Funds Transfer Fraud and Social Engineering Questions
Want a second set of eyes on your application?
We work only with RIAs. We'll go through your answers with you before you submit.
Do you accept funds transfer requests via email?
This is a follow-up to Question 22a regarding the disbursement of client funds. This question focuses specifically on the communication method used for such requests.
Why the carrier asks
This question helps the insurance carrier evaluate your firm's vulnerability to cybercrime. Email is the single most common channel (or "vector") for social engineering and funds transfer fraud attacks. By confirming whether you use this high-risk channel for money movement instructions, the underwriter can assess your firm's exposure to potentially significant fraud-related E&O claims.
Key terms
- What does "Accept Funds Transfer Requests via Email" mean? This means you receive and act on instructions from a client to move money, where the initial instruction arrives in an email. Even if you perform other verification steps later, using email as the channel for the initial request is what this question is about.
- What is "Business Email Compromise (BEC)"? A sophisticated scam where a criminal hacks into or spoofs a legitimate email account (like a client's) and sends fraudulent instructions to an advisor, tricking them into wiring money to the criminal's account.
How to answer
To answer this question, you must determine if your firm's procedures allow for a client to initiate a money movement request by sending you an email.
- This is a simple "yes" or "no" question.
- If your policy is to accept such requests, even if you follow up with a phone call, the answer is "yes."
- If your firm has a strict policy to never accept money movement instructions via email and you require clients to use a more secure method (like a phone call or a secure client portal), the answer is "no."
Common mistakes
- Mistake: Believing that because you call to verify the request, you can answer "no."
- The question is about whether you accept the request via email as the first step. If the process starts with an email, you must answer "yes." The verification step is a crucial control, but it doesn't change the fact that you use a high-risk channel.
- Pitfall: Thinking this doesn't apply because it happens rarely.
- Even one instance of accepting a request via email exposes your firm to this risk. The policy should be consistent.
- Mistake: Assuming your secure email portal is exempt.
- If the "secure portal" is just an encrypted email system, the risk of the client's own email account being compromised still exists. The answer is likely still "yes."
Frequently asked questions
What is the best practice for handling client disbursement requests?
The industry best practice is to have a strict policy not to accept any money movement instructions via email. Instead, firms should require a live phone conversation with the client using a known, trusted phone number, or instructions submitted through a multi-factor authenticated client portal.
We do accept requests via email, but we always call the client to confirm. Is that okay?
Answering "yes" to this question is not automatically disqualifying, but it does indicate higher risk. Your procedure of calling to confirm (known as "out-of-band verification") is the most important mitigating control you can have. Be prepared to describe this process in detail.
Why is email so risky for these requests?
Email accounts are frequently compromised by criminals. It is very easy for a fraudster to send you an email that looks exactly like it came from your client, creating a situation where you could be tricked into sending money to a criminal's account.
Are callbacks to the customer at a prearranged number utilized to ensure the authenticity of funds transfer requests?
This is a follow-up to Questions 22a and 22b. It addresses the specific controls used to verify money movement instructions.
Why the carrier asks
This question helps the insurance carrier evaluate your firm's specific risk mitigation practices against fraud. Using a callback to a prearranged number is considered a critical and highly effective safeguard against social engineering and funds transfer fraud. A "yes" answer indicates that you have a strong verification process, which can significantly reduce the likelihood of a successful fraud attempt and may be viewed favorably by underwriters.
Key terms
- What is "Callback Verification"? This is a verification process where you proactively contact a client to confirm that a money movement request is legitimate before you act on it.
- What is a "Prearranged Number"? This is a phone number that you have established with the client ahead of time as a trusted contact number. It should be a number you collected through a secure method (e.g., during the in-person onboarding process), not a number provided in the potentially fraudulent email itself.
How to answer
To answer this, you need to confirm if your firm's standard procedure includes this specific verification step for money movement requests.
- The Process: When your firm receives a request to transfer funds (especially via an insecure method like email), do you have a mandatory policy to call the client to get verbal confirmation?
- The Number: Do you make this call to a phone number that is already on file and known to be authentic, rather than a number listed in the email making the request?
If this is your firm's standard procedure, you can answer "yes." If you do not perform this specific verification step, you should answer "no."
Common mistakes
- Mistake: Calling a number listed in the potentially fraudulent email.
- This is a critical error. Fraudsters will often include their own phone number in a fake email. A proper callback must be to a prearranged number already in your system that you know belongs to the client.
- Pitfall: Only performing callbacks for large transfer amounts.
- While better than nothing, best practice (and what underwriters look for) is a consistent policy for all transfer requests, regardless of the amount. Criminals often start with small transfers to test a firm's controls.
- Mistake: Thinking that since you "know" your client's voice, you don't need a prearranged number.
- The principle of a prearranged number is to ensure you are contacting the legitimate client at their known point of contact, bypassing the potentially compromised communication channel.
Frequently asked questions
What if we verify requests by emailing the client back?
This is not a secure method and does not count as callback verification. If a criminal has compromised your client's email account, they will simply reply to your verification email and approve the fraudulent request. The verification must be "out-of-band" (i.e., through a different channel like the telephone).
Do we have to do this for every single transfer request?
From a risk management and insurance perspective, yes. Having a mandatory policy that is followed every single time is the strongest defense against this type of fraud.
What if we can't reach the client at their prearranged number?
The correct procedure is to not process the transfer until you have successfully made verbal contact with the client and confirmed the request is legitimate. The delay is preferable to a potentially catastrophic fraudulent loss.
Are password(s) and/or passphrase(s) utilized with customers to ensure the authenticity of funds transfer requests?
This is a follow-up to the previous questions on funds disbursement. It addresses a specific control used to verify money movement instructions.
Why the carrier asks
This question helps the insurance carrier evaluate another layer of your firm's security practices. Using a pre-established password or passphrase is a recognized safeguard against social engineering and funds transfer fraud. While not as robust as a callback verification on its own, it adds a layer of authentication. A "yes" answer can demonstrate a more security-conscious approach to protecting client assets from fraud.
Key terms
- What is "Password/Passphrase Verification"? This is an authentication method where you require a client to provide a secret word (password) or phrase (passphrase) to confirm their identity before you will act on a money movement request. This secret code should be established securely with the client ahead of time.
How to answer
To answer this question, you need to confirm if your firm uses a pre-agreed-upon password or passphrase as a step in verifying a client's identity before moving money.
- The Process: When your firm receives a request to transfer funds, do you have a procedure that requires the client to provide a password or passphrase?
- Application: Is this used for all clients and all requests, or only under specific circumstances?
If you use this security measure as part of your process, you can answer "yes." If you do not use passwords or passphrases for this purpose, you should answer "no."
Common mistakes
- Mistake: Confusing a client's account password with a specific passphrase for verification.
- This question is not about the password a client uses to log into their account portal. It's about a separate, specific code used to verbally or otherwise authenticate a money movement request.
- Pitfall: Using easily guessable information as a passphrase.
- Information like a mother's maiden name or the last four digits of a Social Security number are not secure passphrases, as this data is often compromised in data breaches. The code should be unique and known only to you and the client.
- Mistake: Believing this method is a complete replacement for callback verification.
- While helpful, this method is not as secure as a callback to a prearranged number. A criminal who has compromised a client's computer could potentially find the password stored in a file. It is best used as a part of a multi-layered security approach, not as the only defense.
Frequently asked questions
How do we establish a secure password with a client?
It should be done through a secure channel, ideally in person during onboarding or over the phone. It should never be established or confirmed via email.
We use this, but only for certain high-risk requests. Should we still answer "yes"?
Yes. Any use of this safeguard indicates a level of protection against fraud. Be prepared to explain how and when you apply this method.
Is this the same as Multi-Factor Authentication (MFA)?
It can be a component of MFA. For example, your process might be to receive a request, call the client back (first factor), and ask for their passphrase (second factor). Using passwords in combination with other methods is a strong security practice.
Do you use sending a text message to a prearranged number with customers to ensure the authenticity of funds transfer requests?
This is a follow-up to the previous questions on funds disbursement. It addresses another specific control used to verify money movement instructions.
Why the carrier asks
This question helps the insurance carrier evaluate another layer of your firm's security practices against fraud. Using text messages (SMS) to verify a transaction is a common authentication method. While it can be an effective part of a multi-layered defense, it also has known vulnerabilities (e.g., SIM swapping). Underwriters want to know if you use this method to understand the specific technologies and risks present in your verification process.
Key terms
- What is "Text Message Verification"? This is an authentication process where, after receiving a money movement request, you send a text message to a client's prearranged mobile number to confirm the request is legitimate. This might involve the client replying "YES" or you sending a one-time code that the client must provide back to you.
- What is a "Prearranged Number"? As with callback verification, this is a mobile phone number that you have established with the client ahead of time as a trusted contact number through a secure method.
How to answer
To answer this question, you need to confirm if your firm uses text messaging as a step in verifying a client's identity before moving money.
- The Process: When your firm receives a request to transfer funds, do you have a procedure that involves sending a text message to the client for confirmation?
- Application: Is this used for all clients and all requests, or only under specific circumstances?
If you use this security measure as part of your process, you can answer "yes." If you do not use text messages for this purpose, you should answer "no."
Common mistakes
- Mistake: Believing text message verification is foolproof.
- While useful, SMS verification is vulnerable to "SIM-swapping" attacks, where a criminal tricks a mobile carrier into transferring a client's phone number to a new SIM card controlled by the criminal. This allows them to intercept verification texts. Because of this risk, it should not be the only method of verification.
- Pitfall: Texting a number provided in a potentially fraudulent email.
- Just like with phone callbacks, the text must be sent to a prearranged number you have on file, not a number provided in the email making the request.
- Mistake: Using text messaging as the primary communication channel for sensitive information.
- Texting is not a secure channel for discussing detailed financial matters. It should be used for verification purposes only (e.g., sending a code), not for transmitting sensitive client data.
Frequently asked questions
Is text message verification better than a phone call?
No. A live phone call ("callback verification") to a prearranged number is generally considered more secure than a text message because it allows for a two-way conversation and is less susceptible to certain types of fraud like SIM-swapping. However, using both is a very strong, multi-factor authentication approach.
What's the best way to use text message verification?
It's most effective when used as one part of a multi-factor authentication (MFA) process. For example, after receiving an emailed request, you could call the client to discuss it, and as a final step, send a one-time code to their phone via text, which they must read back to you to authorize the transfer.
Is there a specific app we should use for this?
Using a dedicated, encrypted messaging app or a feature within a secure client portal is more secure than standard SMS text messaging.
Do you send confirmation to a prearranged email address?
This is a follow-up to the previous questions on funds disbursement. It addresses another specific control used to verify money movement instructions.
Why the carrier asks
This question helps the insurance carrier evaluate another potential layer of your firm's security practices against fraud. Sending a confirmation to a prearranged email address can serve as a documented step in your verification process. However, because email itself is a vulnerable channel, underwriters assess this practice to understand how it fits into your overall security posture and whether it is a primary control or a supplementary one.
Key terms
- What is "Email Confirmation"? This is a verification process where you send a message to a client's pre-established email address to confirm that a money movement request is legitimate before you act on it.
- What is a "Prearranged Email Address"? This is an email address that you have securely collected from the client ahead of time and have on file as their official contact email. It should not be an email address that was provided in the transfer request itself.
How to answer
To answer this question, you need to confirm if your firm uses email confirmation as a step in verifying a client's identity before moving money.
- The Process: When your firm receives a request to transfer funds, do you have a procedure that involves sending a confirmation to a known client email address?
- Application: Is this used for all clients and all requests, or only under specific circumstances?
If you use this security measure as part of your process, you can answer "yes." If you do not use email confirmation for this purpose, you should answer "no."
Common mistakes
- Mistake: Using email confirmation as your only verification method.
- This is a critical error. If a criminal has compromised your client's email account, they can both send the fraudulent request and reply to your confirmation email, making the control useless. Email confirmation is one of the weakest forms of verification when used alone.
- Pitfall: Replying to the same email that made the request.
- A proper confirmation should be sent by starting a new email thread to the prearranged address on file, not by simply hitting "reply." This helps defeat certain email-forwarding scams.
- Mistake: Believing this makes your process secure.
- While better than nothing, email confirmation is not a robust security control against a determined fraudster. It should only be used as a supplementary step in a process that includes stronger methods like a phone callback.
Frequently asked questions
How is this different from accepting a request via email (Question 22b)?
Question 22b asks if the client can start the process by emailing you. This question asks if you use email to confirm a request that may have been received through another channel. For example, a client might call you with a request, and you might follow up with a confirmation email for their records.
Is this a good security practice?
It is a good record-keeping practice, but it is a weak security practice if used alone. It provides a paper trail, but it does little to prevent fraud if the client's email account has been compromised. Its value increases significantly when combined with other, stronger verification methods.
Do you use a different method to verify the authenticity of funds transfer requests from customers?
This is a follow-up to the previous questions on funds disbursement. It is a catch-all question to identify any other verification controls you may use.
Why the carrier asks
This question gives you an opportunity to describe any unique or alternative verification methods your firm uses that were not covered in the previous, specific questions. Insurers recognize that firms may have innovative or customized security controls. This question allows the underwriter to get a complete picture of all your safeguards against funds transfer fraud and to give you credit for any additional robust procedures you have in place.
Key terms
- What is a "Different Method"? This refers to any verification process your firm uses that is not a phone callback, a password/passphrase, a text message, or an email confirmation. This is a "catch-all" to describe any other security step you take. Common examples include:
- In-person verification (client must come to the office).
- Video call confirmation.
- Secure client portal authentication (requiring the client to log in to approve a transfer).
- Use of a third-party authentication app.
How to answer
To answer this, you need to consider if you use any other verification methods not previously discussed.
- Review your Process: Think through your entire funds transfer verification process. Is there any other step you take?
- Describe the Method: If you answer "yes," you must be prepared to describe the method in detail in a type-in field on the application.
If you do not use any other methods beyond what has already been covered, you can answer "no."
Common mistakes
- Mistake: Re-listing a method that was already covered.
- Do not answer "yes" and then describe your callback procedure again. This question is only for different methods.
- Pitfall: Being too vague in your description.
- If you answer "yes," a vague description like "we use other checks" is not helpful. You need to be specific, for example: "For all transfers over $50,000, we require the client to approve the transfer request through their secure, multi-factor authenticated client portal."
Frequently asked questions
We require clients to log into their secure portal to approve all money movements. Does this count?
Yes, absolutely. That is a perfect example of a "different method" that is a very strong security control. You would answer "yes" and describe this process.
We don't have a formal policy, but for my biggest client, I sometimes drive to their house to get a signature. Should I list that?
Yes. While informal, it is a method of verification you use. You would answer "yes" and describe it as "in-person verification for certain clients or high-value transfers." This demonstrates a high level of care, even if it's not a firm-wide policy.
Do you send your customers pre-filled wire instructions?
This is a follow-up to the previous questions on funds disbursement. It addresses a specific practice related to facilitating wire transfers.
Why the carrier asks
This question helps the insurance carrier evaluate your firm's vulnerability to a specific type of social engineering attack. When you send pre-filled wire instructions to a client (especially via email), you create a document that a criminal can intercept and alter. A fraudster could change the account and routing numbers to their own, and then send the altered document to your client, tricking them into wiring money to a fraudulent account. This practice creates a significant liability risk for your firm.
Key terms
- What are "Pre-Filled Wire Instructions"? This refers to any document or template (digital or paper) that you provide to a client that already contains specific banking details for a wire transfer, such as the recipient's name, bank, account number, and routing number. You might send this to make it easier for a client to fund their account with you.
How to answer
To answer this, you must determine if your firm ever provides clients with wire instruction forms where the banking details are already filled in.
- This includes sending PDFs via email, providing templates on your website, or handing out physical copies.
- The key is whether you are the source of the document containing the sensitive banking information.
If you engage in this practice, you must answer "yes." If you never provide pre-filled instructions and instead have clients obtain wiring details directly from the source (e.g., from the custodian's secure website), you can answer "no."
Common mistakes
- Mistake: Believing that sending instructions via encrypted email is safe.
- Even if your email is secure, the client's email account can be compromised. A criminal can intercept the document, alter it, and send it to the client from a spoofed or hacked account. The secure channel does not eliminate the risk.
- Pitfall: Thinking this is the client's risk, not yours.
- If a client loses money after acting on fraudulent instructions that originated from your firm (even if they were altered later), your firm will almost certainly be involved in the dispute and may be held partially or fully liable.
- Mistake: Assuming that because it's convenient for the client, it's a good practice.
- While convenient, it is a high-risk practice from a cybersecurity perspective. The convenience does not outweigh the potential for catastrophic fraud.
Frequently asked questions
What is the best practice for providing wire instructions?
The industry best practice is to not send pre-filled wire instructions via email. Instead, you should instruct the client to obtain the instructions directly from the source, for example, by logging into their secure account at the custodian (e.g., Schwab, Fidelity) or by calling a known, trusted number at the receiving institution to verbally confirm the details before initiating a wire.
We send the instructions, but we also tell the client to call us to verify the numbers before sending. Is that okay?
This is a good mitigating control, but it does not eliminate the initial risk. You would still answer "yes" to this question and then be prepared to describe your verification process in detail. The best practice is to avoid sending the instructions in the first place.
How many of your firm’s staff has the ability to send transfer requests to your custodian or bank?
This is a follow-up to the previous questions on funds disbursement. It addresses the internal controls related to staff access.
Why the carrier asks
This question helps the insurance carrier evaluate your firm's internal risk of social engineering and funds transfer fraud. The more individuals who have the authority to initiate money movement, the more potential targets a criminal has for an attack. By understanding how many staff members have this critical ability, an underwriter can assess the scale of your firm's internal control risk.
Key terms
- What is the "Ability to Send Transfer Requests"? This refers to the authority or system access that allows a staff member to initiate a funds transfer instruction to a custodian (e.g., Schwab, Fidelity) or a bank. This includes any employee who can directly submit wire instructions, authorize an ACH transfer, or otherwise send a request that results in the movement of funds.
How to answer
To answer this question, you need to provide the total number of employees, contractors, or other personnel within your firm who have the explicit authority or system access to send a funds transfer request.
- Review Permissions: Identify all staff members who have logins or authority to access custodian platforms for the purpose of moving money.
- Count Individuals: Provide a specific count of these individuals.
- Include All Roles: This could include anyone from senior advisors to administrative staff, if they have the capability to initiate such transactions.
Common mistakes
- Mistake: Only counting senior advisors or partners.
- You must count any staff member with the ability to send a transfer request, regardless of their title. Administrative staff are often targeted by fraudsters because they may have access but less training.
- Pitfall: Thinking that because a staff member's access is supervised, they don't count.
- Even if a transaction requires a manager's approval, the staff member who can initiate the request still represents an access point and must be included in the count.
- Mistake: Excluding staff who only handle certain types of transfers.
- If a staff member can initiate any type of transfer (e.g., only ACH, not wires), they still have the ability to send a transfer request and must be counted.
Frequently asked questions
What if a staff member only prepares the transfer form but someone else has to sign and send it?
In this case, the person who only prepares the form does not have the ability to send the request and should not be counted. The person who provides the final authorization and sends the request should be counted.
Is there a "right" number for this question?
No, but a lower number is generally better from a risk management perspective. The principle of "least privilege" suggests that only the staff members who absolutely require this ability to do their job should have it. A smaller number of access points is easier to monitor and secure.
What kind of follow-up questions should I expect if the number is high?
Be prepared to discuss the roles of these staff members and, most importantly, the safeguards and access controls you have in place. This includes things like dual authorization requirements (requiring two people to approve a transfer), audit logs to track activity, and specialized training on fraud prevention.
How many employees do you have that are not family members?
This is a follow-up to the previous questions on funds disbursement and staff access. It addresses the composition of your staff.
Why the carrier asks
This question helps the insurance carrier evaluate the internal control environment of your firm. While family-run businesses can be very strong, insurers view them as having a different risk profile than firms with non-family employees. The level of trust, formality of procedures, and methods of oversight can differ. A larger number of non-family employees can increase the number of potential targets for social engineering, as criminals may try to exploit weaker links in a larger organization. This question helps the underwriter understand this dynamic.
Key terms
- Who is a "Non-Family Employee"? This is any employee who is not a close relative of the firm's principals or owners. Close relatives typically include a spouse, parent, child, or sibling. You should count any employee who does not have such a family connection.
How to answer
To answer this question, you need to provide the total number of your employees who are not family members of the firm's principals.
- Count Individuals: Review your staff roster and count all employees who do not have a close family tie to the firm's ownership.
- Include All Roles: This includes full-time, part-time, and temporary employees if they are not family members.
Provide the specific number. If all of your employees are family members, the answer is "0".
Common mistakes
- Mistake: Only counting full-time employees.
- You must include all non-family employees, regardless of their employment status (full-time, part-time, etc.), as they all represent a potential vector for a social engineering attack.
- Pitfall: Getting offended by the question.
- This question is not a judgment on your family or your employees. It is a standard question used by insurers to understand the internal control environment. Family businesses often have higher levels of implicit trust and less formal oversight, which is a unique risk factor an underwriter must consider.
- Mistake: Thinking that since a non-family employee doesn't have access to funds, they don't need to be counted.
- All employees must be counted. A criminal might target a junior, non-family employee in an attempt to gather information that can be used to impersonate a more senior person at the firm in a later attack.
Frequently asked questions
Why does the insurance company care if my employees are family or not?
Insurers view this as a factor in assessing internal controls. Family-run firms may have different dynamics regarding oversight and formality of procedures compared to firms with a larger base of non-family employees. Both models have unique risks, and this question helps the underwriter understand which profile fits your firm.
We have a long-term employee who is "like family" but not actually related. How do we count them?
They should be counted as a non-family employee. This question is based on actual familial relationships (by blood or marriage), not on the length or closeness of a working relationship.
What follow-up questions should I expect if we have a high number of non-family employees?
Be prepared to discuss the formal safeguards and internal controls you have in place, such as dual authorization for transfers, restricted system permissions, and mandatory anti-fraud training for all staff.
Does the firm require background checks on all employees with access to sensitive information?
This is a follow-up to the previous questions on staff composition. It addresses a specific internal control related to employee vetting.
Why the carrier asks
This question helps the insurance carrier evaluate your firm's internal security and hiring practices. Requiring background checks on all employees with access to sensitive data is a fundamental control for mitigating internal fraud and reducing vulnerability to social engineering. A firm that vets its employees is seen as a lower risk than one that does not, as it takes proactive steps to prevent hiring individuals who may pose a threat to the firm or its clients.
Key terms
- What is a "Background Check"? A pre-employment or periodic process to investigate an individual's history. This typically includes, at a minimum, a criminal record check. It can also include verification of employment history, credit checks, and checks of regulatory databases (like FINRA's BrokerCheck).
- What is "Sensitive Information"? Any data that, if compromised, could harm clients or the firm. This includes client financial records, account numbers, social security numbers, and especially the ability to access or initiate funds transfers.
How to answer
To answer this question, you need to confirm if your firm has a mandatory policy to conduct background checks on every employee who will have access to sensitive client or firm information.
- Review your hiring process: Is a background check a standard, required step for all personnel in sensitive roles?
- Consider all employees: This policy must apply to everyone with access, from senior partners to administrative staff.
- "All" is the key word: If you conduct checks on some employees with access but not others, the answer to this question is "no."
If you have a mandatory policy to check all employees with sensitive access, you can answer "yes."
Common mistakes
- Mistake: Answering "yes" when you only check certain employees.
- The question specifically asks about all employees with access. If you only check advisors but not the administrative staff who may also have access to client data, your answer must be "no."
- Pitfall: Conducting only informal reference checks.
- While calling references is a good practice, it is not a formal background check. An underwriter is looking for a formal process that includes, at a minimum, a review of criminal history.
- Mistake: Assuming that because an employee has a professional license, a background check is not needed.
- While licensing bodies conduct their own checks, a direct background check as part of your hiring process is a separate and important internal control.
Frequently asked questions
What type of background check is considered standard?
At a minimum, a criminal background check should be performed. For employees with financial responsibilities, a credit check is also a common and recommended practice. Verifying past employment and checking regulatory databases are also best practices.
We are a small family business. Do we really need to do background checks on family members?
From a risk management perspective, yes. While trust is high in a family business, internal fraud can still occur. A consistent policy for all employees, regardless of relationship, is the strongest control. If you do not check family members, your answer to this question would be "no."
Do we need to do background checks continuously, or just at hiring?
While most firms only perform checks at the time of hiring, a best practice for very high-risk roles is to conduct periodic re-checks (e.g., every few years) to identify any issues that may have arisen since employment began.
This guide explains what application questions generally ask and how carriers tend to read the answers. It isn't legal advice or a coverage determination: your carrier's application and policy wording control. When you're unsure how to answer, ask your broker before you sign.
Working on your RIA E&O application right now?
We work only with RIAs. Send us your application before you submit it and we'll walk through the answers with you, so nothing comes back to bite you at claim time.
Book a call