Before Your Next Renewal

When was the last time anyone read the forms?

The CFO gets the continuation notice. Three policies: cyber, fidelity bond, D&O. The summary page compares this year’s premium to last year’s. Cyber up 4%. Bond is slightly down because of a clean loss year, D&O is flat.

All three policies are bundled to a program. ABA Insurance Services covers roughly a third of community banks; Travelers Select+ covers another large share. Most community banks I talk to carry at least part of their coverage through a program: multiple lines, one carrier family, and three-year policy term.

For this bank, the real renewal was two years ago. That’s when the broker went to market, got competing quotes, presented alternatives. This year is only an anniversary. A continuation notice and a premium adjustment. The broker’s summary: “No material changes to terms and conditions.” Board approves. Policies bind.

A few months later

A wire fraud hits the community bank. $400,000 is stolen. IT responds immediately, but the money is gone.

The CFO files a claim and is blindsided. The bond carrier pays $187,500 on a $400,000 loss.

Scenario outcome
Loss
$400,000
Bond recovery
$187,500
Bank absorbs
$212,500
Social engineering sublimit: $250,000 (frozen since placement).
Co-payment: 25% (added at last anniversary).

He finds out that the social engineering add-on had a sublimit of $250,000 (set when the program was placed initially, and never adjusted) and a 25% co-payment the carrier added at the last anniversary when it revised the form. The co-payment means the bank absorbs 25 cents of every dollar of loss. Both numbers were on the declarations page. The broker’s continuation notice focused on premium, not these “nuances.”

The CFO, frustrated, calls the broker. The broker’s honest answer: he placed the best terms at a competitive premium. Reading the bond line by line is a different job and wasn’t part of the engagement. On a three-year program, there hasn’t been a real renewal conversation in two years.

The three-year blind spot

Community banks don’t buy insurance policy by policy. They buy a program. Bond, D&O, cyber, bundled through a program administrator on a three-year term. ABA adds an association endorsement that satisfies examiners and a profit-sharing distribution that keeps banks renewing. Bundled pricing, simplified administration. The advantages are real.

Between renewals, nobody is watching.

A three-year term still means the carrier can revise its standard forms each year. Definitions can shift. Coverage on emerging risks like AI liability can be narrowed. When the carrier updates a program form, the new version applies to every bank on the program from the next anniversary onwards.

“No material changes” means the carrier didn’t overhaul the form. It doesn’t mean the bank’s operations, wire volume, or vendor relationships stayed the same. The form moved quietly at the anniversary. The bank moved loudly all year. Nobody reconciles the two until a loss falls through.

On an annual policy, the bank shops carriers every twelve months. On a three-year program, “we are on the program” satisfies boards and examiners without anyone asking whether the standard form fits this bank.

What the renewal process doesn’t catch

Three issues show up at many banks I have audited. They survive because nobody is looking for them.

Sublimits that stopped keeping pace

The aggregate limit on the cyber policy may get adjusted. The sublimits on specific coverages (e.g., social engineering, funds transfer fraud, dependent business interruption) stay frozen at whatever level they were set when the policy was first placed.

I have seen banks carrying $5 million in cyber aggregate where the dependent BI sublimit is $250,000. That’s a $5 million policy that pays $250,000 on the bank’s most likely operational loss.

The bond has the same problem. The headline limit might be $2 million, but social engineering is often capped at $250,000, with a co-payment and a verification requirement attached.

On a three-year program this compounds. Wire volume increased. The bank added digital banking, new vendors were onboarded. The sublimits stayed where they were three years ago.

The verification requirement

This is the one finding I flag for immediate action at every audit, regardless of where the bank stands in its policy term. It doesn't need to wait for renewal.

The bond’s social engineering add-on requires the bank to follow a specific callback procedure above a threshold (often $25,000). If the bank didn’t follow the steps exactly, the claim gets denied. This is a “condition precedent”: the carrier declines the claim, and doesn’t need to prove that the failure to follow the callback procedure caused the loss.

The bond requires a callback to a number the bank already has on file. The number in the wire instructions doesn’t count. Email doesn’t count.

Does the bank’s wire procedure exactly match what the bond requires? If not, fix it now. Don’t wait for renewal. The mismatch voids coverage regardless of where the bank stands in its policy term.

Policies point fingers at each other

Every policy has an “other insurance” clause and exclusions that reference the other policies’ territory. When a single event (ransomware, a data breach, a wire fraud) triggers multiple policies at once, carriers point at each other. The bank absorbs whatever falls between. (For the full breakdown, see the policy interaction map.)

You would expect better coordination on a program where all three come from the same carrier family. The policies are still separate contracts written by separate underwriting teams. The D&O cyber exclusion doesn’t reference the cyber policy. Same carrier, same gap.

Who reads the forms

Placing the program and reading the program are two different jobs. The broker places it. Reading up to 180 pages of dense policy language, cross-referencing definitions and exclusions, testing them against a specific bank’s wire procedures and vendor contracts and regulatory exposure. That’s the other job. I’ve spent my career on the carrier and MGA side, which is where you learn which exclusions carriers enforce at claim time and which ones sit in the form without ever being litigated.

Renewal is when that second job counts. After the policies bind, the language is fixed. On a three-year program, that window opens once and closes for three years.

The language is what pays the claim

Most banks review their premium at renewal. On a three-year program, that’s once every three years. Almost none review the language.

Renewal within 90 days? That's the window to read the forms before they bind. Review sublimits, verify the callback procedure matches your wire process, and confirm which policy responds to which loss.
Mid-term on a multi-year program? The language is already fixed, but the risks it's supposed to cover are not. Wire procedure mismatches you can fix today. Sublimit and coordination gaps go on the list for your next renewal negotiation.

Get in touch.

Joerg Proeve, Founder and Principal at Breezy Risk
Joerg Proeve

Founder & Principal of Breezy Risk. Carrier and MGA background in insurance, earlier career in cybersecurity and engineering. Audits insurance for community banks and credit unions.

More about Joerg →