Häufig gestellte Fragen
Are the GoBD a law?
No, the GoBD are not a stand-alone law but a circular issued by the German Federal Ministry of Finance and thus an administrative instruction of the tax authorities. However, they give concrete form to statutory requirements from the German Fiscal Code (AO), the German Commercial Code (HGB) and the German VAT Act (UStG), so that observing them is effectively binding in practice. The currently valid version was most recently amended by BMF circulars of 11 March 2024 and 14 July 2025, among other things due to the introduction of the e-invoicing mandate. Violations can lead to formal accounting deficiencies and, in extreme cases, to the accounting being rejected followed by an estimation of the tax bases.
Who do the GoBD apply to?
The GoBD apply without any de minimis or turnover threshold to all taxpayers with business income, that is, to large corporations as well as to small businesses under Section 19 UStG, the self-employed and freelancers. The method of profit determination is irrelevant: they cover both businesses that prepare balance sheets and those that determine their profit via a cash-based income statement (Einnahmen-Überschuss-Rechnung, EÜR). The only decisive factor is that tax-relevant data is recorded, processed or stored in IT systems — which in practice affects virtually every company that generates documents digitally. Small companies must therefore also maintain procedure documentation, although its scope may be adapted to the complexity of their processes.
How long must GoBD-relevant data be retained?
The retention periods are governed by the AO and HGB and are six or ten years depending on the type of document. For accounting records — such as invoices and receipts — the period was shortened from ten to eight years by the Fourth Bureaucracy Relief Act as of 1 January 2025; for credit institutions, insurance companies and securities institutions, however, it was subsequently raised back to ten years. Within the applicable period, the data must not only exist but must also be kept unalterable, machine-analysable and capable of being made legible within a reasonable time. Since the periods can change by law, the current legal position should always be checked or tax advice sought before any data is destroyed.
What data access rights does the tax office have during a tax audit?
The tax authorities' right to digital data access is regulated in Section 147(6) AO and comprises three access types. With direct access (Z1), the auditor works directly on the company's system; with indirect access (Z2), employees run the requested analyses; and with data carrier provision (Z3), the relevant data is exported in an analysable format. While the tax authorities may choose between the access types and also combine them, companies must be able to provide the tax-relevant data for all three access types cumulatively — not merely alternatively. In the ERP environment, this is ensured above all through robust logging, a role concept and standardised export formats such as the DATEV interface.
What are the consequences of GoBD violations?
If a tax auditor identifies formal deficiencies, such as missing log files or inadequate procedure documentation, they can reject the accounting as non-compliant. In that case, the tax office may estimate revenues and profits, which frequently leads to back payments and late-payment surcharges at the company's expense. If data or data access requested in the course of an external audit is not provided on time, an additional cooperation delay penalty (Mitwirkungsverzögerungsgeld) under Section 200a AO can be imposed since 1 January 2025, amounting to 75 euros per full calendar day (for a maximum of 150 days, i.e. up to 11,250 euros), which under certain conditions can be increased by a surcharge. The concrete consequences depend heavily on the individual case and the severity of the findings, which is why clean documentation and audit-proof archiving are important from the outset.
Is a certified ERP system sufficient for GoBD compliance?
No, a mere software certification is not sufficient, because the tax authorities explicitly do not issue binding GoBD attestations for individual products. What matters instead is the interplay of technology, configuration and lived processes — that is, permissions, audit-proof archiving, logging and complete procedure documentation. Many vendors nevertheless have their systems attested by auditors, which can serve as an indication of technical GoBD suitability but does not replace the organisational embedding within the company. Practical relevance and implementation effort therefore depend heavily on the existing system landscape and the business processes to be mapped.
