Records a small business should keep, and for how long

A small business should keep enough evidence to explain sales, purchases, expenses, tax filings, customer balances, supplier dues, payroll, bank movements and ownership of major assets. Good records support daily decisions, tax work, loan applications, payment disputes and recovery after a lost device.

Retention periods depend on the type of record and current law. Use this guide to organise categories, then confirm exact periods with official requirements and a qualified accountant or lawyer. When two rules apply, follow the longer verified requirement.

Keep source documents and ledger records

The ledger summarises activity; source documents support it. Keep:

  • Sales invoices, bills of supply and credit/debit notes
  • Purchase invoices and supplier statements
  • Expense bills and receipts
  • Customer udhar and payment ledger
  • Bank and UPI statements
  • Cash-closing records
  • Inventory counts and stock adjustments
  • Tax returns, challans and reconciliations
  • Payroll, attendance and employment records where applicable
  • Contracts, leases, licences and registrations
  • Loan agreements and repayment schedules
  • Asset purchase and disposal documents

A bank statement showing ₹12,000 paid does not explain whether it was rent, stock or loan repayment. The invoice or agreement provides the business meaning.

Keep cancelled and corrected documents with an audit trail. Deleting them can break invoice sequence and make totals harder to reconcile.

Organise by year, month and document type

Use one predictable structure. For example:

2026-27 / Purchases / 2026-07 / Supplier Name / Invoice Number

For paper, use labelled files and a monthly index. For digital records, use consistent filenames without unnecessary sensitive details. A file called 2026-07-18_supplierABC_INV1042.pdf is more useful than scan009.pdf.

Link the document reference to the ledger entry. If the application stores an attachment, make sure backups preserve required records for the correct authenticated owner. Do not include another cached account’s documents.

Avoid putting Aadhaar numbers, customer phone numbers or bank account numbers in filenames. File listings and backup logs can expose them.

Worked example: evidence for one purchase

A retailer buys ₹24,000 of stock on 12 July and pays:

  • ₹10,000 by bank on 12 July
  • ₹8,000 by UPI on 20 July
  • ₹6,000 by bank on 2 August

Records should include the supplier invoice, goods-received note or count, purchase ledger entry, three payment entries, bank/UPI references and the supplier balance between dates.

If the owner keeps only the final bank payment, July purchases appear too low and the supplier balance is invisible. If the owner records ₹24,000 as an expense and also records each payment as another expense, cost is doubled.

A clean file links invoice ABC-778 to purchase ₹24,000 and treats the later entries as settlement of that payable. At month end, the supplier statement confirms ₹6,000 remained due before 2 August.

This complete chain is useful for stock cost, tax review, cash planning and a lender’s verification.

Set retention periods deliberately

Create a schedule with record category, legal basis, start date, minimum period, responsible person and disposal method. Different laws may govern tax, companies, labour, contracts and financial records.

Some records should be retained longer than ordinary transaction files. Property, major asset, loan, litigation, ownership and unresolved tax documents may matter for the life of the asset or dispute plus a verified period.

Do not destroy records under audit, notice, dispute, investigation or legal hold even if the normal period has ended. Document the hold and release.

Protect privacy while retaining evidence

Retain only what the business needs or must keep. A sales invoice does not usually need a customer’s full ID-proof image. Optional ID proof should be consent-based, encrypted, local-only by default and deleted when no longer justified.

Restrict access. Counter staff may need invoices but not payroll or tax credentials. Use device locks, account authentication and owner-scoped cloud rules. Do not send a complete customer database to an AI tool for document sorting.

When sharing with an accountant or lender, provide the requested period and categories. Avoid a full backup if a sales summary and selected statements are enough.

Back up and test restoration

Follow a 3-2-1 idea where practical: three copies, on two types of storage, with one protected offsite or cloud copy. For a small business, that might be the active app/database, an encrypted periodic export and an owner-approved cloud backup.

A backup must be restorable. Test with non-production or controlled data. Verify owner identity, schema version and record counts. A restore should replace only the signed-in account’s records and leave other cached accounts untouched.

Protect encryption keys separately and securely. A backup that cannot be decrypted is not useful; an unencrypted backup containing customers and finances is a privacy risk.

Record when a backup completed and investigate failures. Do not assume a cloud icon proves every record was uploaded.

Reconcile before archiving

At month or year end:

  • Confirm invoice sequence
  • Match sales and purchase totals
  • Reconcile bank accounts
  • Review outstanding customers and suppliers
  • Count inventory
  • Resolve duplicate or missing entries
  • Export required reports
  • Lock or mark the period after review

Archiving unreconciled data preserves uncertainty. Add adjustment notes rather than changing history without explanation.

Keep the software version or export schema metadata where relevant. Future systems need context to import old files correctly.

Dispose securely

When a verified retention period ends and no hold applies, destroy records securely. Shred sensitive paper rather than placing it in open waste. Delete digital copies from active storage, backup cycles and shared folders according to a documented process.

Deletion must be scoped. A user deleting their account must not delete another account’s cached records. Cloud application data and authentication deletion should be confirmed separately.

Keep a disposal log for significant batches: category, period, authority, date and method. Do not list sensitive customer details in the log.

Practical takeaway

Maintain both the ledger and supporting documents, organised by year, month and type. Set a verified retention schedule, restrict access, back up securely, test restore and destroy records only after legal and business needs end.

Choose one recent month and trace ten entries from ledger to evidence and back. Fix naming and missing links before scanning years of paper. Continue with GST invoice requirements and moving from paper to digital to create a system that remains understandable over time.