Fraud Prevention Is a Policy Choice - Why Identity is so Difficult

 




This week, the Association of Certified Fraud Examiners is holding its national conference, the Super Bowl for fraud fighters. Professionals from around the world will gather to discuss what is working, what is failing, best practices, emerging threats, and what comes next.

I am proud of the work our community is doing.

Fraud examiners, investigators, advocates, attorneys, representatives, technology professionals, and public servants are working every day to protect vulnerable people and preserve confidence in our institutions. They see the consequences when identity systems fail. They also understand that stopping fraud and helping legitimate people gain access are not competing missions. Both are necessary.

Legacy technology will certainly be part of the conference discussion. It should be. The Social Security Administration still relies on tens of millions of lines of COBOL code to process benefits for the American public. Better technology can improve identity management, authentication, data matching, and fraud detection.

But technology is only part of the story.

Identity management is fundamentally about policy and tradeoffs. A former CIA director once explained the problem this way: if you protect your diamonds and pencils equally, you will lose more diamonds and make the pencils much harder to use. The most secure information system is one that is turned off, disconnected, and accessed by no one. It is also useless.

The real question is not whether we can impose stronger identity controls. We can. The question is what level of surveillance, friction, and exclusion Americans are willing to accept.

As a nation, we need to decide whether we want a true national identity system, as India, China, and other modern nations have developed, or whether we want to continue playing the bureaucracy game. The United States has no comparable national framework. Instead, we rely on a collection of agency records, state-issued documents, credit files, and private-sector identity tools that were never designed to function as one coherent system.

We have also forced the Social Security number into a role it was never designed to perform. The SSN was created to track earnings. It was not designed as a secure credential, an authentication tool, or a national identity system.

A Social Security number is not secret. It does not contain modern security features. Once compromised, it generally remains connected to the individual for life. SSA rarely issues a new number, even in cases of fraud, and changing the number does not erase the financial accounts, credit history, government records, or damage connected to the old one.

There is also no national identity-theft response capability comparable to what consumers expect from Visa or Mastercard when a payment card is compromised. A credit card can be shut down, monitored, and replaced. A stolen identity cannot.

Victims are instead sent among SSA, the Federal Trade Commission, financial institutions, credit bureaus, law enforcement, and other agencies. Each organization owns one piece of the problem. No one owns the whole person or the full recovery.

At the same time, private industry often knows more about people’s habits and behavior than the federal government does. Banks, payment networks, telecommunications companies, credit bureaus, retailers, and technology platforms can evaluate devices, transactions, locations, account histories, and behavioral patterns.

Government generally does not possess this information and often cannot combine the information it already has. There are legitimate privacy reasons for that. But we should be honest about the tradeoff. We demand that government stop sophisticated fraud while denying it many of the tools and data used by industry to identify suspicious behavior.

The answer cannot simply be to collect everything. Nor can it be to pretend that a Social Security number, a driver’s license, and a credit-history question amount to a modern identity system.

A recent account posted online illustrates the problem.

The individual could successfully access Login.gov using an authenticator application and a code sent to a current phone number. But when attempting to enter My Social Security, SSA did not recognize that same phone number because an older number remained connected to the agency’s records.

SSA referred the individual to Login.gov. Login.gov could not resolve the SSA record problem.

The individual then tried ID.me. They had a physical passport and driver’s license, along with a photograph of their Social Security card, but were told they needed the physical card. A W-2 could be accepted as an alternative, but the available W-2 masked the first six digits of the Social Security number. A federal tax return displayed the full number, but that document was not accepted.

Consider what happened. The person possessed a passport, a driver’s license, access to a verified phone, an authenticator application, a photograph of the Social Security card, a W-2, and a federal tax return. They were still unable to access their own earnings record.

That is not meaningful security. It is procedural failure.

Every organization followed its own rules. Every system protected its own narrow boundary. Yet no one could resolve the person’s identity across the full process.

What happens to the older American who does not have a driver’s license? The homeless applicant whose address cannot be verified? The person whose credit file is thin, frozen, or tied to an address where they no longer live? The disabled claimant who cannot easily travel to an office or navigate a complicated digital process?

These are not edge cases. They are often the very people government programs exist to serve.

Advocates for people with disabilities often get this balance right. They already operate under strong know-your-customer expectations. They verify who they represent, maintain records, obtain signed authorizations, and put their professional standing behind the information they submit.

That accountability matters. Attorneys risk their law licenses for misrepresentation. Non-attorney representatives risk their eligibility to practice, their reputations, and the foundation of their income. They have a direct incentive to know their clients and ensure that information submitted to the government is accurate.

Government should build on that trusted relationship rather than force every claimant to start from zero. A verified representative should be able to help establish identity, protect a filing date, correct errors, and guide a claimant through alternative verification when the standard digital process fails.

That does not mean eliminating safeguards. It means recognizing that identity assurance can come from accountable people as well as technology.

Recently, we met with ID.me to discuss reducing identity-verification barriers for the people we serve nationwide. The conversation was practical and focused on improving access without abandoning security.

Government cannot solve identity management by purchasing another tool and declaring victory. We need a national discussion about what kind of identity system Americans want, what information may be used, who may use it, how errors are corrected, and what recourse exists when an identity is stolen.

Our community is already doing much of this work. It is protecting the public, identifying weaknesses, and helping legitimate people navigate systems that too often fail them.

The country should listen.

Fraud prevention matters. Privacy matters. Access matters. Accountability matters.

The objective should not be perfect security. It should be trusted identity, trusted access, and a clear path to resolution when the system gets it wrong.

Comments

Popular posts from this blog

Breaking the Bottlenecks: Information, Access, and the Fight for Time ACRD 2026 Annual Conference Keynote: Kissimmee, Florida

The McDonaldization of the Social Security Administration

When the Excuse Expires