Nigeria’s tax authority may generally raise an additional or revised assessment within six years where a person was under-assessed or not assessed.
An audit begun before the deadline can continue beyond it, while deliberate misstatements remove the ordinary time limit and make durable records essential.
Six Years Can Outlast Business Memory
FinPolNomics Green Finance originated the Tax & Transfer Pricing Nugget for this explainer, which highlights Nigeria’s six-year additional-assessment window and the practical case for extended record retention.
Sustainable Stories Africa applies its Metrics and Insights & Data standards by separating the general limitation period, the continuing-audit exception and the unlimited exposure attached to deliberate misstatement.
The central lesson is institutional. A tax position may be questioned after employees leave, systems change, or businesses restructure, so the evidence must remain longer than the people who prepared it.
The Six-Year Assessment Window Has Important Exceptions
Section 36 of the Nigeria Tax Administration Act 2025 allows the tax authority to assess or raise an additional assessment when it discovers that a taxable person was not assessed or was assessed for less than the proper amount.
The general limit is six years from the relevant assessment.
The clock does not automatically end an audit already in progress. If an audit started before the six-year period expired, it may continue and produce an assessment after the period. A company cannot safely destroy the supporting records merely because the calendar crossed the sixth anniversary while questions remained open.
A further exception applies where there is a deliberate misstatement in a return.
- In that situation, the ordinary limitation does not protect the taxpayer; the authority may assess at any time and as often as necessary.
- Intent therefore changes the duration of exposure, not only the severity of an immediate dispute.
The FinPolNomics recommendation to keep records for at least seven years is a prudent operational buffer.
- The statutory recordkeeping provision generally speaks of retaining books for at least six years after the relevant year of assessment, which can span roughly seven calendar years depending on timing.
- Open audits and special rules may require longer retention.
The period should be calculated for each assessment and issue rather than by a single generic expiry date.
- Amendments, related assessments and different tax types may have different timelines.
- A central statute-of-limitations register should show the basis for every date and identify matters that remain open because an audit began in time.

Time Often Weakens Evidence Before Tax Liability
A six-year exposure is difficult because business context decays.
- Staff move, vendors close, email accounts are deleted, software is replaced, and transaction descriptions lose meaning.
- The tax law may still permit an assessment when the organisation can no longer reconstruct why a decision was made.
Documents alone are not enough if they cannot be linked.
- A contract, invoice, payment and tax treatment should share a transaction identifier or indexed file path.
- Without that connection, the company can spend weeks rebuilding an audit trail that once existed implicitly in several employees’ inboxes.
Judgment files require particular care.
- Transfer pricing, deductibility, exemptions, valuations and revenue timing often depend on facts that do not appear in the ledger.
- A short memorandum prepared when the transaction occurs can be more reliable than a lengthy explanation reconstructed five years later.
Digital preservation should include readable formats and system context.
- Exported data needs field definitions, exchange-rate sources, code tables and reconciliation totals.
- Retaining an inaccessible backup tape does not create usable evidence.
Third-party records can disappear even when the taxpayer’s archive is sound.
- Important supplier confirmations, valuation reports and platform statements should be downloaded and stored when created.
- Contracts should require service providers to supply historical data for a defined period and to cooperate with lawful audit requests after termination.
Acquisitions and disposals need specific retention planning.
- A buyer may inherit historical exposures without inheriting the people or systems that created them, while a seller may still need access to records after a business unit transfers.
- Transaction agreements should allocate custody, access, cooperation and costs for the full tax review period.
Data rooms should preserve final versions and indexes rather than become temporary project sites that disappear after closing.
Record Retention Supports Governance And Business Resilience
A strong retention framework starts with risk, not storage volume.
- Tax returns, computations, financial statements, invoices, contracts, approvals, payment proof, related-party documentation and correspondence should be grouped by assessment year and entity.
- High-risk transactions can have longer schedules than routine records.
Legal holds must override normal deletion.
- Once an audit, objection, appeal or investigation begins, relevant records should be preserved until the matter and all related periods are finally closed, even if the normal schedule has expired.
The same discipline strengthens wider resilience.
- Records support insurance claims, anti-fraud investigations, grant reporting, sustainability metrics and due diligence during financing or acquisition.
- Tax retention can become part of an enterprise evidence architecture rather than a separate archive.
Data minimisation still matters.
- Companies should not keep every personal detail indefinitely merely because a tax file exists.
- Retention should preserve what the law and legitimate business needs require while applying security, access and deletion controls to unnecessary sensitive data.
Retention costs should be compared with dispute costs.
- Secure digital storage is usually cheaper than recreating six years of evidence under an assessment deadline.
- A mature policy reduces duplicate copies while preserving the authoritative record, allowing the business to control cost without sacrificing defensibility.
The policy should also address physical originals.
- Some instruments, certificates or stamped documents may carry evidential value that a scan cannot fully reproduce.
- Store them securely, link them to the digital index and record any authorised movement.
- For ordinary records, high-quality digital copies may be sufficient under applicable rules, but the company should confirm format requirements before destroying originals.
Consistency matters more than a crowded storeroom: every retained item should be findable, protected and connected to the relevant assessment year.
Build Records That Survive Staff Turnover
Set a written policy with a seven-year minimum operational period for core tax records, subject to longer statutory requirements and open-matter holds.
Map each record class to an owner, a system and a destruction trigger.
Create an annual tax archive immediately after filing.
- It should contain the final return, payment proof, signed accounts, calculations, reconciliations, elections, legal opinions and significant transaction files.
- Use checksums, permissions and tested backups to protect integrity.
Run retrieval tests.
- Ask a person who did not prepare the return to locate and explain a sample of material transactions from several years earlier.
- The time taken and gaps found are practical retention metrics.
Finally,
- Connect departures and system migrations to tax preservation.
- Exit procedures should transfer decision context, while technology projects should export historical data with documentation before legacy systems are retired.
The evidence must outlive organisational change.
Boards should receive an annual attestation covering retention compliance, open legal holds, failed backups and planned system retirements.
Significant gaps need remediation budgets and owners.
- The test is not whether a policy exists, but whether the organisation could produce a complete file promptly when the NRS asks.
Path Forward – Preserve The Story Behind Every Number
The six-year rule is a minimum planning horizon, not a signal to delete records automatically. Audits in progress and deliberate misstatements can extend exposure.
A seven-year operational policy, supported by legal holds and tested retrieval, gives companies a better chance of defending the facts when institutional memory has moved on.
EDITOR’S DATA NOTE
This explainer provides general public-interest information. They are not legal, tax, investment or accounting advice. Readers should verify current law, Gazette orders and NRS guidance and obtain advice for specific facts.
The Act’s general six-year window can be extended by an audit begun before expiry. Deliberate misstatement removes the ordinary time limit. Record destruction should always be suspended for open matters.
LEGAL NOTE: General editorial information only. Tax outcomes depend on current law, guidance and specific facts; obtain professional advice before acting.