Guides

How Long Accounting Firms Must Keep Client Records: The Retention Patchwork No Single Rule Covers

UK accounting firms face five different record-retention clocks per client file, not one. Here's how long each document type must be kept, and why that's a workspace problem.

Osuria Team

Ask most firms "how long do you need to keep client records?" and the honest answer is: it depends which record, for which client, measured from which date. That is not a trick question. It is the actual shape of UK record-retention law for accounting firms, and it is a very different problem from "keep everything, delete nothing," which is how most firms handle it by default.

A single client file routinely contains documents governed by at least four or five separate retention regimes, each with its own trigger date and its own minimum period. Treating the file as one object with one retention rule is the mistake. Here is what the law actually requires, document type by document type.

The Patchwork, Document by Document

Self-assessment records (sole traders, individuals, partners). HMRC requires records to be kept for at least five years after the 31 January submission deadline for the relevant tax year — in practice around five years and ten months measured from the end of the tax year itself. This is the baseline most firms already know, but it only covers personal tax records, not everything else in the file.

Limited company accounting records. Companies Act 2006 sets a three-year minimum for private companies, but UK tax law's six-year requirement effectively overrides it in practice, since HMRC can request records within that window. A firm advising a limited company needs to retain its accounting records for six years from the end of the relevant financial year — double the self-assessment clock, and measured from a different starting point (financial year end, not filing deadline).

VAT records. Six years is the standard retention period for VAT records. Firms with clients using the VAT One Stop Shop (OSS) or Import One Stop Shop (IOSS) schemes for EU sales face a longer ten-year requirement for those specific records — a distinction easy to miss if a firm applies one VAT retention rule across its entire client base.

PAYE and payroll records. These carry the shortest standard clock: three years from the end of the tax year they relate to. A payroll bureau or a firm running client payroll is working against a materially different (and shorter) deadline than the same firm's self-assessment or VAT retention obligations — as the distinct deadline structure facing payroll bureaus makes clear.

Client due diligence records under the Money Laundering Regulations 2017. This is the clock most firms underweight. Regulation 40 requires accountancy service providers to retain customer due diligence documentation for five years beginning on the date the firm knows, or has reasonable grounds to believe, that the business relationship has ended — not from when the records were created, and not from a tax year end. Records relating to an occasional transaction follow the same five-year rule from completion of that transaction. Firms are also required to delete this personal data once the retention period expires, unless a specific legal ground to keep it longer applies. The regulations cap total retention at ten years even where other grounds might otherwise extend it.

The outer bound. Where HMRC suspects deliberate non-compliance, it can go back as far as 20 years. This is not a routine retention target for firms to plan around, but it is worth knowing it exists as the ceiling case.

Why This Is a Workspace Problem, Not a Filing-Cabinet Problem

The retention periods above don't just differ in length. They differ in what starts the clock. Self-assessment and VAT records run from a tax year or filing deadline. Company accounting records run from financial year end. AML due diligence records run from the end of the client relationship — a date that, for an ongoing client, hasn't happened yet and isn't predictable in advance.

That means a single client's file isn't on one retention schedule. It's on several, running in parallel, with different start triggers and different lengths, and the AML clock for that same client doesn't even start until they stop being a client. A firm that applies one blanket "keep for six years" policy across an entire client file is either under-retaining AML records (which only begin counting at offboarding) or over-retaining payroll records by double the required period, with no way to tell which from a quick look at the file.

Want to see how this works in practice? Explore Osuria’s client portal

This is fundamentally a document-tagging and metadata problem, not a storage-capacity problem. A workspace that treats "the client file" as an undifferentiated folder has no way to know that the payslips inside it reach their deletion point three years after one date, while the engagement due diligence documents reach theirs five years after a completely different, not-yet-determined date.

The GDPR Tension Nobody Resolves by Just Keeping Everything

UK GDPR's storage limitation principle requires that personal data not be kept for longer than necessary for the purpose it was collected for. Firms sometimes read the retention periods above as permission to keep everything for the longest applicable period "to be safe." That reasoning runs in the wrong direction. The retention periods are statutory minimums for specific regulatory purposes — they tell a firm when it is not yet allowed to delete something. They are not a justification for keeping data past the point it's actually needed, and the MLR 2017 deletion requirement makes this explicit for AML records specifically: once the five-year (or capped ten-year) period expires, the regulations require deletion, not optional housekeeping.

The practical target, document type by document type, is a retention floor and a deletion ceiling, not an indefinite archive — which is a more detailed data-governance exercise than "back everything up forever," and is covered in more depth, including the lawful-basis and data-subject-rights side of the same question, in our UK GDPR and ICO compliance guide for accounting firms.

Where This Collides With Offboarding

The AML clock makes client offboarding a retention trigger, not a retention exit. The moment a client relationship ends is precisely the moment the five-year due diligence retention period begins — meaning a firm's obligation to securely hold certain records about a departed client is often just starting at the exact point the file otherwise feels "closed." Firms that treat offboarding as "export what the client wants, then archive or delete the rest" risk deleting the one category of record (CDD documentation) that the regulations specifically require them to keep running for years afterward.

This is a natural extension of the handover problem covered in our guide to client offboarding and practice transfers: offboarding isn't just about what leaves with the client. It's about what the firm is still legally required to retain, and for how much longer, after the client is gone.

What This Actually Requires From a Client Workspace

None of the above is solved by picking a single retention period and applying it firm-wide. It requires:

  • Retention metadata at the document-type level, not the client-file level — so payroll records, VAT records, company accounts, and AML due diligence documents each carry their own applicable retention window rather than inheriting one blanket rule.

  • Trigger-date tracking that isn't always "today" — most retention clocks need a stored trigger date (tax year end, financial year end, relationship-end date) that is set once and doesn't depend on someone remembering to calculate it later.

  • Retrievability for records that must outlive the active relationship — AML due diligence documentation has to remain securely accessible for years after a client stops being a client, which means a workspace's access model needs a state between "active client with full access" and "deleted," not just those two options.

  • An actual deletion mechanism, not just an upload mechanism — GDPR's storage limitation principle and the MLR 2017 deletion requirement both assume records get removed once their purpose and retention period have passed, which only happens if the system is built to flag that point rather than accumulate indefinitely by default.

A branded digital workspace that keeps every client's documents, communications, and file history in one organised, access-controlled place is a reasonable foundation for this — but only if the underlying document handling can distinguish a payslip from a due diligence record, because the law already does.

If your firm is still managing retention with a single shared drive and a mental note to "sort it out eventually," explore the Digital Workspace to see what document organisation built for this kind of regulatory variation actually looks like, or start using Osuria to bring client records, retention-relevant metadata, and secure access into one place from day one.