HOA Lost Money – Which Insurance Policies Should the Board Notify

roof age and insurance

The payment was approved on Friday. By Monday, the contractor says it never arrived.

The board checks the email chain and discovers that someone changed the banking instructions. While the bank investigates, owners begin asking how the transfer was authorized and whether the directors failed to supervise the process.

What began as one missing payment may now involve several separate problems: a direct financial loss, a compromised email account, and potential allegations against the board.

The immediate question is not simply, “Which policy covers this?” The more useful question is, “Which insurers need to know, and what information will each one require?”

This guide gives HOA boards and property managers a practical process for reporting and documenting financial incidents without assuming that one policy will handle every part of the loss.

 

Table of Contents

 

Quick Answer: What Should the HOA Do First?

After discovering missing money, payment fraud, unauthorized system access, or a financial claim against the board, the HOA should:

  1. Contact the bank or payment provider immediately.

  2. Secure affected email, banking, and accounting accounts.

  3. Preserve financial and electronic records.

  4. Notify every insurer that could reasonably be connected to the event.

  5. Forward written demands or legal notices without delay.

  6. Avoid admitting fault or promising reimbursement.

The board does not need to determine final coverage before giving notice. Crime, cyber, D&O, and fiduciary liability policies may have different reporting requirements, and waiting for one insurer’s decision could create problems under another policy.

 

Step 1: Identify What the HOA Lost

Start by describing the loss in practical terms rather than assigning it an insurance label.

Did money leave the association’s account? Was sensitive information exposed? Did the HOA incur investigation or system-restoration expenses? Has someone demanded compensation from the board?

These outcomes are not interchangeable.

What happened

Immediate need

Policy commonly reviewed

Funds were stolen or fraudulently transferred

Recovery of the direct loss

Crime/Fidelity

Email or accounting access was compromised

Investigation and incident response

Cyber

Owners accuse the board of poor oversight

Legal defense

D&O

A claim concerns an employee benefit plan

Specialized legal defense

Fiduciary Liability

The policy shown in the final column is only a starting point. Definitions, endorsements, exclusions, sublimits, and the exact method used to cause the loss will determine whether coverage may apply.

 

Step 2: Separate the Incident Into Claim Components

One event can produce several expenses and allegations. Treating all of them as a single “money claim” can make reporting less precise.

Consider a fraudulent vendor payment. The HOA may face:

  • the amount transferred to the criminal;

  • forensic expenses to determine whether an email account was compromised;

  • costs associated with exposed resident or vendor information;

  • a demand from the legitimate contractor for payment;

  • allegations that the directors ignored payment controls.

The missing money may create a crime claim. The compromised account and investigation may create a cyber claim. A written allegation against the directors may create a D&O claim.

That does not mean every policy will pay. It means each component should be identified and reported to the appropriate insurer for evaluation.

A simple incident worksheet can help. List every financial loss, response expense, third-party demand, affected system, and person involved. Then match each item to the policy that may need to review it.

 

Step 3: Notify Potentially Relevant Insurers

Boards sometimes delay notice because they are unsure which policy applies. That uncertainty is a reason to report the incident, not a reason to wait.

Notice provisions can differ substantially. A crime policy may focus on when the loss was discovered. A cyber policy may require the insured to contact an approved response provider. D&O and fiduciary liability policies are often written on a claims-made basis, making the timing of a demand especially important.

The initial notice should provide known facts without speculation. Include:

  • when the incident occurred and was discovered

  • the amount currently believed to be missing

  • the accounts, systems, and people involved

  • actions already taken

  • any demand, complaint, subpoena, or legal notice received

If the investigation is incomplete, say so. The HOA can provide additional information as it becomes available.

 

Step 4: Preserve the Right Evidence

A financial claim is easier to evaluate when the association can reconstruct what happened.

Preserve original emails rather than relying only on screenshots. Email headers, login records, forwarding rules, access logs, and multifactor-authentication history may help determine whether an account was compromised.

Financial documentation may include bank statements, transfer confirmations, canceled checks, invoices, vendor records, approval logs, accounting reports, and reconciliation records.

Governance records can also matter. Keep meeting minutes, resolutions, payment procedures, contracts, management agreements, reserve reports, and communications showing who had authority to approve the transaction.

The board should suspend routine deletion of relevant emails or files. If litigation is reasonably anticipated, legal counsel may recommend a formal document-preservation notice.

 

Step 5: Track Written Demands Against the Board

A lawsuit is not always the first event that qualifies as a claim.

An owner’s attorney may send a letter alleging financial mismanagement. A vendor may demand payment after funds were diverted. Residents may request reimbursement or threaten legal action over an assessment.

Depending on the D&O or fiduciary liability policy, a written demand for monetary or nonmonetary relief may satisfy the policy’s definition of a claim.

Create a log recording:

Item

Information to record

Date received

Exact delivery date

Sender

Owner, vendor, employee, atto4rney, or regulator

Recipient

Board, manager, director, or association

Requested action

Money, records, corrective action, or legal relief

Reported to

Insurer, agent, attorney, or response provider

Date reported

Confirmation of timely notice

Forward the original document to the appropriate insurer or agent. Do not rely on a board member’s summary of what it says.

 

Step 6: Avoid Actions That Could Complicate the Claim

The board will naturally want to reassure residents and resolve the problem quickly. However, some actions could affect the investigation or the insurer’s position.

Avoid admitting that the board, manager, or employee was negligent before the facts are established. Do not promise that the HOA will repay a vendor or owner. Do not negotiate a settlement, sign a release, or retain expensive response services without checking applicable policy requirements.

Communications to residents should be accurate but limited to confirmed facts. If personal information may have been exposed, the HOA should consult its cyber-response team or legal counsel before sending a broad notice.

The board should also avoid disciplining or confronting a suspected individual without preserving records and obtaining appropriate advice. Premature action could result in lost evidence or additional employment-related allegations.

 

A 24-Hour Financial Claim Checklist

During the first day, the HOA should prioritize recovery, security, evidence, and notice.

  • Ask the bank whether a transfer can be recalled, frozen, or traced.

  • Change affected credentials and secure administrator accounts.

  • Preserve emails, logs, invoices, bank records, and approvals.

  • Document who discovered the incident and when.

  • Notify the insurance agent and potentially relevant carriers.

  • Forward every written demand or legal communication.

  • Record all actions in a single incident timeline.

  • Ask insurers before hiring outside forensic or response vendors.

Law enforcement or regulatory reporting may also be appropriate, depending on the incident and applicable requirements.

 

Review Coverage Before the Next Incident

The best time to resolve reporting uncertainty is before money disappears.

The HOA should keep a current policy schedule showing the insurer, policy number, limits, deductible or retention, reporting contact, and policy period for crime, cyber, D&O, and fiduciary liability coverage.

The board should also compare its largest possible transfer with applicable crime and social-engineering limits. A $25,000 fraud sublimit may not provide meaningful protection if the association regularly sends six-figure construction payments.

Review whether directors, volunteers, employees, property managers, and management-company personnel fit the relevant policy definitions. Confirm whether the cyber policy requires the use of approved vendors and whether defense expenses reduce the D&O limit.

This review turns a collection of separate policies into a more coordinated financial-loss response plan.

 

Frequently Asked Questions

Should an HOA wait for the bank’s investigation before reporting a fraudulent transfer?

Usually, no. The bank and insurers can investigate at the same time. Waiting could affect recovery opportunities or policy reporting requirements.

Should the HOA notify both its crime and cyber insurers?

Potentially. If electronic deception or unauthorized system access contributed to the loss, both policies may need to evaluate different parts of the incident.

Does notifying several insurers mean the HOA can collect twice?

No. Multiple policies may review the same event, but insurance is not intended to provide duplicate recovery for the same loss.

Can an owner’s letter qualify as a D&O claim?

Possibly. Some policies define a claim to include a written demand for monetary or nonmonetary relief. The exact wording controls.

Where does fiduciary liability fit?

It is most relevant when allegations involve responsibilities connected with an employee benefit plan. Ordinary disputes over reserves, budgets, or assessments are more likely to raise D&O questions.

What if the HOA does not yet know the full amount of the loss?

The incident can still be reported using the information currently available. The association can update the insurer as the investigation develops.

 

How StarNet Insurance Group Can Help

A financial incident can move quickly from a banking problem to a cyber investigation and then to allegations against the board. Clear reporting procedures help the HOA respond without forcing one policy to perform a job it was not designed to handle.

StarNet Insurance Group can help HOA boards and property managers review reporting requirements, covered persons, fraud sublimits, defense provisions, and potential gaps across their crime, cyber, D&O, and fiduciary liability policies.

Coverage depends on the insurer, policy, endorsement, exclusion, limit, applicable law, and circumstances of the claim. This article provides general educational information and is not legal, financial, or coverage advice.

 

Contact StarNet Insurance Group to review your association’s financial-loss response plan before the next large payment or written demand arrives.

 

Internal Resources

HOA D&O Insurance: Board Decisions That Can Trigger a Claim

HOA Crime Fidelity Insurance: Theft and Fraud Risks

HOA Cyber Liability: Email Scams, Wire Fraud, and Resident Data Breaches

Lawsuit Defense Costs: Why Liability Limits Aren’t the Whole Story

 

External Resources

FBI: Business Email Compromise

CISA: Use Multifactor Authentication

FTC: Data Breach Response—A Guide for Business