XTKGet started
Practice tips

16 min read

How long must accountants keep client records?

By The XTK team · Product

A bar chart of statutory record-retention periods — New Zealand 7 tax years, Canada 6, the United Kingdom 5, Australia 5, the United States 3 — each with a paler extension for its notable longer period, above a separate AML/CDD bar of 5 to 7 years that starts only when the client leaves

Five to seven years, in most of the markets a Xero practice works in. New Zealand's Inland Revenue says seven tax years. The Australian Taxation Office says five. The Canada Revenue Agency says six. HMRC counts from a filing deadline rather than a year end. And money-laundering rules in both the United Kingdom and Australia do not start counting until the client leaves.

So the useful answer is not a number. It is a small set of clocks, each started by a different event, applied to different documents. Get that far and you have a policy — but not yet the ability to comply with it, because a seven-year period outlives most software subscriptions, most of the staff who created the files, and several product decisions by your vendors. A practice can hold an impeccable policy and still be unable to produce a 2021 engagement letter, because the tool it lived in was cancelled in 2024. Duration is a policy question. Custody is an architecture question — which is why where your client documents live decides whether you can comply with the policy you wrote — and it is the half that fails quietly.

Whose records are they? Three obligations, three clocks

Three separate duties get collapsed into one figure, and that collapse is how a practice ends up over-retaining and under-retaining in the same filing cabinet.

  1. Your client's own statutory records — the company's or the taxpayer's duty to keep its books, which you may be holding on their behalf. The period belongs to them, but the files are in your Drive, so in practice it becomes yours to honour.
  2. Your engagement file and working papers — the practice's own duty, set less by tax law than by your professional body and by how long you could be sued. In England and Wales, section 5 of the Limitation Act 1980 gives six years from the date the cause of action accrued for a claim founded on simple contract, which is why professional indemnity insurers and retention policies tend to converge on six or seven.
  3. Your client due diligence evidence — money-laundering records, on a clock that does not start when the work was done but when the relationship ends. This is the one most commonly filed in the wrong year folder, because it belongs to the client rather than to any engagement, and because it is gathered during onboarding, years before the clock that governs it starts running.

The commonest response is a flat “seven years for everything”, and it is wrong in both directions at once: too short for a client you onboarded in 2019 and disengaged last month, and too long for personal data you have had no reason to hold since 2020.

How long must you keep client records?

Five jurisdictions, five headline periods, and in every one of them the headline is the general rule rather than the whole rule. Each figure below comes from the revenue authority's own guidance or from the statute itself.

JurisdictionMost recordsNotable longer periodSet by
United Kingdom5 years after filingPublic companies, 6 yearsHMRC
Australia5 yearsCompanies, 7 yearsATO
New Zealand7 tax years10 years, if extendedInland Revenue
United States3 years6 years, income understatedIRS
Canada6 yearsLonger if the CRA directsCRA
Each period read from the revenue authority's or the regulator's own guidance, or from the statute itself, on 10 August 2026. Periods depend on entity type and document class, and they change — verify anything you intend to rely on.

Every row hides something a summary would flatten.

  • The United Kingdom runs two clocks and neither starts at your year end. HMRC tells the self-employed to keep records at least five years after the 31 January submission deadline of the relevant tax year — and 15 months after the date of submission instead, where a return goes in more than four years late. Separately, section 388(4) of the Companies Act 2006 requires accounting records to be preserved for three years from the date they are made by a private company, and six by a public one — a distinction almost every retention template ignores.
  • Australia's five years is measured from the later of two events. The ATO counts from when you prepared or obtained the record, or completed the transactions it relates to, whichever is later — and for depreciating and capital gains tax assets you keep the record for as long as the asset is held, then five years after disposal, which for a commercial property can be decades. Company financial records run longer again: section 286 of the Corporations Act 2001 obliges a company to keep them, and ASIC puts the period at at least seven years after the transactions covered are completed. The ATO's own page tells readers to check ASIC's seven years alongside its five.
  • New Zealand is the strictest of the five and adds two conditions the others do not. Inland Revenue requires records, including electronic ones, to be kept for at least seven tax years, in English or Māori unless it approves another language, and — the clause that matters for any cloud-based practice — if you store records offshore, including in cloud computing, either you or your provider needs Inland Revenue's approval. The Commissioner can extend the seven years to ten.
  • The United States three-year figure is a period of limitations, not a retention policy. The IRS sets three years generally, six where more than 25% of gross income is unreported, seven for a claim on worthless securities or a bad debt deduction, four years for employment tax records, and indefinitely where no return was filed or a fraudulent one was. State boards of accountancy then add their own periods for the firm's own files, so there is no single national answer for a US practice.
  • Canada's six years runs from the end of the last tax year the records relate to, not from the date of the document — and from the filing date where a return is filed late. The CRA can require longer, and it is the one authority here with a formal route to destroying records early: you ask permission rather than deciding for yourself.

For the practice's own papers rather than the client's, the ICAEW's document retention helpsheet gives the profession's most quotable default: firms may destroy correspondence and other papers more than seven years old, except those they think may be of continuing significance, with audit working papers kept at least six years from the date of the auditor's report. Note the shape of it — a default with a judgement call attached, which means somebody has to exercise the judgement rather than the software.

When does the clock actually start?

Rarely on the date printed on the document, which is why filing by document date makes a purge unauditable. Across the five jurisdictions above the start event is the filing deadline, the date of submission, the date the record was made or obtained, the end of the last tax year it relates to, or the completion of the transaction — and money-laundering rules add the end of the business relationship, asset rules the date of disposal.

Which gives the single most useful filing rule in this article: file by the year the clock starts, not the year the document was created. A 2026 engagement letter for a client whose relationship ends in 2031 is a 2031 record for due diligence purposes, and no amount of policy will make that obvious to whoever runs the purge in 2036 unless the folder says so.

The clock that starts when the client leaves

Client due diligence records are the ones practices file wrongly, because they are the only category whose period is triggered by disengagement. Regulation 40 of the United Kingdom's Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 sets five years beginning on the date the relevant person knows, or has reasonable grounds to believe, that the transaction is complete or that the business relationship has come to an end. It also does something none of the tax rules do: it caps retention, at ten years for records of transactions within a continuing relationship. ICAEW reads it the same way, and extends it to non-engagement documents about the relationship and its monitoring.

Australian practices have a newer version of the same question. From 1 July 2026, accountants providing designated services came inside the Anti-Money Laundering and Counter-Terrorism Financing regime as reporting entities — the reform generally called tranche 2 — and AUSTRAC's record-keeping obligations run to seven years, with customer identification records kept seven years after you stop providing designated services. Whether your practice is caught depends on which services you provide, which is a question for your own advice — but if the answer is yes, your identification records now outlast your tax workpapers. Be precise about what that record is. The OAIC's privacy guidance for AML/CTF reporting entities says that from 1 July 2026 for tranche 2 entities the Act does not require you to keep scanned copies or photocopies of identity documents themselves: what you keep is the details you relied on, the type of document, what you did to verify the customer and the outcome. The same guidance brings practices under the $3 million small-business threshold inside the Privacy Act for this work. So if you are still collecting ID by email, the copy you did not need to keep is sitting in an inbox, while the record you do need has no folder with a period attached to it.

New Zealand, Canada and the United States run their own regimes, with their own triggers and periods — do not port a number across a border. The structural point does travel: this is the one category whose clock starts on the day you stop working for someone, which is exactly the day a practice is most likely to tidy up.

Is there an upper limit? Yes, and it is easier to miss

Retention has a ceiling as well as a floor, and the ceiling is data protection. Article 5(1)(e) of the UK GDPR requires personal data to be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed”. Keeping a client's identity documents indefinitely because storage is cheap is not caution. It is a second compliance problem, taken on to avoid thinking about the first.

Australia states the duty as an action rather than a principle. Under Australian Privacy Principle 11.2, an entity must take such steps as are reasonable in the circumstances to destroy personal information or ensure it is de-identified once it is no longer needed — unless Australian law or a court order requires it to be retained. Read those halves together and the floor and ceiling stop competing: the statutory period is precisely the answer to why you still hold the file, and the day it expires is the day that answer runs out.

Which makes deletion a required step rather than an optional one. It is also harder than it sounds: a client's records sit in the Drive, the practice email archive, a portal, whatever someone saved to a laptop, and the backups behind all four. Deleting from one is not deleting. No document tool makes that disappear, ours included.

A retention policy with no deletion step is a hoarding policy with a compliance vocabulary.

Can you still open it in year seven?

This is the half a retention policy never covers, because it reads like an IT question. It is not: an obligation you cannot discharge is the same as an obligation you ignored. Four questions, asked of every system that holds client documents.

  1. If the subscription stops today, do the files remain readable? A vendor whose product becomes a login screen has not been storing your records; it has been renting you access to them.
  2. Are they in formats that outlive the vendor? Ordinary PDFs and Office files in ordinary folders will open in 2033. Rows in a proprietary store depend on somebody still running the software that reads them.
  3. Does the evidence travel with the document? A signed agreement whose audit trail lives in a dashboard is two artefacts in two custody arrangements, and only one of them is yours.
  4. Could someone who joins in 2031 find the 2026 file without asking anyone? Retention is not achieved by a file existing. It is achieved by a stranger locating it under time pressure.

A retention procedure a practice can actually run

Seven steps, none of which needs a project. A practice that does these can answer a regulator, a professional body or a departing client without a search party.

  1. Write a period per document class rather than one number for everything: tax records, statutory records, engagement files and working papers, due diligence evidence, correspondence. Five lines is a complete policy for most firms.
  2. State that period in your engagement letter, including that files are destroyed afterwards without further notice and that originals are returned at the end. It turns a policy into a term the client has agreed to.
  3. File by the year the clock starts. Everything else here depends on that one habit.
  4. Put one annual purge in the practice diary, owned by a named person, on a fixed date after your busiest filing season rather than during it.
  5. Keep a one-line log of what was destroyed and when. It is the only evidence that a deletion was a decision rather than an accident, and it is what you produce when someone asks for a file you no longer hold.
  6. Export and hand back before you offboard a client, not after — access to your systems ends on disengagement, and the clock on their due diligence records starts the same day.
  7. Re-check the policy whenever you change document software. A migration is the most common way a retention period is quietly broken, so ask what happens to the files you do not bring over.

What XTK does and does not do here

Start with what XTK does not do, because it is the more important half. There is no retention engine: no scheduled deletion, no legal hold, no policy enforcement, no records-management module, no ethical walls. XTK will not stop anyone deleting a file inside the retention period, and it will not delete one for you when the period ends. If a regulator expects retention enforced by software rather than encouraged by policy, buy a practice document management system — the honest comparison names SuiteFiles and FYI and says who should choose them.

What XTK does is the custody half. Every document sits in your practice's own Google Drive, OneDrive or SharePoint, in a folder per client, as an ordinary file you could open tomorrow without XTK's help — so the period runs against storage you already own, back up and control the residency of. Folder templates take the same [DATE:yyyy] tokens as document templates, so a standard structure stamps itself with the right year as it is created and every client ends up the same shape.

The exits matter more than the features. Disconnecting storage removes XTK's access and leaves every file where it is. A lapsed trial or a cancellation puts the practice into a server-enforced read-only state rather than taking anything away — you can still browse, and a zip download of selected files still works, so getting your documents out is not gated behind paying again. Closing the account deletes XTK's own records and never touches your Drive; the deletion and data-rights page states the mechanics. And a completed signature produces one file, with the Certificate of Completion appended as the signed PDF's final page beside the untouched original, rather than a document here and a certificate in a dashboard.

And the honesty note this site owes on every article of this kind: uploads go from your browser straight to Google or Microsoft, but downloads, zip downloads, PDF merges, template generation and signature flattening stream bytes through XTK's backend — in flight, never written to disk or stored — and “Convert to PDF” hands that one file to CloudConvert, a disclosed third-party sub-processor and the only operation that sends a document outside your own storage provider. The full account of what moves where is the thing to read before signing anything off, alongside the Privacy Policy.

The question to ask before your next software change

Retention policies are written as though the only variable is time. The variable that actually decides whether you comply is custody: whose storage, whose format, whose subscription. So before you migrate, adopt or cancel anything, ask the question in its unflattering form — if this contract ends and nobody renews it, which of my retention obligations quietly become impossible? A practice that can answer that has a retention policy. One that cannot has a filing habit and a document about it.

Frequently asked questions

How long do accountants have to keep client records?

Between five and seven years for most records in most Xero markets, but the period depends on the jurisdiction and the document. As of August 2026, New Zealand's Inland Revenue requires at least seven tax years, the Australian Taxation Office five, the Canada Revenue Agency six from the end of the last relevant tax year, HMRC five years after the 31 January filing deadline for the self-employed, and the IRS three years as a general period of limitations. Company financial records and money-laundering records usually run longer than the tax figure.

Do we have to keep records for a client who has left the practice?

Yes, and one clock only starts when they leave. Under regulation 40 of the UK's Money Laundering Regulations 2017, client due diligence records are kept for five years beginning when you know or reasonably believe the business relationship has ended. Tax and statutory periods continue running on their own timetable regardless of whether the client is still yours, so disengagement reduces your access to the client, not your obligations.

Can we keep client records electronically instead of on paper?

Generally yes — the revenue authorities in the UK, Australia, New Zealand, the United States and Canada all accept electronic records, provided they are complete, legible and producible on request. New Zealand adds two conditions worth knowing: records must be in English or Māori unless Inland Revenue approves another language, and storing records offshore, including in cloud computing, requires that either you or your cloud provider has Inland Revenue's approval.

Who owns the working papers, the practice or the client?

Broadly, documents you prepared for your own purposes as part of delivering the engagement are the practice's, while documents belonging to the client that you hold on their behalf remain theirs. The distinction affects what you must hand over on disengagement as well as what you must retain, it is governed by your professional body's rules and your engagement terms rather than by tax law, and it is worth settling in the engagement letter rather than at the point of a dispute.

What happens to our retention obligations when we change document software?

They do not move with the software, which is the risk. A migration typically carries across current files and leaves a tail behind — old clients, archived years, anything outside the new system's structure — and that tail is usually the part still inside a retention period. Before you migrate, ask what happens to files you do not bring over, whether the outgoing system stays readable without a subscription, and who is accountable for the records in it.

Do we have to delete records once the retention period ends?

You have to consider it, and in some places act on it. Article 5(1)(e) of the UK GDPR permits personal data to be kept no longer than is necessary for the purpose, and Australian Privacy Principle 11.2 requires reasonable steps to destroy or de-identify personal information no longer needed, unless a law or court order requires retention. In practice this means a retention policy needs a deletion step with a named owner and a log, not merely a maximum period.

Give Practice Manager its missing half

Install the extension, connect your Drive, and open your first client — your whole practice can be working in context today.

30-day free trial for your whole practice — no credit card required.