24.3 Public Benefit Disbursements: EBT and Reloadable Debit Cards
Key Takeaways
- Robust disbursement internal controls enforce separation of duties across procurement, receiving, voucher entry, and payment release, automated three-way matching, tolerance thresholds, and post-payment recovery audits to eliminate duplicate payments.
- Public benefit disbursements utilize Electronic Benefit Transfer (EBT) and reloadable debit cards governed by Quest network operating rules, biometric verification, and chip technology to ensure secure delivery of social assistance.
- Public disbursement architectures rely on Electronic Funds Transfer (EFT), distinguishing between low-cost batch processing via the Automated Clearing House (ACH) and immediate, irrevocable real-time gross settlement via Fedwire.
Public Benefit Disbursements: EBT and Reloadable Debit Cards
Governments administer massive public assistance transfer programs—including the Supplemental Nutrition Assistance Program (SNAP), Temporary Assistance for Needy Families (TANF), Women, Infants, and Children (WIC), and State Unemployment Insurance (UI). Historically distributed via physical food stamp paper coupons or paper benefit checks, these programs suffered from massive coupon trafficking, physical theft, check-cashing fee gouging by predatory lenders, and slow emergency delivery.
Electronic Benefit Transfer (EBT) Framework
Today, public assistance is administered electronically nationwide through Electronic Benefit Transfer (EBT):
- The Quest Operating Network: EBT programs operate under standardized national operating rules established by the Quest Network (administered by the National Automated Clearing House Association / NACHA). This ensures that an EBT card issued in one state functions seamlessly across retail grocery point-of-sale terminals nationwide.
- Account Segmentation: A single plastic card with a magnetic stripe and smart EMV chip accesses separate underlying benefit accounts (e.g., SNAP funds can only be spent on authorized food items at USDA Food and Nutrition Service approved retailers; TANF funds can be withdrawn as cash at ATMs or spent on general living necessities).
- Security Protocols: Transactions require a four-digit personal identification number (PIN) selected by the recipient. Modern programs are integrating smart chip technology and biometrics to eliminate card-skimming fraud at unmonitored retail terminals.
Prepaid Reloadable Debit Cards for Emergency and Specialized Relief
During natural disasters (e.g., FEMA disaster relief distributions) or temporary emergency programs (e.g., pandemic economic stimulus or municipal direct assistance), governments partner with financial institutions to issue prepaid reloadable debit cards:
- Allows the immediate, remote electronic loading of funds to displaced or unbanked citizens who lack commercial checking accounts.
- Eliminates the vulnerability of checks being stolen from destroyed postal mailboxes.
- Enforces programmatic spending rules, enabling governments to restrict card usage geographically or by merchant category (e.g., building supplies, lodging, and groceries).
Accounts Payable Disbursement Controls and Three-Way Matching
Accounts payable operations represent the final protective barrier against improper public payments. Under federal standards (e.g., the Payment Integrity Information Act of 2019 [PIIA], 31 U.S.C. § 3351) and the GAO Green Book, entities must maintain rigorous expenditure internal controls.
Strict Segregation of Duties Across the Procurement-to-Payment Lifecycle
To eliminate the opportunity for an employee to create a fictitious vendor, submit a fraudulent invoice, and divert public funds, the expenditure cycle must enforce strict functional segregation among four independent operational roles:
+---------------------------------------------------------------------------------------------------+
| ACCOUNTS PAYABLE SEGREGATION OF DUTIES LIFECYCLE |
+----------------------------+----------------------------------------------------------------------+
| OPERATIONAL ROLE | MANDATED RESPONSIBILITIES & ACCESS RESTRICTIONS |
+----------------------------+----------------------------------------------------------------------+
| 1. PURCHASING / | • Verifies budget appropriation; solicits competitive quotes. |
| REQUISITIONING | • Issues official Purchase Order (PO) to approved vendor. |
| | • CANNOT receive physical goods or enter vendor invoices. |
+----------------------------+----------------------------------------------------------------------+
| 2. RECEIVING & | • Physical warehouse/receiving dock inspects delivered goods. |
| INSPECTION | • Counts physical units; verifies condition against packing slip. |
| | • Files electronic Receiving Report (Goods Receipt). |
| | • CANNOT issue POs, enter invoices, or access disbursement checks. |
+----------------------------+----------------------------------------------------------------------+
| 3. ACCOUNTS PAYABLE | • Receives vendor invoice directly from vendor. |
| VOUCHER ENTRY | • Performs automated Three-Way Match (PO, Receiving Report, Invoice)|
| | • Verifies clerical accuracy and records liability in ledger. |
| | • CANNOT create vendors, hold physical cash, or sign/release checks.|
+----------------------------+----------------------------------------------------------------------+
| 4. TREASURY DISBURSEMENT | • Authorizes release of payment batch (ACH, Fedwire, check printing)|
| RELEASE & CUSTODY | • Maintains custody of digital signature keys and check stock. |
| | • Transmits payment files to bank via secure encrypted portal. |
| | • CANNOT approve vouchers, alter vendor data, or reconcile accounts.|
+----------------------------+----------------------------------------------------------------------+
The Automated Three-Way Match Architecture
The absolute cornerstone of accounts payable internal control is the Three-Way Match. Prior to approving any commercial invoice for payment, the automated financial management system must electronically match and reconcile three independent source documents:
- The Purchase Order (PO): Originating from the Purchasing Department, establishing that the acquisition was legally authorized, within budget, contracted at agreed-upon unit prices, and subject to formal municipal procurement terms.
- The Receiving Report (Goods Receipt Note): Originating from the Receiving Dock or field inspector, certifying that the goods or services were physically received, inspected, verified for acceptable condition, and counted for quantity.
- The Vendor Invoice: Originating externally from the commercial vendor, demanding payment and detailing quantities billed, agreed unit pricing, freight charges, and remittance bank details.
+---------------------------------------------------------------------------------------------------+
| THE AUTOMATED THREE-WAY MATCH ARCHITECTURE |
+---------------------------------------------------------------------------------------------------+
| |
| [PURCHASE ORDER] [RECEIVING REPORT] [VENDOR INVOICE] |
| • Authorized Unit Price • Actual Delivered Quantity • Billed Unit Price |
| • Authorized Total Quantity • Inspection / Quality Acceptance • Billed Quantity |
| • Payment Terms • Delivery Date • Remittance Bank Info |
| \ | / |
| \ | / |
| v v v |
| +-----------------------------------------------------------------------------+ |
| | ENTERPRISE ERP THREE-WAY MATCHING ALGORITHM | |
| | | |
| | 1. Does Billed Quantity (Invoice) = Delivered Quantity (Receiving Report)?| |
| | 2. Does Billed Unit Price (Invoice) = Contracted Unit Price (PO)? | |
| | 3. Does Total Delivered Quantity ≤ Total Authorized Quantity (PO)? | |
| +-----------------------------------------------------------------------------+ |
| | |
| +-----------------------+-----------------------+ |
| | | |
| [ALL DATA MATCHES] [PRICE / QTY VARIANCE] |
| | | |
| v v |
| System Generates Approved System Places MATCHING HOLD |
| Disbursement Voucher Alerts Purchasing & AP Supervisor |
| Queued for Treasury Release Payment Blocked until Formal Change Order |
+---------------------------------------------------------------------------------------------------+
System Tolerance Thresholds
Enterprise ERP systems implement automated tolerance thresholds to balance rigorous control against operational bottlenecks:
- Price Tolerances: Most governments enforce a 0% price increase tolerance. If the vendor bills $102.00 per unit for an item contracted on the PO at $100.00, the system automatically flags a price variance and places the invoice on a "matching hold," blocking payment until the purchasing agent negotiates a corrected invoice or issues a formal, approved change order.
- Quantity Tolerances: For bulk commodities (such as asphalt, gravel, road salt, or heating fuel), slight delivery variances are unavoidable due to scale differences or moisture content. Systems typically allow a minor quantity tolerance (e.g., ±1% to 2%) within established budgetary ceilings.
Post-Payment Recovery Audits and Duplicate Disbursement Detection
Even in governments equipped with modern ERP systems, improper disbursements occur. Common systemic vulnerabilities include vendors inadvertently submitting identical invoices twice (e.g., an electronic PDF followed by a paper billing), departments entering duplicate vouchers under slightly different vendor profiles, or invoices paid via P-Card being subsequently keyed into accounts payable for check processing.
Forensic Data Analytics for Duplicate Payment Detection
Internal auditors and accounts payable supervisors deploy specialized forensic data analytics to screen 100% of historical disbursements for improper duplicates. Forensic algorithms evaluate two levels of matching:
- Exact Matching: Identifies payments sharing the identical Vendor Taxpayer Identification Number (TIN), identical invoice number, identical invoice amount, and identical or near-identical payment date.
- Fuzzy Logic Matching: Detects sophisticated or accidental duplicates where invoice numbers or vendor details were slightly altered during data entry:
- Punctuation and Whitespace Discrepancies: Matches
INV-89102withINV89102orINV 89102. - Transposed Digits: Matches
INV-12345withINV-12435sharing identical dollar amounts and delivery dates. - Vendor Suffix and Trailing Character Variations: Detects identical billings submitted with an added suffix, such as
Invoice 5501andInvoice 5501-A. - Alternate Vendor Master Profiles: Identifies different vendor ID numbers in the master file that share identical bank routing and account numbers, identical physical street addresses, or identical federal EINs.
- Punctuation and Whitespace Discrepancies: Matches
Recovery Audit Contracting (RAC)
Under federal statutes (including the Improper Payments Elimination and Recovery Act [IPERA] and OMB Circular A-123) and state statutory recovery mandates, public entities engage third-party Recovery Audit Contractors (RACs):
- Contingency Fee Structure: RAC firms are compensated purely on a contingency basis, receiving a negotiated percentage (typically 10% to 25%) of the actual cash recovered, requiring zero upfront public budget expenditure.
- Scope of Audit: RAC auditors analyze historical general ledger accounts payable files, vendor statements, and contract files spanning multiple prior fiscal years to identify:
- Unclaimed vendor credit memos resulting from returned goods or over-shipments.
- Duplicate vendor disbursements never repaid.
- Erroneous payments of sales and use taxes (from which public entities are legally exempt).
- Volume rebate discounts earned under master contracts but never credited by suppliers.
- All recovered cash net of the contingency fee is restored directly to the respective public funds.
Practical Public Finance Scenario: Electronic Disbursement & P-Card Fraud Audit
Scenario: During an annual operational control review of a regional transportation authority, the Chief Internal Auditor analyzes a random sample of disbursements executed during the preceding fiscal year. The audit uncovers four disturbing operational patterns:
- A facilities maintenance foreman possessed a P-Card with a $2,500 single-transaction limit. Over a three-day weekend, the card recorded four separate transactions of $2,450, $2,400, $2,490, and $2,475 at a regional heavy equipment supply dealer for a single industrial commercial lawn tractor priced at $9,815.
- The authority suffered a $165,000 unauthorized cash withdrawal from its primary operating checking account resulting from an external fraudulent ACH debit initiated by an unknown online entity using the authority's published bank routing and account numbers.
- An accounts payable clerk keyed an invoice for $48,000 for specialized track replacement bolts. When the system halted the voucher because no receiving report existed in the database, the clerk overrode the system hold using a supervisor's shared password, releasing an ACH payment. Two weeks later, the physical bolts arrived, and the vendor submitted a second invoice that was matched against the real receiving report and paid again.
- Monthly P-Card statements revealed multiple charges totaling $3,800 at upscale dining restaurants and luxury luggage retailers. The charges were approved by an approving official who admitted to "rubber-stamping" statements without looking at attached receipts because the cardholder was a senior executive.
Professional Auditor Assessment & Remediation Strategy
- Sanction Transaction Splitting (Item 1):
- The four transactions represent an unequivocal, deliberate instance of transaction splitting executed to evade the $2,500 single-transaction P-Card limit and bypass formal competitive bidding for capital equipment exceeding the micro-purchase threshold.
- Remediation: The foreman's P-Card must be revoked immediately. The matter must be referred to human resources and legal counsel for formal disciplinary and potential criminal investigation. The equipment acquisition must be reviewed by central procurement.
- Deploy ACH Fraud Controls (Item 2):
- Operating accounts must never be left exposed to unrestricted external debits. The bank failed to enforce basic municipal safeguards.
- Remediation: The finance director must immediately instruct the depository bank to place an ironclad ACH Block on the operating account, prohibiting all incoming debits. If specific recurring debits are legally required, they must be shifted to an account protected by an ACH Debit Filter that strictly limits debits to pre-authorized Originator IDs with established dollar ceilings. The authority's legal counsel must file an immediate formal claim under NACHA rules to recover the unauthorized debit.
- Enforce Three-Way Matching and Segregation of Duties (Item 3):
- Bypassing the receiving report requirement represents a critical failure of the Three-Way Match, enabling a duplicate payment of $48,000.
- Remediation: Revoke shared administrative passwords, mandate individual biometric or hardware multi-factor authentication for all system overrides, and configure the ERP software so that only the Director of Finance can authorize an override of a matching hold. Implement automated duplicate payment fuzzy-matching analytics. Demand an immediate $48,000 refund from the bolt vendor for the duplicate disbursement.
- Restructure Supervisory Review and Approving Official Accountability (Item 4):
- Approving Officials who execute rubber-stamp approvals without inspecting itemized receipts compromise the entire P-Card control framework.
- Remediation: Update the P-Card policy to explicitly establish joint and several personal financial liability for approving officials who approve unauthorized non-business expenses without verifying itemized receipts. Mandate immediate payroll deduction or personal reimbursement from the senior executive for the unallowable dining and luxury luggage expenses. Block restaurant and luxury retail Merchant Category Codes (MCCs) across all administrative cards.
In a municipal accounts payable internal control system, what is the primary purpose of executing an automated 'Three-Way Match' before releasing payment on a commercial vendor invoice?