Document Management System South Africa: what to keep, where it may live, and how fast you must produce it | NexBDM Blog
NexBDM

NexBDM Blog

Document Management System South Africa: what to keep, where it may live, and how fast you must produce it

By NexBDM Team · 2026-08-29

Key takeaways

  • South African law never defines a document management system. It sets three separate tests instead: how long records are kept and in what form, whether an electronic copy counts as the record, and where that copy may physically sit. Each one lives in a different instrument.

South African law never defines a document management system. It sets three separate tests instead: how long records are kept and in what form, whether an electronic copy counts as the record, and where that copy may physically sit. Each one lives in a different instrument.

A document management system in South Africa has to satisfy three separate legal tests, not one. The Companies Act sets how long records are kept and in what form. The Electronic Communications and Transactions Act sets whether an electronic copy counts as the record. A 2012 SARS public notice sets where tax records may physically sit and how quickly you must hand them over.

Most guides on this subject describe software features. This one describes the requirements, because they are written down, they are specific, and almost none of them are about features.

The phrase "document management system" appears nowhere in the law

That is the first thing worth knowing, and it explains why the topic is so consistently muddled. There is no South African statute that defines a document management system, certifies one, or lists what it must do. What exists instead is a set of obligations spread across three instruments, each written for a different purpose and each adding a requirement the others do not.

So the honest way to choose a system is not to compare feature lists. It is to read the three requirements off the page and ask whether the arrangement you already have satisfies them. Below is each one, with the section that carries it.

What to keep, and for how long

The base rule is section 24(1) of the Companies Act 71 of 2008. Records a company must keep under the Act or any other public regulation must be kept:

"in written form, or other form or manner that allows that information to be converted into written form within a reasonable time"

and, under section 24(1)(b), "for a period of seven years, or any longer period of time specified in any other applicable public regulation".

Read the first half again, because it is doing more work than it looks. The Act does not require a document. It requires convertibility into written form within a reasonable time. That is a retrieval standard wearing the clothes of a storage standard. A shoebox of receipts satisfies it. A folder of thirty thousand unnamed scans, with no index, arguably does not, because nothing in it can be converted into anything within a reasonable time.

Section 24(3) then lists what every company must maintain by name: the Memorandum of Incorporation and any amendments, the record of directors, reports presented at annual general meetings, annual financial statements, accounting records, notices and minutes of shareholders meetings with the resolutions adopted, general communications to holders of securities, and minutes of all meetings and resolutions of directors and their committees. Most carry their own seven year clock from their own event, which is the detail that catches people out: the clock does not start when you filed the document, it starts when the thing happened.

Where the records may live

Two separate rules apply here and they are not the same rule.

Under the Companies Act. Section 25(1): the records referred to in section 24 "must be accessible at or from the company's registered office or another location, or other locations, within the Republic". Section 25(2) then requires the company to file a notice setting out the location or locations where those records are kept or from which they are accessible, if they are not kept at or made accessible from the registered office, or if they are moved from one location to another. That filing obligation is routinely missed by businesses whose records moved into cloud storage years ago and whose registered office is an accountant's address.

Under the tax rules. This is the stricter one, and it is the reason the question matters. Section 30 of the Tax Administration Act 28 of 2011 lets you keep records in an electronic form prescribed by the Commissioner in a public notice. That notice is Government Notice 787, published in Government Gazette 35733 on 1 October 2012, and its Schedule, rule 4.1, says:

"'Records' retained in an electronic form must be kept and maintained at a place physically located in South Africa."

Rule 4.2 provides the way out: a senior SARS official may authorise storage at a location outside South Africa, but only where the system stays accessible from the person's physical address in South Africa for the whole retention period, the locality does not affect access, there is an international tax agreement for reciprocal assistance in the administration of taxes in place with that country, every other rule is satisfied, and the records can still be produced to SARS on request within a reasonable period. SARS publishes a declaration form for this, the EFR001.

The practical question that follows is not which storage brand you use. It is where that provider actually holds the data, and whether anyone in the business has ever obtained the authorisation rule 4.2 describes. In most small companies the honest answer to both is that nobody has looked.

What makes an electronic copy count

Here the answer depends on how the record was born, and the two paths have different tests.

If the record was born electronic, an emailed invoice or a signed PDF, section 16(1) of the Electronic Communications and Transactions Act 25 of 2002 is the retention test. Where a law requires information to be retained, keeping it as a data message satisfies that requirement only if all three of the following hold:

  • "the information contained in the data message is accessible so as to be usable for subsequent reference";
  • the data message is in the format in which it was generated, sent or received, "or in a format which can be demonstrated to represent accurately the information generated, sent or received"; and
  • "the origin and destination of that data message and the date and time it was sent or received can be determined".

The third condition is the one systems fail. Origin, destination, date and time are not properties of the document. They are properties of the thing holding it. Print an emailed invoice to PDF, drop it in a shared folder, and you have preserved the content while destroying exactly the four fields section 16(1)(c) names. The file is still readable. It is no longer evidence of who sent it, to whom, or when.

If the record was born on paper and you scanned it, section 16 is not the test you are meeting, and the SARS notice deals with it directly. Rule 5.5 requires that where a record is converted from a non-electronic form, or from one electronic form to another, a separate record is kept of the conversion: a chronological record and explanation of all changes or upgrades to the software and hardware used, explanations of any data migrations, a detailed record of the controls which maintained the integrity of the old system, and an explanation of archival and back-up facilities for systems no longer in use.

Underneath both sits the integrity standard. Rule 3.2(a) of the notice defines an acceptable electronic form by pointing straight at section 14 of the ECT Act, which assesses integrity by "considering whether the information has remained complete and unaltered, except for the addition of any endorsement and any change which arises in the normal course of communication, storage and display", in the light of the purpose for which the information was generated, and having regard to all other relevant circumstances.

So the chain, in full, runs: Tax Administration Act section 30(1)(b), to the 2012 public notice, to rule 3.2(a), to ECT Act section 14. Four steps across three instruments to answer one question, which is why so few people answer it.

One more provision is worth knowing because it works in your favour. Section 15(4) of the ECT Act says a data message made in the ordinary course of business, or a copy or printout or extract from it "certified to be correct by an officer in the service of such person", is on its mere production admissible in evidence and is rebuttable proof of the facts it contains. Note the condition. The printout does not carry itself. Somebody in the business has to certify it, and if you have never designated who that is, you have a document and no officer.

How fast you must produce it

This is the part that turns filing from a tidiness question into an operational one, and it has a number attached.

Section 26(5) of the Companies Act: where a company receives a request made in the prescribed manner, "it must within 14 business days comply with the request by providing the opportunity to inspect or copy the register concerned to the person making such request".

That number is already scheduled to get shorter. Section 4(g) of the Companies Amendment Act 16 of 2024 substitutes the subsection so that a company must comply "within 10 business days", and it widens the object from "the register" to "the register or the records concerned". Less time and more scope, in one amendment. That substitution had not been brought into operation by the commencement proclamations published so far, the batch effective 27 December 2024 and the one effective 22 May 2026 covering sections 5, 6 and 19. If you are reading this later, the two places a change would show up are the proclamations in the Government Gazette and the notices page on the CIPC website.

The sensible planning number is the shorter one. A business that can produce a record in ten business days can produce it in fourteen. The reverse is not true, and nobody gets advance warning of a proclamation.

Separately, rule 7.1 of the SARS notice requires electronic records to be available for inspection at all reasonable times, at premises physically located in South Africa, or accessible from such premises where authority under rule 4.2 has been granted. There is no notice period in that one at all.

The three requirements nobody plans for

These sit in the same 2012 notice as everything else, and they are the ones that never appear in an article about choosing software.

  1. The passwords are part of the record. Rule 6 requires measures for adequate storage of electronic records for the whole retention period, and rule 6(b) names, specifically, "the storage of all electronic signatures, log-in codes, keys, passwords or certificates required to access the 'electronic records'". Rule 6(c) adds procedures to obtain full access to anything encrypted. In plain terms: if one person holds the credentials and leaves, the compliance leaves with them, and the records being intact is no defence.
  2. Internet-based transactions need their log files described. Rule 5.6 requires the written system description to cover the log files created to identify individual transactions and the security measures used to maintain the identity, integrity and authenticity of transactions. Anyone selling online is in scope.
  3. The index itself is a requirement. Rule 5.4(f) asks for "a data dictionary that explains how 'records' are indexed when created, processed, stored or backed-up". Not a folder structure. A written explanation of how the indexing works.

Off the shelf or built for you: the rule that decides

There is a clean decision rule sitting in rule 5 of the notice, and it is the most useful thing in there for a small business.

Rule 5.1: a person who uses software or an electronic platform "that is commonly recognised in South Africa" to keep records electronically need not keep the documentation described in that rule at all.

Rule 5.2: if the platform is altered or adapted for your environment, created or designed for you, or is not commonly recognised in South Africa, you must keep it. Rule 5.4 then lists seven things that written description must cover: how transactions are created, processed and stored; how and what reports are generated; how often electronic records are stored; the format used to store and archive records, including the media, software and hardware; the physical locality where records are stored or archived; the data dictionary; and the procedures and protocols in place to prevent unauthorised deletion, alteration and destruction of records and reports.

That is a real trade-off, stated in law rather than in opinion. A common platform costs you flexibility and saves you a documentation obligation. A custom build costs you that documentation permanently, and the obligation grows every time the system changes. Neither choice is wrong. But a business that commissions a bespoke system and never writes the rule 5.4 description has taken on an obligation it does not know it has.

How this differs from the neighbouring problems

Three related questions get answered elsewhere on this site, and it is worth being clear about which is which, because the overlap is where people get lost.

This post is about none of those. It is about the holding and the retrieval: the same document, correctly signed and correctly drafted, and whether you can prove what it is and put your hand on it inside ten business days.

How the work actually gets reduced

Reading the above as a to-do list is how it becomes a project nobody finishes. Read it as a set of things that should happen automatically at the moment a document arrives, and it becomes small. Six mechanisms, in the order they pay off:

  1. Capture the metadata at intake, not later. When a document is filed the instant it arrives, from the mailbox or the form it came through, the sender, the recipient, the date and the time come with it. That is section 16(1)(c) satisfied as a side effect of arriving, rather than reconstructed from memory two years afterwards, which cannot be done.
  2. Index on the fields a request will use. Party, document type, date, financial year, entity. A request never arrives phrased as a folder path. Indexing on the fields people actually ask in is also, conveniently, the data dictionary rule 5.4(f) wants.
  3. Log every conversion as it happens. Each scan or format change writes its own rule 5.5 entry automatically, so the conversion record exists without anyone maintaining it by hand. Nobody has ever kept that log manually for seven years.
  4. Start the retention clock at the event, not at the filing. Seven years from the resolution, the meeting or the statement, whichever applies, set once at capture. That stops both failures at the same time: deleting early, and keeping everything for ever because nobody knows what is safe to remove.
  5. Hold access at the business, not at a person. Credentials, keys and certificates stored with the records, per rule 6(b), so a departure or a lost phone does not take the archive with it.
  6. Test the retrieval on a schedule. Once a quarter, pick a record at random and produce it, timed. Ten business days is the target. This is the only one of the six that tells you the truth about the other five, and it takes an afternoon.

None of that requires a new department. It requires that the filing step stop being a separate act of discipline performed after the work, and start being part of how the document arrives. That is the whole change, and it is the difference between a compliant archive and a folder everyone is afraid of.

Frequently Asked Questions

Is a scanned copy enough, or must I keep the paper?

A scan can be enough. Section 30 of the Tax Administration Act permits electronic form as prescribed by the Commissioner, and the 2012 public notice sets those rules. The catch is rule 5.5: a conversion from paper must have its own separate record of how and when it happened.

Can I keep my company records in cloud storage outside South Africa?

Not by default for tax records. Rule 4.1 of the SARS notice requires electronic records to be kept at a place physically located in South Africa. Rule 4.2 allows an offshore location, but only with authorisation from a senior SARS official and five conditions satisfied.

How long must a South African company keep its records?

Seven years under section 24(1)(b) of the Companies Act, or longer where another public regulation says so. Most of the section 24(3) records run their own seven year clock from their own event, such as the date a resolution was adopted, not from the filing date.

How quickly must I produce records when someone asks?

Section 26(5) of the Companies Act currently allows 14 business days for a request made in the prescribed manner. The Companies Amendment Act 16 of 2024 replaces that with 10 business days and widens it beyond the register, once that provision is proclaimed.

Do I need written documentation of my filing system?

Only if it is custom. Rule 5.1 of the notice exempts platforms commonly recognised in South Africa. If your system was built or adapted for you, rule 5.4 requires a written description covering seven specific things, including a data dictionary.

Where to start

If reading the six mechanisms above produced a quiet feeling that your own filing would not survive a ten day request, that is worth testing rather than worrying about. Pick one document from three years ago and try to produce it, with proof of who sent it and when.

If that takes longer than an afternoon, the problem is not discipline. It is that the filing step sits outside the work instead of inside it. A business autopsy maps where documents actually enter your business and where they stop being findable. If you would rather start with a conversation, book a discovery call.

Related reading on this site: CIPC annual returns for the filing obligations that depend on these records, the POPIA compliance checklist for the personal information sitting inside them, workflow automation for small business for how the capture step gets built, and the business compliance checklist for where this fits in the wider set of obligations.

Sources

  • Companies Act 71 of 2008, sections 24, 25 and 26.
  • Companies Amendment Act 16 of 2024, sections 3 and 4.
  • Electronic Communications and Transactions Act 25 of 2002, sections 14, 15 and 16.
  • Tax Administration Act 28 of 2011, sections 29, 30 and 31.
  • Government Notice 787, Government Gazette 35733, 1 October 2012, on the electronic form in which records must be held, Schedule rules 3 to 7.

Book a free strategy call →