For a claims shared-services leader or the claims head at a third-party administrator, the blocker on AI investigation is not whether it works. It is that the cost has to land on somebody's expense line, and the three models a claims leader reaches for first are each closed off by something already written down: a NAIC guideline, a California regulation, and the accounting definition of what counts as a claim-specific expense.
Share-of-savings pricing, the "we take a cut of the fraud we stop" model, is prohibited for administrators inside its scope by NAIC Guideline GL-1090 section 9.A, which bars an arrangement whose effect is to make compensation "contingent upon savings effected in the payment of losses." Per-case client approval before each investigation runs into California 10 CCR section 2698.33(c)(2), which bars SIU contract provisions that "could provide disincentives to the referral and/or investigation of suspected insurance fraud." And absorbing the spend into the base administration fee buries it in unallocated loss adjustment expense, where it competes with the administrator's own margin rather than the client's loss budget.
What is left is the one model that works: a flat per-claim investigation charge, applied at the point of referral, on every eligible claim, disclosed in the administration agreement before the first claim is referred. GL-1090 section 9.C expressly permits compensation based on "the number of claims paid or processed." Underneath that charge sits the accounting fork that decides everything else - allocated versus unallocated loss adjustment expense, reported since 1998 as defense and cost containment versus adjusting and other. Get the fork right and the charge is chargeable to the client's loss fund. Get it wrong and the administrator eats it, and the program dies in month two.
The multi-book structure that looks like the hardest possible place to deploy AI investigation is actually the easiest place to prove it. One workflow, N books, N independent proof points, and a per-claim unit cost that only a shared operation can amortize. The Coalition Against Insurance Fraud and Aon found in 2024 that national carriers report expense per investigation roughly 50% below regional carriers, which is the shared-services thesis stated by the industry's own benchmark. This post covers the allocation math, the accounting fork, the delegated-obligation mechanics, the multi-tenancy question, and the order in which books should go live. For the stage-by-stage view of what actually automates across a claim, start with the complete guide to claims automation.
A shared-services claims operation cannot buy investigation, it can only allocate it
Claims shared services is an operating structure in which one claims organization administers several books, legal entities, or client carriers under separate agreements. It runs as a cost center, so it owns no loss ratio it can improve by spending more. Every purchase resolves into an allocation question - which book pays, on which expense line, under which contract - before it resolves into a business question.
Start with the size of the pool that decision sits inside. For the year ended December 31, 2025, the NAIC full year property and casualty results put US net premiums earned at $958,726 million and loss expenses incurred at $86,003 million. Loss adjustment expense is therefore about 9.0% of earned premium. The same report shows a 66.5% net loss ratio, a 25.8% expense ratio, and a 92.9% combined ratio. Roughly nine cents of every earned premium dollar is the cost of handling claims, and that nine cents is the pool a shared-services operation competes inside.
Fraud investigation is a small slice of it. The 2024 Insurer SIU Benchmarking Study from the Coalition Against Insurance Fraud and Aon, its sixth iteration, covering 35 participating property and casualty carriers, puts SIU budgets at about 0.12% of premium, down from 0.13% two years earlier. Against a loss-adjustment pool worth roughly 9% of earned premium, SIU spending runs on the order of 1.3% of everything the industry spends adjusting claims. The two ratios come from different years, the SIU share from the 2024 study and the premium base from full-year 2025 results, so treat 1.3% as an order of magnitude rather than a decimal.
That is the first uncomfortable fact for a shared-services leader. The line you are being asked to grow is among the smallest on the claims expense sheet, and it is the only one that has to be justified separately to every book that touches it.
The unit cost is worse than it looks, because nobody measures it the same way twice. The Coalition and Aon put budget expense per investigation just above $1,200 in 2024, up about 11% from two years earlier. That figure is the SIU department's budget divided by its investigations. It excludes adjuster hours spent on the file, outside vendor invoices booked to defense and cost containment, and counsel time. The fully loaded number, the SIU slice plus everything that lands elsewhere on the ledger, runs roughly double at about $2,500 per manually investigated case. The two numbers are not competing estimates of the same thing. One is a departmental budget slice; the other is what the investigation actually consumed.
Automated investigation changes the arithmetic by changing the unit. Hesper runs 15+ investigation phases in parallel on a flagged claim and returns an audit-ready file in hours rather than weeks, at roughly $150 per case against ~$2,500 for the manual equivalent. For a single carrier that is a cost reduction. For a shared-services operation it is something more useful: a unit price small enough to put on a rate card and charge per claim, which is the only form in which a cost center recovers anything at all. A single-carrier business case runs that arithmetic once. A shared-services case runs it N times, against N different contracts, with N different answers to the question of who pays.
ALAE or ULAE: the line item that decides the business case
Allocated loss adjustment expense is claim-specific: defense, litigation and medical cost containment tied to an identified claim. Unallocated is everything else, the administrator's overhead of running a claims operation. Under the NAIC definitions effective January 1, 1998, the same fraud investigator falls on either side of that line depending on the capacity they are working in.
Texas Department of Insurance Bulletin B-0002-98, issued January 15, 1998, reproduces the NAIC lists verbatim. Under allocated loss adjustment expense, described as "defense, litigation and medical cost containment expenses, whether internal or external," item (v) covers "Fees or salaries for appraisers, private investigators, hearing representatives, reinspectors and fraud investigators, if working in defense of a claim, and fees or salaries for rehabilitation nurses, if such cost is not included in losses." Under unallocated, which the bulletin defines as the expenses in the loss adjustment expense group other than the allocated ones, item (iv) covers "Fees or salaries for appraisers, private investigators, hearing representatives, reinspectors and fraud investigators, if working in the capacity of an adjuster," and item (i) covers "Fees of adjusters and settling agents." The bulletin notes the lists are "not intended to be all inclusive."
Read those two items next to each other. The job title is identical in both. The only words that move the expense from one bucket to the other are "if working in defense of a claim" versus "if working in the capacity of an adjuster." That single phrase decides whether investigation spend is allocable to a claim or absorbed as overhead, and AI investigation spend inherits the same fork.
Washington codified the same line. WAC 284-24D-020, effective July 22, 2007, defines allocated loss adjustment expense as "defense and cost containment expenses paid or incurred for defense, litigation and medical cost containment expenses and services," and expressly excludes "expenses or costs associated with external or internal claims adjusting staff." Same fork, written from the other direction.
One naming note, because the terms diverged after 1998. In the annual statement and Schedule P these buckets are reported as defense and cost containment, or DCC, and adjusting and other, or A&O. ALAE and ULAE remain the universal shorthand in claims conversations. This post uses DCC and A&O from here.
Now the consequence. An AI investigation platform bought as a departmental subscription for the shared-services operation and booked to A&O is fixed overhead the administrator absorbs, competing directly with the administrator's own margin. The identical capability, scoped and invoiced per claim as claim-specific investigative work performed in defense of a claim, is allocable to that claim and follows the claim's expense treatment, which in deductible, self-insured retention and program structures reaches the client or insured layer. Treaty terms determine whether allocated expense is shared with a reinsurer, and those terms vary contract to contract, so do not build a business case on recovery nobody has read in the actual treaty.
What makes a claim-specific allocation defensible
An allocation survives a claim file audit when it ties to a specific claim, with a specific record of what was done, by what method, and when. That is a documentation requirement before it is a technology one. It is also the reason a scored recommendation is a weak basis for a per-claim charge and a documented investigation is a strong one. Hesper's output is audit-trail-native by design: every step is logged with sources, reasoning and timestamps and attached to the claim record. That artifact is what a per-claim charge is defending when a client's audit asks why book A was billed for 412 investigations last quarter and book B for 96.
The underlying point predates AI pricing entirely. A 1996 Casualty Actuarial Society discussion paper on TPA service pricing and incentive contracts concluded that "the aggregate approach used in insurance regarding unallocated adjustment expenses (ULAE) is not appropriate for pricing TPA products." Aggregate overhead does not price a service that someone else consumes claim by claim. Per-claim work needs per-claim accounting, and that was true thirty years before anyone was allocating an AI investigation charge.
The same investigation, two expense buckets. Booked to A&O it is the administrator's overhead, absorbed once and spread across every book. Scoped as claim-specific defense and cost containment it lands in DCC on the individual claim and follows that claim's expense treatment out to the client or deductible layer, book by book.
The chargeback models that survive contact with the contract
There are four ways to recover the cost of AI investigation from the books or clients that consume it. One is prohibited outright for administrators inside GL-1090's scope. One works commercially but creates a compliance problem most buyers do not see coming. Two survive both the accounting rules and the SIU contract rules, and only one of those two preserves allocability.
Start with the prohibition, because it kills the model claims leaders reach for first. GL-1090 section 9.A: "A TPA shall not enter into an agreement or understanding with a payor or, with regard to workers' compensation, a payor, employer or co-employer in which the effect is to make the amount of the TPA's commissions, fees, or charges contingent upon savings effected in the payment of losses covered by the payor's obligations. This provision shall not prohibit a TPA from receiving performance-based compensation for providing hospital or other auditing services, from providing managed care or related services, or from being compensated for subrogation expenses."
Section 9.C then says what is left open: "This section shall not prevent the compensation of a TPA from being based on premiums or charges collected or the number of claims paid or processed." Share of fraud avoided is closed. Per claim is open, by name. That is not a vendor preference, it is the shape of the rule, and it is why Hesper prices a flat per-case rate and takes no contingent or success-based compensation anywhere. The per-case unit economics behind that rate are in the Hesper pricing guide.
The second model fails somewhere less obvious. A per-case charge that the client approves claim by claim looks like prudent cost control, and in most vendor categories it would be. Read it against California 10 CCR section 2698.33(c)(2), which requires that an SIU contract "Not include provisions that could provide disincentives to the referral and/or investigation of suspected insurance fraud," and it reads differently: a design in which the cheapest path for a client's own claims staff is to decline the investigation. The regulation is written around effect, not intent. The same section requires the contract to "Specify all SIU or integral anti-fraud personnel duties and functions to be performed by the parties to the contract and how the insurer monitors performance of the contract responsibilities," to not purport to relieve the insurer of any obligation, and to "Expressly require the contracted entity to comply with all applicable provisions of the IFPA and this article." Subsection (c)(5) flows all of it down to subcontractors and sub-subcontractors, and subsection (d) set April 1, 2021 as the deadline for existing contracts to conform.
The third row is the design that holds. Standing authority to investigate every flagged claim, a flat per-claim charge, and disclosure up front. GL-1090 section 10 requires the administrator to disclose to the payor all charges, fees and commissions it receives, which means the rate belongs in the administration agreement rather than in an invoice line nobody negotiated. Section 11.A(1) adds the governance sentence a multi-book operation should tape to the wall: "The insurer may have more than one master services agreement with a given TPA, but it must be unambiguous which master services agreement applies for a given claim." One rate card, one referral trigger, and an unambiguous mapping from claim to agreement.
The rate itself matters for a reason that is not obvious. A per-case charge near $2,500 invites a conversation about every case, because it is large enough for a claims manager to have an opinion about. Every one of those conversations is a moment where an investigation does not happen. At roughly $150 per case the charge stops being a decision and becomes a rate, which is precisely what makes standing authority acceptable to a client and what holds coverage at 100% of flagged claims instead of the ~25% a manual operation reaches. The compliance argument and the economic argument point the same direction here, which is rare enough to be worth naming.
Scope caveat worth stating to your own compliance team
GL-1090 is an NAIC Guideline rather than a model law, and its scope covers life, annuity, health, stop-loss and, in one version, workers' compensation administration. It does not reach general property, auto or liability claims administration, and state TPA statutes vary in scope and in what they borrow from the guideline. Treat it as the clearest written statement of the structure regulators expect, not as the statute governing your auto book. Model #900 carries a scope line of its own running the other way: section 1 states it is not intended to cover claims involving workers' compensation, fidelity, suretyship or boiler and machinery insurance, and Model Regulation #902 section 2 repeats that exclusion. The California SIU regulations carry no such limit and reach the fraud-referral side of the work regardless of line.
Who actually owns the SIU obligation when a TPA administers the book
Functions delegate. Obligations do not. Every state that has written this down says it in nearly the same words: an insurer may contract out the performance of SIU work, and remains answerable for it. The contract moves the labor, not the liability, which is why the carrier client will want visibility into every investigation run on its book.
California is the most explicit. 10 CCR section 2698.30(p) defines an SIU as "an insurer's unit or division that is established to investigate suspected insurance fraud" and adds that the SIU "may be comprised of insurer employees or by contracting with other entities" for the purpose of complying with the Insurance Frauds Prevention Act. Section 2698.31 states the whole obligation in one sentence: "The insurer shall comply with applicable sections of the IFPA and these regulations regarding the establishment, operation and continuous existence of an SIU." And section 2698.33(a) closes the loop: any contract for the performance of SIU duties "shall not relieve the insurer of any obligation under these regulations or the IFPA."
The definition of who counts is broad. Section 2698.30(f) defines a "contracted entity" as "any entity with which an insurer contracts to perform SIU or integral anti-fraud personnel duties or functions on behalf of the insurer," and expressly includes "subcontractors and sub-subcontractors." The regulation carves out discrete task vendors, naming surveillance, accident reconstruction, background checks, scene inspections, social media checks, interviews, witness canvassing, AOE/COE investigations, activity checks and "database vendor services including, but not limited to, ISO ClaimSearch, LexisNexis, and Accurint." Then it closes the carve-out again: entities that "participate in the claims handling function of the insurer," that "make decisions on behalf of the insurer with respect to the insurer's SIU or integral anti-fraud functions," or that contract with others to perform those duties, are contracted entities. A TPA administering claims sits squarely inside that. The definition also excludes an insurer's own affiliates and subsidiaries, which is why an in-group shared-services entity and an unaffiliated administrator do not start from the same place under this regulation. For the section-by-section treatment of the California regime, see the guide to California 10 CCR 2698 SIU compliance.
Other states land in the same place with different words. The New York Department of Financial Services states plainly that "New York Insurance Law permits insurers to use the services of an outside contractor to perform the functions of an SIU," while requiring the insurer to file copies of all executed contractor contracts with its Fraud Prevention Plan, and to name each investigator with title, job description and geographic location. There is no minimum investigator count in New York; companies "must justify the adequacy of these resources." Florida Statutes section 626.9891 lets an insurer "Contract with others to investigate and report possible fraudulent insurance acts by insureds or by persons making claims for services or repairs against policies held by insureds," treats that contractor as part of the anti-fraud investigative unit, and requires the insurer to electronically file a copy of the executed contract with the Division of Investigative and Forensic Services.
GL-1090 says the same thing about administration generally. Section 7.B: a payor using a TPA "shall retain responsibility" for benefits, premium rates, collateral and reimbursement procedures, underwriting criteria and claims payment procedures. Section 7.C: an insurer using a TPA "is responsible for the acts of the TPA" and for producing the TPA's relevant books and records to the commissioner on request. Section 7.E resolves ties: "In the event of a dispute between the payor and the TPA regarding which of them is to fulfill a lawful obligation ... the payor shall fulfill such obligation." Section 7.G puts the duty to provide for competent administration on the payor. Section 7.H requires a semiannual review, including at least one on-site audit of the TPA's operations, where the TPA administers covered benefits for more than one hundred individuals on behalf of an insurer and the two are not affiliated, and specifies that "The cost of such reviews or audits shall be borne by the insurer and not reimbursed by the TPA."
Two records provisions follow from that and matter to any investigation platform. Section 5.A requires the TPA to "maintain and make available to the payor complete books and records of all transactions performed on behalf of the payor," kept "for a period of not less than five (5) years from the date of their creation." Section 5.G preserves the TPA's own continuing access "notwithstanding any contractual agreements between the payor and the TPA that operate to the contrary." Whatever an investigation layer produces is part of the payor's claim file: portable at termination, retained for five years, and producible to a regulator on request.
The filed-document version of this appears in the NAIC Antifraud Plan Guideline #1690, adopted October 29, 2020. Section 4.C(7) requires an insurer using an external SIU to name the company and give contact information, to specify "the internal person(s) or position(s) responsible for maintaining contact with the external company(ies)," and to describe "how they will monitor and/or gauge the external / third party's compliance with insurer antifraud mandates." That third requirement is the one that decides which vendors are viable in a delegated structure. Monitoring compliance in someone else's operation is a documentation exercise, and a scored output does not satisfy it. A complete investigative record does.
The SLA floor is a regulation, not a negotiation
The service levels in a claims administration agreement are negotiated. The service levels underneath them are not. NAIC Model #900 defines an insurer to include third party administrators, which lands unfair claims settlement standards on the administrator directly, and Model Regulation #902 sets the clock those standards run on.
Model #900 section 2.C: "'Insurer' means a person, reciprocal exchange, interinsurer, Lloyd's insurer, fraternal benefit society, and any other legal entity engaged in the business of insurance, including agents, brokers, adjusters and third party administrators." The prohibited practices that follow are not abstract for an administrator. Section 4.C bars "Failing to adopt and implement reasonable standards for the prompt investigation and settlement of claims arising under its policies." Section 4.F bars "Refusing to pay claims without conducting a reasonable investigation." Section 4.G bars "Failing to affirm or deny coverage of claims within a reasonable time after having completed its investigation related to such claim or claims."
Model Regulation #902 supplies the clock. Acknowledge receipt of a claim within fifteen days, and note section 6.A's closing line: "Notification given to an agent of an insurer shall be notification to the insurer." Respond to a department inquiry about a claim within twenty-one days. Advise the first party claimant of acceptance or denial within twenty-one days of properly executed proofs of loss. If more time is needed, say so with reasons within those same twenty-one days, and then, per section 7.B, "If the investigation remains incomplete, the insurer shall, forty-five (45) days from the initial notification and every forty-five (45) days thereafter, send to the claimant a letter setting forth the reasons additional time is needed for investigation." Tender payment within thirty days of affirming liability where the amount is determined and not in dispute.
The scope of what counts is wide. Section 3.G defines investigation as "all activities of an insurer directly or indirectly related to the determination of liabilities under coverages afforded by an insurance policy or insurance contract." Section 4.B sets the documentation standard: "Detailed documentation shall be contained in each claim file in order to permit reconstruction of the insurer's activities relative to each claim." An AI investigation record is not an optional artifact against that sentence. It is the thing the sentence asks for.
The fraud carve-out is narrower than it is usually treated. Section 7.A provides that where "there is a reasonable basis supported by specific information available for review by the insurance regulatory authority that the first party claimant has fraudulently caused or contributed to the loss, the insurer is relieved from the requirements of this subsection; provided, however, that the claimant shall be advised of the acceptance or denial of the claim within a reasonable time for full investigation after receipt by the insurer of a properly executed proof of loss." Section 7.B carries the same carve-out against the extended-investigation clock, phrased around a reasonable basis for suspecting fraud. That buys a reasonable time for full investigation. It does not buy indefinite time, and it costs the 45-day letter cadence in the meantime.
Map a manual investigation onto that clock. Manual SIU investigation takes 14+ days per case, and 14 days is where the work starts rather than where it lands. A file that opens on day three of a claim and runs a fortnight or longer routinely crosses the twenty-one day mark, drops into the 45-day letter cadence, and then produces another letter every forty-five days until it closes. An investigation that closes in hours rather than weeks resolves inside the twenty-one day window and never generates the first letter.
In a shared-services operation that letter is not one letter. It is one letter per open investigation per book, produced by staff you allocate, tracked on a client scorecard you are graded against, and reviewed in a stewardship meeting where it is the most visible evidence anyone has about your investigation program. Cycle time here is not a claims-experience metric. It is a per-book operating cost with a compliance tail attached.
One workflow across N books means one defect across N books
Shared services concentrates the upside and the exposure in the same place. Model #900 makes an act an improper claims practice when it is committed with such frequency as to indicate a general business practice. A single workflow running across every book is, by construction, the fastest available way to establish frequency.
The text is section 3: an act is an improper claims practice if "A. It is committed flagrantly and in conscious disregard of this Act or any rules promulgated hereunder; or B. It has been committed with such frequency to indicate a general business practice to engage in that type of conduct." Section 6.A sets penalties at up to $1,000 per violation and $100,000 in aggregate, rising to $25,000 per violation and $250,000 in aggregate where the conduct is flagrant. Section 7 adds up to $25,000 per act and $250,000 aggregate for violating a cease and desist order, plus possible suspension or revocation of license.
One carrier's under-investigation pattern is one carrier's problem. A shared operation runs one intake rule, one referral threshold and one investigative workflow across every book it administers, so a defect in any of the three is replicated N times before anyone notices. Frequency is exactly what section 3.B tests for, and a shared workflow manufactures frequency.
Turn it around and the same mechanic runs in your favor. A workflow that is right is right N times. Across US property and casualty carriers, manual SIU teams fully investigate roughly 25% of flagged claims and the rest are paid, denied without full work, or queued indefinitely. Moving that book by book to 100% of flagged claims is the version of concentration you want: one control, applied identically, evidenced identically, across every entity you administer. The variance between per-book coverage numbers is itself the finding a shared-services leader should be reporting, because no single enterprise coverage figure exists in a multi-book structure.
The obligation is specifically enforceable, not merely billable. In Clear Blue Insurance Group v. Yachtinsure Services, reported by Insurance Journal on June 6, 2025, a TPA stopped adjusting claims after a $66 million arbitration award, and the US District Court for the Western District of North Carolina ordered it to resume. The ruling as reported noted that "The public has an interest in the insurance industry functioning effectively and reliably, which requires the prompt adjustment of claims." The narrow point for a shared-services leader is that claims administration is an obligation a court will order performed. Continuity of the investigative workflow across books is not only a service-quality question. For the evidentiary side of what that record has to withstand once a file becomes litigation, see the general counsel view of AI fraud investigation and litigation.
The measurement obligation is already written into filed documents. Antifraud Plan Guideline #1690 section 4.C(8)(b) asks an insurer to describe "The manner in which the insurer tracks SIU / investigative information for compliance purposes (i.e. number of SIU referrals received, number of investigations opened, outcome of investigations conducted, etc.)." Referrals received and investigations opened are two separate counts, and the gap between them is the coverage gap in a document a regulator holds. In a shared operation you file that gap once per entity, which is either N pieces of evidence that the model works or N copies of the same problem.
Five claims structures, five different answers to the same four questions. The table is the summary of everything above, and the last column is the thing that actually fails first in each structure.
Data segregation is architectural, not contractual
A confidentiality clause is a promise. Tenant isolation is a control. Roughly thirty jurisdictions now require the second. Under the NAIC Insurance Data Security Model Law, a registered administrator is itself a Licensee, and any vendor it gives access to nonpublic information is a Third-Party Service Provider, which puts a specific and non-delegable duty on the administrator.
Model #668 section 3.I defines a Licensee as "any Person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered pursuant to the insurance laws of this State," and section 3.P defines a Third-Party Service Provider as "a Person, not otherwise defined as a Licensee, that contracts with a Licensee to maintain, process, store or otherwise is permitted access to Nonpublic Information through its provision of services to the Licensee." Section 4.F then requires that a licensee "exercise due diligence in selecting its Third-Party Service Provider" and "require a Third-Party Service Provider to implement appropriate administrative, technical, and physical measures to protect and secure the Information Systems and Nonpublic Information that are accessible to, or held by, the Third-Party Service Provider."
Four more provisions shape the operating rhythm. Section 4.D(2)(i) requires the information security program to "Include audit trails ... designed to detect and respond to Cybersecurity Events and designed to reconstruct material financial transactions sufficient to support normal operations and obligations of the Licensee." Section 5.C makes the licensee complete the investigation of an event occurring in a third-party provider's system, or confirm and document that the provider did. Section 6.A requires notification to the commissioner within 72 hours. Section 4.I requires each insurer domiciled in the state to certify compliance in writing by February 15 each year.
The reach is wide enough that "which state's rule governs my architecture" has an unhelpful answer. Per the NAIC Cybersecurity Working Group adoption map dated April 1, 2026, 28 jurisdictions have adopted Model #668 and one is pending, with New York, New Jersey and Rhode Island shown under their own insurance data security provisions. An administrator serving client carriers across those jurisdictions cannot answer the segregation question per state. It has to answer it once, in the architecture.
There is a distinction worth holding precisely here, because it is often collapsed. Contributory data sharing is a consented, opt-in industry utility: carriers deliberately contribute claim data to a shared pool and get cross-carrier signal back. Verisk's ISO ClaimSearch is the long-standing example, and the strengths and limits of that model are covered in what cross-carrier fraud data networks can and cannot do. Incidental commingling is different: one client's claim data influencing another client's outcome without a consent model behind it. The first is legitimate and valuable. The second is what a TPA's master services agreements typically prohibit outright.
That distinction is architectural, so it has to be answered architecturally. Shift Technology, for example, describes its Insurance Data Network as "an agentic intelligence layer that assesses cross-carrier claim history, synthesizes key insights, and recommends relevant next actions for claims handlers." That is a deliberate and legitimate cross-carrier design with its own consent model, and Shift's public materials do not detail a confidentiality framework for multi-carrier administration environments one way or the other. The point is not that anyone is doing anything improper. It is that a cross-carrier premise and a TPA's per-client confidentiality obligations are different starting assumptions, and an administrator has to know which one its vendor was built on before a client asks.
The gap on the detection side is structural rather than a criticism. FRISS positions itself around trust automation for P&C insurers and addresses a single carrier with a single book: "your book of business," "your customers." Detection is upstream; investigation is downstream. Neither framing is wrong, but nobody at the detection layer is currently answering the multi-book deployment question, which leaves the administrator to answer it. The controls that answer it are tenant isolation, per-client key separation, no cross-tenant model training, and a documented posture that a client carrier's own third-party risk reviewer can read. Hesper holds SOC 2 Type I and does not train on customer data. The review a carrier client will run on you as its administrator is the same review it would run on a vendor one layer down, which is walked through in the procurement and AI vendor risk playbook.
The rollout sequence: what book one has to prove before book two starts
Sequence the rollout by contract and consent homogeneity, not by claim volume. Book one should be the book where standing authority to investigate flagged claims already exists, where the administration agreement does not require client sign-off on a new subprocessor, and where the antifraud plan amendment is a form rather than a negotiation.
The plan amendment is the item most often discovered late. Guideline #1690 section 2.D defines a material or substantive change as "any change, modification or alteration of the operations, standards, methods, staffing or outsourcing utilized by the insurer to detect, investigate and report suspected insurance fraud," and section 3.E requires the insurer to amend and submit the plan when one occurs. Adding an AI investigation layer is a change in method and usually in outsourcing at once. Florida separately requires the executed contract to be filed. New York requires executed contractor contracts to accompany the Fraud Prevention Plan, along with the name, title, job description and geographic location of each SIU investigator. California's section 2698.40 requires the SIU Annual Report within 90 days of the Department's notification, including total hours of insurer employee time spent on fraud investigations, California claims processed and referred, and for contracted SIU operations "a complete copy of the fully executed, existing contract, including all attachments and addenda." Every one of those is a per-book filing event rather than a one-time corporate task, and each one has to be complete before the workflow it describes goes live on that book.
Consolidation is available and it is worth using. Guideline #1690 section 4.B states that "One antifraud plan may cover several insurer entities if one SIU has the fraud investigation mission for all entities." California section 2698.40 similarly allows a primary reporting insurer within a holding company group to satisfy the SIU annual reporting requirement on behalf of other insurers in the group. That is the regulatory basis for shared claims services existing at all. It also concentrates the filing, which is the same double-edge as the workflow: one plan describing one method across every entity is either one clean answer or one repeated exposure.
Contract length decides the order more than fraud incidence does. The 1996 CAS work on TPA pricing catalogued service-length structures that have not changed much: twelve months, twenty-four months, life of the partnership, and life of the claim. A book on a twelve-month agreement can adopt a new per-claim charge at the next renewal with a rate-card conversation. A run-off book administered on a life-of-claim basis carries claims priced under an agreement written years ago, and adding a per-claim investigation charge to it is a repricing negotiation rather than a rollout step. Sequence renewals first, multi-year agreements second, run-off last, and do not let claim volume reorder that list.
One structural note that catches shared-services buyers off guard: the buying center is duplicated once per client. The entity that signs the software contract may not be the entity whose loss fund carries the charge, so a single approved business case has to survive N separate client-side reviews with different stakeholders, different risk appetites, and different renewal dates. The seat-by-seat map of who champions and who blocks inside one of those reviews is in the carrier buying center map. Multiply it by your client count and you have your real timeline.
Four numbers should be fixed on book one before book two opens. Fix means measured under a definition you have written down, not estimated in a steering meeting.
- Flagged-claim coverage, expressed per book. A shared operation has N coverage figures, not one, and the variance between them is the finding worth reporting.
- Cycle time from referral to closed investigative report, measured against the 21-day and 45-day marks in Model Regulation #902 rather than against an internal target.
- Fully loaded cost per investigated case, stated in both buckets: what landed in DCC and what stayed in A&O. If you cannot split it, you cannot charge it back.
- Referral acceptance ratio, tracked separately for adjuster referrals and automated referrals, because the two behave nothing alike.
The benchmark on that last number is unflattering and it is the one to put in front of a skeptical client. The Coalition and Aon found adjuster referrals were accepted 70% of the time in 2024 while referrals from automated fraud detection tools were accepted only 36% of the time, which means 64% of what the detection layer produced did not survive first contact with a human reviewer. That is the same phenomenon as the 60-85% false positive rate rules-based systems generate, seen from the receiving end. More detection alone does not produce more resolved files, which is why the investigation layer is where a shared operation should spend next. Adoption work at each site still has to happen, and the per-location version of that is covered in the claims operations manager transition guide.
What shared is actually worth: the scale number the industry already published
National carriers report expense per investigation roughly 50% below regional carriers. That is the shared-services thesis stated by the industry's own benchmark: investigation cost per case falls with scale. The open question for a shared operation is how to capture that gap without the national carrier's headcount, because headcount is the one input that is not growing.
The Coalition and Aon study puts the supply side in numbers. SIU headcount grew 0.5% from 2023 to 2024, against 1.4% in the prior study. Staffing runs at 0.67 SIU full-time equivalents per $100 million of gross written premium, down from 0.9 two years earlier. Each investigator carries 174 accepted referrals a year, up from 162. Field investigators average 11.6 referrals a month and desk investigators 17.9. The headcount splits 39% field, 35% desk and 14% management and supervisors, at an average salary just under $96,000, with 70% of respondents running a fully remote SIU structure. Referrals per investigator went up while investigators per dollar of premium went down. That is a capacity problem, and capacity problems do not resolve by hiring at 0.5% a year.
The 174 figure is a useful independent check on Hesper's published 200+ cases per investigator. Two different measurement traditions landing in the same neighborhood is corroboration rather than contradiction, and it means the shared-services capacity model can be built on a number the industry already recognizes.
Sixty percent of accepted referrals still come from adjusters, twenty-nine percent from automated detection tools, and ten percent from everything else. A shared-services operation that has bought detection and not investigation has spent money upstream of its actual constraint, and the referral mix is the cheapest way to show that to a client who believes the detection purchase already solved it.
The mechanism that closes the gap is throughput per investigator, not headcount. A manual investigator completes roughly 10 investigations a month. With automated investigation running 15+ phases in parallel on every flagged claim, the same investigator supervises 800+ cases a month and spends their time on the judgment calls: which findings hold, which need a human interview, which go to referral. The investigator's role shifts from execution to decision-making. That is the shape in which a shared operation gets the national-carrier unit cost without the national-carrier payroll.
Scale of balance sheet is not the variable, which is good news for mid-sized administrators. IBISWorld data current to June 2026 describes the US third-party administrators and insurance claims adjusters industry as "highly fragmented with no companies holding a market share greater than 5%," across roughly 123,000 businesses. The revenue figure attached to that industry code is a broad aggregate covering all administrators and adjusters including health, so it is not a property and casualty claims-administration number and should not be used as one. The fragmentation is the usable fact: nobody in this market wins on size. The scale that matters is per-workflow scale, and a workflow scales differently from a company.
Carrier groups are formalizing exactly this structure. Insurance Journal reported on April 13, 2026 that Old Republic launched Lodestar as an independent TPA brand, previously part of PMA Companies, serving middle-market and large employers, national carriers and distribution partners in all fifty states. Every operation set up that way runs the allocation math in this post on day one, and workers compensation is where administered claims and SIU obligations overlap most heavily, which is the line covered in the workers compensation use case.
One honest concession. Every large administrator is building adjuster-assist AI, and some of it is good. It is a different layer. Adjuster assist speeds the handling of a claim: summarizing the file, drafting correspondence, surfacing the next step. It does not investigate a flagged one. The stack runs prevention, then detection, then investigation, and the three are bought from different places for different reasons. Detection is upstream; investigation is downstream. Nobody in the administration market is currently claiming to run 15+ investigation phases in parallel on 100% of flagged claims across every book they administer, which is the specific gap a shared operation should be shopping for.
The sentence to hold on to through the whole procurement is short. Make every flagged claim investigable. In a single-carrier structure that is a coverage improvement. In a shared-services or TPA structure it is a product: a per-claim service, priced on a rate card, evidenced by a record, allocable to the claim that consumed it, and identical across every book you administer. That is the move from fraud detection to fraud resolution, expressed in the only currency a cost center can actually spend.
Key takeaways
- Share-of-savings pricing for investigation is closed off inside GL-1090's scope by section 9.A, which bars administrator compensation contingent upon savings effected in the payment of losses, while section 9.C expressly permits compensation based on the number of claims paid or processed.
- A per-case charge that a client approves claim by claim risks California 10 CCR section 2698.33(c)(2), which prohibits SIU contract provisions that could provide disincentives to the referral or investigation of suspected insurance fraud, because the cheapest path for the client becomes declining the investigation.
- The NAIC definitions effective January 1, 1998 put the same fraud investigator in allocated expense if working in defense of a claim and unallocated expense if working in the capacity of an adjuster, which is what decides whether AI investigation spend is chargeable to a client's loss fund or absorbed as administrator overhead.
- NAIC Model #900 section 2.C defines insurer to include third party administrators, so unfair claims settlement standards land on the administrator directly, and section 3.B's general business practice test means one shared workflow running across N books replicates any defect N times by construction.
- The Coalition Against Insurance Fraud and Aon found national carriers report expense per investigation roughly 50% below regional carriers, so scale is already the industry's own explanation for investigation unit cost, and a shared operation is the structure that can capture it at 100% flagged-claim coverage rather than ~25%.