NevTan Sign
NevTan Sign
guide

E-Signatures for Accountants and Tax Preparers: Engagement Letters, Client Authorizations, and Year-End Paperwork

E-Signatures for Accountants and Tax Preparers: Engagement Letters, Client Authorizations, and Year-End Paperwork
NS 10 min read

Most guides on this topic tell you e-signatures are legally valid under ESIGN and UETA, and stop there. That's true, and it's not the part that matters for a tax practice.

What matters is that the IRS imposes its own requirements on top of general e-signature law, those requirements differ by form, and the hardest one — Form 8879 — has an identity verification rule that a standard e-signature setup does not satisfy. Get that wrong and you have returns filed without valid authorization on file.

This guide separates the three tiers: documents where ordinary e-signature rules apply, documents where the IRS adds requirements, and the practical fallback when verification fails.

Key takeaways

  • Engagement letters follow ordinary ESIGN/UETA rules. Most of your volume sits here.

  • Form 8879 signed remotely requires IAL2 identity verification, typically third-party KBA, every single time.

  • Form 2848 and 8821 require a different procedure: photo ID inspection plus secondary document verification.

  • A wet signature scanned and emailed to you is not a remote e-signature and needs no KBA. This is your fallback.

  • Form 8879 is retained by you, not filed with the IRS.

  • Your platform choice is also a Safeguards Rule decision, not just a workflow one.

The three tiers

Document

What applies

Practical implication

Engagement letters, organizers, internal acknowledgements

ESIGN / UETA only

Standard e-signature workflow is fine

Form 8879, 8878

Pub 1345 identity verification

Remote signing needs IAL2 / KBA every time

Form 2848, 8821

Form instructions' authentication procedure

Photo ID inspection and secondary verification

Treating these the same is the error that causes compliance problems. Most e-signature platforms handle tier one well, tier two only if they integrate a KBA provider, and tier three not at all, because it's a procedure your staff performs rather than a feature.

Tier one: engagement letters and general documents

This is the easy tier and usually 80% of your volume.

Under the ESIGN Act and UETA — adopted in 49 states, with New York operating under its own Electronic Signatures and Records Act — an electronic signature has the same legal effect as a handwritten one where the parties intend to sign electronically and the record can be retained and reproduced.

Build these as reusable templates with merge fields for client name, entity, tax year and fee terms. Field placement matters more than people expect, particularly for clients signing on phones: signature field placement strategies and forms and fields that get signed cover the specifics. The NevTan Sign template library includes a service agreement you can adapt as an engagement letter base, though your engagement letter should be reviewed by counsel or drawn from your professional body's model letters. [LEGAL REVIEW]

One thing to build in: a consent-to-electronic-delivery checkbox. ESIGN requires consumer consent before you deliver electronically a record that law requires to be in writing, and it costs nothing to capture it up front.

Tier two: Form 8879, and the rule most guides miss

Form 8879 is the e-file signature authorization. Two facts people get wrong before we even reach signatures:

  • It isn't filed with the IRS. You retain it. The retention period runs three years from the return due date or the date the IRS received the return, whichever is later.

  • The taxpayer must be sent a copy of the return to review before signing the form. And if amounts on the 8879 change beyond the thresholds set in Pub 1345, a new form must be signed.

In person versus remote

A remote transaction is one where the taxpayer signs electronically and you are not physically present. The two situations carry different requirements, and this is the distinction the whole rule turns on.

In person, the requirement is essentially identity document inspection: check a valid government-issued photo ID, compare the photo to the person, and record their identifying details.

Remotely, the bar is considerably higher. Pub 1345 Section 5.3.2 requires an identity verification method meeting NIST SP 800-63-3 Identity Assurance Level 2, which in practice has meant third-party knowledge-based authentication, where the taxpayer answers multiple-choice questions drawn from public records, credit files and similar sources. This verification has to happen every time the taxpayer remotely signs, not once at onboarding.

This is the sentence to take away: a standard e-signature platform with email links or SMS codes does not satisfy this. You need a platform that integrates a KBA provider, and you need it switched on for these forms specifically.

When KBA fails, and it does

KBA is genuinely difficult for clients. The typical flow asks four or more questions drawn from credit records within a time limit, a single wrong answer fails the whole set, and only two or three attempts are allowed. Clients who have moved recently, have thin credit files, or are elderly fail at meaningful rates.

When a taxpayer fails the knowledge-based questions after three attempts, obtain a handwritten signature instead.

And here's the fallback worth knowing in advance: a handwritten signature on Form 8879 delivered to you by mail, fax, email or a web upload is not a remote electronic signature at all. Pub 1345 states that wet-signed copies may be delivered to you electronically with no special requirements applying to the signature. The client signs paper, photographs it, uploads it. No KBA, fully compliant.

Build this into your process as the documented Plan B rather than improvising it in March.

Tier three: Forms 2848 and 8821

These follow a different procedure again, and SMS codes are not it.

Where a taxpayer electronically signs Form 2848 in a remote transaction, the party submitting it must attest that they authenticated the taxpayer's identity. For an individual client that means: inspect a valid government-issued photo ID and compare the photo to the taxpayer via a self-taken picture or video conferencing, and record their name, SSN or ITIN, address and date of birth, then verify name, address and SSN against secondary documentation such as a tax return, IRS notice or letter, Social Security card, or a credit card or utility statement.

Note that this authentication duty applies to clients you don't already know, and any form of electronic signature is acceptable for forms submitted through the online tool — the signature technology is not the constraint; the identity procedure is.

Submission runs through the "Submit Forms 2848 and 8821 Online" tool on the IRS tax professionals page, which requires a Secure Access account, with Tax Pro Account offering real-time processing for individual POA and TIA as an alternative to online, fax or mail submission, which can be slower.

Practically: this is a staff procedure with a checklist, a video call and a saved record. Write the procedure down, train on it, and document each instance.

Security obligations you're also choosing

Selecting an e-signature platform for a tax practice is a data security decision.

The FTC Safeguards Rule. Tax preparers are financial institutions under GLBA and must maintain a written information security plan. Your e-signature vendor becomes a service provider under that plan, which means vendor due diligence, documented controls and contractual security commitments. IRS Publication 4557 covers preparer obligations.

IRC §7216. Disclosing or using tax return information outside permitted purposes requires client consent, with specific formatting rules. Whether routing return information through a particular platform triggers this is a question worth putting to counsel before you roll out, not after. [LEGAL REVIEW]

Phishing exposure. Tax practices are a standing target, and the attacks cluster in season. Preparer credentials give access to hundreds of complete identity profiles. Multi-factor authentication on the signing platform is a baseline, and staff need to recognise fake signature requests — see phishing protection basics. Documents sent by email alongside signing requests should be enAzcrypted rather than attached in the clear.

Review how any platform you're considering handles document protection and access control. NevTan Sign's security page sets out its approach.

Building the workflow

Map documents to requirements first. A spreadsheet with document name, signer count, tier, verification method and retention period. This is your configuration blueprint and it prevents the tier confusion described above.

Set reminders. 24 hours, 72 hours, then a phone call. Most unsigned documents are forgotten rather than refused.

Handle joint returns properly. Both spouses must sign Form 8879 for a joint return, and each must clear identity verification separately when signing remotely. Configure two distinct signer roles. A form captured with only the primary taxpayer's signature is a live problem.

Route sequentially where review matters. Signed engagement letter to the engagement partner, then to document storage. Common signing workflows covers the patterns, and NevTan Sign integrations shows what connects to practice management systems.

Store the completion certificate with every document. Signer name, email, IP, timestamp and authentication method. For 8879 specifically, the KBA result is part of your compliance record, not a nice-to-have. How audit trails work explains what a defensible trail contains.

Organize by client and tax year, and confirm the platform exports in a portable format before you commit. Document management platform considerations covers retrieval and retention.

Some documents still need a notary. Certain trust, estate and state-level filings do. Remote online notarization covers how that works where your state permits it.

Multiply hours saved by your fully-loaded staff cost, not your billing rate — recovered admin time only converts to revenue if you can actually sell it. The larger gain for most firms is compression of the January bottleneck, where unsigned engagement letters delay the start of return work during your narrowest window.

Budget for KBA transaction costs, which are usually per-attempt and add up across a season with failures and retries.

Choosing a platform

Criteria specific to tax work:

  1. KBA integration with a recognised third-party provider, and clear reporting on pass/fail per attempt. Without this you cannot collect 8879 remotely. Ask for it explicitly rather than accepting "IRS compliant" as an answer.

  2. Per-document audit certificates you can export and hand to an examiner.

  3. Multi-signer roles with independent verification per signer.

  4. Practice management integration, so signed status drives the next task.

  5. Retention and export controls matching your state board's requirements.

  6. Security posture meeting your Safeguards Rule obligations.

Solo practitioners can often start simpler — free and low-cost options work for tier one documents, with wet signatures for 8879. Multi-partner firms should weight routing and access control. How to choose an e-signature tool covers general evaluation, and NevTan Sign vs DocuSign has a direct comparison.

Common mistakes

  1. Applying one verification level to everything. Three tiers, three treatments.

  2. Assuming SMS satisfies the 8879 requirement. It doesn't.

  3. No documented fallback for KBA failure. Decide the wet-signature process before the season starts.

  4. Verifying identity once at onboarding. For 8879 it's required per signature.

  5. Missing the second spouse on a joint return.

  6. Storing the signed PDF without the certificate.

  7. Skipping vendor due diligence under the Safeguards Rule.

FAQ

Can clients sign Form 8879 electronically?
Yes, but remote signing requires identity verification meeting NIST IAL2, generally third-party KBA, performed each time the form is signed. In-person signing follows a lighter photo ID procedure.

What if a client fails KBA?
Obtain a handwritten signature. A wet-signed form scanned and emailed to you is not treated as a remote electronic signature and carries no KBA requirement.

Is SMS verification enough for Form 8879?
Not on its own. An access code proves device possession, not identity. The requirement is identity proofing at IAL2. Confirm how your platform meets it and keep the evidence.

What's required for Form 2848 signed remotely?
Photo ID inspection by self-taken photo or video call, recording the taxpayer's identifying details, and verification against secondary documentation. The submitter attests to having done this.

Are e-signatures binding on engagement letters?
Yes, under ESIGN and UETA, where both parties intend to sign electronically and the record is retainable. Engagement letters carry no IRS-specific signature requirement.

How long should signed records be kept?
Form 8879 for three years from the return due date or IRS receipt date, whichever is later. State boards and professional standards often require longer, so apply the longest applicable period.

Do both spouses sign Form 8879 on a joint return?
Yes, and each needs independent identity verification when signing remotely.

Does using an e-signature platform trigger §7216 consent?
It depends on how return information flows through the vendor. Raise it with counsel before rollout. [LEGAL REVIEW]