← Back to the blog 🇲🇽 Mexico · Tax prevention · 6 min read

"I'm too small for the SAT to audit me": the myth that has cost mid-size businesses the most

Written for Mexico. This analysis applies to Mexican federal tax law — ISR (income tax), IVA (VAT) and SAT rules — and cites Mexican statutes. Amounts are in Mexican pesos (MXN).

Quick answerFalse — and it is the myth that has sunk the most mid-size taxpayers. The SAT (Mexico's tax administration) no longer selects audits by hand: it cross-checks by algorithm, automatically and for EVERY RFC (federal taxpayer ID), the CFDIs (digital tax invoices) issued and received against what was declared, the stamped payroll against the withholdings remitted, the VAT against suppliers, and the financial information that reaches it without asking permission. Big companies get the deep audit with a human team; mid-size and small ones get the mass acts that need no auditor: invitation letters, deep surveillance, electronic reviews (art. 53-B CFF) and the restriction of digital seals (17-H Bis) that shuts off your invoicing. Running them costs almost nothing, so size no longer hides you: your real risk is set not by how much you invoice, but by how many inconsistencies you pile up.

The line gets said with dinner-table confidence: "the SAT doesn't have the people to audit us all — it goes after the big ones." Does the SAT really only audit large companies? The premise is true and the conclusion is false. The SAT does have limited auditors, and it does concentrate its deep audits where there is more revenue to collect. What the myth ignores is that enforcement stopped needing auditors: now that every invoice in the country passes through its servers in real time, reviewing a small taxpayer costs what it costs to run a query. And the queries run themselves.

How the SAT selects today: the algorithm, not the auditor

Every CFDI you issue and receive, every stamped payroll receipt, every return, every DIOT (the VAT informative return) from your suppliers and the financial information the banks hand over by law — it all lives in the same database and is cross-checked automatically. You declared less than you invoiced; you stamped payroll whose withholdings you never remitted; you credited VAT from a supplier that appears on the 69-B blacklists; your deposits don't square with your income: each cross-check that fails generates a flag, and the flags turn into acts that need not a single auditor sitting in front of your books — invitation letters and deep surveillance (which are not audit powers, but are the official prelude to them), electronic reviews under art. 53-B CFF resolved through the tax mailbox, and the most surgical of all: the restriction of the digital seal certificate (art. 17-H Bis CFF), which shuts off your ability to invoice until you clear it up. None of those tools distinguishes by size; they distinguish by inconsistency.

What is true: some sins attract more than others

Not everything on this board weighs the same. Unremitted withholdings — the money you deducted from your workers and did not hand over —, VAT you collected but do not pay and the purchase of invoices are in a different category of severity: they stop being administrative errors and cross into tax-fraud territory, and on top of that they put your assets at the mercy of a third party's luck (when the invoice mill blows up, the splash hits you). We take all three apart, with their exact consequences, in the three capital tax sins — if you read a single prevention article, make it that one.

Your real risk profile (and how to lower it)

The practical consequence of the algorithmic model is liberating once you grasp it: your risk is manageable, because it depends on your consistency, not on your luck. The orderly mid-size firm — CFDIs that square with returns, withholdings remitted, verified suppliers, no personal discrepancies — has a very low risk profile even if it invoices tens of millions. The disorderly small one — chronic zeros against bank movement, half-stamped payroll, cheap suppliers of dubious origin — has the electronic review on the horizon even if it invoices two. The concrete triggers that put you in the crosshairs, and how to fix each one before they do it for you, are in the 7 mistakes that put you in the SAT's sights; you can run the initial X-ray of your situation yourself with our tax exposure diagnostic. Labels: operating consistently and documented — low risk, for real, regardless of size; known inconsistencies left uncorrected — countdown: spontaneous correction, before the requirement lands, is still the cheapest lever in all of tax law (it eliminates substantive penalties); assuming you are invisible because you're small — the myth this article came to bury.

Want to know what flags your RFC already has?

The exposure diagnostic reviews your situation the way the algorithm sees it: CFDI vs. returns cross-checks, withholdings, compliance opinion, mailbox, suppliers against the 69-B lists and individual-taxpayer discrepancies. You walk out with an honest traffic light and the order of correction — what gets fixed spontaneously this week and what gets shielded with a file before the authority asks.

Frequently asked questions

What are the odds of being audited if I don't invoice much?

Of receiving a traditional on-site audit: low — those are reserved for large matters. Of receiving a mass enforcement act (invitation letter, electronic review, seal restriction): high if your cross-checks fail, because running them costs almost nothing and they fire off by algorithm. And in practical effect they hurt just as much: restricted seals or a negative compliance opinion halt your operation even if you never face a formal audit.

Is an invitation letter the same as an audit?

No: the invitation letter and deep surveillance are not audit powers — they are prompts to self-correct, with no assessment of a tax liability. But ignoring them is the worst response: you confirm to the authority that the inconsistency exists and that you do not intend to fix it, which is the recipe for escalating to an electronic review or seal restriction. Attending to them — correcting or clarifying with support — closes the file cheaply.

Does the SAT see my bank accounts even if I'm a small individual taxpayer?

Yes. Financial institutions hand over account and deposit information through the CNBV when the authority requires it (art. 32-B CFF), and certain flows are reported automatically — cash deposits above MXN $15,000 a month, among others. The size of the taxpayer does not change the plumbing: the information flows the same for every RFC.

How many years back can the SAT audit me?

The general rule is 5 years (art. 67 CFF); it extends to 10 in cases such as not being registered with the RFC, not keeping accounting records or not filing returns — and the clocks are suspended while audit powers are being exercised. In other words: today's carelessness remains reviewable well into the next decade. The full detail, with the clocks that stop, is in our article on the statute of limitations.

Let's talk about your case

The first step is always the same: an honest diagnostic of where you stand. Write to us on WhatsApp or call — a reply the same business day.

← Back to the blog