We’ve written before about mapping a client-fund fraud loss across cyber, crime and social-engineering forms. That review assumes the firm is asking the right question: what happened to the money. There’s a second claim hiding behind the first one — what the client says the firm should have done to stop it.
A client whose closing or settlement funds get wire-fraud rerouted doesn’t just have a stolen-money problem. Once the funds are gone, the client’s next move is often a negligence claim against the firm itself: you had the money, you had the instructions, why didn’t you catch it. That claim doesn’t go to the crime policy. It goes to professional liability — and whether it’s covered there is not automatic.
Two real rulings show how differently this goes
In one case, the Eleventh Circuit reversed a summary judgment for an E&O insurer and held that a law firm’s management of client funds held in trust is itself a “professional service” — meaning a malpractice claim over how those funds were handled falls within the professional liability policy’s scope, even though a fraudster caused the underlying loss.
In another, a federal court in Florida reached the opposite result on the same basic fact pattern. In Harrington Law Associates v. Landmark American Insurance Co., a firm was sued for negligence after a fraudster’s fake wire instructions diverted $511,500 in client closing funds. The court upheld the insurer’s denial: the E&O policy’s theft exclusion barred any claim “arising out of theft” by “any person” — not just the insured — and since the negligence claim was inseparable from the fraudster’s theft, the exclusion applied anyway.
Same fact pattern. Same type of claim. Opposite outcome, because the two policies used different theft-exclusion language.
What actually decides it
The line between “this is a crime claim” and “this is an E&O claim” runs through two things in the specific policy form, not through the general shape of the loss:
- Whether the E&O form’s theft or dishonesty exclusion is written broadly enough to catch a third party’s fraud, or narrowly enough to only exclude the insured’s own theft
- Whether managing client trust or escrow funds is treated, in that policy and that jurisdiction, as part of the “professional services” the E&O form actually covers
A crime or cyber policy paying the stolen-funds claim doesn’t resolve the second claim — the client’s negligence allegation against the firm — if the E&O form excludes it. And an E&O form that would otherwise respond to the negligence claim doesn’t help if the theft exclusion is written the way it was in Harrington.
The submission needs to show which client-money workflows exist (trust, escrow, settlement, general operating), what the firm’s engagement letter or retainer actually promises about safeguarding funds, and — before binding — the exact theft-exclusion language in whatever E&O form is being quoted. That last part is not a detail to check after a claim. It’s the fact that decided both cases above.
A firm that needs a narrower theft exclusion than its admitted E&O market will offer is often headed to E&S for exactly that reason — the same diligent search documentation applies once admitted options are exhausted on the specific wording the firm actually needs.