Skip to main content
Compliance

The Year-End Audit Trail: Which Records Prove What, Before Auditors Ask

In short

An auditor asks for one December invoice as it looked on the day it was booked. Which records will you be asked to show at year end, and what can each kind of evidence prove about a file: that it existed then, that it is unchanged, who signed it, and who the person was.

The Year-End Audit Trail: Which Records Prove What, Before Auditors Ask — Swiss Trust Layer

In February, the auditor of a small Zurich trading company asks for one thing: the supplier invoice behind a large December booking, as it looked on the day it was booked. The bookkeeper finds a PDF. It opens fine. But the auditor's next question is the one that takes longer to answer. How does anyone know this is the file that was on the system in December, and not a copy that was tidied up in January?

That question is the whole subject of a year-end document audit trail. Before the books close, it helps to know which records you will be asked to show and what each kind of evidence can actually prove.

What the Swiss rules ask of your records

The Code of Obligations starts with the voucher. Under Article 957a of the Code of Obligations, bookkeeping follows proper accounting principles, and those include proof of the underlying voucher for each booking and the possibility of checking it afterwards. A voucher can be on paper or in electronic form. The annual report has its own timetable: Article 958 gives six months after the end of the financial year to prepare it and put it to the body that approves it, and it has to be signed.

Then comes retention. Article 958f sets ten years, counted from the end of the financial year, for the books, the vouchers, the annual report and the audit report. The annual report and the audit report are kept in writing and signed. Books and vouchers may be kept electronically, as long as they still match the underlying transactions and can be made readable at any time.

The Federal Council's Ordinance on the Keeping and Retention of Accounting Records (GeBüV) fills in the detail for electronic records. Article 3 says records must be kept so that they cannot be changed without that being noticeable. Article 9 goes further for storage that can be altered: the integrity of what is stored has to be secured by a technical method, and the time of storage has to be provable in a way that cannot be falsified. The ordinance gives a digital signature as an example of the first and a time stamp as an example of the second. It also asks for the procedures to be documented and for the related logs to be kept.

Four things an auditor may ask you to show

It helps to separate them, because one piece of evidence rarely covers all four.

That the file existed at a given time

A file's own "modified" date is set by whoever holds the file, and anyone can change it. A qualified electronic time stamp is different. Under Article 41 of eIDAS, it carries a presumption that the date and time it shows are accurate. Whoever disputes it has to bring the evidence.

That it has not changed since

The same Article 41 presumption covers the integrity of the data the time stamp is bound to. In practice a hash of the exact file is bound to the time, so a changed file no longer matches. This is the property GeBüV Article 3 is describing in general terms.

Who signed

A signature on the document shows who approved it. The annual report is the obvious case, since Article 958 requires it to be signed. Whether a scanned signature, an advanced one or a qualified one is enough depends on the form the rule asks for, and that is a question for your accountant, not for a time stamp.

Who the person was

This is the gap people forget. A time stamp says nothing about who put the file there. If a counterparty or an authority asks who made or approved a record, the answer needs an identity check behind the name. Swiss Trust Layer's identity check ties a sealed record to a person verified against a passport, so the name on the record has something behind it.

What sealing does, and what it does not

Sealing a file on Swiss Trust Layer records a hash of the exact file together with a qualified time stamp. Later, anyone can check the file against the seal, and the check either matches or it does not. That answers the first two questions above.

It does not answer whether the invoice was correct, whether the booking was right, or whether your accounts are complete. It is not bookkeeping software, and it does not make your books compliant. GeBüV also asks for documented procedures and retained logs, and a seal does not write those for you. Whether your whole setup meets the ordinance is something for your accountant or auditor to judge.

A practical order for the last weeks of the year

Start with the records that are hardest to reconstruct later: bank statements, the invoices behind the largest bookings, stock count sheets, signed contracts, board or owner approvals. Seal them when the set is final, and keep the seal certificates next to the files. If you migrate records to a new system, log the transfer as Article 10 of the ordinance asks, and check that the files still match their seals afterwards.

Then note, per record, which of the four questions it can answer. Gaps show up quickly. A supplier contract may have a time stamp and no identity behind it. A signed annual report may have a signature and no proof of when the final version existed.

Before the auditor asks

The auditor in our opening example does not need a story about December. They need a file and a check that agrees with it. If you want that for your own year-end set, start sealing your records, or read how the process works first.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

Four Dates Sit on the Q4 Calendar. One of Them Decides How a Dispute Goes
Compliance

Two obligations still land before the end of the year and two have been running for a while. Three of them are things you comply with. The fourth changes what happens once you are already in an argument, because it lets a court order you to produce your own evidence. That is the one worth preparing for.

September 29, 2026Read Article →
We Said September Would Not Be Quieter. Here Is What Changed
Compliance

At the end of August we argued that September only looks like a quiet month, because the obligations that landed earlier in the year keep running whether or not there is a headline date attached. September is over. Here is what actually moved, what moved on this platform, and what is still open going into the last quarter of the year.

September 28, 2026Read Article →
September 2026 Compliance Recap: What Already Binds You and What Doesn't Yet
Compliance

Three weeks into September and the alerts in your inbox disagree about dates. Two EU AI Act obligations already bind somebody, two deadlines are still months away, and two court matters that get quoted as settled law are nothing of the kind.

September 20, 2026Read Article →
What Happens If You Lose Every Password: Recovery Tied to You, Not a Login
IP & Copyright

Any service can send a reset email. None of them help once you have lost that email too, along with the phone, the password manager and every backup code. A register that ties each deposit to your verified identity is built for exactly that day, because getting back in does not depend on any credential you still hold.

September 30, 2026Read Article →
One Code Identifies the Work Without Exposing the File: ISCC, Explained
Product & Technology

A qualified timestamp proves when a file existed. A hash proves it is exactly that file, byte for byte. Neither one answers a different question: is this the same work after someone resizes it, re-saves it, or re-encodes it for a different platform. That is the gap the International Standard Content Code closes, and it does it without anyone handing over the underlying file.

September 27, 2026Read Article →