Who qualifies, and how the IRS checks
An applicant "must be a payer of income subject to backup withholding" reported on one of nine forms: 1099-B, DIV, G, INT, K, MISC, NEC, OID or PATR (IRM 3.42.8.7). That is the same list the CP2100 program reads. A payer that files only 1099-R, 1099-S, 1098, W-2 or 1042-S is not on it. The eligible business-partner class for the program is "payers of income subject to back-up withholding" and nothing else (Figure 3.42.8-2); a CPA firm or service bureau gets access as a payer's Authorized Agent, not in its own right.
There is also a history test: payers "must have filed Form 1096 ... reporting income paid on a Form 1099 series, or submit information returns electronically, in one of the last two years." The assistor verifies it on the Payer Master File ("Use IDRS CC PMFOL to research Payer Master File and verify payer is eligible"). The backup withholding manual calls the underlying list the Payer Authorization File (IRM 5.19.3.5.1.6). A brand-new payer with no 1099 history under its EIN can be refused; vendors onboarding a new client should warn them, and the client should file under its own EIN once before relying on access.
The four roles
IRM 3.42.8.7, Figure 3.42.8-3.
Every person on the application must have their own login. "Users cannot log in to an e-Services application ... using another person's username and password." If the help desk discovers a shared credential it calls it "a security violation," asks for the credential owner, and if the owner does not come to the phone "the call must be terminated" and a case is opened; re-enabling requires the owner to pass high-risk authentication (IRM 3.42.8.3.1.2). A shared AP-department login is the fastest way to lose the program.
The resubmit trap and the departed Principal
"Many users forget to resubmit the application after making additions or changes. Unlike an IRS e-file Application, the TIN Matching Application requires a PIN entry only at the initiation of the application, not after each subsequent change" (IRM 3.42.8.7.1). A user added to the application cannot see the TIN Matching links until the application returns to Completed status. This is the most common access failure the help desk sees, and its instruction is to submit the application for you "in the interest of good customer service."
When the only Principal has left the company, "only an owner, officer, or partner of the company can replace/add the new Principal," and if a Principal is still listed the caller "must know who the existing Principal is and give you the individual's name" (IRM 3.42.8.7.3). The assistor authenticates the caller against business-account records before the new Principal submits. Deleting or restoring an application is a Level 2 escalation, not a same-call fix (IRM 3.42.8.7.2). Put the TIN Matching application on the offboarding checklist next to the TCC application.
Limits, codes and turnaround
Interactive: up to 25 name/TIN pairs per request. Bulk: up to 100,000 per file, semicolon-delimited, with a 50-character name limit; "The customer will receive a response within 24 hours" (IRM 3.42.8.7.4, 7.5). If nothing arrives, resubmit, record the tracking number and timestamp, and call after a further 24 hours. The two most common error messages are "Line %1 contains invalid data or has more or less semicolons" and "96 Hour Lockout" (IRM 3.42.8.7.7).
| Code | Meaning |
|---|---|
| 0 | Name and TIN match IRS records. |
| 1 | TIN missing or not nine digits. |
| 2 | TIN not currently issued. |
| 3 | Name and TIN do not match. |
| 4 | Invalid request: letters or special characters in the TIN, or a missing field. |
| 5 | Duplicate request. |
| 6 | Matched on SSN when TIN type was "unknown." |
| 7 | Matched on EIN when TIN type was "unknown." |
| 8 | Matched on both SSN and EIN when TIN type was "unknown." |
"TIN Matching does not divulge a taxpayer's TIN or a business's EIN. It only verifies whether the TIN and name combination which the user submitted matches IRS records." The help desk will not supply the correct number either: if a caller asks, the script is that the IRS is not authorized to disclose it and the payer must go back to the payee (IRM 3.42.8.7.4).
The proximal-match rule
The program "allows for a proximal match for SSN's." The first letter of the name control must match; the second and third, or third and fourth, letters may be transposed; and "any valid character in the second, third, or fourth position will create a proximal match (i.e., AXCD, ABXD, and ABCX would all be valid proximal matches for name control ABCD)" (IRM 3.42.8.7). Two consequences. A code 0 for an individual proves the first letter and most of the surname, not that the name is exactly right. And the rule is stated for SSNs only; a business name with an EIN gets no such tolerance, which is why the same typo passes for a person and fails for a company. The name control page covers the derivation rules.
The 96-hour lockout
"The TIN Matching program contains a built-in security feature that detects when a customer's EIN, SSN or ITIN is being researched using different names." When it fires, "Account access is blocked for four days (96 hours)" and "They will have to wait for the system to unlock them" (IRM 3.42.8.7.6). The help desk cannot lift it. A bulk file caught by the lockout still gets a tracking number but "does not return result codes"; the only sign is a message in the Secure Mailbox. The natural temptation after a CP2100, trying the same TIN with three spellings of the vendor's name, is exactly the pattern the feature is built to catch. De-duplicate, and re-solicit the payee instead of guessing.
One TIN, one name per request. Trying name variants against a single TIN is treated as fishing and locks the whole account for four days.
The deletion clock on your results
Bulk results and other Secure Object Repository deliveries are "deleted after 3 business days if read, 30 business days if unread" (Figure 3.42.8-8). Download the file the day you open it. Nothing in the manual requires the IRS to retain your results, and nothing in the program constitutes your record of having checked; the downloaded file with its date is the evidence you will want for a 972CG response. A representative or service bureau attached to many payers should also know that "Only 14 organization links can be seen" in the interface (IRM 3.42.8.9.3).
What the help desk will and will not do
The e-help Desk handles access and technical problems with e-Services products; "In general, the e-help Desk does not answer account-specific questions" (IRM 3.42.8.2). Identity proofing is done by credential service providers under the SADI system, and "the IRS will no longer provide ID proofing and authentication services"; the help desk supports only "did not create account" and restrict/un-restrict requests (IRM 3.42.8.4). The Short ID, an 8 to 10 character code on the "Select Your Organization" page, is what the help desk asks for on nearly every escalation and what API integrations key on (IRM 3.42.8.6.2). The five-digit e-Services PIN "can't be all the same numbers, can't begin with zero and can't be the same as the last PIN" (IRM 3.42.8.9.1).
Questions people ask
Can our accounting firm run TIN matching for us under its own account?
Only as your Authorized Agent on your application, with your written authorization. Tax professionals as a class are not eligible partners for TIN Matching; the eligible class is payers of income subject to backup withholding (Figure 3.42.8-2).
We got code 0 on a vendor and still received a CP2100 for them.
Two possibilities the manual supports: the proximal rule passed a near-miss on an individual's name that the filing match did not, or the record changed between the check and the filing. Keep the dated result; it is evidence of a responsible-manner check for the penalty response.
Does the program cover 1099-R or 1042-S payees?
No. Neither form is on the eligibility list, and a payer that files only those forms is not eligible at all. Those payees are validated through the W-9 or W-8 process and, for EINs, Letter 147C.