A cross-carrier fraud data network answers exactly one question: have we seen this claim, person, vehicle, or provider before? That match is a lead, not a verdict. ISO ClaimSearch, NICB, and newer intelligence networks like Shift's IDN check an incoming claim against the industry's shared claim history and surface anything with a prior record - a duplicate claim filed at another carrier, a known ring, a salvaged VIN, a flagged provider. What none of them do is investigate the claim they flag. That work still lands on a human SIU investigator's desk.
This matters because the two questions get conflated in procurement. A match engine tells you a claim resembles others in the system. It does not tell you whether this specific claim is fraudulent, with documented evidence a state DOI examiner or a court would accept. The first is detection. The second is investigation. They are different layers of the stack, and buying more of one does not do the job of the other.
This post is written for the SIU director who runs ISO ClaimSearch and NICB queries daily and already knows a match report is a starting point, not a finish line. It covers what the three main networks are, what they catch well, what they structurally miss, how the detection network and the investigation layer differ question-for-question, and why a better network - the direct read on Shift IDN's 2026 expansion - raises more flags without closing the gap. Detection is upstream; investigation is downstream. For the wider three-layer model this sits inside, see prevention vs. detection vs. investigation.
What a cross-carrier fraud data network is
A cross-carrier fraud data network is a shared or consortium database that checks an incoming insurance claim against claim history contributed by other carriers, then surfaces matches - duplicate claims, prior losses, known rings, and flagged vehicles or providers. It is a matching engine. It answers whether the industry has seen a claim like this before; it does not resolve whether this claim is fraudulent.
Three networks run the US P&C market, and they sit at different points. ISO ClaimSearch, operated by Verisk, is the largest. Per Verisk's own description of ClaimSearch as the backbone of the P&C claims ecosystem, it holds over 1.8 billion US claims records, represents roughly 95% of the US P&C market, draws from 2,800-plus contributors, and is queried by around 200,000 claims professionals every day. When a claim is submitted, ClaimSearch matches it against that history and returns any prior-loss, duplicate, or watchlist hits. It is the industry's matching layer, and it is essential infrastructure.
NICB, the National Insurance Crime Bureau, is a different animal - not a commercial database but a non-profit consortium. Per public NICB reference material, it is supported by more than 1,100 property-casualty and self-insured companies and is focused on preventing, detecting, and defeating insurance fraud and vehicle theft. Its member materials describe coverage of roughly 96% of personal-auto and about 82% of all P&C premiums. NICB runs the public VINCheck lookup for vehicle-theft and salvage history and publishes its Hot Wheels (top stolen vehicles) and Hot Spots (vehicle-theft geography) reports. Its value is referrals, ring intelligence, and law-enforcement liaison - all of which still hand off to a human investigator.
Shift Technology's IDN (Insurance Data Network) is the newest of the three - a cross-carrier intelligence network that surfaces connections across participating carriers' claims. It improves the signal, meaning it finds more cross-carrier links than any one carrier could see alone. All three - ClaimSearch, NICB, and IDN - occupy the detection and matching layer. None occupies the investigation layer beneath them. That layer is still manual SIU, and it is the one a data network cannot fill by adding more data.
What these networks catch well
Cross-carrier networks are strongest at anything with a prior record. Because they match an incoming claim against a large body of shared history, they reliably catch duplicate and double-dipped claims filed across carriers, prior-loss history, salvage and theft records, and hits against known fraud rings and provider watchlists. Where a claim resembles something already in the system, a match engine is fast, cheap, and hard to beat.
The scale is the point. A carrier querying ClaimSearch is checking a single claim against 1.8 billion records from 95% of the market in seconds. No manual process reaches that. If the same claimant filed a similar loss at three other carriers, or if the VIN was previously totaled, or if the treating provider is on a watchlist, the match surfaces it instantly. This is genuine, high-value work, and it is the reason every serious SIU runs these queries daily.
NICB's vehicle-crime intelligence is a clear example of the category done well. VINCheck lets an investigator confirm whether a vehicle was reported stolen or declared salvage before a claim is paid. Hot Wheels and Hot Spots tell an SIU which makes and which metro areas are being targeted, which sharpens where to look. On organized rings, the consortium model matters: one carrier's questionable-claim referral becomes intelligence the whole membership can use, and NICB's law-enforcement liaison turns that intelligence into arrests. This is the sort of pattern work that no single carrier can do alone, and it is exactly what a shared network is built for.
Detection and investigation are different questions
A cross-carrier network answers 'have we seen this claim, person, VIN, or provider before?' - a matching question against shared history. Investigation answers 'is this specific claim fraudulent, and here is the documented evidence' - a resolution question about one claim. A network is excellent at the first and does not attempt the second. Treating a match report as a resolved case is the error; a match is a lead that still has to be worked.
What they structurally miss
The limits of a cross-carrier network are structural, not a data-quality problem you can fix with more contributors. A match engine can only recognize what already exists in shared history. That single design fact produces four gaps: it flags but does not investigate, it is blind outside its contributing footprint, it cannot see first-time or synthetic fraud, and organized rings can vary their details to stay below the match threshold.
They flag; they do not investigate
A match is where the work starts, not where it ends. Once a network flags a claim, someone still has to run the investigation - document forensics, statement cross-reference, timeline reconstruction, financial and network analysis - and produce a documented finding. Manual SIU investigation takes 14+ days per case, and one investigator can carry only 200+ cases at once. The result is a capacity wall: across US P&C carriers, only about 25% of flagged claims are fully investigated. Rules-based and match-based flagging also carries a 60-85% false-positive rate, so a large share of the flag pile is triage noise before any real fraud is confirmed. The coverage math behind this is laid out in why most flagged insurance claims are never fully investigated.
Coverage gaps and data latency
A contributory network only sees what its members contribute. ClaimSearch covers roughly 95% of the US P&C market, which means - by simple derivation, not a sourced stat - a match engine is structurally blind to fraud in the remaining share of non-contributing volume, and to anything filed with a carrier that does not participate. NICB represents about 82% of P&C premiums, leaving a long tail of non-member exposure. Contribution and refresh cadence also introduce latency: a claim filed elsewhere last week may not yet be matchable this week. And the standard data caveat applies - garbage in, garbage out. A match is only as good as the record it matches against.
Novel and first-time fraud with no prior match
This is the gap that is growing fastest. A match-based network cannot flag fraud that has no prior record, because there is nothing to match against. First-time claims, synthetic identities, and AI-generated photos or documents pass the network clean. Per Claims Journal, citing Reinsurance Group of America, synthetic identity fraud grew from roughly $8 billion in 2020 to more than $30 billion by mid-2025. The same report notes UK insurer Admiral saw a 71% year-over-year increase in fraud in 2025, with AI-generated evidence a contributing factor. This is precisely the category a match engine is structurally unable to see - and it is the category expanding fastest.
Organized fraud that stays below the match threshold
Sophisticated rings understand how matching works and engineer around it. By varying identities, addresses, phone numbers, and treating providers just enough, a ring can keep any single claim below the threshold that would trigger a hard match. A fuzzy near-match may still surface, but a near-match is a lower-confidence lead that a human has to confirm - which pushes it right back into the same capacity wall. The network did its job by surfacing the possibility; resolving whether it is real is investigation, and investigation is where the throughput ceiling sits.
A cross-carrier network answers 'seen this before?' and stops. First-time fraud, synthetic identities, and AI-generated evidence have no prior record to match, so they pass clean - and every real match still lands on a human investigator who can work only about a quarter of the flags. The gap is not data quality; it is the investigation layer beneath the flag.
Detection network vs investigation layer
Side by side, the network's job and the investigation layer's job are different questions, and the difference is not one of degree. A network answers whether a claim has been seen before and returns a match instantly; the investigation layer answers whether a claim is fraudulent and returns documented evidence. Buying more matching capacity does not add investigation capacity, and vice versa.
Read the table as an SIU director would: the left column is where a match report leaves you, and the right column is where a case has to end up before it is defensible. The distance between them is the investigation - 15+ phases run in parallel on each flagged claim, producing a finding a human SIU lead reviews rather than a score that hands the work back to a human who then does it. That is the difference between a lead and a resolution.
Each of these is essential and none is a competitor to investigation - they are the industry's detection and matching infrastructure. The shared structural limit is the same across all three: they raise a flag, and the flag has to be worked by hand. For the deeper detection-vs-investigation contrast against the specific vendor behind ClaimSearch, see Hesper AI vs. Verisk.
A better network raises more flags - which widens the gap without an investigation layer
A better detection network surfaces more matches, which means a larger flag pile - and if investigation throughput is fixed at about 25% coverage, more and better flags produce more unworked leads, not less loss. This is the direct read on Shift IDN's expansion: improving the signal is real progress on detection, but the bottleneck moved downstream years ago, to the investigation layer, and a bigger flag pile does not move it.
The scale of the loss makes the arithmetic unforgiving. Per the Coalition Against Insurance Fraud, insurance fraud steals at least $308.6 billion every year from American consumers, and fraud is present in about 10% of property-casualty losses. That total spans lines a single network under-covers. Per the Insurance Information Institute, citing the same study, the breakdown inside that $308.6 billion is roughly $74.7 billion in life insurance, $45 billion in property-casualty, $34 billion in workers' compensation, and $7.4 billion in auto theft. Fraud does not concentrate where a match engine is strongest; it is distributed across lines, which is another way of saying the flag pile is large no matter how good the matching gets.
The mechanical point for a claims VP evaluating the stack: the loss-ratio lever is not the quality of the match. It is the share of matches that get resolved. If a carrier improves detection and lifts the number of good flags by some margin while investigation coverage stays at 25%, the incremental flags mostly go unworked - they are paid, denied without full work, or queued. The leakage that survives is not a detection failure. It is a downstream capacity failure. A network that raises more flags without a matched increase in investigation capacity widens the coverage gap it just made more visible.
Flagged-claim coverage: manual SIU vs an investigation layer (Hesper internal benchmark)
Where an AI investigation layer fits
An AI investigation layer sits directly downstream of the networks: the network raises a flag, and the investigation layer resolves that flag end-to-end with an audit-ready file. It is complementary to ISO ClaimSearch, NICB, and Shift IDN - not a replacement for any of them - and it can also run standalone. The industry's contributory data infrastructure is not the problem an investigation layer solves; working the flags that infrastructure produces is.
Hesper AI takes a flagged claim - whether the flag came from a ClaimSearch match, an NICB referral, an IDN connection, or a FRISS or Shift score - and runs 15+ investigation phases in parallel on it: document forensics, statement and EUO cross-reference, timeline reconstruction, financial pattern analysis, and network analysis, among others. It completes a case in 2-4 hours rather than 14+ days, at roughly $150 per case versus about $2,500 manually, and lifts throughput from around 10 investigations per investigator per month to 800+. Because every flagged claim can be worked, coverage moves from about 25% to 100%. This is the shift from fraud detection to fraud resolution.
The positioning is precise, and it holds against the categories a network cannot address. A match engine cannot see first-time or synthetic fraud because there is no prior record; an investigation layer works from the actual documents, metadata, and story of the claim, so it does not depend on a match existing at all. That is why an AI investigation layer catches what a network structurally misses - not because it has more data, but because it asks a different question about each claim. A carrier keeps its ClaimSearch contribution, its NICB membership, and any intelligence network, and adds the layer that investigates what they raise.
For a compliance officer, the defensibility is the reason this layer clears review. Every phase Hesper runs is logged with its sources, reasoning, and timestamps, so each finding is produced as an audit-trail-native record that satisfies California 10 CCR 2698.36's documented-decision requirement and the antifraud-plan obligations under NAIC Model Act 680. When a state DOI examiner pulls a case, or an NICB or law-enforcement handoff needs a file, the reconstructable record is already there. The investigator's role shifts from execution to decision-making: the agent produces the evidence, the human adjudicates. To see how this sits within the full fraud-tech stack, the layered model is covered in prevention vs. detection vs. investigation.
Key takeaways
- A cross-carrier fraud data network answers one question - have we seen this claim, person, VIN, or provider before - and that match is a lead, not a verdict; ISO ClaimSearch, NICB, and Shift IDN all occupy the detection and matching layer, not the investigation layer beneath it.
- These networks catch anything with a prior record extremely well: ClaimSearch matches a claim against 1.8 billion records from about 95% of the US P&C market, and NICB adds VIN/theft data, ring intelligence, and law-enforcement liaison across 1,100-plus member companies.
- The limits are structural, not data-quality problems: a match engine is blind to fraud outside its contributing footprint and, more importantly, to first-time and synthetic fraud with no prior record - a category that grew from about $8 billion in 2020 to more than $30 billion by mid-2025.
- A better network raises more flags, but if investigation throughput stays at about 25% coverage, more and better matches produce more unworked leads rather than less loss - so the loss-ratio lever is the share of flags resolved, not the quality of the match.
- An AI investigation layer is complementary to these networks and standalone-capable: it takes each flagged claim and runs 15+ phases in parallel in 2-4 hours instead of 14+ days at roughly $150 versus about $2,500, lifting flagged-claim coverage from about 25% to 100% - from fraud detection to fraud resolution.