Selling across Europe with the OSS makes life simpler: a single quarterly return instead of registering for VAT in every country. But there’s a part few sellers think about until the letter arrives: keeping your records and making them available in case of an audit.
In this article we look, in plain terms, at what a “SAF-OSS” is, how long you must keep the data, and how tax export and GDPR export let you be ready for an audit without a last-minute scramble.
What is the “SAF-OSS”
SAF stands for Standard Audit File: put simply, a structured file that collects tax data in a format the authority can read and verify. Some countries have the SAF-T (Standard Audit File for Tax), which the tax office can request during audits.
For the OSS there is no single official, mandatory “SAF-OSS” imposed at European level the way SAF-T is. When people say SAF-OSS they mean, in practice, the audit file of your OSS transactions: the ordered set of records you must be able to produce electronically if asked.
In short: you don’t need a magic format, you need complete, consistent records that can always be exported.
The obligation many forget: 10 years of retention
Anyone using the OSS (and IOSS) must keep transaction data for 10 years from the end of the year in which the transaction took place, and make it available electronically on request from the tax authority of the Member State of identification or of consumption.
Translated for a seller:
- it’s not enough to have filed the quarterly return;
- you must be able to rebuild and re-export the data even years later;
- and you must do it quickly and in a usable format, not with scattered files or ones you can’t find.
This is where tidy management makes the difference between a routine check and weeks of stress hunting for old reports.
What an audit-ready OSS ledger must contain
A “healthy” OSS ledger contains, for each transaction, at least:
- the reference period;
- the Member State of consumption (where the customer is);
- the transaction type (sale, return, refund, credit note);
- the taxable base and the rate applied;
- the VAT amount due in that country;
- the reconciliation of returns, refunds and credit notes against the original sales.
And, as a safety net, the original marketplace files (Amazon VAT Transaction Report, eBay/Shopify exports): they’re the source everything derives from and the strongest proof of traceability.
How VATManager keeps you “audit-ready”
The idea is simple: the data should already be tidy before anyone asks for it. With VATManager you have three tools that work exactly towards this.
1. OSS reports and ledgers always to hand
The OSS Report aggregates sales by state and rate, and the VAT Ledgers (sales, purchases, receipts) keep the various transaction types separate. They’re the documentary basis of your audit file: you can regenerate them for any past period.
2. Tax archive export with an integrity “seal”
From Account → Privacy, the tax archive export returns the retained evidence — including the original imported files — in a single package. The key point: the operation generates a receipt with a digital fingerprint (SHA-256 hash) and the export date.
That hash is like a seal: it proves the exported content is exactly that and hasn’t been altered. It’s ideal to keep alongside your documents, or to hand to your accountant.
3. GDPR export: your portable copy
Also under Account → Privacy, the GDPR export (right to data portability) gives you a complete, machine-readable copy of all your data, with a list (manifest) of what it contains and a content hash. It’s designed for you — to move your data or keep a copy — but it’s also an excellent tidy backup of your history.
Note: the tax export requires you to have unlocked your vault (sensitive data is encrypted), and the two exports have different purposes — one is the archive of tax evidence, the other is GDPR portability of your data.
The “audit-ready” checklist
- The OSS reports for each quarter are saved and re-downloadable.
- You keep the original marketplace files (not just the aggregates).
- Returns, refunds and credit notes are reconciled with sales.
- You’ve run the tax archive export at least once and kept the receipt with hash.
- You have an up-to-date GDPR export copy as a backup.
- You know where these files are and could hand them over the same day.
Tick every box and a possible request from the authority becomes a half-hour task instead of an emergency.
📎 Learn more: SAF-T: what it is and when it concerns an e-commerce seller — Data retention and GDPR for tax reports — How to prepare your accountant for the OSS return — Quarterly OSS export: an operational checklist. See also the docs on Data export (GDPR and tax) and the OSS Report.
Frequently asked questions
How long must I keep OSS records? 10 years from the end of the year in which the transaction took place, with the obligation to make them available electronically on request from the tax authority.
Is there an official, mandatory SAF-OSS format? No, not a single format imposed EU-wide the way SAF-T is in some countries. The obligation is to keep structured, complete records and be able to export them electronically. “SAF-OSS” is the practical name for this audit file.
Is VATManager’s export valid as evidence in an audit? It’s supporting material: the tax archive export includes a SHA-256 hash that certifies its integrity. The formal assessment during an audit remains up to the authority and your adviser.
This article is for information only and does not constitute tax advice. For your specific situation, consult your accountant.