What a state sales tax audit notice contains, and the 30-day response window
A state sales tax audit begins with a formal written notice from the state's Department of Revenue or Department of Taxation. The notice is not a request. It cites the statutory authority for the examination, identifies the entity under audit, defines the proposed period under review, and names the assigned field auditor.
For a Shopify or Shopify Plus brand, the notice arrives by certified mail to the registered agent address or the business address on file from the original sales tax permit registration. If that address is stale, the notice goes to the wrong location and the 30-day response clock starts regardless. The first failure point in most multi-state audits is a notice that sat unread for three weeks at an outdated registered agent.
Standard notice contents:
- The taxpayer's legal entity name and account number with the state
- The statutory authority for the examination: Cal. Rev. & Tax. Code §7051 for California CDTFA audits [1]; NY Tax Law §1138 for New York DTF audits [3]; Tex. Tax Code §151.616 for Texas Comptroller audits [5]
- The proposed audit period, typically three years measured from the notice date or the date of the last examination
- The assigned field auditor's name and direct contact information
- A response deadline, typically 30 calendar days from the notice date
The 30-day window is for acknowledging the audit and scheduling the opening conference, not for producing records. Extensions of 15 to 30 additional days for conference scheduling are routine and should be requested in writing before the deadline.
Four triggers account for most multi-state audits at the $20M to $80M band: a nexus inquiry letter that generated no response; a 1099-K cross-match where gross receipts reported to the state didn't reconcile with filed sales tax totals; an M&A diligence review that surfaced historical exposure and triggered a voluntary disclosure cross-referencing the selling entity; and automated threshold monitoring, where states cross-match marketplace-reported sales against registered seller lists to surface brands that crossed $100,000 in taxable sales without registering. California also audits approximately 5 percent of registered taxpayers on a rolling random-selection basis, independent of reported liability. [1]
The opening conference: scope, period, and the sampling-method decision
The controllers TaxCloud has watched succeed at the opening conference do one thing consistently: they ask for statistical sampling instead of block testing before the auditor frames the scope. That single move tends to compress the final assessment more than any rebuttal made later. By the time fieldwork starts on a block-test methodology, the election window has closed and the rebuttal path is procedural arithmetic, not methodology.
The opening conference is the first formal meeting between the brand's representative and the field auditor, typically scheduled within 30 to 60 days of the notice. Four decisions made here govern what follows.
Audit period
The proposed period under review is confirmed or negotiated. The standard statute of limitations is three years from the return due date in most states: California (Cal. Rev. & Tax. Code §6487), [1] New York (NY Tax Law §1147), [3] and most others. Texas uses a four-year standard period (Tex. Tax Code §151.615). [5] A three-year audit covering fiscal years 2022 through 2024 means every return and underlying transaction record filed during that window is in scope.
Audit methodology
The auditor proposes how to test the brand's records. Two primary methods:
| Method | How it works | Typical application |
|---|---|---|
| Block testing | Auditor selects a specific time block (one month or quarter) and projects the error rate from that block across the full audit period. | Smaller transaction populations; limited record availability; single-channel brands. |
| Statistical sampling | A statistically valid random sample drawn from the full transaction population, with results projected across the full period. | High-volume, multi-channel brands; agreed methodology between brand and auditor. |
Sampling-method election
In most states, the brand can request statistical sampling instead of block testing. [8] The request must be made at or before the opening conference. For a multi-channel brand processing tens of thousands of transactions per month across Shopify, Shopify Plus, Amazon, Walmart, and BigCommerce, statistical sampling reduces the risk of a single anomalous period (a Black Friday spike, a sitewide promotion month) distorting the full-period projection. The brand owns the request; the auditor's default is whatever method makes their work shortest.
Records in scope
The auditor defines what fieldwork will require: sales journals, purchase journals, exemption certificates, general ledger excerpts, and tax calculation logs. For a multi-channel brand, this includes platform transaction exports, the calculation provider's rate logs, and consolidated SST filing statements for the 23 full member states. Knowing what the auditor will ask for before the conference lets the brand assess which records exist and where gaps are. TaxCloud's reporting API generates the transaction-level rate logs and period-summary reports field auditors request as standard first-IDR items, so the controller knows what is in hand before the opening conference closes.
The IDR cycle: what auditors request from an ecommerce brand
The single most expensive controller misstep across the multi-state audits TaxCloud has supported is missing an IDR response window. States interpret silence as concession. We have watched brands hand over six-figure assessment lines by failing to extend a single IDR deadline in writing. The cost of the missed window is rarely the work of the IDR itself. It is the auditor's authorization, on a missed deadline, to complete fieldwork using whatever records are already in hand, which produces the least favorable projection available.
Fieldwork runs on Information Document Requests. Each IDR is a written list of records, data exports, or written explanations the brand must deliver by a set date. A standard multi-state audit runs three to six IDR cycles, each with a 10-to-30-day response window. Extensions are routinely granted on first ask, but the request must go in writing before the deadline.
The first IDR typically covers foundational records:
- Sales journals or platform transaction exports for the full audit period, broken down by ship-to state
- Purchase journals covering the same period
- General ledger exports for the sales tax liability accounts
- Sales tax returns filed during the period, including amended returns and payment confirmations
- Consolidated SST filing statements for member states where applicable [8]
- The exemption certificate file for all transactions claimed as exempt during the period
For a brand on Shopify or Shopify Plus selling across 25 to 40 states, the first IDR is a documentation project before it is an accounting project. The auditor needs to understand how transactions were captured at checkout, how rates were applied at the jurisdiction level, how marketplace-facilitated sales were tracked, and how the calculation provider logged each transaction against what was filed.
Subsequent IDRs narrow. After reconciling transaction logs against filed returns, the auditor identifies variances: transactions that appear taxable but were not taxed, exemption claims that lack supporting certificates, periods where reported gross receipts don't match platform exports. Each later IDR asks the brand to explain a discrepancy or produce missing documentation.
Exemption certificate review is where multi-channel ecommerce brands face the most concentrated fieldwork exposure. The auditor samples claimed-exempt transactions and requests the supporting certificate for each. Missing certificates, expired certificates, and certificates on the wrong form for the state are the three most common sources of proposed adjustments. A searchable, organized certificate library with expiration tracking is the evidence chain the auditor works through in this phase. TaxCloud's exemption certificate library stores certificates by customer and state with expiration tracking, so the controller can produce a specific certificate inside a 15-day IDR window rather than working through archived files in the middle of month-end close.
The brand is entitled to representation throughout fieldwork by a CPA, a tax attorney, or both. The field auditor communicates with whoever the brand designates as its authorized representative.
The exit conference, Notice of Determination, and the taxpayer rights advocate
The taxpayer rights advocate is the single most underused resource in a state sales tax audit. Brands that engage California CDTFA's, [2] New York DTF's, [4] or Texas Comptroller's [6] advocate office early, at the first procedural friction rather than after the assessment lands, see the friction decompress quickly. The advocate doesn't dispute the substantive tax position. The advocate handles delayed auditor responses, methodology concerns the supervisor hasn't addressed, and reasonable accommodation on document production. It is a parallel channel, not an alternative to the formal appeal path, and it is available from the opening conference forward.
The formal lifecycle runs through the exit conference and the Notice of Determination. When fieldwork closes, the field auditor prepares preliminary findings. The exit conference is where those findings are presented before the formal assessment issues. It is the last substantive checkpoint before proposed numbers become the official assessment.
Exit conferences typically occur 30 to 90 days after the final IDR cycle closes. The auditor presents:
- The proposed adjustment amount by period and by category (taxable sales underreported, exempt sales rejected for missing or deficient certificates, use tax on unreported purchases)
- The methodology used to arrive at the amount: sampling method applied, error rate, projection period
- Penalty calculations and interest accrued to the proposed assessment date
- The statutory basis for each category of adjustment
The brand's rebuttal window to preliminary findings is 30 to 60 days depending on the state. This window is used for three purposes: submitting documentation not produced during fieldwork (certificates retrieved after the relevant IDR closed, additional calculation records); disputing the sampling methodology, projection arithmetic, or error-rate calculation; and presenting legal arguments on taxability positions where the auditor's classification is contested.
If additional evidence or a methodology argument changes the auditor's findings, the assessable amount is reduced before the formal notice issues. If the rebuttal is not accepted or only partially accepted, the auditor closes their file and the case moves to formal assessment.
The formal assessment instrument is called a Notice of Determination in California, [1] a Notice of Determination and Demand for Payment in New York, [3] and a Notification of Audit Results leading to a formal Comptroller's assessment in Texas. [5] Regardless of the instrument name, it states the total tax due, the penalty, and the interest accrued to the assessment date, and it includes both a payment deadline and an appeal deadline, typically 30 days from the notice date.
Paying the assessment to stop interest accrual does not waive appeal rights in most states. Payment and protest can proceed simultaneously. The decision to pay-and-protest, protest-only, or accept is a tactical call with counsel before the brand responds to the formal notice.
How long a multi-state ecommerce audit takes
Audit duration tracks pre-audit reconciliation state more reliably than it tracks the state itself. Brands that already had the transaction-to-return reconciliation chain in place when the notice arrived close audits in 6 to 8 months. Brands that build the chain during the audit close in 12 to 18. The cost of late preparation is roughly 2x in audit duration and 3x in staff-accountant time at close, because the same records get assembled under IDR deadline pressure rather than on a controlled schedule.
State and period scope set the band; preparation state moves the brand inside the band. The 6-to-18-month range is real, but it covers a wide spread.
| State | Typical duration | Standard lookback | Notes |
|---|---|---|---|
| California (CDTFA) | 12 to 24 months | 3 years (Cal. Rev. & Tax. Code §6487) [1] | Formal conference program; highest transaction volume for multi-channel brands |
| New York (DTF) | 12 to 18 months | 3 years (NY Tax Law §1147) [3] | Methodical process; AND-test threshold adds nexus complexity for many brands |
| Texas (Comptroller) | 9 to 18 months | 4 years (Tex. Tax Code §151.615) [5] | Longer lookback than most states; well-resourced audit division |
| Washington (DOR) | 9 to 18 months | Varies | Aggressive on gross-receipts measurement; explicit trailing nexus rules under RCW 82.08.052 [7] |
| Illinois (IDOR) | 9 to 12 months | 3 years | Standard process; formal administrative hearing rights |
| SST member states (GA, OH, NC, WI) | 6 to 12 months | Varies | Smaller tax base per state; audits less likely to escalate beyond the field auditor |
| Lower-volume states (WY, ND, SD) | 4 to 8 months | Varies | Single-period audits typical; fewer IDR cycles; faster resolution |
Three variables extend timelines beyond the typical range: the number of tax periods in scope, contested sampling methodology that escalates to the audit supervisor, and extended IDR cycles when the auditor's own response to rebuttal documentation takes additional time.
The multi-state coordination challenge is the second observed pattern, and the more expensive one. A multi-state ecommerce brand at $20M to $80M typically faces concurrent audits across three to five states inside a 12-month window once enforcement activity starts. The mistake is treating each audit as independent. The states share data; the brand's response to California CDTFA shapes what New York DTF asks for six months later. A position taken at the opening conference in one state, especially on sampling methodology or sourcing rules for facilitated sales, becomes part of the documentary record other states reference. Controllers managing concurrent audits run the team as a portfolio: one set of reconciliation artifacts, one position memo on contested taxability questions, one response calendar across all open IDRs.
The audit response team and the compliance provider's role
A state sales tax audit for a $20M to $80M ecommerce brand is a team project with four distinct roles.
The controller
The controller owns the project. They are the primary liaison with outside counsel, the person who reviews and approves IDR responses, and the decision-maker on whether to challenge preliminary findings at the exit conference or accept an assessment. If the audit escalates to the supervisor level or a formal protest hearing, the controller decides which positions the brand can support with documentation.
The staff accountant
The staff accountant runs the document work: exporting transaction records for the audit period, pulling filed returns and payment confirmations, retrieving exemption certificates by customer and state, reconciling account totals across periods. An audit covering three years of transactions across 30 states is a documentation marathon. This is the role that wears down under concurrent multi-state audits, and the capacity planning question is whether one staff accountant can absorb two simultaneous IDR cycles on top of routine month-end close.
The CPA or tax attorney
The CPA or tax attorney advises on positions, challenges the sampling methodology when the proposed method is unfavorable, manages communications with the field auditor, and represents the brand at the exit conference and any formal proceedings. Most brands in their first multi-state audit engage outside representation from the opening conference forward.
The compliance provider
The compliance provider is not a participant in audit proceedings. Its role is producing the artifacts the brand hands to the auditor.
The brand here is past wondering whether the audit will arrive. The question is what the operating model looks like when three state audits open inside the same fiscal year. TaxCloud is built for that artifact-supply layer: the calculation logs, the SST filing statements, and the certificate library the auditor will ask for, organized the way an IDR cycle requires them. The brand owns the audit response, the legal positions, and the formal proceedings. TaxCloud absorbs the calculation, filing, and certificate documentation so the controller and their team can direct their attention to what the auditor is actually challenging.