Why GAO Did This Study Synthetic identity fraud is a growing concern among financial institutions, which reported $182 million in related suspicious activity in 2021. The Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018 directed SSA to combat such fraud by developing a database to electronically verify identifying information. However, questions have been raised about the service’s financial viability and use by industry participants.
GAO was asked to examine, among other objectives, the extent to which SSA has (1) followed guidance and best practices for cost estimation for its Electronic Consent Based Social Security Number Verification service, (2) designed user fees to promote cost recovery for the service, and (3) taken steps to expand use and benefit of the service.
GAO reviewed relevant laws, guidance, and agency documentation and data and interviewed SSA officials responsible for the service. GAO also interviewed 16 industry participants selected to reflect a mix of entities and uses of the service.
What GAO Found
The Social Security Administration (SSA) launched the Electronic Consent Based Social Security Number Verification service in June 2020. The service seeks to reduce synthetic identity fraud, which combines fictitious and real information to fabricate an identity. The service allows authorized entities—generally financial institutions and their service providers—to verify an individual’s name, Social Security number, and date of birth electronically. SSA spent about $62 million from fiscal year (FY) 2018 through FY 2023, based on SSA data. However, SSA did not follow agency guidance for planning IT investments when estimating costs for the service. Moreover, its guidance on cost estimation did not consistently incorporate GAO best practices, such as documenting the estimation process. By establishing appropriate controls to ensure that all significant IT investments follow agency guidance and updating guidance to incorporate additional best practices, SSA could improve cost estimation for future projects.
SSA is required to fully recover the service’s costs and collected about $25 million in user fees (40 percent of $62 million total costs) as of the end of FY 2023. SSA has not met its projections for fee collections due to lower-than expected industry participation. SSA will need to collect about $14 million annually to meet its goal to recover all costs by the end of FY 2027, based on GAO’s analysis (see figure). But it is unclear if SSA can meet its goal without increasing users or fees. Subscription data through December 2023 demonstrate that the service has not significantly increased users since enrollment opened in FY 2022, and fee collections decreased after SSA increased fees in July 2023….
What GAO Recommends
GAO is making seven recommendations to SSA, including that it implements appropriate controls over IT investments, updates cost estimation guidance, develops strategies to expand use of the service, and establishes related performance measures and goals. SSA concurred with all seven recommendations and stated that it will evaluate its policies and processes to determine how to address them.
Not Yet a Premium Partner/Sponsor? Learn more about the OS AI Premium Corporate and Individual Plans here. Plans start at $250 annually.