The flood took the documents. The aid requires the documents.
Emergency programmes are asked to move money in days to people who have lost everything, including the paperwork that proves who they are. The usual framing is a trade-off between speed and assurance. It is not a trade-off. It is a binding that nobody established in advance.
Picture a disaster recovery centre four days after the water went down. It is a school gymnasium with folding tables, a queue that goes out of the door and around the car park, and a small number of staff who have not slept properly since the declaration.
A woman reaches the front of the queue. She is asking for help with temporary housing, because the ground floor of her home is uninhabitable and the water took the filing cabinet with it. The caseworker's screen asks for a government identification number, a document, and an address that matches a record. She has a phone, which she charged in a car, and nothing else. Her driving licence is somewhere under two inches of silt. The house she has lived in for eleven years is currently a lease that exists only in an email account she cannot get into, because the password was in the password manager on the laptop, which is also under the silt.
The caseworker has two options and both are bad. Turn her away, which is the wrong answer for a person standing in a gym asking for help getting her family indoors. Or accept an attestation and pay, which is the answer the programme is designed to give in a declared emergency, and which is also the answer that a person three states away, who has never seen this town, is currently giving into a web form using her name and a stolen identification number.
Six weeks later she gets a letter saying her claim has already been paid.
Short answer. Emergency programmes relax identity proofing because documents are destroyed and people need money fast, and fraud follows the relaxation. The usual fix, tightening document checks, denies aid to real victims who have no documents. The missing capability is a document independent binding between a person and a key, established in ordinary times through everyday institutions, so agencies can recognise the same person and prevent duplicate claims without ever seeing an identity document.
Why does every emergency programme face the same impossible choice?
Because identity proofing, as built, is documentary. Nearly every verification process in the world ultimately reduces to: show me a document issued by an authority, and let me check that your face matches it and that the details match a record somewhere. That works well in ordinary conditions. It is precisely and completely broken by the conditions emergency programmes operate in.
Consider what an emergency does to each input. Documents are destroyed by water and fire, or left behind in an evacuation measured in minutes, or were never issued because the person was born somewhere with an incomplete civil registry. Addresses stop matching records because the address no longer exists or the person is now four hundred kilometres away in a relative's spare room. Phones are lost, or the number was on a contract that has lapsed. Connectivity is degraded exactly where the damage was worst. Credit and utility records, which back-office verification services rely on, become unreliable because the utilities themselves are offline.
So the programme faces a choice it has already made in advance by statute and policy: pay quickly. Emergency assistance that arrives in ninety days is not emergency assistance. That is a correct policy decision, and it means proofing gets relaxed, and every actor who watches these programmes knows it gets relaxed.
This is the same structural failure this series has described in a very different setting, where an organisation verifies a person once at a boundary and then has no way to recognise them afterwards. We called it the enrolment binding gap in the identity failure map. Here it appears at national scale and at the worst possible moment: the programme is trying to verify, in the storm, a binding that nobody established in the calm.
What does it cost when the check is too strict?
We are going to take this direction first, and at length, because most writing on this subject leads with fraud and treats exclusion as a regrettable side effect. That ordering is wrong. In a disaster, exclusion falls on people in acute crisis, and the harm is immediate and personal in a way that a line item in an improper payments report is not.
The people least able to satisfy a document check are, with grim reliability, the people who most need the payment. Someone with a stable address, a current licence, a credit file and a smartphone will clear an identity check in four minutes. Someone who was already housing insecure before the fire, who has an expired identification document, who is not on a utility bill because they live with family, who has thin credit, or who is elderly and has not driven in fifteen years, will fail. Not because they are not who they say they are. Because the verification system's inputs are proxies for stability, and they were unstable before the emergency and are now more so.
The failure modes compound. A person who fails an automated check is routed to manual review, which in a disaster means a longer queue and a caseworker who is already overwhelmed. A person who fails twice often gives up, and abandonment does not appear in fraud statistics at all. It appears, if anywhere, in a different agency's numbers months later, as an eviction or a hospital admission.
There is also a specific harm worth naming for displaced populations. Requiring documentary proof of identity from someone fleeing persecution can be actively dangerous, because the documents that establish who they are can also establish what they are to the people they fled. Any design that assumes a document, or that builds a central register of who claimed what, is not neutral for that population. It is a risk.
What does it cost when the check is too loose?
The other direction is a real problem too, and it deserves to be stated plainly rather than waved away, because a programme that loses public confidence loses funding, and the people harmed by that are the same people harmed by exclusion.
At the government wide level the numbers are large. The Government Accountability Office reported that federal agencies estimated roughly 186 billion dollars in improper payments across dozens of programmes in fiscal year 2025 (GAO-26-108694), and contemporaneous reporting cited figures a few billion either side of that depending on which programmes are counted. It is important to be careful with that number, because it is routinely misquoted: improper payments are not the same as fraud. A substantial share are documentation and eligibility errors, payments made in the wrong amount, or payments that were probably fine but lacked evidence to confirm. Conflating the two is the most common error in coverage of this subject and it poisons the policy debate.
The clearest identity specific evidence comes from the pandemic period, where relaxed proofing met a programme designed for an order of magnitude fewer claimants. GAO estimates cited in congressional materials put pandemic unemployment insurance fraud somewhere in the range of 100 to 135 billion dollars. Whatever the precise figure, the mechanism is not in dispute: identity fraud concentrated in the window where verification was loosened, and it was committed at volume by people who never went near a disaster zone.
Disaster assistance sees the same pattern at smaller scale, and inspectors general pursue these cases routinely. We are deliberately not quoting a single headline conviction figure here, because the numbers that circulate for individual disaster fraud cases are hard to trace to a primary document, and the argument does not need one.
The mechanism that matters for our purposes is duplication. The same identity, or several fabricated ones, claiming across multiple programmes and multiple jurisdictions, is the highest yield version of this fraud, and it works because no two programmes can tell they are looking at the same claimant without sharing personal data they often may not lawfully share.
Why is this not actually a trade-off?
Here is the reframing.
Agencies experience this as a dial between speed and assurance, and they are not wrong that the dial exists given the tools they have. But the dial only exists because of a prior absence. The verification is hard in the emergency because there is no durable binding between the person and anything they can still present. Everything the system asks for is something the emergency destroyed.
Ask a different question: what does the programme actually need to know? Not, usually, who this person is in the full civil registry sense. It needs two things. It needs to know that this claimant is a distinct human being, so that one person cannot claim four times. And it needs to know, for the subset of claims where it matters, that this is the same person who holds a particular relationship, such as being the tenant at the damaged address.
Uniqueness is not identity, and programmes keep buying the second when they need the first. That distinction is the whole argument. Preventing duplicate claims does not require knowing anyone's name. It requires being able to tell that two claims came from the same person, which is a much weaker and much cheaper property, and one that can be established without a document and without a central register of identities.
The primitive: continuity from any prior enrolment
Suppose that at some ordinary moment before the emergency, this person was enrolled somewhere. Not by the disaster agency, which had no reason to enrol anyone. By a bank opening an account, an employer at onboarding, a mobile operator activating a line, a school, or a government wallet programme. At that moment, on their own device, a key was created and a one way person key was derived. No image was stored, no template was retained, and no central database of faces was created. What exists afterwards is a key on a device and, at the enroling institution, a value that cannot be reversed into a face.
Now the emergency happens and the device is gone. The person arrives at the recovery centre with a borrowed phone. They perform a liveness ceremony on that phone, the same on device check they did originally, and the same one way person key is derived. The agency does not learn who they are. It learns that this is a person, present and live, and that this specific person has or has not already claimed.
That is continuity: same human, new device, no documents. It is the exact case the mechanism was designed for, and it happens to be the case emergency programmes need most.
What would this look like at the counter?
The claim submission carries the key and a statement of what kind of evidence backs it, rather than a document image.
POST /claim
{
"programme": "disaster-assistance-2026-09",
"person_key": "pk:7d1a...e93", // one-way, derived on device
"continuity": {
"level": "reestablished", // enrolled | glance | reestablished
"prior_enrollment": "2024-03-11", // exists, not who or where
"liveness": "passed"
},
"claim": { "household_size": 4, "address_at_incident": "..." },
"sig": "ed25519:..."
}
And the agency's logic stays boring, which is what you want in a gymnasium at hour ninety.
on_claim(c):
assert sig_valid(c) # offline, published key
if already_claimed(c.person_key, c.programme):
return DUPLICATE # without learning who they are
match c.continuity.level:
"reestablished" -> route = FAST_PATH # prior binding, live now
"enrolled" -> route = FAST_PATH # enrolled at the counter
_ -> route = CASEWORKER # staffed, and normal
record(c.person_key, c.programme)
return route
Two properties are worth pausing on. First, the duplicate check compares keys, not identities, so two agencies can both learn that a claimant has already been served without either of them sharing a name, a number, or a face, which is a materially better privacy posture than the data matching arrangements used today. Second, a person with no prior enrolment is not rejected. They are enrolled at the counter in the same ceremony, which takes seconds, and from that moment they are recognisable at the next touchpoint. That is what stops the second and third claim even for someone who arrived with nothing at all.
Which emergency scenarios does this actually cover?
| Scenario | What the programme needs | Available today | With prior binding |
|---|---|---|---|
| Resident lost documents in the flood, has a phone | Uniqueness plus a link to the address | Document upload, likely to fail | Continuity re-established in seconds, fast path |
| Resident lost documents and phone | Uniqueness | Manual review queue | Continuity on a borrowed device, fast path |
| Never had a government document | Uniqueness | Trusted referee or attestation, slow | Enrol at the counter, recognised thereafter |
| Claiming across two programmes | Cross programme duplicate detection | Post payment data matching, months later | Duplicate detected at submission, no data shared |
| Fabricated identity submitted online | Proof of a live, distinct human | Weak, this is where the fraud concentrates | Cannot produce a live key at scale |
| Person fleeing persecution | Aid without a record of who they are | Documentary proofing, actively risky | Uniqueness without identity |
| No connectivity at the site | Verification offline | Degrades badly | Receipt verifies offline against a published key |
The final row is not a detail. Offline verification, which we describe in general terms in the post on verifying without calling the issuer, is the property that makes any of this usable in a field setting where the network is the first thing to fail.
Honest limits
This is a policy argument as much as a product one, and the gap between them should be stated clearly. Manav has no government or humanitarian deployment. Nothing described here is running in a disaster programme anywhere.
- Prior enrolment cannot be assumed, and coverage is the whole argument. Continuity only helps someone who was bound somewhere beforehand. Today, almost nobody is. The realistic path is that enrolment happens for ordinary reasons at banks, employers and operators over years, and emergency readiness is a by-product. That is a slow, unglamorous answer, and we think it is the true one.
- The people with the least prior enrolment are the people with the most need. This is the uncomfortable centre of the whole proposal. Anyone housing insecure, undocumented, or outside the formal economy is least likely to have been enrolled by a bank or an employer, which means a continuity based design would work best for the people who need it least, unless enrolment is deliberately extended to institutions that reach everyone. Any programme adopting this must plan for that explicitly or it will reproduce the inequity it was meant to fix.
- Enrolling at the counter stops the second claim, not the first. A fabricated first claim from a live human still succeeds. What breaks is scale, because one human cannot become forty.
- A staffed path must be the normal route, not the exception. Phones fail, hands are injured, people are in shock, and some will not or cannot complete any digital ceremony. NIST's identity proofing guidance in Special Publication 800-63A contemplates trusted referees and applicant references for exactly these situations, and any emergency design should treat that path as a first class route with adequate staffing rather than a fallback nobody budgeted for.
- Cross programme matching has legal limits. Matching keys shares less than matching names, and it is still a data sharing arrangement between agencies, subject to privacy law that varies by jurisdiction and that exists for good reasons. This does not route around that. It makes the sharing minimal enough to be defensible.
- None of this addresses eligibility. Uniqueness and continuity say nothing about whether the claimant's house was actually damaged, which is a different and equally hard verification problem.
What an agency or NGO can do this quarter
- Separate the two questions in your own programme design. Write down, for each control, whether you are establishing identity or establishing uniqueness. Most programmes discover they have been paying for the first when the second was sufficient.
- Measure your exclusion rate, not only your fraud rate. Count abandonment at the identity step, manual review queue times, and second attempt failures. If you cannot produce those numbers, you are optimising one side of a two sided problem.
- Treat the trusted referee path as designed capacity. Staff it, measure it, and stop treating it as an exception, because in a disaster it will carry a large fraction of the hardest cases.
- Ask what duplicate detection would require without sharing identities. Put the question to your counterparts in adjacent programmes before the next declaration rather than during it.
- Talk to the institutions that enrol people in ordinary times. Banks, employers, operators and schools in your region are where any pre-existing binding will come from. Nothing you build during an emergency will create one.
- Insist that any verification supplier can operate offline. If it needs a live callback to a vendor, it will fail at the site where you need it most.
- Write the privacy posture down first. Decide, before procurement, whether your programme will hold biometric templates or only one way keys. That decision is much harder to reverse afterwards, and it determines whether your claimant register becomes a target.
If you want to see what a document free, no signup presence check actually feels like in a browser, there is a working demo at the walk-up verification lab, and the mechanics of scoped, offline verifiable receipts are in the documentation. The related problem of re-establishing an account after losing every device is covered in recovery without the identity document upload, and the reason document checks themselves are weakening is in the piece on injection attacks against verification.
Frequently asked questions
How do agencies verify identity after people lose their documents? Mostly they relax the requirement. In a declared emergency, programmes accept self attestation, alternative evidence, or in person verification at a recovery centre, and rely on post payment audits to catch problems later. Some use identity verification vendors and data matching against credit and utility records, which degrade in exactly the areas that were worst affected.
How much emergency aid is lost to identity fraud? Precise figures are contested. The Government Accountability Office reported roughly 186 billion dollars in federal improper payments for fiscal year 2025, but improper payments include documentation and eligibility errors, not only fraud. The clearest identity specific evidence is pandemic unemployment insurance, where GAO estimates cited in congressional materials range from 100 to 135 billion dollars.
Can duplicate claims be prevented without a national biometric database? Yes, and that is the important part. Duplicate detection needs to know that two claims came from the same person, not who that person is. A one way person key derived on the claimant's own device lets two programmes both learn that a claimant has already been served without either holding a face, a name, or a shared identity record.
What is pre-enrolment and why does it matter for emergencies? Pre-enrolment means the binding between a person and a key is established in ordinary times, through a bank, employer, mobile operator or wallet programme, long before any emergency. It matters because verification in a disaster is trying to check a relationship that must already exist. You cannot create the binding in the storm.
Does requiring a phone exclude the people who need help most? It would, if it were required. Any workable design has to let a person complete the check on a borrowed device and has to keep a staffed human route as a normal path rather than an exception. NIST's proofing guidance already contemplates trusted referees for this reason. A programme that treats the staffed path as an afterthought will fail the people it most needs to reach.
Is this safe for refugees and people fleeing persecution? It is safer than documentary proofing, which is the relevant comparison, because it does not require producing papers that reveal who or what you are, and it does not create a register of who claimed what. It is not risk free. Any cross programme matching arrangement, however minimal, needs a specific assessment for populations where being identified is itself the danger.
Sources
- US Government Accountability Office, improper payments reporting including GAO-26-108694: gao.gov
- US Government Accountability Office, fraud risk framework and work on state administered programmes: gao.gov
- US House Committee on Ways and Means, materials citing GAO estimates of pandemic unemployment insurance fraud: waysandmeans.house.gov
- NIST Special Publication 800-63A, identity proofing and enrolment, including trusted referees and applicant references: pages.nist.gov
- US Department of Homeland Security Office of Inspector General, disaster assistance oversight: oig.dhs.gov
- FEMA, individuals and households assistance programme guidance: fema.gov
- UNHCR, registration and identity management in displacement settings: unhcr.org
- World Bank, Principles on Identification for Sustainable Development: id4d.worldbank.org
You cannot verify in the storm a relationship that nobody established in the calm.