Once a year, every insurer admitted in California uploads its SIU organizational chart to the Department of Insurance, "including names and titles of personnel." New York requires the geographical location and assigned territory of each investigator, plus the reporting structure between the unit and general management. Florida requires a chart with position titles and descriptions of staffing. SIU team structure is a regulatory filing before it is a management decision, and the capacity question gets answered second, inside whatever the filing already committed to.
That would be a footnote if the filing were cheap to change. It is not. The NAIC's Antifraud Plan Guideline defines a material or substantive change to include any alteration of "the operations, standards, methods, staffing, or outsourcing" an insurer uses to detect, investigate and report suspected fraud, and requires the plan to be amended and resubmitted when one happens. California asks the forward-looking version of the same question on its annual form: describe any significant, anticipated changes to the insurer's structure and operations. A structure you have to pre-announce to a regulator is not a structure you tune quarterly against referral volume.
Then the arithmetic underneath it. Every staffing standard in US SIU regulation is indexed to premium or policy count. New Jersey writes one investigator per 30,000 automobile policies. California, New York and Florida all list the number of policies written as a staffing rationale criterion. The industry benchmark is 0.67 SIU FTE per $100 million in gross written premium. The work is indexed to something else entirely: the referral queue, 45% of which is now machine-generated. Premium is a denominator the carrier controls. Referral volume is a denominator the detection vendor controls. Those two have been diverging for two study cycles.
What follows covers the parts of SIU org design that get decided somewhere other than the SIU: reporting lines, span of control, the desk and field split, the five-state model comparison, and the rules governing an outsourced unit. It sits underneath SIU operations: how Special Investigation Units run in 2026, which covers the operating model end to end. Every non-Hesper number here comes from the Coalition Against Insurance Fraud and Aon 2024 Insurer SIU Benchmarking Study or from the regulation itself, and both are linked.
SIU team structure is a filed document before it is a design
An SIU org chart is a compliance artifact. California, New York and Florida require a chart or a written description of the unit to be filed with the state, New Jersey requires the filed plan to establish the unit and meet fixed investigator ratios, and the NAIC model treats a change in staffing or outsourcing as an event that triggers a refiling. Structure gets authored for an examiner first.
Start with California, because California collects the most. 10 CCR 2698.40(b)(6) requires the annual SIU report to include "A written description or chart outlining the organizational arrangement of the insurer's SIU and integral anti-fraud personnel, including personnel of any contracted entities, who are responsible for the detection, investigation, and reporting of suspected insurance fraud that occurred in California." The instruction on the form itself is blunter. Section B, "ORGANIZATION AND STAFFING," item 1: "Go to the Attachment tab located at the top of this page and upload a copy of your 2023 SIU organizational chart, including names and titles of personnel."
The same form reaches past the unit. Section B item 4 asks the insurer to "upload the organizational chart and phone roster as of December 31, 2023 that list all integral anti-fraud personnel of the primary insurer and each subsidiary who service California business lines," or else to report those people by job classification: claims handlers, underwriters, policy handlers, call center staff, legal staff, premium auditors. A separate block headed "CONTRACTED SIU FUNCTIONS" records that "The primary insurer has entered into a written contract with the following company(ies) to perform one or more SIU functions" and instructs the filer to upload the executed current contracts. The build-versus-buy decision is not a strategy slide in California. It is a named vendor and an attached contract, filed annually. The Department's SIU Compliance Unit "evaluates the accuracy, completeness, and timeliness of the report filed by approximately 1,100 insurers each year."
The names do not become public. 10 CCR 2698.40(e) provides that "the name(s) of the insurer's personnel who will communicate with the Fraud Division shall not be made part of the public record and shall be released only pursuant to the provisions of Insurance Code section 1873.1." That is why no top-20 carrier org chart appears in this post, and why you will not find one anywhere else either. The data exists, in volume, in a file cabinet you cannot open.
Alongside the chart, 2698.40(b)(7) requires "A description of how the SIU is adequately staffed to meet the requirements herein and the expertise of the staff." That description has to include "The total number of SIU staff employed by the insurer to investigate suspected insurance fraud occurring in California," "Total hours of insurer employee time spent working on fraud investigations of suspected insurance fraud that occurred in California," "Total hours of contracted SIU personnel time spent working on fraud investigations related to the insurer's claims," and "A description of how the insurer measures the effectiveness of its SIU." Headcount, hours, vendor hours, and a self-declared effectiveness measure. That is an operating plan wearing a filing's clothes.
New York collects a different cut of the same thing, and its version is the one that constrains geography. Under 11 NYCRR 86.6(b)(2), the fraud prevention plan must contain "a description of the organization of the Special Investigations Unit, including the titles and job descriptions of the various investigators and investigative supervisors, the minimum qualifications for employment in these positions in addition to those required by this regulation, the geographical location and assigned territory of each investigator and investigative supervisor, the support staff and other physical resources, including database access available to the unit and the supervisory and reporting structure within the unit and between the unit and the general management of the insurer." A regional model is not an internal preference in New York. It is a filed fact, investigator by investigator, territory by territory.
Florida asks for less and still asks for the chart. Fla. Stat. 626.9891(3)(e) requires "A description or chart of the insurer's anti-fraud investigative unit, including the position titles and descriptions of staffing; and" (3)(f) requires "The rationale for the level of staffing and resources being provided for the anti-fraud investigative unit." Florida also sets the floor for what counts as a unit at all: 626.9891(2)(c) requires the insurer to "Designate at least one employee with primary responsibility for implementing the requirements of this section." One named person is a compliant Florida org chart.
Reorganizing is a filing event
The NAIC Antifraud Plan Guideline (GDL-1690) is where the latency becomes explicit. Section 2.D defines the trigger: "'Material or substantive change' means any change, modification or alteration of the operations, standards, methods, staffing, or outsourcing utilized by the insurer to detect, investigate and report suspected insurance fraud." Section 3.E states the consequence: "If an insurer makes a material/substantive change in the manner in which they detect, investigate and/or report suspected insurance fraud, or there is a change in the person(s) responsible for the insurer's antifraud efforts, the insurer will be required to amend [and submit] their antifraud plan within [insert number of days] days of the change(s) being made." The brackets are in the model text, because each adopting state fills in its own number.
Read those two sections next to each other and the structural point lands. Staffing is named. Outsourcing is named. A carrier that moves twelve investigators from a regional pool into a national desk unit, or swaps an outsourced field vendor for in-house hires, has made a material change to the thing it filed. That is not a reason to avoid the reorganization. It is the reason the reorganization arrives on a regulatory calendar, not an operational one, and it is the mechanical explanation for why SIU structure is stable in an environment where referral volume is not.
The NAIC filing also asks the two questions that are the org-design decision, in so many words. Section 4.C(9) asks for "A statement as to whether the insurer has established an internal SIU to investigate suspected insurance fraud," followed by "(a) A description as to whether the unit is part of any other department within the organization" and "(b) A description or chart outlining the organizational arrangement of all internal SIU positions/ job titles." Section 4.C(10) asks for "A statement as to whether the insurer utilizes an external/third party as their SIU or in conjunction with their internal SIU." Centralized versus embedded, and in-house versus outsourced, are fields on a form. For the California layer in detail, see the California 10 CCR 2698 SIU compliance guide.
Every staffing standard is indexed to premium; the work is indexed to referrals
Carriers size SIUs against exposure and staff them against a queue. New Jersey's ratio is per policy, California's and New York's staffing rationale criteria start with policies written, and the industry benchmark is 0.67 FTE per $100 million in gross written premium. The queue is set by referrals, which is a different number moving in a different direction.
The Coalition Against Insurance Fraud and Aon surveyed 35 P&C carriers for the 2024 study, the sixth iteration since 2012. It is a small sample and worth naming as one. It is also the only public dataset that answers structural questions about US SIUs at all. Its headline staffing number: "carriers saw an average of 0.67 FTE per $100 million in gross premiums written," where "just 2 years ago the average was 0.9 FTE." That is a 26% decline in the industry's own staffing ratio in two years, by derivation from the study's two figures.
Absolute headcount barely moved. Study participants "saw an increase in SIU staff at 0.5%," against 1.4% in the 2022 study. Budgets tell the same story from the finance side: "SIU budgets represent about 0.12% of overall premium. This is slightly down from 2022 with a reported 0.13%." The entire fraud investigation function of a US P&C carrier costs 12 basis points of premium, and carriers reported planning increases of nearly 4% for the coming year. A CFO looking at that line is not looking at a cost problem. That is the point: the SIU is too small to be a savings target and too small to absorb a volume shock.
Apply the ratio and the org chart gets concrete. At the industry-average 0.67 FTE per $100 million in gross written premium, a carrier writing $2 billion supports roughly 13 SIU FTE and a carrier writing $5 billion supports roughly 34. Both figures are derived by straight multiplication of the study's ratio, not reported by any carrier. At the same study's role mix, management is 14% of the unit, so the $2 billion carrier's roughly 13 FTE carries about 2.2 management-level roles, which is consistent with the reported span of 6.1 staff per manager. Also derived.
One more budget number, with a caveat attached. The study reports that "The budget expense per investigation in this study is up about 11% from the 2022 study results coming in at just above $1,200." That is a budget-allocated expense per investigation, which is not the same measure as a fully loaded cost per completed investigation and should not be set against one. The study also notes that "national carriers reported expense per investigation is about 50% lower than regional carriers," and immediately qualifies it: "Scale and line of business however have an impact on those companies as the regional carriers tend to have a greater percentage in commercial lines." That is a scale observation with a mix confound, not a verdict on centralization.
Now the other denominator. In the same study, automated SIU investigative referrals "now represent 45% of all referrals to SIU," alongside "a drop in adjuster referrals, now at 49%." Automated referrals moved six percentage points in one study cycle. SIU headcount moved half a percentage point. Nothing in the regulation, and nothing in the industry benchmark, indexes staffing to that. New Jersey counts policies. California counts policies, insureds, claims received and suspected fraudulent claims detected. New York counts policies, insureds and claims received. Florida counts policies and claims. Detection output appears in none of the staffing formulas, and it is the thing filling the inbox.
That divergence is the structural defect, and it is nobody's fault. Detection tooling got better and cheaper, which is what it was supposed to do. The unit that works the output was sized on a different axis, against a filed rationale that takes a regulatory cycle to revise. The consequence shows up as coverage: manual SIU teams across US P&C carriers fully investigate roughly 25% of the claims they flag, on Hesper internal benchmarks. The lane that scales with investigators, not with software is the one we size in the claims triage decision framework.
What the regulators actually dictate about reporting lines
Independence from claims is a legal requirement in New York and New Jersey, expressly optional in Florida, and unaddressed in California. New York goes further and states where the reporting line may join: not below the executive level. A carrier writing in all four runs the strictest design everywhere, so the most restrictive state sets the national org chart.
New York states the rule in the plan-contents provision. 11 NYCRR 86.6(b)(1) requires "establishment of a full-time Special Investigations Unit separate from the underwriting or claims functions of the insurer, which shall be responsible for investigation of cases of suspected fraudulent activity and for implementation of the insurer's fraud prevention and reduction activities under the Fraud Prevention Plan." Full-time and separate. Not a virtual team, and not a percentage of an adjuster's week.
The Department of Financial Services then answers the operational question directly in its SIU FAQ. Asked how an insurer demonstrates that an SIU is separate from claims and underwriting, DFS says: "Each SIU should be established as a separate unit with its own budget line. Investigative personnel should not perform claims or underwriting functions and; claims and underwriting personnel should not perform investigative functions. The SIU should not report to claims or underwriting personnel except at the executive level." The stray semicolon is in the source. So is the most useful sentence in US SIU org design: the reporting line may only join claims at the executive level.
New Jersey is equally direct and gets there in one line. N.J.A.C. 11:16-6.4(c)1 provides that "SIU investigators and SIU specialists shall be a separate unit from the claims or underwriting unit." No qualifier, and no executive-level carve-out written into the rule.
Florida takes the opposite position in its definitions section, which is the most overlooked fact in this area. Fla. Stat. 626.9891(1)(b) provides that "'Designated anti-fraud unit or division' includes a distinct unit or division or a unit or division made up of employees whose principal responsibilities are the investigation and disposition of claims who are also assigned investigation of fraud." Florida expressly contemplates a unit staffed by people whose main job is adjusting claims. The embedded model is not a workaround there. It is in the statute.
California says nothing about independence. Its staffing rule, 10 CCR 2698.32, is a competence standard: an SIU "shall be composed of employees who have knowledge and/or experience in general claims practices, the analysis of claims for patterns of fraud, and current trends in insurance fraud, education and training in specific red flags, red flag events, and other criteria indicating possible fraud." Read 2698.30(o) alongside it and the definition is deliberately permissive: an SIU "may be comprised of insurer employees or by contracting with other entities for the purpose of complying with applicable sections of the Insurance Frauds Prevention Act (IFPA)." Competence and capability, not org placement.
Texas is the floor. Tex. Ins. Code 704.051 says "A plan issuer who collects direct written premium shall adopt an antifraud plan under this subchapter," and 704.052 says the plan "must include a description of the issuer's procedures for: (1) detecting and investigating possible fraudulent insurance acts; and (2) reporting possible fraudulent insurance acts to the insurance fraud unit." Procedures, not a unit. No chart, no staffing rationale, no separation from claims.
Anyone expecting one national template will not find one. The NAIC's Fall 2021 state page for the Insurance Fraud Prevention Model Act lists only five jurisdictions under Model Adoption: Arkansas, Maine, North Dakota, Rhode Island and West Virginia. Every other state with activity sits under Related Activity, which the NAIC key defines as jurisdictions that have not adopted the most recent version of the model in a substantially similar manner. The rest of the country wrote its own rule, which is why the table below has five different answers in most rows.
Read down the separation row and the multi-state design problem resolves itself. A carrier writing in New York, New Jersey and Florida cannot run one embedded unit and one independent unit without maintaining two filed structures, two sets of job descriptions and two reporting lines. Almost nobody does that. They run the New York design nationally, because the New York design is compliant everywhere and the Florida design is compliant in one place. "We are centralized and independent" is the modal answer to an org-design question that was settled by the strictest jurisdiction, usually without anyone running the comparison. For the New York rules in full, see the New York SIU compliance guide.
Five structures, and what each does when the queue grows
Underneath the legal constraint there are five shapes a US P&C SIU actually takes. The differences that matter are not on the chart. They are in what breaks when referral volume moves faster than headcount, which is the condition every SIU has been operating in for two study cycles.
The staffing ratio nobody has, and the one state that wrote one down
New Jersey is the only state that names a number: one SIU investigator or specialist per 30,000 New Jersey automobile policies serviced. Everywhere else the standard is a justification test. New York's Department of Financial Services answers the question in three sentences, and the answer is that there is no number.
N.J.A.C. 11:16-6.4(c) sets three ratios in three subparagraphs: "2. Automobile insurers shall employ at least one SIU investigator or SIU specialist (when permitted by N.J.A.C. 11:16-6.4(d)2) for each 30,000 New Jersey automobile policies serviced. 3. Health insurers offering comprehensive benefits contracts shall employ at least one SIU investigator or SIU specialist (when permitted by N.J.A.C. 11:16-6.4(d)2) for every 60,000 insured lives. 4. Health insurers offering limited benefits contracts shall employ at least one SIU investigator or SIU specialist (when permitted by N.J.A.C. 11:16-6.4(d)2) for every 250,000 insured lives." Below the thresholds in 11:16-6.4(a), no unit is required at all: "Except for automobile insurers that insure fewer than 2,500 New Jersey automobile policies, and health insurers that insure fewer than 10,000 lives, the plan filed in accordance with N.J.A.C. 11:16-6.3 shall establish a full-time Special Investigations Unit ('SIU')."
Note what the New Jersey ratio counts. Policies serviced. Not claims received, not referrals, not suspected fraudulent claims. A low-frequency book and a high-frequency book get the same mandated investigator count at the same policy count. The one hard number in US SIU regulation is indexed to exposure, and it is the cleanest illustration of the denominator problem in the whole regulatory corpus.
California replaces the number with a performance test. 10 CCR 2698.32(a) provides: "Adequacy. The adequacy of an insurer's SIU staffing shall be determined by its demonstrated ability to establish, operate and maintain an SIU that is in compliance with these regulations. Factors that may be considered in staffing the SIU include, but not limited to, the number of policies written and individuals insured in California, number of claims received with respect to California insureds on an annual basis, volume of suspected fraudulent California claims currently being detected and other factors relating to the vulnerability of the insurer to insurance fraud." Demonstrated ability is a harder standard than a ratio, because the carrier writes its own benchmark and then has to live inside it on examination.
New York says the same thing in the plainest language any regulator uses on this subject. Asked whether there is a requirement for an SIU to include a minimum number of investigators, DFS answers: "No. Each company has broad latitude in deciding how much of its resources will be dedicated to fraud prevention. However, companies must justify the adequacy of these resources."
Two states hand the caseload question back to the carrier in nearly identical words. New York, 11 NYCRR 86.6(b)(3), asks the plan to contain "the rationale for the level of staffing and resources being provided for the Special Investigations Unit which may include, but is not limited to the following objective criteria such as number of policies written and individuals insured in New York, number of claims received with respect to New York insureds on an annual basis, volume of suspected fraudulent New York claims currently being detected, other factors relating to the vulnerability of the insurer to fraud, and an assessment of optimal caseload which can be handled by an investigator on an annual basis." Florida, 626.9891(3)(f), asks for "an assessment of the optimal caseload that one investigator can handle on an annual basis." Every regulator asks the carrier to name the number. No regulator names it. The one that does, New Jersey, names it per policy.
California wrote an FTE proration formula, which tells you what it expects the org chart to look like
Under 10 CCR 2698.40(b)(7)(D), a carrier that cannot report California-specific investigator hours may instead divide the number of California claims or transactions that resulted in an opened SIU investigation by the number of investigations opened nationwide during the last calendar year, multiply nationwide SIU headcount by that quotient, and multiply the result by 2080 hours. The regulator built a slicing formula for a national unit and denominated it in headcount times 2080. There is no stronger evidence anywhere that the modal US SIU is one centralized unit, accounted for the way a services firm accounts for utilization.
Against that regulatory vacuum, the only published caseload figures are the benchmarking study's. It reports that "the annual accepted referrals per investigator increased to 174, compared to 162 reported in the 2022 study." Split by role, field investigators average 11.6 accepted referrals a month and desk investigators 17.9. Those numbers reconcile: weighting the monthly figures by the 39% field and 35% desk shares of headcount gives 174.9 accepted referrals a year, derived, which is within a point of the reported 174. That is a well-built dataset, and it is worth saying so given how little else in this area survives arithmetic.
Three different numbers get used interchangeably in caseload conversations and they measure three different things. 174 is accepted referrals per investigator per year, from the Coalition and Aon study. 200 or more cases per investigator is Hesper's internal benchmark for open cases carried at a point in time, which is a stock rather than a flow and includes work accepted in prior periods. Roughly 10 completed investigations per investigator per month is Hesper's internal benchmark for realistic finished throughput against a manual cycle time of 14 or more days per case. Accepted, carried and completed are not the same denominator, and a staffing rationale that mixes them will not survive a question from an examiner who reads carefully.
The gap between accepted and completed is the operative one for capacity planning, and it is a number a carrier can measure from its own case management system this quarter. We put it on the dashboard in the SIU KPIs worth tracking in 2026, and set it against peer figures in SIU performance benchmarking.
Span of control, desk versus field, and where the analysts sit
Each management-level role in an SIU now has 6.1 staff reporting to it, down from 6.3 in 2022. Management, supervisors and team leads are 14% of headcount, field and desk investigators about three quarters, and analysts 4%. The span narrowed while 70% of units went fully remote.
The study states both numbers plainly: "Management level roles now have 6.1 staff level positions reporting to them compared to 6.3 in 2022," and "Management, supervisors, and team leads represent 14% of the overall SIU staffing." Nothing else in public sources gives a span-of-control figure for an insurance SIU. It is the number that decides how many people a unit can add before it has to add a manager, and therefore the number that decides what a growth plan costs.
The study summarizes the top of that chart as "desk and field investigators represent roughly three quarters of the total headcount in SIU." Two derived readings are worth separating, because they get confused constantly. Field is 39% and desk 35% of total SIU headcount. Among investigators only, that is about 53% field to 47% desk. The first pair is the one to use when sizing a unit. The second is the one to use when arguing about the desk-field mix.
On the direction of travel, quote the study rather than a summary of it: "the balance between field and desk investigators is creeping closer to a 50/50 ratio across the industry. This is primarily being driven by large companies. That said, small and mid-size companies still lag as they are closer to 30/70 and 40/60, respectively." The report does not say which side of those small-company ratios is field and which is desk, so neither will we. What it does say elsewhere is unambiguous about workload: "In 2019, desk investigators were managing 42% of the accepted referrals. That has shifted over the last 2 studies where the metric moved to 44% and now 47%, in the most recent version."
Put the span number next to the location number and the org tells you something about itself. "In 2024, 70% of companies are operating in a fully remote SIU structure with 29% in a hybrid model," with large companies at 73% fully remote and mid-size companies showing the highest hybrid share at 39%. A unit that is more remote, more desk-weighted and more supervised at once is spending a larger share of itself on oversight. That is a reasonable response to losing the ability to see work happen. It is also expensive, and it is the specific cost an inspectable work product removes.
Analysts sit at 4% of headcount and are repricing faster than anyone else in the unit: "desk and field investigator positions increased 7% and 4%, respectively, analysts roles saw the biggest change with an increase of nearly 12% in the same period," against an average SIU salary of "just under $96,000 per year compared to $89,000 in 2022." Four percent of headcount is one analyst in a 25-person unit. That is the entire in-house capacity for pattern work, link analysis, and anything the case management system does not compute by itself. Where that function sits, and what tooling it gets, is covered in the SIU technology stack in 2026.
For a public example of how the role families get named, CNA publishes four: Case Management, which "Oversees day-to-day claims investigation operations and delivers subject-matter expertise"; Major Case Investigations, for "complex, high-risk claims exposures, such as organized crime-rings, medical provider treatment fraud"; Intelligence Analysts, which "Investigates internal and external sources of information to assess suspected fraudulent claims or provider activity"; and Clinical Investigator, bringing "knowledge and expertise of medical practices and standards." CNA publishes no headcount and no reporting line, and neither does any other named US carrier. That is the disclosure ceiling in this market, set by the same confidentiality provisions that keep filed charts out of public records.
Hesper's position on the span question is narrow and worth stating as a constraint rather than a benefit. Running 15 or more investigation phases in parallel on every flagged claim - document forensics, OSINT, statement cross-reference, timeline reconstruction, financial pattern analysis - produces a file that is complete before a human opens it. What that changes structurally is the review-versus-supervise ratio. The investigator's role shifts from execution to decision-making, and a manager reviewing finished, sourced files can hold a wider span than a manager checking in on work in progress. It does not move the 6.1 by itself, and no vendor should claim it does.
Reorganizing the SIU is a refiling event, so the org chart moves on the regulator's calendar and not the queue's. Chart, names and titles, staffing rationale, funnel data, and the material-change trigger that sends every reorganization back through the loop.
The SIU-to-claims interface is where the referral quality problem shows up
Adjusters generate 49% of referrals to SIU and automated tools 45%. Adjuster referrals are accepted at 70%, automated referrals at 36%. The gap reads as a detection tuning problem, and it is at least as much a capacity problem, because acceptance is a decision made by an intake function that is 3% of the unit.
The study's own wording: "Adjusters continue to lead the way in referral acceptance ratio at 70%, however this is down from the 2022 study findings at 76%," while automated tools saw "an increase of four percentage points from 32 to 36% since the last study." Both trends move toward each other. Adjuster referrals are getting rejected more often, machine referrals slightly less often, and the composition of the queue is shifting toward the source with the lower acceptance rate.
Convert volume into accepted work and the two charts in the study reconcile. Adjusters at 49% of volume accepted at 70% contribute 34.3 units of accepted work. Automated tools at 45% accepted at 36% contribute 16.2. Total 57.2 accepted, of which automated tools are 28.3%, derived, against the 29% the study reports for automated tools in its accepted-referrals-by-source breakdown, with adjusters at 60% and all other sources at 10%. The internal consistency matters, because it means the acceptance gap is a real property of the dataset and not an artifact of two questions asked differently.
There are two honest readings of a 36% acceptance ratio and the study supports neither exclusively. Read as a signal problem, it says automated detection surfaces a lot of claims that do not merit an investigation. Read as a capacity problem, it says an SIU that can work a fixed number of cases will decline the marginal referral no matter how good it is, and the marginal referral is now overwhelmingly the machine-generated one. An acceptance ratio mixes signal quality and available capacity by construction and cannot separate them. That ambiguity is the finding. Nobody should call it a false-positive rate, and no vendor should be named for it: the study reports the figure for automated fraud detection tools as a category.
Structure is what turns one reading into the other. Intake operators and gatekeepers are 3% of SIU headcount. In a 25-person unit that is under one full-time person deciding what gets worked. Whatever capacity signal exists in the organization reaches the accept-or-decline decision through a function too small to be where a strategic tradeoff gets made, and it arrives without a way to record why the marginal case was declined. Nothing in any of the five state rules examined here requires the reason for declining a referral to be captured with the referral.
The other side of the interface is larger than the SIU by an order of magnitude and is not on its org chart. California defines integral anti-fraud personnel as insurer personnel "who the insurer has not identified as being directly assigned to its SIU but whose duties may include the processing, investigating, or litigation pertaining to payment or denial of a claim or application for adjudication of claim or application for insurance," and adds that "These personnel may include claims handlers, underwriters, policy handlers, call center staff within the claims or policy function, legal staff, and other insurer employee classifications that perform similar duties." Those people generate 49% of referrals. They also carry a training obligation the SIU owns: new-hire anti-fraud orientation within 90 days, including "an organization chart depicting the insurer's SIU," while SIU personnel themselves "shall receive at least five (5) hours of continuing anti-fraud training per calendar year" under 2698.39(c)(3).
States collect the funnel that results. California's annual filing collects, for each reported company, "The number of California claims processed by the insurer during the last calendar year," "The number of claims or other transactions referred to the SIU during the last calendar year that involved suspected insurance fraud occurring in California," and the number of those referred claims "that resulted in the SIU's opening an investigation." Florida collects the equivalent by March 1 across 11 data items, including the number of claims received, the number of claims referred to the anti-fraud investigative unit, and the number of claims investigated or accepted by it. Neither state publishes the aggregate, so there is no public industry referral-acceptance denominator from any state fraud bureau. The regulator knows the coverage number for every filer. Nobody else does.
Set the accepted figure against completed throughput and the backlog is arithmetic. A desk investigator accepts 17.9 referrals a month. Realistic completed throughput on Hesper internal benchmarks is roughly 10 full investigations per investigator per month, against a manual cycle time of 14 or more days per case. The difference does not disappear. It becomes carried caseload, and eventually it becomes a decline at intake, which is how a capacity constraint gets recorded as a referral-quality statistic. That mechanism is the subject of why most flagged insurance claims are never investigated.
One observation about the vendors on the other end of that 45%. FRISS, Shift Technology, Verisk, Guidewire and Duck Creek build at the detection and claims-system layers, which leaves org design to the carrier. That is not a criticism. The 45% figure is evidence detection tooling is doing exactly what it was bought to do. The gap is that the volume it generates lands in a unit whose size is filed against premium and whose shape takes a plan amendment to change.
In-house, outsourced, and the rules that govern the vendor version
Outsourcing the SIU is permitted in every state examined here, and it is regulated more tightly than most carriers expect. New York requires the contract to be filed and each investigator's New York time apportioned as a percentage. California collects the executed contracts on the annual report and on request. New Jersey makes the vendor jointly responsible.
New Jersey states the permission and the joint liability in one provision. 11:16-6.4(e): "The plan may provide that the functions of the SIU may be assigned to an outside vendor or third party administrator. In such case, the plan shall provide that the outside vendor or third party administrator shall also be responsible, together with the insurer, for compliance with N.J.A.C. 11:16-6." Outsourcing moves the work. It does not move the obligation.
California's contracting rule, 10 CCR 2698.33, is the most demanding of the five on contract terms. Subsection (a): "Any contract entered into by an insurer, or an entity under contract with an insurer for the performance of SIU or integral anti-fraud personnel duties or functions as provided under these regulations, shall not relieve the insurer of any obligation under these regulations or the IFPA." Subsection (b): "Notwithstanding any other provisions of these regulations, a complete and executed copy of any such agreement, including all attachments, exhibits and amendments thereto, shall be provided to the Fraud Division upon request by the Fraud Division." Subsection (c) then requires the contract to "Specify all SIU or integral anti-fraud personnel duties and functions to be performed by the parties to the contract and how the insurer monitors performance of the contract responsibilities" and to "Not include provisions that could provide disincentives to the referral and/or investigation of suspected insurance fraud." The section was retitled and amended operative October 1, 2020, and the 2005 version required the contract on execution rather than on request, so cite the current text in a filing.
The disincentives clause deserves a second read from anyone structuring a commercial arrangement around fraud work. A contract that pays less when more cases get referred, or that caps investigation volume, is the thing the rule contemplates. It is also why contingent or savings-share pricing on investigation work is a structurally awkward fit in California, regardless of how attractive the economics look on a spreadsheet.
New York permits contracting inside the same provision that mandates the unit. 11 NYCRR 86.6(b)(1) provides that "In the alternative the insurer may contract with a provider of services to perform all or part of this function, but shall remain primarily responsible for the development and implementation of its Fraud Prevention Plan." The agreement is filed with the Insurance Frauds Bureau as part of the plan and "must provide for specified levels of staffing devoted to the investigation of suspected fraudulent claims." Then the requirement nobody expects: "In the event that investigators employed by a provider of services will be working for more than one insurer or on cases in states other than New York, the plan must apportion the percentage of the investigator's efforts which will be devoted to working for the insurer on its New York cases." A shared investigator is a fraction, filed as a fraction.
The NAIC model asks for the vendor relationship in structural terms. Section 4.C(10)(a) requires that where "an external/third party is used to substantially perform the insurer's SIU function, the insurer shall provide the name of the company(ies) used and contact information for the company(ies)." Section 4.C(10)(b) requires the insurer to "specify the internal persons or position responsible for maintaining contact with the external company(ies) which will serve as the insurer's SIU" and to provide "a description of how they will monitor and/or gauge the external/third party's compliance with insurer antifraud mandates." Every outsourced SIU still has an internal org chart. It has exactly one box on it.
Florida makes the build-or-buy choice explicit at the top of the statute: establish "a designated anti-fraud unit or division within the company" or "Contract with others to investigate and report possible fraudulent insurance acts," under 626.9891(2)(a), while still requiring at least one designated employee under (2)(c). California keeps score in vendors and hours: the annual report names every company contracted to perform SIU functions and carries their executed contracts as attachments, section D asks the insurer to list all TPAs and MGAs and to "state whether the TPA or MGA maintains its own SIU, uses the SIU of the primary insurer, or contracts with an external SIU," and 2698.40(b)(7)(E) separately collects "Total hours of contracted SIU personnel time spent working on fraud investigations related to the insurer's claims." A regulator reading two consecutive filings can see an insourcing or outsourcing shift without being told about it.
One structural option gets missed at group carriers. NAIC Section 4.B provides that "One antifraud plan may cover several insurer entities if one SIU has the fraud investigation mission for all entities." A shared-services SIU across affiliated entities is contemplated by the model, which matters for holding companies running several statutory entities behind one claims operation.
Outsourcing is a legitimate model and a large share of US field investigation runs on it. What it does not do is change the shape of the problem. A vendor SIU buys capacity linearly: more cases means more invoices, at roughly a fixed unit price, with the same 14-or-more-day cycle time per case and the same one-case-at-a-time constraint on the person doing the work. It converts a headcount decision into a purchase order, which is genuinely faster than a plan amendment. It does not make the marginal investigation cheaper next year than it was this year, and nothing about the org chart compounds.
What changes when investigation capacity stops being headcount
Every constraint above is a headcount constraint in compliance clothing. The filing latency, the premium-indexed ratio, the narrowing span and the 36% acceptance ratio all resolve to one fact: a human investigator holds one case at a time. Adding capacity that is not headcount is the only move that does not start with a hiring plan.
The trend lines are not close. SIU staff grew 0.5% in the last study cycle while automated referrals grew six percentage points as a share of a growing queue. The labor pool will not close that gap. The Bureau of Labor Statistics puts employment of claims adjusters, appraisers, examiners and investigators at 389,700 in 2025 with median pay of $78,020, and projects a 6% decline through 2035, a loss of 21,800 jobs. That occupational group is far larger than SIU alone and should never be quoted as an SIU headcount, but the direction is the relevant part, and SIU pay already sits above it at just under $96,000 on the Coalition and Aon study.
SIU leaders in the study named their top concerns in this order:
- Artificial intelligence and fraud identification automation
- Data quality/analytics
- Legal/regulatory environment and oversight
- Managing emerging fraud trends
- Staffing and talent management
- Technology
- Training and fraud awareness
Automation is first on that list and staffing is fifth, which is a sensible ranking from people who already know the headcount answer. The 0.5% growth figure is not a budgeting failure. It is what a filed staffing rationale indexed to premium produces when premium grows slower than referral volume. Arguing for more investigators means reopening the rationale, and the rationale was written against criteria that do not include how many claims a detection vendor flagged this quarter.
The alternative is capacity that is not a person. Hesper runs 15 or more investigation phases in parallel on every flagged claim and returns a complete file in hours, not weeks, against a manual baseline of 14 or more days per case. Per-case attention stops being the constraint, which is the only mechanism that moves coverage from roughly 25% of flagged claims toward 100%. That is the move from fraud detection to fraud resolution, and it is a capacity argument rather than a headcount argument: the investigator's role shifts from execution to decision-making, and the unit gets re-aimed at judgment work rather than shrunk.
The output has to survive the same examination the org chart does. California 10 CCR 2698.36(a) requires every investigation to include "A thorough analysis of a claim file, application, or insurance transaction, that includes consideration of factors indicating insurance fraud," identification and interviews of potential witnesses, "Utilizing one or more industry-recognized databases identified by the SIU as appropriate for use in fraud investigations involving the particular line of insurance in question," "Preservation of documents and other evidence obtained during an investigation," and "Writing a concise and complete summary of the entire investigation, which is specific to the investigation at hand, is separate from any other document prepared in connection with the investigation, and includes the investigators' findings regarding the suspected insurance fraud and the basis for their findings." An audit-trail-native design logs every step with sources, reasoning and timestamps, which is what makes the fifth element fall out of the work instead of being written afterward from memory. It is also the mechanism behind the span argument earlier: a manager can review a complete file faster than they can supervise the process that would have produced it.
Be honest about the filing consequence, because it cuts both ways. Introducing an automated investigation layer is a change to the methods an insurer uses to investigate suspected fraud, and under NAIC Section 2.D that is a material or substantive change requiring a plan amendment. So it is a filing event too. The difference is that it is a one-time filing that changes throughput permanently, instead of an annual negotiation over an FTE count indexed to a premium number that has nothing to do with the queue. Compliance officers should plan for the amendment and should expect the state to ask what the system does, who reviews its output, and how its work is documented, which is what NAIC 4.C(9)(e) already asks about investigation procedures.
Layering stays honest as well. FRISS, Shift Technology and Verisk operate upstream at detection and scoring, and the 45% of the referral queue that tools like them generate is a sign that layer is working. Hesper AI sits downstream of detection and is complementary to FRISS, Shift Technology, and Verisk - not a replacement. Detection is also built in, so it runs standalone at carriers with no upstream scoring vendor. What no one else occupies is the layer between a flag and a defensible decision, which is the layer every rule in this post regulates and the only one where an org chart is the bottleneck. Make every flagged claim investigable, and the chart you filed stops being a capacity ceiling.
Key takeaways
- The SIU org chart is a filed regulatory artifact in California, New York and Florida, and California collects it annually with names and titles under 10 CCR 2698.40(b)(6), which is why no carrier's structure is publicly available and why yours is authored for an examiner before it is authored for a queue.
- NAIC GDL-1690 Section 2.D makes any change to staffing or outsourcing a material or substantive change and Section 3.E requires the antifraud plan to be amended and resubmitted, so restructuring an SIU runs on a regulatory calendar rather than an operational one.
- Every staffing standard is indexed to exposure - New Jersey's one investigator per 30,000 auto policies, the policies-written criteria in California, New York and Florida, and the industry's 0.67 FTE per $100 million in gross written premium - while the workload is set by a referral queue that is now 45% machine-generated.
- New York and New Jersey require the SIU to be separate from claims and underwriting, New York adds that it should not report into claims except at the executive level, and Florida expressly permits an embedded unit, so the strictest state sets the national org chart for any multi-state carrier.
- Span of control tightened to 6.1 staff per management role while 70% of units went fully remote and desk investigators took 47% of accepted referrals, which means the org is spending more of itself on supervision at exactly the point where a complete, reviewable investigation record would let it spend less.