
Auditors do not care how good your dashboards look. They care whether every dollar of revenue on your P&L ties back to a signed contract, a delivery date, and a defensible judgment call. If you are heading into your first ASC 606 audit, or your third one that still feels chaotic, the checklist below is what auditors actually test, organized the way fieldwork actually happens.
You will get a full walkthrough of the five-step model as an audit lens, a checklist you can run against your own contracts this week, the most common findings that stall sign-off, and how contract modifications get tested. None of this requires a finance department. It requires a system that ties every schedule back to the general ledger before the auditor asks.
What you'll learn in this article
- Why ASC 606 audits are harder for SaaS companies than for most other business models
- How the five-step revenue recognition model maps to what auditors request as evidence
- A complete, usable checklist organized by audit area, not by accounting theory
- The most common audit findings at SaaS companies, and the checklist item that prevents each one
- How contract modifications and renewals get tested, and what the modification memo needs to contain
- A 90-day cadence for turning audit prep into a repeatable operating rhythm
Why ASC 606 audits trip up SaaS companies specifically
ASC 606 has applied to privately held software and SaaS companies since January 1, 2019, and the challenges have not gone away with time. Cohen & Co's January 2025 analysis of revenue recognition challenges for software and SaaS companies names three that recur year after year: whether implementation services are distinct from the subscription, how professional services get timed against milestone billing, and how you estimate stand-alone selling price when bundled deals leave you with thin historical data.
The reason these keep resurfacing is structural. ASC 606 is a principles-based standard, not a rules-based one. It asks you to depict the transfer of promised goods or services in an amount that reflects what you expect to be entitled to, per the core recognition principle. That means judgment, not a lookup table. Judgment is exactly what auditors are trained to probe.
Revenue is also the single most scrutinized line on any set of financial statements. The Deloitte roadmap on SEC comment letter considerations identifies six recurring themes in SEC staff comment letters on ASC 606: significant judgments, performance obligations, contract costs, disaggregation of revenue, contract balances, and remaining performance obligations. Revenue recognition has ranked among the top five SEC comment letter topics in both 2024 and 2025, with principal-versus-agent classification, disaggregation, and contract balances leading the list.
"You do not need to be a public company to feel this pressure. Series B and later investors, acquirers running diligence, and lenders reviewing covenants all use the same lens your auditor will use."
— Aleksandar Stojanovic, CEO & Founder at FiscallionIf your revenue recognition cannot survive that scrutiny, the audit is where it surfaces.
The five-step model, read as an audit lens
You do not need a refresher on the mechanics of ASC 606 here. If you want the deferred revenue rollforward and commission capitalization mechanics in detail, that is covered in our guide to revenue recognition in SaaS. What matters for audit readiness is what each step of the model asks an auditor to test.
| Step | What the standard requires | What the auditor tests |
|---|---|---|
| 1. Identify the contract | A contract exists when parties have approved it and rights and payment terms are identifiable | Signed contracts or order forms, evidence of approval, collectibility assessment |
| 2. Identify performance obligations | Determine which promised goods or services are distinct | Contract language, implementation scope, distinctness analysis memo |
| 3. Determine the transaction price | Estimate the consideration you expect to be entitled to, including variable amounts | Pricing schedules, usage-based fee logic, discount and credit terms |
| 4. Allocate the transaction price | Split the price across performance obligations based on stand-alone selling price | SSP methodology, bundled deal allocation workpapers |
| 5. Recognize revenue | Recognize as (or when) each obligation is satisfied | Deferred revenue rollforward, delivery evidence, revenue schedules by contract |
Each row is a distinct evidence request during fieldwork. If you cannot produce the workpaper behind a row, expect a finding, a delay, or both.
The checklist: what to have ready before fieldwork starts
This is the checklist itself, organized the way auditors actually request evidence rather than the order the standard is written in. Keep this readable and run through it against your own contract set before your auditor asks for it.
Contracts and Step 1 evidence
- Executed contracts or order forms for every active customer, plus your top 20 customers by revenue
- A contract modification schedule covering every amendment, upsell, downgrade, or renewal in the audit period
- Evidence of contract approval (signature, e-signature audit trail, or documented sales process)
- A collectibility assessment for customers with extended payment terms or unusual credit risk
Performance obligations and stand-alone selling price
- A written revenue recognition policy memo covering your product lines and bundle types
- A distinctness analysis for implementation, onboarding, and professional services attached to your subscription. Deloitte's roadmap frames the test as two questions: can the customer benefit from the service on its own or with resources readily available to them, and is the service separately identifiable within the context of the contract
- A documented SSP methodology, including how you estimate SSP for bundles where you lack an observable stand-alone price
Transaction price and variable consideration
- Documentation of usage-based fees, overage charges, and credit or refund terms
- A constraint analysis for variable consideration, showing why the amount included in the transaction price is not subject to significant reversal
- Discount and rebate schedules, tied to the customers and contracts they apply to
Recognition schedules and reconciliations
- A deferred revenue rollforward by customer or contract, reconciled to the general ledger
- Unbilled receivable and contract asset schedules, where recognition has outpaced invoicing
- Month-end close evidence showing revenue recognition was reviewed and approved before the books closed, not adjusted after the fact
- A revenue schedule by contract type, distinguishing subscription revenue from implementation and professional services revenue
Contract costs
- A capitalized contract cost schedule for sales commissions subject to amortization over the expected benefit period, per KPMG's Revenue recognition Handbook
- Documentation of the amortization period and method used for capitalized costs
Disclosure readiness
- A disaggregation of revenue analysis (by product line, geography, or contract type, consistent with how you manage the business internally)
- A remaining performance obligation summary, showing committed but unrecognized revenue and when you expect to recognize it
The document requests above are what shows up first in nearly every SaaS revenue audit. Treat contracts and the deferred revenue rollforward as the two items an auditor asks for before anything else, and have both ready before the engagement letter is signed.
The PBC list, translated for a lean team
Auditors formalize the checklist above into a prepared-by-client (PBC) list. For a first-time audit, that list commonly runs well beyond what a founder expects. Illustrative PBC templates for a first audit often include 80 to 150 individual items across all financial statement areas, not just revenue, and audit prep guides for early-stage companies note that a first-year audit typically takes 8 to 16 weeks from planning to signed opinion, with subsequent years running 4 to 8 weeks once the process is established. Treat these figures as directional. Your actual timeline depends on your auditor, your contract complexity, and how much of the checklist above is already assembled before fieldwork begins.
For a lean team without a finance department, the practical move is not to build every schedule from scratch during fieldwork. It is to assign ownership before the engagement letter arrives:
- Revenue policy memo and SSP methodology: owned by whoever runs FP&A or accounting, reviewed by the CEO or a fractional CFO before it goes to the auditor
- Contract and modification schedule: owned by sales operations or revenue operations, pulled from the CRM and reconciled against signed paper
- Deferred revenue rollforward and contract cost schedule: owned by accounting, tied out to the general ledger every close, not assembled once a year for the auditor
- Disaggregation and RPO summary: owned by FP&A, built from the same revenue schedule used for board reporting so it does not get built twice
The tie-out discipline matters more than any individual schedule. Every number an auditor sees should already reconcile to the general ledger before they ask. A schedule built in a spreadsheet that does not tie to the GL gets rejected, and rejected schedules are what extend a four-week audit into an eight-week one.
The same document discipline shows up in how we build revenue recognition models for SaaS clients in practice:
The checklist above and that working method share the same premise: audit readiness comes from the schedules you already maintain, not the ones you assemble under deadline.
The most common audit findings, and what prevents each one
Every SaaS company runs into a version of the same handful of findings. Practitioner-reported patterns from SaaS revenue recognition audit reviews point to five that recur most often.
| Common finding | What causes it | Checklist item that prevents it |
|---|---|---|
| Implementation fees recognized upfront | Treating a bundled setup fee as immediately earned when it is actually part of a combined performance obligation | The distinctness analysis for implementation and onboarding services |
| Inconsistent treatment of similar bundles | Different account managers negotiating similar deals with no shared SSP reference point | A documented SSP methodology applied consistently across the customer base |
| Revenue following invoice dates | Recognizing revenue when an invoice goes out rather than when the obligation is satisfied | Recognition schedules tied to delivery evidence, not billing dates |
| Unexplained deferred revenue swings | No rollforward discipline, so period-over-period changes cannot be explained by contract activity | A deferred revenue rollforward reconciled to the GL every close |
| Missing or thin modification memos | Renewals and upsells processed as pricing changes with no accounting analysis behind them | A contract modification schedule with a memo for each change |
"If you recognize your company in more than one row of that table, you are not unusual. You are, however, looking at exactly where an audit will slow down, and exactly what to fix before it starts."
— Aleksandar Stojanovic, CEO & Founder at FiscallionContract modifications and renewals under audit
Renewals and upsells are where SaaS revenue recognition gets tested hardest, because they happen constantly and rarely get the same scrutiny as a new logo deal.
A modification exists whenever the parties approve a change to scope, price, or both, whether that approval is in writing, oral, or established by customary business practice. PwC's revenue guide makes an important point that catches teams off guard: even a document that looks like a brand-new contract with an existing customer can still be a modification if its pricing depends on the original agreement.
Under ASC 606, a modification gets accounted for one of four ways, per the Deloitte roadmap on contract modification types:
- As a separate contract, when the added goods or services are distinct and priced at their stand-alone selling price
- As a termination of the old contract and creation of a new one, applied prospectively, when remaining goods or services are distinct from those already delivered
- As a cumulative catch-up adjustment, when the remaining goods or services are not distinct from those already delivered, so the modification is treated as part of the original contract
- As a combination of these approaches, when a modification includes elements of more than one category
Auditors test renewal and upsell pricing against your SSP methodology specifically because this is where inconsistency hides. A renewal priced well below SSP with no documented rationale is a signal, not a footnote. Your modification memo for each change needs to state which of the four categories applies, why, and how the transaction price was determined or reallocated as a result.
Build the memo at the time of the modification, not months later when the auditor asks. Reconstructing rationale after the fact is where audit timelines slip.
What to do 90 days out
Audit readiness is not a sprint you run once a year. It is a byproduct of how your accrual accounting operates every month. A 90-day runway looks like this:
- Weeks 1-4: Assemble the checklist above against your current contract base. Identify gaps in the modification schedule and SSP documentation first, since these take the longest to reconstruct.
- Weeks 5-8: Reconcile the deferred revenue rollforward and contract cost schedule to the general ledger for every month in the audit period, not just the period-end balance.
- Weeks 9-12: Draft or update the revenue recognition policy memo, disaggregation analysis, and RPO summary. Have a second reviewer, ideally someone with CFO-level judgment, walk through the SSP methodology before the auditor does.
The pattern underneath all of this is the same one that shows up in every accrual accounting conversation: revenue recognition is not a task you complete for the audit. It is a monthly discipline that makes the audit uneventful. Building that discipline, deferred revenue rollforwards, contract cost amortization, and a close process that ties out every month, is what turns audit prep from a fire drill into a formality.
Every Fiscallion engagement works directly with Aleksandar Stojanovic at the CFO layer, applying FP&A leadership experience gained through the growth of a SaaS company to €100M ARR to exactly this kind of audit-readiness build. If your accrual accounting operations need that discipline in place before your next audit, or before your next fundraising round asks for it, explore accrual accounting support for B2B SaaS.
Frequently asked questions
What documents should a SaaS company prepare for an ASC 606 revenue recognition audit?
Start with the checklist categories above: signed contracts for your top customers, a contract modification schedule, a written revenue recognition policy memo, your SSP methodology, a deferred revenue rollforward reconciled to the general ledger, a capitalized contract cost schedule for commissions, and a disaggregation and remaining performance obligation summary. Illustrative PBC templates for a first audit commonly list 80 to 150 individual items across all financial statement areas, but revenue-specific documentation is almost always requested first because it is the most scrutinized line on the statements. Have each schedule tied to the general ledger before the engagement starts, not assembled during fieldwork.
How do SaaS subscription contracts affect the ASC 606 five-step model during an audit?
Subscription contracts complicate every step of the model because they routinely bundle a recurring license with implementation, onboarding, or professional services. Step 2 requires you to determine whether those bundled services are distinct, using the two-part test from Deloitte's revenue recognition roadmap: can the customer benefit from the service independently, and is it separately identifiable within the contract. Step 4 then requires an SSP for each obligation, which is difficult when most of your deals are custom-negotiated bundles with thin observable pricing history. Auditors will ask you to demonstrate both the distinctness conclusion and the SSP methodology with actual workpapers, not just a policy statement.
What are the most common ASC 606 audit findings for SaaS companies?
The most frequently cited findings are recognizing implementation or setup fees upfront when they should be deferred as part of a combined obligation, treating similar contract bundles inconsistently across customers, recognizing revenue based on invoice dates rather than delivery, unexplained swings in the deferred revenue balance with no rollforward to explain them, and missing or thin documentation behind contract modifications. These patterns show up repeatedly in practitioner reviews of SaaS revenue recognition. Each one traces back to a specific gap in documentation or process discipline, which is exactly why the checklist above is organized by finding, not just by accounting topic.
How should SaaS companies handle contract modifications and renewals under an ASC 606 audit checklist?
Treat every renewal, upsell, downgrade, and pricing change as a modification that needs its own record, even when it looks routine. A modification exists whenever both parties approve a change to scope or price, per PwC's guidance on contract modifications, and it gets accounted for as a separate contract, a termination-and-new-contract, a cumulative catch-up adjustment, or some combination of these, depending on whether the remaining goods or services are distinct from what was already delivered. Build the modification memo at the time of the change, documenting which category applies and how the transaction price was set or reallocated. Auditors specifically test renewal pricing against your SSP methodology, so a renewal priced well outside that range without a documented reason is one of the fastest ways to trigger a finding.
The takeaway
An ASC 606 audit is not a test of how well you can explain revenue recognition after the fact. It is a test of whether your monthly close already produces the evidence an auditor needs, without a scramble. The checklist above gives you the specific items to assemble now, before the engagement letter arrives, and the finding-by-finding table shows exactly where SaaS companies lose time when that discipline is missing.
Get the checklist in place this quarter, and your next audit stops being a fire drill and starts being a formality your accrual accounting process already supports.








