No items found.

How to Audit Gift Card Issuance: Approval Trails, Reconciliation and Finance Reporting

Team The Reward Store
October 5, 2026
October 6, 2026
Table of Contents

Sign up for our newsletter for trending top content!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

To audit gift card issuance, trace each issued card from a recorded approval, through a timestamped issuance event tied to a recipient reference and a campaign budget, to the supplier settlement that paid for it. Then reconcile those three records to one another and to the general ledger at every month end. A gift card issuance platform makes this a by-product of normal operation when approvals, issuance, budget movements and settlement are held as records that cannot be edited after the event. The audit is defensible when an independent reviewer can reperform the trace from the records alone, without asking anyone to explain them.

‍

Why Gift Card Issuance Is Treated as a Cash Equivalent Activity

‍

Gift card issuance is audited as a cash equivalent activity because value becomes spendable by whoever holds the code at the moment of issuance, so the control must sit at issuance and not at redemption. A cash equivalent is an asset that converts into spending power without further approval and with little friction. Once a code is delivered, the issuer has no payment run to stop, no bank to recall the funds and no counterparty to query, which separates issuance from an ordinary supplier payment.

‍

The three risks internal audit tests

‍

Internal audit, working within the COSO Internal Control Integrated Framework or a Sarbanes-Oxley Section 404 control set, tests three risks. Unauthorised issuance includes insiders who hold both approval and issuing rights. Misstatement arises when liabilities or expenses fall in the wrong period, because late issuance is easily missed at cut off. Financial crime exposure arises when issued value is used to move funds out of the organisation, which is why anti money laundering teams applying Financial Action Task Force guidance take an interest.

‍

Why accounting treatment changes what the audit looks for

‍

Cards sold to customers create a contract liability under IFRS 15 or ASC 606, with breakage assessed on the unredeemed portion. Promotional cards are commonly expensed at issuance. The treatment depends on the facts and on technical accounting advice, but the audit consequence is constant: the issuance record must state which type each card is, because the journal entry follows from it.

‍

What a Defensible Approval Trail Contains

‍

A defensible approval trail records who requested an issuance, who approved it, under which authority limit, for what value and campaign, and when, and it carries a reference that appears on every issuance event it authorised. An approval trail is a chronological record that shows each authorisation step an issuance passed through before value was created.

‍

The fields every approval record needs

‍

Requester, approver, approved value, campaign and timestamp are usually present. The field most often missing is the approval reference stored on the issuance record itself. Without it, an auditor holds two lists that agree in spirit but cannot be matched card to approval. Approval by email fails for this reason: the evidence exists, but the link to the issuance is somebody's memory.

‍

Segregation of duties

‍

Segregation of duties is a control that prevents one person from both authorising and executing the same transaction. The usual breach is a campaign manager who requests a budget, approves a top up and triggers issuance under one login. The diagnostic is whether the system can show approver and issuer as different accounts for every campaign, not whether policy says they should be.

‍

Choosing an approval model

‍

No single model suits every programme.

‍

Approval Model Comparison
Approval Model Suits Weakness
Budget owner approves each campaign budget Few campaigns with stable values Concentrates authority and gives no check on top ups
Tiered approval by value Wide range of issuance sizes Requests split to stay under a threshold
Approval at budget level, rules enforced at issuance High volumes where per issuance approval is impractical Depends on caps and rules being unalterable without a recorded change

‍

Tiering needs a detective control, for example a review of repeated issuances to one recipient that sit just below a threshold.

‍

Issuance Logs, Recipient Records and Retention Requirements

‍

An issuance log must record each card individually, be append only and identify the recipient through a reference that resolves to a person, while retention follows the longer of the statutory financial record period and internal policy. An issuance log is a record that captures each card issued with its value, timestamp, campaign, approval reference and recipient reference.

‍

What the log must hold per card

‍

Batch totals are the common failure. A log showing only that a campaign issued a total value cannot answer the auditor's first test, which is to pick one card and ask for its full history. A gift card issuance platform that logs at card level answers that in one step. A system that exports totals forces reconstruction from several sources, and reconstruction is what an auditor discounts.

‍

Recipient records and data protection

‍

Under the UK and EU General Data Protection Regulation, storage limitation in Article 5(1)(e) pushes towards deleting personal data, while audit pushes towards keeping the record. Article 17(3)(b) allows retention where a legal obligation requires it, but it does not cover data kept only for convenience. A workable design keeps identity in the human resources or customer system of record and holds only a pseudonymous recipient reference in the log, so the audit record survives an erasure request without carrying more personal data than it needs.

‍

A counter argument is that auditors prefer full identity in the log because it avoids a second lookup. That preference is reasonable for fraud investigation. The trade off is settled by giving the investigator controlled access to the lookup, not by copying identity into the log.

‍

Retention

‍

Retention periods differ by jurisdiction and record type, so the policy should state a rule and not a number: retain for the longer of the financial record period in each relevant jurisdiction and internal policy, confirmed with the tax adviser. Where one programme spans several jurisdictions, apply the longest.

‍

Tracking Budget Movement: Allocations, Top Ups and Reversals

‍

Budget movement is tracked by treating each campaign budget as a ledger in which every allocation, top up, issuance draw down and reversal is a dated entry with an approver. Budget movement history is a record that shows every change to a campaign budget and what caused it.

‍

The ledger test

‍

The auditor's test is arithmetic: opening allocation plus top ups, less issuance, plus reversals, must equal the closing balance of each campaign. Failures cluster in three places. A cap is raised informally to keep a campaign running. A top up is funded from another campaign without a recorded transfer. A cancelled card's value is never returned, so the budget shows value as consumed that was never spent.

‍

Preventive and detective controls

‍

A spend cap that stops issuance at the limit is a preventive control, because it stops the event. A monthly review of budget movement is a detective control, because it finds the event afterwards. Both are needed, since a cap does not show whether the limit itself was changed legitimately.

‍

As an illustration of the preventive side, Reward Factory is a gift card issuance platform from The Reward Store, with campaign management and budget governance built in. Its budget governance includes a spend cap that pauses issuance automatically once reached, top up at any time and variable budgets per campaign, which are the events a budget ledger has to evidence.

‍

Reversals

‍

A card can be reversed only if it has not been redeemed, so redemption status must be checked before a reversal is booked. Obtain it from the issuing system where it reports redemption status, or from the supplier where it does not.

‍

Reconciling Issuance Against Settlement

‍

Settlement is reconciled by matching three records in sequence: the issuance log to the supplier settlement statement, then both to the general ledger, with every difference classified. Settlement reconciliation is a control that compares the value recorded as issued with the value the supplier has charged and explains each difference.

‍

A worked scenario

‍

Consider a regional retailer running a seasonal campaign across several regions through one gift card supplier. At month end the issuance log exceeds the settlement statement. The finance controller finds that the difference equals the cards issued on the final evening, because the system stamps events in UTC while the supplier cuts off at local time. A second, smaller difference comes from cards voided and credited in the following month. Neither is an error, but both need a recorded explanation. Without one, the difference would be written off as a rounding variance, and a genuine duplicate issuance could sit inside it. The fix is a documented cut off time zone and a standing list of timing items.

‍

Choosing reconciliation depth

‍

Reconciliation Approach Table
Situation Approach Reason
Supplier statement lists each card Card level match Differences are identified individually
Statement gives batch or campaign totals only Campaign level match plus a sample of cards traced Card level proof is unavailable, so sampling compensates
Low volume, infrequent programme Two way match of approved budget to statement, dual sign off A card level three way match costs more than the risk it addresses

‍

When the recommended approach is the wrong choice

‍

A full card level reconciliation is the wrong choice for a small, occasional programme. The effort exceeds the exposure, and a control nobody sustains is worse than a simple one that is performed. Use a monthly comparison of approved budget with the settlement statement, a second reviewer's signature and an annual sample traced from approval to settlement. Whatever the depth, never net one difference against another, because offsetting errors disappear that way.

‍

The Questions Auditors Ask and Where Organisations Cannot Answer

‍

Auditors ask questions that test authorisation, completeness, accuracy, cut off and access, and organisations most often fail on those that require two records to be joined.

‍

Questions from internal audit

‍

  • Show the approval for this card. This fails when the issuance record carries no approval reference.
    ‍
  • Which accounts can change a budget cap, and when were those rights last reviewed? This fails when no user access review exists.
    ‍
  • Can the person who approves also issue? This fails when roles are described in policy but not enforced in the system.

‍

Questions from external audit
‍

  • Provide the complete population of issuance for the period. Auditors must test the completeness and accuracy of any report they rely on, known as information produced by the entity. Manually assembled spreadsheets fail this test.
    ‍
  • What was issued after period end but dated within it? This is the cut off question, and it fails when time zones are undocumented.
    ‍
  • How was the treatment of unredeemed cards determined? This fails when redemption status cannot be produced.

‍

A Monthly Close Routine That Stays Audit Ready

‍

A close routine stays audit ready when every step produces a retained, signed artefact, so evidence accumulates during the month and is not assembled afterwards. A weekly cycle suits a programme with high daily volume, because a monthly cycle then finds differences too late to trace.

‍

  1. Fix the cut off time and time zone, and record them in the close file.
    ‍
  2. Export the issuance population from the system, retain the export unchanged and record its record count and total.
    ‍
  3. Match every issuance to an approval reference and list the exceptions.
    ‍
  4. Roll forward each campaign budget and agree the result to its closing balance.
    ‍
  5. Reconcile to the settlement statement and classify each difference as a timing item, an error or unexplained, clearing the unexplained items before sign off.
    ‍
  6. Agree totals to the general ledger and confirm that sold and promotional cards are classified correctly.
    ‍
  7. Review changes to user access and to caps made during the month.
    ‍
  8. Have a preparer and an independent reviewer sign, with the reviewer not being a campaign approver.
    ‍

Where a Gift Card Issuance Platform Fits, and What Reward Factory Does

‍

A gift card issuance platform fits at the point where issuance, campaign rules and budget are controlled together, so that the records described above are created as issuance happens. Reward Factory, from The Reward Store, issues and manages gift card programmes for retailers and brands across a store network of any size. It supports regional, influencer, aggregator and loyalty campaigns, each holding its own independent rules, and provides a spend cap that pauses issuance automatically, top up at any time and variable budgets per campaign. It tracks issuance and campaign performance in real time and reports the redemption status of cards it has issued. It does not operate redemption.

‍

Frequently Asked Questions

‍

What does an auditor expect to see in a gift card approval trail?

‍

An auditor expects the requester, the approver, the authority limit applied, the approved value, the campaign and a timestamp, held in a record that cannot be edited afterwards. The approval must also carry a reference stored on each issuance event it authorised, so that any single card can be matched to its approval without relying on email or memory.

‍

How often should gift card issuance be reconciled to the supplier statement?

‍

Reconcile at least monthly, aligned to the finance close, and more often where daily issuance volume is high. The frequency should allow a difference to be found while the transactions behind it can still be traced. Every difference should then be classified as a timing item, an error or unexplained, and none should remain unexplained at sign off.

‍

What is information produced by the entity, and why do external auditors test gift card reports for it?

‍

Information produced by the entity is data generated by an organisation's own systems or spreadsheets that an auditor relies on as evidence. External auditors test that an issuance report is complete and accurate before using it, so a population exported directly from the issuing system, with its record count and total retained unchanged, is easier to accept than one rebuilt manually.

‍

How long should we keep gift card issuance records, and does GDPR allow it?

‍

Keep them for the longer of the statutory financial record period in each relevant jurisdiction and your internal policy, confirmed with your tax adviser. GDPR storage limitation does not prevent this where a legal obligation requires retention, but hold only a pseudonymous recipient reference in the log and keep identity in the system of record.

‍

Can the same person approve a gift card budget and issue the cards?

‍

They should not. Segregation of duties requires that the person who approves a budget, a top up or a cap change is a different user account from the person who triggers issuance. Where a small team makes this impossible, add a compensating control, such as an independent monthly review of every approval and cap change by someone outside the programme.

‍

Why does the issuance log not match the supplier settlement statement at month end?

‍

The usual causes are timing differences and not error. Cut off differences arise when the issuing system and the supplier use different time zones or period end times, and voided cards are often credited in the following month. Duplicate issuance and incorrect values are less common causes, which is why each difference needs an individual explanation and must never be netted.

‍

What does Reward Factory show a finance team about issuance in real time?

‍

Reward Factory provides real time tracking of issuance and campaign performance, without waiting on a separate report. Its budget governance covers a spend cap that pauses issuance automatically once reached, top up at any time and variable budgets per campaign. It also reports the redemption status of cards it has issued, and it does not operate redemption.

Sign up for our newsletter for trending top content!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.