Stop Accepting “Good Enough” Identity Verification

Steve Kelley

July 28, 2026

Stop Accepting “Good Enough” Identity Verification

During the pandemic, federal and state agencies pushed hundreds of billions of dollars in emergency benefits out the door as fast as they could. They had to. People were in crisis.

But speed without assurance has a cost. The impacts are well-documented now. More than $200 billion in improper payments flowed through programs like unemployment insurance, PPP, and EIDL, much of it enabled not by sophisticated hacking, but by identity verification that was not up to the task: Stolen Social Security numbers (SSNs), synthetic identities assembled from breached data, and claims filed in the names of dead people, incarcerated individuals, and victims who would not discover the fraud for months.

The systems were not breached at all. They worked as designed. And that is the problem.

We have spent decades building rigorous standards for how government protects data: FIPS 140-2 validated encryption, FedRAMP authorization, and continuous monitoring, to name just a few. But we routinely grant someone access with just a data check, versus an identity check that meets NIST SP 800-63A Identity Assurance Level 2 (IAL2), the baseline associated with strong remote identity proofing and identity verification. We lock the vault and then hand the combination to anyone who can match an SSN and a date of birth.

It’s past time we close this standards gap.

We Don’t Tolerate "Close Enough" Anywhere Else

In safety-critical domains, we demand high assurance because the consequences of failure are real. Nobody accepts "close enough" seatbelts. Nobody accepts "close enough" food safety inspections. Security teams don’t accept “close enough” with FIPS compliance or critical CVE remediation.

Yet that is how many agencies are still approaching digital identity. If the system is mostly sure you are who you claim to be, then it let them through. When it fails, we call it fraud, as if fraud is the predictable outcome.

The failure cuts twice. Legitimate people get locked out of benefits and services. Fraud rings get through using stolen personally identifiable information (PII) and synthetic documents. The problem lies in not only how systems are designed, but how we have come to accept the “close enough” standard they are built on.

“Good Enough” Identity Has a Price Tag

When digital identity assurance is low, the impact is concrete.

  1. Real people get hurt. Victims spend months or years untangling identity theft. Communities lose trust in the agencies and programs that serve them. The U.S. Government Accountability Office (GAO) has flagged improper payments as a persistent, government-wide vulnerability for decades.
  2. Benefits get stolen at scale. Criminal networks do not need to beat every control. They need to beat the weakest one. Once an attack works, it gets automated and repeated across agencies.
  3. Weak identity undermines program integrity. Account takeover, eligibility fraud, and improper payments all become easier when identity proofing is treated as a convenience layer instead of a security control.

And here is the uncomfortable truth: "close enough" is a choice. NIST SP 800-63 sets clear assurance levels for evidence collection, validation, and verification, while OMB M-22-09 places identity at the center of federal zero trust.

Why This Is Getting Harder

Federal digital identity teams are facing a collision of policy mandates and adversary capability. The conversation has moved beyond generic "online identity verification" to NIST specs like SP 800-63A identity proofing (IAL2), authentication assurance (AAL), federation assurance (FAL), and agency playbooks such as ICAM / FICAM and the Digital Identity Risk Assessment (DIRA).

At the same time, fraud is industrialized. Attackers use bots, synthetic identities, AI-generated documents, face swaps, and deepfakes. Attackers and scammers are capitalizing on the reality that adoption will be slow.

For agencies, the stakes are not abstract: improper payments, program integrity, fraud, waste, and abuse, public trust, and zero trust access decisions.

What High-Assurance Identity Should Look Like

If we are going to stop accepting "good enough," we need to layer our identity assurance, like we layer our security posture and risk acceptance.

High-assurance identity in government should align with the federal language of Identity, Credential, and Access Management (ICAM) and the NIST digital identity framework. In practice, that means identity proofing that is:

  1. Multi-layered: not one check, but several signals that are hard to defeat at the same time
  2. Resistant to replay, injection, and spoofing: built for adversarial conditions, not ideal ones
  3. Auditable: decisions can stand up to oversight, security review, and public scrutiny
  4. Equitable: strong enough to stop fraud without excluding legitimate users
  5. Scalable: able to support secure digital and remote onboarding for large, geographically distributed populations without forcing every user into an office or manual-review queue
  6. Grounded in biometrics: tied to the person, not just the data they can submit, so verification is based on who is present, not only what facts are known

Data aggregation and legacy eKYC checks can help confirm that submitted information matches a record, but they do not prove that the person presenting that information is the rightful owner of the identity in that moment.

If stolen PII is already circulating, data matching alone becomes a weak gate. Biometrics, paired with liveness and authoritative evidence, help answer the harder question: is this a real, present person who actually matches the claimed identity, not just someone who knows the right facts? That makes them far harder for deepfakes or other AI-generated attacks to defeat, because an attacker has to do more than submit matching data; they have to convincingly mimic a live human being and pass biometric and liveness checks in real time.

Agencies should evaluate vendors against those outcomes, not just a feature checklist. There is a real difference between a system that matches data and a system that delivers high-assurance identity verification grounded in authoritative evidence, biometrics, liveness, fraud defense, and remote onboarding at scale.

The Bar Needs to Be Higher Because the Stakes Already Are

Government services, benefits, and systems depend on trust. Identity is the front door. If an agency cannot establish identity and trust with the true owner on the other side of the transaction, the entire zero trust strategy starts to wobble.

No amount of downstream detection fully makes up for weak verification at the point of entry.

A Challenge for Leaders

If you own digital services at the federal, state, or local level, ask:

  1. What happens when our identity controls fail?
  2. Which attacks are we designed to stop, and which ones are we not prepared for?
  3. Does our current approach meet the assurance level NIST SP 800-63 would require for the risk profile of our services?
  4. If we were building our identity solution today, would we still accept what is in-place now?

"Good enough" can be a temporary state. But it cannot be the standard.

The Mandate Is Clear

Identity verification is a safety-critical control. It deserves the same rigor we apply to encryption, infrastructure security, and every other domain where failure has serious consequences.

The frameworks exist. The threat is here. The bar needs to rise.

Do not settle for less.

Ready to raise the bar on identity verification? Learn more about how Incode helps federal, state, and local agencies stop fraud without adding friction for legitimate users.

Steve Kelley
Steve Kelley is a Senior Director of Federal Sales at Incode, leading the company’s strategy across U.S. government agencies. He focuses on deploying biometric identity verification and AI fraud prevention to help agencies establish trust in the AI era.
Linkedin
Chapters