Sorry, I pasted the wrong link for [1], which describes how 18F thought facial recognition was racist, so it simply did not implement it for high-security accounts despite being required by spec, and falsely assured agencies that it was in compliance anyway. It is here:
https://www.gsaig.gov/content/gsa-misled-customers-logingovs...
The executive summary says: "Our evaluation found GSA misled their customer agencies when GSA failed to communicate Login.gov’s known noncompliance with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, Digital Identity Guidelines. Notwithstanding GSA officials’ assertions that Login.gov met SP 800-63-3 Identity Assurance Level 2 (IAL2) requirements, Login.gov has never included a physical or biometric comparison for its customer agencies. Further, GSA continued to mislead customer agencies even after GSA suspended efforts to meet SP 800-63-3. GSA knowingly billed IAL2 customer agencies over $10 million for services, including alleged IAL2 services that did not meet IAL2 standards. Furthermore, GSA used misleading language to secure additional funds for Login.gov."