Nearly every business in a Southeast small town buys the same architecture: a package policy, a workers' comp policy, an auto policy, an umbrella. A community bank does not. Its program is built around a financial institution bond, with a management liability tower and a technology tower bolted to it, and property is almost an afterthought until a hurricane makes it one.
That structural difference is why bank insurance goes wrong in a specific way. The losses do not usually fall inside a policy that failed. They fall in the seams between three separate towers that were bought at different times, from different carriers, on different renewal dates, by different people.
The Southeast still has real community banks — single-charter institutions in Claxton, Statesboro, Vidalia, Waynesboro, Dublin, Evans, and a hundred towns like them, holding local deposits and lending against local dirt. They are small enough that the insurance program is often handled alongside everything else and large enough that a single coverage gap is a board-level event.
They also sit at an awkward size for the market. Too specialized for a generalist agent, too small to command a dedicated financial-institutions team at a national broker. The result is a program that renews on autopilot, with limits set years ago and a bond schedule nobody has re-read since the last examination.
| Coverage | What it answers for | Characteristic failure |
|---|---|---|
| Financial institution bond | The bank's own money and securities — employee dishonesty, in-transit, forgery, counterfeit | Insuring agreements left off the schedule years ago and never revisited |
| Directors & officers liability | Claims against the board and management, including by regulators and shareholders | Insured-vs-insured exclusion with no receiver carve-back |
| Bankers professional liability | Customer claims arising from lending, deposit and account services | Retro date reset at a carrier change, erasing prior years |
| Cyber & privacy | Breach response, network interruption, regulatory defense, extortion | Bought as a small endorsement, sized for a dentist's office |
| Social engineering / fraudulent instruction | The authorized-but-deceived wire transfer | Sublimit far below the exposure — or the grant is simply absent |
| Employment practices liability | Wrongful termination, discrimination, harassment claims | Third-party (customer) coverage missing at a public-facing business |
| Fiduciary & trust E&O | The bank's own benefit plans; separately, trust administration for customers | The two are confused; trust activity assumed to sit in the professional form |
| Property, BI & equipment breakdown | Branches, ATMs, vault, operations center, alternate-site operating cost | Percentage named-storm deductible nobody has translated into dollars |
This is the section worth the page.
A financial institution bond is not a surety bond despite the name, and there is no third party guaranteeing anything. It is first-party insurance on the institution's own money and securities. The nearest general-business equivalent is a commercial crime policy, but the bank form is built around perils an ordinary crime form either treats differently or never contemplated: in-transit and armored carrier loss, forged and altered instruments, counterfeit securities and currency, and in some forms loan loss arising from employee dishonesty.
Four mechanics decide what it actually does:
If you read one endorsement in the whole program, read the exclusions on the directors and officers form.
Financial institution D&O commonly carries a regulatory exclusion and an insured-versus-insured exclusion. The second one was written for a sensible reason — to stop collusive suits between a company and its own officers. But when a regulator or receiver steps into the institution's shoes and sues former directors, a broadly worded insured-versus-insured exclusion can be read to remove precisely the claim the directors most needed covered.
Three questions, on the form as issued:
The bond covers your money. Bankers professional liability covers claims made against you by customers arising out of banking services: lending and loan servicing, deposit account administration, wire and payment services, escrow, and customer account handling generally.
Lender liability is the subset that produces most community bank claims — allegations around loan commitments, workout conduct, foreclosure handling, collateral treatment, and breach of an alleged duty of good faith. It arrives most often in the same season the loan portfolio does badly, which is also the season the D&O tower gets tested. Those two events correlate, and a program built as though they are independent is under-limited.
These forms are almost always claims-made. Three consequences follow, and they are the same ones that catch every claims-made buyer:
Confirm also whether trust activity is inside the professional form or needs separate trust E&O. If the bank exercises trust powers, this is not a detail. And keep it distinct from fiduciary liability, which protects the bank as sponsor of its own retirement plan — a completely different exposure that shares a confusing vocabulary. The general structure of professional forms is covered on our E&O page.
Here is the loss shape that has hurt community institutions most in recent years, and the reason it is hard to insure.
Traditional bond and crime language responds to computer fraud or funds transfer fraud — an unauthorized party manipulating a system. A social engineering loss looks nothing like that. An authorized employee, holding an entirely convincing fraudulent instruction, performs a completely authorized transfer. Every step is authorized. Several older forms therefore do not respond at all.
What fixes it is a specific social engineering fraud or fraudulent instruction insuring agreement, and there are three things to read on it, in this order:
Also settle in writing whether the policy answers for the bank's own loss or a customer's loss the bank chooses to make good. They are different questions and community banks frequently face the second one first, for relationship reasons, before anyone has checked whether it is insured. Full treatment on our social engineering and wire transfer fraud page.
Sitting beside it, cyber and privacy coverage at a bank is not the small endorsement a generalist would attach. It needs breach response, network interruption for a core-processing outage, regulatory defense, extortion, and — the one most often missing — dependent business interruption reaching the core processor and any fintech partner, because the outage that stops a community bank is usually somebody else's outage.
Banks tend to treat property as the boring part of the program. In Georgia, South Carolina and Florida it is not.
Portions of a bank program — particularly cyber and some professional layers — frequently place on a non-admitted basis. That is normal in this class and not a downgrade, but it means the forms are not standardized and must be read as issued rather than assumed.
Bettr Coverage is an independent commercial insurance agency serving Georgia and the wider Southeast. A community bank is one of the few accounts where the program's architecture — three towers with different carriers, dates and forms — is itself the risk. On a review we read the bond's schedule of insuring agreements against the operation as it runs today, read the D&O regulatory and insured-versus-insured exclusions for carve-backs and check whether Side A DIC is in place, confirm the professional form's retroactive date and whether trust activity is inside it, find whether a social engineering grant exists and translate the sublimit into a realistic wire, size cyber for a core-processing dependency rather than an office, and convert every named-storm deductible on the branch schedule into dollars. One agency, one relationship, all of it read together. For agency-level context, see how we work in the Statesboro and Savannah area.
Send the bond with its schedule of insuring agreements, the D&O policy with endorsements, and the branch statement of values. We'll tell you which insuring agreements are missing, whether the insured-versus-insured exclusion has a receiver carve-back, whether a social engineering grant exists and what its sublimit really is, and what each named-storm deductible costs in dollars.
Get a free coverage reviewA financial institution bond at the center, plus D&O, bankers professional liability including lender liability, cyber and privacy with a social engineering grant, EPLI, fiduciary liability for the bank's own plans and trust E&O if trust powers are exercised, property with business income and equipment breakdown across the branch network, commercial auto, workers' comp, and excess layers over the specific towers that need them.
It is not a surety bond and involves no third-party guarantee — it is first-party insurance on the bank's own money and securities. Compared with a commercial crime form it adds banking-specific perils: in-transit and armored carrier loss, forged and altered instruments, counterfeit securities and currency. Read the schedule of insuring agreements: a bond is a menu, and what is absent from the schedule is absent from the coverage.
It turns on two exclusions. A regulatory or receiver exclusion may remove it outright, and a broadly worded insured-versus-insured exclusion can be read to remove a claim brought by a receiver standing in the institution's shoes. Look for a receiver carve-back and for Side A difference-in-conditions coverage, which pays individual directors directly when the institution cannot or will not indemnify them.
Coverage for customer and third-party claims arising from banking services — lending and servicing, deposit administration, wire and payment services, escrow and account handling. Lender liability is the subset that drives most community bank claims. The bond does not cover any of it: the bond covers your money, the professional form covers claims against you. It is almost always claims-made, so the retroactive date matters at every carrier change.
Only with a specific social engineering or fraudulent instruction grant. Traditional computer fraud and funds transfer fraud language contemplates an unauthorized party manipulating a system; in a social engineering loss the employee is authorized and the transfer is authorized, so older forms may not respond. Check three things: whether the grant exists, the sublimit, and what callback verification the condition requires.
Percentage-based named-storm deductibles that scale with insured value, flood excluded from the property form and needing separate placement, the operations center insured as ordinary contents rather than as a critical technology asset, business income sized to rebuild a building instead of restoring operations at an alternate site, and statements of values that drift out of date after remodels.
Call reports and audited financials, loan concentrations with CRE and participations identified, past-due and non-accrual trends, internal and external audit results with responses, regulatory posture, board composition, trust assets if applicable, dual control documentation, written wire callback procedures, vendor management for core processing and fintech partners, tested incident response and continuity plans, the information security program, a branch schedule with values and distance to coast, and full loss history including losses absorbed below retention.
For general information only. Not legal advice, not accounting or regulatory advice, and not a quote or contract of insurance. Policy forms, insuring agreements, endorsements, sublimits and exclusions vary by carrier and form edition — financial institution bond insuring agreement schedules, manifest intent and single-loss deductible provisions, discovery and notice conditions, directors and officers regulatory and insured-versus-insured exclusions and any carve-backs, Side A difference-in-conditions terms, claims-made retroactive dates and extended reporting provisions, trust errors and omissions scope, social engineering and fraudulent instruction grants with their sublimits and verification conditions, dependent business interruption scope, and named-storm deductible calculations must all be read as actually issued. Banking, flood insurance and public-deposit collateralization requirements are set by federal and state authority and are amended; confirm your institution's obligations with the relevant agency, your examiners and qualified counsel. Coverage subject to policy terms, conditions, exclusions and carrier appetite.