Contact ussales@ventavid.com
VentaVid

Glossary

Our sales with video glossary is here to help you gain an understanding of specific video and marketing terms

Red flag indicator

In this article

Red flag indicator: what it signals, and what it does not

A red flag indicator is a single observable characteristic of a customer, a transaction or a claim that experience associates with financial crime, and that tells a reviewer to ask a further question. It raises the level of scrutiny on a file, and it is not evidence of wrongdoing by the person the file belongs to.

Compliance teams tend to say red flag. Counter-fraud teams say indicator or signal. Supervisors say typology. All three describe the same object doing the same job.

What does a red flag indicator mean?

A red flag is binary and local. Either the characteristic is present on this file or it is not. That is the whole of what it tells you, which is why the useful ones are written as questions rather than as conclusions.

Compare a well-drafted indicator with a badly drafted one. "Customer requests a change of payee shortly before settlement" is checkable and points at a specific follow-up. "Customer seems evasive" is an impression, it cannot be audited, and it imports whatever the reviewer brought to the call.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

Where red flag indicator lists come from

Nobody sensible writes one from scratch. Published lists are the starting point, and firms then narrow them to their own book:

  • Standard setters. The FATF publishes typology and red flag reports drawn from real case material. Its 2020 report on virtual assets, for example, sets out indicators built from more than 100 case studies contributed across the FATF Global Network.
  • National supervisors and financial intelligence units, which publish sector guidance and alerts reflecting local offending patterns.
  • Industry bodies and insurers' own case files, which is where most claims-side indicators originate.
  • The firm's own confirmed findings, which is the only source that tells you whether an indicator works in your book rather than in someone else's.

Red flag indicator example: the early claim

A household claim arrives nineteen days after the policy incepts, for a laptop and a watch, with a receipt that is a photograph of a screen rather than an original document. Two indicators, and the file is routed for enhanced review.

The review takes four days. The customer had switched insurer after moving flat, and the retailer only ever issued a digital receipt, which she had screenshotted from her email on a cracked phone. The referral was right and the claim was honest. Both of those are normally true at once.

How a red flag differs from a risk score

The two are constantly confused, and the difference is worth holding onto. A red flag is one observation. A risk score is an aggregate, produced by weighting many observations into a single band. Flags are inputs, scores are outputs.

That matters operationally in two ways. A single serious flag should be able to escalate a file even when the overall score is low, so a scoring model that can average away a sanctions match is badly built. And a stack of weak flags should not add up to an accusation, because ten weak reasons to look are still only a reason to look.

Why an innocent explanation is the normal case

Nearly every indicator on every list has an ordinary explanation that is more common than the criminal one. Round-number transfers are how people pay deposits. A shared IP address across two claims is usually a bodyshop, a hotel, a fleet depot or a mobile carrier range. A customer who knows the policy wording in detail may simply have read it. Detailed knowledge of the claims process is what you would expect from someone who has been through it before.

This is not an argument for ignoring indicators. It is the reason the base rate has to stay in the reviewer's head. Where a firm treats a fired indicator as a finding, the output is wrongful declines, complaints, ombudsman referrals and supervisory attention on files that would have paid.

Using indicators without generating complaints

  • Tie each indicator to a next action. A flag that does not name the question a handler should ask will be ignored or over-read, and both are expensive.
  • Measure and retire. Track how often each indicator precedes a confirmed finding. Indicators that never do are noise with a governance cost.
  • Prefer provenance to impression. Indicators about how a document or an image was produced age better than indicators about behaviour, and they hold up against edited media in a way that visual inspection does not. The pattern is set out in our piece on shallowfake insurance claims, and the technical version appears as control points around a digital submission.
  • Never let a flag decide alone. Automated escalation is fine. Automated rejection without meaningful human involvement runs into the restrictions on solely automated decision making in European data protection law, and the position differs by jurisdiction.
  • Write down why. A referral that records which two things looked wrong is worth more than a checklist with everything ticked, both to the investigator and to whoever has to justify the file later.

The insurance-specific version of all this, including the circumstantial, documentary and behavioural families, is covered in our entry on the fraud indicator.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

See the damage before you decide

Send one link, get guided, verified claim video back. No app, no account.