Skip to content

Häufig gestellte Fragen

Is a standard DMS sufficient for audit-proof archiving?
A document management system on its own is not automatically sufficient – audit-proof archiving only comes about through the right technical configuration and properly regulated processes. The system must enforce immutability, log every action without gaps and keep documents available and machine-readable for the entire retention period, for example via WORM storage (Write Once, Read Many) and audit trails. A GoBD procedural documentation (Verfahrensdokumentation) is also mandatory, describing how records are created, captured, processed and archived. Without this organisational documentation, even a technically correct solution is deemed non-traceable in the event of a tax audit.
How long must documents be retained in DMS archiving?
The retention periods derive from commercial and tax law and are staggered by document type. For accounting records, the Fourth Bureaucracy Relief Act (BEG IV) has introduced a shortened period of eight years, whereas for banks, insurers and securities institutions it remains ten years due to a later legislative amendment. Ten years continue to apply to commercial books, inventories, opening balance sheets and annual financial statements, while six years apply to other commercial and business letters. What matters is always the specific record and document type, which is why the retention rules are ideally stored directly in the DMS.
Do emails and e-invoices have to be archived separately?
Business-relevant emails are subject to retention obligations and must be kept in an audit-proof manner for six to ten years depending on their content, ideally by connecting the email archive to the DMS. For e-invoices, which domestic B2B recipients have had to be able to receive since 1 January 2025, the structured XML data set must be stored unchanged in its original format – a mere PDF printout is not sufficient. E-invoices within the meaning of the EN 16931 standard include in particular XRechnung and ZUGFeRD from version 2.0.1 (excluding the MINIMUM and BASIC-WL profiles). Structured, immutable retention over the entire period is central here, as the XML counts as the original document for tax purposes.
Is GoBD-compliant archiving in the cloud permitted?
Archiving in the cloud is permissible in principle, provided the GoBD principles are observed and unrestricted data access is ensured at all times. Within the EU or the EEA, electronic retention is possible without separate approval under Section 146 (2a) of the German Fiscal Code (Abgabenordnung), as long as full data access remains guaranteed; for servers in third countries, by contrast, approval from the tax authority is generally required under Section 146 (2b) AO. Technical and organisational measures such as encryption, backups and access controls must permanently safeguard integrity and availability. Responsibility for proper record-keeping always remains with the company, even if an external service provider operates the system.
What happens in a tax audit if the archiving is not GoBD-compliant?
Formal deficiencies in electronic archiving are coming increasingly into focus during tax audits, as they are easy for auditors to detect. If, for example, the Verfahrensdokumentation is missing or the immutability of records cannot be demonstrated, the tax office can reject the accounts in whole or in part. The frequent consequence is an estimation of the tax base, which regularly turns out to the company's disadvantage and can lead to back payments plus interest. Technically sound DMS archiving combined with well-maintained procedural documentation reduces this risk considerably.
How does DMS archiving differ from a backup?
Backup and archiving pursue different goals and do not replace one another. A backup serves to restore data after a loss, is continuously overwritten and says nothing about the immutability of individual records. DMS archiving, by contrast, preserves business-relevant documents immutably, traceably and searchably over the statutory retention periods, for example via WORM storage, versioning and checksums. Only this combination of protected storage, complete logging and procedural documentation meets the requirements for audit-proof archiving and GoBD compliance.