> It's hard to game, simple to apply and trivial to verify (once you issue SSN you check with IRS once a year if they are really paid what the company said it will pay). And if companies try some fraud they are now in the business of tax fraud.
This is one of the areas where it may be easier to game - at least until the people committing the fraud have gained a bit, shut down the business, and moved on (at least for the smaller instances - larger consultancies would have more difficulty but they game in other ways).
Government agencies are notoriously siloed and often have laws preventing all but the most limited data exchange between agencies.
Consider https://krebsonsecurity.com/2017/03/student-aid-tool-held-ke...
The IRS Data Retrieval Tool isn't "send data from IRS to DoEd" but rather "send data to the individual who then sends it to DoEd".
The exchange of data between agencies is specified in Information Exchange Agreement
https://www.cms.gov/about-cms/information-systems/privacy/da...
https://www.ssa.gov/dataexchange/documents/IEA(F)%20State%20...
https://home.treasury.gov/policy-issues/tax-policy/tax-infor...
https://www.hhs.gov/guidance/sites/default/files/hhs-guidanc...
The referenced privacy act: https://home.treasury.gov/footer/privacy-act
This leads to it being easier for each department to establish its own set of data (so it doesn't need to go through the difficulty of having an IEA with all of that additional bureaucracy and since there's more than enough work for for underfunded agencies working with data that you don't have gets deprioritized) ... and such fraud is likely easier to do or takes many years to raise up enough discrepancies to merit further investigation by qualified investigators.