Audit Preparation:

EROMoENZQATEC

Track Record

100% Audit Clearance Rate
Expert Advisory Services
Nationwide Coverage

Audit Success.
Engineered.

We identify compliance gaps before the regulators do. Specialist forensic auditing for New Zealand's education sector.

ECE Record Retention in a Cloud World

by IntegrityReady | Jun 8, 2026 | Early Learning Sector

Your cloud system is a black box. If an auditor can’t pull a clean, verifiable attendance record for any day in the last 7 years, your funding is at risk, your tax compliance is questionable, and your board is exposed.

7 years. That’s the anchor. The ECE Funding Handbook, the Tax Administration Act 1994, and Inland Revenue’s SPS 21/02 all converge on a single, non-negotiable retention period for the records that underpin your funding claims and tax obligations. Yet in the rush to cloud-based attendance, enrolment, and staffing systems, many services have outsourced their memory to vendors whose terms of service, data migration plans, and backup procedures are rarely scrutinised at board level.

The Audit Trigger

Auditors are trained to look for the cracks. They probe for inconsistent timestamps—attendance edited days later with no audit log. They compare roll reports, enrolment records, and funding claims, hunting for gaps that reveal manipulated or incomplete data. They ask for historic records after a software migration and watch for the silence that follows. The smoking gun? A cloud system that cannot produce a complete audit trail for each child’s attendance and each staff member’s hours over the full 7-year period. When that happens, the Ministry of Education is entitled to treat all funding claimed during that time as unreliable. The result: clawback.

The Regulatory Hook

The ECE Funding Handbook is explicit: records must meet two tests—integrity (complete, unaltered, protected against unauthorised changes) and usability (locatable, retrievable, preserved, interpretable). The Handbook also requires that electronic attendance systems meet the criteria in chapter 6-3. Separately, Inland Revenue’s SPS 21/02, issued under the Tax Administration Act 1994, demands that electronic records be secure, backed up, and capable of being retrieved into legible hard copy. Critically, business records must be kept in New Zealand unless the Commissioner authorises offshore storage. Use overseas cloud software without a local backup or documented IRD approval, and you are in breach. The Privacy Act 2020 adds another layer: children’s information must be stored safely, accessed only by authorised personnel, and securely disposed of when no longer needed. BYOD habits that put records on personal phones, USB sticks, or unencrypted laptops undermine every one of these obligations.

Director Action Point

“Ask the CEO: Can our cloud provider export a complete, unaltered attendance and staffing record for any date in the last 7 years, and is that data stored in New Zealand with a documented backup and recovery procedure? If the answer is ‘I think so,’ you have a governance gap.”