IRS knowledge-based authentication requirements apply whenever a taxpayer electronically signs Form 8879 or Form 8878 remotely: the tax software must verify the taxpayer’s identity through questions drawn from their credit file, allow no more than three attempts, and record a specific audit trail for every signing event. If the taxpayer fails, the e-signature option is locked and a handwritten signature is required. Electronic Return Originators who skip these steps face sanctions up to expulsion from e-file.
When KBA Is Triggered
The requirement attaches to remote e-signature transactions on IRS authorization forms. That means Form 8879, the e-file Signature Authorization for individual returns, and Form 8878, the equivalent authorization used for filing extensions like Form 4868.1Internal Revenue Service. About Form 8878, IRS e-file Signature Authorization Before the software accepts the signature, it runs an identity check.
A credit reporting company generates the questions in real time from non-public data in the taxpayer’s credit report. These are not the security questions the taxpayer set up themselves. They ask about things like previous addresses, the type of loan held with a particular lender, or other details specific to that person’s records, and they arrive in multiple-choice format.2Internal Revenue Service. Frequently Asked Questions for IRS e-file Signature Authorization
The pull is a soft inquiry. It doesn’t affect the taxpayer’s credit score, and it isn’t a credit check in the lending sense.
The Three-Attempt Limit
The taxpayer gets up to three tries. After three failed attempts, the software locks the e-signature option, and there is no override.2Internal Revenue Service. Frequently Asked Questions for IRS e-file Signature Authorization At that point the ERO has to collect a handwritten signature on the authorization form. The return itself can still be e-filed; only the signature method changes.
The In-Person Exception
KBA is a remote-transaction rule. If the taxpayer electronically signs while physically present in the ERO’s office and has a multi-year business relationship with that ERO, no further identity verification is needed. A multi-year relationship, in this context, means the ERO prepared the taxpayer’s return in a prior year and already ran them through KBA at that time.2Internal Revenue Service. Frequently Asked Questions for IRS e-file Signature Authorization New clients signing in person still need to go through identity verification.
Records the ERO Must Keep
Every e-signature event, whether the taxpayer passes or fails, has to generate an audit trail captured automatically by the software. The IRS requires these data elements for each event:
- A digital image of the signed authorization form.
- The date and time the signature was captured.
- The taxpayer’s computer IP address (remote transactions only).
- The taxpayer’s login identification or username (remote transactions only).
- The result of the identity verification, successful or not.
- The method used to sign the record, such as a typed name or a system log reflecting completion of the process.
The ERO is responsible for storing these records securely.2Internal Revenue Service. Frequently Asked Questions for IRS e-file Signature Authorization If the IRS reviews your e-file operation and these records aren’t there, the compliance problem is yours. This is on top of the broader obligation, under IRS Publication 4557, to maintain a written information security plan for client data.3Internal Revenue Service. Publication 4557 – Safeguarding Taxpayer Data
What to Do When the Taxpayer Cannot Pass
Some taxpayers cannot pass KBA no matter how careful they are. Young adults with no credit history, recent immigrants, older taxpayers who have been off the credit grid for years, and anyone with a frozen credit report all produce the same result: the system doesn’t have enough data to build meaningful questions. Nothing is wrong with the taxpayer’s identity; the data just isn’t there.
When KBA fails or cannot be completed, the taxpayer signs the authorization form by hand. That form can be returned to the ERO in person, by U.S. mail, private delivery service, fax, email, or through an internet portal.2Internal Revenue Service. Frequently Asked Questions for IRS e-file Signature Authorization Practices that serve populations with thin credit histories should treat handwritten signature collection as a routine step rather than an exception.
Sanctions for Non-Compliance
The IRS uses a tiered sanction structure for e-file violations:
- Level One covers violations with little or no impact on return quality or the e-file program. The IRS may issue a written reprimand.
- Level Two covers violations with an adverse impact on return quality or the program. The IRS may restrict e-file participation or suspend the provider, principal, or responsible official for one year.
- Level Three covers violations with a significant adverse impact. The IRS may suspend the provider for two years, or in cases involving fraud or criminal conduct, expel the provider from e-file indefinitely.
Repeated Level Two or Level Three behavior, further infractions after the IRS has already flagged the issue, a felony conviction, identity theft involvement, or fraud can all push a sanction up to permanent expulsion.4Internal Revenue Service. IRM 8.7.13 e-file Cases For a preparation business, losing e-file privileges is close to a shutdown, since most individual returns are now filed electronically.
What KBA Costs the Preparer
KBA carries a per-attempt fee that the tax professional pays. Third-party verification vendors charge each time a taxpayer tries to answer the questions, whether the attempt succeeds or fails. Fees of roughly $1 to $2 per attempt are common across tax software platforms. In a busy practice the math moves fast: a married couple filing jointly means two signers, and one failed first attempt by one spouse means three verification charges on a single return.
Merging documents into a single signing event, such as combining state and federal returns, keeps each signer to one KBA pass. Firms serving clients with thin credit files should plan for a higher failure rate, the additional per-attempt charges that come with it, and the administrative time of collecting handwritten signatures as a fallback.
Where the Standard May Be Heading
The IRS ties e-file identity verification to the National Institute of Standards and Technology Special Publication 800-63, targeting Identity Assurance Level 2 for remote transactions.5National Institute of Standards and Technology. SP 800-63A Implementation Resources – IAL2 Remote Identity Proofing NIST itself has since stepped back from KBA. In the current version of SP 800-63, NIST states that knowledge-based authentication “is no longer recognized as an acceptable authenticator” and that knowledge-based verification “cannot be used to satisfy the verification requirements for IAL2 or IAL3 in identity proofing,” on the reasoning that attackers can too easily discover the answers.6National Institute of Standards and Technology. NIST SP 800-63 Digital Identity Guidelines – FAQ
The IRS still requires KBA for e-file signature authorization. That gap between NIST guidance and current IRS practice is worth watching, since the IRS has already moved its online account tools to a document-and-biometric verification model through ID.me and could eventually change the e-signature standard as well. For now, KBA is the operative rule for Forms 8879 and 8878.
A Note on IRS Online Account Verification
The identity questions you may encounter when logging into an IRS online account are a separate system. The IRS uses ID.me, a third-party provider, for services including Online Account access, Get Transcript, Online Payment Agreements, and Identity Protection PIN retrieval, and that verification relies on government-issued ID and a selfie rather than credit-file questions.7Internal Revenue Service. New Identity Verification Process to Access Certain IRS Online Tools and Services The KBA requirements described above apply only to e-file signature authorization.