Nobody Is Watching the Money Once It Leaves Washington

This piece includes the first public description of the Federal Payee Integrity System, a proposal the Program Integrity Alliance has spent the past year developing.
The Government Accountability Office, an agency not known for dramatic pronouncements, published a report last month that effectively says something remarkable: The government’s decentralized fraud defenses are no longer well matched to the threat they are intended to stop.
GAO never says it quite that directly, but then it rarely does. The report, “Combating Fraud: Managing Risks in Federally Funded, State-Administered Programs,” offers a careful accounting of twenty federal programs and the oversight gaps running through each one. But the findings, read together, describe a system that is losing ground.
Start with the scope. The twenty programs GAO examined, including Medicaid, SNAP, and disaster assistance, account for roughly $1.1 trillion in federal obligations, nearly 90 percent of all funding that flows through states and other government entities. GAO has previously estimated that the federal government loses between $233 billion and $521 billion a year to fraud, 3 to 7 percent of federal obligations government-wide. The upper end of that range is larger than the annual budget of all but five federal agencies.
The report is striking because GAO’s central finding is structural— it concludes that every layer added between the federal government and the end recipient, whether a state, a subrecipient, a contractor, or a subcontractor, creates a new entry point for fraud and a new gap in oversight. Federal agencies do not have a direct legal relationship with subrecipients. That responsibility falls to the states, which pass funds down the chain while federal agencies oversee the states rather than the money itself. Visibility diminishes at every level.
That diminishing visibility shows up in the audit data. GAO analyzed nearly 90,000 single audits conducted between 2020 and 2024 across eighteen of the twenty programs and found severe, persistent findings in eighteen of them, meaning problems significant enough to trigger a modified audit opinion or a material weakness, and unresolved for at least two years or flagged in three consecutive audits. SNAP and the Children’s Health Insurance Program had the worst rates, at 19.2 percent and 24.4 percent of audits respectively. These are the same weaknesses showing up year after year, in program after program, without correction.
The improper payment numbers tell a parallel story. Federal agencies reported $186 billion in improper payments across 64 programs in fiscal year 2025, up $24 billion from the year before. Among the twenty programs GAO reviewed, Medicaid alone accounted for $37.4 billion in estimated improper payments, a 6.1 percent error rate on $666.1 billion in obligations. SNAP’s rate was higher still, at 10.9 percent. Temporary Assistance for Needy Families did not report an estimate at all, because HHS says it lacks the statutory authority to collect the data it would need to calculate one. GAO recommended in 2022 that Congress fix that, but Congress has not.
Perhaps the most telling finding involves the tools that already exist to prevent fraud before it happens. The Treasury Department operates a program called Do Not Pay, which lets agencies verify a recipient’s identity and eligibility before a payment goes out, checking against bank account data, incarceration records, and the Social Security Administration’s death records. Treasury says its fraud prevention and recovery efforts yielded $7.2 billion in fiscal year 2024. The tool is free to use, yet only about 4 percent of federal programs use its full suite of services. Most agencies cite legal barriers around data-sharing agreements or the staff time required to integrate it, but the tool sits there, mostly idle, while agencies process claims on faith and clean up the damage afterward.
The report also surfaces a case that captures how far fraud tactics have outpaced the government’s defenses. A Pandemic Response Accountability Committee official described a scheme in which a single Social Security number was used to file for unemployment benefits in 40 states at once, something GAO says would have been virtually impossible to pull off, let alone detect, a decade ago. Organized fraud groups now use bots and AI to submit large volumes of applications within minutes, often recycling the same stolen documentation across programs and states, specifically targeting programs that share eligibility criteria so a single stolen identity can be monetized multiple times over.
GAO’s own survey work explains part of why agencies aren’t further along. In a 2023 review of the 24 agencies covered by the Chief Financial Officers Act, GAO found that a third had no regular fraud risk monitoring or evaluation process at all, and half did not adapt their controls based on whatever evaluation they did conduct. Agencies cited staffing, funding, and expertise shortfalls.
Then there’s the data itself, which turns out to have its own integrity problem. GAO’s review of subaward reporting on USAspending.gov found records so degraded that one listed a subaward amount of $1 quintillion. Five others exceeded the entire U.S. gross domestic product for the year in which they were supposedly made. The system that is supposed to let anyone track where federal grant money actually goes lacks the basic validation controls to catch numbers that are, on their face, impossible.
GAO has made at least 50 recommendations specifically targeting these twenty programs since it published its Fraud Risk Framework in 2015. Agencies have implemented 28. Twenty-two remain open, at EPA, the Department of Energy, HHS, and HUD, addressing issues that in some cases date back years. Medicaid has sat on GAO’s High-Risk List for over a decade, for reasons GAO lists plainly: significant improper payments, weak enforcement of how states use Medicaid funds, and limited federal oversight of state-level spending data.
The report does not offer a sweeping fix. GAO documents the gap and, program by program, the recommendations that remain unaddressed. It does not tell Congress how to close it. Fixing these issues is a legislative choice and the shape of that choice is known.
Treasury operates a free identity verification tool that only 4 percent of programs use in full, because the alternative, each agency running its own contract with its own vendor, is what current law defaults to. The same fragmentation is what let a single stolen Social Security number file for unemployment benefits in 40 states at once. Expanding use of Treasury’s existing tool would help, but it would not solve the underlying problem, which is that even a fully adopted Do Not Pay is still hundreds of agencies and states each checking a payment against a shared list, one at a time, after they’ve already decided who they think the person is.
At the Program Integrity Alliance, we’ve spent the past year developing a different answer, one we’re proposing publicly for the first time here. We call it the Federal Payee Integrity System, or FPIS. Instead of every agency and state independently verifying the same people over and over, often through the same commercial vendors, being paid duplicately to run the same entities repeatedly, FPIS would resolve a person’s identity once, at the Treasury level, and issue a single Federal Payee ID that every program can check against. Agencies would keep full authority over who qualifies for their benefits. Treasury would simply confirm, before a payment goes out, that the person receiving it is who they claim to be and isn’t already collecting the same benefit under a different name in a different state.
That kind of infrastructure would have caught the 40-state case before the first payment, not after the twentieth. It is also, not coincidentally, the kind of reform GAO’s own findings point toward. The report describes agencies drowning in fragmented verification systems and recommends wider use of the tools that already exist. A centralized identity resolution and payment enforcement mechanism, one that leaves eligibility decisions to the agencies themselves, closes the largest structural gap exploited by fraud networks.
GAO has provided the evidence of a systemic problem, one many of us have long known about. Congress has signaled a willingness to engage in more bold legislative reform to help arm agencies in the fight against fraud. The time is now for real action.
Article first posted on GovIntegrity.