What should sales tax workpapers include for a multi-state brand?
A sales tax workpaper is the controller's evidence file. It is the artifact a state auditor walks through to verify that the brand registered when it should have, calculated tax correctly, collected exemptions with valid documentation, filed the return that matches the engine's output, and remitted the cash. Five sections do that work. Each section has a defined source system, a defined audit purpose, and a defined sign-off owner.
| Section | What it tracks | Source system(s) | Audit purpose |
|---|---|---|---|
| Threshold tracking | When each state's economic or physical nexus threshold was crossed and the basis for that determination | Shopify Orders API extract, marketplace settlement reports, payroll system, 3PL inventory log | Defends registration timing and the trigger date the brand asserts |
| Taxability decisions | SKU-category to state-specific taxability with the statute, regulation, or ruling basis cited per state | Product master, internal taxability memo, tax provider category mapping | Defends every line of the calculation engine's rate determination |
| Exemption summary | Per-state count and dollar value of exempt sales, tied to certificate IDs in the cert pool | Exemption certificate management system, ERP exempt-customer flag, tax provider exemption log | Defends the gap between gross sales and taxable sales for B2B and exempt-entity orders |
| Source-to-return reconciliation | The bridge from gross sales in the channel system to taxable sales on the filed return, including marketplace offsets | Shopify Orders API, Amazon and Walmart settlement reports, ERP invoice ledger, tax provider calculation log | Closes the loop between what the channel saw, what the engine calculated, and what the state received |
| Filing summary | Per-state per-period filing log with confirmation numbers, remittance dates, and assessed amounts | Filing platform, state DOR confirmation, ACH or wire log | Defends timely filing and produces the per-return audit trail |
State audit manuals describe the same five-section pattern from the auditor's side. The Multistate Tax Commission's Audit Quality Standards require the auditor to verify that the taxpayer's records permit reconciliation of the records to the returns filed before sampling begins. [1] The California CDTFA Audit Manual requires the auditor to start with a reconciliation of total sales as reflected in the books of account to total sales as reported on the sales and use tax returns. [2] The Texas Comptroller's audit procedure begins with a check of the relationship between the books of account and the reports filed. [3] The workpaper exists to answer those questions before they get asked.
How the workpaper ties to source-system data
The defining property of a defensible workpaper is traceability. A summary number on the workpaper is not evidence. The evidence is the underlying transaction record, and the workpaper has to point at it by ID.
Each section pulls from a defined system of record:
- Direct ecommerce volume. Shopify Orders API extract or Shopify Plus order export. Order ID, line item ID, customer billing and shipping address, gross sale amount, tax collected, and the tax provider's calculation reference ID.
- Marketplace volume. Amazon Marketplace Web Service (MWS) settlement reports and Amazon SP-API tax detail. Walmart Marketplace settlement and tax reports. TikTok Shop seller reports. The marketplace facilitator's tax-collected total per state is what offsets the brand's threshold and return obligation in marketplace-facilitator states.
- B2B and wholesale. ERP invoice ledger. NetSuite, QuickBooks Online, or the equivalent. Invoice number, customer ID, ship-to state, line items, exemption flag, and the certificate ID in the cert pool that supports the exempt status.
- Tax calculation. The tax provider's per-transaction calculation log. For every order, the log carries the rate components applied (state, county, city, special district), the rule version, the sourcing decision, and the calculation reference ID that the order record on the channel side carries back.
- Filings and remittance. The filing platform's per-return submission record, the state DOR confirmation number, and the ACH or wire confirmation from the bank.
The traceability test is straightforward. Pick any taxable-sales figure on the workpaper. Drill down. The figure should resolve to a list of order IDs. Each order ID should resolve to a record in the source system with a tax calculation reference. The tax calculation reference should resolve to a line in the provider's calculation log showing the rate components used. The aggregate of those lines should match the workpaper's per-state taxable-sales total. The taxable-sales total should match the figure on the filed return. The remittance should match the return.
This is where the data-pipe matters as much as the math. TaxCloud's native Shopify and Shopify Plus integration writes the calculation reference back to the order record at checkout, so the order-to-calculation tie does not depend on a nightly batch job. The reporting API exposes the per-transaction calculation log directly, which is what feeds the source-to-return reconciliation section of the workpaper without a separate extract.
How to document a non-taxable or exempt position so it holds at audit
Most assessments at audit are not failures of arithmetic. They are failures of documentation behind a non-taxable or exempt position. A taxability decision that looked sensible in the product master does not survive contact with a state auditor unless the workpaper carries the basis for that decision in a form the auditor can audit.
Two patterns separate cleanly: taxability decisions on the brand's own products, and exemptions on a specific customer's purchases.
Taxability decisions
For every SKU category that the brand has decided is non-taxable or partially taxable in a given state, the workpaper carries a cite stack:
- The state statute or regulation that the position rests on. A clothing brand selling into Minnesota cites Minn. Stat. §297A.67, subd. 8, which exempts clothing. [4] A grocery brand selling shelf-stable food into Pennsylvania cites 72 P.S. §7204(29) and the PA DOR's grocery taxability bulletin. The citation appears alongside the category-to-state mapping in the taxability matrix, not in a separate memo.
- The state-issued private letter ruling or technical bulletin where one exists. If the brand requested a ruling from a state DOR on a specific product or fact pattern, the ruling number, date, and full text live in the workpaper. State auditors weight letter rulings heavily, particularly when they were issued to the taxpayer rather than to a third party.
- The position paper from a Big Four or specialist sales tax firm if the brand outsourced the determination. Auditors rarely accept a vendor whitepaper as authority on its own, but a written position from an engagement-letter signatory carries weight, especially where the position acknowledges contested treatment and explains why the brand chose its posture.
- The brand's internal taxability-determination memo. For category decisions made in-house (typically by the controller with the tax provider's input), a one-to-two page memo per category records the facts, the cited authority, the decision, and the date. The memo's date is what an auditor will look at if state guidance shifted after the decision.
Exemption certificates
For every exempt sale on the workpaper, the exemption summary section carries the certificate ID in the cert pool, the validation date and method (manual review, vendor lookup, MTC Uniform Sales & Use Tax Exemption Certificate validation, SST-certified service), and the certificate's state-specific validity period. Per-state validity matters. Some states accept blanket certificates that do not expire; others require renewal every one to four years. The validity period is a workpaper field, not a footnote.
The exemption summary is also where the calculation engine's evidence ties back. TaxCloud's reporting API exposes the per-transaction exemption reference, so each exempt line in the workpaper resolves to both the cert pool record and the calculation log entry that suppressed the tax. That two-way tie is what auditors test when they pull an exempt-sale sample.
How the workpaper format shifts at $10M, $50M, and $100M+
Workpaper format scales with channel count, system count, and the number of states the brand files in. The structure is constant. The plumbing changes.
At $10M on Shopify direct, single channel
The workpaper is typically a spreadsheet with one tab per registered state. The controller (or a staff accountant) builds it monthly by pulling the Shopify Orders API extract, importing the tax provider's calculation log, and running a per-state reconciliation against the filings. Threshold tracking lives in a separate tab against the full 50-state grid. Taxability decisions live in a static matrix referenced by SKU category. Exemption certificates live in a vendor-hosted cert pool linked by ID from the spreadsheet. The audit-defense value at this band comes from the controller's familiarity with every line, not from system-generated authority.
At $30M to $50M with three channels (Shopify direct, Amazon, Walmart or wholesale)
The workpaper is system-generated by the compliance platform, with the controller performing exception review monthly. The platform pulls the three channels' settlement and order data, runs the engine-to-channel reconciliation, and surfaces exceptions: orders without a tax calculation, exempt sales without a valid certificate, marketplace-facilitator sales miscategorized as direct, returns from a prior period landing in the current month. The controller's job is to triage the exception queue and document resolution. The workpaper holds both the system-generated reconciliation and the exception log with controller sign-off.
At $80M and above with four-plus channels and an ERP
The workpaper is a multi-system reconciliation artifact pulled from the data warehouse. Shopify Plus, Amazon, Walmart, TikTok Shop, and direct B2B through NetSuite or a comparable ERP all flow into a central data store. The controller and the staff accountant who owns sales tax run the reconciliation in the warehouse, with the workpaper as a generated output. Per-state exceptions go to the controller for sign-off before filing. At the larger end of this band, the audit committee receives a quarterly summary of unresolved exceptions, the dollar exposure each carries, and the resolution plan. Filing platform and tax engine outputs feed the warehouse on a daily cadence; the workpaper is a recompiled view, not a separately maintained file.
The pattern across all three bands is the same: source data, calculation log, exception queue, filed return, remittance. What changes is who runs the reconciliation and where it lives. The workpaper is the controller's deliverable in every case.
How an auditor uses the workpaper in the field
State auditors do not typically read the workpaper cover to cover. They sample. The workpaper exists to support every sample they pull.
The auditor's pattern is consistent across CDTFA, Texas Comptroller, NY DTF, and the MTC joint audit program. The auditor selects a transaction sample, often statistically derived from the brand's gross sales population. For each sample transaction, the auditor follows a four-step chain:
- Source matches workpaper. The auditor pulls the underlying record from the source system (the Shopify order, the Amazon settlement line, the NetSuite invoice). The record's gross amount, ship-to state, taxability flag, and exemption status must match how the transaction appears on the workpaper.
- Workpaper ties to return. The sample transaction's per-state totals must roll up into the per-state taxable-sales figure on the filed return for the relevant period.
- Return ties to remittance. The remittance amount on the state DOR confirmation and the bank's ACH log must match the return's tax-due figure.
- Treatment ties to authority. For exempt or non-taxable treatment, the workpaper must point at the certificate (with validation date and validity period), the statute or ruling, or the position memo that supports the call.
Gaps between any of those four ties are where assessments land. If the source order shows $1,000 in California taxable sales and the workpaper rolls $980 into the return, the $20 gap becomes a base for an assessment plus penalties and interest, often projected across the full population by the sampling factor. If the workpaper shows a B2B sale as exempt but the cert pool has no certificate ID for the period, the auditor reclassifies the sale as taxable and assesses against gross.
The workpaper's job is to make the four ties hold across every sample the auditor pulls, not just the ones the brand expects to be tested.
Building the workpaper into the monthly close
The single most important decision a controller makes on sales tax workpapers is when to build them. The defensible answer is incrementally, through the monthly close, with the close calendar carrying explicit sales tax tasks rather than treating them as a downstream of finance close.
The cadence at scale:
- Monthly. The compliance platform generates the per-state reconciliation against the calculation log and the filed returns. The controller (or the staff accountant owning sales tax) reviews exceptions, resolves what can be resolved within the period, and books the unresolved items into an exception register with a target resolution date. Exemption certificates received during the month are validated and posted to the cert pool with workpaper reference. Threshold tracking is updated against the latest month's volume.
- Quarterly. The controller signs off on the quarter's workpaper. At brands above $50M revenue, the audit committee or external auditor reviews the workpaper and the exception register. Per-state nexus exposure is reviewed against the prior quarter's footprint and the current quarter's plan (new 3PLs, planned hires, marketplace expansions).
- At audit notice. The audit-response package is pulled directly from the workpaper, plus the cert pool, plus the calculation logs for the periods under review. A controller who has been running the monthly cadence pulls the package in days. A controller who has not pulls it in weeks, often with material gaps that surface during fieldwork.
Three operational consequences follow at the $20M to $80M band. First, the workpaper is a finance-close artifact, not a tax-team artifact. At this scale the brand does not have a tax team; the controller owns sales tax inside the finance close. Second, the exception register is the most-used part of the workpaper at audit time. Exceptions that were resolved in-period close cleanly. Exceptions that were carried for months without resolution are where the auditor finds the assessment. Third, the data feeding the workpaper has to be production-grade. A nightly batch that drops 0.5% of transactions becomes a sampling base error at audit, and the auditor projects the error across the full population.
At a 25-state filing footprint with three to five channels feeding it, the workpaper has to hold the four ties at production scale. The question is what it looks like at a 25-state filing footprint with three to five channels feeding it. TaxCloud is built for that: 13,000+ jurisdictions through one API, consolidated SST filing across the 23 full member states that ties the filed-return side of the reconciliation back to the calculation log, native Shopify and Shopify Plus integration so direct-channel data flows into the same compliance view as marketplace volume, and the reporting API that exposes the per-transaction rate and exemption-certificate references the workpaper resolves to.