Control points
What are control points: control points explained
Control points are the technical signals and recorded session events that a capture system logs around a digital submission, such as device history, IP reuse, virtual camera detection and recording location. They tell a reviewer which cases deserve a closer look. They never decide whether a claim is genuine.
What do control points mean in evidence review?
They exist to answer one question for a reviewer: does this case deserve more of my attention than the last forty? They are not a fraud score and not a verdict. A signal is a reason to look, never a reason to reject.
Control points fall into three groups. Automatic signals are computed about the submission and the device. Session events are the log of what happened between the link opening and the submission completing. A signed seal binds the package together.
Typical automatic signals include:
- Time of receipt, set by the server rather than by the participant's phone.
- Digital fingerprint, a SHA-256 hash of every file on arrival.
- Capture-only enforcement, meaning the video had to be recorded in the flow rather than selected from the gallery.
- Virtual camera detection, flagging software that presents a stored video file to the browser as though it were a live lens.
- Jailbroken or rooted device detection.
- Device seen before and IP address seen in earlier claims, the two reuse signals.
- Recording location, a GPS reading with an accuracy radius.
How control points work: ignore, info, amber, red
Raw signals are close to useless on their own, because almost every one has an innocent explanation. So the useful design is not detection, it is grading. Each signal gets a weight set by the organisation, commonly on a four-step scale:
- Ignore. Recorded but not surfaced. You keep the data without adding noise to the queue.
- Info. Visible in the case for context, with no effect on routing.
- Amber. Worth a second look by the handler before the decision goes out.
- Red. Routed to a specialist or counter-fraud team for review.
Where several signals fire, the heaviest colour normally decides how the case is treated. The organisation sets those weights against its own risk appetite, rather than accepting a black-box score it cannot explain to a regulator or to the customer.
Control points example: the shared IP address
Two damage submissions arrive in the same week from the same IP address, and the system raises a reuse signal. A handler looks, and finds both came from the wifi of a bodyshop that submits on behalf of its customers.
The signal did its job. It bought thirty seconds of human attention and produced a clean explanation. Treated as automatic evidence of fraud, that same signal would have wrongly delayed two honest claims.
What control points never prove
A red control point means a human should look harder. It does not mean the claim is fraudulent, and on its own it should never trigger a rejection, a referral to a fraud register, or an accusation.
There are two reasons. The first is accuracy. A device seen before might be a household insuring two cars with you. A shared IP might be a hotel, a fleet depot, a broker's office, or a mobile carrier range covering thousands of subscribers. A developer or a privacy-minded customer may run a rooted phone. A GPS reading far from the reported address may mean the vehicle was recovered to a garage.
The second is regulatory. Decisions with a significant effect on an individual, taken automatically on the basis of profiling, sit under strict conditions in European data protection law. A system that quietly declines on signal weight alone is walking into that territory. Keep the human decision central: the system supplies context, the organisation decides.
When do control points matter?
They matter because the underlying threat changed. Cheap editing tools raised the volume of altered evidence, and the difficult cases are rarely full deepfakes. They are ordinary photos with one detail edited, the pattern covered in our pieces on shallowfake insurance claims and AI-generated insurance fraud.
Control points do not answer that by proving authenticity. They make the capture path itself observable. If the flow requires a live recording in the browser and a virtual camera is detected, that is a specific, checkable fact about the session rather than an opinion about the image. It still needs a person to interpret it, which is where our guide to remote claim inspection picks up the workflow.
Write the response into policy before switching the signals on. Decide who reviews amber cases, what a red case triggers, what you tell the customer, how long you hold the signal data, and how often you check whether a signal produces anything useful. A control point nobody acts on is only a retention liability.
Venta Capture, a product of VentaVid, records 28 control points per submission, made up of 10 automatic signals, 21 recorded session events and 1 signed seal, with SHA-256 fingerprints, GPS location, a signed seal verifiable with a public key, and GDPR-compliant storage with configurable retention.