Open table of contents
Key takeaways
- Preserve originals and document changes instead of silently replacing history.
- Link business event, document, booking, payment and decision where applicable.
- Keep process documentation aligned with actual practice.
- Test exportability and access before an audit or staff change exposes gaps.
The traceability chain
| Link | Question a reviewer should answer |
|---|---|
| Business event | What actually happened and when? |
| Source document | Which original evidence supports it? |
| Processing | How was information captured or transformed? |
| Booking/result | Where did the amounts and classification go? |
| Review/change | Who decided, changed or approved it, and why? |
| Export/archive | Can the record be retrieved in a usable form? |
Not every transaction needs a long narrative. Routine cases can rely on documented standard processes. Exceptions need enough context to explain why the standard did not apply.
Immutability does not forbid correction
A wrong record may be corrected. The control objective is that the original state and correction remain traceable rather than being overwritten without evidence. A correction should retain author, timestamp, reason, affected record and supporting document. If a filing or downstream report changed, that effect should also be recorded.
Practical control checklist
- Original documents are retained in their received form where required.
- Imports have identifiable source, period and run information.
- Duplicate and rejected records have a documented disposition.
- Manual changes record author, reason and date.
- Permissions and approvals reflect actual responsibilities.
- Process documentation describes the current workflow and systems.
- Exports are periodically tested for completeness and readability.
- Retention and deletion rules are defined and followed.
Example: corrected supplier invoice
An invoice for €1,190 is replaced by a corrected invoice for €1,130. A traceable process retains the original, records why it is no longer operative, links the replacement, shows the resulting booking correction and identifies the reviewer. Deleting the first file and overwriting the amount may produce the right final number but destroys the explanation of how it arose.
In a connected DeinHans case, the visible chain can be: original invoice → extracted facts → owner answer about business purpose → prepared proposal → accountant correction or approval → bank settlement → corrected invoice → revalidated proposal and handoff. Each arrow needs an identifiable source or decision. The useful audit trail is the ability to follow that chain; a log entry or a green status alone is not proof that the surrounding process is complete.
What software can and cannot do
Software can preserve versions, link evidence, log decisions, control access and produce exports. DeinHans can support a connected workflow between documents, transactions, questions and reviews. Compliance still depends on configuration, actual use, surrounding processes, retention and professional judgment. A feature label is not a GoBD certification.
Important: The BMF GoBD letter is administrative guidance with detailed requirements and context. Businesses should have their concrete process documentation and controls reviewed for their systems and obligations.
A proportionate documentation set
Start with a current system list, roles and permissions, source-to-booking flow, document-handling process, correction procedure, close and approval steps, backup/retention approach and export procedure. Add detail where risk and complexity justify it. The goal is not decorative documentation; it is an accurate operating description that another qualified person can follow.
Test the documentation against reality
Select a recent sales transaction, supplier invoice, payout and correction. Ask a person who did not process them to follow the documented path from source to result and export. Record every undocumented spreadsheet, manual rename, shared login or off-system approval they encounter. Update the process or remove the workaround; do not leave a knowingly fictional diagram.
Repeat the test after a system migration, new integration, organizational change or material provider update. Version the documentation with owner, approval date, systems covered and effective period.
Access, retention and export controls
Review who can upload, edit, approve, export and administer. Remove access after role changes and avoid shared credentials. Confirm that retention settings cover original documents, metadata, processing history and corrections for the applicable requirements. Deletion should follow an approved schedule and preserve legal holds where relevant.
Test exports before they are urgently needed. Verify completeness across dates and sources, readability, stable references and ability to connect records to evidence. Keep the test result and any remediation. An archive that exists but cannot be interpreted or reconciled is not a reliable audit trail.
Sources
Sources were checked on 21 July 2026. This article provides orientation and is not tax, legal, or accounting advice.
Related resources
Prepare your month with clear next steps
DeinHans structures evidence, payments, and questions so you and your accountant work from the same context.
DeinHans for businesses