Skip to main content
Audit and records retention

NetSuite Audit and Records Retention: Keeping Transactions Producible After the Account Closes

An audit request for a closed year arrives long after the people who posted the entries have moved on, and often after the NetSuite account has been switched off. This page sets out what an archive has to hold to answer an auditor or a tax inquiry from source records, how you show it is complete, how an outside reviewer is given their part of it and nothing else, and what we do not do. It draws on archives we have delivered for audit and retention since 2023.

The obligation outlasts the account

Whatever period you and your advisers have set for keeping financial records, the requests that test it come from outside: an auditor examining a closed period, a tax authority asking about an old filing, a counterparty disputing an invoice. Each needs a transaction, the posting behind it and the document that supports it, produced together. Judge each way of holding NetSuite history by that test.

A reading room of bound ledgers with one lamp lit, the records of a closed year still readable when the auditor asks for them

Keep a NetSuite account open to read it

The records stay where they are, visible to the people with seats, for as long as the licence renews. The renewal continues for data nobody enters, and the history cannot be handed to a buyer, a former subsidiary or a successor system without the account. How that cost is shaped is on the caretaker licence cost page.

Keep the exports you took on the way out

A folder of CSV files proves that you kept something. It fails the moment an auditor asks for the posting behind an invoice or the document attached to it: relationships are lost in the flattening, custom records are commonly missed, and nobody can run a trial balance from a folder.

Extract into a hosted, read-only archive

The records, their relationships and the attachments are extracted once, verified against the source and hosted where finance, auditors and advisers can search, report and export without a NetSuite licence. Records cannot be modified after the archive is finalised; the data stays yours and exportable. This is what we deliver, with AcroXtract for the extraction and DBVault for the access.

What the archive has to hold to answer an auditor

An auditor does not ask for a table. They ask for one transaction, then for everything that explains it, and an archive built for audit answers each layer from the records themselves.

1 · The transaction, with its lines

The invoice with its line items, the vendor bill with its expenses and linked purchase orders, the payment with the invoices it was applied against, the journal entry with every line. Sublists survive as sublists.

2 · The ledger posting behind it

The archive holds the GL impact of every transaction: the accounts, subsidiaries and periods it posted to, and each accounting book where Multi-Book is in use. It is what lets a trial balance for a closed year be produced from the archive rather than rebuilt in a spreadsheet.

3 · The document that supports it

File Cabinet files keep their folder structure and stay attached to their records, so the signed contract or the supplier's PDF opens from the transaction it supports.

4 · The context around it

Customers, vendors, employees and subsidiaries; the chart of accounts, items, departments, classes and locations; custom records as named record types of their own, including sets a SuiteApp created, which is where manual exports most often fall short.

5 · The history of changes

System Notes and audit trails, so a change made years ago can still be explained. Availability differs by record type, so they are named explicitly in the agreed scope rather than assumed.

An archive atrium with galleries of bound ledgers on every level, each volume where an auditor would expect to find it

What the archive preserves

Relationships: a transaction resolves to its entity, its lines and its posting.

GL impact per transaction, by subsidiary, period and accounting book.

File Cabinet attachments, linked to their records.

Custom records and custom fields alongside the standard types.

Records that cannot be modified after finalisation.

Snapshots and CSV exports, so the data can leave.

The period is yours to set

How long the records must be kept is decided by you and your advisers, not by us: requirements differ by jurisdiction and industry, and we do not review or classify the contents of your records. What we provide is an archive hosted for the period you decide, as a subscription, with the data exportable if that period ends.

How you show an auditor the archive is complete

The first question an auditor asks of an archive is how you know it matches the account it came from. A matching row count proves that rows arrived, not that the values are right, the relationships survived, or inactive records and custom fields were included. Verification runs in layers, and the last layer is your own team's.

A trial balance for a closed year laid out on a desk, produced from the archive after the ERP that recorded it was switched off

Automated comparison against the source

Extracted records are compared against the source account at the database level, not by a spot count, as the fifth step of every AcroXtract engagement. Where a count differs, the cause is looked for before anything is treated as missing: filters, inactive records, permissions, or records that changed during the extraction.

Reconciliation your team can run

Because the GL impact is held, your finance team can run the trial balance and general ledger from the archive for a closed period and set them beside the statements you filed, by subsidiary and accounting book. It is the check an auditor understands without explanation.

Relationships and attachments, tested

Transactions still resolve to their entities and lines, and File Cabinet documents open from their records. During validation your team works the archive against the questions an auditor actually asks, each issue raised as a ticket against the archive under test and tracked until resolved.

Checks for an export you already hold

If you already hold an export, the checks that catch a gap are in How to verify a NetSuite export is complete.

Giving an auditor access without giving them everything

Once finalised, the archive is hosted read-only on DBVault, and the second audit question follows the first: who can see what, and can you prove who saw it. The answer is a mechanism.

A named profile for the engagement

An auditor's access is set through a named restriction profile; the product's own guidance calls its example "Auditor - Read Only Access". It limits which archives they can open, which record types, which File Cabinet folders and which subsidiaries, each as an allow list or a deny list; archives outside the profile are not shown. It does not limit by date; the auditor filters what they can see by period.

Files reached only through records

Direct browsing of the File Cabinet can be switched off for the profile, so a document is reachable only as an attachment on a record the auditor may already see. Someone given access to look up invoices cannot wander the document store.

Logged, and administered by you

Login events and download history are kept inside the platform, so who opened the archive and who took what out has an answer. Your administrator invites the auditor, assigns the profile and removes the access when the engagement ends; sign-in uses multi-factor authentication, with single sign-on available.

What this does not do

Restrictions apply to viewer roles; administrators cannot be restricted. Saying so removes a discovery from the vendor assessment.

It does not load data back into NetSuite or into a successor ERP; where a migration is running, we supply the data in CSV or MySQL form to the team doing the load.

It is cloud-hosted only; there is no on-premises option, and workflows locked in the NetSuite user interface are not part of a data archive.

It provides the records and the controls, not an audit or legal opinion; whether an archive satisfies a particular audit procedure or retention rule is for you and your advisers to determine.

Situations in this family

The sections above are the answer these situations share; what differs is the trigger, the boundary and the proof.

Financial audit evidence

Auditors will ask for old transactions, GL posting detail, approvals and attachments after NetSuite is gone. The job is to answer with traceable source records rather than reconstructed spreadsheets, with the auditor's access controlled.

Tax inquiries and statutory retention

The records must stay accessible for the period your advisers determine, long after operational use ended. The job is to separate that retention from the cost and upkeep of a live ERP: a hosted archive for the period you decide, with the data exportable.

Change control for an ERP migration

Before approving the archival step, compliance teams ask for the extraction procedure, the validation evidence, the security assurance and the access-control model. Each has something current behind it: the six-step process, the ticketed validation period, the ISO 27001 certification and SOC 2 Type II report, and the profiles above.

Auditor self-service access

External auditors find records themselves instead of asking finance or IT to run searches, through a viewer profile scoped to their engagement, with logins and downloads logged and your administrator in control.

Validating the extraction

Project and compliance teams ask how counts, accuracy, files and custom records were checked before NetSuite access was lost: automated comparison against the source, then your own validation period. The verification step is on the AcroXtract page; the checks for an export you already hold are in the verification guide.

Backup evidence for a SOC 2 audit

Where NetSuite stays live and the question is whether backups ran, that is a different service: an independent off-site copy of the live account, taken on a schedule, described on the continuous backup page.

When to start, and what the cost is shaped by

Start from the earlier of two dates: the day the account closes and the renewal you intend not to pay. Verification needs the source account open, so the extraction and your team's validation both sit inside that window, and a delta extraction picks up what changed if people are still working in NetSuite during the first pass.

The extraction is sized on what the AcroXtract sizing form collects: database size, File Cabinet size and user count. Hosting on DBVault is a subscription for the period you decide, with no source-system licence to renew and no per-report charge; the comparison with an account kept open only to be read is on the caretaker licence cost page.

To start we need access to the account, a contact who knows its customisations, the date it will close, and who will need the records afterwards and for how long. If data entry has already stopped, say so: a single full extraction may be all it needs.

Archives kept for audit and retention since 2023

All case studies

Each of these organisations left NetSuite or retired an account and kept its history for audit or record retention. The write-ups describe what was extracted, how it was confirmed and how it is used.

Questions asked about audit and retention after NetSuite

How long do we have to keep NetSuite records after we leave?

That is for you and your advisers to decide; requirements differ by jurisdiction, industry and contract. What we see is that retention obligations are commonly measured in years. The archive is hosted for the period you decide, and the data stays exportable as snapshots and CSV, so the records do not depend on the subscription continuing.

Can Blueacrobat certify that the archive meets our retention or audit requirements?

No, and no vendor can without your legal and regulatory context. We preserve the data to an agreed scope, verify it against the source and provide the controls on this page. Whether that satisfies a particular rule or audit procedure is for you and your advisers; we provide the technology and the support, not a legal or audit opinion.

What will an auditor be able to see, and how do we limit it?

Your administrator creates a restriction profile scoped to the archive, subsidiaries, record types and File Cabinet folders the engagement covers, switches off direct file browsing, and assigns it when the auditor is invited. Nothing outside the profile is visible. Within it they can search by document number, transaction number, entity or memo, open the attachments on those records, run the financial reports and export what they may see as CSV, with logins and downloads logged so you can answer who looked at what.

How do we show an auditor that the archive is complete?

With verification and your own validation. Extracted records are compared against the source at the database level, relationships and attachments are checked, and your finance team then works the archive against real questions, each issue ticketed against the archive under test and tracked to resolution. A trial balance run from the archive for a closed period can be set beside the statements you filed.

Can the archive produce a trial balance for a closed year?

Yes. The archive holds the GL impact of every transaction, so financial statements run from the archived data: trial balance, balance sheet, income statement, general ledger and transaction detail, with audit reports such as the transaction journal, period comparison and reversals. Multi-Book accounting is supported. A custom report built in NetSuite is not reproduced automatically; the reports you rely on are confirmed during scoping and tested during validation.

Are System Notes and approval history included?

They are named explicitly in the agreed scope rather than assumed, because what is accessible differs by record type. Where accessible they come across with the records, and your validation period is where you confirm they answer the questions you expect.

Where is the archive hosted, and what assurance can we give our security team?

On AWS in a supported region, read-only, with encryption at rest and in transit and multi-factor authentication; single sign-on is available. Blueacrobat holds ISO 27001 certification and a SOC 2 Type II report, supplied through your security review. The detail is on the trust centre.

Plan your NetSuite audit and retention archive

Tell us who will ask for the records, when the account closes and how long you have decided to keep them. We will walk through what the archive would hold, how completeness is shown, and how an auditor's access is scoped and logged.

Thank you for your inquiry.

One of our representatives will be happy to get back to you within one business day.
Oops! Something went wrong while submitting the form.
SOC 2 Type II badge