Nestack Agent Care
Industries / Insurance / Fraud-review assistant

Insurance AI agent · Fraud review

Fraud-Review AI Assistant

Surface the indicators on a claim or application, link the claims, parties and providers behind them, and hand an SIU investigator an evidence pack — the referral is theirs, and the clock keeps running.

4–6 weeksTypical delivery
Your stackDeployment
InvestigatorReferral
Agent CareAfter launch

What this agent does

Surfaces the indicators, never the finding

In
01

Take the claim or application as submitted — parties, loss detail, documents, images, payees and policy history.

02

Read the indicator set the SIU signed off, at the version in force, with the evidence each indicator requires.

Reason
03

Run those indicators and record which fired, on which field, against which value in the file.

04

Link the claims, parties, addresses, vehicles, bank details and providers that connect this case to others.

05

Test every link before it counts — a shared address that is a block of flats or a hire desk is not a link.

Decide
06

Where nothing fires and no link holds, the case carries on down its normal path, unmarked and unheld.

07

Everything else goes to a qualified SIU investigator, with the claim clock and the adjuster's file untouched.

Out
08

Hand over an evidence pack — each indicator, the record behind it, each link, and what was checked and ruled out.

09

Retain the indicator version, what fired, who read it, what they decided and what the investigation found.

Product statement

The agent surfaces indicators and assembles evidence. Whether that becomes a referral belongs to a qualified investigator, and anything that touches the claim — a hold, a payment, a denial, a letter to the insured — belongs to a licensed adjuster. A flag is not a finding, on any tier and in any configuration.

Example workflow

One case, end to end

AgentHuman
1Case receivedA claim at notification, mid-life or reopening, or an application at new business, with the file as it stands
2Indicator set pinnedThe indicator set, version and approval date the SIU has in force for that line and claim type, with the date read
3Indicators runEach indicator marked fired or not fired, against the field and the value in the file that made it fire
4Links tested, pack assembledRelated claims, parties, addresses, vehicles and providers, each link corroborated or dropped, with what was ruled out
No human action required

Stages 1 to 4 run without a person in the loop — the indicator run, the link tests and the evidence pack are finished before an investigator opens the case. Nothing has been alleged.

5DecisionSplits on whether any indicator fired or any link held
Nothing fired, no link held

Carries on down the normal claim path.

An indicator fired or a link held

Goes to an SIU investigator, unreferred.

SIU investigator

Reads the evidence themselves, decides whether this is a referral, and writes the reason in their own words.

Refer · Close · Send back
Closed — handed back
6Investigator outcome recordedRefer, close or send back, in the investigator's own words, under their name, with the indicator version attached
7Outcome evaluatedReferral precision against investigator outcomes, indicator contribution, cohort disparity and time in hold for claims later cleared
Investigator outcomes

Every case closed with nothing found is counted against the indicator that sent it.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Concluding that a person committed fraud.
Referring a case to a fraud bureau.
Holding, delaying or reducing a payment.
Denying, rescinding or voiding cover.
Automation boundaryAgent acts unaided
Pin the indicator set, version and approval date to the case.
Run the approved indicators and record what each one fired on.
Test every link before it counts, and say what it rests on.
Assemble the evidence pack from records the file already holds.
Write actions run only inside the approval boundaries agreed during implementation. Holding a payment is not one of them — a licensed adjuster places any hold under their own authority, and the clock is measured from there.
Telling the insured, a provider or a third party.
Writing into a shared industry fraud database.
Adding, retiring or reweighting an indicator.
Reopening a case an investigator has cleared.

Example output

One case, annotated

Everything the agent marks is attached to the indicator and the record line it fired on.

Fraud-review output · single caseIllustrative example
Case
Indicator set
Claim status
Indicators fired
Confidence
Referral
Third-party motor injury
In force, dated
Open, no hold
Three of forty
88%
None — investigator's
As receivedThe file as it stands and the indicator set in force for that line, with the version and the date it was read.
Evidence used Prior claim, same vehicle Invoice reused across files Hire period overlaps loss
Why three firedThree approved indicators matched values in the file — not the claimant.
ActionReferCloseSend back
What the score decidesHow much checking the pack still needs, not whether to refer. It never holds the claim.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every claim and applicationFrom FNOL, claims and new business
03Indicators & links

Apply the indicator set the SIU owns

The indicators your unit approved, at the version in force for that line and claim type — read at run time and stamped with the date.

01Approved path

Keep the clean claims moving

A case where nothing fires and no link holds is not marked, not held and not queued — it carries on down the path it was already on.

02Human review

Hand over a file, not a score

The indicators, the records they fired on, the links that survived corroboration and what was already ruled out — assembled before the case is opened.

04Build an evidence trail

Retain the indicator version, what fired, the links tested and dropped, the investigator's own reason and how the case closed — on both paths.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Claims & policy adminGuidewire ClaimCenter · Duck Creek
Sapiens · claim and policy APIs
SIU & referralSIU case systems · referral queues
State fraud-bureau filing · NICB
Industry & shared dataISO ClaimSearch · shared registers
Watch lists · external data sources

Agent

Fraud review & referral support

Runs indicators
Tests links
Hands to SIU

Documents & paymentsInvoices and estimates · image forensics
Document metadata · payment hold
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and a referral

Each control wraps the one inside it. An indicator clears every layer before an investigator sees it, and the referral itself sits outside all six.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeReturn indicator running to staff if precision or disparity degrades.Roll back
L5TraceabilityRecord the indicator version, what fired, who read it and the outcome.Record
L4Clock protectionA flag holds nothing; only a licensed adjuster may hold a claim.Protect
L3No-finding ruleNo conclusion of fraud, no referral, no score that stands for one.Withhold
L2Link corroborationNo link counts on one shared value without a second fact.Corroborate
L1Indicator versioningIndicator set, version and approval date pinned to the case.Pin
Model coreIndicator run — which indicators fired, the record each fired on, the links tested and retrieval confidence
L1 – L2Decide whether an indicator may stand
L3Keeps a finding out of the agent
L4Keeps the claim clock running
L5 – L6Keep the trail and pull automation back

How Nestack evaluates it

Evaluate the pack — and what the investigator did with it.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the evidence pack an investigator opens
Depth of coverage ▼
E1Final-output evaluationDid what fired hold up against what the investigator found?
E2Step-level evaluationWas each link corroborated, or did it rest on one shared value?
E3Tool evaluationDid it read the correct claim, party, policy and shared-data record?
E4Indicator contributionWhich indicators carry the referrals, and are they stable over time?
E5Slice evaluationHow does performance change across claimant cohorts, lines and areas?
E6Business outcomeTime in hold for claims later cleared, and what investigators closed.
Floor — the referral an investigator stands behind

Failure modes

Where each failure originates in the agent

Seven failure modes plotted against the five stages of the agent lifecycle.

Agent lifecycleDirection of processing →
01 · Indicator lookup1 mode
FR-01

Indicator is a cohort proxy

It tracks a postcode or a cohort, not behaviour.

Stage pinsThe indicator set, version and approval date in force
02 · Case retrieval1 mode
FR-02

Cleared allegation resurfaces

A closure returns as a fresh signal on a new claim.

Stage gathersThe claim, the parties, the documents and shared data
03 · Link testing2 modes
FR-03

Shared address read as a link

A block of flats or a hire desk counted as a link.

FR-04

Provider flagged on volume

High claim count read as a pattern of fraud.

Stage testsEvery connection to another claim, party or provider
04 · Pack / handover1 mode
FR-05

Flag runs the clock down

A legitimate claim sits past its statutory deadline.

Stage hands overThe evidence pack an SIU investigator actually opens
05 · Drift / Version2 modes
FR-06

Indicator set goes stale

Yesterday's patterns run against today's fraud.

FR-07

Alert volume trains dismissal

Packs arrive faster than the unit can read them.

Stage tracksIndicator changes, fraud patterns and closed outcomes
Sev-1 · the agent has shaped an accusation Sev-2 · the pack overstates what is known Sev-3 · signal degrades, investigators stop reading

Affected slices

The flags land on the people least able to wait

A few claimant cohorts carry most of the flags an investigator later closes with nothing found, and they are the cohorts least able to sit out the delay. Nestack reports performance by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Low-income postcode cohorts7.4%3.7× Review
Hire and courtesy vehicles5.6%2.8× Review
First-time claimants3.6%1.8× Watch
Repeat renewing policyholders1.5%0.8× Normal
Bar: unfounded-flag lift vs. renewing-policyholder baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

Closed with nothing found is a result, not a non-event

An indicator sent that investigator there, and a claimant waited while they read it. Both belong in the evaluation of what the agent surfaced.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

More flags close with nothing found, or one cohort waits longer than the rest.

02Diagnose

An indicator, a link rule, what was retrieved, or where the threshold sits.

03Improve

No indicator, link rule or threshold moves without the SIU lead and a version stamp.

04Verify

The change is replayed over held-back cases and every case closed with nothing found.

05Learn

That case is kept whole, with the indicator that fired, and re-read every cycle.

Learn → DetectThe return edge. Every cycle also reads the clock — a claim that waited on a flag and then cleared is counted as a failure of the agent, not as caution.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, indicator and data sourcing, link testing and pack assembly, evaluation, referral workflow, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Workflow discovery and automation-boundary definition.
02Indicator-set review and SIU sign-off.
03Claims, SIU and shared-data integration.
04Indicator versioning and date pinning.
05Case and party retrieval scoping.
06Link testing and corroboration rules.
07Evidence-pack format sign-off with investigators.
08Clock protection and the no-hold constraint.
09Investigator review and referral workflow.
10Precision, disparity and time-in-hold evaluation.
11Fraud-bureau and shared-data packs.
12Observability, deployment and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne line, one indicator set ProductionProduction SIU integration AdvancedMulti-line / multi-entity
Introduced at Pilot
Indicator run and versioning
Link testing and corroboration
Evidence pack for investigators
Investigator referral gate
Baseline and cohort-disparity evaluation
Introduced at Production
Claims and SIU case integration
Shared-data and watch-list lookups
Time-in-hold and clock protection
Observability and audit trail
Introduced at Advanced
Investigator's fraud-bureau filing pack
Multi-line and enterprise controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on the lines in scope, the indicator sets and shared-data sources used, claims and SIU integrations, case volume, referral workflow controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01The lines, claim types and case volumes in scope Workflow discovery and automation-boundary definitionWeek 1
02Your approved fraud indicators and who signed them off Indicator-set review, versioning and date pinningWeek 2
03Access to claims, SIU case management and shared data Guidewire or Duck Creek, SIU case systems and ISO ClaimSearchWeek 2
04Your rules on what may be shared, and with whom Retrieval scoping and disclosure limits on the packWeek 3
05Real cases, including the ones closed with nothing found Evaluation suite, regression cases and failure-mode testingWeek 4
06Named SIU investigators and a claims lead Referral workflow, pack format and precision trackingWeek 4
07Your claim-handling clocks and who may hold a payment Clock protection, the no-hold constraint and the audit trailWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Phases are drawn over the weeks they actually occupy. The overlap in week 5 is where referral precision is first measured against what investigators closed.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Lines and indicator sets in scope; who may hold a payment W2Indicator versioning, claims, SIU and shared-data integration W3Case retrieval, link corroboration and the evidence-pack format W4Referral workflow, evaluation suite, cohort slices and failure-mode testing W5First live packs, referral-precision measurement and corrections W6Investigators work live cases from agent packs, then handover
Reading the bandReferral precision in week 5 is measured against investigator outcomes on live cases, not a retrospective sample. Each bar covers its own weeks only.
At the end of W6Investigators have worked live cases from agent packs, and no claim in that period was held or delayed on a flag alone.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Insurance AI agent

Build a fraud-review assistant around the investigators you already have.

Show us your indicator set, how a case reaches SIU today, and who may hold a payment. We'll assemble one case as an investigator would want it, and agree what it may never say and what it may never delay.

Nestack Agents · Fraud review & referral supportAGT-INS-06 · Agent Care available after launch