Arver
GoBD · §147 AO · TR-RESISCAN

GoBD audit-proof archiving.

Arver meets all five GoBD requirements technically: immutability, completeness, integrity (SHA-256), machine-readability and automatic procedural documentation — based on §147 AO, HGB and the BMF GoBD amendment July 2025. E-invoice intake for XRechnung and ZUGFeRD included. Hosted in Zurich, Switzerland.

GoBD-compliant

All five GoBD requirements — immutability, completeness, integrity, machine-readability, procedural documentation — are implemented technically.

XRechnung & ZUGFeRD

Incoming XRechnung and ZUGFeRD files are auto-detected, structurally parsed and stored audit-proof with the original byte.

Betriebsprüfung in minutes

One click generates a ZIP with originals, index.csv (DATEV), audit_log.json and the current procedural documentation for the auditor.

History

GoBD timeline — what changed in 2025

The Grundsätze zur ordnungsmäßigen Führung und Aufbewahrung von Büchern, Aufzeichnungen und Unterlagen in elektronischer Form (GoBD) have evolved over two decades. The BMF amendment of July 2025 explicitly addressed e-invoices (XRechnung and ZUGFeRD) and their retention obligations.

  1. 2003

    Initial GoBD published

    The BMF publishes the original principles for compliant electronic archiving. Establishes the framework that still applies today: immutability, completeness, integrity, machine-readability and procedural documentation.

  2. 2014

    GoBD revision

    Clarifies electronic storage rules. Explicitly permits cloud storage under certain conditions, requires the storage provider to be located in the EU/EEA or in a country with adequate data protection.

  3. 2019

    GoBD update

    Addresses mobile scanning, international standards, and clarifies the role of the procedural documentation. Establishes the basis for receiving e-invoices in the future.

  4. 2025

    BMF amendment July 2025

    Explicitly addresses e-invoices: businesses must be able to receive XRechnung and ZUGFeRD, and these must be stored audit-proof. Confirms that the existing five GoBD requirements apply in full to e-invoices. Establishes transition periods for B2B e-invoice mandates.

  5. 2028+

    EU e-invoice mandate rollout

    EU member states progressively require B2B e-invoicing per the EU e-invoice directive (2014/55/EU, EN 16931). Germany has required XRechnung for B2G (federal authorities) since 2020 and extends the obligation to B2B from 2025.

In detail

The five technical requirements in detail

The GoBD define five technical core requirements together with TR-RESISCAN (BSI technical guideline). Arver meets all five. Auditors check each one during a Betriebsprüfung — here is what they look for and how Arver satisfies it.

1

Immutability

Principle

Originals must not change after intake into the archive.

How Arver implements it

Arver stores every document with O_EXCL (write-once) at the storage layer. The file is created and never modified or deleted — not by users, not by administrators, not by the system itself. The only way to "change" a document is to upload a corrected version, which creates a new record with its own hash and audit entry.

What auditors check

Auditors will try to modify a document or check the underlying storage layer. With write-once storage, any modification attempt fails. The audit log records every access, so an unauthorized modification would be visible.

2

Completeness

Principle

All records must be captured. No entry may be missing.

How Arver implements it

Arver provides three intake paths that together cover all document sources: (1) e-invoice inbox (rechnung@your-firm.arver.app) for inbound e-invoices, (2) drag-and-drop upload for paper scans and other PDFs, (3) automatic capture of email attachments. The compliance dashboard surfaces any gaps — e.g. if no documents have been ingested for a week, the dashboard shows a warning.

What auditors check

Auditors cross-check your archive against external sources: bank statements (to confirm all payments have receipts), cash register logs (TSE), incoming mail logs. They look for missing periods or unusual gaps.

3

Integrity

Principle

Every document must be uniquely identifiable and any tampering must be detectable.

How Arver implements it

Arver computes a SHA-256 hash of every document on intake and stores it alongside the document. The audit log entries are chained: each entry contains the hash of the previous entry (prev_hash). Changing a single document or audit entry breaks the chain, and the verification process detects this immediately.

What auditors check

Auditors run a hash verification: they recompute SHA-256 of selected documents and compare with the stored hash. They verify the audit chain by recomputing all hashes. Any mismatch indicates tampering.

4

Machine-readability

Principle

Stored data must be machine-readable and processable by tax software.

How Arver implements it

Arver exports all archive contents as: (1) a DATEV-compatible CSV with the document number, date, gross amount, VAT rate and SHA-256 hash, (2) a JSON manifest of every document, (3) a machine-readable audit_log.json with the chained hashes, (4) an audit_chain_verification.json with the result of the chain check. The export ZIP is ready for direct processing by DATEV, BMD, Agenda or any other tax software.

What auditors check

Auditors may request data in machine-readable form to perform their own analysis. They check that the export can be opened in standard tools and that the data structure is consistent.

5

Procedural documentation

Principle

You must document your actual archiving process.

How Arver implements it

Arver auto-generates procedural documentation (Verfahrensdokumentation) based on real activity in your archive: which users uploaded what, which integrations are active, which retention periods apply to which documents. You add your own narrative (process description, responsibilities, exceptions) and have your tax advisor approve.

What auditors check

This is the most commonly flagged gap in Betriebsprüfungen. Auditors want to see a current, accurate description of your actual process — not a template from a software vendor. Generic templates that have not been adapted to your actual usage are routinely rejected.

Retention

Retention by document type

Retention periods are set in §147 AO and §257 HGB. Some documents are retained for 10 years, others for 6. The clock always starts at the end of the calendar year in which the last entry was made — so a document from 15 March 2024 must be kept at least until 31 December 2034.

Document typeRetentionLegal basisExamples
Incoming invoices (e-invoice)10 years§147 Abs. 3 AO, §257 Abs. 4 HGBXRechnung, ZUGFeRD, PDF
Outgoing invoices10 years§147 Abs. 3 AO, §257 Abs. 4 HGBOwn invoices, credit notes, cancellations
Cash register receipts10 years§147 Abs. 3 AOTSE-signed receipts (Kassenbons)
Bank statements10 years§147 Abs. 3 AOMonthly statements, account confirmations
Accounting records10 years§147 Abs. 3 AO, §257 Abs. 4 HGBJournal, general ledger, sub-ledgers
Payroll records10 years§147 Abs. 3 AO, §41 EStGPayroll register, payslips, Lohnsteueranmeldungen
Contracts10 years§257 Abs. 4 HGBLeases, supply contracts, employment contracts
Annual financial statements10 years§257 Abs. 4 HGBBalance sheet, P&L, appendix
Inventories10 years§257 Abs. 4 HGBAnnual physical inventory, stock lists
Procedural documentation10 yearsGoBD (BMF 2019)Process description of your archiving
Commercial letters6 years§257 Abs. 4 HGBOffers, order confirmations, general correspondence
Shipping documents6 years§257 Abs. 4 HGBDelivery notes, freight documents

Formats

XRechnung & ZUGFeRD — what they are

Germany has two standard e-invoice formats. Both are based on the European standard EN 16931. Arver supports both natively.

XRechnung

Pure XML, machine-readable, no PDF.

XRechnung is the official German e-invoice format for business-to-government (B2G) invoices since 2018 and for business-to-business (B2B) since 2025. It is a pure XML document based on the UN/CEFACT Cross-Industry Invoice (CII) D16B with the German CIUS (Core Invoice Usage Specification).

Standard
EN 16931 / UN/CEFACT CII D16B
German CIUS
urn:xeinkauf:kunft:rechnung.ubl:2
File format
XML only
Validation
KOFO-Kosit validator

Required fields

  • Invoice number and date
  • Seller and buyer identifiers (VAT ID, Leitweg-ID for B2G)
  • Line items with quantity, unit price, VAT rate
  • Net, VAT and gross totals
  • Payment terms and bank details (IBAN, BIC)
  • Delivery date and period

ZUGFeRD

Hybrid — PDF for humans, XML for machines.

ZUGFeRD (Zentraler User Guide des Forums elektronische Rechnung Deutschland) combines a human-readable PDF with an embedded XML. The receiver can read the PDF visually or process the XML automatically. France adopted a similar format called Factur-X, and the two are now compatible (ZUGFeRD 2.x = Factur-X).

Standard
EN 16931 / UN/CEFACT CII
File format
PDF + embedded XML
Profiles
MINIMUM, BASIC, COMFORT, EXTENDED
Compatibility
Factur-X (France)

Profiles

  • MINIMUMOnly the totals. Smallest file size.
  • BASIC WLBasic without lines. For simple invoices.
  • BASICBasic with line items.
  • COMFORTRecommended for most cases. Full data plus most allowances.
  • EXTENDEDMaximum data. All EN 16931 elements.

How Arver handles both formats

On intake Arver automatically detects the format (XRechnung by namespace, ZUGFeRD by embedded XML in the PDF) and parses the structured data. The metadata appear in your compliance dashboard — invoice number, date, seller, gross amount, VAT — without you having to open the file. The original byte (XML or hybrid PDF) is stored alongside, hash-locked and audit-tracked.

  • Auto-detect by file extension and MIME type
  • Parse mandatory fields (invoice number, date, seller, buyer, totals)
  • Store original byte with SHA-256 hash
  • Index metadata for search and compliance dashboard
  • Export as DATEV CSV, JSON manifest or audit ZIP

Audit-proof 101

What does audit-proof archiving mean?

Audit-proof means the property that records and documents cannot be modified after the business transaction is complete — neither intentionally nor accidentally. The legal basis is §147 AO (Abgabenordnung) together with the Principles for the Proper Management and Retention of Books, Records and Documents in Electronic Form (GoBD).

What must be archived audit-proof?

Per §147 (3) AO and §257 HGB, the following documents must be stored audit-proof:

  • Incoming and outgoing invoices (10 years)
  • Accounting records and receipts (10 years)
  • Cash register receipts (10 years)
  • Bank statements (10 years)
  • Payroll and salary statements (10 years)
  • Contracts and contract amendments (10 years)
  • Inventories and annual financial statements (10 years)
  • Procedural documentation per GoBD (10 years)

Business letters and other correspondence must be retained for 6 years (§257 (4) HGB). All retention periods start at the end of the calendar year in which the last entry was made.

The five GoBD requirements

The GoBD define, together with the BSI's TR-RESISCAN, five technical core requirements:

  1. 1
    Immutability
    Originals must not change after intake.
  2. 2
    Completeness
    All records must be captured — no document may be missing.
  3. 3
    Integrity
    SHA-256 hash per document, chained hashes in the audit log.
  4. 4
    Machine-readability
    DATEV CSV, JSON export, machine-readable audit log.
  5. 5
    Procedural documentation
    Process description of your actual usage.

Arver meets all five requirements technically. Organizational responsibility — including the correct process description — stays with the company.

Comparison

How is Arver different from paper filing and classic DMS?

Direct comparison of the three approaches to audit-proof archiving.

AspectArverPaperClassic
ArchitectureCloud-native, PostgreSQL, EU hosting in ZurichFiling cabinets in the office, often disorganisedFile server with Active Directory, often without versioning
StorageWrite-once (O_EXCL), SHA-256 per document, chained audit trailPhysical security, but no tamper detectionEditable by anyone with access — no integrity check
E-invoice intakePersonal inbox · XRechnung / ZUGFeRD / PDF auto-detectedManual scan and fileManual upload, often without OCR
Retention periods10 years automatic, documented per documentManual filing, often no expiry trackingManual, frequently wrong
Procedural documentationAuto-generated based on your actual usageManual Word template, often outdatedGeneric template, rarely adapted
Audit exportOne click: ZIP with originals + index.csv + audit_log.jsonHand over the filing cabinet to the auditorManual file gathering for the auditor
PriceFrom €19 / month (Solo plan)Printer, paper, cabinets, storage spaceFrom €125 (ecoDMS) or more (DocuWare)

FAQ

Questions about audit-proof archiving with Arver

The most common questions from German businesses about GoBD, §147 AO and our solution — answered in depth.

01What does audit-proof actually mean?+
Audit-proof means that a document can no longer be modified after intake into the archive — neither intentionally by a malicious employee nor accidentally by a technical fault. Technically this is achieved through a combination of three measures: (1) write-once storage that physically prevents overwriting a file; (2) SHA-256 hashing that gives each file a unique fingerprint, so later tampering becomes computationally visible; (3) chaining hashes in the audit log, so changing one entry breaks the entire chain. Arver implements all three without further configuration.
02What role does procedural documentation play in a Betriebsprüfung?+
Procedural documentation is the most commonly missing element at Betriebsprüfungen — DATEV repeatedly points out that many companies use software but cannot present the matching procedural documentation. It describes WHICH software you use, HOW you use it (where incoming documents land, who has access, which retention applies), and WHY (on which legal basis). Arver auto-generates procedural documentation based on your actual usage — you only need to add your process description and have it approved by your tax advisor.
03Which retention periods apply to which records?+
Retention periods are regulated in §147 (3) AO and §257 HGB: business letters and other correspondence 6 years, all accounting records (invoices, cash receipts, bank statements, payroll, contracts, annual financial statements, inventories, procedural documentation) 10 years. The period starts at the end of the calendar year in which the last entry was made. For a document dated 15 March 2024 the 10-year retention therefore ends on 31 December 2034. Arver manages these deadlines per document and notifies you 90 days before expiry so you can react in time.
04How does Arver detect an XRechnung?+
On intake Arver first checks the MIME type and file extension. For an .xml file or a PDF with embedded XML, the content is analysed with an XML parser. It recognises XRechnung (based on the urn:xeinkauf namespace) and ZUGFeRD (based on the urn:ferd namespace). From both formats Arver extracts the mandatory fields: invoice number, invoice date, gross amount, currency, seller, tax amount and VAT rate. These metadata are stored in the database together with the original byte and the SHA-256 hash. They appear immediately in the compliance dashboard, without you having to open the file.
05Why is an e-invoice not automatically audit-proof?+
An e-invoice (XRechnung / ZUGFeRD) is initially just an electronic document. Whether it is audit-proof depends on HOW you store it: an e-invoice in a mailbox is NOT audit-proof — it can be deleted, the mail server can crash, the mailbox can be archived. Even an XRechnung on a hard drive is not audit-proof — the drive can fail, the file can be edited. Audit-proofness only emerges from the combination of: (1) write-once storage, (2) hashing for integrity checks, (3) audit log with chained hashes, (4) automatic retention periods, (5) procedural documentation. Arver delivers all five.
06Can I use Arver even without an e-invoice mandate?+
Yes. The e-invoice mandate affects all VAT-liable companies in Germany since 2025 (B2B). But freelancers who only work B2C, or associations, also benefit from audit-proof archiving. If you want to prove your bookkeeping to the tax office, you need audit-proof storage regardless of whether your documents arrive as e-invoices or as PDFs. Arver processes both formats identically — XRechnung is additionally parsed structurally, PDFs are stored as originals with hash.
07How does the audit export work during a Betriebsprüfung?+
During a Betriebsprüfung you click "Audit export" in the dashboard. Arver generates a ZIP with the following contents: (1) /belege/ — all originals with the original byte you ingested; (2) /index.csv — a DATEV-compatible table with document number, date, gross amount, VAT rate and SHA-256 hash; (3) /audit_log.json — all actions with timestamp, actor and target, with chained hashes for tamper detection; (4) /audit_chain_verification.json — the result of a programmatic check of the audit chain; (5) /verfahrensdokumentation.md — the current procedural documentation as Markdown; (6) /README.txt — an explanation of the package for the auditor. The package is generated in under two minutes and contains everything an auditor needs for plausibility checks.
08What does Arver cost compared to DATEV or ecoDMS?+
DATEV interfaces for DMS functions cost between €125 (ecoDMS Business) and several thousand euros per year (DATEV DMS, DocuWare) depending on scope. Add training effort and IT operations. Arver starts at €19 / month for the Solo plan (1 user, 1 GB archive) and the Mittelstand plan is €79 / month (5 users, 20 GB archive). The Kanzlei plan for tax firms with multi-client capability is €249 / month. All plans include e-invoice intake, compliance dashboard, procedural documentation and audit export at no extra charge. No setup fee, no minimum term.
09Do I have to give my tax advisor access?+
On the Solo and Mittelstand plans you can grant your tax advisor read access — they see the same compliance dashboard and can download the audit export, but cannot modify or delete documents. On the Kanzlei plan multi-tenancy is built in: one tax firm manages all their clients from a single dashboard, with role-based access per client. Your tax firm can publish the procedural documentation directly in Arver, which significantly simplifies the annual compliance review.
10What happens if I cancel Arver?+
Within 7 days you receive a complete export: all documents in original format, an index.csv with all metadata, the full audit log as JSON, and your procedural documentation as Markdown. After 30 days your data is deleted — on request with written confirmation. You can also request the export at any time without cancelling, for example if you switch to another system. There is no lock-in trap — your data belongs to you.
11Is Arver suitable for Swiss companies?+
Arver is designed primarily for the EU market. The architecture supports multiple compliance engines that can be configured per country. For Swiss companies we recommend combining Arver (for audit-proof storage) with a Swiss tax solution — the two systems can be connected via the DATEV CSV interface. Note that Swiss retention obligations (10 years per Art. 958f OR) are materially comparable to §147 AO, but have different clock-start rules and disclosure duties. Arver can generate procedural documentation for Swiss clients too — contact us for the configuration.
12Who is liable if a document is lost?+
Our T&Cs govern availability. Arver guarantees 99.9% monthly API availability. Documents are stored in Zurich, Switzerland on two independent storage systems with daily backups. In the event of data loss on Arver's side you receive a flat-rate credit — the statutory responsibility for retaining your records remains with you as the business owner. We recommend keeping a second copy of your most important records on your local DATEV system if you want a second line of defence.

GoBD audit-ready in 5 minutes.

14 days free. No credit card. Setup in under 5 minutes — and you are prepared for the next Betriebsprüfung.