- 10.10.2 Authentication Risk Assessments in Non-Digital Channels
- 10.10.2.1 Program Scope and Objectives
- 10.10.2.1.1 Background
- 10.10.2.1.2 Authority
- 10.10.2.1.3 Roles and Responsibilities
- 10.10.2.1.4 Program Management and Review
- 10.10.2.1.5 Program Controls
- 10.10.2.1.6 Terms and Acronyms
- 10.10.2.1.7 Related Resources
- 10.10.2.2 Non-Digital Authentication Risk Assessments
- 10.10.2.2.1 Program Identification
- 10.10.2.2.2 Preparation
- 10.10.2.2.3 Categorize
- 10.10.2.2.4 Select
- 10.10.2.2.5 Implement
- 10.10.2.2.6 Monitoring
- 10.10.2.2.7 Assess
- 10.10.2.2.8 Authorization
Part 10. Security, Privacy, Assurance and Artificial Intelligence
Chapter 10. Identity Assurance
Section 2. Authentication Risk Assessments in Non-Digital Channels
10.10.2 Authentication Risk Assessments in Non-Digital Channels
Manual Transmittal
September 16, 2026
Purpose
(1) This transmits revised IRM 10.10.2, Identity Assurance, Authentication Risk Assessments in Non-Digital Channels.
Background
This policy applies to the assessment of risk(s) in the authentication process of telephone/voice, in-person, remote in-person, and correspondence exchanges of sensitive information with individuals in authenticated customer contact channels.
Material Changes
(1) IRM 10.10.2.1(1) Purpose statement updated for clarity and consistency.
(2) IRM 10.10.2.1(2) Objectives updated for clarity, update links and email address, removed NOTES.
(3) IRM 10.10.2.1.1(1) Background updated with clarity.
(4) IRM 10.10.2.1.2(1) Authority updated guidelines and regulation.
(5) IRM 10.10.2.1.3(5) Updated email address.
(6) IRM 10.10.2.1.5(1) Used plain language to explain the Program Control.
(7) IRM 10.10.2.1. Updated the definitions and correct IRM links.
(8) IRM 10.10.2.1.7(1) Updated the link to the revised Form 15295.
(9) IRM 10.10.2.2(2) Updated the link to the revised Form 15295.
(10) IRM 10.10.2.2.1 New section explaining Part 1 Program Identification of Form 15295 and how to complete.
(11) IRM 10.10.2.2.2 This section was completely updated for clarity and consistency.
(12) IRM 10.10.2.2.3 This section was updated for clarity and consistency.
(13) IRM 10.10.2.2.4 This section was updated for clarity and consistency.
(14) IRM 10.10.2.2.5 This section was updated for clarity and consistency.
(15) IRM 10.10.2.2.6 This section was updated for clarity and consistency.
(16) IRM 10.10.2.2.7 This section was updated for clarity and consistency.
(17) IRM 10.10.2.2.8 This section was updated for clarity and consistency.
(18) Editorial changes made throughout IRM reflect the revised changes to Form 15295, revised 5-2026, including changes for clarity, plain language, grammar, updates to titles, email addresses, website addresses, legal, and IRM references.
Effect on Other Documents
IRM 10.10.2, Authentication Risk Assessments in Non-Digital Channels, dated February 17, 2023 is superseded.Audience
The intended audience is executives and management officials responsible for setting authentication policy for taxpayers, representatives, and other third parties interacting with the IRS through non-digital channels, including telephone or voice, in-person, remote in-person, and correspondence channels.Effective Date
(10-01-2026)John J. Walker
Acting Chief Privacy Officer
Purpose. This policy applies to the assessment of risk(s) in non-digital customer contact channels and is known as the Non-Digital Authentication Risk Assessment (NDARA). Identity Assurance (IA) owns and provides oversight for the NDARA program by supporting efforts, coordinating meetings including a NDARA Working Group, collaborating with stakeholders, maintaining records in Microsoft Teams and SharePoint, and ensuring program compliance.
Every taxpayer interaction requires strong safeguards, including those that happen outside digital channels. The NDARA helps business units identify and reduce risk when authenticating taxpayers through telephone/voice, correspondence, in-person, and remote in-person interactions. When these interactions have an exchange of taxpayer information and require authentication, the processes need to be assessed on the Form 15295, Non-Digital Authentication Risk Assessment.
This IRM establishes the formal policy to communicate and define program responsibilities, provide resources, describe the steps and assessment process to help program owners identify risks, strengthen controls, protect taxpayer information, and authentication.
Objectives.
Establishes policy for assessing and documenting risk in authentication processes conducted through non-digital customer contact channels (telephone, in-person, remote in-person, and correspondence) where sensitive information is exchanged with individuals. A channel is the method a taxpayer, representative, or other third party uses to interact with the IRS on tax-related matters.
Establishes the NDARA process to ensure consistent risk assessment procedures are used across Business Units.
Provides a link to the Form 15295, Non-Digital Authentication Risk Assessment (NDARA) https://core.publish.no.irs.gov/forms/internal/pdf/f15295--2026-05-00.pdf
Establishes three-year frequency for completing the risk assessment.
Establishes time-frame for addressing deficiencies or risks identified during assessment process.
Applies National Institute of Standards and Technology (NIST) Risk Management Framework concepts to IRS authentication processes as a baseline for completing the NDARA.
Lists related resources for completing the risk assessment.
This risk assessment policy operates in conjunction with other review processes, such as System Security Plans (SSP), Privacy and Civil Liberties Impact Assessments (PCLIAs), Chief Risk and Control Office review, and regular operational review processes.
For determining whether an individual needs authentication, see also IRM 11.3.2, Disclosure of Official Information, Disclosure to Persons with a Material Interest, and IRM 10.5.1, Privacy and Information Protection, Privacy Policy.
This policy does not cover risk assessments for online interactions. For information about risk assessments of online services mail to:it.cyber.cpo.dira@irs.gov
Audience. The intended audience is management officials responsible for determining policy related to the authentication of taxpayers, representatives or other third-parties interacting with the IRS on non-digital channels (telephone/voice, in-person, remote in-person, and correspondence).
Policy Owner. Identity Assurance (IA), under Privacy, is the program office responsible for oversight, policies and procedures for Authentication Risk Assessments in Non-Digital Channels.
Program Owner. The Associate Director, Identity Assurance reports to the Director, Data Oversight and Records and the Chief Privacy Officer and is responsible for IA program oversight.
Primary Stakeholders. All organizations and business units who authenticate taxpayers, representatives or other third-parties over non-digital channels (telephone/voice, in-person, remote in-person, and correspondence).
Contact Information. To recommend changes or make any other suggestions to this IRM section, mail to: *PGLD IA Omni-Innovations
The IRS authenticates millions of individuals each year through telephone, online, in-person, remote in-person, and correspondence channels to ensure the individuals are who they claim to be. Taxpayers, representatives, and other third-parties use multiple service channels to interact with the IRS. The IRS must ensure its authentication processes are assessed for risk and those risks are appropriately addressed. The NDARA evaluates the risks associated with authentication through all non-digital service channels. This policy applies NIST Risk Management Framework concepts as the baseline for assessing program risks.
Relevant federal guidelines include:
National Institute of Standards and Technology (NIST) Digital Identity Guidelines SP 800-63
U.S. Code (USC) 6103 Confidentiality and disclosure of returns and return information
Federal Information Security Modernization Act (FISMA)
Privacy Act of 1974
Office of Management and Budget (OMB) Memoranda M-19-17, Enabling Mission Delivery through Improved Identity, Credential, and Access Management.
U.S. code section 6103 and confidentiality regulations and other Federal guidelines require the IRS to authenticate the identity of individuals with whom it exchanges sensitive but unclassified (SBU) information (including personally identifiable information (PII) and tax information), regardless of the channel. Management officials bear the responsibility to conduct risk assessments of factors, procedures, and processes used to authenticate taxpayers, representatives or other third-parties interacting with the IRS.
The Identity Assurance Associate Director, within Privacy, is responsible for the NDARA process.
Organization executives and management officials who lead programs described in this policy are responsible for these guidelines for continuous monitoring of new and ongoing authentication policies related to these channels.
Executives of each IRS organization are responsible for ensuring an NDARA is completed every three years for each of their respective programs related to these channels. Any risks identified should be documented, mitigated and monitored.
Each IRS organization is responsible for establishing internal processes for managing their risk assessment procedures and monitoring based upon this guidance.
A copy of approved assessments will be emailed to: *PGLD IA Omni-Innovations , for policy team review and coordination on any identified risks.
The Identity Assurance branch manages and reviews the Authentication Risk Assessments in Non-Digital Channels Program.
Management officials must assess the risks associated with authenticating taxpayers, representatives, and other third parties. Refer to Form 15295, Non-Digital Authentication Risk Assessment (NDARA). After submitting an NDARA for review, management officials must reassess their findings based on the status of identified risks and mitigation efforts. The reassessment timeframe depends on whether acceptable mitigations have resolved the identified risks. If all identified risks have been resolved, then the next NDARA must be completed within three years. If identified risks remain when the NDARA is submitted, then management officials must reassess the NDARA every six months until the risk mitigations are accepted and the risks are resolved.
When risk assessments are completed and signed, they become an official record and must be maintained in accordance with Document 12829, General Records Schedule (GRS) 5.7 Item 020. Each office is responsible for reports and audits identifying internal administrative program weaknesses and risks, mitigation action plans, corrective actions, tracking records, correspondence, and other records held by the office responsible for coordinating internal control functions including risks. Destroy records five years after no further corrective action is needed.
The tables lists commonly used terms and definitions:
Term Definition A3 A3 refers to authentication, identity proofing, authorization and access policies and capabilities across all service delivery channels (e.g., in-person, remote in-person, correspondence, and telephone/voice). Authentication The process of establishing or confirming that someone is the previously identified person they claim to be. Authorization The process that establishes the rights or privileges of users to interact with the IRS on behalf of themselves or others (e.g., businesses, individuals). Allows those users to exercise rights that have previously been established. Authorization is required for any person or business conducting IRS business on another person’s behalf (such as tax return preparers). Access The process of allowing an authenticated user to obtain information or perform actions. This is the process of enforcing the authorization decisions. It ensures that only authorized users can access specific resources based on their permissions. Access management determines the taxpayer’s identity and if the taxpayer has authorized access in accordance with policy. Channel The means by which IRS interacts with external stakeholders. Correspondence (mail, fax) Communications, through mail and fax. Digital Relating to, using, or storing data or information in the form of digital signals. Involving or relating to the use of computer technology. In-person/remote in-person In-person authentication to complete and/or request transactions. For example, a taxpayer requesting a transcript may visit an IRS site or through video conferencing, to provide in-person/remote in-person authentication with identification, such as a driver’s license. Information System A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. National Institute of Standards and Technology (NIST) The NIST is part of the Department of Commerce and promotes US innovations and industrial competitiveness by advancing measurement science, standards and technology in ways that enhance economic security and improve the quality of life. NIST defines technical requirements in areas of digital identity proofing, enrollment, authenticators, management processes, authentication protocols, federation, and related assertions. They also offer technical recommendations and other informative text as helpful suggestions. Non-Digital Correspondence, telephone/voice, in-person/remote in-person assistance. Omni-channel Omni-channel approach means having an enterprise-wide A3 environment that is streamlined, integrated, consistent, and accurate across digital and non-digital service channels such as phones and online. Operational Reviews Recurring reviews of programs performed at various operational and business unit levels. Personally Identifiable Information The information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual. [OMB A-130] Process A series of actions or steps taken in order to achieve a particular end. Process Owner The official responsible for oversight and management of a particular IRS process. Risk A potential event or condition that could have an impact or opportunity on the cost, schedule, business, or technical performance of an Information Technology investment, program, project, or organization. See IRM 2.109.2.1.6.1 , Risk, Issues, and Action Item Management Practices. Risk Assessment The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. System Any organized assembly of resources and procedures united and regulated by interaction or interdependence to accomplish a set of specific functions. Telephone / voice Enterprise Architecture approved telephone and voice channels for external communications. Threat Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Vulnerability Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. The table lists commonly used acronyms and definitions:
Acronym Definition DIRA Digital Identity Risk Assessment FTI Federal Tax Information IRC Internal Revenue Code IMD Internal Management Document NDARA Non-Digital Authentication Risk Assessment NIST National Institute of Standards and Technology OMB Office of Management and Budget PCLIA Privacy and Civil Liberties Impact Assessment: See IRM 10.5.1 Privacy and Information Protection, Privacy Policy PII Personally Identifiable Information RAFT Risk Acceptance Form and Tool SBU Sensitive, but Unclassified Information. See IRM 10.5.1 Privacy and Information Protection, Privacy Policy SME Subject Matter Expert SSP System Security Plan
The Non-Digital Authentication Risk Assessment Form 15295 may be accessed at https://core.publish.no.irs.gov/forms/internal/pdf/f15295--2026-05-00.pdf
Privacy Act of 1974 (as amended)
IRC 6103, Confidentiality and Disclosure of Returns and Return Information
NIST Special Publication 800-37, Risk Management Framework
GAO 15-593SP, A Framework for Managing Fraud Risks in Federal Programs
The National Institute of Standards and Technology defines a risk assessment as "the process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system. Part of risk management incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place."
Business Units use Form 15295 when conducting non-digital authentication risk assessments which was designed to assist with this process. The Non-Digital Authentication Risk Assessment Form 15295 may be accessed at https://core.publish.no.irs.gov/forms/internal/pdf/f15295--2026-05-00.pdf
Form 15295 is structured into sections that correspond to the steps in this IRM (Program Identification, Preparation, Categorize, Select, Implement, Monitoring, Assess, and Authorization). The following sections in this IRM explain what is needed to document the processes within each step/phase. The non-digital risk assessment process may begin at any of the steps described in this IRM. Where the risk assessment process begins will be dependent upon the reason for assessment. However, for any initial review under this policy, of either an existing process or a newly developed customer contact channel, the steps must be followed in order.
Provide the internal organizational name and code associated with the program/process being assessed
Select the non-digital authentication channel assessed from the following options:
Telephone/Voice
In-person
Remote In-person
Correspondence
Identify the program/process being assessed under this NDARA. The assessment is tied to the correct program and contact method, since risks vary by channel.
The purpose of this step is to prepare for the assessment by identifying information and resources needed to effectively evaluate risks.
Describe the business functions and processes supporting the exchange of information through non-digital customer contact channels where authentication is required.
Provide the name and email address of the individual(s) responsible. Examples of process roles and responsibilities may include Process Owners, Assessment Reviewers, Business Unit and Technical SMEs, etc.
List all policies, guidance, and resources that employees rely on when authenticating customers within the program.
Provide the date of either the most recently completed NDARA or another risk assessment, such as an assessment of digital channels.
During the past three years, if there were any findings, risks, or issues identified (e.g., fraudulent/false authentication, increase in improper disclosures, etc.) within this process, then select ‘Yes’, otherwise select ‘No’.
If you select “Yes,” identify and list the findings, issues, or risks, including related mitigations and implementation dates. The response must include the audit, study, or risk assessment number or name, a description of the findings, agreed-upon recommendations, and the estimated or actual completion dates.
If there is an active RAFT impacting the program’s authentication process, then enter ‘Yes’, otherwise enter ‘No’.
If ‘Yes’ is selected, then list the applicable risks identified and accepted, and its impact on the program.
The purpose of this step is to consider the components of the customer contact and categorize risks within the process accordingly.
Describe all data in the process required for authentication. There is no need to overly complicate data categorization, such as outlining each individual element of a tax return. A category of "return information" applies to all the data elements.
Identify the data disclosed to the taxpayer or representative (e.g., SBU data, FTI, PII, law enforcement, or non-sensitive items).
Classify the sensitivity of the information as low, medium, or high, and risks if improperly disclosed.
Assess for a low, medium, or high sensitivity designation which requires consideration of potential impacts of improper disclosure and the type of users accessing the data.
The purpose of this step is to select, tailor, and document the controls in place to mitigate any process risks. When identifying controls for the process, consider:
Example: An assessment of risks related to telephone/voice authentication may consider mitigations based on the reliability of an automated system that helps confirm the identity of a caller, based on telephone/voice service provider information.Examine generally accepted best practices.
Reviewing IRS, Treasury, NIST, OMB or legislative guidance specific to the channel.
Identifying industry best practices and tools.
How the authentication process affects, or is affected by, other customer contact channels which could provide support and, if appropriate, mitigate risks where there is overlap.
The availability of options to eliminate or mitigate a risk.
The cost of meeting the privacy and security requirements, compared to the cost of inadequate privacy and security.
Inconvenience, distress or damage to standing or reputation of the program.
The purpose of this step is to implement the selected controls and document their effectiveness. For the purposes of this risk assessment, the reviewer will be assessing the effectiveness of the implementation of controls identified in the select step.
Using the most current annualized data available, review annual trends from the previous three years to determine whether unauthorized disclosure rates have increased, decreased, or remained unchanged. Calculate the unauthorized disclosure rate by dividing the number of unauthorized disclosures by the total number of disclosures. For example, one unauthorized disclosure divided by 100 total disclosures equals a rate of 1%. Explain the process used to monitor error rates and regularly review performance.
The purpose of this step is to ensure continuous monitoring of the processes. Continuous monitoring should occur at a frequency matching the risk and sensitivity of information exchanged within the process.
Describe the activities the business unit performs, monitoring risks to ensure timely detection and proactive mitigation. Examples of continuous monitoring include regular risk reviews, key performance indicators (KPIs) to alert early warning signals, data analytics and reporting, periodic audits, quality reviews, etc.
Describe how results from monitoring activities are communicated to key process stakeholders.
Indicate if there are any automated systems or reports used for monitoring risks, identify report(s), system(s) and frequency of use.
The purpose of this step is to identify if the current procedures provide enough guidance and/or mitigate the risk, then identify the procedures and/or mitigation that ensure authentication is secure.
Determine if the policies and procedures governing the process are sufficient to address and mitigate risks or challenges for effective authentication. If it is determined that the policies and processes are effective, then enter ‘Yes’, otherwise enter ‘No’.
If the response to (2) is ‘No’, then describe procedures that will be reviewed and/or modified to address shortfalls, and the expected timeframe to address them. Examples of process modifications include implementing new technology, adjustments to existing procedures, or the development of new policies and processes. Document any deviations from acceptable levels of risk. Risk acceptance criteria should be based on the business unit’s risk tolerance.
After all mitigations are in place to address identified risks, determine whether any residual risk remains and whether the potential outcomes are acceptable to your program. Refer to your business unit’s risk management guidance for the program’s risk acceptance criteria. If the residual risk is acceptable, enter “Yes.” If the residual risk is not acceptable, enter “No.”
Use the following guidelines to determine the next assessment due date:
If the response in (4) is ‘Yes’, then the next risk assessment must be completed within three years of this assessment.
If the response in (4) is ‘No’, then the next risk assessment must be completed within six months of this assessment.
Obtain the required approvals for accepting the risk and save copies of the approved document following the organization's document retention rules.
Once this assessment is completed and signed, it becomes an official record and must be maintained in accordance with General Records Schedule (GRS) 5.7 Item 020. (Reports and audits identifying internal administrative program weaknesses and risks, mitigation action plans, corrective actions, tracking records, correspondence, and other records are held by the office responsible for coordinating internal control functions including risks. Destroy the assessment after five years if no further corrective action is needed).
Email the completed and signed form to *PGLD IA Omni-Innovations. In your email, include a brief message such as:
“Attached is the completed Form 15295, Non-Digital Authentication Risk Assessment, for your review.”