What Is a Sales Audit? Scope, Records, and Revenue Risks

A sales audit is a structured review of a company’s revenue-generating activities, from how transactions are recorded to whether the right sales tax gets collected. It looks at invoices, contracts, commission calculations, and the internal controls behind them to confirm that reported sales are accurate and that the business is complying with applicable tax and financial reporting rules. For publicly traded companies, federal law makes parts of this review mandatory. For private companies, it’s voluntary but often the cheapest way to catch problems before a state tax authority or an outside auditor finds them first.

When a Sales Audit Is Required

Under the Sarbanes-Oxley Act, the CEO and CFO of a public company must personally certify in every annual and quarterly report that they have reviewed the report, that it contains no material misstatements, and that they have evaluated the effectiveness of the company’s internal controls within the prior 90 days.1Office of the Law Revision Counsel. 15 USC 7241 – Corporate Responsibility for Financial Reports Those controls include everything governing the sales cycle: how revenue gets recorded, how commissions are calculated, and how sales tax obligations are tracked.

The annual report must also include a management assessment of internal controls over financial reporting. For large accelerated filers and accelerated filers, an independent external auditor has to separately evaluate and report on those controls.2Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls Smaller public companies are exempt from the external attestation requirement but still must complete the management assessment. Revenue is the single largest line on most income statements, so the controls around it draw heavy scrutiny.

Private companies have no federal mandate to audit their sales function. They still have exposure. State tax authorities audit businesses on their own schedule, typically looking back three to eight years of sales tax records, and companies paying sales commissions can create wage and hour problems if the payout math is wrong. A voluntary internal audit finds these issues while they’re still cheap to fix.

What a Sales Audit Examines

Auditors don’t review every transaction. They focus on the categories most likely to contain errors, misstatements, or fraud.

Transaction Integrity

The starting point is confirming that recorded sales actually happened. Auditors pull a sample of transactions and check each one against supporting documentation: a purchase order, a shipping record, a signed contract, or an electronic confirmation. Amounts, dates, and customer details get compared against the general ledger. This step catches fictitious revenue entries and duplicate recordings.

Pricing and Discounts

Pricing errors are one of the most common and most preventable sources of revenue leakage. Auditors compare the price on each sampled invoice against the approved master price list or the specific customer contract, then test whether discounts, promotional allowances, and volume rebates match the terms management actually authorized. Unauthorized price overrides always warrant deeper investigation.

Commission Calculations

Commissions sit between the sales function and payroll, which makes them prone to both error and manipulation. The audit traces each commission payment back to the underlying sale, then confirms the payout matches the approved commission schedule. Tiered structures and accelerators complicate the math, and errors compound across pay periods.

Revenue Recognition

Under ASC 606, the revenue recognition standard used in U.S. financial reporting, a company records revenue when it satisfies a performance obligation to the customer, not when cash arrives. The standard follows a five-step process: identify the contract, identify the performance obligations within it, determine the transaction price, allocate that price across the obligations, and recognize revenue as each obligation is fulfilled. Auditors test whether the company applied those steps correctly, especially for contracts that bundle multiple deliverables or span long time periods.

The PCAOB requires auditors to presume that revenue recognition poses a fraud risk. That presumption means they must specifically evaluate which types of revenue transactions could produce a material misstatement from fraud and design their testing around that assessment.3PCAOB. PCAOB Auditing Standard No. 12 – Identifying and Assessing Risks of Material Misstatement

SaaS and Subscription Wrinkles

Subscription businesses face challenges traditional product companies rarely encounter. When a customer pays upfront for a year of software access, the cash doesn’t become revenue on the day it arrives. It sits on the balance sheet as deferred revenue and gets recognized month by month as the service is delivered. Contract modifications complicate the analysis further. When a customer upgrades mid-contract, adds users, or negotiates a discount on renewal, the auditor has to decide whether the change creates a new contract or adjusts the existing one, and each answer changes how revenue gets allocated. Bundled offerings, a subscription plus onboarding plus premium support, require the transaction price to be split across the obligations based on standalone selling prices, with each piece following its own recognition timeline.

Sales Tax Compliance

Sales tax is a distinct component with its own risks. Since the Supreme Court’s 2018 decision in South Dakota v. Wayfair, states can require remote sellers to collect sales tax once they cross an economic activity threshold, even without a physical presence in the state. The threshold in that case was $100,000 in sales or 200 separate transactions within the state.4Supreme Court of the United States. South Dakota v. Wayfair Inc., 585 U.S. 162 (2018) Most states have since adopted similar thresholds. Auditors verify that the company has identified every jurisdiction where it owes tax, that correct rates were applied, and that exempt sales are supported by valid exemption certificates. Missing or expired certificates are one of the most frequent findings in sales tax audits, and the consequences fall on the seller: if you can’t produce the certificate, you owe the tax yourself.

Documentation the Audit Relies On

A sales audit runs on documentation. Gaps immediately raise the risk profile of the engagement. The core records include:

  • Sales invoices and receipts, showing what was sold, the price, the tax charged, and the customer identity.
  • POS system logs or electronic data feeds, used to reconcile daily sales activity against bank deposits and accounting entries. Anomalies here, like voided transactions clustered at unusual times, are one of the first things auditors look for.
  • Customer contracts, essential for testing revenue recognition timing, pricing terms, and discount structures. For SaaS companies, contracts also define the performance obligations that drive the allocation analysis.
  • Pricing master lists and commission schedules, the benchmarks against which actual invoice prices and commission payouts are tested. Deviations without documented authorization count as exceptions.
  • General ledger detail for sales, accounts receivable, deferred revenue, and cash, providing the full accounting trail from transaction to financial statement.
  • Tax exemption certificates justifying why sales tax was not collected on specific transactions. These must be current and properly completed.

How Long to Keep the Records

Retention rules for these documents come from three different regulators and don’t line up neatly. The IRS generally requires businesses to keep records supporting income, deductions, and credits for at least three years after the return is filed. That extends to six years if unreported income exceeds 25% of gross income shown on the return, and to seven years if you claim a loss from worthless securities or bad debt. If you never file a return or file a fraudulent one, there’s no expiration.5Internal Revenue Service. How Long Should I Keep Records?

Companies paying sales commissions have a separate obligation under the Fair Labor Standards Act. Payroll records, sales records, and purchase records must be preserved for at least three years, and records used to compute wages, including rate tables and work schedules, for two years.6U.S. Department of Labor. Fact Sheet 21 – Recordkeeping Requirements Under the Fair Labor Standards Act (FLSA)

Public companies face the longest window. The SEC requires accounting firms to retain workpapers and related documents from an audit for seven years after the audit concludes.7U.S. Securities and Exchange Commission. Retention of Records Relevant to Audits and Reviews As a practical matter, the company itself should keep the underlying sales records at least that long, since the auditor’s workpapers reference them.

How the Audit Runs

Planning

Every sales audit starts with scoping: which product lines, time periods, and transaction types to examine. The auditor assesses risk factors to decide where testing should be heaviest. A division with high staff turnover, a new commission structure, or a recent system migration all raise the risk of misstatement. Sample size depends on the auditor’s assessment of inherent risk, the strength of internal controls, tolerable misstatement, and the expected frequency of errors.8PCAOB. PCAOB AS 2315 – Audit Sampling

Fieldwork

Fieldwork is where auditors dig into the records. Two techniques dominate. Tracing follows a transaction forward, starting with the sales invoice or shipping document and tracking it through to the general ledger. That tests completeness. Vouching works in reverse: start with a general ledger entry and follow it backward to the source document. That tests whether recorded revenue is real and authorized.

Auditors also reconcile between systems. When sales reported by the inventory system don’t match revenue in the accounting system, the gap triggers investigation. Transactions near the end of a reporting period get particular attention because cutoff manipulation, recording next quarter’s sale in the current quarter, most often shows up there. Interviews round out the fieldwork. The standard requires auditors to direct inquiries to employees at varying levels, including those who initiate, record, or process complex transactions.3PCAOB. PCAOB Auditing Standard No. 12 – Identifying and Assessing Risks of Material Misstatement The person entering sales orders often knows about process workarounds that management doesn’t.

Reporting

The audit concludes with a formal report that categorizes findings by severity. Each finding typically includes a description, the root cause, the potential financial impact, and a specific recommendation for remediation. If commission calculations were consistently wrong, the recommendation might target the payroll system logic, the approval workflow, or both. Findings go to management and, for public companies, to the audit committee of the board of directors.

What’s at Stake When Revenue Is Misstated

For public companies, the consequences of a material revenue misstatement escalate quickly. If the error is material to previously issued financial statements, the company has to restate them. A restatement can trigger clawback of executive compensation, a drop in share price, investor litigation, and heightened regulatory scrutiny.9U.S. Securities and Exchange Commission. Assessing Materiality – Focusing on the Reasonable Investor When Evaluating Errors

Officers who certify financial statements containing material misstatements face fines up to $5 million and imprisonment up to 20 years for willful violations.10Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports The SEC’s enforcement arm pursues both companies and individuals for intentional misstatement, and in fiscal year 2024 barred 124 individuals from serving as officers or directors of public companies.11U.S. Securities and Exchange Commission. SEC Announces Enforcement Results for Fiscal Year 2024 Companies that self-report, cooperate with investigations, and remediate control weaknesses before enforcement action generally receive reduced penalties, which is one of the strongest arguments for running internal sales audits on a regular cycle.

Private companies face a different but real risk profile. State sales tax penalties for underpayment typically range from 5% to well over 100% of the tax owed, depending on whether the underpayment was negligent or willful, with interest accruing on top. Catching those exposures internally usually means self-correcting at a fraction of what a state-run audit would cost.

How Technology Has Changed Sales Auditing

Traditional sales audits happen at a fixed point in time and rely on sampling. An auditor reviews a percentage of transactions and extrapolates conclusions about the whole. That approach has worked for decades, but anything outside the sample goes unexamined.

Continuous auditing tools change that equation. Instead of periodic sampling, these systems monitor every transaction in real time and flag anomalies as they occur. An invoice priced below the approved minimum, a commission calculation that deviates from the schedule, a revenue entry booked after the reporting cutoff: automated rules catch these the moment they hit the system rather than months later during an annual review.

AI-powered tools add another layer by identifying patterns that rule-based systems miss. Machine learning models trained on historical transaction data can spot unusual clusters of activity, detect relationships between seemingly unrelated entries, and flag transactions that are technically within policy limits but statistically abnormal. These tools don’t replace an auditor’s judgment. They direct attention to the transactions most likely to contain problems, which makes both sampling-based and continuous approaches more effective.