To audit gift card issuance, trace each issued card from a recorded approval, through a timestamped issuance event tied to a recipient reference and a campaign budget, to the supplier settlement that paid for it. Then reconcile those three records to one another and to the general ledger at every month end. A gift card issuance platform makes this a by-product of normal operation when approvals, issuance, budget movements and settlement are held as records that cannot be edited after the event. The audit is defensible when an independent reviewer can reperform the trace from the records alone, without asking anyone to explain them.
Gift card issuance is audited as a cash equivalent activity because value becomes spendable by whoever holds the code at the moment of issuance, so the control must sit at issuance and not at redemption. A cash equivalent is an asset that converts into spending power without further approval and with little friction. Once a code is delivered, the issuer has no payment run to stop, no bank to recall the funds and no counterparty to query, which separates issuance from an ordinary supplier payment.
Internal audit, working within the COSO Internal Control Integrated Framework or a Sarbanes-Oxley Section 404 control set, tests three risks. Unauthorised issuance includes insiders who hold both approval and issuing rights. Misstatement arises when liabilities or expenses fall in the wrong period, because late issuance is easily missed at cut off. Financial crime exposure arises when issued value is used to move funds out of the organisation, which is why anti money laundering teams applying Financial Action Task Force guidance take an interest.
Cards sold to customers create a contract liability under IFRS 15 or ASC 606, with breakage assessed on the unredeemed portion. Promotional cards are commonly expensed at issuance. The treatment depends on the facts and on technical accounting advice, but the audit consequence is constant: the issuance record must state which type each card is, because the journal entry follows from it.
A defensible approval trail records who requested an issuance, who approved it, under which authority limit, for what value and campaign, and when, and it carries a reference that appears on every issuance event it authorised. An approval trail is a chronological record that shows each authorisation step an issuance passed through before value was created.
Requester, approver, approved value, campaign and timestamp are usually present. The field most often missing is the approval reference stored on the issuance record itself. Without it, an auditor holds two lists that agree in spirit but cannot be matched card to approval. Approval by email fails for this reason: the evidence exists, but the link to the issuance is somebody's memory.
Segregation of duties is a control that prevents one person from both authorising and executing the same transaction. The usual breach is a campaign manager who requests a budget, approves a top up and triggers issuance under one login. The diagnostic is whether the system can show approver and issuer as different accounts for every campaign, not whether policy says they should be.
No single model suits every programme.
Tiering needs a detective control, for example a review of repeated issuances to one recipient that sit just below a threshold.
An issuance log must record each card individually, be append only and identify the recipient through a reference that resolves to a person, while retention follows the longer of the statutory financial record period and internal policy. An issuance log is a record that captures each card issued with its value, timestamp, campaign, approval reference and recipient reference.
Batch totals are the common failure. A log showing only that a campaign issued a total value cannot answer the auditor's first test, which is to pick one card and ask for its full history. A gift card issuance platform that logs at card level answers that in one step. A system that exports totals forces reconstruction from several sources, and reconstruction is what an auditor discounts.
Under the UK and EU General Data Protection Regulation, storage limitation in Article 5(1)(e) pushes towards deleting personal data, while audit pushes towards keeping the record. Article 17(3)(b) allows retention where a legal obligation requires it, but it does not cover data kept only for convenience. A workable design keeps identity in the human resources or customer system of record and holds only a pseudonymous recipient reference in the log, so the audit record survives an erasure request without carrying more personal data than it needs.
A counter argument is that auditors prefer full identity in the log because it avoids a second lookup. That preference is reasonable for fraud investigation. The trade off is settled by giving the investigator controlled access to the lookup, not by copying identity into the log.
Retention periods differ by jurisdiction and record type, so the policy should state a rule and not a number: retain for the longer of the financial record period in each relevant jurisdiction and internal policy, confirmed with the tax adviser. Where one programme spans several jurisdictions, apply the longest.
Budget movement is tracked by treating each campaign budget as a ledger in which every allocation, top up, issuance draw down and reversal is a dated entry with an approver. Budget movement history is a record that shows every change to a campaign budget and what caused it.
The auditor's test is arithmetic: opening allocation plus top ups, less issuance, plus reversals, must equal the closing balance of each campaign. Failures cluster in three places. A cap is raised informally to keep a campaign running. A top up is funded from another campaign without a recorded transfer. A cancelled card's value is never returned, so the budget shows value as consumed that was never spent.
A spend cap that stops issuance at the limit is a preventive control, because it stops the event. A monthly review of budget movement is a detective control, because it finds the event afterwards. Both are needed, since a cap does not show whether the limit itself was changed legitimately.
As an illustration of the preventive side, Reward Factory is a gift card issuance platform from The Reward Store, with campaign management and budget governance built in. Its budget governance includes a spend cap that pauses issuance automatically once reached, top up at any time and variable budgets per campaign, which are the events a budget ledger has to evidence.
A card can be reversed only if it has not been redeemed, so redemption status must be checked before a reversal is booked. Obtain it from the issuing system where it reports redemption status, or from the supplier where it does not.
Settlement is reconciled by matching three records in sequence: the issuance log to the supplier settlement statement, then both to the general ledger, with every difference classified. Settlement reconciliation is a control that compares the value recorded as issued with the value the supplier has charged and explains each difference.
Consider a regional retailer running a seasonal campaign across several regions through one gift card supplier. At month end the issuance log exceeds the settlement statement. The finance controller finds that the difference equals the cards issued on the final evening, because the system stamps events in UTC while the supplier cuts off at local time. A second, smaller difference comes from cards voided and credited in the following month. Neither is an error, but both need a recorded explanation. Without one, the difference would be written off as a rounding variance, and a genuine duplicate issuance could sit inside it. The fix is a documented cut off time zone and a standing list of timing items.
Choosing reconciliation depth
A full card level reconciliation is the wrong choice for a small, occasional programme. The effort exceeds the exposure, and a control nobody sustains is worse than a simple one that is performed. Use a monthly comparison of approved budget with the settlement statement, a second reviewer's signature and an annual sample traced from approval to settlement. Whatever the depth, never net one difference against another, because offsetting errors disappear that way.
Auditors ask questions that test authorisation, completeness, accuracy, cut off and access, and organisations most often fail on those that require two records to be joined.
A close routine stays audit ready when every step produces a retained, signed artefact, so evidence accumulates during the month and is not assembled afterwards. A weekly cycle suits a programme with high daily volume, because a monthly cycle then finds differences too late to trace.
A gift card issuance platform fits at the point where issuance, campaign rules and budget are controlled together, so that the records described above are created as issuance happens. Reward Factory, from The Reward Store, issues and manages gift card programmes for retailers and brands across a store network of any size. It supports regional, influencer, aggregator and loyalty campaigns, each holding its own independent rules, and provides a spend cap that pauses issuance automatically, top up at any time and variable budgets per campaign. It tracks issuance and campaign performance in real time and reports the redemption status of cards it has issued. It does not operate redemption.
An auditor expects the requester, the approver, the authority limit applied, the approved value, the campaign and a timestamp, held in a record that cannot be edited afterwards. The approval must also carry a reference stored on each issuance event it authorised, so that any single card can be matched to its approval without relying on email or memory.
Reconcile at least monthly, aligned to the finance close, and more often where daily issuance volume is high. The frequency should allow a difference to be found while the transactions behind it can still be traced. Every difference should then be classified as a timing item, an error or unexplained, and none should remain unexplained at sign off.
Information produced by the entity is data generated by an organisation's own systems or spreadsheets that an auditor relies on as evidence. External auditors test that an issuance report is complete and accurate before using it, so a population exported directly from the issuing system, with its record count and total retained unchanged, is easier to accept than one rebuilt manually.
Keep them for the longer of the statutory financial record period in each relevant jurisdiction and your internal policy, confirmed with your tax adviser. GDPR storage limitation does not prevent this where a legal obligation requires retention, but hold only a pseudonymous recipient reference in the log and keep identity in the system of record.
They should not. Segregation of duties requires that the person who approves a budget, a top up or a cap change is a different user account from the person who triggers issuance. Where a small team makes this impossible, add a compensating control, such as an independent monthly review of every approval and cap change by someone outside the programme.
The usual causes are timing differences and not error. Cut off differences arise when the issuing system and the supplier use different time zones or period end times, and voided cards are often credited in the following month. Duplicate issuance and incorrect values are less common causes, which is why each difference needs an individual explanation and must never be netted.
Reward Factory provides real time tracking of issuance and campaign performance, without waiting on a separate report. Its budget governance covers a spend cap that pauses issuance automatically once reached, top up at any time and variable budgets per campaign. It also reports the redemption status of cards it has issued, and it does not operate redemption.