Compliance September 8, 2026 7 min read

IRS Publication 1345 Explained for Preparers

Most preparers meet IRS Publication 1345 sideways. A signing tool insists on an identity check before the client can open Form 8879, or a colleague mentions that some record has to be kept for three years and another only until the end of the year, and somewhere behind both of those is a handbook nobody has read cover to cover. This article walks through the parts of Publication 1345 that come up in ordinary practice — remote signatures, identity verification, what happens when the verification fails, and how long each record has to be kept.

This is general educational information for tax professionals, not legal or tax advice. Publication 1345 is revised periodically. For authoritative requirements, refer to the current edition of IRS Publication 1345 and IRS e-file signature guidance, and consult your own compliance resources.

What Publication 1345 Is

Publication 1345 is the IRS's Handbook for Authorized IRS e-file Providers of Individual Income Tax Returns. It is the rulebook for participating in IRS e-file: what an Authorized e-file Provider is expected to do, how returns are submitted, and — the part that shows up most in day-to-day practice — what counts as an acceptable signature on the e-file signature authorization forms.

It is worth understanding that the handbook sets requirements, not implementations. Two firms can have signing workflows that look nothing alike and both be entirely consistent with Publication 1345, because it describes what must be true, not which software makes it true. If you want the short definition rather than the walkthrough, we keep one in the glossary entry for Publication 1345.

Who It Applies To

The role the handbook is written around is the Electronic Return Originator — the ERO. If you originate the electronic submission of a return you prepared or collected, you are the ERO for that return, and the obligations in the handbook are yours. For a solo preparer that is simply "you"; in a firm it is the entity that holds the EFIN, with the practical work distributed across whoever handles signatures and transmission. If the EFIN part is still ahead of you, our guide to what an EFIN is and how to get one covers that step.

Signatures: In Person Versus Remote

The handbook draws a line that governs nearly everything else about e-signing: whether the transaction is in person or remote.

When the taxpayer is physically in front of you, the handbook has the ERO review government-issued photo identification and record the identifying details from it. When the taxpayer signs remotely, you cannot do either of those things, so Publication 1345 requires the ERO to verify identity through an accepted electronic method before the signature is valid.

This is the reason a compliant remote 8879 signature is not the same thing as emailing a PDF and receiving one back. The signature is only part of it; the identity verification is the requirement that has to be satisfied alongside it.

What Identity Verification Means for a Remote Signer

For remote transactions, Publication 1345 requires the ERO to verify the taxpayer's identity using knowledge-based authentication — the handbook references NIST SP 800-63 level 2 assurance — or a method at a higher assurance level.

Knowledge-based authentication, usually shortened to KBA, asks the signer a short set of "out-of-wallet" questions generated from public and credit-history records: previous addresses, an old auto loan, a name associated with a prior mortgage. It has been the traditional method for years, and it works well when the underlying data about a person is rich and current. Our explainer on knowledge-based authentication goes into how the questions are generated and where the method tends to break down.

The requirement can also be satisfied by verification at a higher assurance level. The handbook sets the assurance bar rather than naming a product, so more than one method can clear it. One method preparers use to meet a higher assurance level is document-and-selfie identity proofing: the signer photographs a government-issued photo ID and takes a live selfie that is matched against it, through a service that meets NIST Identity Assurance Level 2. It asks the signer for something they have rather than something they remember, which is why it tends to be the more workable path for clients whose public records are thin — young filers, recent arrivals, people who have not carried consumer debt.

What Happens When KBA Fails

This is the rule most preparers do not know until they hit it, and it is worth knowing before a client is sitting in a failed quiz in the last days before a filing deadline. Under Publication 1345, if the taxpayer fails knowledge-based authentication after three attempts, the ERO must obtain a handwritten signature on the applicable signature authorization form — Form 8878 or Form 8879.

So the failure path is not "try a different question set" or "call the client and confirm verbally." It is a handwritten signature. Practically, that means your workflow needs a fallback that does not depend on the client passing a quiz: an in-person appointment, or a printed form signed by hand and returned. Firms that discover this on the last weekend before the deadline tend to discover it the hard way, and the fix is simply to plan the fallback in advance rather than improvise it.

The Multi-Year Relationship Allowance Is In-Person Only

There is a well-known allowance connected to a multi-year business relationship, and it is very commonly misremembered as "I have known this client for years, so I do not need to verify them again." That is not what the handbook says. The multi-year business relationship allowance applies to in-person transactions.

For remote transactions, there is no long-standing-client exception. Identity verification is required for the remote signing, each time, regardless of how many seasons the client has been with you. Treat prior-year verification as exactly that — a prior year's record — and verify the current one on its own terms.

This is the single most useful thing to get right in a signing workflow, because it is the one where a well-intentioned shortcut looks entirely reasonable from the inside. Our practical guide to e-signing Form 8879 remotely covers how this plays out in an actual signing sequence.

Record Retention: Two Different Clocks

Retention is the other area where the handbook is more specific than the folklore around it, and the important thing to know is that not everything is on the same clock.

Form 8879 is kept for three years from the return due date or the date the IRS received the return, whichever is later. That is the long clock, and it is the one most preparers have heard of.

The other e-file materials are kept until the end of the calendar year. Publication 1345 puts Form 8453 and the documents that go with it, copies of Forms W-2, W-2G, and 1099-R, the taxpayer consents, the copy of the return, and the acknowledgment file on that shorter clock.

The mistake worth avoiding is generalizing the three-year rule across the whole file, or generalizing the calendar-year rule down onto the 8879. They are separate requirements attached to separate materials, and the practical answer for most firms is to keep the signature authorization somewhere durable and organized by year, rather than mixed in with the working papers it arrived alongside.

Building a Workflow That Matches the Handbook

None of this requires a compliance department. It requires a signing process where the right thing is the default:

  1. Verification happens inside the signing flow, so the document does not unlock until identity has been established — rather than as a separate step someone can skip when the day is busy.
  2. Every remote signature gets verified, with no exception path for long-standing clients, because there is not one for remote transactions.
  3. A handwritten fallback exists on paper before the season starts, for the three-failed-attempt case.
  4. The audit trail is stored with the document — the verification result, the timestamps, and the signed form together, not in three systems.
  5. Retention is organized by the clock that applies, with the 8879s kept where you can produce them three years later.

Publication 1345 sits alongside the other security obligations a practice carries, notably the written information security plan the FTC and IRS expect — see our guide to WISP requirements for that side. If you want to see how one system handles the encryption and audit trail behind a signing flow, our security page lays it out, and the product tour shows where signing sits in the wider workflow.

The Bottom Line

Publication 1345 is the handbook behind rules preparers usually meet one at a time. For remote signatures it requires identity verification by knowledge-based authentication at NIST SP 800-63 level 2 assurance or a higher assurance level; after three failed KBA attempts it requires a handwritten signature on Form 8878 or 8879; the multi-year business relationship allowance is for in-person transactions only; and retention runs on two clocks — three years for Form 8879, end of the calendar year for Form 8453 and its documents, W-2, W-2G and 1099-R copies, consents, the return copy, and the acknowledgment file. Build those five facts into the workflow and the handbook mostly takes care of itself.

Get the next guide in your inbox

One practical guide at a time — written by the founder, a working tax preparer. No spam, no drip sequence.

Unsubscribe anytime. We never share your email.

Identity verification built into signing

Choose the identity rung per envelope, up to government ID and selfie at NIST IAL2 — no separate signing subscription. Free for up to 3 clients; e-signature from $29/mo.

Try FinishTax Free →