Key takeaway: A record-retention plan should identify what must be kept, the event that starts the retention period, where the record and backups live, who can access them, and who approves disposal. Test recovery and check legal holds before destroying records. A backup count alone is not proof that the information can be restored safely.
A business may need invoices for a tax return, asset records for a later sale, payroll files for an employment-tax inquiry and contracts for a dispute. These records do not all become disposable at the same fiscal-year anniversary. Their retention rules and technical storage limits need to work together.

Inventory records and assign a responsible owner
List the accounting system, document repository, payroll system, tax archive, email attachments, shared folders, devices and backup services containing business records. Identify the authoritative copy and the other locations where copies can persist. Preserve the information needed to interpret transactions, including relevant attachments, approvals, account mappings and audit history.
For each category, record its purpose, responsible person, retention trigger, required duration, access permissions, recovery method and hold status. A permanent archive preserves readable evidence over time. A recovery backup restores a system or data after an incident. One may help the other, but neither automatically provides all the other’s functions.
For related guidance, our article on Secure CPA Data Request walks through this in “A Secure CPA Data-Request Checklist for Business Owners.”
Use actual tax retention periods and triggers
The IRS record-retention guidance gives these general federal starting points. Unless otherwise stated, measure from filing; an early-filed return is treated as filed on its due date. Keep copies of filed returns, and apply longer requirements where the circumstances demand them.
| Record or situation | General federal guidance |
|---|---|
| Ordinary income-tax support | Three years, subject to longer exceptions. |
| Refund or credit claim after filing | Three years from the original filing or two years from tax payment, whichever is later. |
| Claim for worthless securities or a bad-debt deduction | Seven years. |
| Omitted reportable income exceeding 25% of gross income shown | Six years. |
| No return filed, or a fraudulent return | Keep records indefinitely. |
| Employment-tax records | At least four years after the tax becomes due or is paid, whichever is later. |
| Property purchase, improvements, depreciation and basis | Through the limitations period for the disposal year; preserve earlier property records needed for a carryover basis. |
These are not permission to delete every older file. Special tax situations, extensions of assessment periods, carryforwards, refund claims and other requirements need review. Check contracts, lender or insurer requirements and applicable employment or industry rules before approving a category’s disposal date.
For Florida sales and use tax, DOR generally requires records for at least three years from the date a return was filed or required to be filed, whichever is later. Missing or substantially incorrect returns and substantial underpayments can require longer retention. Other states need their own analysis. Do not substitute “three years from fiscal close” for the actual filing-related trigger.
When an audit, records request, litigation or dispute creates a preservation need, suspend routine destruction of affected records and confirm the hold with counsel or the relevant adviser. Record who imposed and released the hold and which systems it covers. Do not allow an automatic expiry job to remove needed evidence.
Distinguish QuickBooks Desktop and Online backups
Intuit’s Desktop backup instructions describe a company backup that can restore accounting data. Payroll forms are not automatically included and require separate preservation. Verify related files, attachments and the software version needed to restore the actual file. A portable company file or PDF report set is not interchangeable with a complete recovery package.
Intuit’s Online Advanced and Enterprise Suite backup documentation describes plan-specific backup and restore features with exclusions. It lists attachments as included, but audit-log entries, reconciliation reports, bank-feed links and certain other data are not backed up by that feature; payroll information is represented as journal entries. Reconciled status and some other information do not restore completely.
The documented Online feature retains retrievable snapshots for one year. That recovery window is shorter than many tax retention requirements. Preserve required reports and supporting documents separately, and confirm the current product’s capabilities before changing plans, migrating or closing an account.
Design backups around loss scenarios
A 3-2-1 arrangement—three copies including production, on two types of media, with one copy off-site—is a useful starting structure. CISA’s LockBit guidance discusses this pattern together with offline or immutable backups. Three copies accessible through the same compromised administrator account can still be lost together.
Use appropriate isolation, encryption, separate backup credentials and access controls. Protect recovery keys and confirm who can delete snapshots or change retention settings. Choose backup frequency based on the amount of work the business can afford to lose and the time it can remain unavailable. An immutable copy can help resist alteration, but its configuration, retention lock and recovery process must be understood.
Test representative restores in a controlled environment. Confirm that accounting totals, transaction detail, attachments and required records are readable and complete. Record the recovery point, software version, elapsed time, missing data and corrective actions. A “backup succeeded” message alone does not establish successful recovery.
Contain a suspected incident before restoring
For suspected ransomware or unauthorized access, involve qualified IT or incident-response support promptly. CISA’s StopRansomware Guide addresses isolation, preservation of volatile evidence, clean recovery environments and avoiding reinfection. Do not immediately overwrite affected systems or reconnect restored data to a compromised network.
Identify a clean recovery point and preserve the relevant logs and evidence. The CPA can help identify missing accounting records, reconcile restored data and assess filing consequences; technical containment and forensic work require appropriate security expertise. Coordinate any notification or legal duties with qualified advisers. An incident does not automatically extend a tax deadline.
Control access and verify document exchange
Give each person individual access appropriate to their duties. Separate ordinary bookkeeping, payroll, approval, export, deletion and administration permissions where the product supports it. Review access when staff or service providers change, and protect accounts with multifactor authentication.
IRS Publication 4557 and the FTC Safeguards Rule guidance provide primary references for protecting taxpayer and customer information. They do not certify a particular firm’s systems. Independently verify a new recipient or upload channel, and avoid sending sensitive records through ordinary unprotected email. Use authorized accountant access rather than sharing personal passwords or authentication codes.
Dispose of records through an approved process
Before disposal, confirm the retention period, holds, owner approval and all locations containing the record. NIST SP 800-88 Revision 2, Guidelines for Media Sanitization, published in September 2025, provides a current framework for selecting sanitization controls based on information sensitivity and media. Ordinary file deletion is not proof that stored data is unrecoverable. Choose a method appropriate to the device or service and verify the result.
Cloud services and immutable backups may not allow an individual record to be erased from every snapshot immediately. Establish an approved expiry schedule with the provider, restrict surviving copies from routine use and control any restoration that could reintroduce expired data. Confirm that this arrangement satisfies applicable duties; a provider limitation is not a universal legal exemption.
Keep a disposition log showing the record category, period, authorizer, date, method, systems covered and verification evidence. Distinguish completed deletion from copies awaiting scheduled expiry. For physical media handled by a vendor, retain chain-of-custody and destruction evidence. Dispose of paper so sensitive information cannot reasonably be reconstructed.
Coordinate accounting support and technical responsibilities
Contact CPA Firm South Florida to discuss the accounting records, tax periods and reconciliation work needing assistance. Confirm the firm’s actual document-transfer process and responsibilities. Do not assume an accounting engagement includes hosting, permanent archiving, forensic response or media sanitization.
The firm’s pricing page includes cleanup needed for return preparation within the quoted preparation fee, with record condition affecting the quote. Ongoing bookkeeping, migrations, broader reconstruction and other separately requested work need a defined scope. Identify which responsibilities belong to the business, CPA, IT provider, storage provider and counsel.
Frequently asked questions
Is a three-year policy enough for every tax record?
No. Three years is the ordinary federal income-tax period, measured from filing with early returns treated as filed on the due date. Longer rules apply to specified situations, employment taxes and property records. State requirements, claims and legal holds may require more time.
Is a QuickBooks report export a complete backup?
No. Reports can preserve readable information but may omit transaction relationships, attachments, audit history and data needed to restore the accounting system. Confirm coverage for the exact product, plan and backup method.
Does a 3-2-1 backup arrangement prevent every ransomware loss?
No. Copies reachable through the same compromised credentials can be attacked together. Use appropriately isolated or immutable copies, separate access controls and tested recovery procedures.
Must every backup copy disappear immediately when a record expires?
Not necessarily. Backup immutability, provider limits and legal holds may prevent immediate deletion. Use an approved expiry and disposal policy, restrict retained copies, control restores and document what was actually removed and what remains until scheduled expiry.
What happens first after suspected unauthorized access?
Involve qualified IT or incident-response support to contain the incident and preserve evidence. Determine clean recovery points and systems before restoring. Coordinate separately with the CPA and counsel on records, deadlines and applicable reporting duties.