What documents does a state sales tax auditor request on day one?
The CA CDTFA Audit Manual[1], TX Comptroller Audit Procedures Manual[2], and NY DTF Publication 130-D[3] describe substantially the same opening examination request.
| Document category | Auditor's use | Audit phase |
|---|---|---|
| Sales journals, by period | Establish gross revenue base for the tax calculation | Opening examination |
| Transaction-level rate logs | Verify calculation accuracy at the line-item level | Opening + detailed examination |
| Filed returns, all registrations, all periods in scope | Verify what was reported versus what was owed | Opening examination |
| Exemption and resale certificates | Validate every transaction claimed as exempt | Detailed examination |
| Shipping and delivery records | Confirm destination sourcing for rate and nexus determinations | Detailed examination |
| Returns and refunds documentation | Verify credits taken against reported tax | Detailed examination |
| Marketplace settlement reports | Reconcile marketplace-remitted tax against seller's returns | Detailed examination |
| Bank statements, reconciled to gross sales | Mathematical close: verify remittances match filings | Closing examination |
The opening examination runs the first one to two weeks. The auditor is determining whether the records can be reconciled to filed returns. If they cannot, the audit converts to an estimation method, which almost always produces a larger assessment than actual records would support.
For a brand with 20 or more state registrations and volume across Shopify direct, Amazon, and Walmart Marketplace, the day-one request produces eight document categories across multiple states and two to four audit years. The operational problem is not whether those records exist. It is whether they can be located within the auditor's initial production window, typically five to ten business days from the notice date.
Each category has a source: sales journals from QuickBooks Online or NetSuite, calculation logs from the sales tax engine, filed returns from the compliance provider, certificates from the certificate library, settlement reports from marketplace portals, bank records from treasury. The failure mode is not missing records. It is that locating them during an active audit pulls staff off the monthly close.
The reconciliation chain: where penalty assessments concentrate
The auditor's primary analytical task is building a reconciliation chain across four links:
- Sales journals (gross revenue by period)
- Transaction-level calculation logs (tax computed at the line level, including the jurisdiction and rate applied to each transaction)
- Filed returns (tax reported to the state for the period)
- Remittance records (tax paid, confirmed through bank statements or ACH records)
Gaps between any two links are where auditors generate assessments. The CA CDTFA Audit Manual[1] identifies discrepancies between reported gross sales and calculation engine output as the highest-frequency finding in desk audits of remote sellers. The TX Comptroller Audit Procedures Manual[2] describes the same requirement: the auditor foots the books and records to the filed returns, and any variance triggers a line-item examination.
Three gaps produce the majority of penalty exposure for multi-state ecommerce brands.
Sales journal to calculation log gap
Transactions appear in the sales journal but are absent from the calculation log. This happens when orders move through a path not connected to the primary tax integration: manual orders entered in Shopify's admin, orders from a secondary channel that bypasses the calculation engine, or transactions processed during a platform downtime event where tax defaulted to zero. Each unlogged transaction looks like uncollected tax.
Calculation log to filed return gap
The calculation engine produced tax, but it was not reported on the return. Export formats from the calculation engine may not map cleanly to the return schedule's line items, or the return may cover a different date range than the calculation log export. Multi-state brands operating across fiscal-year and calendar-year states encounter this regularly.
Filed return to remittance gap
The return showed tax due, but the bank record does not match. In SST states, the consolidated remittance moves through the Certified Service Provider rather than directly from the brand's bank account. The documentation must show the CSP remitted on the brand's behalf, which requires the CSP's filing confirmation in the same folder as the bank statement for that period.
TaxCloud's reporting API produces transaction-level calculation logs for any period on demand as a dated CSV export, ensuring the calculation record and the filed return reference the same underlying transaction set.
Exemption and resale certificate mechanics at audit
Every transaction claimed as exempt requires a valid certificate. The CA CDTFA, TX Comptroller, and NY DTF each define what valid means by statute and administrative rule. Six elements are required on every certificate:
- Buyer's legal name. Must match the name on the buyer's sales tax permit or exemption registration.
- Buyer's address. Business address, not billing.
- Buyer's registration number. The state-issued permit or account number. A certificate without a verifiable registration number is invalid on its face.
- Statutory basis for the exemption. The specific code section or category: resale, manufacturing, agricultural, non-profit, or direct pay. Stating "exempt" without the statutory basis is insufficient in California, Texas, and New York.
- Seller's name. The certificate must identify the seller it covers.
- Signature and date. Physical or electronic. An undated certificate is treated as invalid in most states.
Blanket versus single-use certificates. A blanket certificate covers all purchases of a qualifying type from the named seller over a defined period. Texas requires review every four years (34 TAC §3.285)[8]; California recommends renewal every three to four years. A certificate more than four years old with no evidence of review is treated as potentially invalid at audit. For brands with B2B or wholesale accounts across 15 or more states, the certificate library is a live maintenance problem: the common audit finding is not a missing certificate but one that expired in 2021 with the brand continuing to treat that buyer as exempt through 2024.
The SSTGB Form F0003 retrospective fix. In the 23 full SST member states plus Tennessee as associate, when a seller cannot locate a certificate for a period under audit, the buyer may execute SSTGB Form F0003[4], the Certificate of Exemption Retrospective. Under SST governing documents, this provides the seller relief from tax liability for the uncertified period, provided the seller acted in good faith. For a brand that missed certificate collection for a significant exempt buyer in an SST state, Form F0003 is the mechanism to close the finding rather than accept the assessment.
TaxCloud's exemption certificate management tracks expiration dates across the buyer base and surfaces certificates approaching the four-year review threshold. The audit record for each certificate includes the buyer's registration verification and the date of last review: the elements an auditor needs to accept a certificate as valid reliance.
Marketplace-facilitated transactions: the offset reconciliation gap
Marketplace facilitator laws require platforms including Amazon and Walmart Marketplace to collect and remit sales tax on third-party sales in most states. For a Shopify Plus brand operating across direct and two or three marketplace channels, this creates an audit documentation problem distinct from every other category.
The seller's return reports one of two treatments: direct-channel sales only (marketplace sales excluded as facilitator-remitted) or all channels with a credit for marketplace-remitted amounts. Either treatment requires documentation: the offset reconciliation, showing gross marketplace sales by state and period, tax collected by the marketplace, the basis for the marketplace's determination, and how the remitted amount maps to the credit taken on the seller's return.
NY DTF Publication 130-D[3] calls for marketplace settlement reports as a first-week production item; the CA CDTFA Audit Manual[1] describes the facilitator credit as a reconciling item requiring third-party settlement data, not seller estimates.
Three failure modes account for most findings in this category.
Marketplace coverage does not align with the seller's nexus footprint
If the brand established nexus in a state before the marketplace's collection covered that state's transactions, there may be a window where neither party collected. The assessment attaches to the brand.
Settlement reports are organized by calendar year, not by the state's measurement period
Connecticut measures on the 12-month period ending September 30. A calendar-year export requires recutting to align to that window. The mismatch creates an apparent discrepancy the brand has to explain during examination.
The marketplace credit on the return does not match the settlement data
This happens when returns are prepared using estimated marketplace-remitted amounts rather than actual settlement figures. A variance, even a small one, triggers a line-item examination.
The operating fix: pull settlement reports by state and period for every audit period, reconcile to returns before the audit begins, and store them in the same folder structure as the filed returns they correspond to. For a Shopify Plus brand with two marketplace channels, this is a standing quarterly maintenance task, not an audit-response task.
Record retention windows by state
Three states that together cover a large share of multi-state audit exposure have explicit retention statutes:
| State | Retention window | Statute | Notes |
|---|---|---|---|
| California | 4 years from the return due date | Cal. Rev. & Tax. Code §6487 [5] | Extended for fraud or non-filing; tolled while a petition is pending |
| Texas | 4 years from the tax due date | Tex. Tax Code §111.0041 [6] | Extended if a return was not filed or was fraudulent |
| New York | 3 years from the filing date | NY Tax Law §1135 [7] | Extended for substantial understatement exceeding 25%; tolled by active audit |
Most states follow windows of three to four years from the return due date, with the same fraud and non-filing extensions. For a brand registered in 20 or more states, the practical approach is to apply the longest applicable window uniformly to all records for that state.
The open-ended exposure window
The windows above assume a return was filed. For periods where no return was filed, most states have no statutory close: the lookback runs from the date the obligation began. A brand that registered in Texas in 2024 but had economic nexus there since 2022 (Tex. Tax Code §151.107) carries two years of pre-registration exposure that the four-year statute does not bound. How that gap is resolved, through a voluntary disclosure agreement or back-registration, determines the retention obligation for those periods.
Retaining beyond the statutory minimum
Tax counsel routinely recommends holding records one to two years beyond the statutory minimum to cover extended-assessment scenarios. Brands that closed pre-registration periods through a VDA should retain the VDA agreement, the agreed lookback scope, and all records produced in the process indefinitely. Those records are the primary defense if the state later questions what the VDA was intended to close.
Building a pre-notice document organization system
The auditor's first-week document request will arrive whether or not the brand is ready. A brand that handles it in 48 hours without touching the close team prepared before the notice came. One that scrambles for two weeks prepared nothing in advance.
The folder structure that makes 48-hour retrieval possible operates three levels deep.
Level 1: by state
One top-level folder per registered state. Every document relating to a state lives under that folder regardless of source system.
Level 2: by period
Within each state folder, one subfolder per filing period. Quarterly filers use YYYY-Q1 through YYYY-Q4. Annual filers use YYYY. The naming convention must sort correctly and stay consistent.
Level 3: by document type
Within each period subfolder, one folder per category: Sales Journal, Calculation Log, Filed Return, Certificates (active during the period), Settlement Reports (by marketplace channel), and Bank Reconciliation.
File naming conventions
Every file encodes state, period, and document type in its name: TX_2024-Q3_SalesJournal.xlsx, TX_2024-Q3_FiledReturn.pdf, TX_2024-Q3_CalculationLog.csv. When an auditor requests the Illinois calculation log for Q1 2024, the file should be retrievable in under two minutes by someone who did not build the system.
The pre-audit gap index
A spreadsheet with one row per state, columns for each document category, and a cell indicating whether records for each period are complete or missing. Run it quarterly; missing cells are where audit exposure concentrates, and finding them first creates time to address gaps rather than explain them.
Custodian assignment
Each state folder needs a named custodian responsible for keeping it current, plus a named backup. The custodian is the first call when an auditor names a specific document. Without one, locating the Nevada Q2 2023 calculation log becomes an all-hands search during an active audit.
The calculation, certificate, and filing artifacts that populate the system come from the compliance stack already in place. TaxCloud is built for that role: transaction-level calculation logs through the reporting API for any period on demand, consolidated SST filing artifacts for the 23 full member states exportable by period and filing confirmation, and an exemption certificate library with expiration tracking and buyer verification records. A controller building the three-level folder structure pulls from those sources as document inputs for each period folder. When the auditor's day-one list arrives, the system answers it.