A pay and chase model creates exposure because it prioritises speed over verification. Once a refund is issued, the agency must recover funds after the fact, which is much harder when criminals use stolen identities or altered forms. If pre payment controls are weak, attackers can exploit the system at scale before audits and reconciliation detect the loss.
Why the model is so attractive to fraudsters
A pay and chase refund model is exposed because it is designed to release money before every claim is fully verified. That creates a large, fast-moving target: once a refund is paid, the agency is no longer preventing loss, it is trying to recover it. The fraud incentive rises sharply when the attacker can submit many claims cheaply and the control gap is only discovered later.
The core weakness is timing. Fraudsters do not need to defeat a perfect system, they only need to get through the initial screening layer. If the refund process treats speed as the default and verification as a later step, then stolen identities, fabricated deductions, and altered supporting documents can be monetised before human review or reconciliation catches up.
At scale, that creates a structural imbalance. Legitimate taxpayers expect fast refunds, but criminals exploit the same operational promise to create repeatable loss. For tax authorities, the issue is not simply bad claims, it is that the payout itself becomes the first point of failure, and recovery is usually more expensive, slower, and less certain than prevention.
Where the fraud exposure comes from in practice
The exposure usually concentrates in the pre-payment control chain, especially identity verification, form validation, document authenticity checks, and duplicate-claim detection. If any of those layers are weak, the refund system can be gamed with synthetic identities, stolen personal data, or manipulated submissions that look consistent enough to pass automated checks.
That risk grows when controls are fragmented across channels or business units. A fraudster can file one claim through a portal, another through a preparer, and a third through a different filing window, then rely on weak cross-checking to avoid immediate detection. The longer the authority waits to reconcile, the more opportunity the attacker has to multiply the loss.
This is why pay and chase models are often more vulnerable to organised fraud than to isolated errors. The model rewards volume and speed, so an adversary with scripts, stolen data, or professional filing networks can create many small exposures that do not look extraordinary until the aggregate loss is already material.
Risk and Threat Considerations
The main risk is not just one fraudulent refund, but the scaling effect of many small payments made before verification. Once a refund leaves the system, the authority must shift into recovery mode, which is usually weaker than the original prevention point and often complicated by fake identities, disposable accounts, or rapidly moved funds.
Failure mechanism: Weak pre-payment controls allow false claims to clear, then delayed reconciliation, poor identity confidence, or limited cross-system matching prevents timely intervention before funds are dispersed.
Impact: Losses accumulate quickly, recovery rates fall, and the agency may also create operational backlogs, taxpayer delays, and reputational damage when legitimate refunds are tightened in response to fraud.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Restricts who can approve or alter refund workflows and claim exceptions. |
| 8 — Audit Log Management | Supports detection of suspicious filing, approval, and refund patterns. | |
| 13 — Data Protection | Protects taxpayer data used to validate claims and detect fabricated filings. | |
| Recommendation — Apply Control 6 to limit refund-process access and privilege to verified operators. Use Control 8 to log refund submissions, approvals, and reversals for fraud review. Use Control 13 to safeguard claimant data used in refund verification and matching. | ||
| NIST CSF 2.0 | PR.AC — Access Control | Supports restricting and validating access to refund systems and payment actions. |
| DE.CM — Continuous Monitoring | Matches the need to spot anomalous refund patterns before losses scale. | |
| RS.MI — Mitigation | Applies to stopping ongoing refund fraud and containing repeat abuse. | |
| Recommendation — Enforce PR.AC to bound who can submit, approve, and release refunds. Implement DE.CM to monitor refund volumes, duplicates, and abnormal claim behavior. Use RS.MI to contain active fraud patterns and suspend compromised filing paths. | ||
Practitioner Guidance
What to prioritise: Treat the highest-value decision point as the pre-payment control set, not the recovery workflow. If the claim can be paid without strong identity confidence, document integrity, and duplicate detection, then the downstream chase process is absorbing risk that should have been blocked earlier.
What to verify: Check whether refund claims are being risk-scored against known fraud patterns, whether multiple filings can be linked quickly across channels, and whether exception handling creates a path for rapid payment without equivalent scrutiny. The practical question is whether the authority can stop a bad refund before disbursement, not whether it can investigate one afterwards.
Practitioner takeaway: Pay and chase becomes dangerous when speed is treated as the primary control objective. The model only works when pre-payment verification is strong enough to keep the chase stage as a backstop, not the main defence.