Audit-proofemail archiving
Audit-proof means an email is complete, unalterable and findable for years, and that every one of those properties can be proven. This page explains the criteria, their legal basis and what an archive has to do to meet them.
What does audit-proof mean?
Audit-proof means that records subject to retention are stored so that they are complete, unalterable, traceable and available throughout the retention period. For email that means every business-relevant message is archived automatically on receipt and on sending, cannot be altered or deleted afterwards, and stays searchable for six to ten years.
The term itself appears in no statute. It comes from records management practice and sums up what follows from several rules taken together: the retention duty in German commercial law, the Fiscal Code, and the GoBD, in which the tax authority describes the conditions under which it accepts books and records. Audit-proof archiving is therefore not a product property but a property of the procedure: it arises from technology, configuration and documentation together.
One practical consequence follows. No vendor can have a product "certified audit-proof", because there is no standard to certify against. What can be audited is always the procedure inside the company: the archive, its configuration and the process documentation around it. Buying the right tool and configuring it wrongly does not produce audit-proof archiving.
Three terms that get mixed up
Audit-proof
The umbrella term. It describes the properties of the store: complete, unalterable, traceable, available.
GoBD-compliant
The tax-law variant. It refers to the German tax authority principles and therefore to records relevant to bookkeeping.
Legally secure
Colloquial and the vaguest of the three. It usually means the same as audit-proof but promises more than software can deliver.
The six criteria
They follow from sections 239 and 257 of the Commercial Code, sections 146 and 147 of the Fiscal Code, and the GoBD. An archive either meets them or it does not; there is no partial credit.
- 01
Completeness
Every message subject to retention is captured, with no gaps and no selection by the user. That is why archiving happens at the handover point, not from the mailbox.
Sec. 239(2) HGB, Sec. 146 AO
- 02
Immutability
Once in the archive, a message cannot be altered, nor deleted before its retention period ends. Later corrections become a new entry that does not overwrite the old one.
Sec. 146(4) AO, GoBD para. 107 ff.
- 03
Traceability
A qualified third party must be able to review the procedure within reasonable time. That requires a log of every access and process documentation describing how archiving works.
Sec. 145 AO, GoBD para. 30 ff.
- 04
Availability and machine readability
Records must stay legible for the whole period and be machine-analysable. A pile of PDF files on a network share does not qualify.
Sec. 147(2) and (6) AO
- 05
Order and access control
The store is ordered and protected against unauthorised access. Who may search is defined; access to other people’s mailboxes is the exception and is logged.
Sec. 239(2) HGB, Art. 32 GDPR
- 06
Retention periods
Every message carries a period that is observed. Once it expires, the message is deleted, because keeping data beyond the legal duty requires its own justification.
Sec. 257 HGB, Sec. 147 AO, Art. 5 GDPR
Six, eight or ten years
Which period applies depends on the content of the message, not on its sender. Each period starts at the end of the calendar year in which the message was created.
| Period | Applies to | Basis |
|---|---|---|
| 6 years | Commercial and business letters, received and sent | Sec. 257(4) HGB, Sec. 147(3) AO |
| 8 years | Accounting vouchers including invoices | since 1 January 2025, Fourth Bureaucracy Relief Act |
| 10 years | Annual financial statements, opening balance sheets, inventories | Sec. 257(4) HGB |
Periods are only ever extended, never shortened: where several rules apply to one message, the longest wins. While proceedings are pending the period is suspended and the message stays in the archive beyond its nominal end.
Which email has to be kept for how longWhat an archive needs to do
The criteria are phrased in legal terms but met technically. Four building blocks carry the load.
Capture at the handover point
Archiving happens before a message reaches the mailbox, and likewise on sending. A user can no longer route a message past the archive, not even by deleting it immediately.
WORM storage
Under the write once read many principle every message is written once and only read thereafter. In standard storage Archive enforces this in software; in compliance storage an object lock is added that holds every object immutable until its period ends.
Chained audit log
Every entry in the audit trail is linked to the previous one by a hash chain whose head is anchored externally. Any interference with the store or with the log itself stays detectable and can be evidenced.
Retention classes and deletion runs
Rules per organisation, group or mailbox assign the period. The deletion run removes messages once it expires but refuses to delete before then. Archive data at rest is additionally encrypted.
How to archive audit-proof
From decision to an auditable store usually takes a few days. The longest part is not the technology but the process documentation.
- 1
Connect the capture point
With Microsoft 365 through a journal rule, with your own mail server through the handover point in the gateway. Both capture incoming and outgoing messages in full.
- 2
Define retention classes
The three standard periods cover the normal case. Exceptions for individual departments or mailboxes become their own rule with their own scope.
- 3
Govern access
Who searches their own mailbox, who may search organisation-wide and who may not search at all. Every access to other people’s messages is logged and can be evidenced later.
- 4
Document the procedure
Process documentation records what is archived, under which periods, who may access it and how deletion works. Without it, even the best store is open to challenge in an audit.
- 5
Import the existing store
Existing PST files and mailboxes are imported so that the retention duty is not met only from the day of go-live onwards.
Archive, backup, mailbox folder
Three things routinely confused in day-to-day work and legally very different.
| Question | Archive | Backup | Mailbox folder |
|---|---|---|---|
| Purpose | evidence over years | recovery after failure | day-to-day order |
| Unalterable | yes, until the period ends | no, it gets overwritten | no |
| Complete | yes, at the handover point | only the state at backup time | only what the user keeps |
| Meets the retention duty | yes | no | no |
A backup does not replace an archive, because it overwrites the store and knows nothing of the state between two backups. Conversely an archive does not replace a backup, because it is not built to return a mailbox to working order.
Backup and archiving comparedFrequently asked questions
Is audit-proof email archiving mandatory?+
For messages subject to retention, yes. Commercial and business letters must be retained under Sec. 257 HGB and Sec. 147 AO, whether they exist on paper or as email. The duty applies to every merchant and every company required to keep books, regardless of size.
What is the difference between audit-proof and GoBD-compliant?+
Audit-proof describes the properties of the store, GoBD-compliant its acceptance by the tax authority. The GoBD are an administrative instruction covering records relevant to bookkeeping; audit-proof is the wider term and includes records that are irrelevant for tax but must be kept under commercial law.
Is an audit-proof folder on a network share enough?+
No. A folder of exported files meets neither completeness, because selection rests with the user, nor immutability, because files can be overwritten, nor machine readability under Sec. 147(6) AO. A write-protected folder is not enough either, as long as an administrator can lift the protection.
Can a product be certified audit-proof?+
No, because there is no standard for it. What can be audited is the procedure inside the company, not the tool. Auditor opinions always refer to one specific installation with its configuration and process documentation, never to the software alone.
What happens once the retention period expires?+
The message is deleted. Keeping data beyond the statutory duty requires its own justification, because under Art. 5 GDPR personal data may only be stored as long as it is necessary for the purpose. A deletion run that acts once the period ends is therefore part of audit-proof archiving.
Do private emails from employees have to be archived too?+
That depends on whether private use is permitted. Where it is prohibited and the prohibition is enforced, all messages are business messages and are archived. Where it is permitted, a rule is needed to govern private messages, usually a works agreement.
Auditable archiving, without a project
Archive captures at the handover point, stores messages unalterably and logs every access. Hosted in Germany, or in your own data centre.
This page summarises the legal position in plain language and does not constitute legal or tax advice. The rules as amended from time to time prevail.