Built as you work, not after

Most compliance programs do the work. Fewer can prove it.

Doing the validation isn't the hard part — proving you did it, eighteen months later, to someone holding a penalty notice, is. TIN Comply logs every validation, screening result, outreach send, correction, and revalidation with a timestamp and the user who ran it, attached to the individual vendor record. The documentation exists before you need it.

Searchable, filterable, and exportable — portal and API activity alike.

Request History 567 requests
NORTHWIND TRADING CO TIN ••••8127 · IRS + Lists + Address Requested by M. Alvarez · 08-17-26 3:34pm ET Match
SUMMIT LOGISTICS GROUP LLC TIN ••••4417 · IRS + Lists W-9 correction requested · revalidation pending Mismatch
HARBOR POINT SERVICES LLC Screened against 330+ lists Escalated to compliance review · 08-14-26 Review
CEDAR RIDGE CONTRACTING Source: API · onboarding integration Match
Filter by type, date, user, source, or company Exportable
Full validation history
Search & filter
Per-user attribution
Export for audit
Included

Part of every TIN Comply plan from $20/mo — not a separate purchase. See pricing

Why it matters

The gap between doing compliance and proving it

Nearly every AP and tax team validates vendors. Far fewer can produce, on demand, the record of what was validated, when, by whom, and what happened next.

That gap only becomes visible under pressure — when a 972CG notice arrives with a 45-day clock, when an examiner asks for the outreach history on forty vendors, or when an OFAC question turns on whether a counterparty was screened before a payment cleared.

At that point the documentation either exists or it doesn't. Reconstructing it from inboxes, shared drives, and the memory of staff who may have left is slow, incomplete, and unpersuasive — and it's happening exactly when you have the least time.

What the clock looks like

  • CP2100 arrives 15 business days to send B-Notices to affected payees.
  • Notice 972CG Roughly 18 months later. 45 days to respond before the penalty is assessed.
  • IRS examination Requests can reach back years across the full vendor population.

None of these windows are long enough to build a record. They're only long enough to retrieve one.

What gets logged

Everything, automatically, attached to the vendor

There's no "enable logging" step and nothing to remember. Every action in the platform writes its own record.

Activity What's captured What it proves
IRS TIN matching Submitted data, result code, timestamp, and whether it came from a user or the API. That the payee was validated before filing — and when.
Sanctions screening Names screened, lists covered, match results and percentages, timestamp. That the counterparty was screened before payment.
W-9 requests Outreach date, delivery method, and message content. Documented solicitation — the core of reasonable cause.
Reminders & revalidations Each reminder dated, corrected data captured, new result recorded. A documented follow-up cadence, not a single attempt.
Non-response tracking Failed response dates and outreach attempt counts per vendor. That the failure was the payee's, not yours.
User & source attribution Which user or API integration initiated each request. Internal control — who did what, and under what authority.
Where the record earns its keep

Four moments where documentation is the whole case

972CG penalty abatement

Reasonable cause turns on whether you acted in a responsible manner — documented solicitation of the correct TIN, with dates. The outreach history, validation results, and B-Notice record are assembled as you work, so the abatement package is a retrieval rather than a reconstruction.

IRS examination response

Filter by vendor, date range, result type, or user and export the structured record. What normally takes weeks of digging through email and spreadsheets becomes a query — and the answer is consistent rather than dependent on who assembled it.

OFAC enforcement defense

Under strict liability the question is rarely intent — it's whether you had a functioning program. Timestamped records showing every counterparty was screened, against which lists, and on what date are that evidence, and they support voluntary self-disclosure if something is found.

Internal controls & SOX

Per-user, per-request logging shows which validations ran, when, and what came back — the evidence internal audit needs that the control operated, not just that it was designed.

Getting to the record

Search, filter, open, export

The history view is the working surface — not an archive you request a report from.

  • Filter by what you're being asked about Validation type, status, date range, user, source (portal or API), company name, or TIN.
  • TINs masked by default History shows masked identifiers, so reviewing the record doesn't mean exposing tax IDs to everyone who can see the screen.
  • API activity included Requests from an embedded integration are logged the same way as portal activity, and can be filtered to specifically.
  • Export the filtered set Structured output for an examiner, an abatement package, or internal audit — scoped to exactly what was asked for.

The useful test: pick a vendor you paid two years ago and ask whether you could show, in five minutes, that their TIN was validated before filing, that they were screened against sanctions, when the W-9 was requested, and who ran each check.

If that takes a week of digging, the documentation isn't a compliance program — it's an archaeology project. This page exists to make that answer a query.

Access control on top

Admins have unrestricted access; regular users only see the features you enable. Combined with per-request user attribution, that gives you both sides of the internal-control story — who could act, and who did.

FAQ

Questions about audit documentation

What documentation does 972CG penalty abatement require?

Reasonable cause abatement requires showing you acted in a responsible manner — which in practice means documented solicitation of the correct TIN, with dates. When the W-9 was requested, when reminders went out, what the vendor responded, and what validation returned each time.

A record reconstructed from inboxes after the notice arrives is rarely complete enough to meet that standard.

How long do I have to respond to a Notice 972CG?

Generally 45 days from the notice date before the proposed penalty becomes a final assessment. That's not enough time to rebuild an outreach history across email, spreadsheets, and staff who may have left — the documentation has to already exist when the notice lands.

What exactly gets logged?

Every TIN matching submission with its result code, source and user; every sanctions screening with names screened, lists covered and match results; every W-9 request with outreach date and delivery method; every reminder and revalidation; and non-response tracking with attempt counts.

All of it timestamped and attached to the individual vendor record.

Can I export records for an IRS examination?

Yes. Search and filter by validation type, status, date range, user, source, company name, or TIN, then export the structured record — replacing manual reconstruction when an examiner asks what was done and when.

How does this support OFAC enforcement defense?

OFAC sanctions carry strict liability, so the question in enforcement is rarely whether you intended a violation — it's whether you had a functioning compliance program. Timestamped records showing every counterparty was screened, against which lists, and on what date are that evidence.

They also support voluntary self-disclosure, which is treated as a mitigating factor, if a problem does surface.

Does the audit trail cover API activity too?

Yes. Every request is logged with its source, so validations run through an API integration are recorded exactly like portal activity, and history can be filtered specifically to API requests.

That matters when validation is embedded in an ERP or onboarding system and no individual user initiated the call.

Build the record while you do the work

Every validation, screening, outreach send, and correction logged with a timestamp and the user who ran it — searchable, filterable, and exportable the day an examiner or a penalty notice asks for it.

Nothing to enable. Nothing to remember.