Blog

GoBD-compliant document filing: what auditors really expect

Compliance

When a German tax audit is announced, the decisive question is rarely whether the books are correct. It is whether you can prove it. That is what the GoBD are about. Not tidy folder structures, but whether a qualified third party can follow your digital document filing within a reasonable time. Clarifying that in advance saves a great deal of explaining later.

What the acronym stands for

GoBD is short for Germany's principles for the proper keeping and retention of books, records and documents in electronic form, and for data access (Grundsätze zur ordnungsmäßigen Führung und Aufbewahrung von Büchern, Aufzeichnungen und Unterlagen in elektronischer Form sowie zum Datenzugriff). They are not a law of their own but a circular from the German Federal Ministry of Finance, setting out how the tax authorities apply the Fiscal Code (Abgabenordnung, AO) to digital processes. It was last revised on 11 March 2024 and 14 July 2025, partly because of e-invoicing.

They apply to virtually every business in Germany subject to bookkeeping or record-keeping duties, including cash-basis filers. There is no exemption threshold for small companies.

The principles auditors measure you against

  • Traceability and verifiability: from document to entry and back again, without detours. This is the audit trail.
  • Completeness: every transaction is recorded, individually and without gaps.
  • Accuracy: facts are represented correctly and posted to the right accounts.
  • Timeliness: cash receipts and payments should be recorded daily. For non-cash transactions, the tax authorities accept recording within ten days.
  • Order: the filing structure is designed, not grown by accident.
  • Immutability: once recorded, nothing can be changed without a trace.

Immutability: where improvised tools fail

That last point is the critical one in practice. An invoice as a Word file on the server, a folder of scans beside it, a spreadsheet for open items: all of it can be overwritten at any time, with no record of the earlier state. That is precisely what the GoBD prohibit. Changes must be logged and the previous version must stay readable.

In practice this means two things. An issued document is locked and never touched again; corrections go through cancellation or a credit note, each with its own number. And document numbers are never reset or reissued, because a gap in a number range is exactly what makes an auditor look closer.

Paper documents may be digitised and then destroyed. This substitute scanning is permitted as long as the process is documented and the image is complete, in colour wherever colour carries meaning. Documents with an original function, such as notarised deeds, are excluded.

Retention: eight years for accounting documents since 2025

Something has changed here that many deletion policies have yet to reflect. Germany's Fourth Bureaucracy Relief Act cut the retention period for accounting documents from ten years to eight, under section 147 AO and section 257 of the Commercial Code (Handelsgesetzbuch, HGB). It covers every accounting document whose retention period had not yet expired at the start of 2025.

Books, inventories, annual financial statements and management reports still have to be kept for ten years, and credit institutions, insurers and investment firms were taken back out of the reduction entirely. The period starts at the end of the calendar year of the last entry.

None of this licenses early deletion: while the assessment period for the relevant taxes is running, or an audit has begun, the documents stay. It is worth aligning your GDPR deletion policy with the new periods all the same, because personal data held longer than necessary is a risk of its own.

Process documentation: the piece most often missing

Few topics produce as much silence in an audit room. Your process documentation describes how a document enters the system, who records and checks it, how it is archived, who may change it and what gets logged. It comprises a general description, user documentation, technical system documentation and operating documentation, and it is versioned whenever the process changes.

Its absence does not automatically invalidate your bookkeeping, but it weakens your position as soon as a second defect appears. The good news: much of it can be derived from your software vendor's system documentation rather than written from scratch.

Data access and e-invoicing

During an audit, the tax authority can access data in three ways: directly on your system in read-only mode (Z1), indirectly through evaluations your staff run to its specification (Z2), or on a storage medium handed over to it (Z3). All three assume machine-readable data. A pile of PDF files is not.

This matters more since the B2B e-invoicing obligation took effect. With ZUGFeRD and XRechnung, the structured XML data set is the part subject to retention, not the visual rendering, so archiving only the PDF leaves the document incompletely retained. Format conversions are allowed if they are documented and the original stays available.

How dCM covers the requirements

In our business software dCM, these points are part of the document flow, not a bolt-on.

  • Locking: issued and dispatched documents become immutable. Corrections run solely through cancellation or credit note, with a full audit trail and the original number preserved.
  • Number ranges: sequential, collision-free and never reset, including custom document types such as a repair order.
  • Linked document chain: quotation, order, delivery note and invoice are derived from one another, with quantity tracking across partial and combined calls. The audit trail is a by-product.
  • E-invoicing built in: ZUGFeRD 2.x as PDF/A-3 with embedded XML, and XRechnung as pure XML per EN 16931.
  • Banking and cash: account movements are retrieved via FinTS and matched to documents automatically, alongside a cash register audit and a tamper-proof log that reaches down to the generated SEPA files.
  • Accounting: a posting portal with document assignment and validation, cost centres, and accounting periods for closing financial years cleanly.
  • Filing: the DMS provides hierarchical folders with permissions, search and a change log, plus an interface for incoming files.
  • Handover: DATEV export for your tax adviser, plus journal, totals, open items and a document ZIP for the auditor. Invoices can be mirrored automatically to a WebDAV target such as Nextcloud.

Everything runs in German data centres, which settles where the records are held.

Conclusion

GoBD compliance is not a product you buy. It is a system that logs changes and locks documents, plus a process that is written down. The effort comes once, the relief returns with every audit. If you are unsure where your filing stands, we are happy to look at it with you.

Note: This article provides general information about the German GoBD rules. It does not constitute legal or tax advice.

All posts

Is your document filing audit-proof?

In 30 minutes we'll show you how dCM locks documents, logs changes and produces audit-ready evaluations, with no strings attached and your processes in mind.