The scene is familiar: the accountant sends an urgent email asking for last quarter's supplier invoices, and the manager spends the next few hours digging through folders, emails and drawers. It's not a personal-organisation problem. It's an operational one.
This article covers the four pillars of a working document system: categorising by type and retention period, distinct rules for physical and digital filing, approval flows with traceability, and compliance with the legal requirements that apply in Portugal. At the end, two concrete paths to get started.
The real cost of disorganised documents
The problem isn't having a lot of documents. It's not having a system to manage them. When documents reach the accountant in disorder, the cycle is always the same: delays produce late filings, which produce fines, which produce more time lost fixing the problem. In most cases the accountant does not handle operational document management — they do the accounting with whatever they receive. Responsibility for handing it over organised sits, as a rule, with the company.
The less visible costs fall into three areas. Physical space, with filing rooms and cabinets that carry a direct cost and an opportunity cost. Retrieval time: finding one specific invoice from two years ago can take hours, and the cost of that hour is the salary of whoever spent it searching. And the impact of mistakes caused by outdated versions — a revised contract that never replaced the old one, an old quote used as a reference, a paid invoice logged as outstanding.
How to categorise documents by type and retention period
Good categorisation is the foundation of everything. Without it, the best software on the market fixes nothing. The starting point is classifying by function, not format. A Portuguese SME typically needs five categories:
- Financial and accounting: purchase and sales invoices, receipts, bank statements, reconciliations.
- Tax: VAT and corporate tax returns, employee income-tax filings, payment slips to the tax authority and social security.
- Employment: employment contracts, payslips, holiday and absence records, hiring and termination documents.
- Commercial and contractual: contracts with clients and suppliers, accepted quotes, insurance policies.
- Corporate: articles of association, minutes, commercial registry filings.
Each category carries a different legally mandated retention period. For tax and accounting documentation, the period is ten years from the end of the calendar year they relate to, under the Corporate Tax Code and the VAT Code. For correspondence and commercial documentation, the Commercial Code likewise points to ten years. On the employment side, certain documents carry a five-year period after the contract ends. Identification documents gathered for anti-money-laundering purposes are subject to seven years, under Law no. 83/2017. There is no single period: it always depends on the nature and purpose of the document.
Naming convention
For categorisation to work, standardising file names from the start is essential. A simple convention such as type_date_entity — for example, invoice_20260101_supplierX — makes searching easier and removes ambiguity. Applying it from the moment a document is received is what separates a usable system from a folder with hundreds of files in no apparent order.
Physical and digital filing: different rules for each medium
Digitising does not remove filing obligations. The two media follow different rules, and can coexist as long as the rules are clear.
For physical filing, good practice is simple: chronological order within each category, clear labelling of boxes and folders with year and document type, and a centralised location index — which can just be a spreadsheet. What matters is that anyone can find any document without relying on a colleague's memory. Permanent documents should be physically separated from those with a defined disposal date.
Electronic filing and the requirements of Decree-Law 28/2019
For electronic filing, Decree-Law 28/2019 sets the conditions for dematerialised invoices and tax documents to carry evidentiary value: provable authenticity, verifiable integrity and guaranteed legibility throughout the whole retention period. In practice, that means scanning at adequate resolution, applying optical character recognition to make content searchable, and standardising names with a consistent convention. Metadata — document type, date, owner and status — is essential for traceability, and logging who scanned it and when is indispensable for audit purposes.
When volume is high, a dedicated document-management system may be justified, especially useful once the team is above five people or documents move across several departments. For smaller volumes, a well-defined process with shared folders and tracking sheets is just as effective, with no implementation cost.
Approval flows and version control
Without a defined flow, documents circulate by email, messages and shared folders with no control. When an audit or an urgent external request arrives, reconstructing the history turns out to take a long time.
For an SME, a three-layer model is enough: creation or receipt, validation, filing. For each stage, you need to define who is responsible, the maximum response time, and where the document moves next. No specialised software is required: a shared folder with subfolders by status, combined with a tracking spreadsheet, covers most situations as long as the rules are written down and followed.
For contracts and documents subject to revisions, version control is essential. Naming should include the version number and replacement date, previous versions should be archived, and a record of who approved each version should be kept. For documents with personal data, GDPR requires accountability mechanisms and, depending on the processing involved, maintaining records of processing activities — which makes logging approvals a compliance requirement, not just good practice.
Legal requirements to meet in Portugal
Any document holding data on employees, clients or suppliers is subject to Regulation (EU) 2016/679 (GDPR) and Portuguese Law no. 58/2019. That implies four concrete obligations:
- Having a lawful basis to keep the data.
- Limiting the retention period to what is strictly necessary.
- Applying security measures against unauthorised access.
- Carrying out secure destruction once the legal period ends.
Secure destruction is not deleting a file. It is guaranteeing the data cannot be recovered on any medium: paper, digital files, backups and internal shares. For paper, shredding suited to the risk level. For files, deletion has to cover backups and secondary locations too.
Where to start: an internal pilot or an operational partner
There are two practical paths to structure this without stalling the business.
Internal pilot. Pick a single high-volume category, such as supplier invoices, and define the full flow: receipt, validation and filing. Run a four-to-eight-week trial, measuring concrete metrics — average retrieval time, documents processed per week, errors found. Only expand once it's validated. Starting small avoids the trap of building a complex system nobody uses.
Operational partner. Outsource the function on a retainer. Many SMEs don't need document-management software if they have someone taking on the function entirely. This is the model Zelo works in: keeping document organisation running day to day, making sure documents reach the accountant in order and within deadline, and delivering a monthly report on the state of the operation.
It doesn't demand complexity, it demands a clear process
The four pillars are simple to state: categorising by type and retention period, distinct rules per medium, approval flows with defined owners, and compliance with legal deadlines. The difficulty isn't in understanding what to do. It's in doing it consistently, month after month, without depending on any one person's memory.
It's the same demand that shows up in month-end close and in what documents to send your accountant: what sets companies apart isn't knowing — it's keeping it up.