Articles · Pandemic unemployment insurance
Reported article
Pondera's 1.1 Million Flags
A Thomson Reuters subsidiary scored nearly ten million pandemic-era unemployment claims for California. The state stopped paying 1.1 million of them. More than half turned out to be real.
In December 2020, California's Employment Development Department hired Pondera Solutions to run a fraud sweep across nearly ten million unemployment claims filed since the pandemic began — everything on the books from before the state had switched on its new identity-verification system, ID.me.1 Pondera and EDD together flagged 1.1 million of those claims as potentially fraudulent. Starting in January 2021, EDD stopped paying them. Claimants were not notified in advance. To get the money moving again, a flagged worker had to pass ID.me's identity check; refuse or fail, and the account closed permanently.2 More than half of the flagged population, about 600,000 people, was later confirmed legitimate.3
Pondera itself, founded in 2011 by Jon Coss and based in Sacramento, built its business selling fraud-detection software to government benefit programs. Thomson Reuters (TSX/NYSE: TRI) announced its acquisition of Pondera on March 19, 2020, folding the company's tools into its risk, fraud, and compliance offerings.4 EDD's contract with the newly acquired subsidiary went live that December, nine months into the pandemic, and after the state's own numbers were already showing the strain.
What the model looked at
EDD's later account of the arrangement, an internal fraud-tools assessment prepared with consulting support from Accenture, describes Thomson Reuters' product as a "fraud detection tool" layered on top of the department's manual screening. The assessment says it was used to screen new claimants for non-identity fraud risk and to supplement the manual identity checks on claimants who filed by phone or on paper.5 The capabilities EDD evaluated included claimant and employer validation against shared identifiers (home address, IP address, email address), deceased-recipient matching, geospatial clustering of claimants and employers, and a "fictitious employer" module for spotting fabricated businesses filing claims for fabricated employees. Every claim run through the system came out the other end with a numeric risk score on a scorecard.6 Separately, EDD cross-matched claims against incarceration and institutional records held by the California Department of Corrections and Rehabilitation, the Department of State Hospitals, and the Department of Juvenile Justice — internal EDD checks that the assessment reports "in addition to" the Thomson Reuters and ID.me tools.7
None of that is exotic as fraud analytics goes. Pondera's national business, as documented separately by the Electronic Privacy Information Center through public-records requests to agencies in California, Nevada, Illinois, the District of Columbia, and other states, ran the same kind of scoring (under the product name FraudCaster) across a wider set of inputs still: race, disability status, citizenship, criminal history, homelessness status, household composition, and more, drawn from data brokers, credit reporting agencies, and government databases. EPIC says the company does not publish an error rate for the score.8 Pondera's own CEO, in comments EPIC quotes from the period, put a number on his priors: in some states, Jon Coss said, he believed 75 percent of applications to federal programs were "very likely fraud."9 EPIC's review is a multi-state records project, not an audit of California's UI action specifically, and its findings about FraudCaster's inputs elsewhere aren't proof of the exact variables EDD's contract used. What the California record and the national record agree on is the shape of the tool: a proprietary score, built on data the scored person cannot see, that an agency uses to decide whom to pay.
What 1.1 million and 600,000 mean
A risk score is not a finding. EDD's decision to stop paying 1.1 million claims was the department's own action, taken on Pondera's output; the 600,000 reversals are equally EDD's own later determination, not a court judgment or an audited fraud rate. The state's Legislative Analyst's Office put the gap between those two numbers before the Legislature in February 2022, in a budget review titled "Assessing Proposals to Address Unemployment Insurance Fraud."
The LAO placed the batch review inside a longer sequence. A Governor's strike team, convened in July 2020 to investigate EDD's claims backlog, had reported that September that the department's pre-pandemic manual fraud-review process caught roughly one fraudulent claim for every 500 applications flagged for scrutiny, and that "a culture of allowing fear of fraud to trump all other considerations" had contributed to the backlog rather than solved it. The strike team's recommendation was that any new anti-fraud measure be supported by data and weighed against its cost to legitimate claimants.10 EDD's next major move, three months later, was hiring Pondera to run the batch review that flagged 1.1 million claims. The LAO's assessment was blunt about what that sequence showed: EDD's use of the tool "raises concerns that EDD has not internalized the strike team's fraud-related recommendations."11
The LAO also separated the state's fraud numbers into pieces the batch review doesn't answer for by itself. Of the fraud administration officials estimated across the pandemic's unemployment programs, $18.7 billion (94 percent) was attributed to the federally funded Pandemic Unemployment Assistance program, against $1.3 billion attributed to the state's own regular UI benefits. The LAO's own view was that even the $1.3 billion figure was likely overstated, since EDD counted a claim as fraudulent whenever a worker failed to respond to a request for additional verification, a category that includes people who had simply given up on an unresponsive agency. A separate estimate cited in the same review, drawn from the strike team's own findings, put likely fraud in the state program as low as $100 million against $35 billion paid.12 None of those figures are the same measurement as "claims Pondera flagged," and the LAO's report does not combine them; the 1.1 million figure is a count of claims stopped, not a dollar loss estimate.
The LAO recommended against buying the tools permanently
By early 2022, the tool that had flagged the 1.1 million claims had become a budget line item. The Governor's 2022-23 budget proposed $29.8 million for six third-party UI fraud contracts, two of which were Thomson Reuters products: "Automated Batch Review," described in the budget documents as the same software used in January 2021 to suspend the 1.1 million claims, and "Identity Risk Analytics," a related tool to let EDD screen new claims daily rather than weekly.13 The LAO recommended the Legislature reject both, on the ground that making the pandemic-era tools permanent would repeat the same trade-off the strike team had already flagged, without a demonstrated need now that ID.me was screening new claims in real time.14
Thomson Reuters' relationship with EDD did not end there. EDD's fraud-tools assessment, covering calendar years 2020 through 2022, credits the company's tools with flagging about a million additional claims across the three years and reports billions of dollars in claimed fraud avoided — figures the assessment attributes to the vendor's own reporting and EDD's internal tracking, not to an independent audit or adjudication, and measured against a different baseline than the one-time 1.1-million-claim sweep.15 The same document records that in January 2022, EDD and Thomson Reuters implemented a change called "Results Based Rule Calibration," intended, in EDD's own description, to reduce how often legitimate customers were caught by an alert while keeping the alert effective against actual fraud .16
EDD still could not fully inspect the tool. Its assessment says “some information remains proprietary” and that the department would have to “request changes to terms and conditions to gain full access” to material needed for evaluation, including information that third parties hold.17
Three vendors, three roles
The unemployment-benefits fraud fight in California ran through at least three separate private contracts. Pondera, under Thomson Reuters, built the risk score that told EDD which claims looked suspicious; EDD made the decision to stop paying them. ID.me supplied the identity-verification gate a flagged claimant had to clear to get reinstated, a separate contract with its own separate record of wait times, accessibility complaints, and biometric-privacy scrutiny.18 Bank of America, under yet another contract, issued the prepaid debit cards EDD used to disburse benefits and handled disputes over frozen accounts and unauthorized withdrawals — a relationship with its own federal injunction and its own $225 million in regulatory penalties.19
Notes
- California Legislative Analyst's Office (LAO), "The 2022-23 Budget: Assessing Proposals to Address Unemployment Insurance Fraud," Feb. 15, 2022, "Background" section: "In December 2020, EDD hired Pondera, an investigation consulting firm owned by the Thomson Reuters news service, to review nearly 10 million claims issued during the pandemic, but before ID.me came online, for potentially fraudulent characteristics." ↩
- LAO, same report: "EDD and the contractor identified 1.1 million claims as potentially fraudulent. EDD stopped payments for these claims. Workers were not notified ahead of time. To reopen their accounts, workers had to verify their identity using ID.me or their accounts would be closed permanently." The budget-proposal description of the "Automated Batch Review" contract in the same report identifies this as the tool "used in January 2021 to suspend 1.1 million claims," dating the suspension itself to January 2021. ↩
- LAO, same report: "Ultimately, more than half of the claims (600,000) flagged as fraudulent were confirmed as legitimate." ↩
- Thomson Reuters, "Thomson Reuters Acquires Pondera Solutions," Mar. 19, 2020 (PR Newswire, Mar. 19, 2020, 06:30 ET): announcing the acquisition of Pondera Solutions, "a leading provider of technology and advanced analytics to combat fraud, waste and abuse in healthcare and large government programs"; Pondera "[f]ounded in 2011," based in Sacramento with an office in Florida; Jon Coss identified as CEO and founder; financial terms not disclosed. ↩
- California Employment Development Department, Fraud Tools Assessment (prepared under Assembly Bill 138, Ch. 78, Stats. 2021, adding Cal. Unemp. Ins. Code § 340(a)(1)), Section 2 ("Scope of Fraud Assessment Tool Review"): identifying "Thomson Reuters [Pondera and CLEAR platform] and ID.me" as the two primary fraud tool vendors in scope, describing Thomson Reuters' offerings as "Fraud detection screening; Business intelligence; and Investigations management," used to "screen new UI customers for non-identity related fraud risk (e.g., mailing address, county and federal incarceration status)" and to "complement EDD's manual process to screen identity related fraud risk for paper and phone UI claim filers," and stating "TR was implemented in December 2020." ↩
- Same document, Section 5.3.1 ("TR Pondera – Capabilities Assessment"), listing as met features: Claimant Validation ("shared values (such as home address, IP address, e-mail address), deceased participants, behavioral pattern matching, and other anomalies"), Employer Validation, Procedural Flagging, Geospatial Analysis, Street View, Data Matching ("multiple lists used for fraud detection"), Scorecard ("ready access to claimants and their associated risk score"), and Fictitious Employer Schemes. ↩
- Same document, Section 2 and Section 5.5 ("Internal Processes and Cross Matches"), describing EDD's internal cross-matching against the California Department of Corrections and Rehabilitation (CDCR), Department of State Hospitals (DSH), and Department of Juvenile Justice (DJJ) as distinct from, but adjacent to, the Thomson Reuters tool's non-identity fraud screening for "mailing address fraud, county and other states incarceration status." ↩
- Electronic Privacy Information Center (EPIC), "Screening and Scoring Spotlight: Pondera's Fraud Prediction Algorithms for Public Benefits" (epic.org/pondera-surveillance), describing EPIC's public-records requests to agencies in California, the District of Columbia, Georgia, Illinois, Indiana, Iowa, Kansas, Louisiana, Massachusetts, Montana, Nevada, and South Carolina; describing Pondera's FraudCaster product as scoring applicants using data "from data brokers, social media scrapers, credit reporting agencies, location servicers, and government records databases," including "race, disability, citizenship, criminal history, failure to report income, homelessness status, income, household composition ... Medicaid assistance, paternity, and 'purpose of care'"; and stating "Pondera does not make public any of its error rates." ↩
- Same EPIC page: "Jon Coss, Pondera CEO, has publicly stated that in some states, he believes that 75% of applications to federal programs are 'very likely fraud.'" ↩
- LAO, "Assessing Proposals to Address Unemployment Insurance Fraud," Background section on the Governor's strike team: strike team convened July 2020, overseen by the state's Government Operations Agency, publishing its assessment in September 2020; quoting the strike team's finding that "for each 500 claims EDD staff flagged for more thorough review, one fraudulent claim was uncovered," and its finding that "[t]here has developed at EDD a culture of allowing fear of fraud to trump all other considerations." ↩
- LAO, same report, Assessment section: "The department's use of the Thomson Reuters software to suspend 1.1 million claims, of which at least 600,000 were legitimate, raises concerns that EDD has not internalized the strike team's fraud-related recommendations." ↩
- LAO, same report, Assessment section and accompanying figure: administration estimate of $18.7 billion (94%) in suspected PUA-program fraud versus $1.3 billion (6%) in suspected state UI-program fraud; LAO's assessment that the $1.3 billion figure is "likely overstated" because EDD counted a claim as fraudulent whenever a claimant did not respond to an identity-verification request; and a separate estimate, attributed to the strike team's findings, of as little as $100 million in state UI fraud against $35 billion paid. ↩
- LAO, same report, Proposal section: 2022-23 Governor's Budget request of $29.8 million General Fund for six third-party UI anti-fraud contracts, including "Automated Batch Review. Thom[s]on Reuters software tool used to flag potentially fraudulent claims. Same tool used in January 2021 to suspend 1.1 million claims," and "Identity Risk Analytics. Thom[s]on Reuters software contract to allow EDD to review new UI claims daily instead of weekly." ↩
- LAO, same report, Recommendations section: "We recommend the Legislature reject the pandemic era anti-fraud contracts with Thom[s]on Reuters for automated batch review and identity risk analytics because the state's use of these programs adversely impacted the experience of several hundred thousand unemployed workers with legitimate claims and are not likely to be useful now that automated identity verification is in place." ↩
- EDD Fraud Tools Assessment, Section 5.3.3 ("TR Pondera – Mitigated Fraud"): reporting, by EDD's own tabulation, 703,378 "Fraud Claims Prevented" and $6,109,869,842 "Fraud Mitigated" for calendar year 2020; 247,220 claims and $4,379,141,875 for 2021; 50,725 claims and $125,787,258 for 2022. These figures are the vendor/EDD's own reporting of claims flagged and estimated dollars associated with them, not an independently audited fraud-loss figure, and are a different, ongoing measurement from the single December 2020–January 2021 batch review of historical claims discussed above. ↩
- Same document, Section 5.3.4 ("TR Pondera – Next Steps"): "In January 2022, EDD worked with TR to update two primary areas, Binary Alert Enhancement and Result Based Rule Calibration, to improve the fraud detection processes. The Result[s] Based Rule Calibration ensures fewer legitimate customers are improperly impacted by the alert while maintaining the effectiveness of the alert in preventing fraud." ↩
- California Employment Development Department, Fraud Tools Assessment, Thomson Reuters/Pondera evaluation sections: EDD's statements that portions of the algorithms and business-rules documentation remained proprietary and that access would require changes to contract terms and conditions. ↩
- Same document, Sections 5.4.1–5.4.5, covering ID.me's implementation (October 2020), NIST identity-assurance alignment, wait times for supervised verification chats (reported at 75.6 minutes for January–March 2022, reduced to a reported 3 minutes after remediation), and data-retention and accessibility findings. ↩
- Yick v. Bank of America, order regarding preliminary injunction, May 17, 2021, `cases/yick-v-bank-of-america-edd/documents/CASE_CAND_3-21-cv-00376_Yick-v-BofA_doc89_ORDER-RE-PI_2021-05-17.pdf`, and preliminary injunction, June 2, 2021, `cases/yick-v-bank-of-america-edd/documents/CASE_CAND_3-21-cv-00376_Yick-v-BofA_doc103_PRELIMINARY-INJUNCTION_2021-06-02.pdf`; CFPB consent order 2022-CFPB-0004, July 14, 2022, Source document ($100 million penalty), and OCC civil money penalty order AA-ENF-2022-22, July 14, 2022, Source document ($125 million). Penalties total $225 million; consumer redress is additional, and the bank consented to both orders without admitting or denying the findings. ↩
Primary sources used in this article
- California Legislative Analyst's Office, "The 2022-23 Budget: Assessing Proposals to Address Unemployment Insurance Fraud", February 15, 2022 (updated May 16, 2024)
- Thomson Reuters, "Thomson Reuters Acquires Pondera Solutions", March 19, 2020
- California Employment Development Department, Fraud Tools Assessment (prepared under Assembly Bill 138)
- Electronic Privacy Information Center, "Screening and Scoring Spotlight: Pondera's Fraud Prediction Algorithms for Public Benefits"