<
```

Financial Document Retention Policy in India: GST, Accounting and Audit Records

How long should a business keep its invoices, accounting records, vendor documents, tax files and audit evidence?

Many organisations answer this question in one of two ways.

Some delete records as soon as they appear operationally unnecessary. Others retain every document indefinitely across physical archives, shared folders, employee laptops and disconnected applications.

Neither approach provides proper control.

Deleting records too early can create compliance and audit risk. Keeping everything forever increases storage costs, exposes sensitive information for longer than necessary and makes important documents harder to find.

A financial document retention policy gives the organisation a clear framework for deciding:

  • What records must be retained.
  • Why each record is being retained.
  • How long it should remain available.
  • Who can access it.
  • What happens when the retention period expires.
  • When destruction must be paused.

What Is a Financial Document Retention Policy?

A financial document retention policy is a formal set of rules governing the storage, preservation, archival and disposal of finance-related records.

It connects every document category with:

  • A responsible department.
  • A legal, regulatory, contractual or operational reason.
  • A retention trigger.
  • A minimum retention period.
  • An approved storage location.
  • Security and access requirements.
  • A disposal method.
  • Exceptions such as audits, litigation or investigations.

The policy should apply to both physical and digital records.

Scanning paper documents does not automatically create a compliant retention process. The digital copy must still be complete, authentic, searchable, protected and connected to an audit trail.

Why Indian Businesses Need a Retention Policy

Finance documents are often stored across:

  • ERP systems.
  • Accounting software.
  • Email inboxes.
  • Shared drives.
  • Vendor portals.
  • Physical files.
  • Branch offices.
  • Employee computers.
  • Scanned-document folders.
  • Tax-compliance platforms.

When responsibility is spread across these locations, the business may not know whether the official record is complete or where it can be retrieved.

A documented financial-records policy helps prevent:

  • Premature deletion.
  • Uncontrolled permanent storage.
  • Duplicate copies.
  • Missing audit evidence.
  • Inconsistent practices across branches.
  • Unauthorised access.
  • Destruction during a dispute or investigation.
  • Dependence on individual employees.
  • Delayed responses to tax notices and audits.

Important Retention Requirements in India

There is no single retention period that applies to every financial document.

The correct period depends on the organisation, document type, applicable legislation, regulatory status, ongoing proceedings and contractual obligations.

The following examples provide a starting point, but each business should validate its final retention schedule with qualified tax, legal and compliance professionals.

GST Accounts and Records

Section 36 of the CGST Act requires registered persons to retain relevant books of account and records for 72 months from the due date of the annual return for the corresponding year.

Where an appeal, revision, proceeding or investigation is continuing, the relevant records must be retained for one year after final disposal or for the normal statutory period, whichever is later.

GST records may include:

  • Tax invoices.
  • Bills of supply.
  • Credit notes.
  • Debit notes.
  • Delivery challans.
  • E-way bills.
  • Payment vouchers.
  • Refund vouchers.
  • Purchase and sales registers.
  • Input-tax-credit documentation.
  • GST returns.
  • Reconciliation files.
  • Supporting accounting records.

CBIC rules also permit records to be maintained electronically, require suitable backups and state that an account of audit trails and source-document interlinkages may need to be produced on demand.

This means retention should cover more than the final invoice PDF. The business should preserve the supporting trail needed to explain the transaction.

Companies Act Books and Financial Records

Section 128 of the Companies Act requires a company to preserve books of account relating to at least the eight financial years immediately preceding a financial year.

A company's retention schedule may therefore need to cover:

  • Books of account.
  • Relevant supporting papers.
  • Financial statements.
  • Journal and ledger records.
  • Bank reconciliations.
  • Fixed-asset information.
  • Supporting schedules.
  • Branch accounting records.
  • Board-approved financial information.

The eight-year requirement should be treated as a statutory baseline for applicable corporate records, not as a universal period for every document.

BFSI and KYC Records

Banks, NBFCs and other regulated entities may have additional sector-specific obligations.

The RBI's KYC Direction states that specified registration records should be maintained for five years after the business relationship has ended or the account has been closed, whichever is later.

BFSI organisations should map retention requirements separately for:

  • Customer KYC.
  • Loan applications.
  • Sanction documents.
  • Agreements.
  • Transaction records.
  • Collateral documents.
  • Consent records.
  • Regulatory submissions.
  • Complaints and grievance records.
  • Re-KYC history.

Kleeto's document management solution for banks and NBFCs is designed around loan files, KYC documents, collateral records and regulatory audit trails.

Suggested Financial Document Retention Categories

A retention schedule should organise records by purpose rather than placing every finance file under one generic category.

1. Accounting Records

Examples include:

  • General ledger.
  • Trial balance.
  • Journal entries.
  • Profit and loss statements.
  • Balance sheets.
  • Cash-flow statements.
  • Bank reconciliations.
  • Fixed-asset registers.
  • Cost-centre reports.
  • Management accounts.

2. Accounts Payable Records

Examples include:

  • Vendor invoices.
  • Purchase orders.
  • Goods receipt notes.
  • Service confirmations.
  • Approval records.
  • Payment vouchers.
  • Credit and debit notes.
  • Vendor correspondence.
  • Payment references.
  • Exception-resolution records.

Link this category to Kleeto's invoice processing and archival solution, which connects invoices with purchase orders, GRNs, tax records and payment evidence.

3. Accounts Receivable Records

Examples include:

  • Customer invoices.
  • Contracts.
  • Delivery evidence.
  • Credit notes.
  • Receipts.
  • Collection correspondence.
  • Dispute records.
  • Ageing reports.
  • Write-off approvals.

4. Tax and Statutory Records

Examples include:

  • GST returns.
  • GST reconciliations.
  • TDS and TCS records.
  • Tax challans.
  • Tax audit reports.
  • Income-tax returns.
  • Statutory registers.
  • Regulatory correspondence.
  • Notices and responses.
  • Supporting calculations.

5. Vendor Records

Examples include:

  • PAN and GST certificates.
  • Udyam documentation.
  • Bank proof.
  • Vendor agreements.
  • Approval records.
  • Licences.
  • Insurance certificates.
  • Vendor-master changes.
  • Due-diligence records.

6. Contracts and Financing Documents

Examples include:

  • Loan agreements.
  • Sanction letters.
  • Facility agreements.
  • Guarantees.
  • Security documents.
  • Lease agreements.
  • Vendor contracts.
  • Customer contracts.
  • Amendments and renewals.

7. Audit and Control Evidence

Examples include:

  • Internal-audit reports.
  • Statutory-audit evidence.
  • Control-testing records.
  • Management responses.
  • Reconciliation sign-offs.
  • Approval matrices.
  • Exception reports.
  • Remediation records.
  • Audit correspondence.

How to Create a Financial Document Retention Policy

Step 1: Build a Document Inventory

List the finance records created or received by every team, branch, entity and system.

Do not rely only on folder names. Interview the people performing the processes and identify the actual source documents, approvals, calculations and supporting evidence.

Step 2: Assign a Record Owner

Every document category should have a responsible owner.

Possible owners include:

  • Finance.
  • Tax.
  • Treasury.
  • Procurement.
  • Legal.
  • Compliance.
  • Company secretarial.
  • Internal audit.
  • Information technology.
  • Business operations.

The owner is responsible for defining the official record and ensuring the policy is followed.

Step 3: Identify the Retention Basis

For every category, record why it must be retained.

The basis may be:

  • Legislation.
  • Regulatory direction.
  • Contract.
  • Limitation or dispute period.
  • Audit requirement.
  • Internal-control requirement.
  • Operational need.
  • Historical or permanent corporate value.

Avoid assigning an arbitrary period simply because it is used for another document category.

Step 4: Define the Retention Trigger

A retention period needs a clear starting event.

Examples include:

  • End of the relevant financial year.
  • Due date of the annual return.
  • Date of final payment.
  • Contract expiry.
  • Vendor deactivation.
  • Loan closure.
  • End of the customer relationship.
  • Completion of an audit.
  • Final disposal of litigation or proceedings.

"Keep for six years" is incomplete unless the policy explains when those six years begin.

Step 5: Define the Official Copy

Multiple versions of the same document may exist in email, ERP, DMS and local folders.

The policy should identify:

  • Which version is the official record.
  • Where it must be stored.
  • Whether the original physical copy is required.
  • Whether a verified digital copy is sufficient.
  • Who can modify metadata.
  • Whether users may download local copies.

Step 6: Apply Security Controls

Financial records may contain personal information, banking information, tax identifiers, commercial pricing and confidential agreements.

Apply controls such as:

  • Role-based access.
  • Document-level permissions.
  • Encryption.
  • Multi-factor authentication.
  • Download restrictions.
  • Watermarking.
  • Version control.
  • Activity logs.
  • Secure external sharing.
  • Backup and restoration procedures.

Step 7: Introduce Legal and Audit Holds

Normal destruction must stop when records are relevant to:

  • Litigation.
  • Tax proceedings.
  • Regulatory investigations.
  • Internal investigations.
  • Fraud reviews.
  • Insurance claims.
  • Contract disputes.
  • Statutory or internal audits.

A legal-hold process should identify the affected records, suspend deletion and notify the responsible custodians.

Step 8: Automate Disposal

Once the applicable period ends and no hold applies, records should move through an approved disposal process.

Digital files may require secure deletion from:

  • Primary repositories.
  • Workflow systems.
  • Local folders.
  • Export locations.
  • Temporary storage.
  • Backups, according to the organisation's backup lifecycle.

Physical files should be destroyed through a controlled process with appropriate authorisation and destruction evidence.

What a Retention Schedule Should Contain

A practical retention schedule can include these columns:

Field Purpose
Document category Identifies the record family
Document examples Defines what belongs in the category
Record owner Assigns responsibility
Retention basis Records the legal or business reason
Retention trigger Defines when the period starts
Minimum period States how long records remain active
Storage location Identifies the official repository
Access group Defines who may view or manage records
Hold conditions Explains when destruction must stop
Disposal method Defines secure deletion or shredding
Review date Ensures the rule is periodically reassessed

Why Shared Drives Are Not Enough

A shared drive can store files, but it does not automatically manage document retention.

Common limitations include:

  • Users creating inconsistent folder structures.
  • Documents being renamed or overwritten.
  • No relationship between invoices and supporting evidence.
  • Limited audit history.
  • Manual deletion.
  • No legal-hold mechanism.
  • Access continuing after responsibilities change.
  • Difficulty enforcing different retention rules.

A proper document management system can connect metadata, permissions, workflow, audit trails and retention rules within one controlled repository.

Kleeto's DMS supports smart search, workflow automation, activity logs, retention enforcement and document-level access controls.

Common Financial-Record Retention Mistakes

Applying One Period to Every Document

Different records have different statutory, regulatory, contractual and operational requirements.

Starting the Period from the Upload Date

The correct trigger may be the financial year, annual-return date, contract closure or final disposal of a proceeding—not the date on which someone scanned the file.

Keeping Only the Final Document

An invoice without its approval, purchase order, GRN, payment proof and reconciliation history may not provide a complete audit trail.

Deleting Records During Proceedings

Documents relevant to litigation, investigations, tax reviews or audits may need to remain preserved beyond the normal schedule.

Retaining Everything Permanently

Permanent storage increases cost, security exposure and retrieval difficulty. Records should be retained for a defined reason.

Ignoring Physical Records

A digital policy that does not address paper archives, original agreements, title documents or branch files remains incomplete.

Failing to Test Retrieval

A retained record has limited value if it cannot be found quickly and exported with its supporting history.

How Kleeto Supports Financial Record Retention

Kleeto helps finance teams move from uncontrolled storage to policy-driven document management.

Businesses can use Kleeto to:

  • Digitise physical finance archives.
  • Index documents using structured metadata.
  • Connect invoices with supporting records.
  • Apply role-based permissions.
  • Maintain version and activity histories.
  • Configure retention rules by document type.
  • Suspend disposal where records are under review.
  • Track physical and digital records.
  • Retrieve audit evidence using vendor, date, entity, GSTIN or financial-year filters.
  • Securely dispose of eligible records after approval.

Explore Kleeto's finance document management solution for finance-specific document control, workflow and archival.

Financial institutions can also read Kleeto's guide to document management solutions for financial institutions.

Frequently Asked Questions

How long should GST records be retained in India?

Section 36 of the CGST Act requires relevant accounts and records to be retained for 72 months from the due date of the annual return for the corresponding year. A longer period may apply where an appeal, investigation or other proceeding remains active.

How long should companies keep books of account?

Section 128 of the Companies Act requires companies to preserve books of account for at least the eight immediately preceding financial years. Other documents may have different periods based on tax, regulatory, contractual or legal requirements.

Can financial documents be stored electronically?

Yes. GST rules permit electronic records, but businesses should maintain proper authentication, backups, audit trails and the ability to produce readable records when required.

Should every financial record be retained permanently?

No. Records should be retained according to a documented legal, regulatory, contractual or business requirement. Permanent retention should be reserved for records with a genuine long-term need.

What is a legal hold?

A legal hold is an instruction that temporarily suspends the normal deletion or destruction of records relevant to litigation, investigation, audit, tax proceedings or another dispute.

Who should own the document retention policy?

The policy normally requires joint ownership across finance, tax, legal, compliance, records management and information technology. Individual document categories should also have clearly assigned business owners.

How often should a retention policy be reviewed?

The policy should be reviewed periodically and whenever there is a material change in legislation, regulatory guidance, business systems, document processes or organisational structure.

Conclusion

A financial document retention policy is not simply a list of storage periods.

It is a governance framework connecting legal requirements, finance processes, document security, audit readiness and controlled disposal.

The strongest policies clearly define:

  • Which documents form the official record.
  • How long each record must be retained.
  • When the period starts.
  • Where the record is stored.
  • Who can access it.
  • When deletion must be suspended.
  • How disposal is authorised and evidenced.

With structured retention rules and a searchable document-management platform, finance teams can respond faster to audits, reduce uncontrolled storage and protect important financial evidence throughout its required lifecycle.