Audit-proof archiving: how to archive in line with the GoBD

This article gives you an overview of what audit-proof archiving actually means, what the requirements demand, and how more efficient processes can follow from them.

Audit-proof archiving: how to archive in line with the GoBD

E-invoicing is bringing a change to accounting that many organisations still underestimate. From 2027, a growing number of companies in Germany will have to issue invoices as a structured data set, staggered by turnover at first, and across the board from 2028. At first glance this is simply an obligation. At the same time, it creates the conditions for a far more efficient filing system, because structured documents can be captured, assigned and then archived in an audit-proof way automatically.

The GoBD set out what a clean archive looks like: less manual capture, clearly defined processes. This article gives you an overview of what audit-proof archiving actually means, what the requirements demand, and how more efficient processes can follow from them.

TL;DR – the essentials at a glance

  • Audit-proof archiving means retaining documents in a way that keeps them unalterable, complete and retrievable at any time.

  • The GoBD define six principles for this (including unalterability and traceability) and require procedural documentation.

  • Retention obligations cover invoices (10 years), accounting vouchers (8 years) and business correspondence and emails with a tax connection (6 years), among other records.

  • E-invoices such as XRechnung and ZUGFeRD must be retained as a structured data set. Because the data is machine-readable, filing can largely be automated.

What does audit-proof archiving mean? A definition

Audit-proof archiving (revisionssichere Archivierung) means that documents subject to retention obligations, such as tax-relevant records, are stored so that they remain unalterable, complete and retrievable at any time until the end of the retention period. The term comes from German commercial and tax law. It describes a state in which a tax auditor can trace every document in its original form.

One point matters above all: "audit-proof" is the result of technology and organisation together. Your software has to meet the technical requirements and your processes have to be documented. Only both together produce an audit-proof filing system. The legal framework for this comes from the GoBD.

GoBD guidelines: the six principles

The GoBD (principles for the proper keeping and retention of books, records and documents in electronic form, and for data access) are a circular issued by the German Federal Ministry of Finance (BMF). They set out in concrete terms what Section 147 of the Fiscal Code (AO) and Section 257 of the Commercial Code (HGB) mean for digital accounting.

Their six principles read like a blueprint for a reliable archive:

  • Traceability: the origin of a document, how it was processed and every change to it must be logged and traceable for third parties.

  • Completeness: all business transactions are recorded without gaps. No selective filing.

  • Accuracy: the records reflect the actual business transaction correctly.

  • Timeliness: documents are captured and filed promptly, not retrospectively weeks later.

  • Order: systematic filing with unambiguous assignment, with documents linked to the corresponding entries.

  • Unalterability: once archived, data may no longer be changed after the fact. Corrections remain traceable.

On top of this comes the procedural documentation (Verfahrensdokumentation): a written description of how documents reach your archive, how they are secured there and how they are made available in the event of an audit.

Which documents do you have to archive in an audit-proof way?

All tax-relevant records are affected. In each case the retention period begins at the end of the calendar year in which the document was created:

Type of record

Retention period

Legal basis

Invoices (incoming and outgoing)

10 years

Sec. 147 AO, Sec. 14b UStG

Accounting vouchers

8 years (since 2025)

Fourth Bureaucracy Relief Act (BEG IV)

Commercial books, annual financial statements, balance sheets

10 years

Sec. 147 AO

Business correspondence and emails with a tax connection

6 years

Sec. 147 AO

Payroll tax records

6 years

Sec. 41 EStG

A note on BEG IV: the reduction from ten years to eight has applied since 1 January 2025 to accounting vouchers only. Be careful here, though. Incoming and outgoing invoices still have to be retained for ten years under the VAT Act (Sec. 14b UStG). There is also an exception for credit institutions and insurers, for which the BMF has kept the period at ten years across the board.

E-invoicing: structured formats as an efficiency opportunity

With the e-invoicing obligation, structured formats such as XRechnung and ZUGFeRD move to the centre of accounting. What sounds at first like extra red tape is in fact an opportunity in digital terms: structured data can be read out, assigned and filed automatically. That means less typing, no transfer errors and clean workflows.

For archiving, the principle of originality applies:

  • With XRechnung, you have to retain the structured XML data set in its original form.

  • With ZUGFeRD, a hybrid format combining PDF and XML, the entire file has to be archived unchanged. Extracting only the XML part is not enough, because the document arrived as an original in its entirety.

One misunderstanding comes up frequently, and it concerns the form. Printing out a digital invoice and deleting the file breaches the GoBD. Digital originals have to be retained digitally.

The BMF also makes clear that simply storing documents in a normal email inbox or on a local hard drive is not sufficient. The reason is that unalterability is not assured in that case. Files on network drives can be moved, overwritten or deleted without any system logging it. Their status is then no longer reliably traceable for the tax auditor.

Audit-proof archiving: requirements for your software

An audit-proof archive therefore needs more than a storage location. But no vendor can sell audit-proof status as a finished product feature. It only emerges from the interplay of technology, process and documentation. Your software has to provide the basis for it.

Suitable software exists in several categories: document management systems (DMS), specialised email archiving, WORM storage and cryptographically secured cloud solutions. Which one fits depends on your document volume and the systems you already have.

Look for these criteria:

  • Unalterable filing: once saved, documents cannot be overwritten or deleted unnoticed.

  • Complete audit log: every access, every change and every deletion is logged.

  • Completeness and order: documents are unambiguously assigned and can be evaluated by machine.

  • Rights and role management: clear rules on who may view, file or export documents.

  • Procedural documentation: the route documents take into the archive is described in writing.

  • Auditor export: the data can be made available for a digital tax audit (Z1/Z2/Z3 access).

  • Data backup: a backup strategy following the 3-2-1 rule, with a tested restore.

  • Data protection and data sovereignty: encrypted storage, ideally hosted in Germany and compliant with the GDPR.

One point is regularly overlooked here: deletion obligations and retention obligations can contradict each other. The GDPR requires personal data to be deleted as soon as the purpose no longer applies. Tax law requires the same data to be kept for eight or ten years. If you use automatic deletion policies, you should therefore check them against the tax retention periods.

Find the right software.

What to look for in a secure data exchange solution — including a criteria catalogue and checklist.

Procedural documentation is mandatory

Even the best software achieves little without procedural documentation. It describes how documents enter your organisation, and how they are captured, indexed, processed, archived and finally deleted.

It usually consists of four parts:

  • General description

  • User documentation

  • Technical system documentation

  • Operating documentation

You also have to retain the documentation itself for ten years and update it whenever a system or process changes. One thing is important: do not overwrite older versions, so that the history remains traceable for the auditor.

The blind spot: the route into the archive

Discussion of audit-proof archiving almost always revolves around the archive itself. The GoBD, however, look at the entire flow of documents, and that flow starts on arrival, with all the security gaps that come with it. A document that arrives as an attachment to an unencrypted email, or that is shared via consumer file-sharing services, is not protected against manipulation in transit. If you do not control the incoming channel, you will struggle to demonstrate an unbroken chain of documents later on.

The same applies on the way out. Records go to the tax adviser, annual financial statements to the auditor, salary data to external service providers, and during a tax audit entire data sets travel to the tax office. If that runs through email attachments and consumer file sharing, your clean structure breaks down at exactly the point where the data leaves the building.

This is where FTAPI comes in, with a clear boundary. Audit-proof long-term filing of your accounting records is the job of a DMS or an archive system. FTAPI secures the stretch before and after it, meaning the receipt and the sending of sensitive documents. The whole data flow, in other words. What the solution offers in concrete terms:

  • Secure sending: send sensitive records by email with end-to-end encryption, without the recipient needing software or a certificate.

  • Complete documentation: exchange large volumes of documents and file them in line with the GDPR and in an audit-proof way, with a complete audit trail covering every access.

  • Digital document intake: request records in structured, encrypted form through secure online forms, for example documents from suppliers or data for an audit.

That keeps it traceable who sent or received which document, and when. The foundations are right for regulated organisations: FTAPI is audited to BSI C5 Type 2, certified to ISO/IEC 27001/17/18 and hosted entirely in Germany. Your data stays under German jurisdiction, with no access by US authorities.

In short: FTAPI is not your GoBD archive, but the secure route into it and back out again. The documents you have to archive in an audit-proof way reach and leave your desk encrypted and traceable.

Six steps to audit-proof archiving

Ultimately, software, documentation and document intake all interlock in audit-proof archiving. Set them up in this order and you can archive in line with the GoBD from the outset, instead of patching things up later.

Here are the six most important steps once more:

  • Map your document flows. Record the channels through which tax-relevant documents arrive: email, post, portals, interfaces.

  • Assign document types and retention periods. Define for each type of document whether six, eight or ten years apply.

  • Secure your incoming channels. Replace unencrypted email, fax and consumer file-sharing services with controlled routes.

  • Select an archive system. Check the criteria in the list above and ask to be shown logging and export in action.

  • Produce your procedural documentation. Describe the entire route from receipt through to deletion.

  • Review regularly. Check at least once a year that process and documentation still match.

Conclusion: putting audit-proof archiving into practice in line with the GoBD

Audit-proof archiving means keeping tax-relevant documents unalterable, complete, traceable and available at any time throughout the retention period. You archive in line with the GoBD when you meet its six principles and record the route of every document in your procedural documentation. Retention periods currently run to six, eight or ten years, depending on the type of record.

E-invoicing is now generating more and more structured data that can be captured, assigned and filed automatically. That turns an obligation into an efficiency gain: less manual work, orderly processes and a tax audit that becomes routine. The biggest gap here is not in the archive itself, but in the flow of documents before and after it. Make the receipt and the sending of sensitive documents encrypted and traceable, and you close the chain of documents and create the basis for an audit-proof filing system you can rely on.

Frequently asked questions about audit-proof archiving

Audit-proof archiving means retaining tax-relevant documents in a way that keeps them unalterable, complete, traceable and available at any time throughout the retention period. That state comes from suitable technology combined with documented processes, not from a single certificate.

Audit-proof describes the technical properties of the filing system, such as unalterability and logging. GoBD-compliant means meeting all the requirements of the BMF circular, including procedural documentation. Audit-proof software is the basis; GoBD compliance additionally covers the organisational obligations.

No. The BMF makes clear that simply storing them in an email inbox or on a hard drive does not meet the requirements, because unalterability is missing. Invoices have to be filed in a system that logs changes and deletions and prevents them.

With XRechnung, the original XML has to be retained. With ZUGFeRD, the structured XML part is generally sufficient; a human-readable rendering is needed only if it contains additional information of tax relevance. The format has to be preserved unaltered throughout the retention period.

Invoices, commercial books and annual financial statements for ten years, accounting vouchers for eight years since 2025, and business correspondence and payroll tax records for six years. The period begins at the end of the calendar year in which the document was created.

Note: this article does not constitute legal or tax advice. All content has been prepared with the greatest possible care, but makes no claim to completeness or legal validity.

Stay up to date.

Sign up for our newsletter and receive regular content on digitalisation, data security, and secure data exchange.