraud or funds transfer fraud — an unauthorized party manipulating a system. A social engineering loss looks nothing like that. An authorized employee, holding an entirely convincing fraudulent instruction, performs a completely authorized transfer. Every step is authorized. Several older forms therefore do not respond at all.

What fixes it is a specific social engineering fraud or fraudulent instruction insuring agreement, and there are three things to read on it, in this order:

  1. Does the grant exist? Not "do we have crime coverage" — does this specific agreement appear on the schedule.
  2. What is the sublimit? It is routinely a small fraction of the policy limit, and routinely a small fraction of a realistic wire.
  3. What verification does the condition require? Callback verification to a previously known number is a common condition precedent. Failing to document it is a coverage defense even where the grant is present.

Also settle in writing whether the policy answers for the bank's own loss or a customer's loss the bank chooses to make good. They are different questions and community banks frequently face the second one first, for relationship reasons, before anyone has checked whether it is insured. Full treatment on our social engineering and wire transfer fraud page.

Sitting beside it, cyber and privacy coverage at a bank is not the small endorsement a generalist would attach. It needs breach response, network interruption for a core-processing outage, regulatory defense, extortion, and — the one most often missing — dependent business interruption reaching the core processor and any fintech partner, because the outage that stops a community bank is usually somebody else's outage.

Property: a branch network is a coastal portfolio

Banks tend to treat property as the boring part of the program. In Georgia, South Carolina and Florida it is not.

The rest of the program

What a good community bank submission contains

  1. Recent call reports and audited financial statements; total assets and growth trend.
  2. Loan portfolio by concentration, with commercial real estate concentration and any participations identified.
  3. Past-due and non-accrual trends, and allowance methodology.
  4. Most recent internal and external audit results with management responses.
  5. General regulatory examination posture, and whether any formal or informal agreement is in place.
  6. Board composition and independence; director questionnaires where required.
  7. Trust assets under administration, if trust powers are exercised.
  8. Dual control and segregation of duties documentation.
  9. Wire transfer procedures, including callback verification, in writing.
  10. Vendor management for core processing and any fintech or third-party relationship.
  11. Incident response and business continuity plans, with the date last tested.
  12. Information security program — multifactor authentication, endpoint protection, backup and recovery.
  13. Branch schedule with values, construction, protection class and distance to coast.
  14. Full claim and loss history, including losses absorbed below the retention.

Portions of a bank program — particularly cyber and some professional layers — frequently place on a non-admitted basis. That is normal in this class and not a downgrade, but it means the forms are not standardized and must be read as issued rather than assumed.

A five-minute check: Pull three documents — the bond's schedule of insuring agreements, the D&O insured-versus-insured exclusion, and the crime or cyber schedule where a social engineering sublimit would appear. If any insuring agreement is missing from the first, if the second has no receiver carve-back, or if the third shows no fraudulent-instruction grant, you have found the program's real exposure without reading a single page of premium.

Where Bettr Coverage fits

Bettr Coverage is an independent commercial insurance agency serving Georgia and the wider Southeast. A community bank is one of the few accounts where the program's architecture — three towers with different carriers, dates and forms — is itself the risk. On a review we read the bond's schedule of insuring agreements against the operation as it runs today, read the D&O regulatory and insured-versus-insured exclusions for carve-backs and check whether Side A DIC is in place, confirm the professional form's retroactive date and whether trust activity is inside it, find whether a social engineering grant exists and translate the sublimit into a realistic wire, size cyber for a core-processing dependency rather than an office, and convert every named-storm deductible on the branch schedule into dollars. One agency, one relationship, all of it read together. For agency-level context, see how we work in the Statesboro and Savannah area.

Does your bond schedule still match how the bank runs?

Send the bond with its schedule of insuring agreements, the D&O policy with endorsements, and the branch statement of values. We'll tell you which insuring agreements are missing, whether the insured-versus-insured exclusion has a receiver carve-back, whether a social engineering grant exists and what its sublimit really is, and what each named-storm deductible costs in dollars.

Get a free coverage review

Common questions about community bank insurance

What insurance does a community bank need?

A financial institution bond at the center, plus D&O, bankers professional liability including lender liability, cyber and privacy with a social engineering grant, EPLI, fiduciary liability for the bank's own plans and trust E&O if trust powers are exercised, property with business income and equipment breakdown across the branch network, commercial auto, workers' comp, and excess layers over the specific towers that need them.

How is a financial institution bond different from a crime policy?

It is not a surety bond and involves no third-party guarantee — it is first-party insurance on the bank's own money and securities. Compared with a commercial crime form it adds banking-specific perils: in-transit and armored carrier loss, forged and altered instruments, counterfeit securities and currency. Read the schedule of insuring agreements: a bond is a menu, and what is absent from the schedule is absent from the coverage.

Does D&O cover a regulatory action against former directors?

It turns on two exclusions. A regulatory or receiver exclusion may remove it outright, and a broadly worded insured-versus-insured exclusion can be read to remove a claim brought by a receiver standing in the institution's shoes. Look for a receiver carve-back and for Side A difference-in-conditions coverage, which pays individual directors directly when the institution cannot or will not indemnify them.

What is bankers professional liability?

Coverage for customer and third-party claims arising from banking services — lending and servicing, deposit administration, wire and payment services, escrow and account handling. Lender liability is the subset that drives most community bank claims. The bond does not cover any of it: the bond covers your money, the professional form covers claims against you. It is almost always claims-made, so the retroactive date matters at every carrier change.

Does insurance cover a wire sent because of a fraudulent email?

Only with a specific social engineering or fraudulent instruction grant. Traditional computer fraud and funds transfer fraud language contemplates an unauthorized party manipulating a system; in a social engineering loss the employee is authorized and the transfer is authorized, so older forms may not respond. Check three things: whether the grant exists, the sublimit, and what callback verification the condition requires.

What property issues matter most for a Southeast branch network?

Percentage-based named-storm deductibles that scale with insured value, flood excluded from the property form and needing separate placement, the operations center insured as ordinary contents rather than as a critical technology asset, business income sized to rebuild a building instead of restoring operations at an alternate site, and statements of values that drift out of date after remodels.

What do underwriters want from a community bank?

Call reports and audited financials, loan concentrations with CRE and participations identified, past-due and non-accrual trends, internal and external audit results with responses, regulatory posture, board composition, trust assets if applicable, dual control documentation, written wire callback procedures, vendor management for core processing and fintech partners, tested incident response and continuity plans, the information security program, a branch schedule with values and distance to coast, and full loss history including losses absorbed below retention.

For general information only. Not legal advice, not accounting or regulatory advice, and not a quote or contract of insurance. Policy forms, insuring agreements, endorsements, sublimits and exclusions vary by carrier and form edition — financial institution bond insuring agreement schedules, manifest intent and single-loss deductible provisions, discovery and notice conditions, directors and officers regulatory and insured-versus-insured exclusions and any carve-backs, Side A difference-in-conditions terms, claims-made retroactive dates and extended reporting provisions, trust errors and omissions scope, social engineering and fraudulent instruction grants with their sublimits and verification conditions, dependent business interruption scope, and named-storm deductible calculations must all be read as actually issued. Banking, flood insurance and public-deposit collateralization requirements are set by federal and state authority and are amended; confirm your institution's obligations with the relevant agency, your examiners and qualified counsel. Coverage subject to policy terms, conditions, exclusions and carrier appetite.