Skip to content
Decision-Evidence Operating System

Outcome · Counter-fraud, or SIU

The investigation that recovers the money is the one most likely to be thrown out for how it was run.

Open-source collection on a claimant is lawful in narrow circumstances and unlawful just outside them. The line is drawn by what was authorised, by whom, how far the collection went and how long the material was kept — and none of that is usually written down while it is happening.

The one verified number in this market is an absence

0independent, non-vendor benchmarks of commercial insurance-fraud platforms found — a documented search, run 19 August 2026

How we count this

The search is dated and its absence of results is the finding: every widely-quoted fraud-detection number we could locate is published by the vendor selling the platform it describes, and our citation ledger tags each of them unverified. We do not restate them as fact here, and a page that did would fail this site’s own honesty gate. That is why the metrics on this page are about authorisation and retention — the parts of an investigation a court examines — rather than a detection rate nobody has independently measured.

What a governed SIU file is specified to look like

340surveillance collections in the specified SIU dataset, each with necessity and proportionality recorded before collection
28of them refused at authorisation — the refusals stay in the file, because the boundary is the evidence
62auto-purged at retention expiry, with nobody having to remember. The falsifier: find a collection with no expiry — there are none

These are the demo-data corpus specification’s numbers — specified, gate-carried, and designed rather than generated. They describe what the demo dataset must contain to be honest about how an SIU lane should run; they are not counts from any live deployment, and no customer data exists behind them.

How we count this

The legal shape is not ours: the European Court of Human Rights held in Vukota-Bojić v. Switzerland that covert surveillance of a claimant by an insurer can violate the right to private life, and the line of authority since turns on whether authorisation, scope and duration were fixed before the watching started. The specification encodes that ordering — necessity and proportionality recorded before collection, expiry attached at collection — because it is the ordering a court has already tested.

The pilot metric

Projectednet indemnity recovered per investigator-day, measured against a paired baseline lane

How we count this

Net means after the cost of the investigation and after amounts later conceded on appeal. A recovery that is given back at the ombudsman was never a recovery, and counting it as one is how this metric is usually inflated.The falsifier: if recoveries rise while the share of investigations carrying a complete authorisation record falls, the lane is buying recoveries with legal exposure and the result is recorded as negative. Both series are reported, always together.

The mechanism: authorisation before collection, not after the dispute

The authority to look is a recorded decision with a named owner, taken before the first query runs. It states the grounds, the scope and the expiry, and it is part of the file from the beginning rather than an account of it written later.

Every external tool call lands in the investigation trace with its provenance, so what was searched, when, and against which source is legible without reconstructing an analyst’s browser history.

Retention limits attach to the material at collection and expire on their own. A retention policy that depends on someone remembering to delete something is the one that fails at exactly the moment it is examined.

The European Court of Human Rights held in Vukota-Bojić v. Switzerland that covert surveillance of a claimant by an insurer can violate the right to private life. The control that survives that judgement is a record of authorisation and scope made before the collection, not a justification assembled after the dispute.

ROS/src/routes/osint*.ts

NX/services/nexus-workflows/src/services/tool-executors/

Convening Triage + Graduated Escalation

A meta-decision agent scores each submission or claim and convenes the right room, the right chair and the right autonomy tier — and the routing decision is itself a logged event.

NX/services/nexus-orchestrator/src/routes/dispatch-routes.ts

One-Log, Many-Regulator Evidence Fabric

One governed event stream compiles into every regulator’s artefact, instead of four teams reconstructing four different stories from the same week.

NX/services/nexus-workflows/src/services/governance.ts

See it in the console

Decision room — in session
Decision room — in sessionSee it in the gallery →

What runs today, for an SIU file

The collection connectors, the trace and the recorded authorisation run on the two dispatch tiers that are in production. The jurisdiction-pack emitters that would render an investigation file per regime are projections, so a data-protection request today is answered from one complete stream by a person.

Start with the referrals you already make

Nothing about this changes which claims your model refers. It changes what exists afterwards: an authorisation with a name on it, a scope that was set before the search, and material that expires without anyone having to remember it.

Book the 20 minutes

A person replies with two or three times. Not a sequence.