The Person Was the Same. The Matching Rules Weren’t.
Identity matching looks like a data problem until two systems receive the same data and reach different conclusions.
A 2026 Social Security Administration Office of the Inspector General review of SSA’s Numident verification systems makes that problem visible at extraordinary scale. SSA maintains thousands of data-exchange agreements with federal, state, and other partners. Four Numident verification systems processed billions of transactions between fiscal years 2021 and 2025, with roughly 1.3 billion resulting in nonmatches.
OIG found examples in which automated systems rejected incoming identity information because of relatively small discrepancies even though manual criteria—or criteria used by another SSA verification system—would have accepted the same information.
The person did not change.
The institutional relationship between the records did.
Identity Is a Relationship Decision
A name, date of birth, Social Security number, address, or other identifier is evidence about identity. None of those values alone is the person.
An institution decides whether two sets of evidence refer to the same entity by applying rules: exact-match requirements, tolerances, corroborating attributes, risk thresholds, exception procedures, and contextual constraints.
That makes entity resolution a governed relationship.
If two systems apply different matching logic without an explicit institutional reason, the same person can occupy contradictory institutional states at the same time.
The Topology Break Occurs Between Evidence and Context
GovKM represents institutional work through:
Source → Evidence → Authority → Context → Decision → Action → Record → Institutional Memory → Future Reuse.
In identity verification, external identity attributes arrive as Source and Evidence. Matching criteria establish the Context under which the institution decides whether the evidence represents an existing identity.
If those criteria differ across systems, then:
same Evidence → different Context → different Decision.
The resulting records can each be internally consistent while being institutionally inconsistent.
Consistency Does Not Mean One Universal Threshold
Continuity does not require every identity system to use one rigid matching algorithm.
A high-risk financial transaction may legitimately require stronger evidence than a low-risk informational lookup. A manual adjudication workflow may appropriately consider evidence that an automated service does not.
The requirement is that differences be governed and reconstructable.
The institution should be able to explain why this system uses this threshold, which risk model supports it, when the criteria were approved, how exceptions are handled, and what happens when another system reaches a conflicting identity conclusion.
AI Can Hide the Difference Rather Than Fix It
Probabilistic identity matching can improve recall, recognize spelling variation, and reason over more attributes than traditional exact-match systems.
But replacing explicit deterministic rules with a model does not remove the governance requirement. It increases the need for lineage.
If an AI system says two records belong to the same person, the institution should still be able to establish which evidence was considered, which authority permits that degree of confidence, what threshold applied, and how the decision can be challenged or re-evaluated.
A model score is not identity. It is evidence supporting an institutional identity decision.
Conflicting Identity States Propagate
Identity decisions rarely remain isolated. They influence eligibility, payment, access, fraud detection, record linkage, correspondence, and downstream analytics.
A false nonmatch can fragment one person into multiple institutional representations. A false match can merge different people into one representation. Either error can then propagate into later records and future AI retrieval.
Continuity therefore requires a path for conflict resolution, correction, and downstream requalification when an identity decision changes.
The GovKM Proposition
Identity is not a field value. It is a governed relationship among evidence, matching criteria, authority, and context.
An enterprise does not have identity continuity merely because every system stores identifiers. It has identity continuity when those systems can explain and reconcile why they treat records as representing the same—or different—entities.
The person may be the same.
The institution must make sure its matching rules know why.



