KBA and Form 8879: When the IRS Requires It
The IRS requires knowledge-based authentication when a client e-signs Form 8879 remotely. Here is when KBA applies, when it does not, and what to do instead.
By Rashad Bayram | Published: 7/30/2026
The short answer: If a client electronically signs Form 8879 or 8878 while you are not physically present, the IRS requires knowledge-based authentication: an identity quiz generated from the client's credit record. That rule comes from IRS Publication 1345 , and skipping it makes the remote e-signature non-compliant. It does not apply in three cases: an in-person e-signature, where you inspect photo ID instead; an in-person signature for a client you already have a multi-year business relationship with; and a handwritten signature the client returns to you by mail, fax, email or upload. Note that the multi-year exception is an in-person rule only. There is no long-standing-client carve-out for remote e-signing. Knowledge-based authentication is the step that trips up more remote filing seasons than any other, usually because nobody realised it was required until a client could not get past it. It is worth understanding precisely, because the rule is narrower than it first appears, and the ways around it are entirely legitimate. What KBA actually is Knowledge-based authentication asks the taxpayer a short set of multiple-choice questions that only they should be able to answer, generated on the fly from their credit file and public records. Which of these streets have you lived on. Which lender held this auto loan. What was the monthly payment range on a mortgage you closed six years ago. The taxpayer is not being asked to remember a password they set. They are being asked to confirm facts about their own financial history, which is why the check is called knowledge-based. Publication 1345 sets the standard: identity verification must be "in accordance with National Institute of Standards and Technology, Special Publication 800-63, Electronic Authentication Guideline, Level 2 assurance level and knowledge-based authentication or higher assurance level." The record check is typically run through a credit reporting company, which generates the questions from the client's credit report. Note the "or higher assurance level" clause, because it means KBA is the floor rather than the only permitted method. Note too that the IRS cites SP 800-63 without a revision number, and the "Electronic Authentication Guideline" title with a single "Level 2" assurance level belongs to the older revisions (SP 800-63-1 and -2 ). From revision 3 onward the suite replaced that single scale with separate identity, authenticator and federation assurance levels, and the current SP 800-63-4 , published July 2025, keeps that model. You will not find a "Level 2" in it. When the IRS requires it The trigger is a remote transaction . Publication 1345 defines that as one "in which the taxpayer is electronically signing the form and the ERO isn't physically present with the taxpayer." For those, the ERO must record the taxpayer's name, Social Security number, address and date of birth, and verify that this information is consistent with what comes back from "record checks with the applicable agency or institution or through credit bureaus or similar databases." In practice that is KBA. This applies to both e-file signature authorizations. If you are not sure which one you are collecting, the difference between Form 8878 and Form 8879 is worth a minute. The three cases where it does not apply KBA is not required in three situations: an in-person electronic signature, an in-person signature for a client you already have a multi-year business relationship with, and a handwritten signature returned to you by mail, fax, email or upload. 1. In-person electronic signatures. If you are physically present while the client signs, you inspect a valid government photo ID, compare the photo to the person, and record the name, SSN (or ITIN), address and date of birth. Publication 1345 is explicit that for in-person transactions "the identity verification through a record check is optional." No quiz required. 2. A multi-year business relationship. For in-person signing, you do not have to re-confirm identity at all if you already have a multi-year business relationship, defined as having originated tax returns for that taxpayer in a prior tax year and identified them using the verification process at that time. Be careful with this one. It lives entirely inside Publication 1345's in-person section. The remote-transaction rules contain no equivalent, so a client of fifteen years signing remotely still needs the record check. A long relationship shortens your in-person process; it does not exempt anyone from KBA when they sign from their kitchen table. 3. A handwritten signature returned to you. This is the exclusion most preparers do not know exists, and it is stated directly in Publication 1345: "An electronic signature via remote transaction does not include handwritten signatures on Forms 8878 or 8879 sent to the ERO by hand delivery, U.S. mail, private delivery service, fax, email or an Internet website." Read that carefully. If the client prints the 8879, signs it by hand, and sends the scan back through your portal, that is not a remote electronic signature transaction. The electronic-signature identity verification rules, KBA included, do not govern it. That is not a loophole. It is the IRS drawing a line between an electronic signature, which is a signature created inside a software process the IRS wants standards for, and a handwritten signature that merely travels electronically. Your professional obligation to know your client does not disappear, and you still keep the signed form. But you are not obliged to run a credit-record quiz on a client who signed with a pen. The distinction turns on where the pen stroke happened, and it is easy to get wrong. Publication 1345's list of acceptable electronic signature methods includes "a handwritten signature, mark or command input on a display screen by a stylus device" and "a digitized image of a handwritten signature that is attached to an electronic record." So a client who draws their signature on screen with a finger, stylus or mouse inside your portal has produced an electronic signature, and if you were not in the room, that is a remote transaction requiring KBA. A client who prints the form, signs the paper with an actual pen, and uploads the scan has not produced an electronic signature via remote transaction , which is the category the KBA rule attaches to. The two look almost identical to the client and are treated completely differently by the rule, so be explicit in your instructions about which one you are asking for. What you have to record when it is an electronic signature These requirements attach to electronic signature transactions. If you took route 3 above and the client wet-signed on paper, none of it applies to that signature, because it was never an electronic signature transaction. You still keep the signed form and, per Publication 1345, Forms 8878 and 8879 must be kept for three years from the return due date or the IRS received date, whichever is later. For an actual electronic signature, Publication 1345 requires the signing software to capture: A digital image of the signed form The date and time of the signature The taxpayer's IP address (remote transactions only) The taxpayer's login username (remote transactions only) The identity verification result: passed KBA, or for in-person, confirmation that government photo ID was checked The method used to sign, a system log, or another audit trail of the signing The ERO must be able to hand all of that to the IRS on request. Signatures must also be linked to their records so they cannot be excised or copied onto a different document, and the record must be tamper-proof once signed. When a client fails the quiz If the client fails three attempts, the software must lock identity verification and Publication 1345 requires you to obtain a handwritten signature on the 8878 or 8879 instead. There is no appeal and no fourth try. Plan for it, because failures are frequently nothing to do with fraud. A young client with a thin credit file, a recent immigrant, someone who has frozen their credit, or a client who genuinely cannot remember a car payment from 2019 will all struggle. Warning clients before you send the request, and having the wet-signature fallback ready, turns a filing-season emergency into a five-minute detour. Two things worth telling clients up front. First, the record check may create a "soft inquiry" on their credit report. Soft inquiries are not credit applications and, as a matter of general credit-reporting practice, are not used in scoring by FICO or VantageScore. Publication 1345 itself makes no such finding, and note the verb it uses: the software should carry an advisory explaining the use of third-party data, how that data is used, whether a soft inquiry will be generated and "the effect, if any, on the credit report, credit scores and reporting to lenders," and how the inquiry may appear on the report. It should also advise that the IRS is not given access to the credit report and that the credit reporting company is not given access to the tax data. Those advisories sit on Publication 1345's "should" list for software developers, unlike the three-attempt lockout, which is on the "must" list. Second, the check needs no extra paperwork from them. Publication 1345 states plainly that identity verification via a record check "does not require additional consents from the taxpayer beyond those obtained for preparing and filing their taxes; nor does it violate the provisions of Internal Revenue Code section 7216 or its regulations." The contrast with Canada If your practice spans both countries, do not assume the processes match. They do not. The CRA does not require knowledge-based authentication for an electronically signed T183. It expects you to be satisfied of the client's identity, the signature to carry a date and time stamp down to the second, and the form to be retained for six years, but it prescribes no identity-quiz technology. The full picture is in the T183 electronic signature rules . Do not read that as "Canada has no rule," though, because the CRA substitutes a channel control where the IRS uses an identity control. Where the signature is not applied in person, the CRA requires the signed form to reach the other party either using "the electronic address most recently provided to the other party for that purpose," or through "an access controlled, secured electronic location, such as a secure website, that is accessible to the individual only because the other party has made that location known and granted access to the individual." So a Canadian preparer exchanging a T183 over an address the client happened to mention once is not compliant either, because that is not an address provided for that purpose . The requirement is lighter on identity proofing and stricter on the channel. Build two workflows, not one. Where Taxformify fits I build Taxformify , so here is the honest boundary. Taxformify does not perform knowledge-based authentication. It has no credit-bureau integration and does not run an identity quiz. That means you should not use it to collect a remotely e-signed US Form 8879 or 8878, because that specific transaction is exactly the one the IRS requires KBA for. What it is built for, within these rules: Canadian T183 and T183CORP signatures , where no KBA requirement exists, the secure portal is designed to meet the CRA's access-controlled delivery condition, and the signing record with its date, timestamp and verifiable certificate is what the CRA cares about 8879s the client prints, signs with an actual pen, and uploads back , which Publication 1345 excludes from the remote electronic signature definition, with the reminders that stop the form sitting in someone's inbox for three weeks. To be precise, because the distinction matters: this is the wet-ink-then-scan route. A signature drawn on screen with a finger or stylus is an electronic signature and would need KBA. In-person 8879 signing , where photo ID replaces the quiz Engagement letters, consent forms and organizers , none of which carry the 8879 identity rule at all If you need remote electronic 8879 signatures at volume, you need a signing provider with KBA or higher-assurance identity proofing built in. I would rather tell you that than have you discover it during a file review. If the Canadian side or the document chase is your bottleneck, book a short demo and I will show you the flow on a real form. I am not a CPA, and neither is my co-founder, though he runs a tax practice with over 1,500 clients. Everything above is drawn from Publication 1345 itself, linked below, and this is general information rather than tax or legal advice. IRS requirements change; confirm the current publication for the year you are filing. Frequently Asked Questions What is knowledge-based authentication (KBA) in tax? KBA is an identity check in which the taxpayer answers multiple-choice questions generated from their credit report or other public records, such as a previous address or the lender on an old car loan. In tax practice it is the method the IRS points to for confirming who is on the other end of the screen when a client electronically signs Form 8878 or 8879 without the preparer physically present. Does Form 8879 require KBA? Only when the client electronically signs it remotely, meaning the ERO is not physically present. IRS Publication 1345 requires identity verification for those transactions at NIST SP 800-63 Level 2 assurance with knowledge-based authentication or higher. If the client e-signs in your office, or returns a handwritten signature by another route, the KBA rule does not govern that transaction. When is KBA not required for Form 8879? Three situations. First, an in-person electronic signature, where you inspect government photo identification instead and a record check is optional. Second, an in-person signature where you already have a multi-year business relationship, meaning you originated returns for that taxpayer in a prior year and verified their identity then. Third, a handwritten signature returned to you by mail, fax, email, hand delivery or a website, which Publication 1345 explicitly excludes from the definition of a remote electronic signature transaction. Does a wet signature emailed or uploaded back to me require KBA? No. Publication 1345 states that an electronic signature via remote transaction does not include handwritten signatures on Forms 8878 or 8879 sent to the ERO by hand delivery, U.S. mail, private delivery service, fax, email or an internet website. The client printing the form, signing it by hand, and returning the scan is therefore not a remote electronic signature transaction, so the electronic-signature identity verification rules do not apply to it. Your ordinary professional duty to know your client still does. What happens if my client fails the KBA questions? The software must disable identity verification after three attempts. If the taxpayer fails after three tries, Publication 1345 requires the ERO to obtain a handwritten signature on Form 8878 or 8879 instead. There is no fourth attempt and no override, so it is worth warning clients in advance that a thin or frozen credit file can cause a failure that has nothing to do with them being who they say they are. Does KBA affect my client's credit score? The record check may create a soft inquiry on the credit report. Soft inquiries are not credit applications and, as general credit-reporting practice, are not used in FICO or VantageScore calculations. Publication 1345 does not itself rule on the effect. It says the signing software should carry an advisory covering how third-party data is used, whether a soft inquiry will be generated, its effect if any on the report, scores and reporting to lenders, and how it may appear, along with an advisory that the IRS gets no access to the credit report. What records must I keep for an e-signed 8879? The software must record a digital image of the signed form, the date and time of the signature, the taxpayer's IP address and login username for remote transactions, the identity verification result (passed KBA, or confirmation that photo identification was checked in person), and the method used to sign or an audit trail of the signing. The ERO must be able to produce all of it to the IRS on request. Disclaimer This article is for general informational purposes and is not tax advice. Tax laws change frequently and individual situations vary. TaxFormify does not provide tax advice. Consult a licensed CPA or enrolled agent for guidance on your specific circumstances. Further reading Form 8878 vs 8879: Which IRS e-File Authorization Do You Need? : which authorization you are actually collecting. T183 Electronic Signature: The CRA Rules : the Canadian equivalent, and why it is simpler. Tax Workflow Automation: A Day in the Life : where the signature step sits in the wider filing-season workflow. Stop Chasing Clients for Tax Documents : the bottleneck that usually precedes the signature. Sources IRS Publication 1345, Handbook for Authorized IRS e-file Providers of Individual Income Tax Returns (PDF) , Rev. 12-2025, the electronic signature and identity verification requirements. Every quotation above is from this document. IRS, About Form 8879, IRS e-file Signature Authorization IRS, About Form 8878, IRS e-file Authorization for Form 4868 or Form 2350 NIST Special Publication 800-63-2, Electronic Authentication Guideline , the older revision whose "Level 2" framing the Publication 1345 language matches, and the current SP 800-63-4 that superseded it CRA, Using electronic signatures , for the Canadian contrast CRA, Forms T183 and T1013 , the six-year T183 retention rule