
During the pandemic, federal and state agencies pushed hundreds of billions of dollars in emergency benefits out the door as fast as they could. They had to. People were in crisis.
But speed without assurance has a cost. The impacts are well-documented now. More than $200 billion in improper payments flowed through programs like unemployment insurance, PPP, and EIDL, much of it enabled not by sophisticated hacking, but by identity verification that was not up to the task: Stolen Social Security numbers (SSNs), synthetic identities assembled from breached data, and claims filed in the names of dead people, incarcerated individuals, and victims who would not discover the fraud for months.
The systems were not breached at all. They worked as designed. And that is the problem.
We have spent decades building rigorous standards for how government protects data: FIPS 140-2 validated encryption, FedRAMP authorization, and continuous monitoring, to name just a few. But we routinely grant someone access with just a data check, versus an identity check that meets NIST SP 800-63A Identity Assurance Level 2 (IAL2), the baseline associated with strong remote identity proofing and identity verification. We lock the vault and then hand the combination to anyone who can match an SSN and a date of birth.
It’s past time we close this standards gap.
In safety-critical domains, we demand high assurance because the consequences of failure are real. Nobody accepts "close enough" seatbelts. Nobody accepts "close enough" food safety inspections. Security teams don’t accept “close enough” with FIPS compliance or critical CVE remediation.
Yet that is how many agencies are still approaching digital identity. If the system is mostly sure you are who you claim to be, then it let them through. When it fails, we call it fraud, as if fraud is the predictable outcome.
The failure cuts twice. Legitimate people get locked out of benefits and services. Fraud rings get through using stolen personally identifiable information (PII) and synthetic documents. The problem lies in not only how systems are designed, but how we have come to accept the “close enough” standard they are built on.
When digital identity assurance is low, the impact is concrete.
And here is the uncomfortable truth: "close enough" is a choice. NIST SP 800-63 sets clear assurance levels for evidence collection, validation, and verification, while OMB M-22-09 places identity at the center of federal zero trust.
Federal digital identity teams are facing a collision of policy mandates and adversary capability. The conversation has moved beyond generic "online identity verification" to NIST specs like SP 800-63A identity proofing (IAL2), authentication assurance (AAL), federation assurance (FAL), and agency playbooks such as ICAM / FICAM and the Digital Identity Risk Assessment (DIRA).
At the same time, fraud is industrialized. Attackers use bots, synthetic identities, AI-generated documents, face swaps, and deepfakes. Attackers and scammers are capitalizing on the reality that adoption will be slow.
For agencies, the stakes are not abstract: improper payments, program integrity, fraud, waste, and abuse, public trust, and zero trust access decisions.
If we are going to stop accepting "good enough," we need to layer our identity assurance, like we layer our security posture and risk acceptance.
High-assurance identity in government should align with the federal language of Identity, Credential, and Access Management (ICAM) and the NIST digital identity framework. In practice, that means identity proofing that is:
Data aggregation and legacy eKYC checks can help confirm that submitted information matches a record, but they do not prove that the person presenting that information is the rightful owner of the identity in that moment.
If stolen PII is already circulating, data matching alone becomes a weak gate. Biometrics, paired with liveness and authoritative evidence, help answer the harder question: is this a real, present person who actually matches the claimed identity, not just someone who knows the right facts? That makes them far harder for deepfakes or other AI-generated attacks to defeat, because an attacker has to do more than submit matching data; they have to convincingly mimic a live human being and pass biometric and liveness checks in real time.
Agencies should evaluate vendors against those outcomes, not just a feature checklist. There is a real difference between a system that matches data and a system that delivers high-assurance identity verification grounded in authoritative evidence, biometrics, liveness, fraud defense, and remote onboarding at scale.
Government services, benefits, and systems depend on trust. Identity is the front door. If an agency cannot establish identity and trust with the true owner on the other side of the transaction, the entire zero trust strategy starts to wobble.
No amount of downstream detection fully makes up for weak verification at the point of entry.
If you own digital services at the federal, state, or local level, ask:
"Good enough" can be a temporary state. But it cannot be the standard.
Identity verification is a safety-critical control. It deserves the same rigor we apply to encryption, infrastructure security, and every other domain where failure has serious consequences.
The frameworks exist. The threat is here. The bar needs to rise.
Do not settle for less.
Ready to raise the bar on identity verification? Learn more about how Incode helps federal, state, and local agencies stop fraud without adding friction for legitimate users.