Fraud-as-a-Service: Inside the Industrial Economy Reinventing Digital Crime

Fraud is no longer a technical skill. It’s a shopping experience.

What used to require specialized knowledge, custom scripting, and underground connections is now available through polished marketplaces that look indistinguishable from mainstream e-commerce platforms. Scrollable product cards. Star ratings. Tiered subscriptions. “Customers also bought…” recommendations.

Fraud-as-a-Service (FaaS) is not just an ecosystem – it is a parallel economy, built on the same principles as Amazon, Fiverr, and Shopify, but optimized for identity crime.

The result is a dramatic shift in the threat landscape: lower entry barriers, lower operational costs, and attacks that scale instantly. Fraud is no longer limited by human capability – it is limited only by how quickly these marketplaces can generate new products.

This blog exposes how the FaaS ecosystem actually works, what is available inside these marketplaces, and why the industrialization of fraud is reshaping digital risk.

Modern identity fraud now operates like a consumer marketplace

The biggest misconception about digital crime is that it is messy, unstructured, and technically demanding. The truth is the opposite.

Today’s fraud marketplaces offer:

  • User accounts with dashboards, order history, customer tickets
  • Subscription plans (“Basic,” “Pro,” “Enterprise”)
  • Tiered pricing by volume, geography, and document type
  • Built-in automation (bots, scripts, testing tools)
  • 24/7 support via Telegram or live chat
  • Refund guarantees for non-working identities or scripts
  • Tutorials & onboarding with step-by-step videos

The experience mirrors legitimate SaaS:

  • “Upload your target list here.”
  • “Select your document pack.”
  • “Choose your delivery format (PNG, PDF, MP4 liveness).”
  • “Add to cart → Check out with crypto → Instant delivery.”

And like Fiverr, each vendor specializes. There are providers for:

  • Latin American passports
  • US tax records
  • UK banking profiles
  • SIM provisioning
  • Credit card dumps segmented by BIN and issuer
  • Bots tailored specifically for major IDV vendors

Fraud hasn’t just scaled – it has industrialized.

What is actually available: A catalog of the modern fraud economy

This is the part most institutions underestimate. The breadth and maturity of offerings is staggering. Here is what is openly sold across FaaS platforms – with the same clarity you’d expect from Amazon.

A. Synthetic Identity Kits

Full synthetic personas sold as complete packages:

  • Name, DOB, SSN fragments, address history
  • AI-generated headshots with multiple angles
  • Pre-built social media history
  • “Proof of life” selfies for liveness checks
  • Steady digital footprint entropy (posts, likes, connections)
  • Companion documents (W-2s, pay stubs, utility bills)

Vendors guarantee the profile will pass KYC at specific institutions.

And the price range? $25–$200 per profile.

B. Document Forgery Packs

These aren’t crude Photoshopped IDs. They include:

  • High-resolution PSD templates for global passports and licenses
  • Embedded barcodes, holograms, MRZ zones
  • Configurable fields auto-filled via AI
  • Companion video packs for selfie + document flow (“blink & tilt liveness”)

Some vendors offer automated generation APIs: “Generate 1,000 EU passports → Deliver in 40 seconds.”

C. Phishing Kits

Pre-built phishing engines with:

  • Domain spoofing
  • Hosting included
  • Real-time dashboard showing captured credentials
  • Auto-forwarded MFA codes
  • Scripted call-center dialogue for social engineering ops

Price: $10–$50 per campaign, often with free updates.

Many platforms now include "Fraud-GPT” engines – fraud-tuned GenAI models capable of producing tailored scam messages, emotional manipulation scripts, romance-fraud personas, and real-time social-engineering dialog. These systems can hold multi-turn conversations with victims while dynamically adjusting tone, urgency, and narrative to increase conversion rates.

D. Botnets & Automation Engines

Not just credential stuffing – full operational bots:

  • Session replay
  • Checkout automation
  • Device emulation
  • Behavioral mimicry (typing cadence, cursor drift, hesitation modeling)
  • “IDV bypass bots” trained on top vendors’ workflows

These bots now learn from failure and retry with adjusted parameters.

E. Account Takeover Kits

Just add username and phone number. These bundles include:

  • OTP interception
  • SIM swap partners
  • Credential validation bots
  • Reset-flow bypass templates
  • Email change scripts

They are marketed explicitly: ATO at scale. 94% success rate on XYZ bank. Guaranteed replacement if blocked.

F. Credit Card & PII Marketplaces

Highly organized product categories:

  • “Fresh fullz (fraudster lingo for “full information”), US only, 2025–2026”
  • “High-limit BINs”
  • “Verified employer + income”
  • “Vehicle registration data”
  • “Adult site password dumps”

Every item has age, source, and validity score.

G. Ransomware-as-a-Service

Turnkey operations:

  • Payload builder
  • Negotiation scripts
  • Hosting
  • Payment infrastructure
  • Revenue share with the platform (typically 20–30%)

What This Actually Means: Fraud Is No Longer Human

When you step back from the catalog of available tools, one truth becomes impossible to ignore: fraud is no longer defined by human capability. It is defined by the capabilities of the systems that now produce and distribute it.

Every component of the fraud economy – identity creation, verification bypass, account takeover, social engineering, automation – has been modularized, optimized, and packaged for scale. The human actor is no longer the limiting factor. The marketplace provides the expertise, the automation provides the execution, and the criminal business model provides the incentive structure.

The result is a threat landscape that looks less like episodic misconduct and more like a supply chain. Fraud behaves like a coordinated operation, not a series of individual attempts. It adapts quickly, repeats consistently, and expands effortlessly – because the work is performed by tools, not people.

This is why traditional controls struggle. Identity verification was built on the assumption that inconsistencies, friction, and human error would reveal risk. But the industrialization of fraud produces identities that are consistent, documents that are polished, and behavioral patterns that are machine-stable. What used to feel like a red flag – a clean file, a frictionless onboarding journey – is now a symptom of a system-generated identity.

The deeper consequence is strategic: the attacker no longer “thinks” like a human adversary. They probe controls the way software tests an API. They run parallel attempts the way a product team runs A/B tests. They scale operations the way cloud infrastructure scales workloads. And because their tooling is continuously updated, their learning curve is steep – while defenses remain constrained by review cycles, risk committees, and static models.

Conclusion: Digital Identity Must Now Be Proven Through Context

For financial institutions, the rise of Fraud-as-a-Service has exposed the limits of a decades-old assumption: that identity can be validated by inspecting individual attributes. In an industrialized fraud economy, every discrete signal – documents, device profiles, PII, behavioral cues – can be purchased, replicated, or simulated on demand. A synthetic identity can now satisfy every checkbox a traditional onboarding flow requires.

What it cannot reliably produce is contextual coherence.

Real customers exhibit history, relationships, communication patterns, platform interactions, and digital residue that accumulate organically. Their identities make sense across time, across channels, and across environments. Their behavior reflects inconsistency, natural drift, and the kinds of imperfections that automated systems struggle to fabricate.

Synthetic identities, even sophisticated ones, tend to be:

  • too uniform,
  • too compressed in time,
  • too symmetrical,
  • too detached from broader signals in the digital ecosystem.

This is the gap FIs must now address. Identity is no longer something you confirm once. It is something you understand – continuously – by examining whether its story holds together.

The operational shift is simple to articulate, harder to execute:

Verification must move from checking attributes to validating coherence.
Does the identity align with long-term behavioral patterns?
Does the footprint exist beyond the onboarding moment?
Does it behave like a human navigating life, or a system navigating workflows?
Does it fit the context in which it appears?

Fraud has become industrial. Identity fabrication has become automated. What separates real from synthetic is no longer the presence of data, but whether that data forms a believable whole.

Financial institutions that recalibrate their controls toward coherence – contextual, cross-signal intelligence – will be positioned to detect what Fraud-as-a-Service still struggles to imitate: the complexity of genuine human identity.

At Heka Global, our platform delivers real-time, explainable intelligence from thousands of global data sources to help fraud teams spot non-human patterns, identity inconsistencies, and early lifecycle divergence long before losses occur.

In an AI-versus-AI world, timing is everything. The earlier your system understands an identity, the sooner you can stop the threat.

Omer Ovadia & Joy Phua Katsovich

See What Your Existing Data Stack is Missing.

Let’s help you get started.
Submit
Thank you, we will reach out to you soon! If you’d like to contact us directly, you can email us at info@hekaglobal.com.
Oops! Something went wrong while submitting the form.

Resources Post

Pension Scheme Data Readiness: Why Clean Data May Not Be Buy-out Ready

A pension record can pass every standard data check and still fail to reflect the member behind it. Heka explores what true pension scheme data readiness means for trustees and insurers and why accuracy, currency and identity confidence matter alongside data cleansing.

A pension record can be complete, correctly formatted and still fail to reflect the member behind it.

That distinction is becoming increasingly important as more pension schemes prepare for buy-in, buy-out and other endgame decisions. A recent Professional Pensions article on data readiness makes the case that preparing for buy-out requires far more than simply cleaning scheme data. Trustees need to understand their data, validate it and give insurers confidence in the information provided.

We agree. But it also raises a further question: are the processes traditionally used to assess pension scheme data still sufficient for what trustees and insurers need to achieve today?

What is pension scheme data readiness?

Pension scheme data readiness means that member data is complete, accurate, current and sufficiently understood for its intended purpose. For a buy-in or buy-out, it should enable insurers to assess the scheme with confidence and support an efficient transaction. For trustees, it should support good governance, accurate benefits and positive member outcomes.

Data readiness is therefore not a single score or one-off pension data cleansing exercise. It depends on the outcome the scheme is preparing for and the level of confidence required to achieve it.

Why clean pension data is not always ready data

Industry-standard data checks remain an essential foundation. They can identify missing fields, invalid formats, duplicate entries and known inconsistencies. Yet a record can pass those checks while the information within it is no longer true.

For example:

  • An address may be correctly formatted but years out of date.
  • A full name and date of birth may be present, but the member may have changed their name.
  • A member may have moved overseas even though the scheme retains only a UK address.
  • A member may have died without the scheme being notified.
  • Separate records may relate to the same person, or details stored together may not belong to the same individual.

The record may appear complete. That does not necessarily mean the scheme’s understanding of the member is complete.

This is consistent with The Pensions Regulator’s guidance on scheme member data quality, which distinguishes between the presence of data and its accuracy. The regulator expects trustees to manage data quality actively, including regular reconciliation, member tracing and mortality screening.

What data do insurers need for a pension scheme buy-in or buy-out?

Insurers generally need pension scheme data that is complete, accurate, current and clear enough to support pricing, benefit verification and transaction execution. The precise requirements depend on the scheme and transaction, but strong data readiness typically includes:

  • Reliable member identity and status information
  • Current address and contact details
  • Accurate dates of birth and other core identity attributes
  • Confirmed mortality information
  • Consistent membership, payroll and benefit records
  • A clear explanation of previous corrections, assumptions and unresolved issues
  • Evidence of the checks used to validate the data

PASA’s guidance on data readiness for buy-ins and buy-outs notes that complete, accurate and current data can improve insurer engagement, transaction efficiency, pricing and the accurate delivery of member benefits.

Data schedules and benefit specifications may be technically complete, but insurers also need confidence in the people represented by those records. If identity or contact information is stale, contradictory or poorly evidenced, uncertainty can persist even when the dataset looks orderly.

Why pension scheme trustees should look beyond data completeness

Trustees remain accountable for pension scheme data quality, even when the day-to-day work is delegated to an administrator. A high completion score can be reassuring, but it does not answer every question trustees need to ask.

A more meaningful review should consider five dimensions:

  1. Completeness: Are the required data fields populated?
  2. Validity: Does the information follow the expected format and rules?
  3. Accuracy: Does the information reflect the correct member?
  4. Currency: Does it reflect the member’s circumstances today?
  5. Connectivity: Can the scheme confidently identify and reach that person?

The first two dimensions are relatively straightforward to test within the existing dataset. The remaining three often require schemes to look beyond the record itself.

This is where pension scheme member tracing and broader identity validation become important. Rather than asking only whether an address exists, the scheme can assess whether it remains current. Rather than treating a previous “no trace” result as final, it can consider whether new evidence or signals are now available. Rather than reviewing each field separately, it can determine whether the identity attributes fit together and belong to the same person.

The limits of a record-led approach to member tracing

Traditional pension tracing exercises often begin with the information already held by the scheme. That is a logical starting point, but it can also limit the result.

If a scheme holds an old UK address, for example, a process focused primarily on confirming or updating that address may miss that the member has established an entirely new life overseas.

In one scheme-wide tracing exercise, Heka identified members across 61 countries—even though the historical scheme records did not reveal the true scale of the international membership.

The same issue arises with other life events. People marry, divorce, adopt new names, relocate and develop new contact details. Families change, and members die. Pension scheme records do not update automatically as those lives evolve.

A person-led approach starts with a different objective: not simply to improve the existing record, but to establish the most accurate and current understanding of the individual it represents.

That distinction matters. A conventional process may conclude that no new address has been found. A broader identity investigation may establish that the member now uses a different surname, lives in another jurisdiction and can be connected to current contact information through multiple corroborating signals.

Both processes may have been performed correctly. They are working towards different definitions of success.

How does data readiness affect pension scheme transactions?

Poor or poorly understood member data can create uncertainty during a pension risk transfer. Questions that emerge late can require additional investigation, place pressure on administrators and complicate the journey from buy-in to buy-out.

Strong pension scheme data readiness can help trustees and insurers:

  • Identify issues before they become transaction-critical
  • Reduce avoidable questions and manual investigation
  • Build confidence in the membership population
  • Support accurate pricing and benefit verification
  • Plan member communications using current contact details
  • Reduce the risk of discovering material changes late in the process
  • Support a smoother transition of administration and member servicing

The objective is not to promise a perfect dataset. It is to understand the data well enough to explain what has been tested, what has changed, where uncertainty remains and how any unresolved cases will be handled.

Is data readiness only important for buy-in and buy-out?

No. Pension scheme data readiness is relevant to almost every major administration and governance objective.

For pensions dashboards, schemes need accurate identity attributes and an appropriate matching policy to connect people with their pensions.

For member engagement, schemes need current, usable contact information to reach the right person through the right channel.

For mortality screening, schemes need sufficiently strong evidence to identify deaths accurately and take appropriate action.

For ongoing administration, reliable data supports accurate calculations, payments and communications.

For buy-in and buy-out, trustees and insurers need confidence in both the benefits being secured and the people entitled to receive them.

The relevant question is not simply, “Has the data been cleaned?” It is: “Is the data sufficiently understood and validated for the outcome we are trying to achieve?”

How can schemes improve data readiness without creating unnecessary work?

Looking beyond established data checks does not mean every member record requires an intensive manual investigation.

Schemes can use technology to validate records at scale, identify conflicting identity attributes and highlight cases where information is missing or confidence is low. Deeper investigation can then be directed towards the records most likely to affect the intended outcome.

An effective pension data improvement programme should:

  1. Define the outcome, such as dashboard matching, member reconnection or buy-out readiness.
  2. Agree what complete, accurate and current data means for that outcome.
  3. Test the data beyond field presence and formatting.
  4. Identify contradictions, stale information and low-confidence records.
  5. Prioritise cases according to risk and likely impact.
  6. Document the evidence, methodology and changes made.
  7. Put a process in place to maintain data quality over time.

This approach distinguishes between records that are genuinely well understood and those that merely appear complete. It can also make data work more targeted by focusing time and specialist investigation where it is most likely to change the outcome.

From pension data cleansing to identity confidence

The Professional Pensions article is right that data readiness is about confidence, not just cleansing. Building that confidence may require trustees and insurers to look beyond familiar processes and test whether the information held reflects the member as they are today—not only the record as it was originally created.

Industry standards remain the foundation. But as better information and new methods become available, best practice should continue to evolve with them.

For pension schemes, true data readiness means more than having a clean file. It means being able to identify, understand and reach the people behind the data with confidence.

Frequently asked questions about pension scheme data readiness

What is the difference between pension data cleansing and data readiness?

Pension data cleansing identifies and corrects missing, invalid, duplicated or inconsistent information. Data readiness is broader: it means the data is complete, accurate, current, understood and suitable for a specific purpose, such as pensions dashboards, member tracing, buy-in or buy-out.

When should trustees begin preparing data for buy-out?

Trustees should begin assessing pension scheme data quality early in the journey, before approaching the market. Early preparation creates time to investigate complex cases, resolve inconsistencies and explain any remaining uncertainty to insurers.

Why does member tracing matter for buy-out readiness?

Member tracing helps confirm whether contact and identity information remains current. It can identify relocated members, name changes, overseas members, deaths and other changes that may not appear in historical scheme records.

What makes pension scheme member data high quality?

High-quality member data is complete, valid, accurate, consistent, current and usable. It should reliably identify the correct member, support accurate benefits and enable the scheme or insurer to communicate with that person when required.

Can technology replace manual pension tracing?

Technology can validate large volumes of member data, connect fragmented identity information and prioritise records that require attention. Complex or ambiguous cases may still require expert investigation. The most effective approach combines scalable technology with targeted human analysis.

How can Heka support pension scheme data readiness?

Heka helps pension schemes validate member identities, enrich incomplete or outdated records, identify deaths and reconnect with members in the UK and internationally. By bringing together identity and risk signals from multiple sources, Heka helps trustees and insurers develop a more current and confident understanding of the people behind scheme records.

How Can Pension Schemes Trace Members Internationally? A 61-Country Case Study

One pension scheme file led across 61 countries, revealing why international tracing requires more than a name and last-known address.

Pension schemes can trace members internationally by combining global research with identity verification. Rather than relying on a name or last-known address alone, schemes need to connect information across countries and confirm that the person found is genuinely the member they are trying to reach.

A recent Heka project shows why this matters.

A pension scheme for the professional sports industry sent Heka a single file of members it needed to trace. What appeared to be one tracing project quickly expanded far beyond the UK.

Members were found across 61 countries.

For a scheme connected to professional sports, some international movement was expected. Careers change, families relocate and people build lives far from where their pension records began.

The scale, however, was striking. One member file became a global tracing exercise spanning almost every region of the world.

A UK address is only the beginning

Most pension records reflect a particular moment in a member’s life.

They may contain the address used while the member was working in the UK, an old employer record or contact information provided decades ago. Over time, that information can become increasingly disconnected from the person it belongs to.

Members move without notifying the scheme. Some return to their country of origin after working in the UK. Others relocate several times, change their name, retire abroad or join family living overseas.

In this professional sports scheme’s population, those individual journeys collectively reached 61 countries.

The challenge was not simply to confirm that a member had moved. It was to establish where they were now– and whether the information found genuinely belonged to the same person recorded by the scheme.

That distinction matters. A possible name and address match is not enough, particularly when the search crosses countries, languages and very different data environments.

Why is international pension tracing difficult?

International tracing is more complex than searching for a member’s name in another country.

Names may be transliterated or recorded differently across jurisdictions. Address formats vary, and the availability of public and commercial data differs significantly between countries.

A married name, abbreviated middle name or differently formatted date of birth can make the same person appear to be several different people. At the same time, multiple individuals may share similar names and biographical details.

Every country also presents a different tracing environment. A source that provides useful information in one location may not exist– or may work very differently– in another.

A portfolio spread across 61 countries cannot therefore be approached as 61 versions of the same UK search.

International tracing is an identity problem

Reliable international tracing requires more than locating someone with a matching name. It requires evaluating the person’s wider identity.

Depending on the information available, this may involve asking:

  • Do the age and employment history align?
  • Are the previous and current addresses connected?
  • Do family relationships support the match?
  • Is there evidence linking the overseas individual to the original pension record?
  • Does the information collectively point to one person rather than someone with similar details?

Heka brings these signals together to determine whether the person found is genuinely the member the scheme is trying to reach.

This is particularly important when the member’s journey crosses several countries. Each move may leave behind a different fragment of information. The value comes from connecting those fragments into one coherent identity.

One file, 61 different tracing environments

Without consistent international capabilities, overseas cases can become individual exceptions.

They may be set aside for manual investigation, passed between different providers or treated as complex cases requiring a separate approach. Across a large population, that quickly becomes slow and difficult to manage consistently.

The professional sports project showed the value of approaching international tracing at portfolio scale.

Rather than deciding in advance which members were likely to be overseas, Heka reviewed the file as one connected tracing exercise. The investigation followed each member wherever the evidence led.

This meant the scheme did not need to know which members had moved abroad– or where they might have moved– before the tracing began. The geographic complexity emerged from the research rather than becoming a barrier to it.

International members are not always obvious

A member’s last-known address may still be in the UK even if they moved overseas years ago. A UK telephone number may no longer be active, while nationality alone cannot reliably indicate where someone lives today.

If schemes only initiate international tracing when their existing records already point overseas, they risk overlooking members whose relocation was never recorded.

This is especially relevant for schemes with globally mobile workforces, historic international recruitment or member populations accumulated over many decades. But the issue is not limited to schemes that appear international.

Almost any large deferred-member population is likely to include people who have crossed borders since their information was last updated.

The real question is not whether a scheme has international members. It is whether the scheme can identify and trace them when its records no longer show where they are.

Can international tracing be applied across a full member population?

Yes. International tracing can be conducted across a complete member file rather than reserved for individual cases already known to be overseas.

Applying tracing across the full population allows the evidence– not assumptions within the existing data– to reveal where members are now located.

This enables schemes to:

  • Review UK and overseas cases through one consistent process
  • Identify members whose international moves were never recorded
  • Reduce the number of cases treated as manual exceptions
  • Trace members across several countries where necessary
  • Apply identity verification consistently across the population

For schemes managing large or historic member portfolios, this can provide a clearer picture of the population’s true geographic reach.

International reach with consistent evidence

For trustees and administrators, finding a possible address is only part of the process. They also need enough evidence to use the result confidently.

International pension tracing should help a scheme establish:

  • Where the member is currently living
  • Whether the person found matches the original member record
  • Which contact information is current
  • What evidence supports the identity connection
  • Which cases require further investigation

Heka combines international coverage with identity verification, giving schemes a consistent approach even when their members are dispersed across dozens of countries.

How far could one member file take you?

The professional sports scheme began with one file.

Behind it were individual lives that had moved in many different directions: members who had relocated, returned home or built new lives elsewhere. By following those journeys, Heka found members across 61 countries.

For schemes, the lesson is simple: the geographic boundaries of the member data are not necessarily the boundaries of the member population.

The member may have left the UK, but their pension– and the scheme’s responsibility to find them– has not.

A last-known UK address may only be the first chapter. Effective tracing needs to follow the person beyond it.

Managing a member population that may extend beyond the UK? Heka traces and verifies members internationally, helping pension schemes reconnect with members wherever their lives have taken them.

The Family Tree that Changed a Death Benefit Review

Finding one relative doesn’t mean you’ve found the whole family. See how family tree tracing helps schemes identify potential beneficiaries across deceased-member portfolios.

When a pension scheme contacted the son of a deceased member, the case initially appeared straightforward.

He confirmed his father had died and said he was the member’s only child. With no obvious reason to question the information, the scheme could easily have continued its entitlement review based on his account alone.

But it wasn’t the full story.

When Heka mapped the deceased member’s family network, we identified other surviving children – people who had not been disclosed and whom the scheme may otherwise never have known existed.

What appeared to be a simple beneficiary case had exposed a significant risk: a potential beneficiary attempting to position himself as the sole surviving child.

For trustees, this is the uncomfortable reality behind some deceased-member cases. Finding one relative does not necessarily mean that the full family has been found.

A contact is not the same as a complete family picture

When a member dies, schemes often begin with the information already held on file: an expression of wish form, a historic address, a named spouse or the details of one known child.

If that person responds, the case can feel as though it is moving towards resolution. But the first relative reached is only one source of information– and they may not know, remember or choose to disclose the member’s complete family circumstances.

Families are rarely as simple as the records suggest. Members may have:

  • Children from previous relationships
  • Estranged relatives
  • Family members who have changed their names
  • Children or siblings living overseas
  • Grandchildren who may need to be considered
  • Relationships that were never recorded by the scheme

In some cases, the information provided may be incomplete through honest mistake. In others, as our investigation suggested, someone may have a financial reason to leave another relative out.

The challenge for trustees is not simply to locate someone connected to the deceased member. It is to establish a sufficiently complete and evidenced picture of the family before making an entitlement decision.

The risk grows across large deceased-member portfolios

A single complex case can often be escalated for specialist investigation. The operational difficulty becomes much greater when a scheme is managing tens, hundreds or even thousands of deceased-member records.

Each case may require the team to answer a series of questions:

Who are the surviving relatives? Are there other children or family branches that have not been disclosed? Are the contact details still current? Has anyone moved overseas? What evidence supports the relationships identified?

Trying to resolve these questions manually, one case at a time, is slow and resource-intensive. It can also lead to inconsistent outcomes: some cases receive extensive investigation, while others depend heavily on the quality of the information already held or supplied by the first person contacted.

Older cases can be particularly difficult. Contact details may be obsolete, family structures may have changed, and relatives may now be spread across several countries. Without a systematic way to reconstruct the family network, important people can remain invisible.

This creates three connected risks for schemes:

  • Benefits may be distributed without all potential beneficiaries being identified.
  • Cases may remain unresolved because the available member data appears insufficient.
  • Trustees may lack the supporting evidence needed to demonstrate how the family was identified and reviewed.

From tracing an individual to mapping the family

Traditional tracing often focuses on finding a named person. Family tree tracing begins with a different question:

Who else should the scheme know about?

Heka starts with the deceased member and reconstructs the wider family network around them. Depending on the case, this may include a spouse or partner, children, siblings, grandchildren and relatives living overseas.

For each portfolio, Heka can provide:

  • A verified family network identifying potential beneficiaries
  • Current contact information for located relatives
  • Identification of relatives living outside the UK
  • Supporting evidence for the relationships found
  • Clear findings to support the scheme’s own entitlement review

The aim is not to make the trustee’s decision. It is to give trustees a more complete and accurate evidence base on which to make it.

This distinction matters. Family circumstances can be complicated, and entitlement decisions remain subject to the scheme’s rules and trustee discretion. But those decisions are only as informed as the family picture available at the time.

What the undisclosed children changed

Returning to the original case, Heka’s findings did more than produce additional names.

They changed the basis of the review.

Without independent family tree tracing, the scheme might have proceeded on the assumption that the son was the deceased member’s only child. Once the other children were identified, the trustees had a more complete view of the family and could investigate the case appropriately before reaching a decision.

It is a strong example of why beneficiary identification should not rely solely on what one relative says– even when that person appears credible and the case initially seems uncomplicated.

The greatest risk is not always an untraceable person. Sometimes, it is the person the scheme does not yet know it needs to trace.

A portfolio-wide approach to deceased-member reviews

For schemes holding large portfolios of deceased members, family tree tracing can be applied across the full population rather than reserved only for individual cases that have already become problematic.

This allows schemes to:

  • Progress more deceased-member cases in parallel
  • Identify missing branches of a family before contacting potential beneficiaries
  • Prioritise cases requiring deeper investigation
  • Reduce reliance on unverified statements from individual relatives
  • Create a clearer evidence trail for entitlement reviews

Instead of waiting for inconsistencies to emerge case by case, schemes can develop a more complete view of each deceased member’s family from the outset.

Because when a relative says, “I’m the only one,” the scheme should be able to verify whether that is really true.

Managing a portfolio of deceased members? Heka can map and verify family networks at scale, helping your team identify potential beneficiaries and move entitlement reviews forward with greater confidence.