The short version
An IRS audit of a theft-loss deduction is usually a proof exercise. The examiner is not just asking whether something bad happened. The examiner is asking whether the return position fits IRC 165, whether the claimed year and amount are supportable, and whether the records match the deduction.
Start with the audit letter. It controls the deadline, the tax year, the item under review, and the submission method. Then build the response file around the legal elements: theft, ownership, discovery timing, recovery prospects, profit motive if the claim relies on IRC 165(c)(2), and the numbers used on the return.
What the law actually says
IRC 165 allows a deduction for losses sustained during the taxable year and not compensated by insurance or otherwise. For individuals, IRC 165(c) limits deductible losses to losses incurred in a trade or business, losses incurred in a transaction entered into for profit, and certain casualty or theft losses.
For scam and fraud cases, IRS Publication 547 gives the current public IRS framing for financial scams. It says a theft loss from a financial scam may be deductible only if the loss resulted from criminal conduct classified as theft under applicable state law, the taxpayer has no reasonable prospect of recovering the stolen funds, and the loss arose from a transaction entered into for profit.
That is why an audit response should not be a general narrative only. It should connect documents to the rule. A strong file shows what was stolen, why the facts fit the claimed category, when the loss was discovered, what recovery channels existed, what amount was claimed, and why the transaction was not merely personal-use property outside the deduction path.
How an IRS audit changes the problem
The IRS audit page explains that an audit is a review of books, accounts, and financial records to verify that the return was reported correctly and that the tax amount is correct. The IRS may conduct an audit by mail or through an in-person interview at an IRS office, the taxpayer’s home or business, or the taxpayer’s representative’s office. The IRS says the initial contact comes by mail.
For a theft-loss deduction, the practical difference is important:
| Audit posture | What it usually means for the response | Source anchor |
|---|---|---|
| Mail audit | The IRS letter requests additional information about specific return items, such as income, expenses, or itemized deductions. | IRS audits |
| In-person audit | The taxpayer or representative may need to walk the auditor through the records and answer follow-up questions. | IRS audits |
| Written document request | The IRS says it will provide a written request for the specific documents it wants to see. | IRS audits |
| Records request or questionnaire | The IRS records-request page lists record categories and says a mail audit may also require a questionnaire. | IRS audits records request |
Do not assume the same response works for every audit. A correspondence audit may require a clean exhibit package. An office or field audit may require a representative who can explain the tax theory, the record trail, and any weak facts without volunteering unrelated problems.
What examiners usually want to see
Publication 547 says that, for a theft loss, a taxpayer should be able to show ownership, that the property was stolen, when the missing property was discovered, and whether a reimbursement claim exists with a reasonable expectation of recovery. For financial scams, the same publication adds the theft-under-state-law, no-reasonable-recovery, and profit-transaction conditions.
Organize the file by question, not by pile.
| Examiner question | Records that may answer it | Why it matters |
|---|---|---|
| What IRS item is under audit? | Audit letter, tax year, return line, Form 4684 workpapers, amended-return history, prior notice history. | The response must answer the issue actually selected for examination. |
| Was there a theft or financial scam? | Police report, FBI IC3 report, bank fraud report, exchange or platform complaint, platform tickets, civil pleadings, criminal papers, written chronology, state-law theft analysis if needed. | Publication 547 requires theft classified under applicable state law for financial scam theft-loss treatment. |
| Did the taxpayer own the property or funds? | Bank statements, brokerage statements, exchange records, wallet records, purchase records, loan records, contracts, receipts, or other account records. | Publication 547 identifies ownership as a theft-loss proof point. |
| When was the loss discovered? | Timeline, account lockout records, failed withdrawal records, communications ending access, bank recall dates, support-ticket dates, law enforcement report dates. | Publication 547 requires discovery timing support. |
| Was recovery reasonably possible? | Insurance claim, bank recall, exchange recovery ticket, restitution notice, receiver or bankruptcy notice, legal demand, denial, settlement, or closure record. | Publication 547 asks whether a reimbursement claim exists with a reasonable expectation of recovery. |
| Was the transaction entered into for profit? | Investment pitch, account opening records, promised-return messages, trading statements, platform screenshots, subscription or advisory records, contemporaneous notes showing investment purpose. | IRC 165(c)(2) and Publication 547 matter when the claim is not a trade or business loss. |
| Is the amount supported? | Basis records, transfer records, account statements, reimbursement records, salvage or recovery records, Form 4684 computation, and return workpapers. | Publication 547 starts the loss computation with basis and reimbursement adjustments. |
The IRS records-request page also lists ordinary record types such as receipts, bills, canceled checks, legal papers, loan agreements, logs or diaries, and theft or loss documents. For theft or loss documents, the IRS lists insurance reports describing the loss or damage and, if not insured, fire department or police reports on the loss, theft, or accident.
The numbers that frame the audit
The exact deadline and document list come from the audit letter, but these source-backed reference points should shape the first review.
| Audit point | Figure or threshold | Source |
|---|---|---|
| Individual IRC 165 categories | 3 categories: trade or business, profit transaction, and certain casualty or theft losses. | IRC 165 |
| Financial scam theft-loss conditions | 3 conditions: theft under applicable state law, no reasonable prospect of recovery, and profit transaction. | Publication 547 |
| Core theft-loss proof points | 4 points: ownership, stolen property, discovery timing, and reimbursement claim status. | Publication 547 |
| Ordinary mail-audit extension | 30 days, usually one automatic extension if requested as the IRS directs. | IRS audits |
| Tax Court petition period after a Notice of Deficiency | 90 days, and the IRS audit page says it cannot extend that petition period. | IRS audits |
| Audit conclusion categories | 3 outcomes: no change, agreed, or disagreed. | IRS audits |
Do not use the 30-day extension language casually. The IRS page ties it to audits conducted by mail, and it also says a Notice of Deficiency is different. If the letter is certified or references Tax Court rights, the deadline analysis should happen before any document package is sent.
How to build the response package
A useful audit package usually has five parts.
First, include a short cover letter. Identify the taxpayer, tax year, audit letter, issue under examination, and response deadline. State whether the response is complete or whether a specific extension has been requested.
Second, include an exhibit index. The index should tell the examiner what each document proves. A bank statement, police report, wallet export, platform screenshot, and Form 4684 workpaper are more persuasive when the index connects each record to ownership, theft, discovery timing, recovery, profit motive, or amount.
Third, include a timeline. Put transfers, account openings, communications, failed withdrawals, discovery events, recovery efforts, reports, and response dates in order. A timeline helps prevent the file from reading like a collection of disconnected screenshots.
Fourth, include the computation. Show the amount claimed, the basis support, any reimbursement received or expected, and how the number connects to the return. If the audit concerns a crypto or investment scam, separate transfer amount, tax basis, proceeds, reimbursements, and any other tax reporting issues.
Fifth, preserve proof of submission. The IRS audit page tells taxpayers to request confirmation that the IRS received the response when using a delivery service. Keep the submitted package, upload confirmation, fax confirmation, certified mail receipt, or other delivery evidence.
Mistakes that make the audit harder
Do not send a raw document dump. A large file with no index can make the examiner’s job harder and leave the key proof buried.
Do not rely on sympathy instead of proof. The facts may be serious, but the deduction still has to fit IRC 165 and Publication 547’s proof framework.
Do not ignore recovery evidence. A theft-loss audit can turn on whether insurance, bank recall, exchange recovery, restitution, litigation, receivership, bankruptcy, or another reimbursement channel created a reasonable prospect of recovery.
Do not assume a police report is enough. A police report may support the theft story, but it may not prove adjusted basis, profit motive, discovery timing, recovery status, or the amount reported on the return.
Do not miss the procedural lane. A document request, proposed adjustment, audit report, and Notice of Deficiency create different response options and deadlines. If the IRS is moving toward a proposed disallowance, the strategy may need to preserve manager conference, Appeals, payment, penalty, or Tax Court options.
Related reading
For the underlying eligibility rule, start with the planned IRC 165 scam-loss eligibility hub. For document gathering, use the planned theft-loss documentation checklist. If the audit ends with a proposed disallowance, the planned denied loss deduction options article should be added after it is owner-approved and live.
Those sibling references are intentionally not linked in this draft because unpublished internal links can create dead public links. Add the live URLs only after owner approval and publication sequencing are confirmed.
How Sheepdog Tax Resolution can help
Upload the audit letter and request a response plan. The review focuses on the letter deadline, the audit posture, the documents requested, the IRC 165 proof elements, and the best next move before the response window closes.
Sheepdog Tax Resolution is veteran-owned and operated by Noah Green, CPA, CFE. No result is guaranteed. Audit outcomes depend on the letter, the deadline, the law, the available records, and how the facts line up with the return position.
Sources (primary authority first)
- 26 U.S.C. 165, Losses.
- IRS Publication 547 (2025), Casualties, Disasters, and Thefts.
- IRS, IRS audits.
- IRS, Audits Records Request.
Prepared by Noah Green, CPA, CFE.
