IRS TIN matching software that catches mismatches before they become notices
The IRS checks the name and TIN on every 1099 you file. When they don't match, you get a CP2100. TIN Comply runs that same check against official IRS records in real time — at onboarding, in bulk before filing season, or embedded in your ERP — and tells you exactly what's wrong so you can fix it before it ever reaches the IRS.
No IRS enrollment. No per-user limits. Portal, bulk, and API included.
DBA used instead of legal name, name change not updated at SSA, or missing entity suffix (LLC, Inc.).
Request corrected W-9 — ask vendor for legal name exactly as registered with the IRS.
Part of every TIN Comply plan from $20/mo — not a separate purchase. See pricing
IRS TIN matching requirements — who has to validate, and when
IRS TIN matching confirms that the taxpayer identification number and legal name you have on file resolve against the IRS's own records — before a 1099 is filed.
A mismatch that isn't caught before filing doesn't stay a data problem. It becomes a CP2100 line item, then a B-Notice deadline, then backup withholding, and — if it's still unresolved — a penalty assessed per return under IRC §6721. Every one of those steps is avoidable at the point the vendor record is created.
Required fields are deceptively simple. A TIN (SSN, EIN, ITIN, or other supported type) and the legal name — the individual's name as it appears on their Social Security card, or the business name as registered with the IRS. Not a DBA, not a trade name, not the operating name on the invoice. That distinction causes a large share of all mismatches.
The timeline you're racing
What happens when a mismatch is discovered by the IRS instead of by you.
-
1
You file the 1099 The mismatch is now on a filed return.
-
2
CP2100 arrives Each listed payee starts a 15-business-day B-Notice clock.
-
3
Backup withholding begins 24% withheld until a valid TIN is confirmed.
-
4
Notice 972CG Proposed penalties, roughly 18 months later. 45 days to respond.
One bad character in a vendor name is a penalty per return
Information return penalties are assessed per return, not per vendor and not per filing. A vendor master with a few hundred unvalidated records is a few hundred separate exposures.
CP2100 B-Notices
Every mismatch on a filed 1099 becomes a CP2100 line item, and each one starts a 15-business-day B-Notice clock. Matching before filing stops them from reaching the IRS at all.
§6721 penalty tiers
For returns required to be filed in 2026: roughly $60 per return corrected within 30 days, $130 by August 1, and $340 after that. Intentional disregard is higher, with no annual cap.
24% backup withholding
Unresolved mismatches trigger a 24% withholding obligation. TIN Comply flags which vendors require it and confirms when a corrected TIN resolves — so withholding starts and stops on schedule.
Vendor data integrity
Bad TIN data spreads. It causes reporting errors, payment friction, and audit exposure across AP, tax, and compliance. Validating at onboarding keeps the master clean before it compounds.
Reasonable cause abatement is a documentation test. Getting a 972CG penalty abated requires showing you acted in a responsible manner — documented solicitation of the correct TIN, with dates. If that record has to be reconstructed from inboxes after the notice arrives, it usually isn't complete. TIN Comply builds it automatically, as a byproduct of doing the work.
How automated TIN matching works, end to end
The loop closes without anyone chasing a vendor by hand.
Submit
Enter a name and TIN in the portal, upload a bulk file, or send a record via API — whichever fits the workflow you already have.
Validate
TIN Comply submits to the IRS TIN Matching system and screens against over 330 sanctions and watchlists in the same call. Result and sanctions clearance come back together.
Review
Matches are confirmed. Mismatches return a specific reason code — name mismatch, wrong TIN type, invalid TIN — so outreach asks for exactly the right correction.
Resolve
A mismatch can trigger a W-9 request automatically. When the corrected W-9 returns, revalidation runs on its own, and the record updates only on a confirmed match.
You're not buying a result code. You're buying the whole vendor picture.
Submit a TIN, a legal name, and an address once. TIN Comply runs every validation that data supports — IRS TIN matching, company name by EIN, EIN by company name, address validation, sanctions screening, company details, and FATCA GIIN or LEI where supplied — returning each one with what it means and what to do next. Anything it couldn't run, it tells you about instead of quietly skipping.
EIN is valid for filing. No backup withholding obligation on this payee.
No action needed. Save this result as documentation of due diligence for your audit file.
The possible EIN associated with the company name you entered. Use it to verify or correct vendor records.
Cross-reference against the vendor's W-9 Box 1 and Box 2 to guide outreach if there's a discrepancy.
Every card names its data source and timestamp, and every result is written to your searchable request history with the user who ran it — which is what turns a validation into evidence.
IRS TIN matching result codes — and what to actually do about each one
The IRS returns a number. TIN Comply returns the number, the most likely cause, and the correction to request — which is the difference between an exception list and a resolution plan.
| Code | IRS meaning | Most common cause | What to do | Status |
|---|---|---|---|---|
| 6 | Matches SSN records Confirmed match on an SSN-based IRS record. |
— | Nothing. The record is clean for 1099 filing. | Clear |
| 7 | Matches EIN records Confirmed match on an EIN-based IRS record. |
— | Nothing. The record is clean for 1099 filing. | Clear |
| 8 | Matches both SSN and EIN records The IRS holds records under both a personal SSN and a business EIN with a name control overlap. |
Sole proprietor or single-member LLC who has both an SSN and an EIN registered. | Confirm which TIN type is correct for this payee's payment arrangement — form type and entity structure decide it. | Review |
| 3 | TIN/Name does not match The TIN is valid, but the submitted name doesn't match the IRS registration for it. |
DBA or trade name used instead of legal name, missing entity suffix, or a name change never updated with the SSA. | Request a corrected W-9 asking for the legal name exactly as registered with the IRS. Use EIN & Company Lookup to tell them which name to use. | Correct |
| 2 | TIN not currently issued The TIN doesn't exist in IRS records at all. |
Transposed digit, a wrong TIN provided, or a TIN belonging to an entirely different entity. | Request the correct TIN and apply backup withholding until a valid TIN is confirmed by revalidation. | Withhold |
A generic "your information doesn't match" email gets ignored, and when it does get a response the correction is often wrong. Code-specific outreach asks for one precise thing — which is why response quality goes up, not just response rate.
The check is the easy part. The rest is what actually saves the penalty.
Anyone can hand you a result code. These are the pieces that turn a code into a resolved vendor record.
EIN & legal name discovery
When a match fails, look up the IRS-registered legal name for the EIN directly. Outreach then names the specific correct value instead of asking the vendor to guess what's wrong.
IRS lockout protection
The IRS locks accounts for 96 hours when it detects duplicate submissions — including accidental ones from two users or overlapping batch jobs. TIN Comply de-duplicates before anything reaches the IRS, so a routine mistake doesn't cost you four days of validation capability.
Over 330 watchlists on every validation
OFAC SDN, Trade CSL, SAM Procurement Exclusions, FinCEN, BIS Denied Persons, EU, UN and more — across the US, Europe, Asia, Africa, the Americas, and Oceania — screened automatically with every TIN matching call, with fuzzy matching and alias detection. Not a separate workflow, not an add-on fee, and no vendor that slips through because someone forgot.
A match threshold you control
Set the minimum name-match percentage — anywhere from 50% to 95% — that flags a result as a potential match, and choose exactly which lists apply to your company account. False positives are a tuning problem, not a fixed vendor default you have to accept.
An audit trail you didn't have to build
Every validation, mismatch, outreach send, correction received, and revalidation result is logged per vendor with a timestamp. The documentation that supports 972CG reasonable cause abatement exists before you need it.
Real-time, bulk, and TIN matching API — all included
Same validation engine, same audit trail, whichever entry point your team uses.
-
Web portal Validate individual records on demand. No IRS enrollment, no per-user limits, operational the same day you sign up.
-
Bulk validation Upload the full vendor population for Q4 pre-filing cleanup, post-migration checks, or vendor master remediation. No reformatting, and the output is a categorized exception report with outreach ready to launch.
-
API integration Embed matching in your ERP, onboarding platform, or payment authorization flow so validation runs at the point of data entry — bad data caught before it's written.
-
Automated remediation Mismatches route into W-9 correction workflows on their own. Corrected W-9 triggers revalidation, record updates on confirmed match, cycle closes without manual work.
curl -X POST "https://www.tincomply.com/api/v1/validate/irs-tin-name-matching" \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"tin": "123456789",
"name": "ACME SUPPLY CO"
}'
# response
{
"id": "ZfPjt...",
"irsTinNameMatchingResult": {
"message": "TIN and Name combination matches IRS EIN records",
"result": 7,
"completed": true
}
}
TIN matching software vs. the IRS's free program
The IRS tool is free and it works. If you validate a handful of vendors a year, use it. The gap shows up at volume, on mismatches, and when someone asks you to prove what you did.
| Capability | IRS TIN Matching (e-Services) | TIN Comply |
|---|---|---|
| Getting started | e-Services registration plus identity verification before first use. | No IRS enrollment. Most teams validate the same day they sign up. |
| Interactive checks | Up to 25 name/TIN combinations per session. | No per-session or per-user limit. |
| Bulk | Up to 100,000 per file, results generally within 24 hours, in a fixed file format. | Excel, CSV, TSV or delimited, no reformatting, categorized exception output. |
| Result detail | Numeric result code. | Code, plain-language cause, and the specific correction to request. |
| Duplicate submissions | 96-hour account lockout when duplicates are detected. | De-duplicated before submission, so lockouts don't happen. |
| Sanctions / OFAC screening | Not part of the program. | Over 330 lists screened in the same call, every time, with a match threshold you set. |
| W-9 correction workflow | Not available. | Automated outreach, guided vendor portal, automatic revalidation. |
| Audit trail | Whatever you save and organize yourself. | Timestamped per vendor, automatically, built for 972CG abatement. |
Questions AP and tax teams ask before they switch
What is IRS TIN matching?
It confirms that a taxpayer identification number and the legal name you have on file match the IRS's records before you file an information return such as a 1099. It's the same check the IRS runs when it processes your filing — so running it first lets you find and fix mismatches before they become CP2100 notices, B-Notice obligations, or §6721 penalties.
Can I do IRS TIN matching myself for free?
Yes. The IRS offers a free TIN Matching program through e-Services to authorized payers. It requires enrollment and identity verification, limits interactive checks to 25 name/TIN combinations at a time, and returns bulk results in roughly 24 hours.
What it returns is a numeric result code — no cause, no correction workflow, no sanctions screening, and no audit trail. TIN Comply runs the same IRS check with no enrollment, adds the likely cause and recommended action, and automates the correction loop. See the side-by-side comparison above.
Why would a TIN and name not match IRS records?
The usual suspects: a DBA or trade name submitted instead of the IRS-registered legal name, a missing or incorrect entity suffix, a name change never updated with the Social Security Administration, a sole proprietor or single-member LLC supplying the wrong TIN type, or a transposed digit in the TIN.
Most of these are input problems, not fraud — which is why a guided W-9 with plain-language field instructions prevents more mismatches than any amount of downstream cleanup.
What is a CP2100 notice?
A CP2100 or CP2100A is the notice the IRS sends a payer listing the information returns where the payee name and TIN didn't match. Each listed payee triggers a B-Notice obligation — generally sending the payee a B-Notice within 15 business days and starting 24% backup withholding if they don't supply a valid TIN.
What's the penalty for filing a 1099 with an incorrect TIN?
Under IRC §6721, penalties are tiered by how fast the error is corrected. For returns required to be filed in 2026 that's approximately $60 per return corrected within 30 days, $130 per return corrected by August 1, and $340 per return after that or not corrected at all. Intentional disregard carries a higher penalty with no annual cap.
These amounts are indexed for inflation annually — confirm current figures against IRS Publication 1586 before relying on them for a specific filing year.
When should I run TIN matching?
Three points. At vendor onboarding, before the first payment, so bad data never enters the vendor master. In bulk during Q4, across the full vendor population, ahead of January deadlines. And on every corrected W-9, to confirm the correction actually resolves before you accept it.
What is the IRS 96-hour lockout, and how do I avoid it?
The IRS locks a TIN matching account for 96 hours when it detects duplicate submissions — including accidental ones, like two people checking the same vendor or two batch jobs overlapping. TIN Comply de-duplicates before anything reaches the IRS, so a routine internal mistake doesn't take your validation offline for four days.
Where each of these actually earns its keep
Validation is not a January activity. The work that keeps a filing season quiet is spread across the year, and most of it happens long before a return is due.
| When | What is happening | What TIN Comply is doing |
|---|---|---|
| Year-round | New vendors onboarded | API validation at the point of entry, so a mismatch never reaches the vendor master |
| Early October | Pre-filing validation of the full population | Unlimited records in any format, results back the same day, no duplicate lockout risk |
| October – November | Correction outreach on exceptions | W-9 requests triggered from the result code, so each vendor is asked for the right thing |
| November – December | Corrected W-9s coming back | Automatic revalidation — a record only clears on a confirmed match |
| January | 1099 filing | Every combination IRS-confirmed before it goes on a return |
| Spring | CP2100 arrives | Per-vendor history shows whether this is a first or second B-Notice |
| On a 972CG | Penalty response, 45-day clock | The outreach and revalidation record is already built — nothing to reconstruct |
The pattern worth noticing: everything that makes spring easy was done in October. Work a CP2100 →
Tools you can use before you talk to anyone
If you're mid-notice or just checking a file format, start here. No signup, no sales call.
The rest of the vendor validation stack
Start validating in minutes
No IRS enrollment. No per-user limits. Portal, bulk, and API all included — and every validation carries sanctions screening and an audit trail with it.
Most teams are running live validations the same day they sign up.