Tax Knowledge Centre
Sole proprietor verifications: start with the financials, then request what is relevant
By Mark Silberman CA(SA), SAICA Tax Technology Committee

Why this matters
Tax practitioners are increasingly seeing SARS verification requests to sole proprietors demanding every invoice/receipt and proof of payment (POP) for every expense reflected in the income statement — often across hundreds or thousands of transactions. While SARS is empowered to verify returns and request relevant material, blanket population-wide demands can create an unreasonable compliance burden, especially where low-value, high-volume transactions are common.
Practitioners also report scenarios where taxpayers upload extensive documentation and the matter is finalised very quickly thereafter, raising legitimate concerns about whether submissions were meaningfully considered. Even where SARS uses internal tools and risk rules to accelerate case handling, the credibility of the process depends on SARS being able to show that requests are properly targeted and outcomes properly reasoned.
The better starting point: review the financials first
In most proprietor income tax cases, there should already be a coherent set of financial information underpinning the return — typically annual financial statements (AFS) or, at minimum, a structured income statement, balance sheet, and supporting schedules (or accounting reports from the accounting system).
A reasonable and efficient approach is:
- SARS reviews the financials (AFS or equivalent) and the return to identify the specific risk drivers (e.g., unusual margins, large year-on-year movements, atypical expense ratios, or mismatches to third-party data).
- SARS then issues a targeted request aligned to the risk identified — rather than defaulting to "every invoice and POP for all expenses."
This approach aligns with the principle that information requests should be foreseeably relevant and reasonable (rather than limitless). It also reduces noise, speeds up resolution, and improves decision quality.
Verification is not audit: document expectations must differ
A key practical problem is that many "verification" requests are framed like audit requests. That is not just semantics — scope and process matter.
- A verification should ordinarily test specific declarations in the return, usually focusing on identified risk items.
- An audit is typically broader in scope and depth and triggers greater process expectations (including communication and outcome requirements reflected in the audit framework).
Where SARS requests resemble audit-level population testing (everything, everywhere, all at once), practitioners should consider asking SARS to clarify whether the matter has escalated to audit, and to apply the appropriate procedural approach.
What SARS should request for a verification (proportionate and workable)
For verification, the emphasis should be on targeted substantiation, starting from the financials and then drilling down only where needed. A practitioner-friendly, SARS-friendly verification model is:
1) Foundational documents
- AFS / financial statements (or equivalent) that reconcile to the return
- General ledger or expense schedule only for the specific categories under query
- Selected bank statements only where they are necessary to test the queried items
2) Focused substantiation
- Invoices/receipts and POP for the specific expenses or categories flagged
- A sample approach for high-volume, low-value items (where appropriate), rather than 100% testing
3) Clear issue framing
- SARS identifies the risk driver (e.g., "repairs increased 300%," "motor vehicle claim appears excessive," "subcontractor costs inconsistent with turnover"), enabling the taxpayer to respond precisely.
This is materially different from an "audit file." It is a verification response built around financials first, then specific proof where warranted.
What SARS should request for an audit (when the matter truly requires it)
Where SARS has escalated to an audit (or the scope is clearly audit-like), deeper documentation can be appropriate — but it should still be structured and linked to audit objectives. In an audit context, SARS may reasonably request wider accounting records, reconciliations, and fuller populations — provided the requests remain connected to audit issues and are administered fairly.
The key point for practitioners and SARS alike is sequencing and proportionality:
- Start with financials and risk drivers.
- Then request documents relevant to those drivers.
- Escalate depth only if the verification response indicates a need for audit-level enquiry.
Addressing the "AI data harvesting" concern — professionally and without speculation
Clients are increasingly asking whether SARS is collecting "everything" to build future analytics or AI models, especially where outcomes appear to be finalised without meaningful engagement. Practitioners should avoid unprovable allegations, but it is entirely appropriate to ask SARS — neutrality intact — to confirm that requests are limited to what is reasonable and foreseeably relevant to tax administration, and that decisions reflect consideration of what was submitted.
The credibility of SARS processes depends not only on lawful powers, but on demonstrable fairness: targeted requests, sensible volumes, and reasons that show the decision-maker applied their mind.
Practical guidance for practitioners: how to respond without building an audit pack
When faced with a blanket "every invoice + POP" verification request, a defensible and efficient approach is:
- Submit the financials first (AFS or equivalent) and ensure they reconcile to the return.
- Ask SARS to specify the risk items or categories driving the request.
- Provide substantiation only for those items/categories, using sampling for genuinely high-volume, low-value lines where appropriate.
- If SARS insists on population-wide proof, request clarity on whether the matter is now an audit and ask for the appropriate audit process to be followed.
Conclusion
Sole proprietors must substantiate deductions, and SARS is entitled to verify returns. But a workable, credible system starts with the financials, identifies risk, and then requests specific supporting documents appropriate to either a verification or an audit. Blanket "everything" requests in verification cases are costly, often unproductive, and can undermine confidence when outcomes appear too rapid to reflect genuine review.
A "financials-first, risk-based" approach better serves SARS, practitioners, and taxpayers: fewer unnecessary uploads, faster resolution, and outcomes that are easier to justify and defend.