Blog · September 16, 2026 · 20 min read

Digital Receipt Filing That Holds Up

Graphic title card for the article “Digital Receipt Filing That Holds Up” with a stylised receipt with ledger columns.
Grafik: HumanITy

A receipt archive is properly ordered when a stranger finds what they are looking for in it within a reasonable time. That is what German law says in substance: under section 145 (1) of the Fiscal Code (AO), bookkeeping must be such that it can give an expert third party an overview of the transactions and of the situation of the business within a reasonable time, and for the documents themselves section 147 (1) AO asks for a single word, "geordnet", ordered. Which order that is, is left to you. The GoBD, the German principles for keeping books in electronic form, state in margin no. 117 that no particular filing system is prescribed, and name chronological order, subject groups, account classes, receipt numbers or alphabetical order as possible routes; all that must be ensured is that an expert third party can verify the books within a reasonable time. In my own archive four decisions turned out to be the load-bearing ones: one place per matter instead of two half ones, staged access rights, a process documentation that describes how the work is done here, and a rule for when things may be deleted and when precisely not.

At my desk the archive took its present shape when I handed the receipt work over. Before that my head was the filing system, and that worked as long as I was there. Since Peter screens the receipts, sets the receipt type and reconciles the card statement against them, every rule has to be written down. What a setup made of inbox, receipts and assignment looks like is in AI Agent for Bookkeeping and Inbox. This post is about the layer below it: what happens to a receipt once it is in the system. How it gets in there is covered in Receipt Scanning Apps: The Best Tools.

The benchmark is not your working day, it is the day of the audit

Many archives are built like a desk and not like an archive. In day-to-day use almost any structure works, because you know where you put things. It gets used, though, on a day when you are not the one searching: the tax adviser asks for a receipt, an audit looks at a period, or somebody stands in for you.

Margin no. 148 of the GoBD describes who you should be picturing: from an expert third party one may expect knowledge of the filing rules in sections 145 to 147 AO and general data-processing competence, but not specific, product-dependent system or programming knowledge. An archive that only works if you know the author's abbreviations does not, as a rule, meet that benchmark. On top of that comes section 147 (5) AO: anyone presenting documents as a reproduction on a data carrier must provide, at their own expense, the aids needed to make them readable. Think of the archive that way and you build it differently: not more comfortably, but more explainably.

An order a third party can follow

Four decisions are worth taking deliberately and writing down, rather than letting them happen to you.

Decision The question behind it How you notice it is missing
Leading system Which system is the archive, which one is only a corridor The same receipt sits in the bookkeeping tool and in a mail folder, and nobody knows which version counts
Sorting criterion What do you sort by: date order, subject groups, receipt numbers The search starts with the question of who filed the receipt
Naming How do you recognize a receipt without opening it Scan_0042 and Invoice_final_2 in the same folder
Boundary What expressly does not belong in this archive Private till receipts and personnel files sit between the accounting vouchers

One point about the first row is easy to misunderstand: a leading system means that the authoritative version of each receipt is clear. It does not ban technical copies. Backups and compliant replicas are part of the documented procedure; the problem is two equal archives, not the backup.

Two legal points come on top, and they are easily missed when you think only in folder trees. First: under section 146 (5) AO, the books and the other required records may also consist of the ordered filing of receipts, and margin no. 46 of the GoBD sets out that the function of the primary records can be fulfilled on a lasting basis by an ordered and clearly arranged receipt archive. If your archive takes on that role, it is no longer just a collection, it is part of the bookkeeping.

Second: margin no. 110 says that storing data and electronic documents in a file system does not, as a rule, meet the immutability requirements unless additional measures are taken. A folder on your machine or in the cloud is therefore not an archive in the sense of the rules, as long as nothing is added that makes a replacement or a deletion visible. For electronic documents, margin no. 117 additionally requires that receipt, archiving, any conversion and the further processing be logged.

Access: why not everyone should see everything

Access rights feel like bureaucracy in a small business, right up until the first time somebody else is in the system. The GoBD list access and authorization controls based on corresponding authorization concepts in margin no. 100 as the first example of the internal control system, followed immediately by separation of duties. These controls are to be set up, exercised and logged, but their design expressly depends on complexity, organizational structure and the system in use.

The strongest argument sits in margin no. 172. If the data holdings also contain data that is not subject to recording and retention duties, for instance personal data or data covered by the professional secrecy of section 102 AO, then it is on you to organize it so that the auditor can access only the data that is subject to those duties, for example through access restrictions or digital redaction. And then comes the sentence that settles the matter: for data handed over by accident there is no prohibition on its use. That is a statement about the tax procedure and not a release: data minimization, access protection and professional secrecy remain duties of their own and are untouched by it. The separation has to exist beforehand, not in the moment of the audit. That is exactly what the "Boundary" row in the table above is for.

In my own archive three levels have proved enough, and in my experience a small business does not need more:

  1. Read. For whoever has to find and look at receipts but changes nothing. The typical case for a stand-in.
  2. Capture and assign. For whoever uploads receipts, sets receipt types and prepares transactions. This is where most of the work sits, and where nothing is finally decided.
  3. Change, delete, approve. The level that stays with you.

Because receipts usually contain personal data, a second body of law joins in: under Article 32 (4) GDPR you have to take steps to ensure that persons under your authority who have access to personal data process it only on your instructions. What form that instruction has to take is not prescribed by that paragraph. A written role and work instruction is therefore not a requirement lifted from the statute, but it is the practice that lets you demonstrate it if it ever matters. What this means for AI tools that get to see receipts is in AI and Privacy: What the AI Gets to See.

Process documentation: the page that describes how the work is done here

Under margin no. 151 of the GoBD, a clearly structured process documentation must exist for every system in use, from which the content, structure, sequence and results of the procedure are fully and coherently apparent, and it has to be verifiable by an expert third party within a reasonable time. Margin no. 152 names the content: the organizationally and technically intended process from the creation of the information through indexing, processing and storage to unambiguous retrieval, machine evaluability, protection against loss and falsification, and reproduction.

Three things about it are regularly underestimated:

  • It is itself subject to retention. Section 147 (1) no. 1 AO lists, alongside books and records, the working instructions and other organizational documents needed to understand them, and the ten-year period applies to that group. Margin no. 154 adds that its period does not expire as long as the period is running for the documents it is needed to understand.
  • Old versions stay. Under the same margin number it must be demonstrable that the documented procedure matches the one actually in use, and changes must be historically traceable; that is satisfied if they are versioned and a change history exists.
  • It is not purely an IT paper. The description of the internal control system is part of the process documentation under margin no. 102, and the description of data backup under margin no. 106. Anyone who settles access levels and backups anyway has already written two chapters.

Margin no. 155 takes the edge off: as long as a missing or inadequate process documentation does not impair traceability and verifiability, there is no formal defect of substantive weight that could lead to the bookkeeping being rejected. How long it gets depends on the actual procedure and not on your headcount. With one intake channel, one leading system and one backup, the points from margin no. 152 fit on a page: where receipts come from, where they sit, who may do what, how it is checked and how it is backed up. Once a scanning process, several interfaces or a change of system come into it, it gets longer, and the short version only holds if it points to versioned annexes. A free frame for all of this is the model process documentation for replacement scanning published by the German Federal Chamber of Tax Advisers. This is the legal position as it stands in the provisions cited below, and not tax advice for your case: what you specifically have to document is something you settle with your tax adviser.

When something may go, and when it may not

The periods are staggered, and the starting point depends on the type of document under section 147 (4) AO: books, records, inventories, annual accounts and the organisational documents needed to understand them are generally kept for ten years from the relevant final entry or preparation year; accounting vouchers for eight years from the year in which they arose; business correspondence and other documents for six years from the year of receipt or dispatch. The process documentation therefore belongs with the ten-year group, not the eight-year voucher group. The overview is in Bookkeeping Basics for the Self-Employed.

For the archive, a different sentence is the important one, section 147 (3) sentence 5 AO: the retention period does not expire in so far as and for as long as the documents matter for taxes for which the assessment period has not yet expired. If an external audit is running or an assessment is still open, nothing gets thrown away, even if the eight years are formally up.

From that follows a design rule: deleting is an act with a decision in front of it, not a calendar entry. Automatic deletion needs a hold for an audit, legal dispute or open assessment period and, depending on risk, a logged second approval. In a small business a list can be enough, with one line per year stating the earliest deletion date, what currently blocks it and who approved it. The other direction is just as strict: under margin no. 119, documents that were created or received electronically are to be retained in that form and may not be deleted before the period expires. What happens to old years when you switch providers is covered in Accounting Software for Small Businesses.

The day you are not there

If the person responsible drops out, the archive turns into a question of reachability. Section 200 (1) AO obliges you to cooperate in establishing the facts, to present documents for inspection and examination, to give the explanations needed to understand them and to support the tax authority in its data access. Margin no. 175 of the GoBD expressly counts support by persons familiar with the system as part of that assistance, with the extent depending on the circumstances of the business, such as size or headcount. A small business owes less than a large one, but nobody owes nothing.

Two points therefore belong in the archive and not in an emergency folder that nobody finds. First: if your data sits with a third party, meaning the software vendor or the tax firm, that third party has to grant the tax authority access under section 147 (6) sentence 2 AO, evaluate the data or transfer it in a machine-evaluable format, and you bear the cost. Your ability to answer questions therefore hangs on a contract that, in case of doubt, somebody else needs to know about. Second, the storage location is regulated too: section 146 (2) AO generally addresses books and required records kept in Germany; paragraph 2a permits electronic books and required electronic records in EU member states where full data access remains possible, and paragraph 2b permits third countries only after approval on application. These rules do not classify every cloud file by server country alone. Actual access, the provider contract and GDPR obligations also matter.

In practice three lines belonging to the archive will do: where the receipts are, how a stand-in gets in and by which route, and how they are made readable if the system is down. The general part, meaning workflows and access beyond bookkeeping, is covered in Office Organization for the Self-Employed.

What an AI employee does at this point

A written-down archive is the precondition for being able to hand receipt work over at all, to a temp just as much as to an AI employee. In my business that part is done by Peter. He works in the browser in my bookkeeping interface, screens incoming receipts, sets the receipt type and goes through the card statement line by line. He follows a written process description, and what is not in it, he does not do. If something does not fit, he reports it as open instead of making it fit. The professional review and the sign-off stay with me, and the tax adviser stays the tax adviser. How such a role comes about in the first place, I collect on the page on hiring an AI employee.

The connection to this post is closer than it looks. The process description an AI employee needs answers largely the same questions that margin no. 152 puts to a process documentation: where the receipts come from, how they are named and retrieved, what happens to doubtful cases, and what never happens without approval. One does not automatically replace the other, because the process documentation describes the system and not just one role within it. But the effort only arises once.

The access levels above apply to him like they do to anyone else. In my configuration he sees the receipt archive and the statements and nothing else, and anything that changes a state is covered by a step in an approved process. That is a matter of how he is set up, not a property of a product.

Frequently asked questions

How does a digital receipt archive have to be structured?

No particular filing system is prescribed. Margin no. 117 of the GoBD names date order, subject groups, account classes, receipt numbers or alphabetical order as permitted routes and requires only that an expert third party can verify the books within a reasonable time. In practice that means: one leading system, a traceable sorting criterion, telling names, and a clear line on what does not belong in there.

Is a folder on my computer enough as a receipt archive?

As a rule, no. Margin no. 110 of the GoBD says that filing in a file system does not, as a rule, meet the immutability requirements unless additional measures are taken. What is missing is the evidence that nobody replaced a file unnoticed. As a staging post the folder is fine, as an archive it is not.

Who is allowed to see my receipts?

You decide that through permissions, and you should decide it deliberately. The GoBD name access and authorization concepts and separation of duties in margin no. 100 as part of the internal control system. Margin no. 172 matters most: data that is not subject to retention duties has to be separated so that an auditor cannot reach it. The lack of a tax-law exclusion for accidentally disclosed data is not permission to ignore data minimisation, access protection or professional secrecy.

Do I need process documentation as a sole trader?

The GoBD require it in margin no. 151 for every system in use, but its scope follows the procedure. With one intake channel and one leading system that can be a single page; with a scanning process, several interfaces or a change of system, correspondingly more. Margin no. 155 softens it further: as long as traceability and verifiability are not impaired, missing documentation is not a formal defect of substantive weight.

May I delete receipts as soon as the period has expired?

Not without checking. Under section 147 (3) sentence 5 AO the retention period does not expire in so far as and for as long as the documents matter for taxes whose assessment period is still open. With an audit running or an assessment open, everything stays. Every deletion therefore needs a decision in front of it and not just a date.

How to continue

Start with the stranger test, not with a new tool: take three line items from last year's statement and let somebody who does not know your business look for the receipts. Whatever they cannot find in a few minutes shows you which of the four decisions is the weak one.

The second step is the description: where receipts come from, where they sit, who may do what, how it is checked and how it is backed up. For a simple procedure that is half an hour and one page; with several channels, correspondingly more. After that you set up the year list that says when each year may go at the earliest.

The third step is the one the first two are the precondition for: handing the receipt work over. How I did that, with a written process description, staged rights and a control count before and after the assignment, I show in my community Claude Practitioners.

Kevin Welter

Kevin Welter

Developer, IT architect, author of technical books (Kubernetes, cloud infrastructures) and speaker. Runs his business with an AI workforce of fourteen AI employees and shows solo business owners in his community how to hire their first AI employee.

More about AI employees

Your first AI employee up and running within an hour

Join the community