PT-8: Computer Matching Requirements

PT-08 requires federal agencies to follow a structured approval and notification process before running any computerized comparison of

Quick-reference card

FieldValue
Control IDPT-08
Control NameComputer Matching Requirements
FrameworkNIST SP 800-53 Revision 5
Control FamilyPersonally Identifiable Information Processing and Transparency
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityLow

What this control requires

PT-08 requires federal agencies to follow a structured approval and notification process before running any computerized comparison of records across Privacy Act systems. You can’t match records from two or more automated systems to determine benefit eligibility, verify payments, or identify delinquent debts without first getting your Data Integrity Board’s sign-off and entering into a formal computer matching agreement.

Beyond the matching activity itself, the control extends to the investigative follow-up and any resulting adverse action. Before you act against an individual based on matching results, you must independently verify the match output and give the affected person both notice and a chance to contest the findings. This requirement exists because automated record comparisons can produce false positives that, without verification, could wrongly deny benefits or trigger collection actions against the wrong individuals.

The scope here is broader than most practitioners initially assume. A “matching program” under NIST SP 800-53 isn’t limited to the technical comparison. It covers the full lifecycle from board approval through published Federal Register notices to individual due process protections. Missing any step in that chain creates a compliance gap that auditors will flag.

Why it matters

Organizations that skip or fail to complete the PT-08 requirements face direct regulatory exposure under the Computer Matching and Privacy Protection Act, the set of amendments to the Privacy Act of 1974 that established these controls. The risk isn’t hypothetical data loss. It’s an audit finding that your matching program operated without proper authorization, without published notice, or without individual due process protections, undermining your posture across the broader PII Processing and Transparency family.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings from oversight bodies including the Office of Management and Budget. For agencies processing federal benefit determinations, a non-compliant matching program can also invalidate the results of the match, forcing the agency to redo the entire process with proper approvals in place.

The consequences compound when adverse actions are taken without independent verification of matching results. Individuals who are denied benefits or subjected to debt recovery based on unverified automated matches have grounds to challenge those actions, and the agency’s legal position weakens significantly without documented compliance with PT-08’s procedural safeguards. Privacy oversight bodies specifically look for gaps between the matching activity and the procedural protections that should surround it.

What auditors flag

  • No documented Data Integrity Board approval prior to initiating matching activities
  • Computer matching agreements that are expired, incomplete, or missing required statutory provisions
  • Missing or late Federal Register matching notices
  • Adverse actions taken against individuals without independent verification of match results
  • No evidence that individuals received notice and an opportunity to contest findings before adverse action

How to implement

For your organization

The core challenge with PT-08 isn’t technical complexity. It’s procedural completeness. Most compliance gaps arise because agencies treat computer matching as an IT function when it’s fundamentally a governance process with legal, privacy, and operational components that must align before any matching activity begins.

Step 1: Establish or engage your Data Integrity Board. If your agency doesn’t already have one, the Privacy Act requires it for any matching program. The board must include senior agency officials and serves as the gatekeeper for all matching activities. Document the board’s charter, membership, and meeting procedures.

Step 2: Define the matching program scope. Before seeking board approval, document exactly which systems of records will be compared, the purpose of the comparison (benefit eligibility, payment verification, or debt recovery), the data elements involved, and the retention period for matched records. This scoping document becomes part of your approval package.

Step 3: Develop the computer matching agreement. The agreement must comply with Section 552a(o) of the Privacy Act and include the purpose and legal authority for the match, a description of the records to be matched, procedures for individual notice and contest rights, and data security safeguards. Both the source and recipient agencies must sign the agreement before any matching begins.

Step 4: Publish the Federal Register notice. The matching notice must describe the matching program in sufficient detail for public understanding. Allow the required comment period before proceeding with the match. A vendor risk assessment process should also evaluate any non-federal agencies involved in the matching program.

Step 5: Build the independent verification process. Design a verification workflow that confirms matching results through a source independent of the original match before any adverse action is taken. Document who performs verification, what constitutes adequate verification, and how exceptions are handled.

Step 6: Implement individual notice and contest procedures. Create templates for notifying individuals of adverse findings and establish a formal process for receiving and adjudicating contests. Set clear timelines for each step and assign responsibility to specific roles.

Common mistakes to avoid:

  • Treating the Data Integrity Board as a rubber stamp rather than an active oversight body
  • Allowing matching agreements to expire without renewal while matching activities continue
  • Conflating the Federal Register notice requirement with other Privacy Act publication requirements
  • Initiating adverse action before the verification and contest period has closed
  • Failing to document the chain of custody for matched records throughout the lifecycle

Organizations managing third-party compliance requirements should ensure that any non-federal agencies involved in matching programs meet the same procedural standards.

Evidence examples

Evidence TypeExample Artifact
Policy and proceduresPII processing and transparency policy defining roles, approval workflows, and matching program lifecycle requirements
Board authorizationData Integrity Board determination records including meeting minutes, vote outcomes, and conditions of approval for each matching program
Matching agreementsSigned computer matching agreements specifying data elements, legal authority, security safeguards, and individual rights provisions
Federal Register noticesPublished matching notices with proof of publication dates and public comment period documentation
Individual notification recordsTemplates and logs of notices sent to individuals before adverse action, including contest opportunity communications
Verification documentationIndependent verification procedures and records demonstrating match results were confirmed before adverse action
Supporting agreementsMemoranda of understanding, information sharing agreements, and contracts with non-federal agencies participating in matching programs
Privacy planningPrivacy plan sections addressing computer matching requirements, system of records notices, and applicable governing requirements

Cross-framework mapping

No cross-framework mappings have been configured for PT-08. This control is specific to the NIST SP 800-53 privacy baseline and derives from the Computer Matching and Privacy Protection Act amendments to the Privacy Act of 1974.

  • PM-24 — Data Integrity Board: Establishes the governance body responsible for approving and overseeing matching programs, making it the prerequisite control for PT-08 compliance

Frequently asked questions

What is NIST SP 800-53 PT-08?

PT-08 is the NIST SP 800-53 control that requires organizations to obtain Data Integrity Board approval, establish formal matching agreements, publish Federal Register notices, and protect individual due process rights before conducting computerized comparisons of Privacy Act records. The control applies specifically to federal benefit matching programs and federal personnel or payroll record comparisons. It addresses the full matching lifecycle, not just the technical record comparison itself.

What happens if PT-08 is not implemented?

Non-compliance with PT-08 means your matching program operates without the statutory safeguards required by the Computer Matching and Privacy Protection Act, exposing the agency to regulatory findings and potential legal challenges from affected individuals. Adverse actions taken without independent verification of matching results are particularly vulnerable to reversal. Auditors from oversight bodies will flag missing Data Integrity Board approvals and expired computer matching agreements as material findings that require remediation.

How do you audit PT-08?

Auditing PT-08 starts with verifying that a current Data Integrity Board determination exists for each active matching program and that signed computer matching agreements haven’t expired. Review Federal Register notices to confirm they were published before matching activities began and contain the required program descriptions. Examine individual notification records to verify that affected persons received notice and a contest opportunity before any adverse action, and confirm that independent verification procedures produced documented results for each match that led to action.

What is a computer matching program under the Privacy Act?

A computer matching program is a computerized comparison of records from two or more automated Privacy Act systems of records, or between a federal system and records maintained by a non-federal agency. These programs specifically pertain to determining or verifying eligibility for federal benefit payments, recouping payments, or identifying delinquent debts under federal benefit programs. The definition encompasses not just the technical matching activity but also the investigative follow-up and any ultimate adverse action taken based on matching results, which is why GDPR and similar privacy frameworks impose analogous protections for automated decision-making.

Experience superior visibility and a simpler approach to cyber risk management