
I watched an insurer check who someone was at the login screen, then hand them a blank form asking the same thing. It has bothered me ever since.
You know the feeling. You sign in — password, code to your phone, the whole ritual — and the first box waiting asks for your account number.
The Insight: Asking Isn't Always Collecting
European public administration has a principle for this, once-only: give the state something once and it reuses it rather than asking again. It's in Estonian statute and EU law for cross-border public services — nowhere near a private insurer. Borrowing it for one is my move, not the law's.
But it names what the private sector rarely says aloud. Asking for what you already hold isn't inefficiency. It's a decision about whose time is cheaper — and when the data turns out wrong, whose mistake it was. Usually one nobody remembers making.
Moynihan, Herd and Harvey call it compliance cost, and note that burdens look "minor and defensible when designed by the administrator" but "dramatic" when experienced by citizens. They're describing governments and the people who need them; a filing process makes the same choice, more quietly. My own name for this version: re-asking is redundant authentication. Redundant when the form asks to know what the login already proved, not when it asks to check you're still you.
Real-World Lens
A form I couldn't unsee
On an insurance project, filing a request meant completing a PDF, logging into your online account, and sending the form back as a secure message. Everyone doing this was already authenticated. The form still asked for account details the system held. What struck me wasn't the duplication, but that the login had already answered the question the form was about to ask — and it asked anyway. The effort didn't vanish; it moved onto the customer, where nobody measured it. Which tells you who the form was built for: the side that counts its own costs.
Estonia stopped asking parents anything

Since October 2019, Estonian parents don't apply for family benefits. When a birth is registered, the state assembles what it holds, works out eligibility, and produces a pre-filled offer. The parent logs in, reads it, amends what needs amending; the login is the signature. The money doesn't simply appear: someone still confirms — and that, not the data-sharing, is the safeguard when it's a person who'd know.
Under the Hood
Here's where I nearly wrote something wrong.
The obvious fix is to pre-fill the box. The UK's official earnings survey is filled in by employers, about their staff, never by the employee. But it carried pre-filled work addresses apparently never corrected. People at large multi-site firms looked like they travel some 12 km further to work than other workers. Nobody can recover the true figure; that's the point. Silent pre-filling doesn't remove error. It hides it in data that looks clean.
So the fix isn't less asking — it's a different question. The most accurate design, tested against administrative records, showed people what was on file and asked five words: "Is that still the case?" In a survey, at least. India's central bank writes the same rule: if nothing has changed a self-declaration "is sufficient," but fresh documents once those on file expire.
The move | What you meet | What it produces |
|---|---|---|
Silent assumption | Nothing — it acts on what it holds | Decisions made on unchecked data |
Silent discard | A blank box for what it already verified | Your time, spent on its filing |
Explicit confirmation | The value it holds, and a question | Accurate data — and a statement you made |
That last row isn't free. Under consumer insurance law, failing to correct details you were asked to check can count as a misrepresentation. One ombudsman decision cut a stolen-car claim to 80% over a residency answer nobody thought to re-ask. Not that a blank form is safer: fill one in fresh and every line becomes something you asserted.
Confirmation doesn't create that risk; it makes it quiet. Confirm the few things a decision turns on — a long list gets ticked, not read — and re-collect only what's expired, superseded, or never yours to hold.
The login had already answered the question the form was about to ask.
So What?
Two issues ago I argued the opposite: an insurer trusted the email address on file, never checked it, and around 30% of its customers heard nothing. Same defect — the record a service holds and your view of it never meet in one place — but different repairs. That one reached people who were never logged in. This one happens inside a session, where showing the value would have been easy.
So when a form wants what it should already know: are they asking you, or checking with you?
Reply and tell me: what's the most redundant thing a service has asked you for after you'd already logged in?
Next Wednesday: Can I just speak to someone? — the chatbot that won't hand over, the help page that loops, the number that isn't on the site. Who a service protects when it makes a human hard to reach.
Forwarded this? The Listening Loop pulls apart one invisible piece of service design every Wednesday.
See you next week.
Go deeper: Deploying the Once-Only Policy: A Privacy-Enhancing Guide (Harvard Ash Center, 2020) — useful because it argues against itself, worrying openly that joined-up government data could concentrate and increase state power.
Sources:
