Insurers and lenders with vehicle exposure face a structural problem: the data they use to decide describes the past. Bureau scores, registration history, and applicant declarations tell you who the applicant was, not the risk they carry today.
The policy is bound based on who the applicant was. The loan is approved based on what they paid before. After that, in most operations, nobody looks again until renewal or until the loss, whichever comes first.
That interval is where the money goes. Three pillars close it: security at the door, control during the contract, and intelligence at the event.
Why does pricing the past fail?
Because vehicle risk has three distinct origins, and the traditional model only sees one of them.
- Credit risk: the applicant may be unable to pay. The bureau predicts this reasonably well.
- Fraud risk: the applicant never intended to pay. The bureau doesn't predict it and often predicts the opposite, because the professional fraudster keeps a clean file as the entry ticket.
- Behavioral risk: how the asset is used changes after signing. The bureau can't see it, because the data didn't exist when the pull was made.
Treating all three with the same tool produces the outcome the industry knows well: declining applicants who would have performed, binding the ones who won't, and finding out late in both cases.
The scale is large. The Coalition Against Insurance Fraud estimates insurance fraud costs the U.S. economy roughly $308.6 billion a year, with property and casualty accounting for about $45 billion of it. Separately, the FTC reported $15.9 billion in consumer-reported fraud losses in 2025. Most of that exposure is discovered after the loss. In other words, it was priced as if it weren't there.
Pillar 1. Security: block fraud before it enters
The most expensive fraud is the one already inside the book. Once the policy is bound or the asset released, the cost of discovery is the full exposure.
Sophisticated fraudsters clear basic KYC. The documents are valid, the selfie matches, the score is adequate. Nothing is wrong with the file, and that is the point. What distinguishes them is the network around them, not the individual profile.
Zarv ID reads each applicant in the context of the structure they belong to. That is what exposes the fraudster who passed the file review clean.
We covered this in scammers disguised as good customers and the silent behavior of fraudsters. The underlying principle: a single identity has very little surface to hide anything, which is why organized fraud operates as a network.
Two conditions decide whether this pillar works in practice:
- The underlying records have to be read correctly. Court and public records arrive with missing dispositions, duplicate entries, and inconsistent coding across jurisdictions. Under the FCRA, an adverse decision built on a mislabeled record is the user's exposure, not the court's.
- Verification has to be one step. Splitting identity and fraud screening into two separate moments multiplies friction and loses the good applicant in the middle.
Pillar 2. Control: continuous intelligence over the portfolio
Risk doesn't freeze at signing. Drivers change routines, vehicles move to new regions, usage profiles transform. The structure around the customer changes without anything in the file changing.
A carrier that only reassesses at renewal is always pricing the past. The gap between the real change and the discovery is where the loss compounds.
Zarv Signal follows behavior, location, and exposure continuously. That enables three moves the annual model doesn't allow.
Alerting before the event
Abrupt mileage drops, operation outside the declared territory, atypical dormancy, shifts in time-of-day usage. These signals appear weeks before delinquency or loss. Each one opens a window to act while the problem is still a conversation.
Mid-term repricing
When measured risk diverges from priced risk, the premium is corrected mid-term: upward where exposure grew, downward where behavior proved better than assumed. The second case matters as much as the first, because it stops good risks from subsidizing bad ones. We go deeper on this in fleet claims management.
Portfolio-level anomaly detection
Some patterns only surface in aggregate: unexpected geographic concentration, clusters of contracts behaving in sync, vehicles whose usage profile doesn't match the declared purpose.
It's worth stating plainly what separates this from tracking. A tracker answers where the vehicle is, the right question after the loss. Before it, the question is whether this customer's behavior is changing, and location alone doesn't answer that. We laid out the difference in real-time asset monitoring.
Pillar 3. Intelligence: evidence for every decision
Suspicion doesn't deny a claim. Evidence does.
This is where most operations lose money quietly. The adjuster knows something is wrong, can't prove it, and the claim is paid. Denying without support invites litigation, regulatory attention, and a loss frequently larger than the payout itself.
Zarv Lens reconstructs a vehicle's movement history in the 72 hours before and after an event, cross-referencing license plate reads (LPR), position data, and behavioral signals. The output is a technical dossier with chain of custody.
The practical difference lies in the form of the information, not the amount. Declared source, verifiable timestamps, and an audit trail allow a decision to hold up under challenge, whether the outcome is a denial or a normal adjustment.
It also speeds up the legitimate side. Most claims are honest, and the same evidence that supports a well-founded denial shortens cycle time for the claimant who is telling the truth.
How do the three pillars connect?
They are the same reading applied at three moments in the risk lifecycle.
| Pillar | Moment | Question it answers | Product |
|---|---|---|---|
| Security | Before binding | Who is this applicant, and what structure do they belong to? | Zarv ID |
| Control | During the contract | Has behavior changed since approval? | Zarv Signal |
| Intelligence | At the event | What actually happened, and how do I prove it? | Zarv Lens |
The connection matters because each pillar feeds the next. The intake read establishes the behavioral baseline monitoring compares against. Monitoring produces the history investigation queries. And the investigation outcome feeds back into the intake criteria.
Running only one leaves the loop open. Strong intake with no monitoring finds out late. Monitoring without evidence at the event knows it was fraud and pays anyway.
What does this change in the math?
The common error is treating this as a prevention cost. In practice it's an acquisition instrument.
The logic is direct. When an operation can't see behavior, the only control point is the front door. Without information, the only way to reduce risk at the door is to narrow it: more documentation, larger deposits, higher score cutoffs, more co-signers. Every tightening costs conversion.
When an operation can see behavior, the logic inverts. It becomes possible to approve the profile the bureau declines, because the bet is monitored rather than blind. Being wrong at intake stops being fatal: the error shows up early, while renegotiation, plan adjustment, or active recovery are still options.
So the cost of the reactive model goes beyond the vehicle written off. It includes every good applicant declined over the course of a year to hedge against a loss the operation had no way to anticipate. That number never appears in the loss ratio. It appears in the growth that didn't happen.
Frequently asked questions
Does this replace the bureau score?
No. The score remains useful for what it measures well: ability to pay based on history. What it doesn't measure is fraud intent and behavioral change. The three pillars cover what the score can't reach and work alongside it.
Can we start with one pillar?
Yes, and it's the most common path. The choice depends on where the loss concentrates. If the problem shows up at first payment or first non-return, start at intake. If it shows up mid-term or in the loss ratio, start with monitoring.
What's the difference between behavioral monitoring and telematics tracking?
Tracking reports position. Behavioral monitoring interprets pattern: routine, usage intensity, territory, adherence to the baseline set in the first months. Position is an input to behavioral monitoring, not a substitute for it.
Is this for fleets or for individual contracts?
Both, with different indicators. In fleets the relevant signal is aggregate: behavioral dispersion across drivers, exposure concentration, drift from the contracted profile. In individual contracts it's the trajectory of a single customer over time.
How does this hold up in a dispute?
The dossier is produced with chain of custody: source of each data point, capture timestamp, and audit trail. The goal is a decision that is defensible under challenge, and not merely persuasive internally.
What about FCRA compliance?
When network signals are used to make an adverse decision on a consumer, the requirements of the Fair Credit Reporting Act apply, including adverse action notice and the consumer's right to dispute and correct. Explainability is mandatory here: a signal that can't be articulated to the applicant can't lawfully carry the decision.
Conclusion
Security, control, and intelligence are layers of the same risk infrastructure. Book a demo to see the three pillars applied to your book.
Sources: Coalition Against Insurance Fraud, 2022 ($308.6 billion total; ~$45 billion property and casualty); Federal Trade Commission, Consumer Sentinel Network, 2025 ($15.9 billion in reported fraud losses); Fair Credit Reporting Act, 15 U.S.C. § 1681.
