Audit-proof archiving: significance and legislation

The importance of audit-proof archiving can be summarised in a single sentence: documents relevant under tax and commercial law must be retained in such a way that they are complete, unaltered or versioned in a traceable manner, organised, retrievable and verifiable. This is also consistent with the typical GoBD criteria such as traceability, completeness, organisation and immutability, etc.

Audit-proof archiving by law: Which requirements are relevant?

In fact, there is no specific section of the law entitled ‘Audit-proof archiving: the law’. Rather, the obligation to retain records arises from several sets of regulations, and the GoBD (short for ‘Principles for the proper maintenance and retention of books, records and documents in electronic form, as well as for data access’) specify how retention should be organised in electronic systems.

Typical legal reference points for audit compliance in Germany are:

  • German Fiscal Code (Abgabenordnung), Section 147 AO: This regulates the retention of tax-relevant documents and the retention periods depending on the type of document.
  • Commercial Code, Section 257 HGB: This sets out the retention of commercial ledgers, supporting documents, business correspondence, etc.
  • Value Added Tax Act (UStG), Section 14b UStG: This Act defines the legal basis for the retention of invoices.

Important to note: The Federal Ministry of Finance has amended the GoBD, partly due to legislative changes relating to e-invoices, as these have been mandatory since 1 January 2025. For example, a printed e-invoice is not considered an original.

Without a digital solution, audit-proof document archiving in companies is therefore not possible. A closer look at the requirements for suitable software clarifies this in detail.

About the software solution

Typical requirements for software designed for audit-proof archiving

Whether it’s an incoming invoice, a contract, a delivery note or an approval log: in practice, these requirements almost always arise:

Requirement #1: Completeness
Nothing must be lost on the way to the archive, including attachments, approvals, statuses and links to the business transaction.

Requirement #2: Traceability
A point that is particularly relevant with regard to audit trails: who decided, checked, approved or rejected what, and when?

Requirement #3: Immutability or versioned changes
Content that has been finally archived is preserved, no matter what happens. If something needs to be corrected, this must be traceable – e.g. through a new version or a log.

Requirement #4: Organisation and discoverability
Organisation is key: this depends on structure, metadata, unique identifiers, clear storage locations and the ability to search quickly.

Requirement #5: Access rights and protection against unauthorised access
A sensitive issue that can be managed through roles, groups, client segregation and, where necessary, access rights down to document level.

Requirement #6: Retention and deletion periods
The rule here is: retain for as long as necessary (in accordance with the German Fiscal Code (AO), the German Commercial Code (HGB) or the German Value Added Tax Act (UStG)), and delete as soon as permitted and required – for example, in relation to data protection.

Requirement #7: Process documentation
Auditors expect not only files, but also a description of how the system is used.

Get advice on audit compliance with linqi now

How does linqi meet the requirements for audit-proof archiving?

To ensure that the audit-proof nature of digital archiving is efficiently integrated into day-to-day operations, the process is taken into account right from the outset during process automation with linqi. This ensures that the requirements are specifically met:

Completeness: coherent process files instead of isolated documents

linqi ensures that documents are not lost on their way to the audit-proof archive by bundling everything into a clear workflow: files, attachments, mandatory details, status and assignment to the process. Through defined steps, mandatory fields and clear handover points, it remains traceable when a document is complete and when it may be passed on or archived. Optionally, the handover to target systems, such as a DMS, can be automated.

Traceability: approvals, decisions and statuses as a chain of evidence

linqi stores processes in an audit-proof manner, ensuring that it remains traceable who reviewed, approved or rejected a document and when. Decisions are recorded within the process, a status is set, notifications are triggered, and approvals can also be verified at a later date. This is important because, in an audit, it is not only the document that counts, but also the path taken to reach it, including checks, deviations and justifications.

Immutability and versioned changes: clear steps rather than overwriting

In linqi, immutability is ensured through process logic and versioning. A document can be submitted as an original, reviewed and only transferred to a final status once approved. If something needs to be corrected, this is not done by silently overwriting the document, but as a traceable step – for example, as a new version with a documented decision. In addition, linqi supports versioning in process management, ensuring that adjustments to the workflow itself remain traceable.

Organisation and searchability: metadata, process numbers, folders and tags

Digital archiving requires a structure that works in day-to-day practice. linqi supports this through process metadata, unique process numbers per client and folder, as well as tags as an additional organisational tool. This results in a filing system that is not only formally correct but also delivers added value in day-to-day work.

Permissions and protection against unauthorised access: clearly separating roles

linqi offers group- and user-based rights management as well as multi-client capability. In addition, permissions can be assigned on a case-by-case basis when documents are stored in third-party systems. This ensures that access protection remains in place even after the handover.

Retention and deletion periods: Implementing retention periods technically rather than managing them manually

Audit compliance also means not deleting data too early, whilst consistently purging systems once retention periods have expired. linqi supports deletion periods at client and process level, which can be dynamically adjusted as required. This enables the implementation of a deletion strategy that takes retention obligations into account whilst also supporting data protection requirements.

Procedural documentation: Processes as living documentation

Auditors expect not just files, but a traceable description of how the system is used. linqi supports this indirectly, as workflows, roles, responsibilities, approval rules and control points are mapped out in the process design. Supplemented by brief process descriptions, this creates a solid foundation for procedural documentation, including traceable evidence.

Find out more about linqi’s features

How can audit-proof archiving be implemented technically using linqi?

The no-code platform enables audit-proof archiving to be implemented in a practical manner by structuring the process into clear steps. This is illustrated by the example of e-invoices.

Practical example: Audit-proof archiving with linqi: Incoming invoices, including e-invoices

  • Step 1: The invoice is received, for example via upload or from SharePoint.
  • Step 2: linqi parses the e-invoice, automatically recognises the key data and uses it directly within the process.
  • Step 3: Metadata such as invoice number, invoice date or cost centre are automatically populated, including mandatory fields.
  • Step 4: The approval workflow runs in a structured manner through the relevant department, quality assurance and, if necessary, escalation, including status changes and a record of who approved what and when.
  • Step 5: The invoice, together with its context, is then transferred to the DMS and/or DATEV.
  • Step 6: Finally, retention and deletion periods are set so that the invoice is automatically deleted later, as soon as this is permitted.

Request a live demo now

If you can click this button, you can also use linqi to automate audit-proof archiving.

Discover the features

FAQ

Request a free live demo

After a preliminary discussion of approx. 30 minutes, we will automate your process free of charge and demonstrate linqi to you using your own process in a live demo via video call (approx. 60 minutes) to clarify any open questions.

Request Live-Demo

Further Wiki Posts

The DRG system in hospitals

The DRG system forms the basis for the billing of inpatient hospital care. The aim is to ensure standardised, comparable billing of inpatient services based on medical and billing-related characteristics. 

Procedural documentation in government departments and public administrations

It is essential for transparent and legally compliant administrative processes: procedural documentation. How digital solutions can make it easier to create.

AI or process automation? Differences and connections

linqi is all about intuitive process automation, whilst also demonstrating how this approach differs from AI and where artificial intelligence can be usefully integrated into digital workflows.

Automating BPMN - From models to real automation

Experience how easy it can be to transform your existing BPMN processes into automated processes.

Compliance made easy

How linqi helps you meet compliance requirements — with digital workflows that increase transparency and strengthen trust.