SNAP payment error detection: how Elastic helps US states beat the FY2028 penalty

The US Supplemental Nutrition Assistance Program (SNAP) served 41.7 million people across 22.2 million households and moved $100.3 billion in federal spending in FY2024. Starting in federal fiscal year 2028, payment errors on that scale stop being a compliance metric and become a budget line item. Under the One Big Beautiful Bill Act (Public Law 119-21), states at or above a 6% payment error rate must fund a share of benefit costs themselves, rising to 15% at or above 10%. 

FY2025 and FY2026 performance sets each state's starting tier, making the next year and a half the window that matters. For a state spending hundreds of millions a year on SNAP, a 10% error rate pulls tens of millions from the budget annually, and it's not hypothetical: the national rate hit 10.93% in FY2024, with 44 states filing corrective action plans. Elastic's answer is detection built into the same platform that already indexes the case data, not a bolted-on system. The clock is running.

Why SNAP payment errors happen: Eligibility mistakes vs. fraud

Payment errors come from two different places, and eligibility systems built around periodic batch reviews only surface one of them.

Eligibility mistakes happen when caseworkers make honest calls under time pressure, working from policy manuals hundreds of pages long. A missed income exclusion looks identical to fraud on an audit report, but it's a search problem, not an integrity problem.

Fraud and abuse are different. A case correctly approved at intake has since drifted: Income has grown past the threshold, an address is churning across counties, or an identity shows up on more than one open case. Nobody is watching for that drift at scale, because most systems only check eligibility at determination, not continuously. That's not just an assumption: The Government Accountability Office reported in 2025 that USDA's Food and Nutrition Service hasn't comprehensively assessed what theft-prevention measures states even use, so there's no verified baseline for who's watching.

Overnight batch rules engines catch some of this after the fact: A case gets flagged, and someone eventually reviews it. That's necessary but not sufficient. It's reactive, and "the rules engine flagged it" isn't always a satisfying answer to "how do you actually know this is fraud?"

How Elastic detects SNAP fraud: 3 layers of detection

Detecting SNAP fraud requires more than a single tool. It requires a layered approach: one where rules catch what agencies already know to look for, machine learning surfaces what rules miss, and conversational investigation helps analysts act on what the data reveals. Elastic delivers all three on a single platform.

Layer 1: Customizable detection rules

Detection starts with patterns agencies already understand and can codify as threshold-based rules tailored to their programs and policies: income above a household-size threshold, a benefit amount exceeding the published maximum, or a case missing required documentation. For SNAP, this includes real-time enrichment at ingest: As each case is indexed, an ingest pipeline checks income against the state's published limit table and tags the case before it reaches a caseworker, with each flag carrying a documented reason tied to policy, not a hardcoded value.

Layer 2: Advanced detection with machine learning

Rules catch what agencies know to look for. Machine learning finds what rules miss: behavioral drift with no fixed threshold, such as income growing past eligibility over time, an address cycling across counties, or claim activity that's statistically anomalous against an entity's own history. Elastic's machine learning, both unsupervised and supervised, runs continuously against case data instead of a periodic report, giving analysts a single source of truth instead of individual signals scattered across disconnected systems.

Layer 3: Conversational investigation

Rules and machine learning identify patterns; investigators determine what those patterns mean. Elastic Agent Builder gives fraud analysts a conversational interface to the case data, no spreadsheets or complex queries required. An investigator can ask why a case was flagged, compare it against related records, and get a recommendation on next steps. It uses a validated compound key, not a single-field match, so a search for shared identities returns corroborated matches, not coincidental ones, and closes with "this pattern warrants review," not an accusation.

Underneath all three layers is the same foundation: unified access across wage records, income verification feeds, enrollment history, and case notes that were never built to share data, plus entity resolution that surfaces likely duplicate households before a determination is made.

Why real-time fraud detection outperforms batch detection

Most fraud detection tools are reactive: Collect data, run a job, surface results hours or days later. By then, a payment may already be out the door.

Elastic runs all three layers in real time instead. Detection rules fire the moment a case is indexed, not on a batch schedule. Machine learning scores behavioral drift continuously, not in an overnight report. Conversational investigation gives analysts immediate access to any flag, without waiting on a query to be built.

That matters for FY2028. States are measured on a payment error rate that accumulates continuously, not a single annual snapshot, and fraud caught eventually still counts as an error if it was paid out first. A platform that detects at every layer, not just the last one, gives program integrity teams a defensible answer throughout.

For agencies weighing where to focus over the next 18 months: Can your platform catch an error before it becomes part of the error rate? Agencies that want to see this running against their own eligibility data, not a generic demo, can start a conversation with Elastic's public sector team.

Frequently asked questions

Is SNAP payment error mostly a fraud problem or a data problem?

Both, but they require different fixes. Eligibility mistakes happen when caseworkers make honest calls against policy manuals that are hundreds of pages long. Fraud and abuse happen when a correctly approved case drifts over time, such as income growth or address churn that nobody is watching for.

How does Elastic detect SNAP fraud differently from a traditional rules engine?

Elastic layers three detection methods on the same case data: customizable detection rules that tag cases automatically at ingest, machine learning that catches behavioral drift no fixed rule can express, and conversational investigation through Elastic Agent Builder for analysts to verify and act on what the data shows. Some fraud signals get caught the moment a case is written rather than in a later batch job.

Can ingest-time detection catch every type of SNAP fraud?

No. Ingest-time tagging only works for rules answerable from a single case's own fields, like income against a household-size threshold. Cross-document patterns and behavioral anomalies with no fixed threshold require machine learning or conversational investigation instead.

Learn more about how Elastic supports state and local government.