A Practical Guide to Identifying Documentation Gaps Before They Become Audit Problems
ARTICLES & GUIDES
7 Signs Your Certificate Process is Creating Audit Risk
April 20, 2026
Certificate Management
11 Min Read
Exemption certificates can represent on of the most significant documentation challenges in a sales and use tax audit.
A company may have correctly treated a customer as exempt for years, but when an auditor asks for supporting documentation, the strength of the exemption often depends on the records the business can produce and the applicable jurisdiction's rules.
The problem is that exemption certificate risk rarely appears overnight. It tends to accumulate gradually.
A certificate expires. A customer changes legal entities. An employee saves documentation in an email folder. A certificate is accepted without review. A collection campaign is not followed up. Over time, small documentation gaps can develop into a much larger compliance problem.
Here are seven warning signs that your exemption certificate process may be creating unnecessary audit risk.
1. You Don't Know How Many Exempt Customers Are Properly Documented
Consider a simple question:
Certificate health question
What percentage of your exempt customer population currently has acceptable documentation on file?
A company might know that it has 5,000 customers coded as tax exempt but have limited visibility into how many are supported by appropriate exemption certificates. Having 5,000 exempt customers does not necessarily mean having 5,000 properly documented exempt customers.

Without this visibility, management may assume its documentation position is stronger than it actually is.
What a stronger process looks like
Organizations should be able to identify their exempt customer population and categorize supporting documentation using clearly defined statuses such as Valid, Pending, Missing, Expired, and Action Needed. This creates a measurable certificate health rate that can be monitored over time.
2. Certificates Are Stored in Multiple Locations
Ask several employees where they would find the exemption certificate for a particular customer. If the answers include multiple unrelated systems or individual employee locations, you may have a document-management problem.
-
Shared Drives
-
Employee Outlook Mailboxes
-
Local Folders
-
ERP Attachments
-
Sharepoint
-
Tax Engines
-
Exemption Certificates Systems
-
Institutional Knowledge (i.e. "Ask the person who usually handles it")
Why This Creates Risk
-
Duplicate Documentation
-
Lost Certificates
-
Outdated Versions
-
Difficulty Identifying the Current Certificate
-
Limited Expiration Monitoring
-
Slow Audit Response Times
-
Incomplete Audit Productions
A stronger process establishes a defined system of record. Ideally, the team should be able to move quickly from Customer to Jurisdiction to Certificate to Supporting Document without searching multiple unrelated systems.
3. Certificates Are Collected but Not Formally Reviewed
Risky Assumption
“We have a certificate, so we are covered.”
Receiving a document is only the first step. A certificate could contain missing purchaser information, an incorrect certificate type, missing registration information, an unsupported exemption reason, missing signatures, incorrect seller information, an inappropriate jurisdiction, expired documentation, or information that does not match the customer account.
What should happen after collection?
A mature process generally follows a controlled workflow:
RECEIVED - Document enters the approved intake process.
REVIEWED - Required fields and supporting information are checked.
VALIDATED - The documentation is evaluated against established review standards.
APPROVED or ACTION NEEDED - The certificate is accepted or routed for remediation.
The review process should be based on documented standards rather than individual employee judgment alone.
4. You Don't Have a Process for Expiring Certificates
Expiration management is another common source of certificate risk. Some organizations do not discover that certificates have expired until an auditor asks for them.
Warning signs include
-
Expiration dates are not captured
-
There is no upcoming-expiration report
-
Renewal requests are performed manually and inconsistently
-
Customers receive only one renewal request
-
Expired certificates remain attached to active exempt accounts
-
No on owns the renewal process
Not every exemption certificate has the same expiration rules, and requirements vary by jurisdiction and certificate type. Where expiration or renewal considerations apply, a stronger process identifies upcoming needs before documentation lapses.

5. Customer Exemption Status and Certificate Status Aren't Reconciled
Your ERP or tax engine might identify a customer as TAX EXEMPT while your certificate repository shows MISSING CERTIFICATE. Those systems are telling you very different things.
Three data populations should reasonably align:
-
Customer Master - Who is coded exempt?
-
Certificate Repository - Who has appropriate documentation?
-
Transaction Data - Who is actually receiving exempt treatment?
Example Risk Signal
Customer is coded exempt + no certificate exists + significant exempt sales activity = an account that deserves attention.
A certificate supporting exempt treatment in one jurisdiction should not automatically be assumed to support exempt treatment everywhere. Jurisdiction-level tracking is particularly important for multistate customer populations.
Risk-based Remediation
Certificate remediation does not always need to be performed alphabetically. Prioritization can consider:
-
Exempt sales volume
-
Documentation status
-
Jurisdiction
-
Customer activity
-
Certificate age
-
Audit exposure
6. Customer Outreach Isn't Tracked or Escalated
Certificate collection campaigns often begin with an email request and then lose momentum when customers do not respond. Effective campaigns require more than one message.
A structured collection process should track:
-
Initial request date
-
Number of outreach attempts
-
Most recent contact
- Customer response
- Certificate received
-
Certificate reviewed
-
Deficiency identified
-
Next follow-up
-
Escalation status
-
Resolution
Tracking also allows management to measure campaign performance rather than relying on disconnected emails.


Key Takeaway
Don’t wait for an audit to uncover weaknesses in your certificate process. A proactive approach helps identify documentation gaps early, reduce risk, and keep your organization audit-ready.
Proactive collection, validation, monitoring, and organization can significantly reduce exemption certificate risk.
In This Article
1
Visibility into Documentation
2
Multiple Storage Locations
3
Lack of Formal Review
4
No Expiration Process
5
Status Reconciliation Gaps
6
Weak Outreach & Escalation
7
Not Audit-Ready
What Does a Strong Certificate Management Process Look Like?
Centralized Documentation
Standardized Validation
Proactive Monitoring
Structured Customer Outreach
Management Visibility
Audit Readiness
7. Preparing Certificates for an Audit Requires a Major Project
Perhaps the clearest warning sign is what happens when the organization receives an exemption certificate request from an auditor. If the request triggers weeks of searching through folders, inboxes, spreadsheets, and systems, the process may not be audit-ready.
An audit-ready process should allow you to
1
2
3
4
Identify the requested transaction/customer population.
Match customers to supporting certificates.
Retrieve the relevant documentation.
Identify documentation gaps.
5
6
7
8
Perform quality review before production.
Track outstanding items.
Produce documentation efficiently.
Retain a record of what was provided.
Audit readiness does not mean every certificate population will be perfect. It means the organization has enough visibility, control, and documentation to understand its position before responding to the auditor.
