US accounts payable still chases W-9s in email. The form should ask a contractor or vendor to send a completed IRS Form W-9 as a file or a link—without providing a Social Security number field on your public site. The IRS form already has the TIN. Your webpage should not duplicate it in plain text.
Access limited to finance.
The pack already marks file required.
Do not use this for UK Right to Work or bank details.
Follow your 1099 retention schedule.
IRS Form W-9 is how a US person (or entity) gives a payer their taxpayer identification number so 1099 reporting can happen. A ‘W-9 request form’ on your site is not a substitute W-9. It is a delivery mechanism: name, email, and the completed PDF (or a link to it in a locked Drive folder).
UK payees do not complete W-9s. If you also pay UK suppliers, send them a separate vendor process for bank and VAT details—not this page.
If you add an SSN input, you have created a phishing-shaped page. Do not do that.
Store W-9s with the same care you give tax records. A public thank-you page should not echo the file back in HTML.
Bill.com and Airbase request W-9s inside a vendor portal. Everyone else is in Gmail.
Unlisted URL sent to the payee. Notifications to ap@.
Best when you pay hundreds of 1099 contractors.
TINs in inboxes forever. Worse than a dedicated form with retention.
Still valid. Scan into the same record once it arrives.
Host this on an unlisted path. Link it from the vendor welcome email, not from the public footer.
State that you will never ask for SSN in a chat message or a custom text field. The official W-9 PDF is the only TIN container you want.
Public HTML fields that collect SSNs are a gift to attackers and a policy failure. The W-9 PDF already captures TIN. Do not duplicate it.
No. It delivers the official form as a file. Link the current IRS W-9 instructions on the page.
They generally do not file W-9. Use vendor onboarding and tax advice appropriate to non-US payees.
Do not pre-fill tax IDs into HTML. Let them complete the IRS PDF.