# Document management and audit-proof archiving in the mid-market

> Store documents so they can be found and stand up to audits: define the filing structure, implement retention periods, write the process documentation, order permissions and enable search.

URL: https://techport.ai/en/it-beratung/daten-und-information/dokumentenmanagement

---

1.  [IT Consulting](/en/it-beratung)/
2.  [Data and Information](/en/it-beratung/daten-und-information)/
3.  Documents and archiving

[Data and Information](/en/it-beratung/daten-und-information)

# Documents and archiving

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

Documents in mid-sized companies sit in more places than data: on network drives, in mailboxes, in a cloud service, in the ERP, in paper folders and on individual machines. As long as the people who know where things are remain in the company, that works. It stops working during a tax audit, in a legal dispute, during a certification, or when an AI assistant is meant to draw on that body of material.

Document management is a question of order first and of software second. The best solution fails on a filing structure nobody understands.

## How you notice it

*   The same file exists in several versions in different places and none is recognisably the valid one.
*   Assembling documents for an audit takes days.
*   Nobody knows which records have to be kept for how long and which may be deleted.
*   Important documents sit in one person's mailbox.

## Why this happens

Filing structures grow along departments and projects, because that matches the perspective of the person filing. Whoever searches later searches along transactions: for a customer, an order, a machine. Those two views do not match, and without content search only the folder path remains. On top of that, retention periods are rarely known, so in case of doubt everything is kept, which makes searching harder still.

## How we go about it

1.  **Clarify the inventory and the obligations.** We record which types of document exist, where they sit and which of them are subject to retention obligations. That clarification happens together with your tax advisers and, where necessary, with your lawyers.
2.  **Build the structure around transactions.** We create filing that follows the business transaction rather than the organisation chart, with few levels, consistent naming and search across content rather than across paths.
3.  **Implement retention and deletion.** We implement retention periods technically, with unalterable storage for records that require it and a defined deletion procedure for everything that may or must be deleted.
4.  **Document the procedure.** We produce the process documentation describing how records are created, captured, processed and retained. In an audit it is the evidence that your procedure is proper.

## What you gain

*   Records findable in minutes rather than days.
*   Evidence that holds up in audits.
*   A basis on which search and AI assistants return sensible results.

## From our projects

The most common mistake when introducing a document system is carrying the old folder structure into the new tool. The problem moves along with it and the only difference is the licence fee. We therefore start with five typical searches from daily work and test the planned structure against them. The second recurring finding concerns email mailboxes: in many companies they are effectively the archive for business correspondence without anyone having decided that. That is both a retention and an availability risk, because access is tied to one person.

## Good to know

Retention periods in Germany follow from commercial and tax law. Since the Fourth Bureaucracy Relief Act, accounting vouchers and invoices generally have to be kept for eight years, commercial books, inventories, annual accounts and the associated work instructions and organisational documents for ten years, other business letters for six years. Electronic records must remain legible and machine readable throughout the period, and the path from receipt to archiving must be traceable. That is precisely what the process documentation delivers. It is missing in many mid-sized companies and is regularly requested during audits.

## Häufige Fragen

May we destroy paper records after scanning them?

In principle yes, provided the substitute scanning is carried out properly and described in the process documentation, including procedure, controls and permissions. Exceptions apply to individual records where the original is legally required. That boundary should be settled in writing with your tax advisers before you destroy paper.

Do we need a dedicated document system?

Not necessarily. For many companies the first step is orderly filing with search and managed permissions. A dedicated system pays off if you have high document volumes, if approval workflows are to be represented, or if you need unalterable archiving with evidence.

## Let us talk about Documents and archiving

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our software](/en/loesungen)

## Further reading

[IT Governance and ComplianceImplementing e-invoicingWhat the e-invoicing obligation means technically: secure receipt, choose formats, prepare sending, settle archiving and plan for the 2027 and 2028 deadlines in time.](/en/it-beratung/it-governance-und-recht/e-rechnung)[Data and InformationCreating the data basis for AIWhy AI initiatives fail on data and what helps: identify knowledge sources, remove duplicates and outdated versions, mirror permissions, keep content current and make answers verifiable.](/en/it-beratung/daten-und-information/daten-fuer-ki)[IT Governance and ComplianceIT obligations at a glanceWhich IT related obligations affect your company, who owns them, which evidence is needed and how a register of obligations gets you prepared for every audit.](/en/it-beratung/it-governance-und-recht/it-compliance)[KnowledgeIT regulatory radarWhat applies, what is coming, what to do now.](/en/it-beratung/regulatorik-radar)[KnowledgeIT glossaryTerms from IT, software and security, briefly explained.](/en/it-beratung/glossar)

Back to the field [Data and Information](/en/it-beratung/daten-und-information)

## Sources

*   [Section 147 AO, retention of records (in German)](https://www.gesetze-im-internet.de/ao_1977/__147.html)
*   [Section 257 HGB, retention of documents (in German)](https://www.gesetze-im-internet.de/hgb/__257.html)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
