A Comptroller and Auditor General audit of Gujarat’s Goods and Services Tax administration has exposed significant gaps in tax monitoring, including thousands of crores in compliance deviations and an inability to fully examine ₹1,234.71 crore in transactions because supporting records were not produced.
The findings come from the CAG’s Government of Gujarat Report No. 1 of 2026, which was tabled in the Gujarat Assembly on March 25. The audit examined GST administration and departmental oversight for the period ending March 2024.
The most serious concern arose when auditors selected 65 taxpayers for detailed verification. Records sought for 63 of those 65 taxpayers were not produced, leaving auditors unable to fully examine mismatches and potential deviations involving ₹1,234.71 crore.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Auditors found ₹2,606 crore in compliance deviations
The CAG examined high-value inconsistencies in GST data and identified 738 cases requiring scrutiny.
According to reporting based on the audit, deviations were ultimately identified in 291 cases involving ₹2,606.62 crore. These represented 39.70% of the inconsistencies for which departmental responses were available.
Another five cases involving mismatches worth ₹266.63 crore initially received no response.
The audit also found problems in areas including cancellation of GST registrations, restoration of cancelled registrations and delays in recovery of tax dues.
Not every discrepancy represented tax evasion.
The audit accepted explanations in hundreds of cases. Among a subset of responses examined, some inconsistencies arose from taxpayer data-entry errors, while the department had already initiated corrective action in others.
That distinction is important: an audit mismatch is a signal requiring examination, not automatic proof that tax was stolen.
Records missing in 97% of sampled taxpayer cases
The sharper concern involved the department’s ability to produce underlying evidence.
Auditors sought detailed documents from 65 sampled taxpayers, including account statements, ledgers, invoices, audit reports and debit and credit notes.
Records were unavailable for 63 cases — about 96.9% of the sample.
Without those documents, auditors said they could not conclusively examine transactions involving ₹1,234.71 crore.
This does not mean ₹1,234.71 crore was proven to have been evaded.
It means auditors could not determine whether the flagged transactions were properly accounted for because the records necessary to conduct that verification were not made available.
That difference matters when reporting an audit finding. Missing records represent a serious control failure, but they are not the same as a judicial or investigative finding of fraud.
How GST data mismatches are detected
GST operates through several linked electronic returns.
A business reports sales, purchases, tax liability and input tax credit through different filings. Data from those returns can then be compared to detect inconsistencies.
For example, one return may show a particular tax liability while another filing or related taxpayer’s data shows a different amount.
These mismatches can be innocent accounting errors. They can also indicate incorrect input-tax-credit claims, under-reported sales or unpaid tax.
That is why GST departments use risk parameters and data analytics to identify transactions requiring closer examination.
The CAG’s concern was that detecting an inconsistency is only the first step. Authorities also need records, timely scrutiny and follow-up action to determine whether revenue has actually been lost.
Audit raises wider questions over GST oversight
The report did acknowledge action taken by the Gujarat tax department in a number of cases.
Some discrepancies were reconciled after explanations were received, while corrective proceedings had begun in others.
But the inability to obtain supporting records for almost all taxpayers selected for detailed examination weakened the audit process itself.
The findings therefore point to two different problems: potential taxpayer non-compliance on one side and deficiencies in departmental record-keeping and oversight on the other.
The CAG report was officially tabled months ago, despite renewed newspaper coverage dated September 20. Any fresh reporting should therefore describe the development as a resurfaced or revisited audit finding rather than a newly discovered GST scandal.
What this means for you: A CAG “mismatch” does not automatically mean the entire amount was stolen or evaded. For businesses, however, the findings underline why GST returns, invoices, ledgers and supporting records must remain complete and readily available when tax authorities or auditors seek verification.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics