• Sign In
  • info@taxtami.com
  • +263 772 226 466
  • | |
  • Home
  • Domestic Tax Courses
    • Income Tax Courses
    • Value Added Tax Courses (VAT)
    • Capital Gains Tax (CGT)
    • ZIMRA Debt Management Courses
    • TaRMS Essentials
    • Zimbabwe Tax Calculators
  • Customs Course
    • Foundations of Customs
    • Duty Computation & Reliefs
    • Modes of Entry: Imports
    • Bonded Movement, Exports & SEZs
    • Control & Enforcement
    • Risk-Based Compliance & Audit
    • Special Persons & Goods
    • Regional & International Trade
    • Disputes & Recourse
    • Professional Standards
  • Rev-News
    • Public Notice Updates
    • Detailed Tax Analysis
  • About Us
  • Contact
TaRMS Essentials · Lesson 1.5 Password Management The full password lifecycle on the SSP — the 90-day expiry, the 5-attempt lockout, the Forgot-Password OTP recovery flow, and the in-session password change.
1

Context

Password Lifecycle States Active within 90-day window Expiry warning 7 days before Expired forced change at login Locked 5 failed attempts OTP recovery Forgot Password In-person reset station visit Day 83 Day 90 OK email lost 5x Figure 1.5 …

2

Legislative

1. Cyber and Data Protection Act, section 7 — data-protection by design Imposes the obligation to apply appropriate technical and organisational measures. Strong-password policies and periodic rotation are textbook section-7 measures.…

3

Conceptual

1. Password rules in force Rule Detail Minimum length 8 characters Composition At least one uppercase, one digit, one special character Expiry 90 days; courtesy email reminder 7 days before Reuse window Cannot reuse the previous 5 passwords…

Context
Legislative
Conceptual
A. Context B. Legislative C. Detailed D. Real-World E. Case Law F. Pitfalls G. Knowledge Check H. Quiz Answers I. Takeaways

Lesson 1.5: Password Management

Cross-checked against the official ZIMRA SSP Help System (mytaxselfservice.zimra.co.zw/help/ssp/en/).

A. Lesson Context: Credentials are Compliance

⏱ Reading time: ~15 minutes·★★ Difficulty: Intermediate

Password management on TaRMS — resets, security questions, 2FA — keeps your account safe. This lesson takes you through the password workflows.

What you'll learn
  • How to reset a forgotten password
  • How to change your password regularly
  • How to enable 2FA
  • What to do if you suspect a breach
Password Lifecycle StatesActivewithin 90-day windowExpiry warning7 days beforeExpiredforced change at loginLocked5 failed attemptsOTP recoveryForgot PasswordIn-person resetstation visitDay 83Day 90OKemail lost5x
Figure 1.5 — Password lifecycle. The cheap path is voluntary change at day 80. The expensive path ends at the right side: in-person reset.
Official ZIMRA Help System reference: password_reset.htm.
ZIMRA SSP — Password Reset
Official ZIMRA SSP screenshot — Password Reset (live from ZIMRA Help System).
Official ZIMRA Help System reference: changing_the_password.htm.
ZIMRA SSP — Changing the Password
Official ZIMRA SSP screenshot — Changing the Password (live from ZIMRA Help System).

Password management on the SSP is more than a security hygiene issue — it is a compliance issue. A locked-out user cannot file; a missed deadline due to a forgotten password is treated by ZIMRA as the taxpayer’s problem, not the system’s. This lesson covers every state in the password lifecycle: setting at registration, voluntary change, periodic forced change at 90-day expiry, lockout after 5 failed attempts, and the OTP-based recovery flow.

By the end the learner will: (i) be able to change their password proactively; (ii) recover from a forgotten-password situation; (iii) handle the 90-day expiry without surprise; (iv) avoid the lockout by understanding the 5-attempt rule; and (v) understand when an in-person ZIMRA station visit is the only recovery path.

Password recovery is one OTP away
Forgot-password recovery sends an OTP to your registered email. Lock-out is recoverable; only stale email turns recovery into an in-person station visit.

B. Legislative Framework: Statutory Authority for SSP Credential Security

1. Cyber and Data Protection Act, section 7 — data-protection by design

Imposes the obligation to apply appropriate technical and organisational measures. Strong-password policies and periodic rotation are textbook section-7 measures.

2. Section 80 Income Tax Act — false statements

Where a return is filed under a credential that has been compromised, the section 80 risk attaches to whoever holds the credential. Password hygiene is therefore a section 80 risk-management practice.

3. SSP Terms of Use

Bind the user to (i) keep credentials confidential, (ii) report suspected compromise within 24 hours, (iii) accept liability for acts done through their credential.

4. POTRAZ guidance on access controls (2024)

Treats credential-sharing as per se a section 7 breach.

C. Detailed Conceptual Explanation: How TaRMS Password Reset, Change and Recovery Work

1. Password rules in force

RuleDetail
Minimum length8 characters
CompositionAt least one uppercase, one digit, one special character
Expiry90 days; courtesy email reminder 7 days before
Reuse windowCannot reuse the previous 5 passwords
Lockout5 consecutive failed attempts → account locked
2FA OTPEmail by default; SMS opt-in

2. Voluntary change workflow

  1. Login.
  2. Click profile menu (initials, top-right).
  3. Choose Change Password.
  4. Enter current password; enter new password twice; submit.
  5. Logout and re-login with the new password to confirm.

3. Forced change at 90-day expiry

On the day the password expires, the next login forces a change-password screen. The user enters the current password and a new one. If the user has not logged in for many months, the expiry change happens at the first attempted login post-expiry.

4. Forgot-Password recovery

  1. Click Forgot Password on the login screen.
  2. Enter the registered email.
  3. Receive an OTP at the registered email (and SMS if configured).
  4. Enter OTP within its 10-minute validity.
  5. Set a new password subject to the rules.
  6. Login normally.

5. Lockout recovery

Five failed attempts triggers a lockout. The lockout is removed by the same Forgot-Password OTP flow. If the email is also compromised or stale, in-person reset at a ZIMRA station with proof of identity is required.

6. In-person reset criteria

Required when:

  • Email on file is no longer accessible.
  • OTP is not arriving (typically a misconfigured email or aggressive spam filter).
  • 2FA settings are corrupted.
  • Account is suspended due to suspected compromise.

Documents to bring: original national ID; latest available TIN Certificate; any document tying the user to the account (recent assessment notice, employer correspondence).

7. Two-factor authentication management

From the profile menu, configure 2FA:

  • Email OTP (default): always on for new logins from unrecognised devices.
  • SMS OTP (opt-in): add the registered mobile and verify with a one-time SMS.
  • Authenticator app (under planned future support): not currently available; check ZIMRA Public Notices.

D. Real-World Applicability: Managing Passwords as a Compliance Discipline

1. The diary discipline

Best practice: diary password change every 80 days (10-day buffer before 90-day expiry). Set the diary at registration and recur thereafter.

2. The departing-employee handover

When an employee leaves:

  • Tax Manager removes them as Assignee (Lesson 3.4)
  • the departing employee’s personal SSP account remains theirs
  • any client TINs they had access to are revoked by removing their assignee status. The personal account is not transferred.

3. The deadline-morning lockout

Most expensive scenario: forgotten password discovered on a deadline morning when the registered email is also inaccessible. Recovery requires an in-person station visit, often unfeasible in time. Prevention: quarterly Profile audits (Lesson 2.1) confirming the email is current.

4. The shared-workstation issue

In small offices, two practitioners sometimes share a workstation. Each must log in under their own credentials; never share passwords. The browser-stored password from one user must not be used by another.

E. Case Law Integration: Authorities on Credential Compromise and Account Liability

1. Adventure Communications revisited

The 2021 SA case treated credential-use as binding the credential-holder. Password compromise without prompt notification (within 24 hours per SSP Terms) magnifies exposure.

2. POTRAZ administrative findings

2024 POTRAZ guidance treats credential-sharing as section 7 breach; multiple administrative findings have followed against firms whose audit found shared credentials.

F. Common Pitfalls: Where Password Practices Create Compliance Risk

1. Browser-saved old passwords

After change, the browser store may serve the old one. Fix: manually update.

2. Stale email leading to OTP failure

Recovery becomes in-person. Fix: quarterly Profile audit.

3. Reusing the same password across systems

Cross-system breach risk. Fix: password manager.

4. Sharing the password "just for today"

Cyber Act section 16 offence. Fix: use Assignee structure (Lesson 3.4).

5. Letting password expiry happen on deadline morning

Diary 80-day proactive change.

6. Treating SMS OTP as guaranteed

SMS delivery is intermittent. Email OTP is more reliable.

G. Knowledge Check: Worked Password-Management Scenarios

Question 1

State the password rules in force on the SSP.

Question 2

Walk through the Forgot-Password recovery workflow.

Question 3 — Scenario

You attempt login on deadline morning; account is locked after 5 failed attempts; the email on file is your old firm’s email which you no longer access. What is your recovery path?

Question 4

What does the SSP Terms of Use require regarding suspected credential compromise?

H. Quiz Answers with Explanations: Solutions Walk-through for Password Problems

Answer 1

Min 8 characters; mixed case, digit, special; 90-day expiry; cannot reuse last 5; 5-attempt lockout; email OTP default 2FA.

Answer 2

Forgot Password link → enter email → receive OTP → enter OTP within 10 minutes → set new password → login.

Answer 3

Forgot-Password OTP fails because the email is inaccessible. Only recovery path: in-person ZIMRA station visit with original national ID and (if available) latest TIN Certificate. Practical timeline: 30–60 minutes at the station, but possibly longer if the deadline is the same day. Contemporaneously document the situation as system-unavailability-equivalent and lodge a help-desk ticket; ZIMRA may, on a discretionary basis, accept a late submission once access is restored. Lesson: quarterly Profile audits prevent this scenario.

Answer 4

Report within 24 hours. Reset password immediately. Audit the History tab (Lesson 2.1) for any unauthorised activity during the suspected window.

I. Key Takeaways: A Practitioner Summary of Password Management

☑ Password lifecycle: set → change → expire → reset → recover.

☑ 90-day forced rotation; 5-attempt lockout; OTP-based recovery.

☑ Diary 80-day proactive change.

☑ Stale email = in-person recovery; prevent via quarterly audit.

☑ Sharing passwords is a section 16 Cyber Act offence.

☑ 24-hour breach notification under SSP Terms.

☑ Continuity: Lesson 1.6 covers User Profile and Session Management.

──────────

TaxTami — Zimbabwe Tax Training

www.taxtami.com · info@taxtami.com

All TaxTami Lessons

Income Tax · VAT · CGT · Debt · TaRMS · Calculators · Customs

Open course menus →
M1 Income Tax
L1Sources of Zimbabwean Tax Law L2Introduction to Taxation in Zimbabwe L3Persons Liable to Income Tax in Zimbabwe L4Tax Residence and Source of Income L5Gross Income Definition and Case Law L6Capital vs Revenue Receipts L7Specific Inclusions in Gross Income L8Fringe Benefits Taxation in Zimbabwe L9Exempt Income under Zimbabwean Tax Law L10Allowable Deductions and General Formula L11Specific Allowable Deductions (section 15(2)) L12Capital Allowances — Fourth Schedule L13Prohibited Deductions under section 16 L14Taxation of Mining Operations in Zimbabwe L15Taxation of Farmers in Zimbabwe L16Taxation of Employment Income and PAYE L17Taxation of Individuals in Zimbabwe L18Taxation of Partnerships in Zimbabwe L19Taxation of Trusts and Deceased Estates L20Corporate Income Tax in Zimbabwe L21Calculation of Income Tax and Tax Credits L22Withholding Taxes — Residents and Non-Residents L23Double Taxation Agreements and Relief L24Transfer Pricing and Anti-Avoidance L25Returns and Record-Keeping Compliance L26Provisional Tax, QPDs and PAYE Administration L27Tax Administration, Returns and Appeals L28Representative Taxpayers L29Other Income-Based Levies (IMTT, Carbon Tax, etc.) L30Objections and Appeals under Income Tax L31Tax Recovery and Collection Procedures L32Digital Tax Administration Systems (ZIMRA TaRMS)
M2 Value Added Tax
L1Zimbabwe VAT Foundations and Conceptual Fram… L2Interpretation and Key VAT Definitions L3Imposition and Scope of VAT L4VAT Rates and Types of Supplies L5Time of Supply Rules L6Value of Supply and Valuation Rules L7VAT on Imports and Exports L8Special VAT Charges and Statutory Levies L9VAT Registration Requirements (ZIMRA) L10VAT Accounting Basis (Invoice vs Cash) L11Input Tax Deep Dive (Capital Goods & Pre-Reg) L12VAT Adjustments and Change-in-Use L13Documentation and Record-Keeping L14Returns, Payments, Interest and Penalties L15VAT Refunds and Exporter Refunds L16Assessments and Self-Assessment System L17VAT Objections and Appeals L18Compliance, Audits and Enforcement L19Digital VAT, Fiscalisation and Technology L20Representative Persons and Withholding Agents L21Special VAT Rules and Industry Provisions L22VAT Anti-Avoidance Rules and ZIMRA Powers L23Practical VAT Application for Businesses L24VAT Exam Prep and Practitioner Toolkit
M3 Capital Gains Tax
L1Capital Gains Tax in Zimbabwe: Introduction, Purpose and Legal… L2Legal Framework of Capital Gains Tax in Zimbabwe L3Specified Assets Under Zimbabwe Capital Gains Tax Law L4Disposal of Assets and Taxable Events L5How to Determine Capital Gains L6Allowable Deductions When Calculating CGT L7How to Calculate Capital Gains Tax (Step-by-Step) L8Capital Gains Tax Exemptions L9Special CGT Rules for Business and Asset Transfers L10Capital Gains Withholding Tax L11Role of Intermediaries and Depositaries L12CGT Returns and Assessments L13Payment of CGT and Clearance Certificates L14How to Object and Appeal a CGT Assessment L15Enforcement and Recovery of CGT by ZIMRA L16CGT Treatment of Corporate Restructuring L17CGT on Property Sales L18CGT on Shares and Securities L19CGT on Cross-Border Asset Transfers L20CGT Compliance, Planning and Audit Risks L21Zimbabwe CGT Case Law and Judicial Interpretation L22Administration of CGT by ZIMRA L23Practical CGT Applications L21Deemed Sales L22Non-Permissible Deductions L23Suspensive Sales
M4 Debt Management
L1Foundations of Tax Debt Management L2Creation of Tax Debt L3Tax Assessments and Debt Collection L4Tax Debt Identification and Classification L5Taxpayer Account Management L6Interest and Penalties on Tax Debt L7Payment of Tax Liabilities L8Tax Clearance Certificates and Debt Status L9Debt Collection Strategies L10Payment Plans and Instalment Arrangements L11Tax Debt Enforcement Powers L12Garnishee Orders and Third-Party Collection L13Attachment and Sale of Property L14Civil Recovery Through Courts L15Tax Debt in Insolvency L16Tax Debt and Business Closure L17Tax Disputes and Debt Collection L18Write-Offs and Remission of Tax Debt L19Taxpayer Engagement and Compliance L20Technology in Tax Debt Management L21Special Tax Debt Situations L22Ethics and Professional Conduct L23Practical Debt Management Case Studies L24Debt Management Practitioner Toolkit L25Calculation of Interest on Tax Debt
M5 TaRMS Essentials
M1 Getting Started in TaRMS
L1.1Introduction to TaRMS and the SSP L1.2Logging In, Dashboard, and Switching TINs L1.3Downloading TIN and VAT Certificates L1.4SSP Self-Registration L1.5Password Management L1.6User Profile & Sessions
M2 Taxpayer Profile & Lifecycle
L2.1Anatomy of the Taxpayer Profile L2.2Adding a New Tax Type: VAT Application L2.3Tax Type Deregistration / Status Change L2.4TIN Deregistration L2.5First-Time Taxpayer Registration
M3 Tax Agents & Assignees
L3.1Tax Agent Registration L3.2Tax Agent Licence Management L3.3Assigning and Removing Tax Agents L3.4Roles and Assignees
M4 Tax Return Management
L4.1Return Submission Fundamentals L4.2PAYE Return Submission L4.3Amending Current-Period Returns L4.4Filing Past Returns and Back-Filing L4.5E-Agreement Filings L4.6Old Period Documents
M5 Tax Clearance (ITF 263)
L5.1Automatic Tax Clearance Generation L5.2Manual Tax Clearance Application
M6 Payments & Single Account
L6.1The Single Account Concept L6.2Changing the Single Account Bank L6.3Searching Single Account Transactions L6.4Balance Lookup L6.5New Payment Workflow L6.6E-Banking & Payment History L6.7Withdrawal & History
M7 Taxpayer Accounting
L7.1The Summary Report L7.2The Tax Type Report L7.3Assessment Notices and Reconciliation L7.4Audit Assessment Notices
M8 Capstone Workflows
L8.1End-to-End VAT Compliance Workflow L8.2End-to-End PAYE Compliance Workflow L8.3Common Pitfalls and ZIMRA Audit Triggers L8.4Your Monthly and Quarterly TaRMS Routine
M9 Specialised SSP Modules
L9.1Employee Management L9.2Refund Management L9.3Invoice Management & Diplomatic / DP Invoices L9.4Audit Management — Voluntary Disclosure (VDA01) L9.5Case Management — Objections, Appeals, Schemes L9.6E-Messaging with ZIMRA Officers
M6 Zimbabwe Tax Calculators
C1Bonus / 13th Cheque Tax C2CGT Suspensive Sale C3Capital Gains Tax C4Corporate Tax & QPD C5General Customs Duty C6Non-Resident Shareholders Tax C7Resident Dividend Tax C8Estate Duty C9Excise & Surtax C10Fringe Benefit Tax C11USD ↔ ZiG Conversion C12IMTT (2%) C13ITF1 Annual Reconciliation C14Mining Royalties C15Non-Resident Fees & Royalties C16Objection Deadline C17PAYE → ITF 16 Reconciliation C18PAYE & Net Salary C19Penalty & Interest C20Presumptive Tax C21Refund / Credit Position C22Stamp Duty / Property Transfer C23TaRMS Return Due-Date C24TCC Eligibility Checker C25VAT Apportionment C26VAT (15.5%) C27VAT 7 Pre-Submission C28Vehicle Import Duty C29WHT on Tenders C30WHT on Contracts
M7 Customs
M1 Foundations of Customs
L1.1Tariff Classification L1.2Customs Valuation L1.3Origin & Preference L1.4Customs Registration & Licensing L1.5Documentation & Bills of Entry
M2 Duty Computation & Reliefs
L2.1Calculation of Duty, Surtax & VAT L2.2Rebates & Suspensions L2.3Export Drawback of Duty L2.4Refunds, Remissions & Bonds L2.5Deferred Clearances
M3 Modes of Entry: Imports
L3.1Motor Traffic & Vehicle Imports L3.2Imports by Rail L3.3Imports by Air L3.4Imports by Post L3.5Form 49 & PCW L3.6ASYCUDA World Declarations L3.7E-commerce & Online Shopping
M4 Bonded Movement, Exports & SEZs
L4.1Bonded Warehouses & Deferred Clearances L4.2Containerisation L4.3Exportation of Goods L4.4Free Trade Zones & SEZs L4.5Temporary Imports & ATA Carnets
M5 Control & Enforcement
L5.1Customs Controls Framework L5.2Searches — Your Rights & Obligations L5.3Customs Offences & Penalties L5.4Customs Appeals Process
M6 Risk-Based Compliance & Audit
L6.1Risk Management & AEO L6.2Preparing for a Post-Clearance Audit L6.3Minerals Identification L6.4Audit Techniques
M7 Special Persons & Goods
L7.1Returning Residents Rebate L7.2Diplomatic & NGO Privileged Imports L7.3Strategic Goods & Permits L7.4Prohibited & Restricted Goods
M8 Regional & International Trade
L8.1SADC, COMESA & AfCFTA L8.2WTO TFA & Revised Kyoto Convention L8.3Green Customs — CITES & MEAs L8.4Multilateral Environmental Agreements L8.5Border Control & IBM
M9 Disputes & Recourse
L9.1Fiscal Appeal Court L9.2Judicial Review in the High Court
M10 Professional Standards
L10.1Integrity & Ethics in Customs L10.2Customs Report Writing
TaxTami TaxTami

Zimbabwe's leading tax education platform, making Zimbabwean tax law simple for students, professionals and business owners.

Courses

  • Income Tax
  • Value Added Tax
  • Capital Gains Tax
  • Debt Management
  • TaRMS Essentials
  • Customs
  • Zimbabwe Tax Calculators

Library

  • All Lessons
  • Legislation Bank
  • Tax Insights
  • Tax News

Account

  • Sign In
  • Dashboard
  • Profile
  • Certificate

Company

  • About
  • Contact
  • AI Use Policy

© TaxTami. All rights reserved.

  • AI Use Policy