EST. LOS ANGELES · READ WORLDWIDE
AUGUST 2026 · VOL. X
InsurTech.me
Where insurance, technology, and capital meet
← ALL EPISODES
EPISODE 104 · INSURTECH TALKS SEP 14, 2023 · GILAD SHAI

Vesttoo Part 2: Fraudulent LOCs and the Collapse of Trust in the ILS Marketplace

WATCH ON YOUTUBE · ALSO ON SPOTIFY

The Missing Layer Wasn’t Exotic. It Was Finance 101: Have Someone Check the Collateral Actually Exists.

This is a follow-up conversation, recorded as the Vesttoo letter-of-credit scandal was actively unfolding — the second installment on a story that, as Emilio Figueroa put it, “keeps on giving,” with new information breaking on almost a weekly basis. Everything discussed is explicitly caveated as based on public reporting, not inside knowledge: the facts were genuinely unclear at recording time, with an active FBI investigation underway.

The core situation: Vesttoo, an insurtech that built a marketplace for the non-catastrophe segment of the insurance-linked securities (ILS) market, was found to have relied on letters of credit that turned out to be fraudulent — allegedly involving China Construction Bank and Standard Chartered, among others. In the weeks before this recording, Vesttoo’s CEO and CFO were suspended, the board took direct control, roughly 75% of staff were let go, and major partners — Corinthian Group (reportedly $1.5-2 billion of exposure) and Clearblue (reportedly up to $1 billion) — began actively working to replace both the fraudulent LOCs and their broader reliance on Vesttoo’s platform entirely.

In Episode 104 of InsurTechTalk, Emilio Figueroa (CEO of Indemnity Lab) and Dario Luna (Managing Partner of Akua Capital) joined me to work through what basic financial controls were apparently missing, what a board should have done differently before the crisis, and what it would actually take for a company in this position to rebuild trust.

About the Guests

Emilio Figueroa is CEO of Indemnity Lab, a strategy advisory firm working across underwriting, claims, operations, reinsurance, and alternative risk transfer for insurance organizations. Dario Luna is Managing Partner of Akua Capital, a boutique advisory firm based in Canada and Mexico, with over 20 years of insurance industry experience spanning regulation, alternative risk contract broking in London, and insurtech entrepreneurship.

What Actually Went Wrong: The Missing Back-Office Check

The mechanism both guests kept returning to is genuinely simple, which is part of what makes the apparent failure so striking. Dario’s framing: standard financial industry practice requires a back-office function, independent of the commercially-driven front office, whose job is specifically to verify that collateral backing a security — in this case, letters of credit backing the equity layer of a deal — is real, current, and verified directly with the issuing institution. This isn’t an exotic control; it’s baseline practice at any mature financial institution.

What Vesttoo apparently relied on instead, per public reporting the guests discussed: checking that an email’s domain name matched the issuing bank, and confirming a voicemail greeting — described by one party (Corinthian Group) as adequate verification. Separately, Vesttoo itself reportedly claimed to have physically visited the bank in question. Emilio’s pointed observation: those two accounts are inconsistent with each other, and neither is remotely equivalent to the standard practice of direct, verified confirmation through a bank’s own back-office channel — the level of diligence any serious investment transaction requires (his comparison: verifying a factory actually exists before buying it, not accepting a photo).

Three Lines of Defense, and Where They Broke

Dario laid out the standard risk-control framework the industry has developed over decades, and the diagnosis of where it apparently failed:

  • First line — the front office has a fiduciary duty to act correctly even while carrying commercial incentives to close deals quickly
  • Second line — an independent back office, reporting outside the commercial chain, whose job is specifically to catch what the front office might rush past
  • Third line — regular, independent audit, ideally more frequent than typical given how dynamic and fast-moving a platform like this was

His view: this is such a basic, well-established framework that its apparent absence isn’t a sophisticated oversight — it’s a fundamental competency gap, made worse by how quickly Vesttoo scaled without building out the controls that scale requires.

KYC Isn’t Enough — You Need KYB

I raised a point from the broader financial industry that applies directly here: know-your-customer (KYC) verification has increasingly given way to know-your-business (KYB) — tracing not just who you’re transacting with, but who the actual beneficial owner behind an entity is, all the way up the chain. A verified email domain or a shell company’s paperwork looking clean doesn’t satisfy that bar; it just confirms the surface-level paperwork is internally consistent, which fraud is specifically designed to produce.

Crisis Response: Speed and Transparency Matter as Much as the Fix Itself

Emilio was direct about the reputational dimension of the crisis independent of the underlying fraud question. His critique: the senior executive team’s departure within a four-day window — after a reported average tenure of 25 years in the industry among those executives — was itself an alarming signal, regardless of what internal facts eventually emerge. Waiting three to four weeks for the board to issue a substantive public response, in an industry built entirely on trust in an intangible product, compounded the damage. His framing: every day of silence between the story breaking and a transparent response is effectively another nail in the company’s reputational coffin, independent of the legal facts still being established.

Ledger CEO Samir Shah’s public comment during the episode’s news cycle — that the issue is contained to this specific case and specific type of security, not a sector-wide problem with ILS broadly — was one data point the guests discussed, with general (though not unconditional) agreement, while stressing that a forensic accounting of exactly what happened is still necessary before anyone can responsibly declare the broader market unaffected.

What the Board Should Have Done Before the Crisis

I pushed both guests on what proactive governance would have looked like, given that boards represent investor fiduciary duty specifically. Dario’s answer: any investor genuinely excited about a company’s technology still has an obligation to ask what could bring the company down — and for a marketplace whose entire value proposition rests on the solvency and credibility of collateral instruments, due diligence on the back-office control structure should have been as central to the investment decision as diligence on the underwriting technology itself.

Emilio’s practical answer to what Indemnity Lab-style strategic review would have flagged: the absence of an independent verification panel for collateral instruments is an immediate red flag in any strategy or operations review — described as “Finance 101,” not a specialized insurance-industry insight.

The Path Back: Patience, Transparency, and Tempered Growth

Both guests were cautiously optimistic that a path forward exists, conditional on what the ongoing audit and FBI investigation ultimately reveal — specifically, whether Vesttoo’s core underwriting technology is genuinely sound and untouched by the fraud, versus implicated in it.

Emilio’s concrete recommendations for rebuilding trust:

  • Show the actual collateral — statements, verified panels, third-party confirmation, not internal assurances
  • Bring in outside guidance immediately — a consulting layer that gives partners a credible, independent voice to point to, rather than relying purely on internal claims
  • Radically increase transparency going forward — proactive, immediate disclosure around any future issue, rather than the internal secrecy that let public speculation fill the information vacuum this time
  • Temper growth expectations — a company that scaled toward writing billions in reinsurance capacity needs to accept a much slower, more heavily controlled growth trajectory going forward, even at the cost of near-term returns

Dario’s framing for investors specifically: take the difficult, expensive corrective measures now, accept that returns will be delayed, and resist the temptation to abandon the company at the point of maximum reputational damage if the underlying technology genuinely adds value to the reinsurance chain.

Could Blockchain Have Prevented This?

I raised a specific detail from public reporting that stuck with me: a screenshot of a trust bank account was reportedly used at some point as evidence collateral existed — a form of proof trivially fakeable, especially in a world where generative AI can now produce a synthetic video call with a fabricated “bank representative.” Both guests agreed that DeFi-style cryptographic verification and ledgering — transparent, tamper-evident records of collateral — represent an available, mature alternative to manual document verification, and that the industry doesn’t need to reinvent this; the technology already exists and is proven elsewhere in finance. The deeper point beyond the specific technology: whatever mechanism is used, it needs to be independently verifiable by a third party, not simply asserted by the party with the incentive to assert it.

What This Means for the Broader Reinsurance Capacity Market

Looking forward, Emilio expected fronting carriers and their MGA/insurtech distribution partners to become materially more conservative about credit risk and collateral verification going forward — likely requiring higher cash-based reserving on quota share and excess-of-loss arrangements rather than relying on LOC-style instruments, at least until confidence in that structure is rebuilt across the market. Both guests also flagged rating agencies as deserving scrutiny in the aftermath — noting that agencies are typically positioned to catch exactly this kind of structural weakness before it reaches this scale, and that the episode should prompt genuine process review on their end, even though neither guest expected the fallout to be sector-wide.

Key Takeaways

  • The apparent root failure wasn’t a sophisticated fraud-detection gap — it was the absence of a basic, independent back-office function verifying collateral instruments directly with issuing institutions, a decades-old standard practice in structured finance
  • KYC (verifying who you’re transacting with) is insufficient on its own; KYB (tracing beneficial ownership through the full chain) is the actual standard modern due diligence requires
  • Crisis response speed and transparency matter almost as much as the underlying facts — weeks of silence let public speculation and reputational damage compound independent of what the eventual investigation finds
  • Board-level due diligence on a fintech/insurtech’s back-office control structure deserves the same weight as diligence on its core technology, especially when the business model’s entire value rests on collateral credibility
  • Rebuilding trust after this kind of failure requires showing verifiable collateral, bringing in independent outside review, radical forward transparency, and accepting a materially slower growth trajectory
  • Cryptographically verifiable, tamper-evident collateral verification (DeFi-style ledgering) is a mature, already-available alternative to manual document checks like bank account screenshots — which are trivially falsifiable, especially with generative AI
  • The broader reinsurance and ILS capacity market is likely to shift toward more conservative, cash-based reserving requirements and heightened scrutiny of collateral instruments as a direct consequence of this episode