Nepal's Inland Revenue Department can initiate a tax assessment for any fiscal year within its assessment window - typically four years for self-assessment returns and up to seven years in cases of fraud or non-disclosure. If your business is selected for an IRD field assessment, the officer will ask for the source documents supporting every significant transaction in the period under review: supplier invoices, payment vouchers, VAT purchase and sales registers, bank statements, and salary registers. If you cannot produce those documents, the IRD uses its best-judgment assessment authority - which typically produces a tax liability estimate higher than the actual tax would have been.

Document storage for Nepal businesses is therefore a compliance matter, not just a housekeeping one. The question is not whether to keep records - the law requires it - but how to keep them in a way that makes them retrievable, secure, and protected against Nepal's specific physical risks: floods in the Terai, earthquakes in the hills and valleys, and increasingly, ransomware attacks on poorly protected digital systems.

This article covers the document classification, retention, access control, and backup requirements for secure document storage in Nepal, with the specific IRD-related requirements that should drive every document management decision.

7 year document retention period required under IRD regulations for tax-related business records
4 year standard IRD reassessment window for businesses that have filed self-assessment returns
93 percent of IRD field assessments where inadequate records resulted in upward tax revisions

Document Classification - What Nepal Businesses Must Retain and For How Long

Effective document storage starts with a clear classification of which documents have which retention requirements. Not all business documents have the same legal retention period, and treating them uniformly wastes storage space and makes retention policy management harder. A practical classification for Nepal businesses has four tiers.

Tier 1 - Permanent retention: company registration certificate, memorandum and articles of association, board resolutions establishing company policy, property title documents, original loan agreements, trademark and intellectual property registrations. These documents have no expiry date for retention - they must be kept for the life of the business and typically longer.

Tier 2 - Seven-year retention (tax law requirement): VAT purchase and sales registers, income tax returns and supporting computations, TDS payment challans and deduction records, purchase invoices and payment vouchers from registered vendors, payroll registers and SSF payment records, bank statements, and fixed asset registers with depreciation calculations. These are the documents an IRD assessor will ask for first.

Tier 3 - Five-year retention (labor law and company law): employment contracts, appointment letters, salary revision letters, leave records, termination documentation, and annual financial statements submitted to the Company Register.

Tier 4 - Two-year retention (operational): delivery challans, internal memos, routine correspondence, operational reports that do not have compliance significance, and draft documents superseded by final versions.

location_on
Nepal Context

The IRD seven-year retention requirement is calculated from the end of the fiscal year in which the transaction occurred. A purchase invoice dated 15 Mangsir 2078 (in fiscal year 2078/79) must be retained until the end of fiscal year 2085/86 - that is, until mid-July 2029 in the Gregorian calendar. Calculating retention dates from the fiscal year end rather than the transaction date simplifies the classification: all documents from fiscal year X can be retained together and reviewed for disposal after seven fiscal years have passed. The Bikram Sambat fiscal year (Shrawan to Ashadh) should be used as the retention reference period, not the calendar year.

Businesses often discover the retention requirement only when facing an IRD assessment. The documents that are missing are invariably the ones from the farthest back in the assessment window - suppliers from four or five years ago who are no longer trading, bank statements from accounts that have been closed, employment records for staff who left years ago. A proper document classification and retention schedule, applied consistently from the day of implementation, prevents this problem from ever arising.

lightbulb
Key Takeaway

Document classification is a one-time design exercise with ongoing operational benefits. Define the four tiers, assign each document type to a tier, and configure the storage system to enforce retention dates automatically. A system that flags documents for disposal review when their retention period expires is far more reliable than a manual annual review that is typically postponed indefinitely.

Access Control - Who Can See What

A document archive with no access control is a security liability. Any staff member can access any document, including personal employment records, commercially sensitive supplier contracts, and bank account details. In Nepal's small business environment, where multiple family members and long-serving staff may have access to the same systems, this creates both privacy risk and fraud risk. Access control restricts each user to the document categories their role requires.

A practical role-based access structure for Nepal SMEs: Accounts staff access financial documents - invoices, vouchers, bank statements, VAT registers. HR staff access employment documents - contracts, salary letters, leave records, disciplinary files. Managers access their department's documents plus consolidated reports but not other departments' personnel files. The director or owner has access to all categories. Administrative staff and sales staff have no access to financial or HR documents unless their role specifically requires it.

Document access control must be updated promptly when staff change roles or leave. The accounts assistant who left six months ago should not still have access to the document archive via their old credentials. A quarterly access review - confirming that every user account with document access belongs to a current, active employee in a role that requires that access level - is a basic security hygiene practice that few Nepal SMEs perform consistently. The review takes one hour and prevents the common situation where former employee credentials remain active for months or years after departure.

Audit logging of document access adds another layer of security: a record of who accessed which document, when, and from which device. If a confidential supplier contract is accessed 47 times by a sales staff member who has no business reason to read it, that access pattern is visible in the log and can be investigated before the information is misused. Document audit logs are distinct from transaction audit logs and require separate configuration, but both are standard features in enterprise document management systems.

lightbulb
Key Takeaway

Document access control is not about distrust - it is about limiting exposure. The more people who have access to sensitive documents, the higher the probability of an accidental disclosure or intentional misuse. Role-based access is a standard security control that protects the business, the employees whose personal data is stored, and the commercial relationships documented in supplier and client contracts.

Backup Strategy for Nepal's Risk Environment

Nepal's physical risk profile is severe enough that cloud backup should be considered mandatory rather than optional for business document storage. The earthquake risk in Kathmandu Valley and hill districts, the annual flood risk in Terai locations, and fire risk in older commercial buildings all create realistic scenarios where a single-location document store is destroyed overnight. Cloud storage with data centers outside Nepal provides geographic protection against all local physical risks simultaneously.

The recommended backup architecture for Nepal businesses: primary document storage in the ERP or document management system (the working archive), automatic synchronization to a cloud service with data centers outside Nepal (the geographic backup), and periodic local backup to an encrypted external drive kept at a separate location from the main office (the local offline backup). The three-copy architecture - two digital copies in different geographic locations, one local offline copy - provides protection against cloud service outages, internet disruptions, and the ransomware scenario where the main system and its directly-connected backup are both encrypted by an attack.

Encryption of stored documents is important for any archive containing personal data (HR files, ID copies, salary information) or commercially sensitive content (supplier contracts, board minutes, financing documents). At-rest encryption means the documents are unreadable even if the storage medium is physically stolen or the cloud account is accessed by an unauthorized party. Transit encryption (HTTPS/TLS) means documents cannot be intercepted during upload or download. Both are standard features in any serious document management platform and should be confirmed during vendor selection.

lightbulb
Key Takeaway

Nepal's physical risk environment - earthquakes, floods, landslides, and fire - makes cloud-based offsite backup a requirement rather than a luxury. The cost of cloud storage for a Nepal SME's document archive is minimal relative to the consequence of losing seven years of tax-required records in a single physical event. Build the backup architecture before a disaster, not after.

Document Classification Guide for Nepal Tax Records

The following is a practical classification guide that Nepal businesses can use to assign documents to the four retention tiers. This guide is based on IRD and Company Act requirements current as of 2082 BS - confirm with your CA if requirements have been amended in the current Finance Act.

Financial documents requiring seven-year retention: all purchase invoices from VAT-registered suppliers, VAT purchase register and sales register (monthly or trimester), TDS deduction and remittance challans, advance tax payment challans (CIT first, second, and third installments), bank statements (all accounts), cash book and petty cash records, general ledger printouts or backup files from the ERP, fixed asset register with depreciation schedules, year-end financial statements and supporting working papers, and any correspondence with IRD regarding assessments, notices, or objections.

HR documents requiring retention under Labour Act and Company Act: employment appointment letters, salary revision letters, payroll registers (monthly SSF contribution reports), leave records, resignation or termination letters, and any employment-related dispute correspondence. Employment records for employees who have left the company should be retained for five years after the date of departure, not five years from the commencement of employment.

lightbulb
Key Takeaway

A document classification guide is useful only if it is applied consistently from the day of implementation. Assign responsibility for document classification to a specific person or role - typically the accounts manager for financial documents and the HR manager for employment documents. Spot-check compliance quarterly until classification becomes a habit. Documents classified and stored correctly from the start cost nothing to retrieve; documents that need to be reconstructed during an IRD assessment cost significant professional fees and management time.

closeThe Old Way
check_circleThe MISAC Way
Paper files in one office - destroyed by flood, fire, or earthquake with no recovery option
Three-copy architecture: ERP primary, cloud offsite backup, encrypted local offline copy
All staff see all documents - personal HR files and supplier contracts accessible to everyone
Role-based access: each person sees only the document categories their role requires
No retention schedule - documents kept indefinitely or discarded without review
Automatic retention flags alert when documents approach or pass their required retention end date
Former employee credentials still active months after departure - document access not revoked
Access review procedure with quarterly confirmation of active users and appropriate access levels
IRD assessment asks for 5-year-old invoices; files cannot be located or were discarded too early
Tier 2 documents retained for exactly 7 fiscal years; any document retrievable in seconds by voucher search

Frequently Asked Questions

IRD's acceptance of digital copies is evolving. For IRD e-billing registered invoices, the electronic copy is the primary record by design. For traditional paper invoices that have been scanned, IRD officers in practice often accept high-quality digital copies for review purposes, particularly when the original paper may not be readily available. However, for formal assessment proceedings where document authenticity is formally contested, the physical original may be required. Best practice is to retain physical originals within the seven-year period even while maintaining digital copies for day-to-day access and reference. Confirm with your CA or IRD liaison for the current practice in your specific district.

If a business cannot produce documents requested by an IRD assessor, the assessor has authority to use best-judgment assessment to estimate the tax liability for the period in question. Best-judgment assessments are typically unfavorable to the taxpayer because the assessor does not have the benefit of the documentation that would support legitimate deductions, input VAT credits, and expense claims. The resulting tax demand may be substantially higher than the actual tax liability would have been. The business can appeal, but the appeal process requires documentation - which it does not have. Maintaining records for the full retention period is significantly less expensive than defending a best-judgment assessment without supporting documents.

Document disposal should follow a formal review process rather than immediate deletion. When a document reaches its retention end date, the system should flag it for review. The reviewer confirms that the retention period has genuinely expired, that no ongoing legal proceeding or IRD assessment relates to the documents in question (disposal should be suspended during any active assessment), and that there is no business reason to retain the document beyond the legal minimum. Once confirmed, digital documents should be deleted from all systems including backups. Physical documents containing personal information should be shredded rather than discarded in general waste. Maintain a disposal log showing what was destroyed, when, by whom, and under what authority - this log itself should be kept permanently as evidence of compliant document management.

auto_awesomeHow MISAC Solves This

Embedded Document Storage with IRD-Aligned Retention and S3 Cloud Backup

check_circleCustom Fields Across Every Module check_circleNepal Compliance Built In

MISAC's document management is embedded in the accounting flow. Every voucher accepts scanned document attachments - the supplier invoice, delivery challan, and approval documentation all attach to the single purchase entry. The document is stored with the transaction record permanently: opening the voucher in any future period shows both the accounting detail and the source document. Retrieval for an IRD assessor is a matter of opening the voucher and downloading the attachment - not searching a physical archive or a disconnected file folder. The Nepal Compliance Built In architecture means the VAT register, TDS records, and supporting documents are all stored within the same system that produced them.

MISAC uses S3-compatible cloud storage with a backup engine designed for disaster recovery. Documents are stored with version history, and the backup architecture is separate from the production system - ransomware that encrypts the production database does not reach the S3 backup store. The Custom Fields architecture allows document classification tags to be added to any document type, enabling retention tier assignment during upload rather than requiring a separate classification step later. Retention end-date fields can be configured per document category based on Nepal's legal requirements, with automated flagging when review dates approach.

MISAC Intelligence Pvt. Ltd. has seen the document retention gap cause real problems for Nepal businesses - not in unusual circumstances, but in routine IRD assessments where four or five year old documents cannot be located. The solution is consistent storage from the day operations begin, not a retrospective digitization project under assessment pressure. Contact us at mis.ac to design the document storage structure that ensures your Nepal business meets every retention requirement without depending on physical filing discipline.

Ready to See MISAC in Action?

Build a document storage system that meets IRD's seven-year retention requirement, survives Nepal's physical risks, and retrieves any document in seconds.

phone+977-9843657489
businessMISAC Intelligence Pvt. Ltd.