Whether the number of those stories and the amount of money involved is worth the hassle to the people not defrauding governments is left as an exercise to the reader...
Whether the number of those stories and the amount of money involved is worth the hassle to the people not defrauding governments is left as an exercise to the reader...
Is it the best solution? Likely not. But the problem is real and does demand a solution of some form.
From the original article: "According to the Department for Education (DfE), which oversees Teachers’ Pensions, death register entries may be matched to scheme members even if personal details differ. The DfE told the Guardian that once a possible match has been identified, the beneficiary may be asked to confirm that they are not the same deceased stranger every 12 months since the system, administered by Capita, does not log a disproved link."
The problem is with the approach in attempting to reduce fraud.
Once a false positive from an incomplete match from the death register is proven false - when the pension recipient tells you they are still alive - you don't need to check up on that same incomplete match every 12 months, because you already know it's false.
Demanding "a solution of some form" completely misunderstands the problem and is the same approach that gave us the Post Office scandal.
I don't follow? This is just a data quality problem. Should it be fixed? Obviously. But everyone deals with bad data. You can't fix that, you just optimize around it.
The Post Office scandal was emphatically NOT about a data quality problem. It was that they were criminally prosecuting people to cover up their data quality problem. Again, everyone has bad data.
The system, administered by C[r]apita, does not log a disproved link... so we get:
DfE: "Hello, are you dead or is our wrong data match from last time still wrong?"
The repeated asking of the same question is them covering up a data quality problem!
Isn't this really a process problem (i.e. a missed requirement), so that after the first instance of a queried match (for whatever reason), the unrelated death record (which will have some kind of unique document identifier or can have one derived from the information on it and date of issue) can be excluded from being matched against the subject user? (As realistically you could have 2 people with same name and DOB, it seems like the issue here is not data quality.)
It sounds like nobody created a requirement in the design stage for the ability to say "I've checked this, it's not the same person, don't flag this same death entry again". That's maybe not something envisaged at requirements time, but the need for it now becomes apparent.
Pretty much the same for all the work UKGOV does to try and combat "fraud", sadly - they always end up spending multiples of the amount they'd save[1]
[1] whilst at the same time enabling fraud of their own like the fast-track PPE contracts, etc.
But that doesn't apply here because the reason KYC/AML is so ineffective -- literally 99.9% ineffective -- is that it's so easy to transfer value in some other way. And in turn to claim that even if you're using a traditional bank.
Money laundering is fundamentally very simple. They open a business that could plausibly generate that amount of profit and then claim the money was the proceeds of that business instead of the illegal one. The bank has no better way to know this is happening than the government, and the only people who do are in on it. So the rules are totally ineffective and because they're totally ineffective, they don't provide a deterrent.
But it's even worse than that. Most government waste is actually somebody's profit or salary, so then they lobby to keep it, but if it's a lot of waste then competing sociopaths lobby to cut it so they can get the tax money, which provides at least some financial pressure to limit the excesses of any given program.
The primary cost of AML/KYC rules isn't tax dollars. They fall on the general public through invasion of privacy, bureaucratic overhead, transaction costs and impaired competition between financial institutions. The general public is a diffuse group without organized lobbyists and without a thorough understanding of how much this is costing them. It also falls disproportionately on people who are already disadvantaged and have even less political influence than average. So there is no one supplying strong political pressure to get rid of it despite the high costs and near-zero effectiveness -- it's basically down to the people who have figured out how stupid this is to make it go away on their behalf.
I thought that was clear enough in context. But: "Anti-Money Laundering" and "Know your Customer". They come up a lot in discussions here. Also, FWIW: if you're unclear about what someone meant, calling them stupid is a really terrible way to educate yourself.
This woman had to confirm three times in one month, and then still had her pension stop.
It's a system contracted out from UKGOV being administered on behalf of UKGOV. If government oversight worked, it would have worked already, surely?
Misaligned interests don’t create market failures. Usually imperfect information or costs/benefits borne by third parties do.
...and their customers... suppliers... partners... employees...
The U.S. has a database of social security numbers of the deceased which is quite interesting for a few reasons. It is closely guarded because social security numbers are assigned sequentially by geographic region so if you know someone’s SSN you can get their date of birth or vice versa.
If you manage to get in that database you are really in trouble because every financial institution has a copy of that list and there is no procedure to get you off. It is quite literally a “financial death sentence.”
This has been false for decades. (early '90s, I think?)
Edit: https://www.ssa.gov/employer/randomizationfaqs.html seems to say that the change was only implemented in 2011, which would mean that even more of the population is unaffected.
Note that enumeration at birth is a recent policy change. Before enumeration at birth, people would not get assigned a number until they (or their parents) asked for one. So while there is a sequential numbering (before that changed) and its tied to geography, the sequence and geography is connected to time and place of assignment, not time and place of birth.
For example, my parents got SSNs for me and my siblings all at once, sometime in the 80s, I beleive as it became required to claim dependents on tax returns. I don't think our SSNs are sequential, but they're close; however my siblings and I have different birth years and could have been born in different states than where we were enumerated.
SSNs aren’t secure credentials without validation, period.
For most of human existence, you would already know if Bob or Jane was dead, since you’d have gone to their funeral or knew someone who had.
[1] https://hansondoremus.com/2014-4-28-there-are-four-kinds-of-...
And where there is a financial incentive for recipients to hide this fact?
That’s about as (actually) knowable as how many folks in LA are drug dealers.
We know some are, clearly, since they’ve been caught. But that is not going to be even close to correct in real terms, because they are of course going to work very hard to not get caught.
https://www.crfb.org/press-releases/fact-sheet-how-much-wast...
States “ According to the Social Security Administration’s Inspector General, in 2013 just over 1,500 deceased individuals in all age ranges were still receiving benefits. They account for only $15 million in improper benefit payments.”
And “According to the Social Security Administration, all improper payments, including payments to the deceased and the very old, are estimated at about $3 billion per year.”
That is in the US. And the SSA is really aggressive in trying to track down these issues. Most other pensions don’t have their resources or the type of political pressure they get.
I’ve personally overheard enough discussions among old folks to know that isn’t even the tip of the iceberg though, anymore than arresting Bob for possessing coke is ‘stopping drug trafficking’.
Frustrating, but I’m sure we’ve all been there in some form as software engineers.
The article is attempting to publicly shame them enough that they fix it, which might work. Most organizations are allergic to bad press.
[0] https://slate.com/business/2012/04/the-four-types-of-economi...
The problem with this is simply that it’s not absolutely free, and the people promising savings through outsourcing need it to be free to make their promises happen. Cutting budgets everywhere removes the slack you need to deal with things like this.
The possibility of impersonation isn't limited to pension pay-outs but many other things as well. A once-per-year on-site visit would work and would just be a cost-of-business item, and that cost could be lowered substantially by collaborating with other entities who take an interest in such information (banks, governments etc).