The Internal Revenue Service maintains a dedicated administrative remedy for businesses whose federal tax identifiers have been used without authorization. Form 14039-B, the Business Identity Theft Affidavit, allows businesses, trusts, estates, and tax-exempt organizations to formally report suspected tax-related misuse of their identifying information, according to guidance published by the Internal Revenue Service.

The existence of standing federal infrastructure for this harm establishes business identity theft as a recognized and recurring administrative problem.

One form of corporate identity theft operates through a specific mechanism. A party obtains the name, EIN, and enough contextual information to plausibly present as an existing business, then contracts under that identity with a counterparty performing ordinary onboarding procedures.

Transactions execute and records generate for which the actual entity was never present and about which it may have no contemporaneous awareness.

The harm surfaces later, often through tax notices to the impersonated entity or through credit, contractual, or reputational consequences that materialize after the underlying transactions closed.

Ordinary counterparty diligence does not necessarily prevent this outcome. Where the impostor presents identifiers that correctly correspond to a real entity, a registry check can authenticate the entity without authenticating the presenter's authority to act for it.

The pattern is neither novel nor confined to tax administration. The IRS continues to maintain business identity theft procedures, while business email compromise represents an adjacent rather than identical impersonation problem. In 2025, it remained among the highest-loss categories reported to the FBI Internet Crime Complaint Center.

What distinguishes corporate identity theft from many adjacent categories is that the harm can attach to a party who is not present in the transaction. This party may have no contractual, technical, or procedural channel through which to be notified that its identity is being used.

The structural limits of counterparty verification


  • Corporate identity theft can operate by presenting under an existing entity's name and EIN, generating fraudulent transactions and records the actual entity never authorized or attended.
  • B2B counterparty diligence produces bounded findings under procedures that vary by sector, transaction, and risk, rather than verifying counterparty identity to any evidentiary standard adjacent to certainty.
  • Signer authority verification requires an independent reference connecting the presenter to the entity. Public formation records do not always provide that reference, and beneficial ownership is not equivalent to authority to bind the entity.
  • The IRS maintains Form 14039-B as a standing Business Identity Theft Affidavit and continues to direct businesses to it for specified forms of tax-related identity misuse.
  • Consequences for the impersonated entity can distribute across tax reporting, reputational, litigation, credit, banking, and regulatory surfaces operating on independent timelines and requiring separate remediation.
  • A diligent counterparty can bear direct financial loss, reputational damage, downstream contractual exposure, insurance questions, and governance consequences even where its ordinary verification controls operated as designed.

What counterparty diligence actually verifies


Business-to-business counterparty diligence is intended to produce a defensible procedural record proportionate to the transaction and its risks. There is no single cross-industry standard. The practice instead decomposes into layers, each generating bounded findings against a particular claim rather than a comprehensive judgment about the counterparty's legitimacy.

Legal existence and registry status represent the most tractable layer. Secretary of State registry lookups or their equivalents in other jurisdictions can confirm that an entity appears in the official register and report its current recorded status.

Sanctions screening against lists maintained by the Office of Foreign Assets Control provides another comparatively structured check, but not a simple deterministic one. Screening must account for identifiers, aliases, ownership, and applicable sanctions rules. Under OFAC's 50 Percent Rule, for example, an entity can be blocked through ownership by blocked persons without itself appearing by name on the SDN List.

Beyond these checks, verifiability degrades. Beneficial ownership information, operational reality assessment through address and business-presence verification, litigation history through court dockets, and Uniform Commercial Code filings indicating asserted security interests all require interpretation and may be incomplete.

Trade references, bank references, and prior counterparty testimony add dimensions the documentary layers do not capture, and introduce their own gameability.

Commercial know-your-business tooling can aggregate many of these layers into consolidated reports or risk assessments. Depending on the provider, it may draw on registry data, sanctions lists, adverse media, credit information, payment data, and other proprietary sources.

These outputs support onboarding decisions but do not constitute proof that the presenter is legitimate. Across much of the stack, a clean result establishes that no relevant inconsistency or adverse evidence was detected within the sources searched.

The 2020 collapse of Wirecard AG illustrated the broader durability of this asymmetry, although Wirecard was an accounting fraud rather than an identity-theft case. The German payments processor received unqualified audit opinions before the discovery that approximately 1.9 billion euros it claimed to hold in trustee accounts could not be located. The episode demonstrated that highly scrutinized institutional records can remain internally coherent even while material underlying facts are false, a failure documented by European securities regulators and the Financial Times Wirecard investigation.

Signer verification and its structural dependency


One layer of this stack warrants specific attention because its failure mode differs from the others. Signer verification asks two related but distinct questions: whether the human presenter is who that person claims to be, and whether that person is empowered to bind the entity.

Government-issued identification can address the first question without resolving the second. A corporate resolution or certificate of incumbency can address the second, but only to the extent that the counterparty has some independent basis for authenticating the document or the authority behind it.

Publicly filed officer, director, manager, or similar records can provide such an external anchor where the relevant jurisdiction and entity type make them available. Their availability and content vary substantially, and beneficial ownership records answer a different question from signer authority.

Where public formation records do not disclose the individuals controlling or managing an entity, a registry search cannot by itself distinguish a legitimate representative from an impostor presenting accurate information about the entity.

This does not make signer authority impossible to verify. It removes one independent reference and forces the counterparty to establish another through means such as an independently sourced contact channel, outside counsel, a known banking relationship, authenticated corporate records, or another trusted intermediary.

The structural failure arises where every document and every communication channel used to establish authority originates with the presenter. At that point, additional self-attestation can become circular rather than independent verification.

Privacy-preserving entity structures also have legitimate uses including asset protection, personal safety, and competitive confidentiality. The verification consequence arrives at the counterparty regardless of the reason an entity's ownership or management information is not publicly exposed.

The Corporate Transparency Act was enacted to improve government access to beneficial ownership information for illicit-finance and law-enforcement purposes, not to create a public signer-authority registry. The information system administered by the Financial Crimes Enforcement Network was designed as a non-public database with access limited to specified government users and, under defined conditions, financial institutions.

Its implementation has since changed substantially. On August 11, 2026, FinCEN issued a final rule permanently removing beneficial ownership reporting requirements for U.S. companies and U.S. persons. Certain foreign entities registered to do business in the United States remain subject to reporting requirements for foreign beneficial owners.

The distinction matters to the structural argument. Beneficial ownership disclosure can support an investigation into who ultimately owns or controls an entity, but it does not by itself establish that a particular employee, officer, agent, or contractor has authority to execute a particular transaction.

Any regime that leaves a counterparty without an independent channel for authenticating that authority reproduces the same verification gap unless private controls create one.

Standard procedures for entity and signer verification


There is no single generally applicable sequence for entity and signer verification across American commerce. Regulated financial institutions provide the clearest codified example. The Federal Financial Institutions Examination Council Bank Secrecy Act and Anti-Money Laundering examination manual describes customer identification, customer due diligence, and beneficial ownership requirements for banks, while ordinary commercial counterparties frequently use some analogous controls without being subject to the same regulatory framework.

Entity-level verification commonly begins with primary source confirmation of formation and current registry status through the relevant Secretary of State or equivalent jurisdiction registrar.

Tax-identifier matching is available in narrower circumstances than a general counterparty-verification service. The IRS Taxpayer Identification Number Matching program permits eligible payers and their authorized agents to compare payee name and TIN combinations with IRS records before filing specified information returns. It is not a generally available service through which any business can validate an arbitrary counterparty's EIN.

Physical presence verification, address confirmation, domain and contact verification, and third-party data augmentation through commercial providers can add operational corroboration to the registry record.

Signer-level verification requires additional evidence. Corporate resolutions, certificates of incumbency, delegations of authority, and similar internal records are commonly used to identify individuals permitted to execute specified categories of transactions.

Cross-referencing the named signer against publicly filed officer, director, manager, or other control records, where available, can provide an external check on the internal document. Government-issued identification can authenticate the individual. Email domains and telephone contacts are more useful where they are independently sourced rather than supplied solely by the presenter.

Notarization can strengthen evidence that a particular person signed an instrument or acknowledged a signature, but it does not by itself establish that the signer possesses corporate authority or that the underlying corporate representations are true.

The framework therefore depends less on the existence of any particular public record than on the availability of evidence independent of the presenter. Public ownership or management information can provide one such anchor, but privately authenticated records, known contact channels, counsel confirmation, or other trusted relationships can serve the same function.

Where no public disclosure is available, the chain does not necessarily terminate at the entity's own attestation. It terminates there only if the counterparty has no independent path through which to authenticate that attestation.

Interim measures available to counterparties in this posture include requiring an opinion letter from the entity's outside counsel affirming the signer's authority or conducting an out-of-band confirmation through independently obtained entity contact information.

Escrow arrangements, performance bonds, and tiered exposure limits scaled to documented operating history address a different part of the problem. They do not verify identity or authority, but can reduce the financial consequences if verification fails.

Independent third-party attestations and references can likewise shift part of the evidentiary burden to parties positioned to confirm underlying facts under professional or commercial responsibility. This is a different mechanism from verification against an authoritative public record.

Consequences for the impersonated entity


The impersonated entity may discover fraudulent activity through downstream administrative or reputational channels rather than through the transaction itself. Tax reporting is among the most legible surfaces.

Current IRS guidance instructs businesses to report suspected identity theft where, among other indicators, they receive notice of a tax return they did not file, Forms W-2 they did not file, a balance due they do not owe, or an EIN associated with a business they did not establish. The IRS also recognizes cases in which income or payments are reported to an EIN even though the business did not receive them.

Responding requires the impersonated entity to establish that the filing or activity was unauthorized and correct the resulting tax record. Repeated misuse can cause the remediation process to cross more than one tax period.

Reputational exposure attaches where an impostor defaults on obligations, delivers deficient work, or engages in conduct that becomes publicly associated with the impersonated name. The resulting confusion may persist after official records have been corrected.

Litigation exposure can arise where the impersonated entity is named in disputes originating from transactions it never authorized, requiring it to establish the absence of a contractual relationship and potentially incur defense costs before the matter is resolved.

Credit and banking consequences can follow where financing or accounts are opened under misappropriated business information. The existence of a separate identity-theft process at the Small Business Administration for unauthorized SBA funding illustrates how the same identity can generate obligations outside the tax system.

Regulatory exposure can emerge where the fraudulent activity occurred in a licensed or supervised space and regulators initially associate the conduct with the real entity. Business opportunity cost accrues throughout remediation as organizational bandwidth is redirected toward correcting records and responding to third parties.

These surfaces can operate independently. A single impersonation event can produce parallel harm streams that surface at different times and require remediation through different administrative, commercial, or judicial channels.

Consequences for the diligent counterparty


The counterparty that contracted in good faith with an impostor may bear direct financial loss on the failed transaction, beginning with the specific commercial exposure of the engagement.

Reputational damage from public association with a fraud event is more diffuse. This is particularly relevant in sectors where counterparty selection itself functions as a market signal.

Downstream contractual exposure follows where the counterparty incorporated, resold, or relied on the impostor's outputs and still owes performance to its own customers.

Regulatory exposure can attach where the actual actor behind the impersonation was a blocked or otherwise prohibited party. OFAC may impose civil penalties for sanctions violations under a strict-liability standard, meaning lack of knowledge does not necessarily eliminate liability, although the surrounding facts and the quality of a compliance program remain relevant to enforcement.

This exposure can therefore exist even where sanctions screening technology functioned as designed, because the identifiers supplied to the screening system belonged to the impersonated entity rather than the actual actor.

Insurance consequences depend on the facts and policy language. A significant impersonation incident may trigger coverage or notification questions across policies addressing professional liability, cyber risk, or corporate governance.

Internal governance consequences may follow through board, audit committee, or management review of the process that failed, particularly where losses are material or the verification process is alleged to have fallen below applicable standards.

Disclosure obligations to investors, lenders, insurers, or acquirers may also be implicated by securities law, financing agreements, acquisition documents, or other contractual provisions depending on materiality and the terms involved.

Even a counterparty that executed ordinary diligence correctly can face these consequences. Business email compromise is not the same fraud mechanism, but it demonstrates the scale at which identity and communications substitution can undermine otherwise legitimate commercial processes. The FBI Internet Crime Complaint Center recorded roughly $3 billion in reported Business Email Compromise losses in 2025, making it one of that year's highest-loss complaint categories.

The Missing Reference


The diligence framework does not automatically create a channel back to the impersonated party. Unless the process includes an independently sourced contact path to the entity being represented, the entity may remain outside the transaction and unaware that its identity is being used.

The coverage boundary of ordinary diligence sits primarily at the parties and information presented for the transaction. The impersonated entity can sit outside that boundary by construction.

Better execution within the existing framework can reduce the risk but does not automatically close it. Independent callbacks, authenticated authority records, trusted third-party confirmation, staged exposure, and other controls can make substitution more difficult, but each depends on the counterparty having access to some reference that did not originate with the impostor.

The harm class therefore can distribute across multiple parties operating in good faith without corresponding neatly to the failure of any single checklist control.

Naming the specific structural gap around signer verification where an independent reference is absent is the first condition for constructing a remedy. This remedy could take the form of policy reform, modification of industry-standard practice, or verification infrastructure that surfaces the missing reference through mechanisms other than public registry disclosure.

Until the gap is named as a category rather than absorbed into the general vocabulary of counterparty risk, ordinary diligence can continue to produce procedurally reasonable decisions while leaving a material form of substitution risk unresolved.

Sources


Article Credits