Verisk Fraud Discovery, announced on September 8, 2026, unifies fraud intelligence, advanced analytics, network analysis, digital media forensics and case management into a single, scalable solution, and every word of that description is Verisk's own. Hiscox, Allianz and the law firm Weightmans are named as adopters at launch. It is modular, so organisations can take the pieces that match their fraud maturity. The release quotes two customers rather than a Verisk executive, claims no accuracy, throughput, recovery or efficiency metric of any kind, and never uses the word SIU. This is a real consolidation of five layers of the fraud stack, and it deserves to be conceded cleanly before anything else is said about it.
Sort every product in this market by the job it does and six layers fall out: intelligence and data, analytics and detection, network analysis, media forensics, case management and queue, and investigation execution. Fraud Discovery names five of them. The sixth is the labour between an accepted referral and a closed, defensible finding, and it is not among the capabilities named in the release. It is also not claimed by FRISS, by Shift, by SAS, by Guidewire, or by any standalone case-management tool. The subject of this post is not a gap Verisk left. It is a layer the category as a whole has never productised.
The evidence that this is a real gap rather than a rhetorical one comes from the industry's own measurement. The Coalition Against Insurance Fraud and PwC surveyed 93 insurers in 2023 and defined overall SIU cycle time as the time between referral acceptance and closure. That clock starts exactly where Fraud Discovery's prioritisation bullet ends: after triage, after the case has landed in the workflow. Of the 64% of respondents who capture that interval, 47% report 21 to 60 days and 12% report 61 days or more. Only 5% report 0 to 20 days. And 36% of all respondents do not measure it at all.
Two housekeeping notes before the argument. Fraud Discovery is a separate platform, not the MCP connector work we covered in where Verisk's Claude connectors stop on September 9, so that post's argument stands unchanged and this one extends it from protocols to platforms. And the category frame underneath both is the three-layer model of prevention, detection and investigation. What follows resolves that model into six layers, because the middle of the stack has got considerably more crowded since we drew it.
What Verisk shipped on September 8
Verisk Fraud Discovery is a fraud prevention platform announced on September 8, 2026 that, in Verisk's words, unifies fraud intelligence, advanced analytics, network analysis, digital media forensics, and case management into a single, scalable solution. It is modular, it has three named launch adopters, and it claims no performance metric of any kind. This section is reporting, not argument.
The launch release carries a London dateline and describes the platform as combining fraud intelligence, analytics, network analysis, digital media forensics and investigation workflows to help organisations do seven things. Those seven are worth reading in full, because every subsequent argument in this post turns on what is in the list and what is not.
- Uncover hidden relationships across people, organisations, policies and claims
- Detect opportunistic, organised and coordinated fraud activity
- Analyse images and documents for signs of manipulation, alteration and deepfakes
- Prioritise investigations and resources using risk insights and intelligence-led decisioning
- Streamline investigations and case management through a single workflow
- Improve fraud visibility and collaboration across underwriting, claims and fraud teams
- Transform data into actionable intelligence
Modularity is stated explicitly: designed as a modular platform, organisations can adopt capabilities based on their fraud maturity and operational requirements. That is a commercially sensible design and it matters for how a carrier should evaluate the thing. Fraud Discovery is not a single product with one price and one deployment. It is a set of capability areas, several of which Verisk already sold separately, now presented under one roof with one workflow across them.
Three organisations are named as adopting Fraud Discovery at launch: Hiscox, Allianz and the law firm Weightmans. Both quotes in the release are customers, not Verisk. James Burge, Global Head of Fraud at Hiscox, frames the problem as connection across the insurance journey. Mike Brown, Head of Fraud at Weightmans, describes the collaboration as a step forward in equipping his firm and its clients with advanced technology to better identify and respond to fraud. Allianz is named as an adopter and is not quoted. No outcomes have been published by any of the three, and none should be inferred.
Weightmans is also the visible precursor. Earlier in 2026 the firm launched Fraud Rely with Verisk, combining Weightmans' proprietary fraud data with Verisk anti-fraud technology to prioritise higher-risk cases, and Legal Futures reported Weightmans as the first UK legal entity to collaborate with Verisk. Insurance Edge covered Fraud Rely in July and the Fraud Discovery launch in September. Read the two together and Fraud Discovery looks less like a surprise and more like the productised version of work Verisk had already been doing with a launch partner.
On availability, the honest description is narrow: a London-datelined launch with UK launch adopters and UK figures, and the release states no geographic availability. Verisk's boilerplate describes the company as a strategic data analytics and technology partner to the global insurance industry, and several underlying components, including Digital Media Forensics and ClaimSearch-derived intelligence, already exist as separate products in more than one market. Anyone reporting this as a US general-availability launch is going beyond what was published. So is anyone reporting it as UK-only. A carrier outside the UK should ask Verisk which modules are available in which markets and on what timeline, and treat the answer as the fact rather than the press coverage.
The release also carries a UK market figure: UK insurers detected £1.16bn in fraudulent claims in 2024 across 98,400 cases, with industry estimating a similar amount goes undetected. No source is named in the release, which is wire-release convention rather than a fault. The figure is the Association of British Insurers'. Insurance Journal reported the ABI data on November 26, 2025: £1.16 billion detected, at least 98,400 fraud-related claims uncovered, a 12% rise from 88,100 in 2023, with motor accounting for 51,700 claims worth £576 million, or 53% of detected fraud by value, and property for 18,700 claims worth £189 million. Insurers also prevented 684,800 fraudulent applications, up 7.4%.
One line item inside that total is directly relevant to the argument of this post. ABI data reported by Insurance Business UK puts £466 million of the £1.16bn in exaggerated losses, up 10% year on year. Exaggeration is the category that a detection score is least able to close on its own. A staged loss can be matched, a synthetic identity can be networked, a manipulated photo can be forensically tested. An inflated contents schedule on a genuine burglary has to be reconciled item by item against receipts, prior claims, resale listings and the insured's own statement. That is investigative labour, and in the ABI's own categorisation it is the most common type of detected fraud in a record year.
What the release claims, and what it does not
Six things are worth stating precisely, because they discipline everything below. The words autonomous, agentic and AI agent appear nowhere in the Fraud Discovery release. No accuracy, detection-rate, throughput, efficiency or recovery metric is claimed. No Verisk executive is quoted; both quotes are customers. The term SIU is never used; the release says fraud teams, investigations and counter-fraud. No geographic availability is stated. And nothing in the release claims that the platform performs investigative work after a referral is prioritised. Verisk never crosses the line this post draws, which means there is nothing here to rebut. This post names a layer. It does not correct a vendor.
What an insurance fraud case management system actually does
Insurance fraud case management is the system that takes in suspected-fraud referrals, prioritises and assigns them, tracks the work against them, holds the evidence, produces the mandatory report for the state fraud bureau and preserves the audit trail. It covers seven functions, and every one of them is a container, a router or a ledger.
That definition is the useful one for a buyer, because it is functional rather than architectural. Vendors in this category differ enormously in how they are built and very little in what they are for. If you are writing requirements, write them against the seven functions and let the vendors argue about architecture afterwards.
Read down the right-hand column and the shape of the category is obvious. Not one of the seven functions is the act of finding out what happened. That is what makes case management the right name for the layer and the wrong name for the job. It is also why the layer is genuinely valuable: a queue nobody can see, a file nobody can reconstruct and a report nobody filed on time are all real operational failures, and a case management system prevents all three.
The second commercially important fact about this category is that it is not a gap in the market. It is already installed. The Coalition Against Insurance Fraud's 2024 State of Insurance Fraud Technology Study, the sixth edition, fielded to 35 carriers between October 3 and November 14, 2024 with 69% of respondents from SIU, asked whether respondents' systems incorporate a list of fraud capabilities and in what ownership model. The study is sponsored by Shift Technology and hosted by the Coalition, which is worth knowing when reading it; the printed figures below are the study's own.
The final column is a Hesper derivation, the sum of the three ownership models, and it is the column a buyer should read first. About three-quarters of surveyed carriers already have fraud case management incorporated in some form, and 34.3% built it themselves. The quiet majority-share competitor in this category is an in-house build, and it has been for years. The same study's forward-looking question puts planned case-management investment over the next 12 to 24 months at roughly 37%, well behind AI and machine learning and predictive modeling at roughly 69% each. Those figures are read off a bar chart rather than printed, so treat them as approximate.
What follows commercially is straightforward and not unflattering to Verisk. A carrier buying a unified fraud platform in 2026 is mostly consolidating capabilities it already owns in pieces: a scoring engine here, a link-analysis tool there, a case queue built in house in 2017 by someone who has since left. Consolidation is a defensible reason to buy, and one workflow across five capability areas is worth real money in reduced swivel-chair time. What the purchase is not doing is adding capacity to the layer that is still a person. We made the same point about the core system in Guidewire ClaimCenter fraud: the investigation is filed there, not run there, where the case record is excellent and the work it records still happens on someone's calendar.
The six layers of the fraud stack
Six layers sit between a claim arriving at a carrier and a fraud finding that survives an audit: intelligence and data, analytics and detection, network analysis, media forensics, case management and queue, and investigation execution. Verisk Fraud Discovery names five of them. The sixth is the labour that turns a prioritised queue into a closed finding.
Most vendor confusion in this market comes from comparing products that occupy different rows as though they were competing for the same one. A carrier that has bought well at layers one through five can still have no more investigative capacity than it had three years ago, because none of those purchases changes the per-case labour at layer six. Sorting the market this way is not a Hesper device; it is what falls out of reading the vendors' own product pages and taking each of them at its word.
Now map the products across the layers. The rule for this table is that a positive entry means the capability is named in the vendor's own release or on its own product page, and a negative entry says "not claimed" rather than "no". We have not used Fraud Discovery, and neither the absence of a marketing phrase nor the presence of one is proof about a product's internals. What a table like this can honestly show is what each vendor has chosen to put its name to.
Read the rightmost column top to bottom. Eight of the nine rows either do not claim the layer or are the manual incumbent. That is the payload of this post. It is not a criticism of any vendor in the table, because none of them has ever said otherwise, and their own product taxonomies are the clearest evidence of it. FRISS calls its investigation product Enterprise Investigations and describes it in its own words as structured, confidential SIU case management on flagged claims, which is an accurate and self-aware label for layer five. FRISS also publishes 75% fewer false positives, 90% of honest claims fast-tracked, more than 45 countries and more than 300 implementations, which is a strong record at layers two and five.
Shift Technology describes its Fraud and Risk agents as assessing for fraud, automatically assigning cases, guiding investigations and autonomously adapting fraud strategies, alongside a footprint it puts at 100% of the top five US P&C insurers, more than 4 billion policies, claims and documents analysed, and 120+ customers in 30+ countries. Guide is the operative verb and it is an accurate one. Assist and execution are different products, and we argued that distinction at length in Shift Claims vs Hesper, so one sentence is all it needs here. SAS sells the enterprise-heavy version of the same layer: SAS Detection and Investigation for Insurance generates a case through a configurable workflow that carries it across the investigative life cycle, on an open platform with an insurance-specific fraud data model, data management and reporting. Guidewire ClaimCenter, with 270+ customers across 30+ countries, ships a native SIU workflow with referral routing, dispositions, workplan activities and a structured outcome record, set out step by step in a carrier-published ClaimCenter SIU reference manual.
Layers one and three deserve a note of their own, because they are the layers most often mistaken for a finding. A cross-carrier hit or a network edge is a lead, not a verdict. Two claimants sharing an address is a fact about a database; whether it means collusion, a shared rental, a family, a body shop that fills in the same address on every form, or a data-entry error is a fact about a claim, and only investigating establishes which. The operating rule for every cross-carrier network and every link-analysis graph is the same one: a match is a lead, not a verdict, and the arbitration between leads is a different layer from the production of them.
Six layers of the fraud stack. Five now ship in one platform. The sixth is not claimed by any of them - not Verisk, not FRISS, not Shift, not SAS, not Guidewire. It is the layer Hesper occupies.
Hesper's own negatives belong in the same table, stated as plainly as everyone else's. Hesper is not a data utility and does not replace ISO ClaimSearch. It does not sell a suspicion score as its product, even though detection is built in. It does not replace the case management system of record; it writes into one. And it does not adjudicate. The SIU lead and the adjuster make the call on what the finding means for the claim. A vendor that will not print its own negatives in a layer table has not thought hard enough about which layer it occupies.
Prioritise is triage, single workflow is a system of record
Prioritisation is triage: it decides which referrals get worked first when capacity is short. A single workflow is a system of record: it decides where the work is written down. Both are valuable, and both are correctly named in Verisk's release. Neither of them is the act of finding out what happened on a claim.
Two of the seven capability bullets carry the weight here. Bullet four is prioritise investigations and resources using risk insights and intelligence-led decisioning. Bullet five is streamline investigations and case management through a single workflow. Read them as a claims operations person rather than as a competitor and they say something precise. Bullet four improves the ordering of a queue. Bullet five improves the container the queue lives in. Both are worth buying. Neither changes the number of hours a specific accepted referral consumes before someone can close it with a defensible answer.
Triage is a real discipline and it has a real ceiling. The ceiling is that triage decides what to work, not what is true. A well-ordered queue with capacity for 400 cases and 5,000 flagged claims in it produces exactly 400 investigations, in a better order than before, which is a genuine improvement in expected loss avoided per investigator-hour and no improvement at all in coverage. We wrote the full version of that argument in the claims triage decision framework, where the point is that a triage model can be excellent and still be answering a question about scarcity rather than a question about the claim.
The industry measures the queue at both ends and leaves the middle unmeasured, which tells you where the attention has historically been. The Coalition and PwC study lists the evaluation factors SIUs actually use: 89% count the number of referrals for suspected fraud, 70% count the number of referrals accepted for investigation, 59% count claims referred that are mitigated and 52% count claims referred that are denied. Cycle time from start to completion by referral is used by 45%, and average cycle time by investigator by 44%. Only 2% count the number of cases reported to the state department of insurance under mandatory reporting.
Those percentages describe a management system that is very good at counting what arrives and what is accepted, and roughly half as good at measuring the interval in between. That interval is the labour. It is also the only part of the process a carrier can compress without either detecting less or accepting less.
What is in that interval is not mysterious, and naming it is the fastest way to see why prioritisation cannot substitute for it. On a single accepted referral: pull and timestamp the evidence before it changes, test the documents for alteration, reconstruct the loss timeline from the statement, the police report, the repair invoice and the telematics, cross-reference the statement against prior claims and against what the claimant has said elsewhere, run open-source checks on the parties and the vendors, reconcile the financial pattern, decide what the contradictions mean, and write it up so an examiner reading the file in eighteen months can follow how the conclusion was reached. Hesper runs 15+ investigation phases in parallel because that list is what an investigation is, and because a human runs it sequentially by necessity.
Prioritisation decides which of those lists gets started. A single workflow decides where the notes go. The list itself is the work, and it is the thing that takes weeks.
The gap between a prioritised queue and a closed finding, measured
The gap between a prioritised queue and a closed finding is measurable, and the insurance industry already measures it. The Coalition Against Insurance Fraud and PwC define overall SIU cycle time as the interval between referral acceptance and closure. Of the insurers that capture it, 47% report 21 to 60 days and 12% report 61 days or more.
Where that clock starts is the whole point. It does not start at FNOL, and it does not start at the moment a model raises a flag. It starts at referral acceptance, which is after triage and after the case has landed in the workflow. Everything Fraud Discovery's bullets four and five improve happens before the clock starts. The study puts it plainly: the time between referral acceptance to closure is also important to evaluate, overall cycle time consideration is reported by 64% of respondents, and of those, 47% report cycle times between 21 and 60 days, 12% report a cycle time of 61 days and greater, and 5% report times of 0 to 20 days. The remaining 36% do not capture cycle time.
Two readings of that chart matter. The first is that the longest bar is the one for carriers that do not measure the interval at all, which is a governance finding as much as an operations finding. The second is that among carriers that do measure, the distribution sits overwhelmingly on the far side of three weeks. Taken across all respondents rather than only those who measure, 47% of 64% works out at roughly 30% of SIUs reporting a 21 to 60 day post-acceptance cycle, and 12% of 64% at roughly 8% reporting 61 days or more. Those two are derivations from the published percentages, not published statistics.
Hesper's internal benchmark for manual desk investigation is 14+ days per case, which sits at the optimistic end of that published range rather than beyond it. An investigator carrying 200+ open cases closes roughly 10 investigations a month at roughly $2,500 per case. Multiply the throughput figure by the SIU headcount and you have the carrier's real annual investigation capacity, and it is fixed before anyone reads a file.
The same shape one tier up, at the state bureau
Before the next numbers, the caveat they require. The California Department of Insurance Fraud Division is the state fraud bureau, not a carrier SIU. Suspected fraudulent claims, or SFCs, are reports made to the Division, largely by carriers under California's SIU regulations, plus anonymous tips. New cases assigned are criminal cases the Division itself opened. These figures do not measure how many flagged claims California carriers investigate, and they should never be quoted that way.
The shape is still instructive. One tier up from the carrier, at a bureau that exists purely to work these referrals, a large intake produces a small number of opened cases. The four CDI anti-fraud program pages publish fiscal year 2023-24 figures separately, for automobile, workers' compensation, property, life and casualty and disability and healthcare. Summing them is a Hesper derivation rather than a published total.
Under 5% of the suspected fraudulent claims reported to the Division in that fiscal year became a new assigned case, against $881.6 million in potential loss across the four programs. The property, life and casualty program is the sharpest single line: 4,580 reports, 52 cases assigned, and the largest potential-loss figure of the four at $362 million. Inside a carrier the same arithmetic runs one book at a time, with no annual report attached to it. The mechanics of how that gap forms are in why 75% of flagged insurance claims are never fully investigated.
The referral machine already outruns the investigation machine
The Coalition and PwC study contains four figures that, read together, explain why better detection does not produce more closed findings. Almost half of respondents, 46%, do not currently have the capability to automate referrals to their investigative team. Even though most respondents use analytics, 83% state that at least a portion, between 51% and 100%, of their referrals are still manual referrals, and 33% use only a manual process for referring suspicious claims through a company associate. Only 33% of respondents detect more than 3% of new claims as suspicious, while 47% detect less than 3%, against an estimate of around 10% of all claims being potentially fraudulent that the Coalition attributes to NICB, III, the Coalition itself, NAIC and IASIU.
So referral volume has a lot of headroom. If a platform closes even part of the distance between a 3% referral rate and a 10% fraud incidence estimate, referral volume roughly triples. That is exactly what a unified platform with better analytics, network analysis and media forensics is built to do, and it is a good thing to do.
Here is the part that makes it a capacity problem rather than a detection win. The same study found that 53% of respondents determine SIU staffing levels by the number of total referrals sent to the SIU team, and another 12% by the total referrals assigned per investigator. Two-thirds of carriers size the investigative team off referral volume. Improve detection and prioritisation without changing the per-case labour, and you have increased the denominator of the capacity problem the tooling was bought to relieve.
The industry says this about itself, in its own words, in the Coalition's 2024 technology study. The benefits respondents name, largest to smallest, include increased speed of detection, more referrals, higher quality referrals, more consistent identification of referrals, increased mitigation of losses determined to be fraudulent after investigation, more consistent claims investigations, uncovering complex or organised fraud activity, enhanced reporting and straight-through processing. The challenges they name include limited IT resources, excessive false-negative and false-positive rates, data integration and poor data quality, lack of cost-benefit analysis, and, verbatim, "SIU cannot handle the volume of potentially fraudulent claims."
Put the two lists side by side. The benefits column is detection and referral volume. The challenges column contains the consequence. That is the thesis of this post written by the Coalition's respondents rather than by a vendor. The same study reports that roughly 71% of carriers saw suspected fraud against them increase over the preceding three years, again read off a bar chart, which is the demand curve underneath both columns.
The pool being drawn from is not small. The Coalition Against Insurance Fraud puts US insurance fraud at $308.6 billion a year, reports that fraud occurs in about 10% of property-casualty insurance losses, and notes that 84% of insurance organisations say the fraud cases they investigate involve more than one industry. Every improvement at layers one through five raises the number of claims that arrive at layer six. That is the mechanism by which better tooling makes the downstream bottleneck more visible rather than smaller.
Media forensics is now table stakes
Digital media forensics tests images and documents for signs of manipulation, alteration and deepfakes. In 2026 it is table stakes rather than a differentiator. Verisk sells it standalone, has bundled it into Fraud Discovery, and licenses the same engine into a competitor's product. Nobody in this category can differentiate on it any more, Hesper included.
Bullet three of the Fraud Discovery release is analyse images and documents for signs of manipulation, alteration and deepfakes. That capability is not new to Verisk. Digital Media Forensics already exists as a separate Verisk product. What makes the commoditisation argument concrete is where else the same engine ships. FRISS and Verisk Claims UK announced a digital-media-forensics partnership under which Verisk's Digital Media Forensic service is embedded into FRISS Media Check, described on both the FRISS press page and the Verisk newsroom. Pieter Nel, Chief Commercial Officer at FRISS, described it as having embedded advanced forensic capabilities into the FRISS solution suite so insurers can verify digital media with confidence. Chris Sawford, Managing Director of Claims UK at Verisk, framed it as enhancing fraud detection, mitigating risk exposure and strengthening trust in digital evidence.
So the same forensic engine is inside Verisk's own new platform and inside a competing vendor's product at the same time, while Carpe sells a rival in Carpe Vision. When that is the market structure, we detect deepfakes too has stopped being a differentiating sentence for anybody. It is a requirement, like TLS. A buyer should check that a vendor has it and then stop weighting it in a scorecard.
Then the turn that matters operationally. Detecting a manipulated photo is a finding about a file, not a finding about a claim. Suppose the forensics come back positive on one of six damage photos on a property loss. That result does not tell you whether the insured manipulated it, whether a contractor supplied it, whether it is a duplicate of a genuine photo cropped badly by a phone app, or whether the loss happened anyway. Something still has to reconcile the flagged image against the recorded statement, the loss timeline, the prior claim history, the repair invoice and the adjuster's own inspection notes, then decide what the combination supports. That reconciliation is layer six. The evidentiary landscape around it is changing quickly, which we covered in deepfake insurance claims and AI-generated fraud in 2026 and in the AI-generated evidence investigation playbook.
Hesper runs document and image forensics as one of 15+ parallel investigation phases, and we do not present it as the product. A forensics verdict that arrives without the rest of the file attached creates a new question rather than closing one, and the SIU still has to answer it.
Incumbents broaden sideways, not down
Incumbent fraud vendors in 2026 are broadening horizontally across the insurance lifecycle rather than descending vertically into investigation depth. Verisk's 2026 acquisition went into catastrophe and geospatial intelligence. Fraud Discovery extends visibility across underwriting, claims and fraud teams. Carpe's newest engine went into small-commercial underwriting. The gravity of this market runs sideways.
Three data points from the last nine months make the pattern legible. First, Verisk acquired McKenzie Intelligence Services in July 2026, a UK geospatial and catastrophe-intelligence firm, folding it into Verisk's Catastrophe and Risk Solutions. That is capital going into a different part of the lifecycle, not into fraud investigation depth. Second, bullet six of the Fraud Discovery release is improve fraud visibility and collaboration across underwriting, claims and fraud teams, which is an explicit horizontal extension of the fraud function across departments. Third, Carpe launched its Minerva Reasoning Engine in August 2026 for small-commercial underwriting, evaluating 200+ business characteristics across 50M+ US business profiles, with claimed reductions of up to 25% in underwriting touches and 30 to 45 minutes saved per submission. Carpe's next major build after Carpe Claims went sideways into underwriting rather than down into investigation, which is the same clause we made in Carpe Data alternatives.
None of those three is a mistake. Horizontal expansion is where the addressable revenue is for a data and analytics business, and catastrophe intelligence, cross-department fraud visibility and small-commercial underwriting are all larger markets than SIU investigation labour. The consequence for a carrier is simply that layer six stays open, because nobody with the balance sheet to close it is aiming at it.
The Allianz double-buy is the cleanest evidence that carriers already reason in layers
Allianz is named as a Fraud Discovery launch adopter in September 2026. In January 2026 Allianz announced a global partnership with Anthropic covering workforce empowerment, operations automation through agentic AI, and regulatory compliance, with named use cases spanning intake documentation through claims processing in motor and health, a multilingual roadside voice assistant at Allianz Partners, food-spoilage claims automation at Allianz Australia and pet-insurance invoice processing. Oliver Bäte, CEO of Allianz SE, and Dario Amodei, CEO and co-founder of Anthropic, are both quoted.
One carrier bought a frontier-model partnership and a specialist fraud platform inside nine months. Those are not substitutes and nobody at Allianz appears to think they are. A frontier-model partnership is capability, governance and a build surface. A specialist fraud platform is packaged intelligence, analytics and a queue. A carrier that understands the difference is exactly the carrier that will ask the layer-six question early, because it is already reasoning about which layer each purchase serves rather than which vendor has the broadest logo slide.
What to ask a fraud case management vendor
A fraud case management evaluation should separate the six layers explicitly, because a platform that scores well on five of them can still leave the sixth entirely to your staff. Ten questions do that work inside a normal demo, and none of them requires a technical briefing to ask or to score.
- Who performs the work between referral acceptance and closure, your system or my staff? If the answer is my staff, you are buying layers one through five, which is a legitimate purchase. It is not investigative capacity, and it should not be scored against that line.
- What is your measured cycle time on the referral-acceptance-to-closure interval, and how do you measure it? The Coalition's 47% reporting 21 to 60 days is the benchmark to hold the answer against.
- What share of accepted referrals does the system close without a human touching the evidence? Zero is an acceptable answer for a case management system. It is not an acceptable answer for a capacity claim.
- When two of your sources disagree, what happens? A network hit that contradicts a recorded statement is the normal case, not the edge case. Ask to see the arbitration on a real file rather than on a slide.
- Does the audit trail reconstruct the reasoning or only the actions? Most case management audit trails are excellent at who did what and when, and silent on why. A market-conduct examiner reads the second one.
- Does the system file the state fraud bureau report or prepare it for a human to file? Both are fine answers. Only one of them removes a deadline from someone's calendar.
- Which of the six layers is this module, and which layers do you expect me to already have? A vendor that answers this crisply is a vendor that has thought about its own boundaries.
- What happens to the queue when the referral rate goes from 3% to 6%? Ask for the staffing implication in headcount, not in a reassurance.
- How does the output appear in the antifraud plan we file under NAIC Model Act 680, and does it satisfy California's 10 CCR 2698.36 documented-decision requirement?
- If a state examiner pulls a closed file in eighteen months, what does the record show about how the conclusion was reached, and who signed it?
Questions nine and ten are the compliance officer's, and they are the two most often skipped in a fraud-tech demo because they sound like paperwork. They are not paperwork. NAIC Model Act 680 has been adopted in 48 states and requires an antifraud plan describing how the carrier detects, investigates and reports suspected fraud. California's 10 CCR 2698.36 requires documented decisions on SIU referrals. A case management system produces the container those obligations live in. Something still has to produce the documented decision the container holds, and if that something is a person working through a backlog, the documentation quality varies with how much time that person had.
Question three is the one that separates the categories fastest, and it is worth being precise about why. Every vendor in this market can point at automation. The useful follow-up is always the same: automation of what. Automated intake is layer five. Automated scoring is layer two. Automated network traversal is layer three. Automated forensics is layer four. Automated closure of an accepted referral with a documented finding attached is layer six, and it is the only one of the five that changes coverage.
Where Hesper sits
Hesper AI occupies layer six and nothing else. It takes a flagged claim, runs 15+ investigation phases in parallel, reconciles what they return, and writes a documented finding into the case management system the carrier already owns. Detection is upstream; investigation is downstream. Hesper is complementary to FRISS, Shift Technology, and Verisk - not a replacement.
The phases run simultaneously rather than sequentially: document and image forensics, OSINT on parties and vendors, statement cross-reference, timeline reconstruction, financial pattern analysis, prior-claim correlation and the rest. A human investigator runs that list one item at a time because attention is the bottleneck, and that is where 14+ days per case comes from. An agent's per-case attention is not a constraint, so the same list runs at once and the finding arrives in hours, not weeks. Every source, decision and timestamp is logged as the work happens, which is why the output is audit-trail-native rather than audit-trail-capable.
The metric that matters is coverage, not speed. Manual SIU teams across US P&C carriers fully investigate roughly 25% of flagged claims; the rest are paid, denied without full work, or left in a queue. At the cost and cycle time of an autonomous investigation layer, the threshold for what is worth working moves and coverage goes to 100%. Make every flagged claim investigable. That is the single change in this stack that moves loss cost rather than moving work around inside it.
Hesper's negatives, stated plainly
Hesper is not a data utility and does not replace ISO ClaimSearch or any contributory database. It does not sell a suspicion score as its product, though fraud detection is built in, which means it runs standalone for carriers whose referrals come from adjuster judgment and configured rules rather than a purchased score. It does not replace the case management system of record; it writes its finding into whichever one the carrier already runs, including Verisk Fraud Discovery if that is the one. And it does not adjudicate. The SIU lead and the adjuster decide what the finding means for the claim, and the investigator's role shifts from execution to decision-making. From fraud detection to fraud resolution describes the layer, not the decision.
For a carrier already running Verisk, the practical question is not whether Fraud Discovery is good. It is which line in the procurement memo it should be scored against. Intelligence, detection, network analysis, media forensics and case management are five real lines and it plausibly serves all five. Investigative capacity is a sixth line, and nothing in the release is offered against it. The vendor-level version of this comparison is in Hesper AI vs Verisk, the shortlist view is in 5 Verisk alternatives for insurance fraud detection in 2026, and the full market map across prevention, detection and investigation is in the 2026 AI fraud platforms buyer's guide.
What Verisk shipped on September 8 is a well-built consolidation of five layers, described accurately and without overclaiming, with three real launch adopters behind it. The layer that is still open is open across the entire category, and it has been for as long as the category has existed. The Coalition's respondents named it themselves when they listed SIU cannot handle the volume of potentially fraudulent claims as a challenge in the same study where they listed more referrals as a benefit. Both of those sentences are true at the same time, and only one of them is a product anyone currently sells.
Key takeaways
- Verisk Fraud Discovery, announced September 8, 2026, unifies fraud intelligence, advanced analytics, network analysis, digital media forensics and case management in one modular platform, with Hiscox, Allianz and Weightmans named as launch adopters, no performance metric claimed, and no geographic availability stated.
- Sorted by job, the fraud stack has six layers, and Fraud Discovery names five of them; investigation execution, the labour between an accepted referral and a closed finding, is not claimed in the release and is not claimed by FRISS, Shift, SAS, Guidewire or any standalone case-management tool either.
- The Coalition Against Insurance Fraud and PwC measure SIU cycle time as the interval from referral acceptance to closure, and of the 64% of insurers who capture it, 47% report 21 to 60 days, 12% report 61 or more, 5% report under 20 days, and 36% of all respondents do not measure it at all.
- Case management is already installed rather than missing: 74.3% of carriers in the Coalition's 2024 technology study have it incorporated and 34.3% built it in house, so a unified platform purchase is mostly consolidation of capabilities a carrier already owns in pieces.
- Two-thirds of carriers size SIU staffing off referral volume, which means better detection and prioritisation lengthen the queue unless something changes the per-case labour, and an autonomous investigation layer that runs 15+ phases in parallel is what moves flagged-claim coverage from roughly 25% to 100%.