Fraud is on the rise — and the critical question is whether government systems can keep pace.
Federal and state agencies have reached a crossroads in tackling fraud. According to the Government Accountability Office, the federal government loses anywhere from $233 billion to $521 billion each year to fraudulent activity. The Labor Department’s inspector general pegs identity-related fraud losses in unemployment programs during the pandemic at more than $100 billion.
Agencies are well aware of the growing fraud problem and have poured considerable resources into prevention initiatives at every level of government. Despite new programs and modernization pushes, however, fraud shows no signs of slowing down. The explosive growth and easy accessibility of generative AI and other cutting-edge tools have created a host of new ways for bad actors to exploit vulnerabilities.
In the meantime, ordinary citizens find themselves trapped in a frustrating loop. They’re asked to scan the same ID, reenter their name and date of birth, and respond to “secret” questions whose answers were compromised and sold long ago — only to repeat the entire ordeal at the next agency, and the one after that. The outcome isn’t enhanced security. It’s sluggish service, increased dropout rates, and vast stockpiles of personal information that turn into liabilities the instant a breach occurs. The irony is that a system designed to confirm identity is steadily eroding both security and citizens’ trust.
However, the government isn’t building from the ground up. Agencies are putting the groundwork in place for stronger defenses and upgraded critical infrastructure. For instance, the National Institute of Standards and Technology released Revision 4 of its digital identity guidelines (SP 800-63-4), which lays out a thorough framework for end-to-end identity programs. Recent updates to FedRAMP have also streamlined the authorization process for software-as-a-service vendors, enabling agencies to adopt modern identity tools more quickly and at greater scale. In addition, 22 states have launched or begun piloting mobile driver’s licenses (mDLs), which offer a highly secure and trustworthy method for digital identity verification.
These advances must be unified and fully leveraged to mount a coordinated government response against fraud. To effectively combat the rapidly escalating fraud threat and modernize identity verification, government agencies need to take three additional, high-impact steps.
First, agencies should embrace recent changes to the FedRAMP program that are fostering a more competitive and innovative landscape of vendors. Specifically, agencies now have greater flexibility to assess newer companies that can meet public-sector standards and bring proven experience fighting fraud in the private sector. For years, identity verification has been controlled by a handful of vendors, largely due to compliance hurdles rather than evolving threat realities. Updated FedRAMP requirements have made it easier for vendors to achieve Moderate Ready and Moderate Authorized status — credentials long required for handling sensitive personal data — paving the way for a wider pool of qualified providers. As these newer providers expand their presence in the public sector, agencies can adopt solutions that offer consumer-friendly experiences without sacrificing security or mission results.
Second, agencies need to make a decisive move away from checkbox-style compliance toward risk-based layering. NIST’s SP 800-63-4 offers an outstanding, well-rounded framework for identity verification, but treating Identity Assurance Levels (IAL) as a mere compliance stamp defeats their purpose. True assurance isn’t defined by a single designation — it’s built from how multiple signals interact and reinforce each other within a given context.
Agencies should follow NIST’s own recommendations and adopt a risk-driven approach rather than a compliance-driven one, understanding that stronger defenses come from stacking multiple, real-time indicators — much like the Swiss-cheese model of security. In real-world terms, an IAL2 process that leverages modern technologies such as an mDL can easily provide stronger assurance than many traditional IAL3 processes. Robust security doesn’t demand routing every user through a single IAL2 checkpoint. It demands combining complementary signals based on the level of risk. Today’s verification platforms already blend passive indicators — such as device reputation, IP and network risk, and behavioral patterns — with active ones like document verification and biometrics. When these signals are layered and cross-verified, they dramatically raise the difficulty and cost of committing fraud while making the experience smoother for legitimate users.
Finally, regulatory bodies and agencies should speed up the adoption of mDLs as a primary weapon against fraud. An mDL is far more than a digital picture of a physical card — it’s a cryptographically signed, issuer-verified credential with real-time revocation capabilities and selective disclosure. It allows agencies to validate key identity details (e.g., Is this license current? What is the person’s legal name?) without gathering excess personal information. The result is reduced breach risk, less stored data, and significantly stronger privacy protections for citizens.
Importantly, more selective data collection and less stored information do not translate to weaker assurance. The cryptographically signed, issuer-verified identity data is virtually impossible to forge, alter, or fake. Agencies should begin accepting mDLs as quickly as possible to enable faster, more trustworthy, and more secure identity verification — while simultaneously safeguarding privacy and strengthening public confidence.
The technology needed to dramatically curb fraud and modernize government operations already exists today. Citizens want seamless access without being repeatedly asked to prove who they are. Agencies want the most effective tools available, reduced fraud losses, and fewer data breaches. Privacy advocates want less personal data floating around. These objectives are fully aligned. What’s lacking isn’t some breakthrough yet to be discovered — it’s decisive action. Fraud is accelerating, and the question remains: will government systems respond quickly enough to keep up?
Bobby Kozyra serves as public sector lead at Persona and is a former U.S. Navy SEAL Officer and U.S. diplomat.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



