How do I make my business records audit-ready?

Applies to: United States · Updated 2026-09-27

Audit-ready is a state you can test: someone other than you can take a figure from your reports, follow it to the transactions and documents behind it, trace back up, and produce everything promptly. Get there by sampling figures, attempting each full trail, timing retrieval and logging every failure as a gap with an owner. Close each gap by recovering the document, substituting other evidence or recording it as unsupported, then hold the state with monthly checkpoints.

What does audit-ready mean in terms you can check?

IRS Publication 583 says you must keep your business records available at all times for inspection by the IRS, and that if the IRS examines a return you may be asked to explain the items reported. Treat your records as audit-ready only when all six of these properties hold:

  • Complete. Every account has its transactions for every month in scope, with no missing statements or numbered documents.
  • Reconciled. Every account with an outside statement agrees with it, and nothing sits unidentified in a suspense or uncategorized account.
  • Supported. Each transaction that needs a document has one that is legible and that a stranger can understand.
  • Traceable both ways. A report figure leads down to its transactions and documents, and any document leads back up to its figure.
  • Retrievable. Someone other than the person who filed a record can find it quickly.
  • Consistent. The books agree with every return and report given outside the business, or each difference is explained in writing.

A full folder of documents is not this state: if nothing links each entry to its document, the trace fails.

How does the two-way trace work?

The IRS's Automated records page says computerized records meet its requirements only if they reconcile with the taxpayer's books and return, shown by demonstrating the relationship between them, and must carry enough transaction-level detail for the underlying source documents to be identified. The trace runs both ways:

  • Down. Start from a report figure and follow it to the account detail, each transaction, and that transaction's document and payment line. This finds figures you cannot support.
  • Up. Start from a document and follow it to its entry, account, period and report figure. This finds documents never recorded, recorded twice or posted to the wrong account or month.

Both directions need each entry to point to its document, by attachment or a memo ID, and each document to match its entry by that ID or by date, payee and amount.

What does one traced figure look like?

March's profit and loss shows Repairs and maintenance of 1,860.00. The March account detail lists three transactions:

DatePayee as enteredAmountDocument found
Mar 4Ace Plumbing640.00Invoice A-2231, attached
Mar 17Metro HVAC985.00Another vendor's receipt
Mar 28Transfer235.00None
Total1,860.00

Tracing each link found these breaks:

LinkWhat you checkBreak found
Report to detailDetail total equals the report figureNone
Detail to transactionA real payee and a memoMar 28 has neither
Transaction to paymentA matching bank or card line in a reconciled monthNone
Transaction to documentPayee, date, amount and purpose matchMar 17 has the wrong file; Mar 28 has none
Document to figureA document pulled from the March folder leads to an entryA 410.00 roofing invoice has none

The real Metro HVAC invoice turns up in an inbox. The 235.00 is the owner's home repair, a personal item to move out of business expense. The roofing invoice could be unrecorded, paid personally or another month's bill, so investigate it before posting anything.

What do reconciled and complete require?

OpenStax's Principles of Accounting (section 8.6) describes the bank reconciliation as the report that explains and documents any differences between the bank's balance and the balance in the company's records; items the bank has recorded but the company has not must then be entered in the books. In a period already reported, do not enter them there: leave the period as reported, log each item as a gap and take it through the correction route for reported periods. Reconcile every account with an outside statement, for every month in scope, and save each reconciliation report:

  • Checking, savings and credit card accounts
  • Loans and lines of credit
  • Payment-processor and marketplace balances
  • Payroll and sales tax balances, against the agency's records or the returns filed

Then clear what reconciled accounts can still hide:

  • Parked items. Every entry in a suspense, uncategorized or "ask my accountant" account is identified and moved, or logged as a gap. In a period already reported, leave the entry as reported, log it as a gap and take it through the correction route for reported periods.
  • Missing runs. No month lacks a statement, no connected feed has stopped, and no numbered series of invoices, checks or receipts has unexplained gaps.

What makes a supporting document good enough?

IRS Publication 583 says supporting documents include sales slips, paid bills, invoices, receipts, deposit slips and canceled checks, and that they support the entries in your books and on your tax return. For readiness, each document passes three checks:

  • Findable. It is attached to its entry, or the entry carries an ID that leads straight to it.
  • Legible. Rev. Proc. 97-22 defines legibility for electronically stored records as an observer being able to identify all letters and numerals positively and quickly; hold faded receipts and cropped photos to that test.
  • Understandable. A note on the entry says what was bought and for what purpose, so a stranger does not need you to explain it.

Which expenses need which receipts is a separate question.

Do the books agree with what you reported outside the business?

For the periods in scope, compare the books with every figure given outside the business:

  • Income, sales tax and payroll tax returns
  • Wage statements and Forms 1099 the business issued
  • Information returns others issued about the business
  • Figures given to lenders, insurers or investors

Where one differs, establish the difference to the cent, identify its cause (timing, a book-only adjustment or an error), and file a written explanation with that period's records.

What changes when the period was already reported?

If nothing from the period has been reported outside the business, correct the record and note why. Once any figure from it has been reported, on a return or to a lender, whether or not the books are closed, do not recategorize, rename or delete entries to tidy up: that creates a new difference from what was filed and erases the record behind it. Log the problem, leave the period as reported, and take the fix through the correction route for reported periods, which is its own question.

Intuit's help page "Lock your books in QuickBooks Online" (updated 9/15/2026) says you set a lock date after you review and reconcile your accounts, and that QuickBooks will then either give a warning or ask for a password, depending on your settings. If you use it, choose the password option, since the page says that with a warning alone users can still make changes; where you can, have someone who does not post entries hold the password.

How should personal and mixed items be handled?

OpenStax's Principles of Accounting (section 3.1) states the separate entity concept: a business may only report activities specifically related to company operations, not those that affect the owner personally. For each personal or mixed item already in the books:

  • Identify it. Review owner transfers and categories that often mix uses, such as phone, vehicle, home office and meals.
  • Resolve it. Record wholly personal items as transactions with the owner, not business income or expense, and split each mixed payment already posted: the business share stays in the expense account and the personal share moves to the owner's account, so the split still totals the amount paid. In a period already reported, leave the entry as reported, log it as a gap and take it through the correction route for reported periods.
  • Evidence the boundary. Write down and date the basis for each split, such as a mileage log, so a reviewer does not draw the line for you.

Keeping them apart from now on is its own question.

What makes electronic records producible?

IRS Publication 583 says an electronic storage system must index, store, preserve, retrieve and reproduce the stored books and records in legible format, and must provide a complete and accurate record of your data that is accessible to the IRS. Rev. Proc. 97-22 also requires reasonable controls ensuring the system's integrity, accuracy and reliability; reasonable controls to prevent and detect unauthorized creation, addition, alteration, deletion or deterioration of stored records; and an inspection and quality-assurance program with periodic checks of them. It lists back-up copies, off-site storage and testing to confirm records integrity as recommended practices, a decision it leaves to the business.

Publication 583 allows paper originals to be destroyed only once the system has been tested to establish that they are being reproduced in compliance with IRS requirements and procedures are established to ensure continued compliance; you must still keep any other required records, and a system that does not meet those requirements may bring penalties unless you keep the originals in a way that lets you and the IRS determine your correct tax.

Turn these conditions into three tests:

  • Retrieve from the entry. Click through from sampled entries to each attachment, across any bank feed, receipt app or shared drive; a file existing somewhere does not prove the link works.
  • Restore from backup. Restore a file to a separate location and open it; an unrestored backup is an assumption.
  • Reproduce legibly. Export or print a sample and confirm every figure can be read.

For receipts scanned into an app or document store, Rev. Proc. 97-22 deems stored records destroyed if you stop maintaining the hardware and software its conditions need, unless they remain available to the IRS in conformity with it, so export the documents and their index before cancelling such a service.

How should records be organized so someone else can find them?

The IRS's page "What kind of records should I keep" says to keep supporting documents in an orderly fashion and in a safe place, for instance organized by year and type of income or expense. Rev. Proc. 97-22 accepts an index for stored records that is functionally comparable to a reasonable hardcopy filing system, and gives as an example a unique identification number for each stored document. A scheme that does both:

  • One folder per year, with subfolders for sales, purchases, payroll, statements, filed returns and judgment notes
  • File names that sort and search, such as 2026-03-17_MetroHVAC_7714_985.00
  • The file name or ID written in the entry's memo, so ledger and document lead to each other
  • Statements and filed returns kept as issued, not only as data inside a system

The standard is retrieval by someone who did not file the record.

How should judgments be documented when they are made?

The IRS's examiner manual (IRM 4.10.7.3) says writings made contemporaneously with an event generally reflect the actual facts, so write the reason when you make the entry. AS 2501, the Public Company Accounting Oversight Board's standard for auditing accounting estimates in financial statements, describes testing a company's process for an estimate as evaluating the methods, data and significant assumptions used and whether the company has a reasonable basis for those assumptions; its questions are a useful model for any note that explains a judgment. A note that answers those questions records:

  • What the policy, estimate, allocation or entry is, and the period it covers
  • The method, the data used and where the calculation is saved
  • The assumptions and why they are reasonable
  • Who decided, and when

Write one for each policy, estimate, allocation and manual or unusual journal entry, and file it with that period's records.

Is the system keeping its record of who changed what?

A lost change history cannot be rebuilt, so check now whether yours exists, whether it can be switched off, what it records and how long it keeps entries. Two examples:

  • QuickBooks Online. Intuit's help page "Use the audit log in QuickBooks Online" (updated 8/4/2026) says you cannot turn off the audit log, that it tracks financial transactions and all account activity, including user sign-ins, settings changes and edits to customers, vendors and employees, and that events recorded in it are available for two years. For any period in scope older than two years, record that the log no longer covers it.
  • Sage 50 (U.S.). Sage's 2026 help page "Using Sage 50's Audit Trail" (published June 17, 2026) says the audit trail logs when a person enters, edits and removes data, and highly recommends setting up user records in the User Security window so Sage 50 can associate the logged-in user with the data entered. Sage says this gives a more complete audit trail, so set up a user record for each person who works in the company file. The page says the audit trail is available in Sage 50 Premium Accounting and higher, so confirm your edition has it and, if not, record that it has no audit trail.

Using the change history to find altered or deleted transactions is a separate question.

Who can enter, change and delete?

OpenStax's Principles of Accounting (section 8.3) notes that password protection can keep employees from accessing systems and changing data without authorization. Keep evidence of the boundary:

  • A separate login for every person, with no shared credentials
  • A dated list of users and roles, updated when anyone joins, leaves or changes duties
  • Outside bookkeepers set up as separate users and removed when the work ends

How do you run the self-test?

Run it before anyone asks:

  1. Fix the scope. Choose the periods that must be ready; how far back to reach is a separate question.
  2. Pick the sample. Take the largest accounts, accounts with manual journal entries, holding accounts, owner and mixed-use accounts, cash sales and a few figures at random from each period, plus some documents pulled from the files.
  3. Hand it to someone else. A person who did not file the records attempts each retrieval without your help.
  4. Attempt each full trail. Go from report to ledger, transaction, payment record and document, then from each pulled document back to its figure.
  5. Time each item. A document should come up from its entry within minutes; anything needing an email search, a call to a former bookkeeper or your memory counts as a failure.
  6. Log every failure. Record the item, the broken link, what is missing, the route, an owner and a date.

If you work alone, retrieve strictly from what the files show and count anything you had to remember as a failure. The example above produces this gap log:

ItemBroken linkRouteOwnerDue
Repairs, Mar 17, 985.00Transaction to documentRecover the invoice from the vendor's emailBookkeeperApr 30
Repairs, Mar 28, 235.00Detail to transactionReclassify as personal if March is not yet reportedOwnerApr 15
Roofing invoice, 410.00Document to figureInvestigate before recordingBookkeeperApr 30

When the list outruns your time, start with large items, items that feed a filed return, and evidence that is decaying, such as copies only a vendor or former provider holds.

What changes if a request has already arrived?

If a notice, examination letter or lender request is outstanding, its deadline governs: preserve everything for the periods it names, change nothing in them, and put the response ahead of any other readiness work. Assembling a response to a tax notice, or the documents a lender or insurer wants, are their own questions.

What can you rely on when the original support is gone?

The IRS's examiner manual (IRM 4.10.7.3) states the best evidence rule, that original evidence be used when possible, and says secondary evidence is used when original evidence is unavailable. Its example of acceptable secondary evidence is an examiner's copies of original documents, and the manual is written to help examiners weigh evidence, not to list substitutes a business may rely on. It treats taxpayers' oral statements as direct evidence that must be thoroughly considered, with the reliance placed on them based on the taxpayer's credibility and surrounding circumstantial evidence. The same section says oral evidence should not replace available documents, cannot alone replace written documentation a specific record-keeping rule requires (for example, IRC 274), and need not be accepted without further inquiry. IRS Publication 583 says that without a canceled check you may be able to prove payment with certain account statements prepared by financial institutions, which must be highly legible and must show:

  • For a check, the check number, amount, payee's name and date the institution posted it
  • For an electronic funds transfer, the amount transferred, payee's name and date the institution posted it
  • For a credit card, the amount charged, payee's name and transaction date

Publication 583 adds that proof of payment by itself does not establish that you are entitled to a tax deduction, and says to keep other documents, such as credit card sales slips and invoices, to show you incurred the cost. Each gap then takes one of three routes:

RouteWhat to do and record
Recover or reconstructAsk the issuer, such as the supplier, bank or former bookkeeper, for a copy; attach it and note when it arrived.
Substitute other evidenceAttach the best substitute, such as the statement line, a contract or a dated account from someone with first-hand knowledge, which cannot alone replace records the law requires in writing, and note that the original is missing, why, and what stands in for it.
Document as unsupportedAttach a dated explanation of what the entry was, why no support exists and what you tried, and keep it on the gap log.

A single lost receipt is covered in its own question.

What if earlier records sit in another system or with a former provider?

Recover access first, because records you cannot reach cannot be tested. The IRS's Automated records page says a taxpayer's use of a third party, such as a service bureau or other third party service, does not relieve the taxpayer of its recordkeeping obligations and responsibilities. Ask the former bookkeeper or provider in writing for the ledgers, reconciliations, attachments and working files for the periods in scope, and export full data from any system before access ends. Meanwhile keep what you already hold unchanged and log each unreachable period as a gap with an owner and a date.

What if the business handles a lot of cash?

Cash transactions leave no record made outside the business, so the evidence is what the business made at the time. IRS Publication 583 describes a daily summary of cash receipts as a record of cash sales for the day, and the IRS's page "What kind of records should I keep" lists cash register tapes among the documents for gross receipts. OpenStax's Principles of Accounting (section 8.3) adds that prenumbered documents provide assurance that all sales are recorded. Keep register records and a daily summary, use prenumbered receipts, get a receipt for each cash payment, and tie deposits to the summaries. Where a day's record is missing, rebuild it from register data and deposit slips, mark it as reconstructed with the method used, and log the gap.

How do you keep the records in this state?

Readiness decays with every unreconciled month, so build these checkpoints into routine:

CheckpointWhat to do
Recording a transactionAttach the document and write the note at once
Making a judgmentWrite the dated note the same day
Every monthReconcile every account with an outside statement, clear holding accounts, save the reports and lock the month
Every quarterCompare the books with each return or report filed that quarter, and trace a few figures both ways
Twice a yearRestore something from backup, review users and access, and note which periods in scope have passed the change history's availability limit
Every yearRun the full self-test and take every open gap to a route, keeping the log with its closed and unsupported entries
A new system, feed, provider or staff memberTest retrieval end to end and review access

Month-end and year-end close procedures are separate questions.

Sources
  1. Internal Revenue Service — Publication 583, Starting a Business and Keeping Records, Publication 583 (12/2024)
  2. Internal Revenue Service — Automated records, Page Last Reviewed or Updated: 21-Aug-2026
  3. Internal Revenue Service — Rev. Proc. 97-22 (electronic storage systems), undated (no date printed on the document)
  4. OpenStax, Rice University — Principles of Accounting, Volume 1: Financial Accounting — 8.6 Define the Purpose of a Bank Reconciliation, and Prepare a Bank Reconciliation and Its Associated Journal Entries, Apr 11, 2019
  5. Intuit Inc. — Lock your books in QuickBooks Online, Updated 9/15/2026
  6. OpenStax, Rice University — Principles of Accounting, Volume 1: Financial Accounting — 3.1 Describe Principles, Assumptions, and Concepts of Accounting and Their Relationship to Financial Statements, Apr 11, 2019
  7. Internal Revenue Service — What kind of records should I keep, Page Last Reviewed or Updated: 03-Aug-2026
  8. Internal Revenue Service — Internal Revenue Manual 4.10.7, Issue Resolution (4.10.7.3, Evaluating Evidence), 4.10.7.3 subsections dated 01-01-2006
  9. Public Company Accounting Oversight Board — AS 2501: Auditing Accounting Estimates, Including Fair Value Measurements, undated standard page
  10. Intuit Inc. — Use the audit log in QuickBooks Online, Updated 8/4/2026
  11. The Sage Group plc (Sage 50 U.S. product help) — Using Sage 50's Audit Trail, Sage 50 U.S. 2026 help, published June 17, 2026
  12. OpenStax, Rice University — Principles of Accounting, Volume 1: Financial Accounting — 8.3 Describe Internal Controls within an Organization, Apr 11, 2019

Machine-readable: markdown · JSON