RevRec EngineRevRec Engine
All articles

Audit

How to Talk to Your Auditor About ASC 606: A Founder's Survival Guide

Your first audit is coming. Here's what auditors actually want to hear about your ASC 606 rev rec — what to prepare, what to avoid saying, and what happens if you can't answer their questions. By a CPA.

Chris, CPA12 min read
Share

Why this conversation matters more than founders think

Most founders treat the auditor like a hostile adversary they have to defend against. That's wrong.

Your auditor's job is to issue an unqualified opinion on your financial statements. They want to issue that opinion. It's faster, cheaper, and easier for them than the alternative (issuing a qualified opinion, which is awful for both of you).

But they can't issue an unqualified opinion if they can't verify your revenue numbers. And they can't verify your revenue numbers if you can't show them how you got there.

This is the audit reality: the conversation is not about whether your revenue is right. It's about whether you can defend your judgments.

A founder who confidently explains their methodology — even if the methodology is imperfect — gets through audits much faster than a founder who has perfect math but no documentation of why.


What auditors actually want (in priority order)

After watching dozens of audits, here's the priority stack of what your auditor cares about:

1. Documentation of your revenue recognition policy

A written document that explains:

  • How you identify performance obligations
  • How you determine transaction price (including variable consideration)
  • How you allocate transaction price across multiple POs
  • Your default recognition patterns by product line
  • How you handle modifications

This document should be 3-10 pages. It doesn't need to be fancy. It needs to exist.

If you don't have this: Your auditor will spend 4x more time interviewing you, asking each question separately. You'll burn weeks of your CFO/controller's time.

2. Workpaper documenting your judgments

For each judgment call (distinct vs. combined PO, SSP allocation, modification treatment, variable consideration constraint), a documented memo explaining:

  • What was decided
  • The ASC citation supporting the decision
  • The alternative considered and why it was rejected

If you don't have this: Your auditor will ask you to recreate the analysis on the spot, in real time, in front of them. This goes poorly.

3. Contract files

The signed agreements for the contracts they're going to test. They'll typically sample 15-30 contracts across your revenue base and ask to see each one.

Pro tip: Auditors prefer signed PDFs in a clearly named folder structure. They will judge you for unorganized contract files. "Customer_Name_OrderForm_2026-01-15.pdf" beats "scan003.pdf" every time.

4. Revenue waterfall by contract

A schedule showing, for each contract: TCV, performance obligations, allocated amounts, monthly recognition amounts, cumulative recognized, deferred balance. By contract. Not just at the aggregate level.

If you don't have this: Your auditor will ask you to build it from scratch during the audit. It will take you 40-80 hours.

5. Journal entry support

For each material month-end recognition entry, the JE itself plus the underlying contracts and waterfalls it derives from. They'll trace amounts.

If you don't have this: The reconciliation between your monthly revenue number and the underlying contracts becomes a forensic exercise.

6. Bank reconciliations + invoice → revenue ties

Your auditor will pick sample contracts, trace the cash receipt to your bank, trace the deferred revenue entry, trace the monthly revenue recognition. Three-way tie.

7. Variance analysis

If your monthly revenue numbers are choppy, your auditor will ask why. Be ready to explain seasonality, customer concentration, modifications, refunds.


The 5 questions every auditor will ask

If you can answer these five questions before your audit starts, you'll close in half the time.

Question 1: "Walk me through how you identify performance obligations."

What you should say:

"We apply ASC 606-10-25-19. For each contract, we identify promised goods or services, then test each for distinctness using the two-prong test: capable of being distinct, and distinct in the context of the contract. Our default position is that subscription access is one performance obligation. Implementation services, professional services, and discrete deliverables get treated as separate POs if the customer can benefit from the subscription without them. We document the distinct-vs-combined analysis for each contract in our judgment workpaper."

What you should NOT say:

"Our subscription is a performance obligation."

(The auditor will ask "what about implementation?" "what about onboarding?" "what about training?" — and you'll find yourself rebuilding the analysis on the spot.)

Question 2: "How do you determine standalone selling price?"

What you should say:

"We maintain an SSP library updated quarterly. For products with sufficient observable standalone sales (>10 deals in the trailing 12 months), we use the observable price. For products without sufficient standalone sales, we use [cost-plus / residual / estimated] methodology, documented per ASC 606-10-32-32 through 32-35. Our SSP library is reviewed and approved by [our Controller / our fractional CFO / me as the founder] each quarter."

What you should NOT say:

"We charge what we charge."

(SSP is one of the top areas where auditors find issues. If you don't have a documented SSP library, your bundled deal allocations are indefensible.)

Question 3: "How do you handle contract modifications?"

What you should say:

"When a contract changes mid-term, we evaluate it under ASC 606-10-25-10 through 25-13. If the modification adds distinct services priced at SSP, we treat it as a separate contract (25-12). If the modification doesn't meet that test, we evaluate whether to treat it prospectively (25-13(a)) or with cumulative catch-up (25-13(b)) based on whether the remaining goods or services are distinct. Each modification is documented in our judgment workpaper with the specific treatment chosen and the rationale."

What you should NOT say:

"If a customer upgrades, we just change their invoice amount."

(This is wrong AND obvious to an auditor. Modifications are one of the top 3 audit findings.)

Question 4: "How do you account for variable consideration?"

What you should say:

"We identify variable consideration sources in each contract — usage-based fees, SLA credits, refunds, volume discounts. For series-based stand-ready obligations like usage fees, we apply the practical expedient under ASC 606-10-32-40, recognizing variable consideration in the period of consumption. For other variable consideration, we estimate using expected value or most-likely-amount methodology and apply the constraint per 606-10-32-11, including only amounts where significant reversal is not probable."

What you should NOT say:

"We recognize usage when it's billed."

(This is kind of right but doesn't demonstrate you understand the framework. The auditor will probe further.)

Question 5: "Walk me through a specific contract."

The auditor will pick a contract from their sample. They'll ask you to trace the entire lifecycle — signing date, performance obligations identified, transaction price, allocation, monthly recognition, status of deferred revenue.

What you should be able to do:

  • Pull up the signed contract within 30 seconds
  • Pull up the workpaper analysis within 30 seconds
  • Pull up the waterfall within 30 seconds
  • Show the journal entries for at least the most recent 3 months
  • Reconcile the deferred revenue balance to the dollar

What you should NOT do:

  • Ask the auditor to "send the question over email so I can look it up"
  • Pull up a spreadsheet with 47 tabs and start scrolling

What documents to prepare (the actual checklist)

Two weeks before your audit kickoff, have these ready:

DocumentFormatNotes
Revenue Recognition PolicyPDF, 3-10 pagesThe bible of your methodology
Judgment WorkpaperWord or PDFEvery material judgment, with ASC citation
Active Contracts ListExcelAll active customer contracts with TCV, term, status
Signed Contract FilesPDF folderOrganized by customer name + date
Revenue WaterfallExcelMonthly recognition by contract, by PO
Deferred Revenue RollforwardExcelOpening balance + additions + recognized + ending
Journal Entry DetailExcelEvery revenue JE with date, accounts, amounts
SSP LibraryExcelStandalone selling price by product, with effective dates
Modification LogExcelAll contract modifications with treatment decisions
Variance AnalysisExcelMonthly revenue variance with commentary

If you're using a tool like RevRec Engine, most of these are auto-generated. If you're in spreadsheets, this checklist is your weekend.


Common founder traps that make audits painful

Trap 1: "Our auditor wouldn't care about that"

If you're hoping your auditor won't notice, they will. Auditors have seen every variation of every problem. The thing you're hoping they don't notice is exactly the thing on their checklist.

Trap 2: Treating audit prep as a one-week sprint

Audit prep is a quarterly discipline, not a one-time event. If you reconstruct everything in the week before audit kickoff, you'll miss things. Build the documentation as you go.

Trap 3: Letting the auditor define the conversation

A confident founder leads the audit walkthrough. You explain your policy, you walk them through your workpaper, you preempt their questions. A passive founder waits to be asked, then scrambles for each answer. Lead the conversation.

Trap 4: Hiding judgments instead of documenting them

Auditors are not surprised by judgments — every ASC 606 application has them. They're alarmed by undocumented judgments. "We made a call and here's why" beats "we just did it that way."

Trap 5: Ignoring auditor adjustments instead of debating them

If your auditor proposes an adjustment to your revenue, push back if you disagree. Have the conversation. Sometimes you're right. Sometimes they're right. Sometimes you compromise. Never just accept silently — it signals to the auditor that you don't really understand your own books, which leads to more invasive testing next year.


What happens if you can't answer their questions

Three things happen, in escalating order:

  1. More invasive testing. Your auditor expands the sample size. Instead of testing 15 contracts, they test 30. Audit fees go up. Timeline extends.

  2. Audit adjustments. Your auditor proposes corrections to your revenue. Sometimes thousands of dollars. Sometimes millions. You post the corrections and move on.

  3. Restatement. Only in serious cases. Your prior period financials are wrong by a material amount and need to be re-issued. This is the catastrophic outcome — investors lose trust, deals fall through, sometimes lawsuits follow.

The good news: the path from "competent founder" to "no findings" is well-defined. Have documentation. Document judgments. Be confident. Lead the conversation.


After the audit: what changes

Most founders are surprised by how much their finance operations need to mature after their first audit. The audit reveals:

  • Where your data flow has gaps
  • Which judgments you've been making implicitly
  • What controls you need (e.g., approval workflows for modifications)
  • Where your existing tools are failing

The founders who handle this well treat the audit as a forcing function for finance ops maturity. They invest in a real rev rec tool (instead of spreadsheets), they hire or contract a Controller, they build documentation discipline.

The founders who handle it poorly view the audit as a one-time event, then go back to spreadsheets, then have an even worse second audit a year later.


The shortcut: use a tool that auto-generates audit-defensible workpapers

This is what RevRec Engine does. For every contract:

  • We document the distinct-vs-combined PO analysis
  • We log the SSP method used for each product
  • We classify and document every modification
  • We track variable consideration with the constraint applied
  • We generate a Word workpaper memo per contract that your auditor can read directly

When your auditor asks "walk me through this contract," you don't pull up a spreadsheet. You pull up the workpaper memo, which already has the answer.

This is the difference between a 4-week audit and a 10-week audit. Between a $50K audit fee and a $150K audit fee. Between getting through diligence smoothly and renegotiating your valuation downward.

See an example audit workpaper → | Start free →


Frequently asked questions

How early should I start preparing for my first audit?

At least 90 days before kickoff. Realistically, 6 months. Most founders underestimate by half.

Will my Big4 auditor accept output from RevRec Engine (or another tool)?

Yes. Auditors accept output from any defensible source — your tool, your spreadsheet, your fractional CFO's analysis. What matters is the documentation and traceability, not the format.

What's the difference between a financial audit and a SOC 2 audit?

Different things. A financial audit verifies your GAAP financial statements. A SOC 2 audit verifies your security controls. SOC 2 doesn't directly require ASC 606 compliance, but enterprise customers often require both — at which point you'll be doing both audits in parallel.

How much does a first audit cost?

For a SaaS startup at $1-5M ARR: $25-60K for a regional firm, $75-200K+ for a Big4 firm. The fee scales with revenue complexity and the cleanliness of your books.

Should I hire a controller before my first audit?

Strongly recommended. Even fractional (10-20 hrs/week, ~$3-8K/month). The controller's job during audit prep is to be the auditor's primary point of contact and to handle the daily PBC list requests. Without one, the audit consumes 30-50% of your founder time for 6-12 weeks.

Can I switch auditors after a bad experience?

Yes, but it's expensive — the new auditor has to rebuild their understanding of your business, your policies, your controls. Switching costs you 30-50% more in fees the second year. Better to make the first auditor relationship work.

What if my auditor finds material errors?

Depends on materiality. <$50K is usually a normal "audit adjustment" — you post a JE, move on. $50K-$500K is uncomfortable but resolvable. >$500K material errors can trigger restatements, especially if they're systemic.

Do I need to be PCAOB-audited for a Series B?

Almost never. PCAOB audits are required for public companies. For a Series B, your investors will typically accept GAAP financial statements audited under AICPA standards. PCAOB only becomes relevant when you're going public.

How do I find a good auditor?

For Seed/Series A: regional firms (BDO, RSM, Grant Thornton, CohnReznick, Withum). For Series B+ approaching IPO: Big4 (EY, PwC, Deloitte, KPMG). Get 3 quotes. Ask for references at similar-stage SaaS companies. Check Glassdoor for the audit team's reputation.

What's the most important thing I can do today to prepare?

Start documenting your revenue recognition policy in a Google Doc right now. Even 1-2 pages. Then add to it every time you make a judgment call. By the time your audit kicks off in 6 months, you'll have a 5-10 page document that takes 80% of the pain out of the audit.


The bottom line

Your auditor is not your enemy. They're a verifier who needs you to demonstrate that you understand your own revenue. The founders who pass audits easily do three things: document their policy, document their judgments, and lead the conversation confidently.

Most of the audit pain comes from not being able to explain your numbers, not from the numbers themselves being wrong. The math is usually fine. The methodology documentation is usually missing.

If you're 3-6 months from your first audit and your current rev rec lives in spreadsheets with no documentation, try RevRec Engine. The workpaper output it generates is exactly what your auditor wants to see — built by a CPA who's been on both sides of the audit table.


About the author: Chris is a CPA and the founder of RevRec Engine. He previously worked as a Big4 auditor and as a finance integrator at growth-stage SaaS companies. He's seen audits from both sides and has strong opinions about which ones go well.

Related reading:

About the author

Chris is a CPA who spent years inside SaaS finance teams watching founders panic at their first audit. He's building RevRec Engine — AI rev rec for SaaS founders without a CFO. Read the full story →

Related reading