Real Pains, Real Problems: What Corporate Tax Teams Keep Telling Us
25 August
An audit doesn't test what your company did. It tests what your company can prove. And the gap between those two things is where a lot of otherwise compliant organizations lose — not because they got the tax wrong, but because they can't reconstruct how a notice from three years ago was handled, by whom, and with what support.
That's worth dwelling on, because the timelines are longer than most people plan for. The IRS generally has three years from the filing date to assess additional tax, but that window stretches to six years if more than 25% of gross income was omitted, and it never closes at all for a fraudulent return or a return that was never filed. States run their own clocks, often comparable or longer. So the notice you resolved and forgot about in 2023 isn't closed history — it's potential evidence in an examination that hasn't started yet.
The question that decides how that examination goes is deceptively simple: when the auditor asks for the history, what will you hand them?
Institutional knowledge walks out the door
In most tax departments, the real audit file doesn't live in a system. It lives in people. The controller who remembers why that state assessment got abated. The analyst who knows which folder the supporting workpapers landed in. The veteran who "just knows" how a particular agency handles a particular issue.
That arrangement is fragile in the best of times and catastrophic during turnover. When the person who handled a notice leaves, the context leaves with them — the reasoning, the correspondence trail, the proof that you responded on time and substantiated your position. A spreadsheet might capture that a notice was "resolved," but it rarely captures how, and almost never preserves the documents that make the resolution defensible two or six years later.
Reasonable-cause penalty relief makes this concrete. That relief turns entirely on a contemporaneous record of what happened and what you did about it. Reconstructed after the fact, under audit pressure, from memory and scattered inboxes, the same facts are dramatically weaker.
What a defensible record actually looks like
Audit-ready isn't a binder you assemble when the examiner calls. It's a byproduct of how you handle notices every single day. A defensible record, per notice, captures the full lifecycle: what arrived and when, which entity and jurisdiction it concerned, who took ownership, what the response was, the supporting documentation attached to it, the agency's confirmation, and the dates at every step. Strung together across the organization, those records become a system of record — a single, queryable source of truth instead of a scavenger hunt.
For public companies, this isn't just convenient; it's a controls question. Auditors and SOX frameworks reward repeatable, documented processes and look skeptically at heroics. "We always get it done" is not a control. "Here is the standardized intake, ownership, deadline, and resolution trail for every notice" is.
An audit workflow built by people who've lived it
Knowing what a defensible record should look like is one thing. Capturing it in the chaos of an active examination is another — which is why Notice Ninja's audit workflow was designed by tax practitioners who ran audits inside the incumbent enterprise tax system and knew exactly where it left them wanting.
The workflow starts where an audit actually starts: with the audit notice. From that first letter, it tracks the entire lifecycle of the examination in one place rather than across inboxes, drive folders, and individual memories. Every Information Document Request (IDR) is logged and tracked — what the agency asked for, what was produced, by whom, and against which deadline — so nothing slips and you always know where each request stands. Every note lives on the record alongside the correspondence, so the reasoning behind a position is preserved, not lost when the person who made it moves on.
And when the examiner asks for the history, you don't reconstruct it — you export a download package: the audit notice, the IDRs and responses, the supporting documentation, and the contemporaneous notes, assembled into a single defensible record. That's the literal answer to the question this article opened with. Instead of a scramble, you hand over a complete, dated, substantiated file.
The point isn't just tidiness. An audit managed this way is faster to respond to, far easier to defend, and dramatically less dependent on any one person being available to explain what happened.
You prepare for an audit long before it arrives
The reframe we'd offer any tax leader is this: audit readiness isn't a project you start when an examination opens. By then, the record is whatever it is. Readiness is built one notice at a time, in the ordinary course — when intake is centralized so nothing is lost, when ownership is explicit so accountability is clear, when documentation is attached at the moment of resolution rather than hunted for years later, and when the history is preserved in a system rather than in someone's head.
Do that, and an audit stops being an exercise in frantic reconstruction. The auditor asks for the history, and you hand them the history — complete, dated, and substantiated. That's not luck. It's the quiet payoff of treating notice resolution as a discipline with a memory.
The examination will come on its own schedule. The only variable you control is what you'll have to show for the years before it.
RELATED POSTS
- Make Audit Resolution a Repeatable Process
- What Your Tax Notices Are Telling You About Your Next Audit