A Betriebsprüfung — a German tax audit — rarely begins with a box of files today. It begins with a question: "Please show me your Verfahrensdokumentation" — the written description of your accounting procedure. A company that cannot produce it will spend the rest of the audit discussing not individual postings but the propriety of its bookkeeping as a whole, and therefore a possible estimation of the tax base under § 162 of the Abgabenordnung (AO), Germany's General Tax Code.
The GoBD — the German principles for the proper keeping and retention of books, records and documents in electronic form — are not a statute but an administrative instruction issued by the Bundesministerium der Finanzen (BMF), Germany's Federal Ministry of Finance. The version currently in force goes back to the BMF circular of 28 November 2019 and has been amended twice: on 11 March 2024 and, most recently, on 14 July 2025. For the 2026 financial year it is this second amending version that applies — it has been in force since the day of its publication.
At doo.FINANCE, an Odoo Gold Partner and advisory firm for finance and compliance, we set up accounting processes for the German Mittelstand that are built to meet the GoBD requirements. This article is deliberately structured as a checklist: first the four items of evidence you must be able to produce in an audit, then the Odoo configuration that generates precisely those items.
GoBD in 2026: what applies, and what changed most recently
Spelled out, the GoBD are the "Principles for the proper keeping and retention of books, records and documents in electronic form and for data access". They give concrete form to §§ 145 to 147 of the Abgabenordnung (AO) and describe how tax-relevant data is to be captured, secured, retained and made accessible to the tax authorities. They prescribe no product: there is no "GoBD certification" for an ERP system, only a procedure that is operated and documented in line with the rules.
Three developments determine what has to be assessed differently in 2026 than in 2025:
- Archiving e-invoices: since the amendment of 14 July 2025, the structured XML file of an e-invoice is sufficient to satisfy the retention obligation. The image part of a hybrid format — the PDF view of a ZUGFeRD invoice, for instance — only has to be retained in addition where it contains tax-relevant information that differs from, or adds to, the XML.
- Z2 data access: the same amendment widens the tax authorities' options for indirect access; read access to machine-evaluable data is expressly provided for as part of a digital audit.
- Aufbewahrungsfristen (retention periods): the Viertes Bürokratieentlastungsgesetz, the Fourth Bureaucracy Relief Act, shortened the period for accounting vouchers (Buchungsbelege) in § 147 (3) sentence 1 AO from ten to eight years. The reduction applies to all records whose period had not yet expired on the day before the Act entered into force (29 October 2024).
Running in parallel is the E-Rechnungspflicht, Germany's e-invoicing mandate. Domestic companies have had to be able to receive structured B2B invoices since 1 January 2025. For issuing them, transitional rules apply: in 2026 you may still use paper or other electronic formats; from 1 January 2027 only companies with prior-year turnover of up to €800,000 may do so; from 1 January 2028, no one may. That makes 2026 the last full year in which the switch can be planned without deadline pressure. We cover the technical side of that switch in detail in our guide to e-invoicing with Odoo.
The GoBD checklist: four items of evidence you must be able to produce
Test your company against four questions. Each of them can be answered with a document or an export — or it cannot.
1. Verfahrensdokumentation: the evidence that is missing most often
The Verfahrensdokumentation describes how a document travels through your company from the moment it arises to the moment it is archived. It is not the software vendor's manual; it is a description of your procedure. It usually consists of four parts:
- General description: business model, organisational structure, and which document types actually arise.
- User documentation: who holds which role, what approvals exist, how entries are posted and reversed.
- Technical system documentation: systems and versions in use, interfaces, data flows, storage locations, backup and recovery concept.
- Operating documentation: how the procedure is run and controlled day to day, including the history of every change to the procedure itself.
The last point is the decisive one: the documentation must be versioned. An auditor examining the 2022 financial year in 2026 wants to know what the procedure looked like in 2022 — not what it looks like today. An undated file with no change history does not answer that question.
2. Unveränderbarkeit and gap-free logging
Under § 146 (4) AO, a posting may not be altered in such a way that its original content can no longer be established — the requirement known as Unveränderbarkeit, or non-alterability. In practice this means corrections are made by reversal entry rather than by overwriting, and every change remains traceable with its time and its user.
The second requirement is the completeness of the number ranges. Sequential invoice and document numbers with no explained gaps are one of the first things a digital audit tests mechanically. A gap is not proof of an error — but it creates a need for explanation, and without an explanation it becomes an argument against the propriety of the books.
3. Data access: Z1, Z2 and Z3
§ 147 (6) AO grants the tax authority three forms of access in the course of an Außenprüfung, a field audit. In practice they are referred to as Z1, Z2 and Z3:
- Z1 — direct access: the auditor inspects the stored data in your own system, on a read-only basis, normally through a user account set up for the purpose.
- Z2 — indirect access: you evaluate the data mechanically according to the auditor's specifications and make the result available.
- Z3 — handover of data media: you hand over the tax-relevant data in a machine-evaluable format for the tax authorities to evaluate.
For your configuration this means two things: you need an auditor account with read rights that limits access to tax-relevant data, and you need an export that works without rework. An export tried out for the first time on the day of the audit is not a procedure but a risk.
4. Aufbewahrungsfristen: eight, ten and six years
Since the reduction brought in by the Viertes Bürokratieentlastungsgesetz, three different Aufbewahrungsfristen apply side by side in § 147 (3) AO. Confusing them is expensive in both directions, because deleting too early costs you the propriety of your books and retaining too long collides with the erasure obligation under the GDPR (DSGVO).
- Ten years: books and records, inventories, annual financial statements, management reports and opening balance sheets, together with the working instructions and organisational documents needed to understand them (§ 147 (1) no. 1 AO) — this includes your Verfahrensdokumentation.
- Eight years: accounting vouchers (§ 147 (1) no. 4 AO), since the Viertes Bürokratieentlastungsgesetz.
- Six years: the remaining documents, in particular commercial and business letters received and copies of commercial and business letters sent.
Each period begins at the end of the calendar year in which the last entry was made or the document arose. It also does not expire for as long as the documents remain relevant to a tax assessment that is not yet final.
Setting Odoo up to meet the GoBD: the configuration that produces this evidence
Odoo is a modular ERP platform. It is not GoBD-compliant in itself and cannot be — what is compliant is always the procedure, not the product. The configuration below is the part we set up regularly at doo.FINANCE, so that the four items of evidence above are produced at the press of a button rather than on request.
German localisation, posting periods and number ranges
The first step is the German localisation (l10n_de) with the matching chart of accounts — SKR03 or SKR04, depending on your existing practice. Changing the chart of accounts mid-year after the fact creates a need for explanation that nobody needs.
The second step is locking the posting periods. In Odoo, under "Accounting → Configuration → Settings", you set a lock date for all users and a separate lock date for tax reports. After the lock date nothing can be posted in that period any more; corrections necessarily run through a reversal entry in an open period. That is precisely the technical implementation of Unveränderbarkeit.
The third step is the number ranges. Define a dedicated sequence per journal, with no reset within the financial year, and document that decision in the Verfahrensdokumentation. Anyone who has set out the structure of their number ranges in writing does not have to improvise an explanation during an audit.
Archiving e-invoices the way the BMF has required since July 2025
For e-invoices within the meaning of § 14 UStG, the Umsatzsteuergesetz or German VAT Act, the part subject to the retention obligation is the structured XML file. Configure Odoo so that the incoming XML file is stored unchanged as an attachment on the document — as XML, not as a converted image. Converting it into TIFF or PDF destroys the machine evaluability that the retention obligation exists to secure.
With hybrid formats such as ZUGFeRD, retain the PDF view in addition where it contains tax-relevant information that is not in the XML — handwritten or subsequently added account-assignment notes, for example. If it contains nothing that differs, the XML is enough. Record that decision in the Verfahrensdokumentation rather than leaving it to whoever happens to process the document.
A word on storage: cloud storage is permitted, but it has to be documented and secured. Storage location, access rights, encryption, backup rhythm and recovery testing belong in the technical system documentation — treated with the same seriousness you bring to the DSGVO side.
Testing auditor access and exports before the audit
Set up a user role with read-only access to the accounting data in Odoo, and grant it only once an audit has been announced. That satisfies Z1 without anyone seeing more than is necessary. For Z3, export the tax-relevant data in a machine-evaluable format; Odoo supplies the posting journals and the chart of accounts as structured files.
The decisive point is not the export itself but its trial run. Carry one out once a year, before the annual closing, and file the result with a date on it. A documented trial run is at the same time evidence of the internal control that the GoBD expect.
If you are coming from DATEV, the historical data of earlier years deserves a decision of its own: it remains subject to the periods above, regardless of which system you run in production from now on. Our DATEV to Odoo migration guide describes how such a switch can be put in order.
What missing evidence triggers — and why prevention is cheaper
Where the bookkeeping shows formal defects, the tax authorities can reject its propriety. The consequence is an estimation of the tax base under § 162 AO — a procedure in which you carry the burden of proof and in which an estimate typically does not fall in your favour. On top of that come a Verzögerungsgeld, a delay penalty under § 146 (2c) AO where a requested data access is not enabled within the time allowed, and interest on additional tax due.
The effort involved bears no relation to that. A Verfahrensdokumentation for a mid-sized business takes a few working days to produce and is updated annually thereafter. The lock dates, number ranges and export profiles are a one-off configuration. What costs time is reconstruction after the fact — under deadlines, with an auditor on the premises.
Our approach therefore reverses the usual order: we begin with the audit situation and work backwards to the configuration. Anything that cannot be produced in an audit is an open item, regardless of how well the system performs day to day.
A GoBD audit of your Odoo system
doo.FINANCE supports mid-sized companies in Germany in setting Odoo up to meet the GoBD: producing and versioning the Verfahrensdokumentation, lock dates and number ranges, archiving e-invoices in line with the July 2025 version, auditor access and tested Z3 exports. As an Odoo Gold Partner we know both sides — the configuration, and what the Finanzamt, the tax office responsible for your business, asks for. Talk to us about a GoBD audit of your system.
Contact us for a free callFrequently asked questions about GoBD compliance with Odoo
Is Odoo GoBD-compliant?
An ERP system cannot be GoBD-compliant in its own right — what is compliant is the procedure in which it is operated. Odoo provides the building blocks required for that: lock dates for posting periods, reversal logic instead of overwriting, logging of changes, document storage on the journal entry, and structured exports. Compliance arises from how these are configured and from the Verfahrensdokumentation that describes them.
How long must I retain accounting vouchers in 2026?
Eight years. The Viertes Bürokratieentlastungsgesetz shortened the period for accounting vouchers in § 147 (3) sentence 1 AO from ten to eight years; it applies to all records whose period had not yet expired on 28 October 2024. Books, inventories, annual financial statements and organisational documents remain at ten years, and commercial and business letters received and sent at six years.
Is it enough to archive the PDF file of an e-invoice?
No. Since the GoBD amendment of 14 July 2025, the structured XML file is the part subject to the retention obligation. With hybrid formats such as ZUGFeRD, the image PDF part has to be retained in addition where it contains tax-relevant information that differs from, or adds to, the XML. If it contains nothing additional, the XML is enough — converting the XML into an image format is not permitted in any case.
What is the difference between Z1, Z2 and Z3?
Z1 is the auditor's direct, read-only access to your system. Z2 is indirect access: you evaluate the data mechanically according to the auditor's specifications. Z3 is the handover of data media, that is, handing over the tax-relevant data in machine-evaluable form. All three follow from § 147 (6) AO; which form is chosen is for the tax authority to decide.
Do small companies need a Verfahrensdokumentation too?
Yes. The GoBD set no size threshold; the scope and level of detail, however, follow the complexity of the business. A trades business with three document types needs a few pages, while a retailer with a web shop, a till system and interfaces needs considerably more. The measure is whether an expert third party can follow the procedure within a reasonable time.
Sources
- BMF circular of 14 July 2025 — GoBD, second amendment
- § 147 AO — rules governing the retention of documents
- DATEV — amendment to the GoBD of 14 July 2025
- KPMG — BMF: second amendment to the GoBD
- Deloitte — Viertes Bürokratieentlastungsgesetz: retention periods
- IHK Region Stuttgart — mandatory e-invoicing for domestic B2B transactions
