LedgerOS
Open LedgerOS
Knowledge HubE-signaturesIdentity verification on signatures
E-signatures

Identity verification on signatures

When knowledge-based authentication is required, how credits work, and what to do when a signer fails.

5 min readUpdated July 24, 2026Requires E-signatures

Some signatures need proof the signer is who they say they are. IRS e-file authorizations are the obvious case, and getting this wrong is not a small problem.

The two signature types

Standard — the signer clicks the link and signs. Right for engagement letters, consents, and most internal paperwork.

KBA — knowledge-based authentication. The signer answers identity questions drawn from public records before they can sign. Required for remote signing of IRS e-file authorization forms.

Automatic defaulting

LedgerOS reads the request title. If it looks like a Form 8879 or 8878, or mentions an e-file authorization, the signature type defaults to KBA.

That default exists because the consequence of sending an 8879 as a standard signature is a return authorized without valid verification. The check is on the title, so name your requests properly — Form 8879 — 2024 rather than Tax form.

The default is a safety net, not a substitute for checking. If you retitle a request or use a generic name, verify the signature type before sending. You can override the default in either direction, and overriding it downward on an 8879 is the mistake worth avoiding.

How credits work

Each KBA attempt uses one credit, pass or fail. A signer can retry up to 3 times.

So a request with two remote KBA signers can consume up to six credits. LedgerOS shows the ceiling before you send, and warns when your balance is low or exhausted.

Failed attempts still cost. That's how identity verification is priced everywhere — the check is performed either way.

Running out

You can't send a KBA request with no credits. Two options:

  • Buy more credits.
  • Mark signers as in-person, which skips verification.

In-person signing

A signer marked in-person skips KBA entirely, because you're verifying identity yourself by having them in front of you.

This is legitimate and it's the correct route for a client sitting across your desk. It is not a workaround for a remote signer you happen to trust — the whole point of the verification is that trust isn't the standard.

When a signer fails

Three failed attempts and they're locked out of that request.

At that point the options are to send a new request and let them try again, or to have them sign in person. Failures are usually thin credit files, recent moves, or genuinely not knowing the answer to a question about a mortgage from 2009 — not fraud.

Failed verification shows under Needs attention in the signature monitor.

Notes and limits

  • Credits are firm-wide, not per client.
  • In-person signers consume no credits.
  • Standard signatures never consume credits.
  • A template can carry its signature type, so an 8879 template always sends as KBA.
Was this article helpful?
Related articles