Operations
Record Keeping — What to Keep and How Long
Good record keeping is a legal requirement, a tax compliance tool, a management instrument, and a business protection mechanism — all at once. SARS can audit any return and request the supporting records. Courts and tribunals can compel production of documents in disputes. The CCMA expects employment records to be available immediately when a matter is referred. POPIA imposes obligations on how personal information is retained and destroyed. The records you keep now are the evidence you will need later. Later is always sooner than you expect.
The most common record keeping mistake in South African small businesses is not carelessness — it is treating record keeping as a single requirement governed by a single rule. There is no single rule. Multiple pieces of legislation impose different retention periods for different record types, and the correct approach is to apply the longest applicable period to each category. Destroying a record that SARS or the Companies Act still requires, even if you believed the purpose for keeping it was spent, is a compliance failure with real consequences.
The Legal Framework: Multiple Laws, One Rule
Four pieces of legislation set the primary retention requirements for most South African businesses:
Tax Administration Act (TAA) requires records that enable a person to satisfy their tax obligations and enable SARS to verify compliance. The general retention period is five years from the date of submission of the relevant tax return — not five years from the end of the tax period. If you filed late, your retention period starts from the actual filing date, extending it further.
Companies Act 71 of 2008 requires companies to keep records, documents, accounts, and books for a minimum of seven years, or longer where other public regulation requires it. This seven-year period applies broadly to company records, financial records, and anything the company is required to maintain under the Act.
Protection of Personal Information Act (POPIA) requires that personal information not be retained longer than necessary for the purpose for which it was collected, unless another law requires longer retention. POPIA yields to other legislation — if SARS requires five years, POPIA agrees. If the Companies Act requires seven years, POPIA steps back. The key point is that POPIA also requires the responsible party to destroy or delete personal information once the retention obligation expires, in a manner that prevents reconstruction. Putting a document in the recycling bin does not satisfy this requirement.
Basic Conditions of Employment Act (BCEA) requires certain employment records to be retained for three years after the termination of employment or the date of the last entry, whichever is later.
The practical rule: apply the longest period. When a record falls under multiple legislative requirements, retain it for the longest required period. A payslip contains personal information (POPIA), is an employment record (BCEA — three years), and supports a tax return (TAA — five years). Keep it for five years from the date the relevant tax return was submitted.
When SARS Can Go Back Further Than Five Years
The five-year general rule is not absolute. SARS has the power to reopen assessments and demand records beyond the standard period in specific circumstances:
Fraud, misrepresentation, or material non-disclosure. SARS can reopen an assessment indefinitely where fraud, misrepresentation, or non-disclosure of a material fact is alleged. SARS bears the burden of proving these circumstances, but the practical implication is that records supporting any return where these risks exist should be kept for as long as the business operates.
Active audits and investigations. If SARS notifies you of an audit or investigation, all records relevant to that audit must be kept until the process is fully concluded — including any objection, appeal, or court proceedings that follow. This can extend the effective retention period by years.
Capital gains tax. A taxpayer must be able to prove the base cost of any asset for capital gains tax purposes. The base cost is established by records of the original purchase and all subsequent qualifying expenditure. For a property purchased in 2005 and sold in 2030, the records establishing the base cost must be kept from 2005 until the CGT return for the year of sale is submitted and the five-year post-submission period has elapsed. Capital gains records can therefore need to be retained for several decades.
Financial Records: What to Keep and For How Long
Tax Records (Five Years from Submission Date, Seven Years Under Companies Act)
Apply seven years as the standard for all financial records unless a specific item has a longer requirement.
Every return filed with SARS — income tax (ITR14), provisional tax (IRP6), VAT (VAT201), PAYE (EMP201, EMP501), and any other return — must be retained. Keep the returns themselves permanently. Keep the supporting records for at least seven years from the date of the relevant return.
Supporting records for tax purposes include: bank statements, all invoices issued to clients, all supplier invoices and receipts, cash sales records, expense receipts, loan agreements and repayment schedules, asset purchase records (for depreciation and CGT purposes), investment records, and any calculations supporting the figures in the returns.
VAT Records (Seven Years)
VAT-registered businesses have additional record keeping obligations. Every tax invoice issued must be retained — a tax invoice must include the supplier's name and VAT number, the recipient's name and address, a unique serial number, the date of issue, a description of the goods or services, the quantity, the total price, and the VAT amount. An invoice that does not contain all required fields is not a valid tax invoice and cannot support an input tax claim. SARS will disallow the input deduction if the invoice is invalid.
Keep records of all zero-rated and exempt supplies separately from standard-rated supplies. Keep a VAT summary for each return period reconciling the output tax declared and input tax claimed to the underlying invoices.
Bank Records (Seven Years)
All business bank statements must be retained. Bank statements are primary supporting documentation for virtually every figure in a tax return and every line in a financial statement. Ensure digital bank statements are downloaded and stored — do not rely on a bank's online portal to retain statements indefinitely. Accounts closed more than two or three years ago typically have limited online history available.
Financial Statements (Permanently)
Annual financial statements — income statement, balance sheet, cash flow statement, and notes — should be kept permanently. They are the primary record of the business's financial history and are required for bank applications, tender bids, potential acquisitions, and dispute resolution at any point in the business's life or after it closes.
Capital Expenditure Records (Until CGT Return is Filed Plus Seven Years)
Records establishing the cost, date of acquisition, and nature of every capital asset must be retained for as long as the asset is held and for seven years after the disposal and relevant tax return is filed. For any asset that might be subject to capital gains tax, this is not negotiable.
Employment Records: What to Keep and For How Long
Contracts and Particulars of Employment (Three Years After Termination, Practically Five to Seven)
Every employee must receive written particulars of employment under the BCEA. These must be retained for at least three years after the employment relationship ends. Retain them for five years to align with the tax retention period, since employment costs appear in your financial records.
Keep all variations, amendments, and addenda to employment contracts alongside the original.
Payroll Records (Five Years from Tax Return Submission)
Payroll records — salary calculations, payslips, deduction records — support both PAYE returns and income tax returns. The TAA five-year rule applies. The payroll records must be sufficient to allow SARS to verify that PAYE was correctly calculated and remitted for every employee in every period.
EMP201 submissions (monthly PAYE declarations) and EMP501 reconciliations (annual employer reconciliation) must be retained for five years from the date of submission.
IRP5 and IT3(a) certificates issued to employees are the primary PAYE compliance evidence. Retain them for five years from the date the relevant EMP501 was submitted.
Disciplinary and Performance Records (Three Years After Termination, Practically Longer)
Disciplinary records — warning letters, hearing notes, outcomes — support the employer's position if a dismissed employee refers a matter to the CCMA or Labour Court. CCMA referral deadlines are 30 days from dismissal, but cases can take 18 to 24 months to resolve, and Labour Court reviews can extend this further. Keep disciplinary records for at least three years after termination — longer if a dispute is still in progress.
Performance improvement plans, poor performance hearings, and related documents follow the same logic. If a performance case might end in dismissal, maintain the full paper trail from the start.
Leave Records (Three Years After Termination)
Annual leave balances, sick leave usage, and family responsibility leave records must support any dispute about leave entitlement or payout on termination. The BCEA requires three years. Given that these records often overlap with payroll records, five years is the practical standard.
UIF Records (Five Years)
Employer UIF declarations and contribution records must be retained for five years. In the event of an employee claiming UIF benefits, the Fund may request confirmation of employment and contribution history.
Employment Equity Records (Three Years)
Employment equity plans, workforce analyses, and annual EEA reports must be retained for three years. For designated employers, the Department of Employment and Labour may audit EE compliance at any time.
Company and Statutory Records: What to Keep and For How Long
Permanent Records
Certain records must be retained for as long as the company exists — or indefinitely, which in practice means permanently:
The company's Memorandum of Incorporation (MOI) and any amendments. The company's registration certificate (COR14.3). The share register and records of all share transfers. Minutes of all board meetings and shareholder meetings. Resolutions passed by the board and shareholders. The beneficial ownership register required under the Companies Amendment Act 2024. Annual financial statements.
These records define the legal existence and governance history of the company. They must be available on demand from CIPC, SARS, courts, or shareholders. Losing them is not a legitimate excuse for non-compliance.
Annual Returns and CIPC Records (Seven Years)
Records of all annual returns filed with CIPC, including the financial statements submitted with them, must be retained for seven years.
Contracts (Duration of Contract Plus Seven Years)
Every material contract — client agreements, supplier agreements, lease agreements, employment contracts, shareholder agreements, loan agreements — should be retained for the duration of the contract plus at least seven years after its expiry or termination. Disputes arising from a contract can emerge long after the contract ends. Prescription periods for contractual claims are generally three years from when the claimant became aware of the claim, but can be longer in specific circumstances. Seven years post-contract covers the realistic window.
POPIA: The Records You Must Destroy
POPIA creates an obligation that most businesses ignore: you must destroy or delete personal information once you are no longer authorised to retain it, in a manner that prevents its reconstruction.
This means that when the retention period for a record containing personal information expires, you cannot simply archive it indefinitely. You must delete it (from all locations — cloud storage, email, hard drive, and backup) or destroy it (physical documents must be shredded, not placed in a recycling bin).
The practical challenge is that personal information appears in records that overlap different retention periods — a payslip contains personal information (POPIA), employment data (BCEA), and tax data (TAA). The approach is:
Retain for the longest applicable legal period. When that period expires, destroy in a POPIA-compliant manner. Document the destruction — date, method, and category of records destroyed. This documentation itself should be retained.
POPIA fines reach R10 million and responsible individuals can face criminal liability for serious breaches. Retaining personal information beyond its authorised period and failing to destroy it appropriately are both compliance failures.
Electronic Records: The SA-Specific Requirements
The ECTA (Electronic Communications and Transactions Act) and SARS public notice 787 govern electronic record keeping. The key requirements:
Electronic records must be kept in the format in which they were generated, sent, or received, or in a format that accurately depicts that information. A screenshot of an invoice is not equivalent to the original PDF. The origin, destination, and date/time of electronic records must be determinable.
Electronic records must generally be stored in South Africa. A senior SARS official may authorise storage outside South Africa, but this requires formal approval. Cloud storage on offshore servers — AWS US-East, Google Cloud US, and similar — may not satisfy this requirement. Many popular cloud services operate South African data centres, or can be configured to store data in South Africa. Confirm this with your cloud provider before relying on it.
Electronic records must be readily accessible and producible on SARS request within the period specified in any audit notice. Records stored in a format that is no longer readable — an obsolete software format, for example — fail this test. Ensure your accounting software exports records in accessible formats (PDF, CSV) that will remain readable over the retention period.
The Practical System
The record keeping burden is only as heavy as the system you build. A business that captures records as they arise, stores them in a consistent structure, and reviews the system annually will find compliance almost effortless. A business that reconciles records once a year under deadline pressure will always be exposed.
Accounting software is the core. Xero, Sage Business Cloud, and QuickBooks all store digital copies of invoices and reconcile automatically with your bank. Every supplier invoice uploaded into the system is stored, searchable, and accessible. Every client invoice issued through the system is retained. These systems produce audit trails that satisfy SARS requirements.
A document management folder structure — physical or digital — should be set up from day one, with consistent categories:
- Company statutory: MOI, registration certificate, share register, board minutes, shareholder resolutions, beneficial ownership register
- Tax: returns by tax year and tax type, supporting calculations
- Financial: bank statements by month, annual financial statements by year
- Employment: one subfolder per employee with contract, payslips, leave records, disciplinary records
- Contracts: one subfolder per material contract with execution copy and all amendments
- Insurance: current policies and renewal schedules
Cloud storage provides the backup and accessibility that physical filing cannot. OneDrive, Google Drive, and Dropbox all offer South African data storage options. A business that relies solely on physical files or a single computer risks losing its records entirely in a fire, flood, or hardware failure. Back up records to at least two locations — one of which is offsite.
The annual records review. At each financial year-end, review your records inventory. Identify anything whose retention period has expired. Destroy POPIA-protected records in a compliant manner. Document the destruction. Archive records that are moving from active to long-term retention. This takes half a day if the system is maintained and several painful days if it is not.
Consequences of Inadequate Records
SARS audit. A SARS auditor who requests records and finds them unavailable, incomplete, or inconsistent is authorised to raise a revised assessment based on their best estimate. This assessment may be higher than your actual tax liability and the burden of proof to dispute it falls on you. Without records, you cannot dispute it effectively.
SARS penalties. The Tax Administration Act provides for penalties for failure to keep records as required — separate from any tax penalties arising from an audit finding. These penalties can be substantial and are imposed even where the underlying tax liability is correctly reported.
CCMA disputes. An employer who cannot produce a signed employment contract, a written notice of a disciplinary hearing, a copy of the warning letter, or payslips for the period in question is in a fundamentally weakened position at the CCMA. Commissioners draw adverse inferences from missing documentation.
Contractual disputes. A supplier who claims you owe them money, a client who denies agreeing to your terms, a landlord who disputes what was included in the lease — all of these are resolved by reference to documents. Without them, the dispute becomes a credibility contest you may lose regardless of the underlying facts.
POPIA enforcement. The Information Regulator has powers to conduct compliance investigations, issue enforcement notices, and impose fines. Businesses that cannot demonstrate a records management framework — including a process for destroying personal information when required — are exposed to enforcement action.
Common Mistakes Worth Avoiding
Applying the five-year rule to all records. The Companies Act requires seven years for most company records. Capital gains records may need to be kept for decades. Apply the longest applicable period.
Counting five years from the end of the tax period rather than the submission date. If you filed your return six months late, your retention period starts from the actual filing date.
Not retaining invalid invoices. An invoice that does not meet VAT requirements cannot support an input tax claim, but it should still be retained as evidence of what was received. Destroying it removes any record of the transaction.
Using a recycling bin or delete key to destroy personal information. POPIA requires destruction in a manner that prevents reconstruction. Documents must be shredded; digital records must be deleted from all locations including backups.
Relying on a bank's online portal for historic statements. Online portals typically retain statements for two to five years. Download statements regularly and store them in your own system.
Storing electronic records offshore without SARS authorisation. Cloud storage on servers outside South Africa requires a senior SARS official's written approval. Confirm your cloud provider's data residency settings.
Not backing up records offsite. A fire, flood, or ransomware attack that destroys your only copy of business records creates a compliance problem at exactly the moment you can least afford it. Two locations, one offsite.
This article provides general information about record keeping requirements under South African law. Retention obligations depend on the specific nature of the records and the legislation applicable to your business. Confirm your requirements with a qualified accountant or tax practitioner. Nothing in this article constitutes legal or tax advice.
This article provides general information about South African business law and regulation. It is not legal, tax, or financial advice. Laws and regulations change — verify current requirements with a qualified professional or directly with the relevant authority before making decisions.
Related articles
