Skip to content
Security & trust

Bank statement retention requirements: how long firms keep them

By Chris Wattinger, Technology Lead at Scale CPA · Reviewed by Howard Telson, CPA, MST · Published · 7 min read
retentioncompliance

The short answer: keep client bank statements for at least three years after the related return is filed, six if there is any chance of a substantial understatement, and four for anything supporting employment taxes. Most firms simplify all of that to seven years in a written policy. The harder problem in practice is having every statement in the first place.

No federal statute names bank statements and assigns them a shelf life. A statement is supporting documentation, so its retention clock runs off whatever it supports: a tax return, a payroll filing, a sales tax reconciliation, a loan file. That is why the honest answer is a range with a policy on top, and why everything below is general guidance for writing that policy rather than advice for any specific client.

What does the IRS actually require?

The IRS frames record keeping around the period of limitations, the window during which a return can be amended by the taxpayer or examined by the agency. Its record-keeping guidance says to keep records supporting an item of income, deduction, or credit until that window closes. The window moves with the facts:

SituationKeep the supporting records
Typical filed return3 years from filing (or 2 years from paying the tax, if later)
Income underreported by more than 25%6 years
Worthless securities or a bad debt deduction claimed7 years
Employment taxesAt least 4 years after the tax was due or paid
Property still ownedUntil the limitations period ends for the year you dispose of it
No return filed, or a fraudulent oneNo limit

Two rows matter more than they look. The clock starts at filing, so a January 2024 statement supporting a return filed in April 2025 stays live until at least April 2028, which is longer than three years from the statement date. And the property row quietly stretches things: the statement showing the wire for an equipment purchase supports basis, so it stays relevant until well after the asset is sold.

Why seven years is the common default

Because nobody can police which statement supports which item. One month of an operating account touches revenue, deductible spend, payroll, and sales tax all at once, and each of those carries its own clock. Sorting PDFs into three-year and six-year piles costs more in staff attention than storing everything ever will.

Seven also covers the realistic worst cases. The six-year understatement window, measured from a filing date the following spring, reaches almost seven calendar years back to the earliest statements of that year. The worthless securities and bad debt rule is seven outright. State agencies run their own limitation periods, some longer than the federal three. So the common move is one number, applied to the whole archive, with zero monthly deliberation.

Storage is effectively free at these volumes; a year of statements for a typical client is a few dozen megabytes of PDF. The asymmetric cost sits entirely on the other side, with the one statement you cannot produce.

Clients that need longer than seven

Some clients inherit stricter rules from their industry, and the policy should list them as named exceptions instead of leaving judgment calls to whoever is closing that month. Broker-dealers and registered investment advisers sit under SEC record-keeping rules with their own clocks. Government contractors generally keep records for three years after final payment. Grant-funded nonprofits inherit retention terms from each award.

Unregulated clients get there in practice too. When a startup heads into a funding round or an acquisition, the diligence team asks for bank statements across the entire trailing period under review. A quality-of-earnings reviewer does not care that your default said seven years was plenty; they care that month 14 is missing.

How should the policy be written down?

A workable retention policy fits on a page and covers:

  • One default and one clock. Seven years, measured from the filing date of the return the records support, is common and easy to administer.
  • Scope. Bank and credit card statements, processor payout statements (Stripe, PayPal, and Square settle money that ends up in revenue), payroll reports, and the workpapers built on them.
  • Named exceptions. The regulated client types above, each with its period, so nobody improvises.
  • Location and structure. One archive, one folder convention, ideally client, then year, then month. An archive nobody can navigate fails an audit request almost as badly as one that was deleted.
  • A destruction step. A policy that only ever adds is a hoarding policy. Accounting firms are covered by the FTC Safeguards Rule, which expects secure disposal of customer financial information, so deletion should be a deliberate, logged process.
  • A hold rule. An open exam, litigation, or a regulator request suspends destruction for that client immediately.
  • Engagement letter alignment. The client keeps originals, the firm retains its copies for the policy period, and the letter says what happens to the file when the engagement ends.

Gaps hurt more than age

In our own close process, keeping a statement too long has never cost us anything; the month that never made it into the file has. Our close stalled waiting on statements more months than we care to admit, and the same failures that stall a close become retention gaps later:

  • The bank connection feeding the archive broke quietly and nobody noticed until year-end.
  • The client switched banks mid-year and the old online access died with the move.
  • An account was closed, and the bank’s online statement history disappeared with it.
  • The March statement lived in a staff inbox, and the staffer left.

Banks will not backstop you forever. Online statement history commonly runs somewhere between 18 months and 7 years depending on the institution and account type, and once an account closes, older copies mean research requests, waiting, and often a per-statement fee. The cheapest moment to get any statement is the month it posts. Every month after that, the price only goes up.

That is why a monthly completeness check belongs next to the retention policy. A simple collection checklist run at close catches a hole while the fix is still a download rather than a bank research request.

Pick seven years, write the policy, and spend your ongoing effort on completeness. Retention protects you only if the archive behind it has every account and every month on file. Audits punish gaps far more often than they punish age, and a gap is cheapest to fix in the month it opens.

How we keep our own archive complete

StatementFlow exists because our archive had exactly these gaps. It was built inside Scale CPA and ran on our own client book first. Each client connects their bank once through a secure invite link and authenticates at their own bank through Plaid or Mastercard Open Banking, so the firm never touches credentials. From there the system learns when each account actually posts its statement, since bank cycles rarely match calendar months, and pulls the official PDF when the bank publishes it, with retries and a second provider when the first has trouble.

Two design choices were made with retention in mind. Every stored file carries its own SHA-256 fingerprint, and Plaid downloads are verified against the provider’s content hash, so what sits in the archive is the exact document the bank produced, which is what you want to hand an examiner years later. And every file lands in the firm’s own Google Drive, organized by client, year, and month. Retention becomes a folder policy you control: age a document out and you delete it yourself, end an engagement and the file is already yours, leave the product and the archive stays put, because the vendor never held it and cannot browse it. A coverage board shows the account-by-month grid, so a missing month is visible at close instead of surfacing during a diligence request three years later.

The limits, stated plainly: it retrieves official statements, including settlement statements from processors like Stripe, PayPal, Square, and Shopify. It does no OCR or data extraction, it is not a bookkeeping engine, and it covers US banks only. It is in early access.

For the collection process a retention policy depends on, start with the complete guide to collecting client bank statements. If the completeness half is where your firm is weakest, request early access and bring your worst-covered client with you.

FAQ

How long should an accounting firm keep client bank statements?
Keep them at least three years after the related tax return was filed, which is the standard IRS period of limitations. Six years applies when income was understated by more than 25 percent, and employment tax records need four. Most firms adopt a single seven-year default in a written retention policy to cover every case.
Does the IRS require bank statements to be kept for seven years?
Not as a blanket rule. The IRS ties retention to the period of limitations for each return: generally three years, six for substantial understatement of income, and seven for worthless securities or bad debt deductions. Seven years is a practical firm default because one statement often supports several of those items at once.
What happens if a bank statement is missing during an audit?
You can usually reorder it from the bank, but expect friction. Online history at many banks runs out after a few years, closed accounts are harder to research, and archive requests can take weeks and carry fees. Rebuilding support mid-audit costs far more than storing a complete, organized archive from the start.
Should the firm or the client keep the bank statements?
Both, and the engagement letter should say so. The client owns their records and keeps originals. The firm retains the copies that support its work for the period in its retention policy, commonly seven years. If the firm controls its own statement archive, offboarding and audits stop depending on the client finding old files.

Keep reading

Chris Wattinger · Technology Lead, Scale CPA. Chris leads technology at Scale CPA and built StatementFlow inside the firm to end the monthly statement chase across its own client book.

Reviewed by Howard Telson, CPA, MST, Partner & Founder at Scale CPA.

LinkedIn · Meet the team behind StatementFlow

Stop chasing. Start closing.

Join the early-access waitlist and be one of the founding firms that never asks a client for a bank statement again.

Get early access