---
title: "Cross-carrier fraud data networks (IDN, ISO ClaimSearch, NICB): what they catch and what they miss"
description: "Cross-carrier fraud data networks - ISO ClaimSearch, NICB, and Shift IDN - answer one question: have we seen this claim before? A match is a lead, not a verdict. What they catch, what they structurally miss, and the investigation layer they leave open."
date: "2026-07-20"
lastModified: "2026-07-20"
author: "Nitish Badu"
tags: ["Guides"]
canonical: "https://gethesperai.com/blog/cross-carrier-fraud-data-networks-limits/"
---

# Cross-carrier fraud data networks (IDN, ISO ClaimSearch, NICB): what they catch and what they miss

> **TL;DR** A cross-carrier fraud data network matches an incoming claim against the industry's shared claim history to answer one question: have we seen this before? That match is a lead, not a verdict. ISO ClaimSearch, NICB, and Shift IDN are strong at anything with a prior record, but a match engine cannot see first-time or synthetic fraud, and it never investigates the flag it raises. The flag still lands on a human SIU investigator - and that is the layer, not the data, that caps how much fraud a carrier actually resolves.
>
> - ISO ClaimSearch holds 1.8B+ records across ~95% of US P&C
> - A network answers 'seen this before?' - not 'is this fraud?'
> - Synthetic identity fraud grew from $8B to $30B+ (2020-2025)
> - Manual SIU resolves only ~25% of the flags a network raises

- **1.8B+** - Records in ISO ClaimSearch (~95% of the US P&C market, 2,800+ contributors (Verisk))
- **$308.6B** - Annual US insurance fraud (~10% of P&C losses (Coalition Against Insurance Fraud))
- **$8B → $30B+** - Synthetic identity fraud, 2020-2025 (The fraud a match engine cannot see (Claims Journal / RGA))
- **~25% → 100%** - Flagged-claim coverage (Manual SIU vs Hesper on the flags a network raises (Hesper benchmark))

A cross-carrier fraud data network answers exactly one question: have we seen this claim, person, vehicle, or provider before? That match is a lead, not a verdict. ISO ClaimSearch, NICB, and newer intelligence networks like Shift's IDN check an incoming claim against the industry's shared claim history and surface anything with a prior record - a duplicate claim filed at another carrier, a known ring, a salvaged VIN, a flagged provider. What none of them do is investigate the claim they flag. That work still lands on a human SIU investigator's desk.

This matters because the two questions get conflated in procurement. A match engine tells you a claim resembles others in the system. It does not tell you whether this specific claim is fraudulent, with documented evidence a state DOI examiner or a court would accept. The first is detection. The second is investigation. They are different layers of the stack, and buying more of one does not do the job of the other.

This post is written for the SIU director who runs ISO ClaimSearch and NICB queries daily and already knows a match report is a starting point, not a finish line. It covers what the three main networks are, what they catch well, what they structurally miss, how the detection network and the investigation layer differ question-for-question, and why a better network - the direct read on Shift IDN's 2026 expansion - raises more flags without closing the gap. Detection is upstream; investigation is downstream. For the wider three-layer model this sits inside, see [prevention vs. detection vs. investigation](/blog/insurance-fraud-prevention-vs-detection-vs-investigation/).

## What a cross-carrier fraud data network is

A cross-carrier fraud data network is a shared or consortium database that checks an incoming insurance claim against claim history contributed by other carriers, then surfaces matches - duplicate claims, prior losses, known rings, and flagged vehicles or providers. It is a matching engine. It answers whether the industry has seen a claim like this before; it does not resolve whether this claim is fraudulent.

Three networks run the US P&C market, and they sit at different points. ISO ClaimSearch, operated by Verisk, is the largest. Per [Verisk's own description of ClaimSearch as the backbone of the P&C claims ecosystem](https://www.verisk.com/blog/verisk-claimsearch-the-backbone-of-the-pc-claims-ecosystem/), it holds over 1.8 billion US claims records, represents roughly 95% of the US P&C market, draws from 2,800-plus contributors, and is queried by around 200,000 claims professionals every day. When a claim is submitted, ClaimSearch matches it against that history and returns any prior-loss, duplicate, or watchlist hits. It is the industry's matching layer, and it is essential infrastructure.

NICB, the National Insurance Crime Bureau, is a different animal - not a commercial database but a non-profit consortium. Per [public NICB reference material](https://en.wikipedia.org/wiki/National_Insurance_Crime_Bureau), it is supported by more than 1,100 property-casualty and self-insured companies and is focused on preventing, detecting, and defeating insurance fraud and vehicle theft. Its member materials describe coverage of roughly 96% of personal-auto and about 82% of all P&C premiums. NICB runs the public VINCheck lookup for vehicle-theft and salvage history and publishes its Hot Wheels (top stolen vehicles) and Hot Spots (vehicle-theft geography) reports. Its value is referrals, ring intelligence, and law-enforcement liaison - all of which still hand off to a human investigator.

Shift Technology's IDN (Insurance Data Network) is the newest of the three - a cross-carrier intelligence network that surfaces connections across participating carriers' claims. It improves the signal, meaning it finds more cross-carrier links than any one carrier could see alone. All three - ClaimSearch, NICB, and IDN - occupy the detection and matching layer. None occupies the investigation layer beneath them. That layer is still manual SIU, and it is the one a data network cannot fill by adding more data.

## What these networks catch well

Cross-carrier networks are strongest at anything with a prior record. Because they match an incoming claim against a large body of shared history, they reliably catch duplicate and double-dipped claims filed across carriers, prior-loss history, salvage and theft records, and hits against known fraud rings and provider watchlists. Where a claim resembles something already in the system, a match engine is fast, cheap, and hard to beat.

The scale is the point. A carrier querying ClaimSearch is checking a single claim against 1.8 billion records from 95% of the market in seconds. No manual process reaches that. If the same claimant filed a similar loss at three other carriers, or if the VIN was previously totaled, or if the treating provider is on a watchlist, the match surfaces it instantly. This is genuine, high-value work, and it is the reason every serious SIU runs these queries daily.

NICB's vehicle-crime intelligence is a clear example of the category done well. VINCheck lets an investigator confirm whether a vehicle was reported stolen or declared salvage before a claim is paid. Hot Wheels and Hot Spots tell an SIU which makes and which metro areas are being targeted, which sharpens where to look. On organized rings, the consortium model matters: one carrier's questionable-claim referral becomes intelligence the whole membership can use, and NICB's law-enforcement liaison turns that intelligence into arrests. This is the sort of pattern work that no single carrier can do alone, and it is exactly what a shared network is built for.

> **Detection and investigation are different questions**
>
> A cross-carrier network answers 'have we seen this claim, person, VIN, or provider before?' - a matching question against shared history. Investigation answers 'is this specific claim fraudulent, and here is the documented evidence' - a resolution question about one claim. A network is excellent at the first and does not attempt the second. Treating a match report as a resolved case is the error; a match is a lead that still has to be worked.

## What they structurally miss

The limits of a cross-carrier network are structural, not a data-quality problem you can fix with more contributors. A match engine can only recognize what already exists in shared history. That single design fact produces four gaps: it flags but does not investigate, it is blind outside its contributing footprint, it cannot see first-time or synthetic fraud, and organized rings can vary their details to stay below the match threshold.

### They flag; they do not investigate

A match is where the work starts, not where it ends. Once a network flags a claim, someone still has to run the investigation - document forensics, statement cross-reference, timeline reconstruction, financial and network analysis - and produce a documented finding. Manual SIU investigation takes 14+ days per case, and one investigator can carry only 200+ cases at once. The result is a capacity wall: across US P&C carriers, only about 25% of flagged claims are fully investigated. Rules-based and match-based flagging also carries a 60-85% false-positive rate, so a large share of the flag pile is triage noise before any real fraud is confirmed. The coverage math behind this is laid out in [why most flagged insurance claims are never fully investigated](/blog/why-flagged-insurance-claims-never-investigated/).

### Coverage gaps and data latency

A contributory network only sees what its members contribute. ClaimSearch covers roughly 95% of the US P&C market, which means - by simple derivation, not a sourced stat - a match engine is structurally blind to fraud in the remaining share of non-contributing volume, and to anything filed with a carrier that does not participate. NICB represents about 82% of P&C premiums, leaving a long tail of non-member exposure. Contribution and refresh cadence also introduce latency: a claim filed elsewhere last week may not yet be matchable this week. And the standard data caveat applies - garbage in, garbage out. A match is only as good as the record it matches against.

### Novel and first-time fraud with no prior match

This is the gap that is growing fastest. A match-based network cannot flag fraud that has no prior record, because there is nothing to match against. First-time claims, synthetic identities, and AI-generated photos or documents pass the network clean. Per [Claims Journal, citing Reinsurance Group of America](https://www.claimsjournal.com/news/national/2026/05/15/337321.htm), synthetic identity fraud grew from roughly $8 billion in 2020 to more than $30 billion by mid-2025. The same report notes UK insurer Admiral saw a 71% year-over-year increase in fraud in 2025, with AI-generated evidence a contributing factor. This is precisely the category a match engine is structurally unable to see - and it is the category expanding fastest.

### Organized fraud that stays below the match threshold

Sophisticated rings understand how matching works and engineer around it. By varying identities, addresses, phone numbers, and treating providers just enough, a ring can keep any single claim below the threshold that would trigger a hard match. A fuzzy near-match may still surface, but a near-match is a lower-confidence lead that a human has to confirm - which pushes it right back into the same capacity wall. The network did its job by surfacing the possibility; resolving whether it is real is investigation, and investigation is where the throughput ceiling sits.

*Figure: A cross-carrier network answers 'seen this before?' and stops. First-time fraud, synthetic identities, and AI-generated evidence have no prior record to match, so they pass clean - and every real match still lands on a human investigator who can work only about a quarter of the flags. The gap is not data quality; it is the investigation layer beneath the flag.*

## Detection network vs investigation layer

Side by side, the network's job and the investigation layer's job are different questions, and the difference is not one of degree. A network answers whether a claim has been seen before and returns a match instantly; the investigation layer answers whether a claim is fraudulent and returns documented evidence. Buying more matching capacity does not add investigation capacity, and vice versa.

| Question | Cross-carrier data network | Investigation layer (Hesper) |
| --- | --- | --- |
| Have we seen this claim / person / VIN / provider before? | Yes - core function (1.8B records, ~95% of market) | Uses the match as one input among 15+ phases |
| Is THIS claim fraudulent, with documented evidence? | No - raises a lead only | Yes - audit-ready finding per claim |
| Time to a worked answer | Instant match, then 14+ days manual to resolve | 2-4 hours per case |
| Coverage of flagged claims actually resolved | ~25% (human capacity limit) | 100% |
| Catches first-time / no-prior-record fraud | No - nothing to match against | Yes - evidence-based, not match-based |
| Cost per investigated case | Match is cheap; working it manually is ~$2,500 | ~$150 per case |

Read the table as an SIU director would: the left column is where a match report leaves you, and the right column is where a case has to end up before it is defensible. The distance between them is the investigation - 15+ phases run in parallel on each flagged claim, producing a finding a human SIU lead reviews rather than a score that hands the work back to a human who then does it. That is the difference between a lead and a resolution.

| Network | Operator | Model | Strongest at | Structural limit |
| --- | --- | --- | --- | --- |
| ISO ClaimSearch | Verisk | Contributory database, ~95% P&C, 1.8B records | Duplicate and prior-loss matching at scale | Flags; does not investigate |
| NICB | Non-profit consortium (1,100+ members) | Referrals, VIN/theft data, ring intel | Vehicle theft, organized rings, LE liaison | Referral lands on a human's desk |
| Shift IDN | Shift Technology | Cross-carrier intelligence network | Surfacing cross-carrier connections | Per-claim depth still manual |

Each of these is essential and none is a competitor to investigation - they are the industry's detection and matching infrastructure. The shared structural limit is the same across all three: they raise a flag, and the flag has to be worked by hand. For the deeper detection-vs-investigation contrast against the specific vendor behind ClaimSearch, see [Hesper AI vs. Verisk](/blog/hesper-vs-verisk/).

## A better network raises more flags - which widens the gap without an investigation layer

A better detection network surfaces more matches, which means a larger flag pile - and if investigation throughput is fixed at about 25% coverage, more and better flags produce more unworked leads, not less loss. This is the direct read on Shift IDN's expansion: improving the signal is real progress on detection, but the bottleneck moved downstream years ago, to the investigation layer, and a bigger flag pile does not move it.

The scale of the loss makes the arithmetic unforgiving. Per the [Coalition Against Insurance Fraud](https://insurancefraud.org/fraud-stats/), insurance fraud steals at least $308.6 billion every year from American consumers, and fraud is present in about 10% of property-casualty losses. That total spans lines a single network under-covers. Per the [Insurance Information Institute](https://www.iii.org/article/background-on-insurance-fraud), citing the same study, the breakdown inside that $308.6 billion is roughly $74.7 billion in life insurance, $45 billion in property-casualty, $34 billion in workers' compensation, and $7.4 billion in auto theft. Fraud does not concentrate where a match engine is strongest; it is distributed across lines, which is another way of saying the flag pile is large no matter how good the matching gets.

The mechanical point for a claims VP evaluating the stack: the loss-ratio lever is not the quality of the match. It is the share of matches that get resolved. If a carrier improves detection and lifts the number of good flags by some margin while investigation coverage stays at 25%, the incremental flags mostly go unworked - they are paid, denied without full work, or queued. The leakage that survives is not a detection failure. It is a downstream capacity failure. A network that raises more flags without a matched increase in investigation capacity widens the coverage gap it just made more visible.

> The bottleneck in fraud stopped being detection years ago. Carriers can already flag far more suspicious claims than they can investigate. Adding a better matching network raises the number of leads; it does not raise the number of leads that become resolved cases. The constraint is investigation throughput, and no amount of additional matching relieves it.
>
> - Hesper AI product research

| Flagged-claim coverage: manual SIU vs an investigation layer (Hesper internal benchmark) | Value | Share |
| --- | --- | --- |
| Manual SIU coverage of flags | ~25% | 25% |
| Investigation-layer coverage | 100% | 100% |

## Where an AI investigation layer fits

An AI investigation layer sits directly downstream of the networks: the network raises a flag, and the investigation layer resolves that flag end-to-end with an audit-ready file. It is complementary to ISO ClaimSearch, NICB, and Shift IDN - not a replacement for any of them - and it can also run standalone. The industry's contributory data infrastructure is not the problem an investigation layer solves; working the flags that infrastructure produces is.

Hesper AI takes a flagged claim - whether the flag came from a ClaimSearch match, an NICB referral, an IDN connection, or a FRISS or Shift score - and runs 15+ investigation phases in parallel on it: document forensics, statement and EUO cross-reference, timeline reconstruction, financial pattern analysis, and network analysis, among others. It completes a case in 2-4 hours rather than 14+ days, at roughly $150 per case versus about $2,500 manually, and lifts throughput from around 10 investigations per investigator per month to 800+. Because every flagged claim can be worked, coverage moves from about 25% to 100%. This is the shift from fraud detection to fraud resolution.

The positioning is precise, and it holds against the categories a network cannot address. A match engine cannot see first-time or synthetic fraud because there is no prior record; an investigation layer works from the actual documents, metadata, and story of the claim, so it does not depend on a match existing at all. That is why an AI investigation layer catches what a network structurally misses - not because it has more data, but because it asks a different question about each claim. A carrier keeps its ClaimSearch contribution, its NICB membership, and any intelligence network, and adds the layer that investigates what they raise.

For a compliance officer, the defensibility is the reason this layer clears review. Every phase Hesper runs is logged with its sources, reasoning, and timestamps, so each finding is produced as an audit-trail-native record that satisfies California 10 CCR 2698.36's documented-decision requirement and the antifraud-plan obligations under NAIC Model Act 680. When a state DOI examiner pulls a case, or an NICB or law-enforcement handoff needs a file, the reconstructable record is already there. The investigator's role shifts from execution to decision-making: the agent produces the evidence, the human adjudicates. To see how this sits within the full fraud-tech stack, the layered model is covered in [prevention vs. detection vs. investigation](/blog/insurance-fraud-prevention-vs-detection-vs-investigation/).

## Key takeaways

- A cross-carrier fraud data network answers one question - have we seen this claim, person, VIN, or provider before - and that match is a lead, not a verdict; ISO ClaimSearch, NICB, and Shift IDN all occupy the detection and matching layer, not the investigation layer beneath it.
- These networks catch anything with a prior record extremely well: ClaimSearch matches a claim against 1.8 billion records from about 95% of the US P&C market, and NICB adds VIN/theft data, ring intelligence, and law-enforcement liaison across 1,100-plus member companies.
- The limits are structural, not data-quality problems: a match engine is blind to fraud outside its contributing footprint and, more importantly, to first-time and synthetic fraud with no prior record - a category that grew from about $8 billion in 2020 to more than $30 billion by mid-2025.
- A better network raises more flags, but if investigation throughput stays at about 25% coverage, more and better matches produce more unworked leads rather than less loss - so the loss-ratio lever is the share of flags resolved, not the quality of the match.
- An AI investigation layer is complementary to these networks and standalone-capable: it takes each flagged claim and runs 15+ phases in parallel in 2-4 hours instead of 14+ days at roughly $150 versus about $2,500, lifting flagged-claim coverage from about 25% to 100% - from fraud detection to fraud resolution.

## Frequently asked questions

### What is a cross-carrier fraud data network?

A cross-carrier fraud data network is a shared or consortium database that checks an incoming insurance claim against claim history from other carriers to surface matches - duplicate claims, prior losses, known fraud rings, or flagged vehicles and providers. The three most common in US P&C are ISO ClaimSearch (Verisk), which holds over 1.8 billion claims and covers roughly 95% of the market across 2,800-plus contributors; NICB, a non-profit backed by more than 1,100 member companies; and newer intelligence networks such as Shift Technology's IDN. All three answer one question: have we seen this before? That match is a lead. It flags a claim for review; it does not investigate or resolve it. A human investigator still works the flag downstream.

### What does ISO ClaimSearch catch, and what does it miss?

ISO ClaimSearch is strongest at anything with a prior record. Because it holds over 1.8 billion claims from roughly 95% of the US P&C market, it reliably catches duplicate or double-dipped claims filed across carriers, prior-loss history, salvage and theft records, and matches to known fraud rings and provider watchlists. What it misses is structural, not a data-quality problem: it cannot see fraud in non-contributing carriers, it lags on data refresh, and - most importantly - it cannot flag first-time or synthetic fraud that has no prior record to match against. It also stops at the flag. ClaimSearch tells you a claim resembles others; confirming whether this specific claim is fraudulent, with documented evidence, is investigation, which the network does not perform.

### Is NICB the same as ISO ClaimSearch?

No, though they are connected. NICB (National Insurance Crime Bureau) is a non-profit supported by more than 1,100 property-casualty insurers, focused on preventing and defeating insurance fraud and vehicle theft through investigation support, member questionable-claim referrals, ring intelligence, and law-enforcement liaison. Its public tools include VINCheck for vehicle-theft history and its Hot Wheels and Hot Spots theft reports. ISO ClaimSearch is Verisk's commercial contributory claims database; NICB members access questionable-claim data through it. The two are complementary: NICB adds investigative coordination and vehicle-crime intelligence on top of the shared claims data. Neither runs an end-to-end investigation of an individual flagged claim - both surface intelligence that a human SIU investigator then has to work.

### If a cross-carrier network flags a claim, why isn't the fraud caught?

Because a flag is where the work starts, not where it ends. A match tells an investigator a claim is worth examining; someone still has to run the 15-plus investigation phases - document forensics, statement cross-reference, timeline reconstruction, financial and network analysis - and produce a documented finding. Manual SIU investigation takes 14-plus days per case, and one investigator can carry only about 200 cases. The result is a capacity wall: US carriers fully investigate only about 25% of flagged claims. Rules-based and match-based flagging also carries a 60-85% false-positive rate, so much of the flag pile is triage noise. Better networks raise more flags, but if investigation throughput is fixed, more flags means more unworked leads - not less loss.

### Can a cross-carrier data network detect new or AI-generated fraud?

Not well, by design. A match-based network can only recognize what already exists in shared history. First-time fraud, synthetic identities, and AI-generated claim photos or documents produce claims with no prior record to match against, so they pass the network clean. This is a growing blind spot: synthetic identity fraud rose from roughly $8 billion in 2020 to more than $30 billion by mid-2025, and UK insurer Admiral reported a 71% year-over-year increase in fraud in 2025, with AI-generated evidence a contributing factor. Catching novel fraud requires evidence-based investigation - examining the actual documents, metadata, and story of the claim - rather than matching it against past claims. That is investigation, not detection.

### Does Hesper AI replace ISO ClaimSearch, NICB, or Shift IDN?

No. Hesper sits downstream of them and is complementary, not a replacement. Cross-carrier networks are the industry's detection and matching layer - they answer 'have we seen this before?' Hesper occupies the investigation layer beneath them, taking a flagged claim and resolving it end-to-end. A carrier keeps its ClaimSearch contribution, NICB membership, and any intelligence network, and adds Hesper to investigate the flags those systems raise. Hesper runs 15-plus investigation phases in parallel on each flagged claim and returns an audit-ready report in 2-4 hours instead of 14-plus days, lifting flagged-claim coverage from about 25% to 100%. Replacing the industry's contributory data infrastructure is not the problem Hesper solves; working the flags it produces is.

### How does adding an investigation layer change the ROI of a fraud data network?

It converts flags into resolved cases. A cross-carrier network's value is capped by how many of its flags actually get investigated - and at roughly 25% coverage, most do not. Manual investigation costs about $2,500 per case and clears roughly 10 cases per investigator per month. An autonomous investigation layer runs each flagged claim for about $150 and lifts throughput to 800-plus cases per investigator per month, making 100% flag coverage economically possible. Against a backdrop of $308.6 billion in annual US insurance fraud - roughly 10% of P&C losses - the constraint was never the quality of the match. It was the capacity to work the match. The investigation layer removes that constraint.
