What a state sales tax audit notice usually contains
A state sales tax audit generally begins with a written notice from the state tax agency. The notice identifies the taxpayer, states the audit authority, names or references the period under review, and usually gives instructions for the first response or conference scheduling step. [1][3][5]
In practical terms, the first notice usually does four things:
- Identifies the legal entity and state account at issue
- States the authority for the examination
- Defines or proposes the audit period
- Starts the clock for the first response
The first deadline is usually not the deadline to produce the full audit file. It is usually the deadline to acknowledge the audit, coordinate representation, and schedule the opening conference.
For ecommerce brands, a common early failure point is stale address information. If the notice goes to an old registered-agent or tax-contact address, the timeline can still begin running before the right internal team sees it.
What happens at the opening conference
The opening conference is the first formal planning step in the audit. This is where the auditor and the taxpayer or representative usually align on scope, period, records, and process.
The key topics are usually:
- Audit period. The proposed years or filing periods are confirmed or narrowed based on the state’s rules and the filing history. [1][3][5]
- Methodology. The parties discuss how the auditor intends to test the records, including whether sampling will be used.
- Records in scope. The auditor identifies the foundational records needed for fieldwork.
- Process expectations. The parties usually discuss deadlines, extensions, contact protocol, and representation.
For high-volume ecommerce brands, this is also the stage where sampling discussions matter. A brand with multiple channels and large transaction counts usually wants to understand the sampling approach before fieldwork gets too far along, because the method used can materially affect the shape of the findings later.
How the IDR cycle works for an ecommerce brand
Fieldwork usually runs through written Information Document Requests, often called IDRs or something similar depending on the state. Each request asks for records, exports, or explanations by a stated deadline.
The first request usually seeks foundational documents such as:
- Sales or transaction exports by period and ship-to state
- Filed returns and payment confirmations
- General ledger or tax-liability account support
- Exemption certificate records for exempt sales
- Calculation logs or tax-engine support where available
- Marketplace and channel support when the business sells through multiple channels
For an ecommerce brand, the first IDR is often a documentation and reconciliation exercise before it becomes a tax-technical exercise. The auditor is trying to understand how transactions moved from order capture to tax calculation to return filing.
Later IDRs usually narrow in focus. Once the auditor finds mismatches, missing support, or categories that need testing, the requests often shift from broad data pulls to targeted explanations and sample support.
Exemption support is often one of the most concentrated areas of fieldwork. When the auditor samples exempt sales, the business usually needs to produce the specific certificate or exemption support tied to the sampled transaction within the stated response window.
What happens at the exit conference and assessment stage
After fieldwork, the auditor usually presents preliminary findings before the formal assessment is issued. This is often called the exit conference or something similar.
At this stage, the auditor typically presents:
- Proposed adjustments by category or period
- The methodology used to reach the proposed number
- Penalty and interest calculations or the framework for them
- The basis for major audit positions
This is often the last major point where additional records, rebuttal explanations, or methodology challenges can still reduce the proposed assessment before the formal notice is issued.
If the case moves forward, the formal assessment instrument may have a state-specific name, but the practical effect is the same: it states the tax, penalty, interest, and the appeal or protest timeline. [1][3][5]
Taxpayer-rights or advocate offices can also matter here. California, New York, and Texas each publish taxpayer-rights or advocate resources for procedural concerns, even though they do not replace the normal appeal path. [2][4][6]
How long a multi-state ecommerce audit usually takes
There is no single uniform timeline, but multi-state ecommerce audits often run for months rather than weeks. The biggest driver is usually not the state alone. It is how much of the reconciliation and documentation work the business has already done before the audit starts.
Three factors usually affect duration most:
- How many periods are in scope
- How prepared the records and reconciliations were before notice
- Whether methodology or sampling disputes extend the process
For brands with operations across many states, the more important planning point is that audits can overlap. Once one state opens a review, the same nexus records, exemption support, marketplace treatment, and calculation documentation may be needed again elsewhere. That is why audit response usually works better as a portfolio process than a one-state-at-a-time reaction.
Who should be on the audit response team
For a mid-market ecommerce brand, the audit response usually works best when ownership is explicit.
- Controller. Owns the project, reviews responses, and coordinates decisions on scope, rebuttal, and escalation.
- Accountant or finance manager. Pulls records, builds reconciliations, and manages the document flow.
- CPA or tax attorney. Advises on methodology, contested positions, and formal protest or appeal steps.
- Compliance provider. Supplies transaction logs, filing support, exemption support, or calculation records where relevant.
TaxCloud fits into that last category. Its useful role here is the artifact layer: calculation logs, filing support, and certificate records that help the business answer audit requests. The business and its representatives still own the actual audit response.