
When a pension scheme contacted the son of a deceased member, the case initially appeared straightforward.
He confirmed his father had died and said he was the member’s only child. With no obvious reason to question the information, the scheme could easily have continued its entitlement review based on his account alone.
But it wasn’t the full story.
When Heka mapped the deceased member’s family network, we identified other surviving children – people who had not been disclosed and whom the scheme may otherwise never have known existed.
What appeared to be a simple beneficiary case had exposed a significant risk: a potential beneficiary attempting to position himself as the sole surviving child.
For trustees, this is the uncomfortable reality behind some deceased-member cases. Finding one relative does not necessarily mean that the full family has been found.
When a member dies, schemes often begin with the information already held on file: an expression of wish form, a historic address, a named spouse or the details of one known child.
If that person responds, the case can feel as though it is moving towards resolution. But the first relative reached is only one source of information– and they may not know, remember or choose to disclose the member’s complete family circumstances.
Families are rarely as simple as the records suggest. Members may have:
In some cases, the information provided may be incomplete through honest mistake. In others, as our investigation suggested, someone may have a financial reason to leave another relative out.
The challenge for trustees is not simply to locate someone connected to the deceased member. It is to establish a sufficiently complete and evidenced picture of the family before making an entitlement decision.
A single complex case can often be escalated for specialist investigation. The operational difficulty becomes much greater when a scheme is managing tens, hundreds or even thousands of deceased-member records.
Each case may require the team to answer a series of questions:
Who are the surviving relatives? Are there other children or family branches that have not been disclosed? Are the contact details still current? Has anyone moved overseas? What evidence supports the relationships identified?
Trying to resolve these questions manually, one case at a time, is slow and resource-intensive. It can also lead to inconsistent outcomes: some cases receive extensive investigation, while others depend heavily on the quality of the information already held or supplied by the first person contacted.
Older cases can be particularly difficult. Contact details may be obsolete, family structures may have changed, and relatives may now be spread across several countries. Without a systematic way to reconstruct the family network, important people can remain invisible.
This creates three connected risks for schemes:
Traditional tracing often focuses on finding a named person. Family tree tracing begins with a different question:
Who else should the scheme know about?
Heka starts with the deceased member and reconstructs the wider family network around them. Depending on the case, this may include a spouse or partner, children, siblings, grandchildren and relatives living overseas.
For each portfolio, Heka can provide:
The aim is not to make the trustee’s decision. It is to give trustees a more complete and accurate evidence base on which to make it.
This distinction matters. Family circumstances can be complicated, and entitlement decisions remain subject to the scheme’s rules and trustee discretion. But those decisions are only as informed as the family picture available at the time.
Returning to the original case, Heka’s findings did more than produce additional names.
They changed the basis of the review.
Without independent family tree tracing, the scheme might have proceeded on the assumption that the son was the deceased member’s only child. Once the other children were identified, the trustees had a more complete view of the family and could investigate the case appropriately before reaching a decision.
It is a strong example of why beneficiary identification should not rely solely on what one relative says– even when that person appears credible and the case initially seems uncomplicated.
The greatest risk is not always an untraceable person. Sometimes, it is the person the scheme does not yet know it needs to trace.
For schemes holding large portfolios of deceased members, family tree tracing can be applied across the full population rather than reserved only for individual cases that have already become problematic.
This allows schemes to:
Instead of waiting for inconsistencies to emerge case by case, schemes can develop a more complete view of each deceased member’s family from the outset.
Because when a relative says, “I’m the only one,” the scheme should be able to verify whether that is really true.
Managing a portfolio of deceased members? Heka can map and verify family networks at scale, helping your team identify potential beneficiaries and move entitlement reviews forward with greater confidence.

Pension schemes can trace members internationally by combining global research with identity verification. Rather than relying on a name or last-known address alone, schemes need to connect information across countries and confirm that the person found is genuinely the member they are trying to reach.
A recent Heka project shows why this matters.
A pension scheme for the professional sports industry sent Heka a single file of members it needed to trace. What appeared to be one tracing project quickly expanded far beyond the UK.
Members were found across 61 countries.
For a scheme connected to professional sports, some international movement was expected. Careers change, families relocate and people build lives far from where their pension records began.
The scale, however, was striking. One member file became a global tracing exercise spanning almost every region of the world.
Most pension records reflect a particular moment in a member’s life.
They may contain the address used while the member was working in the UK, an old employer record or contact information provided decades ago. Over time, that information can become increasingly disconnected from the person it belongs to.
Members move without notifying the scheme. Some return to their country of origin after working in the UK. Others relocate several times, change their name, retire abroad or join family living overseas.
In this professional sports scheme’s population, those individual journeys collectively reached 61 countries.
The challenge was not simply to confirm that a member had moved. It was to establish where they were now– and whether the information found genuinely belonged to the same person recorded by the scheme.
That distinction matters. A possible name and address match is not enough, particularly when the search crosses countries, languages and very different data environments.
International tracing is more complex than searching for a member’s name in another country.
Names may be transliterated or recorded differently across jurisdictions. Address formats vary, and the availability of public and commercial data differs significantly between countries.
A married name, abbreviated middle name or differently formatted date of birth can make the same person appear to be several different people. At the same time, multiple individuals may share similar names and biographical details.
Every country also presents a different tracing environment. A source that provides useful information in one location may not exist– or may work very differently– in another.
A portfolio spread across 61 countries cannot therefore be approached as 61 versions of the same UK search.
Reliable international tracing requires more than locating someone with a matching name. It requires evaluating the person’s wider identity.
Depending on the information available, this may involve asking:
Heka brings these signals together to determine whether the person found is genuinely the member the scheme is trying to reach.
This is particularly important when the member’s journey crosses several countries. Each move may leave behind a different fragment of information. The value comes from connecting those fragments into one coherent identity.
Without consistent international capabilities, overseas cases can become individual exceptions.
They may be set aside for manual investigation, passed between different providers or treated as complex cases requiring a separate approach. Across a large population, that quickly becomes slow and difficult to manage consistently.
The professional sports project showed the value of approaching international tracing at portfolio scale.
Rather than deciding in advance which members were likely to be overseas, Heka reviewed the file as one connected tracing exercise. The investigation followed each member wherever the evidence led.
This meant the scheme did not need to know which members had moved abroad– or where they might have moved– before the tracing began. The geographic complexity emerged from the research rather than becoming a barrier to it.
A member’s last-known address may still be in the UK even if they moved overseas years ago. A UK telephone number may no longer be active, while nationality alone cannot reliably indicate where someone lives today.
If schemes only initiate international tracing when their existing records already point overseas, they risk overlooking members whose relocation was never recorded.
This is especially relevant for schemes with globally mobile workforces, historic international recruitment or member populations accumulated over many decades. But the issue is not limited to schemes that appear international.
Almost any large deferred-member population is likely to include people who have crossed borders since their information was last updated.
The real question is not whether a scheme has international members. It is whether the scheme can identify and trace them when its records no longer show where they are.
Yes. International tracing can be conducted across a complete member file rather than reserved for individual cases already known to be overseas.
Applying tracing across the full population allows the evidence– not assumptions within the existing data– to reveal where members are now located.
This enables schemes to:
For schemes managing large or historic member portfolios, this can provide a clearer picture of the population’s true geographic reach.
For trustees and administrators, finding a possible address is only part of the process. They also need enough evidence to use the result confidently.
International pension tracing should help a scheme establish:
Heka combines international coverage with identity verification, giving schemes a consistent approach even when their members are dispersed across dozens of countries.
The professional sports scheme began with one file.
Behind it were individual lives that had moved in many different directions: members who had relocated, returned home or built new lives elsewhere. By following those journeys, Heka found members across 61 countries.
For schemes, the lesson is simple: the geographic boundaries of the member data are not necessarily the boundaries of the member population.
The member may have left the UK, but their pension– and the scheme’s responsibility to find them– has not.
A last-known UK address may only be the first chapter. Effective tracing needs to follow the person beyond it.
Managing a member population that may extend beyond the UK? Heka traces and verifies members internationally, helping pension schemes reconnect with members wherever their lives have taken them.

An enterprise-grade fraud stack is not a product. It is a latency-constrained decisioning system in which multiple layers – data collection, identity validation, enrichment, scoring, and decisioning – operate as a single flow. In most transaction environments, that entire loop runs in under 300 milliseconds for transaction decisions, and only marginally longer for onboarding.
The challenge is not assembling the stack. Most institutions already have the core components in place, often across multiple vendors and internal systems. The challenge is understanding how those components interact in practice – and where the system produces decisions that appear well-supported, but are not.
A fraud decision is not generated by a single model or rule. It is the result of a sequence of stages, each contributing a different type of signal or constraint.
At a high level, the system collects observable signals, validates identity claims, enriches those signals with external data, applies probabilistic scoring, enforces deterministic rules, and aggregates all outputs into a final decision. Cases that fall outside clear thresholds are escalated, and outcomes are fed back into the system to continuously refine performance.
This flow is consistent across financial institutions, even where implementation details differ . What varies is the relative strength of each layer, and the degree to which each one contributes meaningful signal to the final decision.
In practice, this decisioning flow can be broken down into eight functional layers:
1. Signal Collection
The system captures all observable inputs at the point of interaction, including device fingerprinting, IP intelligence, behavioral biometrics, and identity data. These signals form the raw input for all downstream analysis.
2. Identity Verification (IDV)
Identity attributes are validated against trusted sources such as credit bureau headers, SSA records, and sanctions lists. This establishes whether the identity exists and meets regulatory requirements.
3. Data Enrichment
External data sources are used to expand the identity profile. This includes email intelligence, phone intelligence, address validation, and consortium-based signals that provide additional context beyond the initial claim.
4. Risk Scoring
Machine learning models transform raw and enriched signals into probabilistic risk scores. These models typically target specific fraud types, including application fraud, synthetic identity fraud, and account takeover.
5. Rules Engine
Deterministic rules enforce policy and known fraud patterns. These include hard blocks (e.g., sanctions matches), velocity thresholds, and mismatch conditions that cannot be fully captured by models.
6. Orchestration & Decisioning
All signals, model outputs, and rule evaluations are aggregated into a final decision – approve, review, or decline – through a centralized decisioning layer.
7. Step-Up & Case Management
Cases that fall into intermediate risk bands are escalated through additional verification (e.g., biometric checks, OTP) or routed to human investigation workflows.
8. Feedback & Model Governance
Confirmed fraud outcomes, false positives, and analyst decisions are fed back into the system to retrain models, refine rules, and monitor performance over time.
This architecture is broadly consistent across the industry. The presence of these layers, however, does not guarantee effective decisioning.
The following simplified view highlights how each layer contributes to the final decision, and where its limitations typically emerge:

This view is intentionally reductive. Its purpose is not to describe the system exhaustively, but to make visible where signal strength and decision confidence can diverge.
Failures rarely occur because a layer is absent. They occur when a layer produces an output that appears sufficient, but lacks underlying depth.
An identity may pass bureau and SSA validation, present no device or velocity risk, and return acceptable enrichment signals. Yet the identity may still lack coherence across time – no consistent footprint, no reinforcing signals, and no evidence of persistence.
This is the central gap.
Most stacks are effective at confirming that an identity exists. Many can confirm that a user is physically present. Far fewer can determine whether the identity behaves like a reliable individual over time.
These limitations are not purely technical. They are structural.
Latency constraints limit the ability to incorporate deeper or slower data sources. Scale requires reliance on generalized models rather than case-specific analysis. Cost and conversion pressures reduce tolerance for additional friction or enrichment calls.
As a result, systems tend to emphasize:
Both are necessary. Neither is sufficient to fully resolve identity risk.
The “perfect” fraud stack is a myth. In practice, every stack reflects a set of trade-offs – between latency, cost, scale, and risk tolerance. Different institutions prioritize different parts of the system:

Understanding the structure of a fraud stack is necessary, but not sufficient. The more important task is evaluating how the stack behaves under real conditions.
Key questions include:
Fraud does not typically exploit missing components. It exploits the assumptions created by partial signal coverage.
This report provides a structural view of the modern fraud stack. In the accompanying evaluation guide, we extend this framework to:
Follow us to be notified when the full evaluation guide is released.

A recent data review identified deceased members still recorded as active – including deaths dating back to 2002.

A recent pension data cleanse for a large UK industrial defined benefit scheme identified that approximately 2% of members were deceased, including several individuals whose deaths dated back more than twenty years.
Two members recorded as active in the scheme records were found to have died in 2002.
For large defined benefit schemes, discrepancies of this scale can represent a material number of member records requiring validation before insurer pricing can proceed.
No administrative exception had been raised. The discrepancy only became visible once member records were validated against external sources.
These findings illustrate how member data inaccuracies can remain embedded within scheme records for extended periods without triggering operational alerts.

When schemes approach buy-in or buy-out transactions, insurers undertake detailed due diligence on the member population. Confidence in the integrity of scheme data therefore becomes an important consideration.
Insurers typically review several areas, including:
Where information cannot be independently validated, additional verification work may be required before pricing can be confirmed. In some cases this can extend transaction timelines or introduce further assumptions into pricing models.
The Pensions Regulator also emphasises that trustees are responsible for maintaining complete and accurate member data as part of effective scheme governance.
Pension schemes operate over long time horizons. Member records may remain in administrative systems for several decades and often pass through multiple administrators and technology platforms.
Over time, several structural issues can arise. Members may pass away without the scheme being notified, particularly where contact with the scheme has been lost.
In England and Wales alone, over half a million deaths are registered each year, according to the UK Office for National Statistics (ONS). Reconciling long-standing member records against this scale of national mortality data is therefore an important element of maintaining accurate scheme populations.
Increasing international mobility also reduces visibility within domestic datasets. Addresses and contact details may remain unchanged for extended periods, and historical system migrations can introduce inconsistencies across records.
These issues do not necessarily affect day-to-day administration but can become visible when scheme data is examined more closely during transaction preparation.
To address these risks, schemes increasingly supplement internal records with additional verification sources such as:
Platforms such as Heka help consolidate these signals into structured intelligence. This allows schemes to validate member records, identify mortality indicators, and improve confidence in the accuracy of their member population.
Undetected deaths in scheme records illustrate a broader issue: member data can deteriorate silently over time.
Routine administrative processes may not surface these discrepancies. However, when schemes approach buy-in or buy-out preparation, such gaps can become operationally and financially relevant.
Early validation of member data can therefore reduce uncertainty, support insurer due diligence, and improve readiness for endgame transactions.