Skip to content

E-signatures

Your clients can sign PDFs in their portal: a T183 or T183CORP before you file, an engagement letter, a financial statements acknowledgement. They sign after signing in with their own password, with a code emailed to them as they sign. The signed copy comes back to the client's documents, stamped on every page, with a certificate that records who signed it, how and when.

E-signatures come with every plan.

Ask for a signature

  1. Upload the PDF to the client's portal, or find one that's there under Documents.
  2. Click the pen button beside it (Ask for a signature), or open it with Edit and click Ask to sign.
  3. Under Who signs, tick each person who signs. Only the client's contacts who can sign in to its portal are listed. The likely signers start ticked: the client themselves for an individual; for a business, the contacts whose role is signing authority, director or officer.
  4. Add a Message to the signer if you like, and a Needed by date.
  5. Leave Email them now on, and click Ask to sign.

Each person gets a request of their own, and signs on their own: each signed copy comes back separately, with the signer's name in its title when several people are asked. The document is shared with the client if it wasn't yet. Someone who signed it already is listed, but not ticked. With Only reviewers can share on in Settings › Portal settings, only reviewers can ask for a signature, as for sharing.

Some PDFs can't be signed: one that needs a password to open (save an unlocked copy), a dynamic (XFA) form or one whose form fields can look different from one viewer to the next (print it to PDF first), one that's damaged, one over 300 pages or 25 MB. The page says which, before anyone is asked. A PDF that already has a digital signature can be signed, but the page warns you: the signed copy is a new file, which won't keep that digital signature valid.

What your client does

  1. They open the email and click Review and sign, or find the document under Needed from you › To sign on their portal's overview.
  2. On the Sign page, they click Open the document and read it (Open beside the document in their list works too). Signing isn't possible until they've opened it. What opens is what the signed copy is made of: any form fields are drawn into the pages.
  3. They tick I agree to sign electronically (they can ask you for a paper copy instead) and I've read … and I sign it, then type their full name, in Latin letters. At a business they also give their title, like President. They can draw their signature too.
  4. They click Continue. A 6-digit code is emailed to the address they sign in with. It works for 10 minutes and 5 tries. A new one can be sent once a minute, up to 5 in an hour. They enter it and click Sign.

The code is asked every time someone signs, even if you turned off Email a code at sign-in. It goes to the address they signed in with when you asked them: if they changed their sign-in email since, no code goes, and they're told to ask you. Stop asking, then ask them again, at their new address.

If something's wrong with the document, they click Decline to sign and say why. You're emailed their note.

What you see

In the documents lists, a document waiting shows Waiting for signature, then Signed or Declined, with the signer's name. Documents counts what's Waiting for signature, and its filter also finds the Signed copies.

On the document's page, Signatures lists each signer with what happened: when they were asked and emailed, when they opened it, and when they signed. While a signature waits, Email again sends the request again, and Stop asking stops it. Making the document firm only, deleting it, or removing the signer's portal access stops the request too: the page says so. If the signer can't sign any more (their access was removed another way, or Clients can sign in is off), the request says why.

You're emailed when the client signs or declines: the people assigned to the client, and whoever asked.

The time for a T183

The signed copy's page shows when it was signed, at your firm, as the CRA writes it: Signed 2026/09/29 14:03:22 (America/Toronto). When the T183 was signed outside your tax software, TaxCycle or ProFile asks for that date and time before you file: click Copy and paste it there.

The certificate

The signed copy is a new document, "… (signed)", shared with the client. The original stays as it was. The signed copy has:

  • a footer on every page: Signed electronically by, the name, the time and a reference like FD-7K3Q9X;
  • a Signature and certificate page at the end, with the signature (typed, or drawn), the declaration they ticked, the document and its number of pages, who asked for it, the name the signer typed and their title, the person you asked to sign (whose portal account signed), how they were identified (their password, then a code emailed to them, and when they entered it), the words they agreed to about signing electronically, each step with its time in UTC and at your firm, their internet address and browser, and the SHA-256 fingerprint of the original.

A file can't hold its own fingerprint: the signed copy's SHA-256 is on its page in Firmdesk.

Form fields in the PDF are drawn into the pages as they looked, so the signed copy reads the same in any viewer. Nothing on the certificate shows a SIN.

Know who signs

The CRA expects the firm to know who signs: an e-signature shows who signed, not who the person is. Record your check on the contact: Contacts › the person › Edit contact, then Identity checked on, How it was checked (photo ID in person, photo ID on a video call, known client) and Checked by. It prints on the certificate of each document they sign.

Each person signs from their own portal account. In a household, each spouse signs their own T183.

Which forms can be signed

The CRA accepts an electronic signature on these forms: T183, T183CORP, T183TRUST, T2183, T2200, T1223, RC71, RC72, CPT30, T183-GMT and UHT-183. It accepts one made through a secure, access-controlled website like the client portal. AUT-01 isn't on the list: don't have it signed here. Financial statement acknowledgements are your own documents, which clients can sign here too. An engagement letter is sent to sign from Letters (Engagement letters), where signing it sets up what it says: its PDF can't be sent to sign from the documents pages.

For a Québec return, check Revenu Québec's current rules before relying on an e-signature.

How long signed documents are kept

The CRA asks you to keep a signed T183 for six years after the return is filed. Firmdesk doesn't know when you filed, so it counts from the signing, generously: a signed copy, and the original it was signed from, can't be deleted from the documents pages for the six years after the year of signing (signed in 2026, it can be deleted from Jan 1, 2033). The page says until when. If you filed the return in a later year, keep your own copy until six years after that. Deleting the whole client still removes them, as does deleting your firm from Firmdesk: the page deleting a client says how many signed documents go with it. Your data exports include them, with the signature records.