Skip links

IRS TIN Matching Explained: A 2026 Guide for AP Teams

IRS TIN Matching: How It Works and What It Won't Catch

Every US business that pays contractors, vendors or partners eventually meets the same problem: a name and a taxpayer identification number that do not line up in the eyes of the IRS. The IRS runs a free tool that catches this before you file — the TIN Matching Program. It is genuinely useful, it is under-used, and it is routinely mistaken for something it is not. This guide covers how the programme works, how to get access, how to read the results, what a mismatch costs in 2026, and the exact point where a TIN match stops protecting you.

The short answer

IRS TIN Matching is a free e-Services tool that lets an authorised payer check a payee's name and taxpayer identification number against IRS records before filing a Form 1099. It runs in two modes: interactive, for up to 25 name/TIN pairs at a time with results in seconds, and bulk, for up to 100,000 pairs with results returned within 24 hours. Each pair comes back as a single digit from 0 to 8. It confirms that a name and number pair exists on IRS files. It does not confirm the bank account, the company behind it, or whether the payment is safe to send.

ONE SUPPLIER PAYMENT · TWO DIFFERENT QUESTIONSTHE TAX-REPORTING QUESTIONIs this name and TIN the samecombination the IRS has on file?Answered byIRS TIN Matching (e-Services)Returns a single digit, 0 through 8.THE PAYMENT QUESTIONIs this the right bank account,and is the business real?Answered byAccount and company verificationTIN Matching answers none of this.vsA correct TIN keeps the IRS satisfied. It says nothing about where the money lands.
Figure 1 · A supplier payment raises two separate questions. TIN Matching answers only the first.
25Name/TIN pairs per interactive session
100,000Pairs per bulk file submission
24%Backup withholding rate
$340Per-return penalty, returns due 2026

Sources: IRS Publication 2108 (Rev. 11-2024); IRS Publication 1281 (Rev. 12-2023); IRS information return penalties.

Key takeaways

Access is gated by filing history. You must appear in the IRS Payer Account File, which means having filed information returns in one of the two preceding tax years. New entities cannot enrol.

Run it at onboarding, not in January. A mismatch found eleven days before the 1099 deadline, after you have already paid the vendor, is a mismatch you have no leverage to fix.

Keep dated evidence of every match. A documented match is citable as reasonable cause if a penalty is later assessed. An undocumented one is not.

A match is a tax fact, not a risk verdict. The regulations expressly bar you from using match results to decide whether to open or close an account with a payee — and a clean code 0 tells you nothing about the bank account or the company behind it.

What the IRS TIN Matching Program actually checks

The programme exists because of one mechanic in the tax code. Section 3406 of the Internal Revenue Code requires a payer to withhold income tax from a reportable payment if the payee fails to furnish a correct TIN, or if the IRS tells the payer that the TIN furnished is wrong. Withholding after the fact is expensive and awkward. Checking first is cheaper. So the IRS maintains a separate name/TIN database purely for matching, and tells participating payers whether the combination they hold is the same one the IRS has.

The authority sits in Revenue Procedure 2003-9, which expanded an earlier federal-agency programme to the wider third-party payer community. The mechanics have barely changed since. What has changed is the volume of contractor payments running through mid-market finance teams, and the cost of getting them wrong.

It is worth being precise about what is being compared. TIN Matching checks a name control — up to four characters derived from the payee's name — against the TIN. It is not a lookup service, and it is not a validity check on the number in isolation.

A TIN, for these purposes, means an identifying number assigned under IRC section 6109: an Employer Identification Number, a Social Security Number, or an Individual Taxpayer Identification Number. All are nine digits with no letters. Two format details are worth having to hand when you are triaging a failed match:

  • An ITIN always begins with 9, and its fourth and fifth digits fall within the range 70 to 88. A payee submitting a number in that shape is an individual who is not eligible for an SSN, which affects both which name you submit and how the payment should be documented.
  • An ATIN is a temporary number issued for a child adopted in the United States, in the same nine-digit format. It should not be appearing in a vendor master at all.
TermWhat it isWhere it comes from
TINUmbrella term for any identifying number assigned under IRC section 6109IRS or SSA
EINEmployer Identification Number, used by entities and by some sole proprietorsIRS, via Form SS-4
SSNSocial Security Number, used by individuals and sole proprietorsSocial Security Administration
ITINFor individuals not eligible for an SSN. Begins with 9; digits four and five fall in 70–88IRS, via Form W-7
Name controlUp to four characters derived from the payee name. This, not the full name, is what is matchedBuilt by the IRS from your submission

Which forms and payments it covers

TIN Matching is available only for income subject to backup withholding and reported on a defined set of forms. If you do not file at least one of them, you cannot enrol.

FormWhat it reportsIn scope
1099-NECNon-employee compensation — the contractor and vendor formYes
1099-MISCRents, royalties, attorney proceeds, other incomeYes
1099-KPayment card and third-party network transactionsYes
1099-INT / 1099-DIVInterest and dividendsYes
1099-B / 1099-OIDBroker and barter proceeds, original issue discountYes
1099-G / 1099-PATRCertain government payments, patronage dividendsYes
Form W-2Employee wagesNo
Form W-8 seriesForeign payeesNo

The two exclusions matter more than they look. If you want to validate employee social security numbers, that is a different system entirely — the Social Security Administration's SSNVS, not IRS e-Services. And if your payee is a foreign person or entity documented on a Form W-8, TIN Matching has nothing to offer you. For a US company paying suppliers abroad, that is most of the supply base.

Which payees look exempt but are not

Corporations are generally exempt from backup withholding, which is why many AP teams flag them out of the 1099 population entirely and never think about their TINs again. Four categories break that assumption, and payments to a corporation in any of them remain subject to backup withholding and reporting:

  • Medical and health care payments. This is why healthcare payers ask what a TIN number is "for providers" — a medical practice incorporated as a professional corporation is still in scope. Provider TIN accuracy is a reporting obligation, not an optional hygiene exercise.
  • Attorneys' fees, and gross proceeds paid to an attorney reportable under section 6045(f).
  • Payments for services made by a federal executive agency.
  • Payment card and third-party network transactions. Corporations are not exempt from backup withholding on these.

A payer also cannot treat a payee as an exempt corporation just because the name contains "Company" or "Co." The permitted grounds are narrow: a name indicating an insurance, indemnity, reinsurance or assurance company; a corporate resolution on file; a Form W-9 with an EIN and a statement of domestic corporate status; or a withholding certificate certifying foreign corporate status.

Can you do a federal tax ID reverse lookup?

Not through the IRS, and not through TIN Matching. The system requires a name and a TIN together; submit one without the other and the request returns as invalid. The IRS states plainly that it will not divulge an entity's name or TIN because of privacy obligations under IRC section 6103, and the anti-phishing lockout described below exists specifically to stop people trying to reverse-engineer one from the other.

What is genuinely available depends on what you are trying to establish:

  • If you hold the EIN and want the entity — public company filings with the SEC contain EINs, and tax-exempt organisations are searchable through the IRS Tax Exempt Organization Search. For private companies, neither route works.
  • If the payee holds the EIN and cannot find it — they can request IRS Letter 147C, which confirms the EIN assigned to them. This is the correct answer to give a vendor who says they have lost their number.
  • If you want to confirm the company itself — that is a registry question, not a tax question. State business registries, and commercial data drawn from them, give you legal name, status, incorporation date, officers and ownership. This is the layer that actually tells you whether the business is real.

Anyone selling an "IRS reverse lookup" for private companies is selling something else. Understand which of the three you actually need before you buy.

Before you match: getting the Form W-9 right

TIN Matching validates what you already hold. If what you hold came off an invoice header or an onboarding form somebody typed by hand, matching will tell you it is wrong without telling you why. The upstream control is the Form W-9, and it is the cheapest place in the whole process to fix the problem.

Three points that most AP processes get loosely and should get tightly:

  • Line 1 is the legal name, line 2 is the trading name. This is the single field that determines whether a match succeeds. If your vendor onboarding form has one "company name" box, it is generating code 3s.
  • The certification has to be signed. A W-9 collected without the Part II signature does not certify the TIN, which matters when you need to stop backup withholding — that requires a certified TIN, not a number written on an email.
  • No W-9, no exception. If a payee refuses or neglects to furnish a TIN, begin backup withholding immediately on reportable payments and run the annual solicitations. Waiting for the vendor to comply is not a neutral position; it is an accruing liability.

Electronic and substitute Forms W-9

You do not have to chase paper. Requesters may run an electronic system for collecting Forms W-9, and may build a substitute W-9 into their own onboarding forms. Both are permitted, and both carry conditions.

An electronic system must ensure the information received is what was sent, document every access that results in a submission, make it reasonably certain the person submitting is the person named on the form, provide the same information as the paper version, be able to produce a hard copy on IRS request, and require an electronic signature under penalties of perjury with the paper form's perjury language.

A substitute W-9 must be substantially similar in content and must state the certifications clearly. If a single signature line covers both the certifications and your own terms, the certification language has to be highlighted, boxed or bolded so it stands out, and this exact statement must appear immediately above the signature line: that the IRS does not require consent to any provision of the document other than the certifications required to avoid backup withholding. You may not use a substitute W-9 to make a payee agree to unrelated terms by signing.

Truncating TINs on payee statements

Under Regulations section 301.6109-4, filers may truncate a payee's TIN on most payee statements — the copy that goes to the vendor. Truncation is not permitted on any document filed with the IRS, and a payer's own TIN may never be truncated on any form. For a finance team distributing thousands of 1099s, this is a straightforward reduction in the amount of sensitive data leaving the building, and it costs nothing to switch on.

Who can use IRS TIN matching, and who gets blocked

This is where most first attempts fail, and it is rarely explained clearly.

TIN Matching is restricted to payers and their authorised agents that file information returns. To be granted access, the organisation must appear in the IRS Payer Account File. Payers are added to that file based on their filing history: the IRS describes an authorised payer as one that has filed information returns in at least one of the two preceding tax years.

The new-entity trap

A newly incorporated company, or a new legal entity created in a restructure, has no filing history. It will not be in the Payer Account File, and it cannot get TIN Matching access — no matter how carefully the application is completed. Registered agents of an ERO or e-file provider also get rejected if they are not, in fact, a payer. Plan for the lag before your first filing season, not during it.

Confidentiality and permitted use

The terms of agreement carry real weight, and compliance teams should read them before the tool is rolled out to an AP function.

  • Participants may only submit name/TIN combinations relating to accounts on which a reportable payment has been made or is likely to be made.
  • Combinations already transmitted by that participant may not be resubmitted.
  • Information obtained through TIN solicitation must be kept confidential in accordance with section 31.3406(f)-1 of the Employment Tax Regulations.
  • IRC section 6103 protects the confidentiality of TINs generally, and unauthorised use of the programme can expose the payer, its agents and its individual users to civil penalties under IRC section 7431.
  • Failure to adhere to the terms of agreement may also constitute an unauthorised disclosure under the Computer Security Act of 1987.

In practice this means TIN Matching access should be scoped to named users with a reporting reason to hold it, not opened up as a general company-lookup utility. It is also why the tool cannot substitute for a supplier due-diligence process: the permitted purpose is tax reporting, full stop.

How to apply for IRS TIN matching, step by step

The application itself is short. The identity verification around it is the slow part.

  1. Create an ID.me accountEvery user in the firm who will touch TIN Matching needs their own credential to access IRS e-Services. Do this before anything else — it is the step that stalls teams.
  2. The Principal completes the Application to TIN MatchThe Principal is a partner, an owner of at least 5% of the firm, or a corporate officer who can legally bind the firm before the IRS. Nobody else can submit the original application.
  3. Assign user rolesResponsible Official can update the application and manage users. Authorised Agent can manage users within their location. Delegated User can only run matches. Get this right or your AP team will be locked out of the tool they need.
  4. Add secondary locations if you have themUsers based at a different address to the primary location cannot be delegated until that location is established on the application.
  5. Accept the Terms of Agreement and start matchingThe IRS states that once the Principal has completed the application, users may begin using interactive or bulk TIN Matching the same day.

There is no fee. The IRS charges nothing to apply and nothing per match, and access is available around the clock apart from scheduled maintenance.

If you get stuck

Two different helplines cover two different problems, and calling the wrong one costs you a morning.

ProblemWho to callHours
Access, roles, application, error codese-Help Desk · 1-866-255-0654 (international 01-512-416-7750)Mon–Fri, 7:30am – 7:00pm ET
CP2100 notices, backup withholding, encrypted CD keysTechnical Services Operation · 1-866-455-7438 (or 304-263-8700)Mon–Fri, 8:30am – 4:30pm ET

Two common tickets have answers you can resolve yourself. If you have registered but see no TIN Matching link, the Principal has not submitted the application or has not assigned you a role. If you get Error Code 25000, the input screen has incomplete or missing fields.

Is there a TIN matching API?

Not from the IRS. This is the single most common misconception in the category, and it shapes how teams end up building.

The IRS offers exactly two access methods: a browser screen for interactive matching, and a semicolon-delimited text file uploaded to and retrieved from a secure mailbox for bulk. There is no REST endpoint, no webhook, no JSON, no sandbox and no service-level agreement. A vendor onboarding flow that needs a real-time TIN check inside the application cannot call the IRS directly.

What exists instead is a layer of commercial 1099 filing platforms — Tax1099, Track1099, TaxBandits and others — that hold their own TIN Matching authorisation as authorised agents and expose it through their own APIs and bulk tools. That is a legitimate route, and for a team already filing through one of them it is usually the least friction. Three things to check before you commit:

  • Whose authorisation is being used. An authorised agent must perform TIN Matching under the account established by the payer firm through e-Services. Confirm how the provider handles this, because the terms of agreement attach to the payer.
  • What is actually being checked. Some tools market "TIN lookup" or "TIN verification" but perform a format and checksum validation, not a match against IRS records. A nine-digit numeric string will pass a format check while being completely wrong. Ask which result codes the tool returns — if it cannot return a 0 through 8, it is not doing IRS TIN Matching.
  • Whether the evidence is retrievable. The value of a match in a penalty dispute depends on producing a legible copy of the original transaction, dated. If the provider does not retain per-payee results in an exportable form, you have paid for a check you cannot later prove.

None of these is a payment-verification tool, and none of them claims to be. They sit on the tax-reporting side of the line drawn in Figure 1.

Interactive vs bulk TIN matching

Two modes, built for two completely different jobs. Most teams need both.

INTERACTIVE VS BULK TIN MATCHINGName/TIN pairs per submission1101001K10K100KInteractive25Bulk100,000Logarithmic scale. Bulk accepts 4,000 times more pairs in a single submission.INTERACTIVEBULKResponse timein real time, about 5 secondswithin 24 hoursHow results arriveon screen, immediatelytext file to a secure mailboxInput formattyped into the browsersemicolon-delimited .txtBest used fora single vendor, right nowthe whole vendor master
Figure 2 · Interactive and bulk TIN matching are built for different jobs. Capacity shown on a logarithmic scale.
A documented inconsistency worth knowing

IRS Publication 2108 (Rev. 11-2024) states a limit of 9,999 interactive requests per user ID in a 24-hour period. The IRS TIN matching tools web page states 999. If you are designing a process around the interactive ceiling, plan against the lower figure and confirm with the e-Help Desk before you rely on it. There is no published limit on the number of bulk files you may upload in a day.

When to run it

Most teams run bulk matching in January, alongside 1099 preparation. By then it is largely too late to be useful.

FormTo the recipientTo the IRS on paperTo the IRS electronically
1099-NEC31 January31 January31 January
1099-MISC31 January28 February31 March
Most other 1099s31 January28 February31 March

Statutory dates under IRC section 6071(c). Where a date falls on a weekend or federal holiday it moves to the next business day, so confirm the exact date each season. Certain 1099-MISC boxes carry a later recipient date.

Forms 1099-NEC are due to the IRS and to recipients by 31 January. A code 3 discovered on 20 January leaves you eleven days to contact a vendor, obtain a corrected Form W-9, update the master file and resubmit — during the busiest week of the finance calendar, for a vendor with no particular incentive to reply quickly. The leverage you had is gone, because you have already paid them.

Two changes fix this, and neither is expensive:

  • Match at onboarding, before the first payment. Interactive mode exists for exactly this. A vendor who wants to be paid answers a W-9 query in a day; the same vendor in February may not answer at all.
  • Run the full bulk sweep in the autumn. October or November gives you a clear quarter to resolve mismatches while payments are still flowing and you still have something to withhold against.

Bulk TIN matching file format

The bulk input is a plain .txt file, semicolon-delimited, one record per line. There is no API and no JSON. It is worth building the export properly once, because a malformed file returns Indicator 4 for every affected line and you have burned a submission.

Bulk TIN matching · input format
TIN TYPE; TIN; NAME; ACCOUNT NUMBER (optional)

1;123456789;ACME MANUFACTURING LLC;V-10442
2;987654321;JORDAN REYES;V-10443
3;456789123;OMALLEY & SONS;

TIN TYPE  1 = EIN   2 = SSN   3 = unknown (checks both files)
NAME      1–40 characters. Hyphens and ampersands only.
          Strip commas, apostrophes, all other special characters.
ACCOUNT   optional, up to 20 characters, returned unchanged.

Three details cause most rejected files. Apostrophes must be removed rather than replaced, so O'Malley & Sons becomes OMalley & Sons. The file name itself must not contain extra dots or underscores — TIN Match Vol2.txt is accepted, TIN_Match_Vol2.txt may be rejected. And if you leave out any of the three required fields, that record returns as invalid rather than being skipped.

Results land in a secure mailbox with an email notification. You have 30 days to retrieve the file, and once you have accessed it the results are held for three days before being purged. Build the retrieval into the process rather than leaving it to whoever happens to check.

The lockout nobody warns you about

The system contains an anti-phishing control. If you submit the same TIN with several different names, or the same name with several different TINs, your access is automatically suspended for 96 hours after four attempts. Teams doing manual trial-and-error against a stubborn vendor record trip this regularly, usually in late January when they can least afford to lose four days.

IRS TIN matching result codes 0–8

Every submitted pair comes back as one digit. Only one of them means "file this and move on".

READING THE RESULT: CODES 0–80FILEName/TIN matches IRSrecords1FIXTIN missing, or not 9numeric digits2STOPTIN is not currentlyissued3STOPName and TIN do not match4FIXInvalid request (badcharacters)5FIXDuplicate request6FILEMatched on SSN only (typeunknown)7FILEMatched on EIN only (typeunknown)8FILEMatched on both SSN andEINCodes 6, 7 and 8 are matches — and a signal your vendor master has the entity type wrong.
Figure 3 · The nine result codes, grouped by the action each one requires.
CodeWhat the IRS is telling youWhat to do next
0Name/TIN combination matches IRS recordsFile. Keep dated evidence of the match — you may need it later.
1TIN missing, or not nine numeric digitsA data problem on your side. Fix the record and resubmit.
2TIN is not currently issuedThe number does not exist on IRS or SSA files. Request a fresh Form W-9 and the EIN assignment letter.
3Name and TIN do not matchMost common failure. Usually a name control problem — see below — but treat it as unresolved until proven otherwise.
4Invalid requestFormatting: alphas or special characters where they do not belong, or a missing required field.
5Duplicate requestYou have already submitted this pair. Deduplicate before the next run.
6Matched on SSN, TIN type submitted as unknownA match — and confirmation the payee is an individual or sole proprietor.
7Matched on EIN, TIN type submitted as unknownA match — and confirmation the payee is an entity.
8Matched on both SSN and EINA match. Common for sole proprietors holding both.

Codes 6, 7 and 8 are worth more attention than they usually get. They only appear when you submitted TIN type 3, unknown. Alongside the match, they tell you what the payee actually is. If your vendor master has a payee classified as a corporation — and therefore exempt from 1099 reporting — and the match comes back as code 6 on an SSN, you have a reporting gap that a code 0 would have hidden.

Why code 3 usually is not fraud

Before escalating a code 3, check the name control. The IRS builds it from specific parts of the name and the rules are unforgiving:

  • Sole proprietors must be submitted under the individual's name on line 1, even when the payment goes to a trading name and even when an EIN is used. A sole proprietor submitted only under the DBA will fail every time.
  • Partnerships derive the name control from the trade name, or failing that from the last name of the first partner on the original Form SS-4.
  • Individuals derive it from the last name; hyphenated last names use the first of the two.
  • Entities should be submitted under the legal name from line 1 of the Form SS-4 — the IRS retains prior name controls for an EIN even after a name change, so the legal name gives the best chance of a match.

The sole-proprietor rule causes more code 3s than every other cause combined, because it is the one that feels wrong. A worked example:

What you submitName line 1TINResult
What the invoice saysRiverside Design StudioEIN 12-3456789Code 3
What the IRS holdsDana WhitfieldEIN 12-3456789Code 0

Same business, same EIN, same bank account. The trading name goes on name line 2; the individual's name has to go first. A sole proprietor must never be submitted under the business name alone, whether the number supplied is an SSN or an EIN. If your AP system stores only the "vendor name" your suppliers invoice under, this failure is structural rather than occasional, and it will recur every year until the data model changes.

A marriage that was never reported to the SSA, a DBA in the name field, or an LLC that changed its legal name are the ordinary explanations behind most mismatches. That said, "usually not fraud" is not the same as "never fraud", and the difference is the subject of the second half of this guide.

What happens when you file a wrong TIN: CP2100 and B-notices

Skip the matching step and the IRS tells you about the mismatch after the fact, in the form of a CP2100 or CP2100A notice — formally, a Notice of Possible Payee TIN Discrepancy. Which version you get depends on volume:

Filer sizeError documentsWhat arrives
Large filer250 or moreEncrypted CD or DVD data file, CP2100
Mid-size filer50 to 249Paper CP2100
Small filerFewer than 50Paper CP2100A

The notice starts a clock, and the clock is measured in business days.

THE CLOCK AFTER A CP2100 NOTICEDAY 0CP2100 / CP2100Anotice received15 BUSINESS DAYSSend the “B” Noticeto the payee30 BUSINESS DAYSBegin 24% backupwithholding+30 CALENDAR DAYSStop once a certifiedW-9 is receivedThe IRS does not tell you which notice this is.Tracking whether a payee has appeared once or twice in three calendar years is the payer’s responsibility.
Figure 4 · The statutory clock that starts the day a CP2100 or CP2100A notice arrives.

The sequence, for an incorrect name/TIN combination that agrees with your own records:

  1. Within 15 business days of the notice date or receipt, whichever is later, send the payee the appropriate "B" notice. The First B Notice goes out with a blank Form W-9. The Second B Notice does not — it tells the payee to get validation from the SSA or the IRS instead.
  2. The outer envelope must be marked "IMPORTANT TAX INFORMATION ENCLOSED" or "IMPORTANT TAX RETURN DOCUMENT ENCLOSED". This is a stated requirement, not a nicety.
  3. No later than 30 business days after the notice, begin backup withholding at 24% on reportable payments to any payee who has not returned a signed Form W-9. You may start earlier if you choose.
  4. Stop within 30 calendar days of receiving the certified W-9, or, after a second notice, the payee's social security card copy or IRS Letter 147C.
  5. Remit what you withhold on Form 945, Annual Return of Withheld Federal Income Tax.

Five places payers get this wrong

Each of these is set out in IRS Publication 1281, and each one is missed regularly.

  • Tracking the two-in-three-year rule is your job. The CP2100 does not say whether a payee is on their first or second notice. If the same payee appears twice within three calendar years, the second notice requires the Second B Notice — and a new Form W-9 will not fix it.
  • A returned W-9 with the same wrong details still stops the clock. If the payee responds to a first notification by certifying the same incorrect combination, keep the form on file and do not backup withhold. Counter-intuitive, and it is the published rule.
  • A missing TIN is a different process. No B notice. Begin withholding immediately, and make the initial and up to two annual solicitations to avoid the penalty.
  • The 60-day "awaiting TIN" grace period does not cover contractors. It applies to interest, dividends and certain readily tradable instruments. Non-employee compensation is subject to backup withholding immediately.
  • The Form 945 filer EIN must match the 1099 filer EIN. Backup withholding is remitted on Form 945, on the monthly or semi-weekly deposit schedule in Publication 15. Where a group files 1099s under one entity and remits under another, the amounts do not reconcile against the information returns and the correspondence starts.

One more, because it is the expensive one: if you fail to collect backup withholding when required, you can become liable for the uncollected amount yourself. On $500,000 of contractor payments that is a $120,000 exposure attached to a data-entry error.

What not to do: corrected returns

The instinct on discovering a wrong TIN is to file a corrected 1099. In most cases that is the wrong move, and Publication 1281 says so repeatedly: do not file a corrected information return unless you are also changing a dollar amount reported on the form. Update your records, use the correct information on future returns, and do not send the correction to the IRS.

Three related instructions follow the same logic. If you reported information incorrectly, correct your records and do not send a B notice. If the information changed after you filed, use it going forward and do not send a B notice. If the IRS misprinted your information, note it and take no action. And if you inadvertently omitted a TIN that you did hold, do not contact the payee — just include it next time.

Writing to the IRS about corrections it did not ask for generates correspondence, not credit.

State backup withholding

Federal backup withholding is not the whole obligation. Several states apply their own layer on top, keyed to the federal trigger, and the withholding agent carries the liability.

California is the clearest example. Under Revenue and Taxation Code section 18664, reportable payments are subject to state backup withholding at 7% where federal backup withholding is required, with limited exceptions for interest and dividends and for the release of loan funds by a financial institution. There are no reductions or waivers for backup withholding — unlike nonresident withholding, which the Franchise Tax Board can reduce on request. Section 18668 makes the withholding agent liable for amounts not withheld, under-withheld, or not remitted.

The practical effect is that a single unresolved code 3 on a California vendor can create a 31% combined withholding obligation, remitted to two different authorities on two different schedules. If your vendor base spans states, check each one's rule rather than assuming the federal answer is the whole answer.

Solicitation: the paperwork that actually protects you

A solicitation is a documented request to a payee for their correct TIN. It is the mechanism the regulations give you for avoiding a penalty on a return you already know is wrong, and it is the first thing the IRS looks for when a penalty is disputed. The rules differ depending on whether the TIN is missing or incorrect.

SituationInitialFirst annualSecond annual
Missing TINWhen the account is opened or the transaction occursBy 31 December of the year the account is opened (31 January following, for December accounts)By 31 December of the following year, if still not furnished
Incorrect TINNot applicable — you already hold a TINThe B notice sent within 15 business days of the first CP2100 or CP2100AWithin 15 business days of a second CP2100 or CP2100A in a later year

Two practical points. Sending a B notice in response to a CP2100 satisfies the annual solicitation requirement — you do not need to do both. And where you receive a proposed penalty notice without a CP2100, the annual solicitation must be made by 31 December of the year you received it, unless you already sent a B notice that year. No annual solicitation is required in a year in which you made no reportable payments to that payee.

What a wrong TIN costs in 2026

Filing an information return with an incorrect TIN is a failure under IRC section 6721. Furnishing the payee statement with the same incorrect TIN is a separate failure under section 6722. In practice most incorrect-TIN failures are charged twice.

COST OF A WRONG TIN · PENALTY PER INFORMATION RETURN, RETURNS DUE 2026$0$200$400$600$60Corrected within30 days$130Corrected byAugust 1$340After Aug 1,or not filed$680Intentionaldisregard500mismatchedreturns$170,000in penalties atthe $340 tierA separate penalty applies to the payee statement, so most failures are charged twice.Annual caps apply, and are lower for small businesses. Intentional disregard has no cap.
Figure 5 · Per-return penalties under IRC section 6721 for returns due in 2026.

The per-return amounts escalate with how long the failure goes uncorrected. For returns due in 2026, the IRS sets them at $60 if corrected within 30 days, $130 if corrected by 1 August, and $340 after 1 August or not at all. Intentional disregard carries $680 per return — or 10% of the amount that should have been reported correctly, if that is greater — and no annual maximum. Annual caps apply to the first three tiers and are lower for businesses with average annual gross receipts of $5 million or less.

Amounts apply to returns required to be filed in calendar year 2026 and are adjusted for inflation annually. Confirm the current figures on the IRS information return penalties page before relying on them.

Three rules that change the arithmetic

The headline numbers overstate exposure in most real cases, because three provisions cut in before the bill arrives.

  • One penalty per return. No more than one section 6721 penalty applies to a single information return even where there are several failures on it. A return filed late and with an incorrect TIN attracts the higher of the two amounts, not both.
  • The de minimis exception. Where a return was filed, the information was incorrect, and the failure is corrected on or before 1 August, the return is treated as having been filed correctly. The number of returns this can cover in a year is capped at the greater of 10 or one-half of one per cent of the total information returns you were required to file. For a business filing 4,000 returns, that is 20 free corrections a year — but only if you find them before August.
  • Order of operations. The IRS applies any reasonable-cause waiver first, and the de minimis exception then applies to whatever incorrect returns remain. Arguing reasonable cause well makes the de minimis allowance stretch further.

One provision cuts the other way. The electronic filing threshold dropped to 10 aggregate information returns for returns required to be filed on or after 1 January 2024. Where e-filing is required and returns are filed on paper instead, that is a separate failure — and a proposed penalty for it can arrive on the same notice as the TIN penalties.

Notice 972CG: the bill for last year

Where a CP2100 is a warning, Notice 972CG is a proposed penalty. It arrives after the matching cycle has run, lists the payee records at issue, and proposes penalties under section 6721. Publication 1586 accompanies it, and where the listing runs beyond 250 payee records the IRS supplies it on CD rather than paper.

You have 45 days from the date of the notice to respond — 60 days for filers overseas. An extension has to be requested in writing and must arrive before the deadline expires. If you do not respond, the penalties are assessed as proposed and the balance-due notices follow.

There is no first-time abatement here

First Time Abate covers failure to file, failure to pay and failure to deposit. It does not cover information return penalties. Relief under sections 6721 and 6722 runs through reasonable cause only, under Treasury Regulation 301.6724-1 and Publication 1586 — which means the response has to show significant mitigating factors or events beyond your control, and that you acted responsibly both before and after the failure. "We did not know" is not in that framework. "Here is our dated TIN match, our solicitation record and our remediation" is.

Using a TIN match as reasonable cause

This is the strongest practical argument for running the programme, and it is buried in Publication 2108.

Section 6724 lets the IRS waive section 6721 and 6722 penalties where the failure was due to reasonable cause and not wilful neglect — the detailed rules sit in Treasury Regulation 301.6724-1 and, in plain English, in IRS Publication 1586. A participating payer may cite a name/TIN match as reasonable cause. The IRS will consider a waiver where the payer provides a legible copy of the original match transaction for the combination on which the penalty was assessed, the penalty was assessed after the date of that match, and the abatement is requested in writing citing the use of the programme.

The operational consequence

The match result is only worth as much as your evidence of it. Store the dated result for every payee — the code, the exact name and TIN submitted, and the date — alongside the vendor record. A screenshot filed nowhere is not a defence. Note also that choosing not to participate in TIN Matching cannot be used against you: the regulations state the IRS will not treat non-participation as evidence that a payer lacked reasonable cause.

The vendor file you inherited

An acquisition transfers the vendor master, and with it every unmatched TIN, every stale bank record and every unresolved B notice sitting in the acquired entity's files. Those errors become yours at completion, and the first CP2100 arrives without regard to who created them.

Two things follow. First, errors discovered after an acquisition are a recognised reasonable-cause argument — a response that sets out the acquisition timeline, when the errors were found and what remediation followed is materially stronger than one that does not mention it. Second, and more usefully, this is a diligence item. A bulk TIN match across the target's vendor master before completion tells you how much undisclosed penalty exposure you are buying, and it costs nothing but the time to build the file. A target with a 6% mismatch rate across 8,000 vendors is carrying a six-figure contingent liability that will not appear in the accounts.

What to keep, and for how long

The evidence obligations here are specific, and most teams retain either everything or nothing.

RecordWhy it mattersHow long
TIN match resultCitable as reasonable cause; must be produced as a legible copy of the original transactionWhile the payee is active, plus the penalty window
CP2100 notices receivedEstablishes whether the next notice is a first or second notificationThree years from the date of the first notice
Undeliverable B noticesSame three-year tracking rule; also evidences the solicitation attemptThree years, or until a valid address is obtained
Signed Forms W-9Certifies the TIN; required to stop backup withholdingFor the life of the vendor relationship
Solicitation recordThe specific proof the IRS looks for in a 972CG responseThrough the penalty window for the year concerned

The three-year clock runs even for payees you no longer trade with, because the rule is calendar-based rather than relationship-based. If you resume business with a payee inside that window, the count picks up where it left off.

What changed for 2026: the $2,000 threshold

The One Big Beautiful Bill Act, enacted 4 July 2025, moved two reporting thresholds that had been stable for decades. Both take effect for the 2026 filing year, and both change the shape of your 1099 population.

Reporting ruleBeforeFrom 2026
1099-MISC / 1099-NEC threshold$600$2,000 for payments made after 31 December 2025, indexed for inflation from 2027
1099-K de minimis$600 (as enacted in 2021)Restored to more than $20,000 and more than 200 transactions, retroactively

Two consequences follow. First, guidance published before July 2025 — including some IRS instructions still in circulation — quotes thresholds that no longer apply. Check the date on anything you are working from. Second, and less obviously: fewer reportable payees does not mean fewer risky payees. A supplier you now pay $1,800 a year is outside the 1099 threshold, outside the TIN Matching population, and just as capable of sending you a fraudulent bank-detail change request as the one you pay $200,000.

The limit that matters: a TIN match is not a payment control

Here is the part that most guides skip, and it is the reason a TIN match should never be the last check before money moves.

The Employment Tax Regulations at section 31.3406(j)-1 say two things about the matching details you receive. First, that none of them constitutes a notice of an incorrect name/TIN combination for the purpose of imposing backup withholding. Second — and this is the striking one — that a payer may not take any such matching details into account in determining whether to open or close an account with a payee.

Read that again

A code 3 is not, on its own, a lawful basis for refusing to onboard a supplier or terminating the relationship. The programme is a tax-accuracy tool with a specific permitted use. Whatever risk decision you make about that supplier has to rest on something else — which means you need something else.

And the converse is worse. A code 0 tells you that a name and a nine-digit number appear together on an IRS file. It says nothing about:

  • Whether the bank account you are about to pay belongs to that entity
  • Whether the company is currently active, dissolved, or in an insolvency process
  • When it was incorporated, and by whom
  • Who ultimately owns and controls it
  • Whether the person emailing you new bank details is connected to it at all

An EIN is issued once and, unlike a company registration, is not withdrawn when the business fails or changes hands. A dormant entity's EIN still matches. A shell company incorporated last month with a freshly issued EIN still matches. The match is a fact about a tax file, not a judgement about a counterparty.

It is also a fact with a date on it. A code 0 is accurate as at the moment it was returned and no later. If a vendor changes legal name, restructures or re-registers between your check and the IRS processing your return, a CP2100 can still appear for a payee you validated. The same is true, and more consequentially, of everything the match does not cover: a supplier that was solvent, correctly owned and paying to a legitimate account in March can be none of those things by October. A verification run once at onboarding is a photograph, not a control. That is the argument for continuous, registry-sourced monitoring rather than point-in-time checks.

When every check matches and it is still fraud

The gap is not theoretical. In 2025 the FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints with reported losses of $3.05 billion, out of $20.88 billion in total reported cybercrime losses. Those attacks do not work by inventing a fake company. They work by taking a real, correctly registered supplier that you already pay — one whose TIN matches perfectly — and changing where the money goes.

Picture a supplier file that looks like this on the day the payment run is approved:

What checked out
  • TIN Matching returned code 0 against the legal name
  • Signed Form W-9 on file, certified and current
  • Registered company with a valid registration number
  • Invoice matches the purchase order line for line
What nobody checked
  • Bank details changed by email eleven days ago
  • New account is at a different bank in a different state
  • Account holder name does not match the payee name
  • The company's sole director changed two months ago
  • The reply-to domain differs from the supplier's by one character

Every item on the left is real and verifiable. Not one of them touches a single item on the right. The left-hand column is what TIN Matching, a W-9 and a three-way match give you. The right-hand column is where the loss happens — and it is the same pattern behind the company red flags a bank account match alone will not catch.

How MonitorPay helps

The layer that runs after the TIN matches

MonitorPay does not run IRS TIN Matching — that is the IRS's own tool and it is free. What MonitorPay verifies is everything the match leaves open: whether the bank account is valid and active, whether the payee name matches the legal account holder, and whether the company behind the payment is registered, active and owned by who you think, using registry-sourced data across directors, shareholders, ultimate beneficial owners and group structure. Continuous monitoring flags a change in status or ownership rather than leaving it to be discovered at the next audit. MonitorPay does not initiate or hold funds; it reports whether the destination is safe to pay.

Where TIN matching sits in a supplier verification sequence

Treat it as one layer of three. Each answers a question the others cannot.

WHERE TIN MATCHING SITS IN THE STACK1TAX IDENTITYIRS TIN MatchingProves: the name/TIN pair the IRS holdsLeaves open: the account and the company2BANK ACCOUNTBank account verificationProves: the account exists, the name matchesLeaves open: whether the company is real3THE COMPANYCompany registry dataProves: status, age, directors, ownershipLeaves open: the layer most buyers never runEach layer answers a question the one above it cannot.
Figure 6 · Three layers, three different questions. TIN Matching is the first, not the last.

Put side by side, the three are not competing tools. They answer questions that do not overlap at all.

CheckQuestion answeredGeographyStops a misdirected payment?
IRS TIN MatchingIs this name/TIN pair on IRS records?United States onlyNo
VoP / CoP schemesDoes the payee name match the account holder?Euro area and UK payment railsPartly
Account verificationIs the account valid, active and held by the payee?Varies by providerYes
Registry company dataIs the business real, active and owned by whom?Wherever registries existYes, for the entity risk

What this looks like as a control

If your organisation is subject to SOX, or reports to an audit committee that thinks in those terms, it helps to name what is happening here. TIN Matching is a preventive control over the completeness and accuracy of information reporting. Account and company verification is a preventive control over the disbursement cycle. They are two controls, with two owners, two pieces of evidence and two failure modes — and describing them as one "vendor onboarding check" is how audit findings happen.

Three design points make the evidence hold up:

  • Store the result in the vendor master, not in an inbox. In SAP, NetSuite, Oracle or Coupa this means dedicated fields — result code, date checked, checked by — on the vendor record, not a PDF in a shared drive. If the evidence cannot be pulled per payee on request, it will not survive a 972CG response or a walkthrough.
  • Make the payment block automatic. A control that depends on somebody remembering to look at a field is not a control. Unresolved codes 2 and 3, and any bank-detail change inside a defined window, should hold the payment by default.
  • Separate the two approvals. The person who updates bank details should not be the person who approves the payment run. This is the oldest control in accounts payable and the one most often quietly abandoned during a systems migration.

Run in that order, the sequence is cheap. TIN Matching is free. A registry check on a company you are about to pay costs less than the invoice. The expensive option is the one most AP functions run by default: collect a W-9, match the TIN, pay whatever bank details arrive by email, and find out in the reconciliation.

The single highest-value point to insert the account and company layer is not onboarding. It is the bank-detail change request — the one workflow where a supplier that passed every check at onboarding gets re-pointed at an account that passed none. Treat every change request as a fresh verification event, not an update.

TIN matching stops at the US border

For any US business with an international supply base, this is the structural limit.

TIN Matching covers US taxpayer identification numbers only — SSNs, EINs and ITINs issued under IRC section 6109. A foreign supplier documented on a Form W-8BEN-E has no US TIN to match, and the programme explicitly does not extend to the W-8 series. There is no equivalent international service: verification abroad means company registries, national tax authorities and local banking infrastructure, each with different formats, access rules and coverage.

What replaces it: W-8, 1042-S and 30% withholding

A foreign payee sits in a different regime altogether, and knowing which one you are in changes what you withhold.

US payeeForeign payee
DocumentationForm W-9Form W-8BEN, W-8BEN-E, W-8ECI, W-8EXP or W-8IMY
Reported onForm 1099 seriesForm 1042-S, with Form 1042
Default withholding24% backup withholding, only if triggered30% under IRC sections 1441–1443, by default
Reduced byA certified TINA treaty claim on a valid Form W-8
TIN Matching availableYesNo

Two consequences are easy to get wrong. A foreign person who provides a valid Form W-8BEN, W-8BEN-E, W-8ECI or W-8EXP is exempt from backup withholding and from Form 1099 reporting — but a nonresident alien without that documentation on file is subject to backup withholding, so an incomplete W-8 does not leave you neutral. And the 30% NRA rate is the default rather than the penalty: it applies unless the payee has documented a lower treaty rate before payment.

What none of this gives you is any assurance about the account or the entity. There is no foreign equivalent of TIN Matching, and a Form W-8 is a self-certification — the payee tells you who they are and you accept it. For a US buyer paying a supplier in Vietnam or Mexico, the only independent evidence available comes from that country's company registry and banking infrastructure.

The same limitation applies, in mirror image, to the European payee-verification schemes. Verification of Payee in the euro area and Confirmation of Payee in the UK confirm that a payee name matches an account — within their own geography and their own payment rails. None of them, and not TIN Matching either, was designed to answer a question about a supplier on the other side of the world. A US buyer paying vendors in twelve countries needs an answer that does not stop at a border, and increasingly needs it available to software rather than to a person: the case for a verified payee layer before AI agents move money rests on exactly this.

That is exactly the gap a single cross-border verification layer is built to close, and it is why the same question — is this the right account, at the right company — has to be answered the same way whether the supplier is in Ohio or Ho Chi Minh City. If you are evaluating providers for this, our comparison of bank account verification providers in 2026 covers who actually has coverage outside their home market. For the ownership side of the question, see what UBO verification means for B2B payments.

A practical workflow

For a US finance team paying contractors and vendors, a defensible sequence looks like this:

  1. Collect a signed Form W-9 before the first payment. No W-9, no payment — and begin backup withholding if a TIN is not furnished.
  2. Run TIN Matching at onboarding, not in January. Interactive for a single new vendor; bulk for the existing file. Store the code and the date against the vendor record.
  3. Resolve every non-zero code before the payment, not before the filing. Codes 1, 4 and 5 are yours to fix. Codes 2 and 3 need the vendor.
  4. Reconcile codes 6, 7 and 8 against your entity classifications. A mismatch here means your 1099 population is wrong even though the TIN is right.
  5. Verify the bank account and the payee name separately. This is a different check with a different data source, and it is the one that stops misdirected payments.
  6. Verify the company. Status, incorporation date, directors and beneficial ownership — particularly for a new supplier receiving a first payment.
  7. Re-verify on every bank-detail change. Both layers. No exceptions, no matter who signs the email.
  8. Re-run bulk matching annually, ahead of filing season. Entities change names, merge and re-register; a code 0 is accurate only on the day it was returned.
  9. Monitor between checks. Onboarding is a snapshot. Status and ownership move.
Before the first payment
  • Signed Form W-9, legal name on line 1
  • Interactive TIN match run and code stored
  • Bank account verified against the payee name
  • Company status, age and ownership checked
  • Entity classification reconciled to codes 6, 7 or 8
Every year, and on every change
  • Bulk TIN sweep in October, not January
  • Any bank-detail change re-verified, both layers
  • CP2100 notices logged against the three-year rule
  • Solicitation record kept for each unresolved payee
  • Status and ownership monitored between checks
Get this data your way

Bulk, API, or the online platform

Bank account verification and registry-sourced company data are available through whichever access method fits your process: bulk file checks for a full vendor-master review, the REST API for verification inside your ERP or AP workflow, or the online platform for one-off checks with full audit logs. Coverage spans direct bank account verification in 49+ markets and company data drawn from 200+ government registries.


Frequently asked questions

What is IRS TIN matching?

IRS TIN Matching is a free service in IRS e-Services that lets an authorised payer check whether a payee's name and taxpayer identification number match the combination the IRS holds, before filing an information return. It was established for payers of reportable payments subject to backup withholding under IRC section 3406, and it returns a single numeric indicator from 0 to 8 for each name/TIN pair submitted.

How do I apply for the IRS TIN Matching Program?

Every user creates an ID.me account to access IRS e-Services. The firm's Principal — a partner, an owner of at least 5%, or a corporate officer who can bind the firm — then completes the online Application to TIN Match and assigns user roles. The IRS states that once the application is complete, users may begin interactive or bulk TIN Matching the same day. There is no fee to apply or to use the service.

Who is eligible to use IRS TIN matching?

Only payers and their authorised agents that file information returns. The organisation must appear in the IRS Payer Account File, which is populated from filing history — the IRS defines an authorised payer as one that has filed information returns in at least one of the two preceding tax years. A brand-new entity with no filing history cannot get access until it has filed. Registered e-file providers who are not themselves payers are also declined.

What is the difference between interactive and bulk TIN matching?

Interactive TIN Matching accepts up to 25 name/TIN combinations at a time on screen and returns results in real time, typically within about five seconds. Bulk TIN Matching accepts a semicolon-delimited text file of up to 100,000 combinations and returns the results to a secure mailbox within 24 hours. Interactive suits a single new vendor; bulk suits an annual sweep of the vendor master.

What do the IRS TIN matching result codes 0 to 8 mean?

0 means the name/TIN combination matches IRS records. 1 means the TIN was missing or is not nine numeric digits. 2 means the TIN is not currently issued. 3 means the name and TIN do not match. 4 means an invalid request. 5 means a duplicate request. Codes 6, 7 and 8 are matches returned when the TIN type was submitted as unknown — 6 matched on the SSN file, 7 on the EIN file, and 8 on both.

Does TIN matching prevent payment fraud?

No. TIN Matching confirms that a name and taxpayer identification number appear together on an IRS file. It does not confirm the bank account you are paying, whether the company is still active, who owns it, or whether a bank-detail change request is genuine. An EIN is not withdrawn when a business becomes dormant or changes hands, so a dormant or newly formed entity can return a clean match. Preventing misdirected payments requires separate account and company verification.

Can I refuse to onboard a vendor because of a TIN mismatch?

Not on the basis of the match result itself. The Employment Tax Regulations at section 31.3406(j)-1 provide that a payer may not take matching details received through the programme into account when deciding whether to open or close an account with a payee, and that those details do not constitute notice of an incorrect name/TIN for backup withholding purposes. Any onboarding or termination decision has to rest on independent grounds.

What is a CP2100 notice and how long do I have to respond?

A CP2100 or CP2100A is a Notice of Possible Payee TIN Discrepancy, sent after you file returns containing missing or incorrect name/TIN combinations. Large filers with 250 or more error documents receive an encrypted CD or DVD; filers with 50 to 249 receive a paper CP2100; fewer than 50 receive a CP2100A. You have 15 business days from the notice date or receipt, whichever is later, to send the appropriate B notice to the payee, and you must begin backup withholding no later than 30 business days after the notice if no signed Form W-9 comes back.

What is the penalty for filing a 1099 with the wrong TIN?

An incorrect TIN is a failure under IRC section 6721 for the information return and section 6722 for the payee statement, so it is usually charged twice. For returns due in 2026 the per-return amounts are $60 if corrected within 30 days, $130 if corrected by 1 August, and $340 after 1 August or if not filed. Intentional disregard is $680 per return, or 10% of the amount that should have been reported, with no annual cap. Annual caps apply to the other tiers and are lower for smaller businesses.

Can a TIN match get a penalty waived?

It can support a request. IRC section 6724 allows the IRS to waive section 6721 and 6722 penalties for reasonable cause, and a participating payer may cite a name/TIN match as reasonable cause. The IRS will consider a waiver where the payer supplies a legible copy of the original match transaction for the combination penalised, the penalty was assessed after the date of that match, and the abatement is requested in writing citing use of the programme. That makes dated, retrievable evidence of each match essential.