The Password That Kills Your Own Defence

This article will count 0.25 units (15 minutes) of unverifiable CPD. Remember to log these units under your membership profile.

It is 4pm on the 25th. Your client cannot get into eFiling and the VAT201 is due. Someone in your office types the message that will eventually sit in a complaint file: Do you have the SARS login details, and can you send the OTP that comes through?

The client sends both. The return goes in on time. It is correct. Nobody thinks about it again.

Eight months later the client lodges a complaint, and you find out that the fifteen minutes you saved cost you the only evidence that would have cleared you.

SARS already told us not to do this

This is not new guidance. SARS reminded practitioners to work from their own tax practitioner profile, and we covered it here in Important Update for Tax Practitioners: Use the Correct eFiling Profile. The message was blunt. Use your own profile. Use shared access. Do not work through the client’s login.

What that notice did not spell out is why breaking the rule hurts you more than it hurts SARS.

So let us do that properly.

This is a rule, not a courtesy

When you registered for eFiling you accepted a set of terms. Those terms are not website decoration. They carry the weight of rules SARS is empowered to make under our tax administration law, and they bind everybody who uses the site, your client included.

Two things in them matter here.

The first is that whoever holds an eFiling login has to keep the username and access code confidential. Not confidential from SARS. Confidential, full stop. And if that login is ever disclosed to somebody who should not have it, the disclosure has to be reported to SARS straight away and confirmed in writing within a day.

Read that last part again. The moment the credentials leave your client’s hands, a reporting obligation is triggered. It does not switch off because the recipient was the client’s own accountant. And if you asked for them, you are the person who caused the disclosure.

The part that should actually worry you

Most practitioners hear do not share passwords and think about SARS catching them. That is the wrong fear.

The second thing in those terms is the one that costs practitioners their practices. Responsibility for everything filed through a login sits with the person that login belongs to.

Think about what that means for your file. When you work inside your client’s profile, every action on that profile is recorded as your client’s action. There is no entry against your user ID. No timestamp that points to you. No permission log showing what you were authorised to touch.

So when the client says you filed a return without instruction, you cannot show what you filed.

When the client says you never filed at all, you cannot show that you did.

When the client says you changed the banking details, you cannot show who did.

A borrowed password does not create a risk that SARS catches you. It creates a risk that you cannot defend yourself when a client turns on you. Those are very different risks, and the second one is far more likely to walk through your door.

The document you are already supposed to have

SARS expects a registered tax practitioner to hold a written mandate from each client, and to give SARS a copy of it. The mandate has to set out what the client actually authorised you to do, and it has to record the client’s acknowledgement that the tax liability stays with them. If the arrangement changes, SARS expects a fresh mandate within three months.

When did you last look at yours? Pull three client files at random this week and check. A message containing a password is not a mandate. An engagement letter that says nothing about eFiling authority is not a mandate either.

There is a commercial point here that gets missed. That mandate is the cheapest liability control your practice can hold. It records, in your client’s own words, that the tax liability stays with the client. Practitioners who have it on file settle fee disputes faster and defend complaints better.

It is usually not the practitioner who asks

Here is the uncomfortable pattern. In the complaints that reach a disciplinary committee, the request for credentials very often did not come from the registered practitioner at all. It came from an administrator or a junior, under deadline pressure, who had never been told the rule.

That is not a defence. Your controlling body is required to run a code of professional conduct and a disciplinary process, and you answer for the conduct of the practice carried on under your direction and supervision.

My bookkeeper asked for it, not me, is not an answer to the allegation. It is an admission of a supervision failure, and that is often the worse of the two findings.

If the rule only exists in your head, your practice does not have the rule.

What is actually at stake in your registration

Our tax administration law sets out when a person may not be registered as a tax practitioner, and when SARS has to take an existing registration away. In plain terms, this is what sits behind the word deregistration.

You have to be registered twice. With a recognised controlling body, and with SARS. The window is short, twenty one business days from the first time you advise a client or complete a return. CIBA membership on its own is not compliance.

Dishonesty convictions end it. Theft, fraud, forgery, perjury, corruption offences, or a serious tax offence. Conviction and sentence means SARS deregisters you, and after that no controlling body may register you for five years.

Your own tax affairs can end it. Sustained non-compliance, roughly half of the preceding year, combined with failing to fix it after SARS gives you notice. Both parts are needed, not one. SARS has published worked examples showing how it counts the months.

SARS does not have to come to you first. A senior SARS official can take your conduct straight to your controlling body, and that body is then obliged to report back to SARS on what it did about the complaint. CIBA reports back.

Now read the ladder correctly. A single credential request will not, on its own, get you deregistered. Nobody loses a registration over one message.

The reason to take it seriously is that it almost never arrives alone. It arrives attached to a complaint about a return that was not filed, a refund that landed in the wrong account, or a fee charged for work that was not done. And in that bundle, the credential allegation is the one with no available defence. It is the allegation that costs you credibility on everything else in the file, including the parts you could otherwise have won.

The fix takes four minutes

Your client logs into their own profile. They select User, then Invite User, enter your South African ID number and surname, and assign your permissions from their side. Individual taxpayers can use Obtain Full Shared Access, which gives the taxpayer and the practitioner full and equal access to the relevant tax types.

You then work from your own profile, under your own user ID, generating your own audit trail. Your client keeps sight of their own affairs. Nobody loses anything except the risk.

If the File Return button is missing after you set this up, you probably still need to activate your practitioner status against that taxpayer. We covered the fix in Missing the ‘File Return’ Button?.

For company and trust clients, check who is loaded as the registered representative. That role controls authentication prompts, tax type transfers, and the authorisation of new practitioners. If it sits with your firm by default rather than with a director, public officer or trustee, you are carrying authority you should not be carrying. This is the same weak-access-control problem the Office of the Tax Ombud flagged when it investigated profile hijacking, and its findings put tax practitioners among the most frequent targets. We reported on that in eFiling Profile Hijacking: Tax Ombud Sounds Alarm.

Turn it into something you can bill

Here is the part your competitors will not do.

Package this as an annual eFiling access and mandate review. You check the registered representative, you confirm shared access is properly configured, you refresh the written mandate, and you give the client a one-page report confirming who can do what on their profile.

For a construction client with retention, progress payments and subcontractor invoices, or a transport operator claiming diesel refunds, that report is worth real money. It is the difference between an adviser and a pair of hands. And any client who has watched a refund disappear into somebody else’s account will pay for it without argument.

You are not doing extra admin. You are selling control.

Do these five things this week

1.   Put a written eFiling mandate on file for every client. It must state what the client authorised you to do and record that the tax liability remains theirs.

2.   Send one written instruction to every person in your practice: we do not ask for, and do not accept, a client’s eFiling password or OTP. No exceptions for deadlines.

3.   Split your client list into clients you access by shared access and clients you access with borrowed credentials. Migrate the second group.

4.   Check the registered representative on every company and trust client, and move it where it belongs.

5.   If credentials have already been shared, that disclosure is reportable. Deal with it now, in writing, rather than when a complaint is already open.

Your client’s password is not access. It is the removal of your only proof that you did the job properly.

Join CIBA and we will show you how to turn access controls and mandates into billable advisory work instead of unpaid risk.

Where to check this yourself

The eFiling terms and conditions are published on the SARS website, and SARS’s Tax Practitioner Readiness Programme deals with profile use, user permissions and client mandates directly. If you want to work through the specific provisions and what they mean for your practice, CIBA’s CPD ethics session covers them in detail.

Further Reading

Important Update for Tax Practitioners: Use the Correct eFiling Profile – SARS’s own reminder on portfolio types and why you work from your practitioner profile, not the client’s.

eFiling Profile Hijacking: Tax Ombud Sounds Alarm, Calls for Public Input – Why weak access controls put practitioners at the front of the queue, and what the Ombud recommended.

Navigating the Tax Practitioner Readiness Programme with CIBA – Covers password sharing, user permissions, Power of Attorney, and the difference between RCB membership and SARS registration.

Tax Ethics: Stay Compliant, Protect Your Practice, and Get Paid – How ethical discipline becomes a pricing and positioning asset rather than a cost.

Missing the ‘File Return’ Button? – The practical fix when shared access is set up but you still cannot file.

 

Trending


Latest Podcast



Heynes Kotze, Head of Legal, Chartered Institute for Business Accountants (CIBA)

Head of Legal, Chartered Institute for Business Accountants (CIBA)

Next
Next

Why Ethical Members Report Themselves First