How to Audit Sales: Transactions, Reconciliations, and Nexus

To audit sales, you gather every record that touches revenue for the period, trace individual transactions from source documents through the ledger to the bank, reconcile your internal numbers against outside records like bank statements and Form 1099-K, and investigate anything that doesn’t match. Learning how to audit sales properly means doing this work in a deliberate order, because each step depends on the one before it, and shortcuts are where errors hide.

What to Pull Before You Start

The audit is only as good as the paperwork behind it. Assemble every document that recorded revenue during the period: point-of-sale reports, sales invoices, and any contracts that governed specific deals. Each invoice needs a date, a unique number, the sale amount, and any sales tax collected. Shipping logs and delivery confirmations back up the claim that a product or service actually moved.

Pull deposit slips and merchant processor statements to show funds reached the business account, with a clear breakdown of cash, checks, and electronic payments. Pull the sales tax returns you filed with state agencies too. Those returns represent what you told the government you owed, and comparing them to your internal logs before an outside auditor does is one of the most productive things you can do.

Keep a master list of every price change, discount code, and promotional rate used during the period. That list explains invoices that came in below standard pricing and prevents legitimate discounts from getting flagged as revenue manipulation. File everything by transaction type so you can pull a specific subset without wading through unrelated paper.

Digital records carry the same weight as paper. For online sales, you need server-generated transaction logs with timestamps, order confirmation numbers, and payment gateway records. If you sell through a third-party marketplace, download the platform’s settlement reports showing gross sales, fees withheld, and net payouts for each period.

How long to keep all of this depends on what’s on your return. The IRS asks for three years in the ordinary case, six years if you failed to report income exceeding 25% of the gross income shown on the return, and seven years if you claimed a deduction for worthless securities or bad debt. If you never filed, or filed a fraudulent return, there is no time limit at all.1Internal Revenue Service. How Long Should I Keep Records The same windows govern how far back the IRS can assess additional tax.2Office of the Law Revision Counsel. 26 USC 6501 – Limitations on Assessment and Collection

Check the Controls That Should Have Prevented Errors

Before looking at any single transaction, ask whether the business is set up in a way that makes fraud and error hard to begin with. Weak controls don’t prove anything went wrong. They just tell you problems would have gone undetected.

Separation of duties is the big one. No single person should be able to initiate a sale, record it, handle the cash, and reconcile the books. When one employee controls the entire lifecycle, nothing stops them from taking cash and deleting the record. Split the work so at least two people touch every transaction. Whoever rings up the sale isn’t the one preparing the deposit. Whoever posts the entry isn’t the one reviewing the reconciliation.

For cash businesses, check whether the point-of-sale system issues a receipt for every transaction and whether the receipts run in a prenumbered sequence. Gaps in that sequence are one of the clearest signs of skimming, where an employee collects payment but never records the sale. A simple gap analysis on receipt or invoice numbers can surface missing transactions no ledger review would catch.

Then look at voids and no-sale register openings. A high volume of voids, especially clustered around one employee or one shift, warrants closer scrutiny. Same for register openings that don’t correspond to any sale. Legitimate operations log these events and require a manager to approve each one.

Trace and Vouch the Transactions

The mechanical core of the audit is tracing. Pick a sale and follow it from the original invoice, through the sales journal, into the general ledger, to the bank deposit. A $500 invoice should produce a $500 debit in accounts receivable or cash, a $500 credit in sales revenue, and eventually a deposit containing that amount. Every link has to match. A break anywhere means an error or something worth investigating.

Work the chain in reverse too, a procedure called vouching. Start with a ledger entry and trace it back to the source document. Tracing tests whether actual sales made it into the books. Vouching tests whether entries in the books have real documents behind them. You need both directions.

Do arithmetic checks alongside the tracing. Manually recalculate tax on a sample of invoices and confirm column totals add up. A few pennies off on one invoice is a rounding issue. A pattern of small errors across many transactions points to a software problem or a manual override somewhere in the process.

Sampling

No audit examines every transaction. You select a representative sample. Multistate Tax Commission guidance recommends at least 50 items when the sample covers the full audit period and at least 100 when drawn from a smaller block of time.3MTC. Manual Audit Sampling The right size depends on how much variation exists in transaction amounts and how many deviations you expect. If the initial sample turns up problems, expand it.

Cutoff Testing

Cutoff testing checks whether sales landed in the right accounting period. A sale shipped on December 31 but recorded in January inflates the next period and deflates the current one. Pull shipping documents and invoices from the last few days of the period and the first few of the next, then verify the recording date matches when goods actually left or the service was performed. This is one of the easiest areas to manipulate and one of the easiest to catch when someone looks.

Analytical Comparisons

Step back from individual records and compare big numbers. Gross profit margin is the classic indicator. If margin held at 42% for three years and then dropped to 35% with no price cut or supply disruption behind it, something in revenue or cost figures shifted. The PCAOB notes that analytical procedures comparing recorded amounts to expected relationships can identify potential omissions, though offsetting factors can obscure problems.4PCAOB Public Company Accounting Oversight Board. AU 329A Analytical Procedures Other useful comparisons: sales per employee over time, revenue by location or product line, and the ratio of cash sales to card sales. A sudden spike in cash at one location can mean card sales are being diverted or cash receipts are being fabricated.

Reconcile Against Outside Records

Internal records tell you what the business says happened. External records tell you what third parties observed. The most consequential discrepancies show up when you compare the two.

Bank Deposits

Match daily sales totals against bank deposits. If Tuesday’s register showed $3,200, a deposit around that amount should appear within a day or two. Timing gaps are normal, particularly at month-end when a sale on the last business day clears the next month. Those deposits in transit need documentation but aren’t inherently suspicious. What raises flags is a pattern of deposits falling short of reported sales, or cash deposits missing entirely.

Subtract credit card processing fees, which typically run between 1.5% and 3.5% per transaction, from gross card sales to get the expected net deposit. Skip that step and every card sale will show a small discrepancy, and you’ll waste hours chasing errors that aren’t there.

Form 1099-K

Payment card companies and third-party settlement organizations report your transaction volumes to the IRS on Form 1099-K.5Internal Revenue Service. Understanding Your Form 1099-K For 2026, a third-party settlement organization files a 1099-K only when payments to a single payee exceed $20,000 and the number of transactions exceeds 200. Payment card processors, meaning credit, debit, and gift card companies, file regardless of amount.6Internal Revenue Service. IRS Issues FAQs on Form 1099-K Threshold Under the One, Big, Beautiful Bill

The gross amount on the 1099-K doesn’t reflect fees, refunds, or chargebacks, so it will almost always be higher than what actually reached your bank account.7Internal Revenue Service. Form 1099-K FAQs – General Information Compare the 1099-K gross against your internal card sales report. If the 1099-K shows $100,000 and your logs show $95,000, that $5,000 gap needs an explanation. Sometimes it’s timing. Sometimes the point-of-sale system dropped transactions. Either way, the IRS sees the 1099-K number, and your reported income has to reconcile with it.

Scrutinize Voids, Refunds, and Credit Memos

Voids, refunds, and credit memos reduce reported revenue, which makes them the most common vehicle for both honest mistakes and deliberate theft. Every voided transaction should have a corresponding void slip with a documented reason and manager approval. If an employee can void a sale and pocket the cash without anyone signing off, the control gap invites fraud.

For returns, match three things: the credit issued to the customer, the inventory return log showing the item was added back to stock, and the original sale. A $200 refund should trace back to a real purchase, and the returned item should show up as one additional unit in inventory. A refund with no original sale, or a returned item that never reappears in stock, is a problem.

Legitimate adjustments happen constantly, including price corrections, duplicate entries, and cancellations. The question isn’t whether adjustments exist. It’s whether each one has a clear paper trail. Businesses that treat this documentation casually end up explaining themselves to auditors or, in the worst case, facing accusations of tax evasion. Federal tax evasion carries fines up to $250,000 for individuals and imprisonment of up to five years.8Office of the Law Revision Counsel. 26 USC 7201 – Attempt to Evade or Defeat Tax

Check Sales Tax Nexus If You Sell Across State Lines

If you sell into multiple states, the audit also has to cover whether you’ve been collecting and remitting sales tax everywhere required. Since the Supreme Court’s 2018 decision in South Dakota v. Wayfair, states can require remote sellers to collect once they cross an economic nexus threshold. The most common trigger is $100,000 in annual sales into a state, though some states set it higher. A handful also use a transaction-count threshold, typically 200 transactions per year.

Flag every state where your sales volume approaches or exceeds those thresholds. If a state audit later concludes you should have been collecting, the obligation doesn’t disappear. You owe the full uncollected tax out of pocket, plus penalties and interest. Going back to bill customers years later isn’t an option.

Selling through a third-party marketplace changes this. Most states have marketplace facilitator laws that shift the collection obligation from the seller to the platform. If Amazon or Etsy already collected sales tax on your behalf, that revenue won’t create a liability for you, but you still verify the platform’s reporting matches your records.

What to Do When You Find an Error

Finding errors during a self-audit is uncomfortable and far less expensive than having a government auditor find them first. The consequences depend on what went wrong, how much money is involved, and whether the error looks intentional.

Federal Penalties

The IRS imposes a failure-to-file penalty of 5% of unpaid tax per month, capped at 25%.9Internal Revenue Service. Failure to File Penalty For accuracy issues like negligence or substantial understatement, the penalty is 20% of the underpayment. A substantial understatement means your tax liability was understated by the greater of 10% of the correct tax or $5,000.10Office of the Law Revision Counsel. 26 USC 6662 – Imposition of Accuracy-Related Penalty on Underpayments Interest runs on unpaid balances at 7% per year as of the first quarter of 2026, compounded daily.11Internal Revenue Service. Interest Rates Remain the Same for the First Quarter of 2026

Omitting more than 25% of gross income gives the IRS six years instead of three to assess additional tax.2Office of the Law Revision Counsel. 26 USC 6501 – Limitations on Assessment and Collection That’s why underreporting revenue by a wide margin is much more dangerous than a small error. It keeps you exposed to audit for twice as long.

State Sales Tax Penalties

State penalties for late filing or underpayment vary. Most impose a monthly percentage on the unpaid balance with a cap, often 5% per month up to 25%. Interest on underpaid state sales tax runs anywhere from around 3% to 18% annually depending on the state, and some states tie the rate to the federal prime rate plus a margin, so the number shifts quarterly.

Voluntary Disclosure

If your self-audit reveals you should have been collecting sales tax in a state where you never registered, a voluntary disclosure agreement can cut the damage sharply. These agreements, negotiated with state tax authorities directly or through the Multistate Tax Commission’s national program, waive penalties in exchange for your commitment to register, file back returns, and pay tax owed going forward.12Multistate Tax Commission. Multistate Voluntary Disclosure Program Most states also limit the lookback period to three or four years, shorter than a standard audit reach. The catch is timing. You have to come forward before the state contacts you. Once an audit notice arrives, voluntary disclosure is off the table.

Close Out With Adjusting Entries and a Workpaper File

Every error found during the audit needs an adjusting journal entry to bring the general ledger in line with reality. If internal records showed $50,000 in revenue that should have been $48,000 after accounting for misclassified returns, post the correcting entry. A manager or owner then signs off to confirm the review is complete.

File the final workpapers securely alongside the supporting documents for the period. They do double duty. They demonstrate you conducted a thorough review, and they give you a ready defense file if a government agency comes knocking later. Lenders, investors, and potential buyers also ask to see audit workpapers during due diligence, and a clean report signals the business takes its financial hygiene seriously. The best audits don’t just verify the past. They expose the process weaknesses that produced the errors, so the next cycle starts cleaner than the last one.