What "good-faith acceptance" actually means
The cert pool a controller produces at audit is not graded the way most finance teams expect. The auditor does not simply confirm that a certificate exists for each exempt transaction in the sample. The auditor confirms that the certificate exists, that it was properly completed, and that the seller accepted it under conditions a reasonable seller would have accepted it under. The third element is good-faith acceptance, and it is the element that disallowed exempt sales most often hinge on.
The legal premise behind the standard is straightforward. A state cannot ask a seller to verify the truth of every exempt claim a buyer makes. That would push tax administration onto the seller and defeat the point of the certificate, which is to shift the obligation from the seller to the buyer. Instead, the state asks the seller to act in good faith, then puts the seller back on the hook if the seller had reason to know the claim was wrong.
Three layers sit inside the standard in most states:
- Actual knowledge of invalidity. The seller knew the certificate was wrong and accepted it anyway. The clearest break.
- Reason to know. Something on the face of the certificate or in the surrounding transaction should have prompted the seller to question the claim.
- Constructive knowledge. Information the seller's order entry team would have noticed under normal business diligence, whether or not they actually noticed it.
The reasonable-seller frame is the workable test. If the order entry team would have caught the issue under the brand's documented acceptance procedure, the good-faith defense does not hold. If the issue is only visible in hindsight after the auditor has flagged the buyer's entity, the defense generally does hold.
This is why "we have the cert on file" is the wrong answer to an auditor's question about exempt sales. Having the certificate is necessary. Demonstrating that the brand accepted it in good faith is what defends the exempt position.
The state-by-state statutory standards in 2026
Every major state codifies the standard, with state-specific phrasing that creates real variation in how strict the test reads. Five states drive most of the audit volume a mid-market ecommerce brand sees on B2B exempt sales: California, New York, Texas, Illinois, and Massachusetts.
| State | Statute or regulation | Core standard | Properly completed timing |
|---|---|---|---|
| CA | Cal. Rev. & Tax. Code §6092; CDTFA Reg. 1668 | Seller must "have no reason to believe" the property is being purchased for a non-exempt purpose; must accept the certificate in good faith | At time of sale or within a reasonable period after [1] |
| NY | NY Tax Law §1132(c)(1); 20 NYCRR §532.4 | Seller must accept the certificate in good faith and the certificate must be "properly completed"; the burden is on the seller to prove the sale was for resale or otherwise exempt | Within 90 days of the sale [2] |
| TX | Tex. Tax Code §151.054(d); 34 TAC §3.287 | Sale is exempt if the seller receives "in good faith" a "properly completed exemption certificate"; statutory presumption is that all gross receipts are taxable until the seller meets the standard | Within 60 days of the sale [3] |
| IL | 86 Ill. Adm. Code 130.1405 | Good faith requires the seller to have no actual or constructive knowledge that the certificate is invalid; the certificate must be taken in the regular course of business | At time of sale [4] |
| MA | 830 CMR 64H.8.1; TIR 04-3 | Seller must accept the certificate in good faith; "good faith" requires that the seller not have reason to believe the property purchased is not for the represented exempt use | At time of sale [5] |
Three structural patterns matter when reading the table:
The phrasing of the knowledge floor varies. California uses "no reason to believe." Illinois uses "no actual or constructive knowledge." Massachusetts uses "reason to believe." These read as variations on the same standard, but in audit practice the Illinois constructive-knowledge phrasing is broader than the California reason-to-believe phrasing. An Illinois auditor can argue that a piece of information the seller's team should have caught, even if no one actually flagged it, dissolves the defense.
"Properly completed" is a separate test from good faith. A certificate that is missing required fields fails the properly-completed test on its own, regardless of whether the seller accepted it in good faith. The two tests run in series. The certificate has to be properly completed first; only then does the good-faith analysis matter. This is why field-level validation at acceptance time is load-bearing.
Timing windows differ. Texas's 60-day rule and New York's 90-day rule create a hard cutoff for accepting late certificates. A certificate received after the window does not benefit from the good-faith presumption, even if it is otherwise valid.
The operational implication is that "properly completed" cannot be a manual judgment call at order entry time, and it cannot be deferred. A brand running $20-80M through Shopify with a meaningful B2B mix is processing hundreds of resale and exemption certificates a year across 20-plus states. State-specific field validation at acceptance time, applied uniformly to every certificate, is what produces a cert pool that survives an auditor's first pass. TaxCloud handles this through exemption certificate management with field validation tuned to each state's properly-completed standard, so the certificate either clears at acceptance time or is flagged for the order entry team before the exempt sale is processed.
When a seller loses good-faith protection
Disallowance at audit usually traces to one of four categories. Each represents a failure of the reasonable-seller test, and each is something an auditor will name explicitly in the assessment letter.
Red flags on the face of the certificate
The most common path to disallowance. A certificate that has missing required fields (no signature, no date, no permit number, no description of property purchased), an expired effective date, or internally inconsistent entries (the buyer's name on the certificate does not match the bill-to name on the invoice) fails on its face. The auditor does not need to argue good faith; the certificate is defective. The Texas Comptroller's rule on this is explicit: a certificate that is not properly completed is no certificate at all for purposes of the exemption. [3]
Buyer in an obviously inconsistent industry
A manufacturer-input exemption certificate from a buyer whose registered business activity is retail. A nonprofit exemption certificate from a buyer that is a for-profit LLC. A resale certificate from a buyer that has no resale presence in the destination state. These are the cases where the auditor pulls the buyer's state registration and compares it against the certificate's stated exempt use. The mismatch is the disallowance.
Prior knowledge of the buyer's status
The seller had earlier reason to question the buyer's exempt position and accepted the certificate anyway. A repeated pattern of late payments after exempt purchases, a prior conversation where the buyer asked for "tax-exempt pricing" without producing a certificate, a buyer who has changed exempt-use claims across multiple certificates in the same year. Auditors look for these patterns in the brand's order history, and the brand's own emails and CRM notes can become exhibits.
Constructive knowledge through normal business diligence
The hardest category to defend against, and the most common in Illinois and New York. The argument is that the seller's order entry team should have noticed the inconsistency under standard acceptance procedure. The auditor does not need to prove the team actually noticed. The auditor needs to demonstrate that a reasonable acceptance procedure would have caught the issue. This is why the brand's documented SOP and the validation evidence captured at acceptance time matter as much as the certificate itself. They are the proof that the team did, in fact, run normal business diligence.
The category that surprises mid-market controllers most is the third one. Order history is discoverable. CRM exports are discoverable. A buyer who emailed asking for tax-exempt pricing in March 2024 and produced a certificate in October 2024 has created a paper trail the auditor will find. Good-faith acceptance assumes the seller had no reason to question the claim at the moment of acceptance. Documented evidence that the seller did have reason, and accepted anyway, is the cleanest path to disallowance.
What the SSTGB Form F0003 instructions actually require
The Streamlined Sales Tax Governing Board publishes Form F0003, the Streamlined Sales and Use Tax Agreement Certificate of Exemption, used across the 23 full SST member states plus Tennessee as associate and any non-member state that accepts it.[6] The form's instructions define the good-faith standard that applies across SST jurisdictions, and the SSUTA itself sets the floor in member states.
The SSUTA standard, articulated in Section 317, has three load-bearing pieces:
- The seller is relieved of the tax if the seller obtains a fully completed exemption certificate or captures the relevant data elements within 90 days of the sale.
- The relief does not apply if the seller fraudulently fails to collect the tax or solicits purchasers to participate in the unlawful claim of an exemption.
- The relief does not apply if the seller accepts an exemption certificate when the seller had knowledge or had reason to know that the information was materially false. [7]
Three things follow from how this is structured.
The SSUTA standard is the floor, not the ceiling. Member states can apply additional rules. Tennessee, an SST associate member, layers its own state-specific properly-completed test on top of the SSUTA framework. Most member states accept Form F0003 as sufficient, but reading the SSUTA standard as the only relevant test in a member state misses state-specific overlays.
Fully completed is defined by data elements, not by the form. SSTGB's instructions specify the data the seller must capture: purchaser identification, exemption reason, signature where required, and the state-specific information for each state in which the exemption is claimed. A seller can capture the data elements without using Form F0003. The form is a convenience that ensures the elements are captured uniformly.
"Reason to know" is the operative knowledge standard. The SSUTA standard is closer to the broader Illinois constructive-knowledge framing than to the narrower California reason-to-believe phrasing. A seller in an SST member state cannot rely on the cleanest reading of state common law to narrow the standard; the SSUTA reason-to-know framing controls.
For a mid-market ecommerce brand selling B2B into a mix of SST and non-SST states, the operational consequence is that the brand needs to validate against the more demanding standard, not the more lenient one. The acceptance procedure that defends in an SST state will defend in California. The procedure that just barely passes in California may not defend in an SST state. Validation-method capture, including which lookup was performed and which registration database was queried at acceptance time, is the artifact that proves the brand met the SSUTA reason-to-know floor.
The documentation that supports a defense at audit
A good-faith defense at audit is a documentary argument. The auditor produces the certificate from the sample; the brand produces the surrounding evidence that the certificate was accepted under conditions a reasonable seller would have accepted it under. Five artifacts make the difference.
- The original certificate with all required fields complete. The single most important document. The brand must be able to produce the exact certificate the auditor is challenging, with every field the state requires filled in. Photocopies, scans, and electronically captured records all qualify in most states, but the record must be legible and complete. A certificate produced at audit with a missing signature or a blank state-specific field fails the properly-completed test and the good-faith analysis never starts.
- Proof of validation at acceptance time. This is the evidence that distinguishes a brand that ran normal business diligence from a brand that did not. The artifacts include the date the certificate was validated, the lookup tool or method used, the registration-number verification result (screenshot, API response payload, or audit-log entry), and the order entry team member who completed the check. The auditor is testing whether the brand's stated acceptance procedure was actually followed for the specific transaction in the sample. The validation record is the proof.
- The brand's documented certificate acceptance SOP. A written standard operating procedure that defines what the order entry team checks at acceptance time, in what order, with what tools, and what triggers a rejection. The SOP is the framework that turns individual validation records into a coherent good-faith case. Without an SOP, the validation records read as ad hoc; with the SOP, they read as evidence of a consistent and reasonable procedure.
- Evidence of periodic re-validation for multi-year certificates. Many state-specific certificates and the SSTGB blanket certificate are valid for multi-year periods. A brand that accepted a buyer's certificate in 2022 and never re-validated it through 2026 is exposed if the buyer's registration lapsed or changed during the window. Quarterly or annual re-validation, captured as a scheduled task with results stored alongside the original certificate, is the artifact that shows the brand maintained the cert rather than accepting it once and forgetting.
- The audit-time response showing consistent diligent acceptance. The cert pool is graded as a pool, not as a set of individual transactions. A brand that produces clean records for the sample but has gaps elsewhere in the same population invites the auditor to expand the sample. A pool that reads as uniformly diligent across the full population narrows the audit and supports the good-faith case for the contested transactions.
The marginal cases at audit, the ones where the good-faith defense actually does its work, almost always come down to these documentation layers. For clearly defective certificates (no signature, expired, missing the property description), the good-faith argument fails and the brand owes the tax. For marginal cases (a registration number formatted slightly differently than the state's database expects, an industry code on the certificate that is one digit off from the buyer's filing), the defense holds when the documentation supports it.
This is the layer where validation infrastructure does the real work. The brand needs every accepted certificate to carry its own validation provenance: when it was checked, against what database, with what result, by whom. TaxCloud captures that validation-method record at acceptance time and stores it with the certificate, along with expiration tracking that surfaces re-validation reminders before the cert lapses, so the audit-defense package is produced from the system of record rather than reconstructed under deadline pressure.
The operating model at scale: SOP, validation evidence, re-validation
At $20-80M on Shopify or Shopify Plus with a B2B-heavy exempt-sales pool, the cert population is not small. A brand processing several thousand B2B orders a year across 20-plus states with active resale and exempt-use customers is typically managing 1,500 to 4,000 active certificates at any given time. The audit-defense posture has to be operational, not heroic. The four building blocks below are the operating model that holds up.
A documented acceptance SOP
The SOP defines what gets checked, by whom, in what order. State-specific required fields. Registration-number validation against the state's lookup tool or a third-party verifier. Industry code consistency with the buyer's invoice activity. Expiration date check. Signature presence. The SOP is short (a one or two page document) and uniform across the order entry team. Every certificate flows through it.
Validation evidence captured at acceptance time, stored with the certificate
Each step in the SOP produces a record. The record includes the date, the method, the result, and the team member. The record is stored with the certificate, not in a separate log that has to be joined back at audit time. The audit defense is a single retrieval, not a reconstruction.
Periodic re-validation as a scheduled task
Multi-year certificates need to be re-checked. Annual re-validation is the cadence most controllers run, with quarterly re-validation for the highest-volume buyers or buyers with prior registration changes. The re-validation produces its own evidence record, stored alongside the original.
The audit-time evidence trail through the system of record
When the assessment letter arrives, the controller pulls the certificates for the sample, the validation records for each, the SOP version that was in effect at the time of each acceptance, and the re-validation history. The retrieval is a query, not a forensic exercise.
The reader here is past the point of debating whether to manage exemption certificates as a discipline. The question is what the operating system looks like at a 2,000-certificate steady state across 20-plus states. TaxCloud is built for that: state-specific field validation at acceptance time, validation evidence stored with each certificate, periodic re-validation reminders before certificates lapse, and an audit-time evidence trail you can pull from the system of record rather than reconstruct under deadline pressure.