ShareFile

Knowledge-Based Authentication (KBA)

The purpose of this article is to improve compliance with relevant industry regulations.

How is KBA enabled on a document?

Enabling the KBA setting is done on a per document basis. To do so, set up a document as normal and on the last section before clicking the Send Document button, you can select the KBA Off option. Then check Enable and this will make it say KBA On. The Passcode option cannot be used in conjunction with KBA.

KBA 1

The Document Sender needs to enter the recipient’s Legal Name when sending the document and the signer must have a Social Security Number.

Update

Starting May 30th, 2022, KBA can be enabled for documents sent via the public API endpoints reusable_template/send_document and sending_requests. API documentation: https://api.rightsignature.com/documentation/getting_started

How is a KBA-enabled document signed?

The recipient will receive an email as normal. Once they click on the link, they will be brought to Identity Verification Step 1 of 2.

KBA 2

BlockScore will verify the information and generate some identity verification questions. Once all the areas are filled in, the recipient will click Submit.

Note: The Country field is limited to 2 characters.

KBA 3

The Identity Verification Advisory reads:

KBA 4

Can the signer get locked out of the document?

Yes, after 3 unsuccessful attempts to verify their identity, the recipient will be locked out. They receive the following message:

KBA 5

The Document Sender will have an option to unlock the document, however this may not meet the IRS guidelines.

KBA 6

The sender receives this warning:

KBA 7

Audit Log

Once the signer successfully verifies their identity and signs the document, the authentication will be listed in the document’s History.

KBA 8

It will be noted on the audit log of the Signature Certificate as well.

KBA 9

FAQ

What does KBA stand for and what is it?

“KBA” is an acronym for Knowledge-Based Authentication. RightSignature’s KBA feature gives document senders the ability to enable knowledge-based authentication on a RightSignature document, effectively requiring the signers to verify their identity via a set of personal questions about the signer’s identity before access to the document itself is granted.

The KBA feature was developed to support the identity verification requirements of the IRS guidelines on collecting electronic signatures on Forms 8878 and 8879.

Where can I find more information on the IRS guidelines for collecting electronic signatures on Form 8878 and 8879?

https://www.irs.gov/e-file-providers/frequently-asked-questions-for-irs-efile-signature-authorization

Knowledge-Based Authentication (KBA)