The most valuable underwriting dataset at your carrier is the list of claims you did not pay because fraud was established. At most carriers that list is deliberately not kept in a form underwriting can use. That is not an inference: in its September 2024 issue brief on insurance fraud, the American Academy of Actuaries' P/C Committee on Equity and Fairness writes that claims-denial data "is often shunned" because insurers "fear liability from bad-faith legal causes of action."
That is a defensible legal posture and a poor underwriting outcome. Every confirmed-fraud finding is a labeled example: this class code, this territory, this producer, this policy attribute, with the answer key attached. It is close to the only data in the enterprise where fraud is a fact, not a probability. Shun it and the prevention layer you own - underwriting questions, verification requirements, appetite rules, renewal decisions - runs on suspicion and anecdote.
Retention is the second problem. The first is supply. Manual SIU teams investigate roughly 25% of flagged claims, so three of every four potential findings are never produced at all. There is nothing to shun because there was never anything to keep.
What follows is the underwriting case in underwriting language: where premium-side fraud sits in the fraud pie, why coverage rather than detection accuracy sets the volume of usable signal, what undetected fraud does to the loss costs your rate indications are built on, why raising rate on high-hazard classes recruits more premium fraud, and the five things to ask Claims for. The model underneath it is in our breakdown of prevention, detection, and investigation. Prevention is your layer. This post is about the wire between it and the layer downstream.
The loop most carriers never close
The fraud-signal feedback loop is the path a confirmed-fraud finding travels from a claims investigation back into underwriting: into class-plan data, renewal decisions, verification requirements, appetite rules, and rate indications. At most carriers that path is not a process. Claims books the indemnity avoided, closes the file, and the underwriter who priced the risk never hears about it.
Start with the size of the pool. The Coalition Against Insurance Fraud puts annual US insurance fraud at $308.6 billion, a figure the American Academy of Actuaries reproduces and breaks apart. The slice that belongs to underwriting is premium evasion, at $35.1 billion: roughly 78% the size of the entire property and casualty claims-fraud slice of $45 billion, a ratio derived from the Academy's own two figures, and larger than the workers compensation slice of $34 billion. Citing FBI statistics on non-health-care insurance fraud, the same brief reports that the average US family pays between $400 and $700 per year in increased premiums because of fraud.
Premium evasion is not a rounding error next to claims fraud. It is the same order of magnitude, and it lands on earned premium rather than on loss cost, which means it lands on you.
Now the part that gets miscounted inside carriers. A denied fraudulent claim saves the indemnity once. A confirmed-fraud finding that reclassifies a class code, changes a renewal decision, adds a verification step, or amends an appetite rule saves loss cost on every future policy in that segment, every year, until the guideline changes again. Claims books the one-time save and gets credit for it. Underwriting books the recurring save and almost never traces it back to the investigation that produced it. That accounting habit is why fraud-investigation business cases chronically undercount, and why the function that benefits most is usually not in the room when investigation capacity is bought.
Texas Mutual's own published 2024 fraud recap makes the asymmetry concrete at one carrier for one year: $8.3 million in total fraud and abuse identified against 1,454 referrals received, with $5,956,450 of that in premium fraud and $965,114 in claimant fraud. That is a ratio of about 6.2 to 1 in favor of premium fraud, derived by dividing the two published figures. Attention ran the other way, since 1,189 of the 1,454 referrals received were reviewed as claimant-fraud referrals. This is a carrier disclosing on its own book, not third-party research, and workers compensation is where premium fraud concentrates, so the ratio does not generalize. The shape of it does. The referral volume was chasing the smaller number.
Premium fraud is exposure misstated at the front end of the policy rather than loss misstated at the back end. It hits earned premium instead of loss cost, it is committed by the applicant rather than the claimant, and it is found, when it is found at all, by audit, inspection, or a claim that does not match the policy.
The personal lines version already has a name the industry uses. The Insurance Information Institute reports that as much as 14 percent of all personal auto premiums can be attributed to the cost of covering premium leakage. The dollar figure Triple-I carries comes from a Verisk analysis reported by Claims Journal in August 2017: roughly $29 billion a year in personal auto, split into $10.3 billion from unrecognized drivers, $5.4 billion from underestimated mileage, $3.4 billion from unreported violations and accidents, $2.9 billion from false garaging, $2.8 billion from identity exceptions, and $4.1 billion from other sources. The same analysis found nearly 40 percent of policies see a change in driver, vehicle, or address each year.
Note the vintage. That analysis is from 2017 and Triple-I still carries it as the reference figure. The industry has not refreshed its own estimate of the largest underwriting-side leakage category in personal lines in the better part of a decade, which means no underwriting leader is watching that number move.
Verisk owns this message and has for years. It publishes the leakage figure and sells prevention-layer products against it that verify application data at the point of sale. That is the right response to a front-door problem. The distinction worth drawing is narrower: application verification checks the story the applicant told at bind. It does not take a flagged claim, resolve whether fraud occurred, and route the finding back to the class plan. Prevention-layer verification and investigation-layer adjudication are different inputs, and most carriers buy only the first. Workers compensation is where the gap gets expensive fastest, which we walk through in premium fraud and employer misclassification.
The 75% you never investigate is signal you never generate
Flagged-claim coverage is the share of claims your detection layer flags that go on to receive a completed investigation with a documented outcome. It sets how much underwriting-usable fact your carrier produces in a year. Almost nobody reports it, and it matters more than detection accuracy.
Manual SIU teams investigate roughly 25% of flagged claims. The rest are paid, denied without full work, or queued indefinitely, and all three produce the same thing from an underwriting standpoint. A paid claim with an unresolved flag enters the loss data as a clean loss. A denial without a documented investigation is a legal exposure nobody wants to write down. A queued claim is a placeholder. None of them can be coded to a class, aggregated into a segment, or defended in a filing.
The actuaries writing the Academy's brief describe the same gap in their own vocabulary.
Two structural facts sit under the 25%. Throughput: a manual investigation runs 14+ days per case, a single investigator carries 200+ open cases, and the completed-investigation rate lands at roughly 10 per investigator per month. False positives: rules-based detection runs a 60-85% false positive rate, so much of the queue is noise that still consumes investigator hours. Capacity gets spent producing negative findings, which are quietly useful to underwriting too, and those do not get documented either.
This is where the layer distinction stops being vendor taxonomy and becomes an underwriting constraint. Detection produces suspicion. Investigation produces fact. A suspicion cannot enter a rate filing, cannot support a non-renewal, and cannot justify a new verification requirement in the guidelines. A documented finding can do all three.
The reasons the 75% goes uninvestigated are operational, not philosophical, and we catalogue them in why flagged claims never get investigated. The underwriting-side reading is short: every uninvestigated flag is a signal your carrier paid a detection vendor to generate and then discarded before it became usable.
Latency is a separate failure that compounds with coverage. Trace the components without pretending there is a single sourced total: a claim is flagged at first notice of loss; it waits for an investigator; a manual investigation runs 14+ days if it is one of the 25% that gets worked; the outcome is aggregated quarterly; the quarter rolls into an experience period; the experience period supports a rate filing; the filing sits on a statutory review clock. The renewal date on the policy that generated the signal waits for none of it. It arrives on a fixed calendar date, and it arrives first.
The cleanest fraud dataset your carrier owns is the one your lawyers told you not to keep. Above: the loop it has to travel, hop by hop, and the renewal date that arrives before any of it.
What Hesper is and is not, for this reader
Hesper AI does not price risk, file rates, select risks, or replace any part of the actuarial function. It sits at the investigation layer: it takes a flagged claim and produces a documented, audit-ready finding in hours instead of 14+ days, at roughly $150 per case versus ~$2,500 for a manual investigation, which is what lifts coverage from ~25% of flagged claims to 100%. What the underwriter and the actuary do with that supply of findings is their call. The claim here is about supply, not judgment.
Your loss costs already carry the fraud you did not catch
Undetected fraud does not disappear from your data. It is paid as a legitimate loss, enters the loss triangle, and is developed, trended, and filed as the basis for next year's rate. Rate adequacy is therefore partly a function of investigation coverage, and almost no rate indication carries that variable anywhere in it.
California Insurance Code section 1861.05, the Proposition 103 rate approval standard, sets the test in subdivision (a) and puts the burden on the insurer in subdivision (b).
The burden of proving the rate is justified rests on the applicant, and the proof is built on loss data the applicant knows is partly contaminated by fraud it never detected. California is the strictest version of that standard, not the only one. Every state's filing regime asks the insurer to support the indication with its own experience, and every insurer's experience carries whatever fraud its investigation coverage failed to remove.
It is a professional-standards question for the actuary as well as a commercial one for you. ASOP No. 23, Data Quality, states its scope plainly: "This ASOP provides guidance to actuaries when selecting data, performing a review of data, using data, or relying on data supplied by others, in performing actuarial services." It obliges the reviewing actuary to look for "data values that are questionable or relationships that are significantly inconsistent," and the Academy's fraud brief ties anti-fraud data directly to that standard. ASOP No. 43, Property/Casualty Unpaid Claim Estimates, adds the reserving hook in section 3.6.7, Changing Conditions.
Section 3.6.7 names, as an example of such a condition, "changes in the practices used by the entity's claims personnel to the extent such changes are likely to have a material effect on the results of the actuary's unpaid claim estimate analysis." Section 3.6.3 of the same standard points the actuary back to ASOP No. 23 on data.
The converse of that clause is rarely said out loud. If you lift flagged-claim coverage from ~25% to 100%, you have materially changed claims practice. Paid severity on flagged segments should move. Denial rates should move. Development patterns should move. That is not a side effect to manage quietly at year end. It is the intended result, and your reserving actuary acquires a section 3.6.7 obligation to consider it the moment the change goes live.
Do this before go-live, not at year-end review
Agree a written changing-conditions memo path with the reserving actuary before an investigation-layer deployment starts: which segments are affected, the pre-change coverage baseline, the expected direction of movement in paid severity and denial rate, and how the transition period is treated in the unpaid claim estimate. A coverage change discovered in a year-end review looks like an anomaly. The same change documented in advance looks like a planned improvement in data quality, which is what it is.
The corollary for a VP of Underwriting is that a carrier investigating 25% of flags and a carrier investigating 100% of flags will produce different loss costs from the same underlying book. Two identical books, two different indications, because the measurement instrument differs. The dollar version of that argument is in our guide to claims fraud leakage.
Rate is a weak lever where fraud concentrates
The standard response to inadequate rate on a high-hazard class is to raise the rate. On classes where premium fraud is available and cheap, that response partly defeats itself: the higher the rate, the stronger the incentive to misreport exposure, and misreported exposure shrinks the base the rate is applied to.
The cleanest empirical picture comes from a January 2026 working paper by Russell Ormiston, published by the Institute for Construction Employment Research. It is a working paper, not peer-reviewed research, and should be read at that weight. It examines California workers compensation data from 2018 to 2022 and measures employer payroll reporting rates against the pure premium of the class, indexing every band to the lowest-premium band so the comparison is relative rather than absolute.
Reporting holds within 3 points of the baseline while pure premium stays under $6.00 per $100 of payroll, then falls off a cliff: 65.1% of the baseline rate in the $6.00 to $7.99 band, and 46.1% at $8.00 and above. Read those as relative figures. Ormiston indexes every band to the lowest-premium band precisely because the survey data underlying the denominator undercounts earnings, so the baseline already absorbs whatever misclassification exists in low-hazard classes. The finding is the shape of the fall, not an absolute compliance rate: employers in the highest-hazard classes report less than half the payroll that employers in the safest classes do. Every rate increase applied to that class is applied to a shrinking, self-selecting base.
The classification version of the same behavior shows up in California construction dual-wage classes, where employers reported 61.9% of payroll as high-wage while workers themselves reported 40.8% to the Census, a gap implying that as much as 21.1% of reported payroll is fraudulently classified. Ormiston puts an upper bound of $32.4 billion on misreported California construction payroll from 2018 through 2022, about $6.5 billion a year, and an upper bound of $1.25 billion on underpaid premium from dual-wage-class exploitation over the same five years, about $250 million a year.
That is adverse selection with a mechanism attached, and it usually shows up in your retention data before anyone labels it fraud. The honest employer in a high-hazard class pays the rate that covers the dishonest one's unreported payroll, finds a cheaper quote from a carrier that has not noticed yet, and leaves. The class deteriorates. The indication goes up again. The paper cites Coalition Against Insurance Fraud figures placing national employer fraud in workers compensation at $25 billion, nearly three times the size of employee fraud, and a 2023 Century Foundation estimate of $5 billion a year nationally and $571 million in California in unpaid or underpaid premiums from misclassification in the construction industry alone. Both are secondary citations through Ormiston.
The conclusion is not that rate is useless. It is that on the classes where fraud concentrates, rate is a weak lever and verification is a strong one. That reframes claims investigation: it stops being a loss-cost expense owned by another department and becomes an instrument of rate adequacy on the classes you are least able to price your way out of.
The denial data problem, and why documentation is the unlock
Claims-denial data on established fraud is the highest-quality labeled fraud dataset a carrier can hold, and it is routinely suppressed for reasons unrelated to its analytical value. The Academy's brief describes the suppression directly, and the reasoning is the whole point.
Read what that concedes. There is no prohibition on gathering the statistics. The barrier is a judgment about how the data would look in the hands of a skilled adversary. The same passage names the workaround carriers use: "It may be the case that the company maintains records of claims denials for tracking fraud, but it does not want to have it be prominent in team metrics." The data exists somewhere, quietly, and it does not travel. Underwriting never receives it. Detection models are never retrained on it.
The Academy also describes what happens when the loop does work. The second sentence in this passage is grammatically incomplete as published, and is quoted here exactly as it appears.
That is actuaries describing a closed underwriting feedback loop and specifying its measurement: frequency and severity on the problematic profile should fall, and the fall is quantifiable. It is written as an expectation. At most carriers it is not an outcome, because the two conditions it assumes - that claims handling produces findings, and that underwriting adjusts on them - are the two that are missing.
Here is the line from the legal problem to the operational fix. The reason denial data is legally uncomfortable is that an undocumented denial looks arbitrary in discovery. A denial supported by a reconstructable investigation record, with sources, reasoning, timestamps, and every check that was run, is a different exhibit. It is the document you want an adversary to read. The remedy for "we cannot retain this because of bad-faith exposure" is better documentation, not less data. Change the artifact and you change the retention calculus, and only then does the data reach underwriting.
The documentation obligation is not new either. The NAIC Anti-Fraud Plan Guideline already asks insurers to describe their investigation criteria and detection procedures in the plan they file.
A carrier already commits, in a filed document, to having criteria for investigating suspected fraud and technology for identifying it. The open question is whether the artifact those criteria produce is good enough to retain, aggregate, and reuse. That is the distance between fraud detection and fraud resolution, and it is a documentation question before it is a technology question.
It is also where the economics turn. The Academy's brief warns that carriers anchoring fraud measurement on successful prosecutions end up with SIUs that pursue only the cases a local district attorney would take, and ignore fraudulent payments that would never clear a prosecutor's threshold. That bias is partly a cost artifact. At ~$2,500 per manual investigation you can only afford to work the cases with the largest expected recovery, which are the prosecutable ones. At ~$150 per case the set of findings worth producing expands well past that line, and the findings that matter most to underwriting are usually the unprosecutable ones: the misclassified payroll, the unlisted driver, the address that does not match, the pattern across one producer's book. Nobody prosecutes those. Every one of them is a guideline change.
Hesper's investigation layer is built for that reuse case. Every flagged claim gets 15+ investigation phases run in parallel, with each decision logged with its sources, reasoning, and timestamps, and the output is an audit-ready report a human SIU lead reviews and signs rather than a score handed to an investigator who then does the work. From fraud detection to fraud resolution is the shorthand. What it means for an underwriting leader is that resolution is the only state of a claim that produces a durable, codable, retainable fact.
What the VP of Underwriting should ask for
Closing the loop is mostly a set of requests to Claims and a standing meeting, not a procurement event. Five asks cover it, four of them cost nothing but reporting effort, and they are ordered so each is useless without the one before it.
- Flagged-claim coverage, reported quarterly as a percentage, not a raw referral count. Referral counts move with detection sensitivity and say nothing about supply. Coverage says how much of your potential signal is being generated. If nobody in the building can produce the number, that is the finding.
- Confirmed-fraud findings coded to class code, territory, producer, and policy-issue attributes, not just to claim number. A finding filed against a claim number is invisible to underwriting forever. The coding is a small change to a case-management form and it determines whether any of this aggregates.
- Median days from flag to adjudicated finding, plus the share of findings that land before the affected policy's renewal date. The second number is the one that matters and almost nobody tracks it. A finding that arrives after the renewal is bound protects nothing for a full additional term.
- A standing quarterly read-out from Claims into the underwriting guideline review, with a named owner on each side. Not a dashboard. A meeting with a decision log, where each confirmed-fraud pattern either changes a guideline, changes an appetite rule, adds a verification requirement, or is explicitly declined with a reason.
- A pre-agreed changing-conditions memo path with the reserving actuary under ASOP 43 section 3.6.7, so a material change in investigation coverage is a planned reserving input rather than a year-end surprise.
Ask one is the constraint. The other four assume a supply of adjudicated findings that a 25%-coverage operation does not have, which is why the loop stays open at carriers that genuinely want it closed. Hiring is the traditional answer and it does not scale at roughly 10 completed investigations per investigator per month.
This is the layer Hesper occupies. Detection is upstream; investigation is downstream. FRISS, Shift Technology, and Verisk score and flag claims and are good at it. Hesper takes the flagged claim and resolves it end to end in hours instead of 14+ days, which is what moves 800+ cases per investigator per month through a function that used to move about 10. Hesper is complementary to FRISS, Shift Technology, and Verisk, not a replacement, and the investigator's role shifts from execution to decision-making. For the finance framing before you take this to your CFO, our post on measuring fraud investigation ROI lays out the unit economics.
Make every flagged claim investigable and the underwriting signal gets produced as a byproduct of doing claims work properly. That is the argument. Not that AI investigation prices your book, but that it manufactures, at volume and at a defensible standard, the one input your prevention layer has never been able to get enough of.
Key takeaways
- Premium evasion is a $35.1 billion annual category in its own right, roughly 78% the size of the entire P&C claims-fraud slice, and it lands on earned premium rather than on loss cost.
- At roughly 25% flagged-claim coverage, three of every four potential underwriting signals are never generated, so the loop is starved of supply before latency is even a factor.
- Undetected fraud enters the loss triangle as legitimate paid loss and gets priced forward, while California Insurance Code section 1861.05(b) places the burden of proving the resulting rate on the insurer.
- Ormiston's California working paper shows employer payroll reporting falling to 46.1% of the lowest-premium band's rate once pure premium passes $6.00 per $100 of payroll, which means rate is a weak lever exactly where fraud concentrates.
- The cleanest labeled fraud dataset a carrier owns, claims denied on established fraud, is routinely shunned over bad-faith exposure, and a documented, reconstructable investigation record is what changes that calculus.