A Betriebsprüfung — a German tax audit — rarely begins with a box of files today. It begins with a question: "Please show me your Verfahrensdokumentation" — the written description of your accounting procedure. A company that cannot produce it will spend the rest of the audit discussing not individual postings but the propriety of its bookkeeping as a whole, and therefore a possible estimation of the tax base under § 162 of the Abgabenordnung (AO), Germany's General Tax Code.
The GoBD — the German principles for the proper keeping and retention of books, records and documents in electronic form — are not a statute but an administrative instruction issued by the Bundesministerium der Finanzen (BMF), Germany's Federal Ministry of Finance. The version currently in force goes back to the BMF circular of 28 November 2019 and has been amended twice: on 11 March 2024 and, most recently, on 14 July 2025. For the 2026 financial year it is this second amending version that applies — it has been in force since the day of its publication.
At doo.FINANCE, an Odoo Gold Partner and advisory firm for finance and compliance, we set up accounting processes for the German Mittelstand that are built to meet the GoBD requirements. This article is deliberately structured as a checklist: first the four items of evidence you must be able to produce in an audit, then the Odoo configuration that generates precisely those items.
GoBD in 2026: what applies, and what changed most recently
Spelled out, the GoBD are the "Principles for the proper keeping and retention of books, records and documents in electronic form and for data access". They give concrete form to §§ 145 to 147 of the Abgabenordnung (AO) and describe how tax-relevant data is to be captured, secured, retained and made accessible to the tax authorities. They prescribe no product: there is no "GoBD certification" for an ERP system, only a procedure that is operated and documented in line with the rules.
Three developments determine what has to be assessed differently in 2026 than in 2025:
- Archiving e-invoices: since the amendment of 14 July 2025, the structured XML file of an e-invoice is sufficient to satisfy the retention obligation. The image part of a hybrid format — the PDF view of a ZUGFeRD invoice, for instance — only has to be retained in addition where it contains tax-relevant information that differs from, or adds to, the XML.
- Z2 data access: the same amendment widens the tax authorities' options for indirect access; read access to machine-evaluable data is expressly provided for as part of a digital audit.
- Aufbewahrungsfristen (retention periods): the Viertes Bürokratieentlastungsgesetz, the Fourth Bureaucracy Relief Act, shortened the period for accounting vouchers (Buchungsbelege) in § 147 (3) sentence 1 AO from ten to eight years. The reduction applies to all records whose period had not yet expired on the day before the Act entered into force (29 October 2024).
Running in parallel is the E-Rechnungspflicht, Germany's e-invoicing mandate. Domestic companies have had to be able to receive structured B2B invoices since 1 January 2025. For issuing them, transitional rules apply: in 2026 you may still use paper or other electronic formats; from 1 January 2027 only companies with prior-year turnover of up to €800,000 may do so; from 1 January 2028, no one may. That makes 2026 the last full year in which the switch can be planned without deadline pressure. We cover the technical side of that switch in detail in our guide to e-invoicing with Odoo.
The GoBD checklist: four items of evidence you must be able to produce
Test your company against four questions. Each of them can be answered with a document or an export — or it cannot.
1. Verfahrensdokumentation: the evidence that is missing most often
The Verfahrensdokumentation describes how a document travels through your company from the moment it arises to the moment it is archived. It is not the software vendor's manual; it is a description of your procedure. It usually consists of four parts:
- General description: business model, organisational structure, and which document types actually arise.
- User documentation: who holds which role, what approvals exist, how entries are posted and reversed.
- Technical system documentation: systems and versions in use, interfaces, data flows, storage locations, backup and recovery concept.
- Operating documentation: how the procedure is run and controlled day to day, including the history of every change to the procedure itself.
The last point is the decisive one: the documentation must be versioned. An auditor examining the 2022 financial year in 2026 wants to know what the procedure looked like in 2022 — not what it looks like today. An undated file with no change history does not answer that question.
2. Unveränderbarkeit and gap-free logging
Under § 146 (4) AO, a posting may not be altered in such a way that its original content can no longer be established — the requirement known as Unveränderbarkeit, or non-alterability. In practice this means corrections are made by reversal entry rather than by overwriting, and every change remains traceable with its time and its user.
The second requirement is the completeness of the number ranges. Sequential invoice and document numbers with no explained gaps are one of the first things a digital audit tests mechanically. A gap is not proof of an error — but it creates a need for explanation, and without an explanation it becomes an argument against the propriety of the books.
3. Data access: Z1, Z2 and Z3
§ 147 (6) AO grants the tax authority three forms of access in the course of an Außenprüfung, a field audit. In practice they are referred to as Z1, Z2 and Z3:
- Z1 — direct access: the auditor inspects the stored data in your own system, on a read-only basis, normally through a user account set up for the purpose.
- Z2 — indirect access: you evaluate the data mechanically according to the auditor's specifications and make the result available.
- Z3 — handover of data media: you hand over the tax-relevant data in a machine-evaluable format for the tax authorities to evaluate.
For your configuration this means two things: you need an auditor account with read rights that limits access to tax-relevant data, and you need an export that works without rework. An export tried out for the first time on the day of the audit is not a procedure but a risk.
4. Aufbewahrungsfristen: eight, ten and six years
Since the reduction brought in by the Viertes Bürokratieentlastungsgesetz, three different Aufbewahrungsfristen apply side by side in § 147 (3) AO. Confusing them is expensive in both directions, because deleting too early costs you the propriety of your books and retaining too long collides with the erasure obligation under the GDPR (DSGVO).
- Ten years: books and records, inventories, annual financial statements, management reports and opening balance sheets, together with the working instructions and organisational documents needed to understand them (§ 147 (1) no. 1 AO) — this includes your Verfahrensdokumentation.
- Eight years: accounting vouchers (§ 147 (1) no. 4 AO), since the Viertes Bürokratieentlastungsgesetz.
- Six years: the remaining documents, in particular commercial and business letters received and copies of commercial and business letters sent.
Each period begins at the end of the calendar year in which the last entry was made or the document arose. It also does not expire for as long as the documents remain relevant to a tax assessment that is not yet final.
