Skip to main content
Insurance

From Suspicious Claims to Connected Intelligence: Rethinking Insurance Fraud

Charlie Weaver
EMEA Commercial Territory Manager, Charlie is the Financial Crime Lead for i2's Commercial Markets across Europe, the Middle East and Africa.

The scale of the challenge

Sometimes the difference between an isolated claim and an organised fraud network is simply seeing the connections.

In one investigation, the Keoghs intelligence team connected 33 separate incidents involving a UK retailer’s delivery fleet. What initially appeared to be individual incidents was revealed as an organised fraud network, contributing to an outcome worth approximately £300,000.

That is the opportunity facing insurance investigation teams: not simply identifying suspicious claims, but understanding the people, organisations and relationships behind them.

Insurance fraud is not a marginal issue. It is a growing and increasingly sophisticated challenge for insurers, investigators and ultimately honest policyholders. 

The latest figures from the Association of British Insurers (ABI) show that insurers detected more than 98,400 fraudulent general insurance claims in 2024, a 12% increase on the previous year. The value of those detected claims reached £1.16 billion. Motor insurance fraud alone accounted for £576 million across 51,700 detected fraudulent claims.  

These numbers are significant, but they only tell part of the story. They represent fraud that has been identified. 

The more interesting question is: what remains hidden? 

Fraudsters do not necessarily operate within the boundaries of an individual claim, policy or insurer. As we have explored previously, insurance fraud increasingly needs to be understood as a network problem, rather than a series of isolated claims. 

The behaviours investigators need to identify can connect people, addresses, vehicles, organisations, intermediaries, devices, financial information and previous claims. That creates an opportunity to rethink not only how suspicious claims are detected, but how they are investigated. 

Rather than asking only: “Is this claim suspicious?” 

We should also be asking: “What is this claim connected to?”

This means investigators need better ways to bring fragmented information together, visualise relationships and retain intelligence from previous investigations. In this article, we look at how that approach can help uncover organised fraud networks faster, understand why a claim deserves attention and build intelligence that supports defensible decisions.

image (12)

Moving beyond rules-based detection

Rules and predictive models remain an important part of the counter-fraud toolkit. They can identify anomalies, highlight unusual behaviour and help investigators prioritise workloads. 

But fraud is adaptive. 

Fraudsters can change the characteristics of an individual claim while maintaining the underlying relationships that connect them to other suspicious activity.  

This is where entity visualisation becomes particularly powerful.

Instead of looking at a claim as an isolated record, investigators can explore connections to previous claims, other claimants, vehicles, addresses, telephone numbers, email addresses, bank accounts, repairers, medical providers, legal representatives, brokers and other relevant organisations.

Individually, many of these relationships may be entirely legitimate. The value comes from seeing them together and in context.

3_CrossClaimConnections_NoEdges

From suspicious claims to connected investigations

At an individual level, entity visualisation can help investigators identify inconsistencies and relationships that might otherwise remain buried within separate systems. 

But the real opportunity emerges when we start looking for networks. Consider a hypothetical scenario where several apparently unrelated motor claims involve different individuals. 

On the surface, there may be nothing immediately obvious connecting them. But when the relevant entities and relationships are brought together, investigators might discover recurring addresses, vehicles, telephone numbers, repair organisations, witnesses or other common relationships. 

One connection may mean nothing. Several interconnected relationships may tell a very different story. 

The investigation therefore moves from:  

Claim A is suspicious. 

to: 

Claims A, B, C and D may form part of the same network. 

This distinction is crucial.  

Organised fraud is fundamentally a network problem. 

And network problems are difficult to solve when the underlying information is held in disconnected records. 

Building an intelligence repository

Visual analysis becomes even more valuable when investigators can draw on intelligence accumulated across previous claims and investigations. 

Rather than treating every suspicious claim as a new investigation starting from zero, insurers can build an evolving intelligence picture around entities and relationships. Policy information, claims information, investigation outcomes and relevant intelligence can be brought together to create a richer historical view. 

Over time, the repository can answer questions such as: 

  • Where has this entity appeared before?

  • What relationships have previously been identified?

  • Which claims or policies are connected?

  • Have similar behaviours been observed elsewhere?

  • Has an associated entity previously been investigated?

  • Has the entity appeared in relevant industry intelligence?

  • Is this relationship new, recurring or strengthening?

This creates something much more valuable than a collection of historical records. It creates institutional memory.  

Every investigation has the potential to improve the intelligence available for the next one. 

The importance of defensible intelligence

There is, however, another critical piece of the puzzle. Intelligence needs to be defensible. 

In an increasingly data-driven counter-fraud environment, it is not enough to produce an alert or highlight a relationship. Investigators need to understand the provenance and context behind the information. For example:

  • Where did the information originate?

  • When was it obtained?

  • When was it last updated?

  • What source type was used?

  • How reliable is the source?

  • Has the information been independently validated? 

and more… 

This creates an auditable trail around the intelligence. It allows the investigators to distinguish between a verified fact, an intelligence lead, an analytical inference and an unresolved hypothesis. 

That distinction matters. 

Good intelligence isn’t simply information. It is information with context, provenance and appropriate evidential weight.

Insurance Fraud screen 2609

Connecting intelligence with wider fraud data

The next opportunity is to connect this intelligence with appropriate external and industry data sources. 

The UK already has mechanisms for industry collaboration and fraud intelligence. The Insurance Fraud Bureau, for example, describes its role as providing fraud intelligence and analytics to support the industry, and its 2024 annual report says members investigated more than £153.3 million in suspected insurance fraud.  

The ABI also highlights the Insurance Fraud Register, an industry-wide database of known insurance fraudsters along with CIFAS’s national fraud database.  

The opportunity is to make these forms of intelligence part of a broader, appropriately governed decision-support ecosystem. A new policy or claim could be assessed against relevant internal intelligence and authorised external datasets. 

If there is a meaningful match, that does not automatically mean the individual is a fraudster. Instead, it can create an alert for further assessment. That distinction is fundamental. 

The objective should not be to automate accusations. It should be to make relevant connections and indicators easier to identify so investigators can focus their attention where it matters most.

Creating an intelligence-led alerting model

Imagine a new claim entering the organisation. Rather than simply passing it through a series of static rules, the entities associated with the claim could be assessed against existing intelligence and progressively connected:

New claim → claimant → address → vehicle → previous policy → previous claim → associated entity → external intelligence match

Each element may appear relatively benign on its own. Together, they may reveal something that warrants further investigation. 

This enables a more sophisticated alerting model based on context rather than isolated triggers and importantly, the alert can carry its intelligence with it. 

Instead of an investigator receiving: “High-risk claim.”  They could receive useful investigative context:

“Potential relationship identified with three previously investigated entities, two historical claims and a recurring address. External intelligence match identified. Confidence and provenance available for review.”

The investigator does not simply receive another alert. They receive context that can help them understand why the claim deserves attention and where to investigate next.

5_Alert

Building a feedback loop

The real power comes when this becomes a continuous cycle:

Detect → Visualise → Enrich → Validate → Intelligence-match → Alert → Investigate → Learn

Investigations outcomes feed back into the intelligence repository, new relationships can be recorded, incorrect assumptions removed or downgraded, confidence levels can be updated and new patterns can be identified.

The intelligence cycle - blog graphic (2)

This matters because organised fraud networks evolve. When one route becomes difficult, fraudsters may change entities, locations, intermediaries or behaviours.

A connected intelligence approach gives insurers a better chance of recognising the underlying network, rather than repeatedly searching for the same fraud signature.

The future is connected intelligence

The rise in detected insurance fraud should not simply lead to more rules, more alerts and larger investigation queues. It should encourage us to think differently about the underlying problem. 

The question isn’t just how we identify suspicious claims. It is how we connect intelligence across the entire claims ecosystem to understand what sits behind them.

Entity visualisation can provide the investigative lens. An intelligence repository can provide the organisational memory. Defensible metadata can provide provenance, context and auditability. Appropriately governed external data matching can provide additional intelligence. And intelligent alerting can bring the right information to the right investigator at the right time. 

Moving from isolated claims towards connected intelligence can help investigators reveal relationships, retain what they learn from previous investigations and understand suspicious activity in context. 

Because the real opportunity isn’t simply detecting more fraud. It is detecting it earlier, understanding it more completely and disrupting the networks behind it. 

Ultimately, the most important question is no longer: “Is this claim fraudulent?” 

It is: 

“What does this claim connect to and what does that connection tell us?” 

See connected intelligence in action

See how insurance investigation teams use i2 to connect fragmented information, reveal hidden relationships and investigate complex fraud networks.

 Explore: how Keoghs exposed hidden insurance fraud networks