Turning a Volatile Write-Off Into a Fixed Premium

Every CFO knows the difference between a cost and a risk. A cost you budget. A risk you reserve against, defend to a board, and explain to an examiner when it moves.
Fraud loss is filed under risk at most credit unions. It could be filed under cost.
The volatility, not the level, is the problem
Ask a finance team what makes fraud loss difficult and they rarely lead with the magnitude. They lead with the variance.
A loss line that runs predictably can be planned around at almost any level. A loss line that lands somewhere within a wide band — and where nobody can say in advance where inside that band — creates compounding problems:
- You reserve to the pessimistic end, tying up capital against a loss that may not materialize
- Or you reserve to the expected case and carry earnings risk into every quarter
- Either way, your forecast confidence is a function of your worst month, not your average one
That is a capital efficiency problem wearing a fraud costume. The dollars held against an uncertainty band are dollars not deployed into lending.
What risk transfer changes
Insurance does not make fraud losses smaller. It makes them somebody else’s.
That distinction is the substance of the CFO case. When the residual fraud exposure sits with a carrier rather than the institution:
The provision assumption changes. Losses covered by a policy are not losses the institution absorbs. What was a modeled range becomes a contractual reimbursement plus a known premium.
Earnings volatility compresses. A bad fraud quarter stops being an earnings event. The premium is the same in a good quarter and a bad one — which is the definition of a cost rather than a risk.
Capital held against the uncertainty becomes available. This is the part worth modeling carefully with your own numbers, because the magnitude is institution-specific and depends on how you currently reserve. But the direction is not in question: priced, transferred risk requires less capital held against it than unpriced, retained risk.
The board conversation changes shape. “We expect fraud losses somewhere in a wide range” is a risk disclosure. “We pay a fixed premium, and the exposure is reinsured by Munich Re and Swiss Re, each rated A+ (Superior) by AM Best” is a budget line. Boards approve budget lines.
The prerequisite most institutions miss
None of the above works if you cannot measure the exposure in the first place.
Underwriting requires loss experience. An institution that books fraud losses into general charge-offs — which is most of them, for reasons covered elsewhere on this blog — cannot produce the loss history that pricing depends on. The measurement problem precedes the transfer decision.
The practical sequence:
- Separate fraud loss from credit loss in your own reporting, starting with first-payment defaults and very-early defaults
- Establish the actual range across a meaningful period, not a single bad quarter
- Compare the cost of retaining that range against the cost of transferring it
- Then decide — retain, tighten, or transfer, with a real number underneath the choice
Step 1 has value even if you never buy anything. Most institutions discover their fraud exposure is differently shaped than assumed, which changes channel and pricing decisions on its own.
The question worth asking
Not “how much fraud do we have.”
Ask instead: how much capital are we holding against the fact that we don’t know?
That figure is rarely calculated, and it is usually the larger of the two.


