IMF Identity Check - AM IDT Toll-Free (App 161/162) Telephone Overview
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
When taking calls from impacted individuals, a consistent and proper greeting is required. Refer to procedures in IRM 21.1.1.4, Communication Skills.
Employees are required to authenticate callers to ensure the person calling is the individual impacted by the data breach. See IRM 25.23.12.2, Identity Theft Telephone General Guidance, and IRM 10.10.3, Centralized Authentication Policy – Centralizing Identity Proofing for Authentication Across All IRS Channels, for required use of the Integrated Automation Technologies (IAT) Disclosure tool and the High-Risk Authorization (HRA) IAT tool to perform authentication; IRM 21.1.3.2.3, Required Taxpayer Authentication; and IRM 21.1.3.2.4, Additional Taxpayer Authentication.
If the caller is not the impacted individual, but claims to represent the individual, determine whether the individual provided a Power of Attorney (POA) in connection with the data breach. Do not recognize a representative when the POA on file identifies tax matters but doesn’t specifically identify the data breach as a matter for which the POA has authority.
High-risk authentication per IRM 21.1.3.2.4, Additional Taxpayer Authentication, and IRM 10.10.3 , Centralized Authentication Policy – Centralizing Identity Proofing for Authentication Across All IRS Channels, is also required. Ask the caller for the Breach Number and the Breach Date from Letter 4281C, IM Breach Notification Letter, as part of the authentication process.
The Breach Number is located to the right and just above the Salutation (Dear Taxpayer) on Letter 4281C, and
The Breach Date, if included in the letter, is located in the first paragraph of Letter 4281C.
Get a plain-English answer with a citation back to this text.
Ask AI about this code