DribbleAudit
All posts
Risk18 June 20266 min read

Spotting GST and income-tax risk before the department does

D
DribbleAudit Team · Product

The income-tax and GST departments have both moved to algorithmic scrutiny. ADVAIT in GST and AST in income tax identify anomalies in filed returns and flag them for scrutiny or notice without a human officer making a judgment call. A return that looks fine to a CA manually reviewing it can look very different to a system trained to spot patterns across millions of taxpayers.

The most common pattern most CAs already know: ITC claimed in GSTR-3B that doesn't appear in GSTR-2B. But there are others that are less obvious.

The GST risk signals that generate most notices

An ITC reversal mismatch (claimed more than eligible under Rule 42/43) is the most common. But the department also flags:

  • GSTR-1 vs GSTR-3B discrepancies — tax paid in 3B doesn't match outward supply declared in GSTR-1. Even small differences get flagged.
  • Large cash transactions against a GSTIN with no GST registration by a vendor — suggests bogus ITC from shell suppliers.
  • E-way bill vs GSTR-1 mismatches — e-way bills generated but supplies not declared, or declared at different values.
  • Return gaps — months where GSTR-3B was filed but GSTR-1 wasn't, or vice versa.
  • Turnover exceeding threshold with no migration to the regular scheme from composition.

The income-tax risk signals

In income tax, the SFT (Statement of Financial Transactions) data creates the most visibility for the department. Banks report cash deposits above ₹10 lakh, mutual fund purchases above ₹10 lakh, property purchases above ₹30 lakh, and similar triggers. The AIS (Annual Information Statement) aggregates all of this. If a client's AIS shows transactions that don't appear in their return, a notice is likely.

Other common income-tax risk factors: turnover declared in ITR is materially lower than the GST turnover for the same period (cross-database matching); interest income below the TDS threshold that wasn't reported; large HUF capital transactions without gift documentation.

How Risk Detector works

Risk Detector runs a scan on your client's filed data: GSTR-3B, GSTR-1, GSTR-2B (if uploaded), and ITR data. The output is a risk register — flagged items sorted by severity, with the specific data points that trigger each flag and the regulatory basis for why it's a risk.

You use this before filing a return to catch issues that can be corrected before they become notices. And you use it after filing — on a quarterly basis for active clients — to identify anything that the department's systems might have already flagged.

A CA who shows a client a proactive risk scan and says 'here's what we caught and how we're addressing it' is having a very different relationship with that client than one who fields notice calls reactively.

The professional risk management argument

There's a practice management dimension to this beyond client service. If a client gets a notice for a return you filed — especially if it turns out to be for something that a basic check would have caught — that's a professional conversation you don't want to have. Risk Detector is partly about client protection and partly about your own practice risk management.

The department's notice rates have been rising steadily. The practices that adapt to proactive risk scanning now will have fewer reactive notice-handling events in eighteen months.

See it on your own notices.

14-day free trial. No card required.

Start free trial →