BSI TR-03138 Practical Guide

Implementing Compliant Substitute Scanning per BSI TR-RESISCAN

The complete guide with templates, checklists and case study

Chapter 1: Introduction — Why TR-RESISCAN?

Substitute scanning refers to the process of digitising paper documents in such a way that the digital copies carry the same evidential value as the originals. The paper originals can then be destroyed. BSI TR-03138 (TR-RESISCAN) defines the framework that makes this process legally sound.

Legal basis: BSI TR-03138

The Technical Guideline TR-03138 of the German Federal Office for Information Security (BSI) specifies the organisational and technical measures required for substitute scanning. Courts and regulatory authorities reference it as the benchmark for proper digitisation. Organisations that work in compliance with TR-RESISCAN create the prerequisites for legally destroying paper originals after scanning.

Who needs substitute scanning?

  • Tax advisors and auditors: The GoBD (Principles of Proper Accounting and Documentation) require proper digitisation of tax-relevant documents. TR-RESISCAN supplements the GoBD with evidential value preservation.
  • Government agencies and public administration: The eGovernment Act promotes the digitisation of administrative processes. TR-RESISCAN provides the technical framework for legally compliant implementation.
  • Law firms and notaries: The Code of Civil Procedure (ZPO) places high demands on the evidential value of documents. TR-RESISCAN-compliant scanning ensures that digital documents are recognised as evidence.
  • Healthcare: Patient records, findings and referrals are subject to strict retention requirements. Substitute scanning reduces space requirements without jeopardising the duty to provide evidence.

Benefits at a glance

  • Space savings: Physical archives occupy valuable floor space. After destroying paper originals, rental and operating costs for archive rooms are eliminated.
  • Faster access: Digital documents can be found in seconds via full-text search, instead of searching through folders for minutes.
  • Compliance: A documented, traceable scanning process meets the requirements of auditors and tax inspectors.
  • Cost reduction: Less storage space, less manual search time, less paper handling — the savings add up quickly.

Chapter 2: Conducting the Protection Needs Analysis

The protection needs analysis is the first and most important step in the TR-RESISCAN process. It determines which security measures must be applied during scanning. Without a protection needs analysis, compliant substitute scanning is not possible.

What is a protection needs analysis?

In the protection needs analysis, each document type is assigned to a risk class. The classification is based on the potential consequences if the integrity, confidentiality or availability of the document is compromised. The BSI distinguishes three categories:

Protection Level Document Type (Examples) Requirements
Normal General business correspondence, invoices, delivery notes, internal memos Base module: user authentication, scan profile, visual inspection, transfer note, logging
High Contracts, personnel files, tax assessments, medical records, expert opinions Base module + integrity module: additionally digital signature, hash values, extended integrity verification
Very High Deeds, wills, land register entries, notarial documents DO NOT substitute! Original must be retained. Scan only as additional copy.

Important: Documents with very high protection needs must not be subject to substitute scanning per TR-RESISCAN. Deeds, wills, notarial documents and land register entries must always be retained in their original form. The digital image serves only as an additional working copy.

Template: Protection Needs Analysis

Use the following table as a starting point for your own protection needs analysis. Record all document types that arise in your organisation and assign a protection level to each:

Document Type Protection Level Measures Destruction Permitted?
Incoming invoices Normal Base module Yes
Contracts High Base + Integrity Yes
Personnel files High Base + Integrity + Confidentiality Yes
Notarial deeds Very High No substitute scanning No
[Your document type] [Enter] [Enter] [Enter]

Chapter 3: Scanner Qualification

Not every scanner is suitable for substitute scanning per TR-RESISCAN. Scanner qualification ensures that your devices reliably deliver the required image quality.

Scanner requirements

  • Resolution: Minimum 300 DPI, recommended 600 DPI for fine print and detailed drawings
  • Colour depth: 24-bit colour (also recommended for B&W originals to avoid information loss)
  • ADF quality: Reliable automatic document feeder without paper jams or double feeds
  • Double feed detection: Ultrasonic sensor for detecting multiple sheets fed simultaneously
  • Output format: PDF/A-1b or PDF/A-2b directly from the scanner

MFP vs. dedicated scanner

Multifunction printers (MFPs) can be used for substitute scanning if they meet the qualification criteria. However, dedicated document scanners often offer better image quality, higher speed and more reliable double feed detection. For organisations with high document volumes, a dedicated scanner is recommended as the primary scanning device.

10-point checklist for scanner qualification

No. Check Point Result
1 Resolution at least 300 DPI (recommended 600 DPI)? ☐ Met
2 24-bit colour scanning possible? ☐ Met
3 PDF/A output directly from device? ☐ Met
4 Double feed detection (ultrasonic)? ☐ Met
5 Test image: fine print (6pt) readable at 300 DPI? ☐ Met
6 Test image: colour fidelity with colour originals? ☐ Met
7 Test image: edge area fully captured? ☐ Met
8 ADF: 50-sheet stack without jam or double feed? ☐ Met
9 User authentication at device possible (PIN/card)? ☐ Met
10 Scan profiles centrally configurable? ☐ Met

Tip: Docuflair supports over 358 scanner and MFP models from leading manufacturers. Check the compatibility of your devices before procurement.

Chapter 4: Scan Profile Configuration

The scan profile defines the technical parameters for the scanning process. It is centrally configured and assigned to the respective protection level of the document. A correctly configured scan profile is the foundation for reproducible, quality-assured scan results.

Parameters overview

Parameter Recommendation Rationale
Resolution 300 DPI (standard), 600 DPI (fine print) 300 DPI is sufficient for most business documents. 600 DPI for fine print, technical drawings or documents with small details.
Colour mode Colour (24-bit) Colour scanning is generally recommended, even for B&W originals. Grey values, stamps and handwritten annotations are preserved.
File format PDF/A-1b or PDF/A-2b ISO standard for long-term archiving. Ensures documents remain readable even after years.
Compression JPEG2000 or lossless JPEG2000 offers a good balance between file size and quality. Lossless compression for particularly high protection needs.
OCR Always enable Creates searchable PDFs. Enables full-text search and machine readability (GoBD requirement).
Naming Automatic with date, document type, seq. no. Consistent naming facilitates archiving and later retrieval.

Practical tip: Create a separate scan profile for each protection level. For normal protection needs, a standard profile with 300 DPI and colour is sufficient. For high protection needs, create an extended profile with 600 DPI and lossless compression. This ensures that the correct settings are automatically applied.

Chapter 5: Visual Inspection

Visual inspection is a central component of the TR-RESISCAN process. It ensures that the digital document correctly and completely reproduces the paper original. Without documented visual inspection, substitute scanning is not compliant.

What is checked?

  • Completeness: Are all pages of the original document included in the scan?
  • Readability: Is all text clearly readable, including footnotes, stamps and handwritten annotations?
  • Page order: Does the page order match the original?
  • Orientation: Are all pages correctly oriented (not rotated or skewed)?
  • Colour reproduction: Are colours reproduced correctly (especially stamps, signatures, markings)?
  • Margins: Is the document fully captured without cropped edges?

Sampling or 100% inspection?

The scope of visual inspection depends on the protection level:

  • Normal protection needs: Sampling procedure (e.g. every 10th document) with documented sampling rate
  • High protection needs: 100% inspection of each individual document
  • Very high protection needs: No substitute scanning (retain original)

Inspection protocol template

Check Point Result Remarks
All pages scanned? ☐ OK   ☐ Rescan
Readability sufficient? ☐ OK   ☐ Rescan
Page order correct? ☐ OK   ☐ Corrected
Colour reproduction correct? ☐ OK   ☐ Rescan
Margins complete? ☐ OK   ☐ Rescan
Orientation correct? ☐ OK   ☐ Corrected

Documentation: Date, name of the inspector, document identifier and result of the visual inspection are recorded in the transfer note. Docuflair supports visual inspection directly on the MFP display (quick check) and as a detailed inspection in the web browser.

Chapter 6: Integrity Assurance

Integrity assurance ensures that the digital document cannot be altered undetected after scanning. It is the technical foundation for the evidential value of the digital document.

SHA-256 hash as proof of integrity

Immediately after the scanning process, a cryptographic hash value (SHA-256) is calculated over the digital document. This hash is like a digital fingerprint: even the smallest change to the document would produce a completely different hash value. By comparing the stored hash value with the currently calculated hash, it can be proven at any time that the document has remained unchanged since the scan.

When is the hash calculated?

The hash is calculated immediately after the scan, before the document is further processed, moved or archived. This timing is critical: it marks the earliest possible proof of document integrity. Any later calculation would leave a gap in the integrity proof.

Transfer note

The transfer note documents the entire scanning process and contains:

  • Who scanned (username, authentication method)
  • When was it scanned (date, time, time zone)
  • What was used to scan (scanner model, serial number)
  • Which settings were used (scan profile, resolution, colour mode)
  • Result of visual inspection (inspector name, inspection time, result)
  • Hash value of the digital document (SHA-256)

Cryptographic signature (optional)

For documents with high protection needs, TR-RESISCAN additionally recommends a cryptographic signature. It binds the hash value to a verifiable identity and makes the integrity proof even more robust. In practice, the signature is often implemented via a qualified electronic signature (QES) per the eIDAS Regulation.

How Docuflair ensures integrity: Docuflair automatically calculates SHA-256 hashes for every scanned document. The hashes are stored in a tamper-proof hash chain. The transfer note is automatically generated and attached to the document. Optionally, a cryptographic signature can be added.

Chapter 7: Creating Process Documentation

The process documentation is the central document that describes and evidences your entire scanning process. Without process documentation, TR-RESISCAN-compliant scanning is not complete. Auditors and tax inspectors regularly request it.

What belongs in the process documentation?

Per BSI requirements, the process documentation must contain at least the following chapters:

Sample structure (table of contents)

  1. Scanning concept — Objectives of substitute scanning, scope, responsibilities, roles involved
  2. Protection needs analysis — Classification of all document types by protection level (see Chapter 2)
  3. Scanner qualification — Proof of device suitability, test results, maintenance intervals (see Chapter 3)
  4. Scan profile configuration — Technical parameters per protection level: resolution, colour mode, format, compression (see Chapter 4)
  5. Process description — Step-by-step workflow from document preparation to archiving
  6. Visual inspection procedure — Inspection scope (sampling/100%), inspection protocol, escalation process for defects (see Chapter 5)
  7. Integrity assurance — Hash calculation, transfer note, optional signature (see Chapter 6)
  8. Staff training records — Who was trained when on the scanning process, participant signature
  9. Retention and destruction — Retention periods, destruction process, logging (see Chapter 8)

Practical tip: The process documentation is a living document. Update it whenever you change the process, add new scanners, modify protection levels or make organisational changes. Version the document and record every change with date and responsible person.

Chapter 8: Retention and Destruction

After compliant scanning, the question arises: how long must digital documents be retained and when may the paper original be destroyed?

Retention periods

Document Type Period (Germany) Period (Austria) Legal Basis
Accounting records, invoices 10 years 7 years HGB § 257, AO § 147 / BAO § 132
Commercial correspondence 6 years 7 years HGB § 257 / UGB § 212
Personnel files 3 years after departure 3 years after departure BGB § 195 / ABGB § 1489
Contracts 6–30 years (depending on type) 3–30 years (depending on type) BGB / ABGB (limitation periods)
Social insurance 5 years 7 years SGB IV § 28f / ASVG

Prerequisites for destroying the paper original

  • The scanning process was carried out in compliance with TR-RESISCAN
  • Visual inspection was performed and documented
  • The transfer note is available
  • The integrity of the digital document is secured (hash)
  • The document does not fall under an exception (see below)

Exceptions: never destroy these documents

  • Notarial deeds and certifications
  • Wills and inheritance contracts
  • Land register entries and extracts
  • Documents that must be presented in original form (e.g. citizenship certificates)
  • Documents where the original has intrinsic value (e.g. historical documents)

Documenting the destruction

The destruction of paper originals must be logged. The log contains: document identifier, destruction date, responsible person, destruction method.

Shredder requirements

For destroying confidential documents, a shredder conforming to DIN 66399 with at least security level P-4 (cross-cut, max. 160 mm² particle area) is recommended. For documents with particularly sensitive content (personnel files, medical records), security level P-5 or higher is advisable.

Chapter 9: Ensuring GoBD Compliance in Parallel

TR-RESISCAN and GoBD have different focal points but significant overlap. Organisations that consider both requirements together from the outset save effort and avoid redundancies.

Overlap between TR-RESISCAN and GoBD

Requirement TR-RESISCAN GoBD
Process documentation ✓ Mandatory ✓ Mandatory
Traceability ✓ Transfer note ✓ Audit trail
Integrity ✓ Hash / Signature ✓ Immutability
Orderliness ✓ Scan profile ✓ Proper recording
Machine readability — not required ✓ Mandatory
Evidential value preservation ✓ Core focus — not primary focus

Additional GoBD requirements

  • Machine readability: Tax-relevant documents must be machine-readable. This means: OCR is mandatory, and the data must be in a structured format that the tax authorities can process.
  • Timely recording: Documents must be recorded promptly after receipt (booking within 10 days).
  • Immutability: After recording, the document may no longer be altered. Changes must be logged as new versions.

Practical tip: Create a single process document that covers both TR-RESISCAN and GoBD. The overlap is so significant that a combined document causes less maintenance effort than two separate ones. Mark sections that are relevant only for TR-RESISCAN or only for GoBD.

Chapter 10: Case Study — Tax Advisory Firm with 50,000 Documents/Year

This case study shows how a mid-sized tax advisory firm implemented substitute scanning per TR-RESISCAN and achieved measurable results within one year.

Initial situation

  • Firm: 3 tax advisors, 12 staff, 200 clients
  • Document volume: approx. 50,000 documents/year (incoming invoices, bank statements, contracts, payroll documents)
  • Previous process: Documents sorted in paper folders, 2 rooms as physical archive, manual document retrieval
  • Problems: Long search times, high space requirements, missing documents, no full-text search, no GoBD-compliant archiving

New process with Docuflair

  1. Intake: Documents arrive by post and are scanned at the MFP
  2. Authentication: Staff member authenticates via chip card at the MFP
  3. Scan: Docuflair scan profile (300 DPI, colour, PDF/A-2b) is automatically applied
  4. OCR: Automatic text recognition creates searchable PDFs
  5. Visual inspection: Preview directly on the MFP display, detailed inspection in web browser when needed
  6. Transfer note: Automatically generated with all process information
  7. DATEV handover: Documents are automatically transferred to DATEV Unternehmen online
  8. Archiving: PDF/A documents stored in audit-proof archive
  9. Destruction: Paper originals are destroyed after successful visual inspection and archiving (P-4 shredder)

Results after 12 months

Metric Before After Improvement
Storage space 2 archive rooms (approx. 30 m²) 0.5 rooms (remaining historical stock) 70% less
Document retrieval Avg. 5 minutes per document Avg. 15 seconds (full-text search) 20x faster
Missing documents Avg. 3 per month 0 100% reduction
Compliance No process documentation GoBD + TR-RESISCAN compliant Fully compliant

ROI calculation

Item Amount/Year
Investment
Docuflair TR-RESISCAN licence €2,388
Device licences (3 MFPs) €2,100
DATEV interface €1,500
Setup and training (one-time, amortised) €3,000
Shredder (DIN 66399, P-4, one-time, amortised) €1,000
Archive server/storage €5,000
Total investment €15,000
Savings
Rent for archive rooms (30 m² × €12/m²) €4,320
Time savings document retrieval (200 hrs × €45) €9,000
Time savings filing/sorting (150 hrs × €35) €5,250
Paper, folders, labels €1,500
Avoidance of compliance risks (estimated) €5,000
Total savings €25,070
Net savings (year 1) €10,070

Case study conclusion: The investment pays for itself in the first year. From the second year onwards, one-time costs for setup and shredder are eliminated, increasing net savings to over €15,000/year. The decisive factor was achieving parallel GoBD and TR-RESISCAN compliance with a single process document.

Chapter 11: Conclusion and Next Steps

Substitute scanning per BSI TR-RESISCAN is not a bureaucratic obstacle, but a structured path to less paper, faster access and demonstrable compliance. Organisations that build the process systematically benefit from significant savings while maintaining legal certainty.

5 key takeaways

  1. Protection needs analysis first: Every compliant scanning process starts with classifying your document types. Without a protection needs analysis, there is no substitute scanning.
  2. Qualify scanners, don’t just buy them: A qualified scanner delivers reproducible results. Test your devices with the 10-point checklist.
  3. Document the visual inspection: The best scanning technology does not replace human verification. Document every inspection in the transfer note.
  4. Secure integrity from the start: Hash calculation immediately after the scan, not only at archiving. Any delay weakens the integrity proof.
  5. Implement TR-RESISCAN and GoBD together: A single process document for both requirements saves effort and avoids contradictions.

Ready for TR-RESISCAN-compliant scanning?

Docuflair TR-RESISCAN covers the entire substitute scanning process: from authentication through visual inspection to the automatic transfer note. Schedule a free demo and see how easy compliant scanning can be.

See it live in 15 min

No obligation & free
Start Demo