TLDR: The R&D Tax Incentive is self-assessed, so you attach no evidence when you register. But if AusIndustry reviews your activities or the ATO reviews your expenditure, you carry the burden of proof, and the records must be contemporaneous: created at or near the time the work happened.
You need two record sets: activity records proving the s 355-25 test for each core activity, and expenditure records tying every claimed dollar to a registered activity. Keep both for at least five years from lodgement.
What the law actually requires
Division 355 does not contain a standalone list of documents you must keep. Instead, the record keeping obligation falls out of two places: the general business record keeping rules the ATO administers, and the practical reality that s 355-25 of the ITAA 1997 requires you to demonstrate an experimental activity that meets a four-part test.
Section 355-25(1) requires activities "whose outcome cannot be known or determined in advance on the basis of current knowledge, information or experience", determined only by a "systematic progression of work" that "proceeds from hypothesis to experiment, observation and evaluation, and leads to logical conclusions", conducted for the purpose of generating new knowledge.
Every one of those phrases is a documentary requirement in disguise. A hypothesis you cannot date is not evidence of a systematic progression. A knowledge gap with no prior-art search behind it is an assertion.
The ATO's guidance on the R&D tax incentive and the AusIndustry material on business.gov.au both put it the same way: you must be able to show that the registered activities occurred and that the claimed expenditure related to them.
What "contemporaneous" means in practice
Contemporaneous means the record existed while the work was happening, or immediately after it. Not reconstructed at registration time, not assembled the week before a review.
The tribunals are unambiguous on this. In Absolute Vision Technologies [2022] AATA 2319, documents prepared after the fact for an internal review were not accepted as contemporaneous, and there was marked discord between the records and the activities as registered. Amending a deficient registration with documents produced well after the income year is unlikely to succeed.
Royal Wins Pty Ltd [2020] AATA 4320 goes further: with no contemporaneous documentation that a hypothesis was developed or tested, the activities were ineligible regardless of how much work had actually been done.
A useful test: could a reviewer verify the date from the system that produced the record, rather than from your say-so? Git history, ticket timestamps, email headers, lab notebook entries and payroll exports pass. A Word document titled "R&D narrative FY25" does not.
For a broader survey of which artefacts count as evidence across a claim, see contemporaneous evidence for a defensible R&D claim. This article stays on the record keeping requirements themselves and how long you have to hold them.
Two record sets, two regulators
R&D claims are assessed by two agencies with different questions, so your records need to answer both. Activity eligibility sits with Industry Innovation and Science Australia and its delegates at AusIndustry. Expenditure and the offset sit with the ATO.
| Dimension | Activity records | Expenditure records |
|---|---|---|
| Regulator | AusIndustry / IISA | ATO |
| Question answered | Did this meet s 355-25? | Was this spend on that activity? |
| Typical artefacts | Prior-art searches, hypothesis notes, test protocols, results logs, evaluation notes | Time logs, payroll, invoices, contracts, apportionment workings |
| Failure mode | No documented knowledge gap or hypothesis | No nexus between cost and registered activity |
A claim can survive an AusIndustry review of activities and still be adjusted by the ATO on expenditure, or the reverse. Build both sets.
Activity records: proving each core activity
Map your evidence to the limbs of the test, and note when each piece must exist. Timing is what separates usable evidence from decoration.
| Test element | Evidence that proves it | Must exist |
|---|---|---|
| Outcome unknown in advance | Prior-art, literature and patent searches; expert statements that current knowledge cannot determine the outcome | Before the activity starts |
| Purpose of new knowledge | Project plans, meeting records, expenditure approvals stating the R&D purpose | At planning or start |
| Hypothesis | Dated note or experimental plan stating the hypothesis and its basis | Before experiments |
| Experiment | Test protocols specifying variables varied, held constant and measured; CRO or research contracts | Before or during |
| Observation | Raw data logs, trial run records, test reports, timestamped issue-tracker entries | During |
| Evaluation and conclusions | Analysis notes, test reports with interpretation, records of negative results and the next hypothesis | During or after each cycle |
| Supporting-activity nexus | Records showing direct relation to a named core activity, plus dominant-purpose rationale where required | Throughout |
The two records most companies are missing
The pre-activity prior-art search and the dated hypothesis. Both must predate the work, which means neither can be manufactured later.
Active Sports Management (2023) put it plainly: the contemporaneous formation of a hypothesis is the essential starting point of the activities. Trial and error with no isolable variables, "we tried a few things until it worked", is not a repeatable, verifiable experiment.
GQHC [2024] AATA 409 adds the quality bar. Hypotheses must be scientific, specific and capable of being validated or invalidated. Vague commercial aims failed. Observation and evaluation must be evidenced, not asserted, and maintaining adequate documentation is itself part of the systematic progression.
Records for clinical and behavioural R&D
Health-tech claims often carry their uncertainty in the outcome, not the code. If the open question is whether your intervention measurably shifts a symptom score, your record set is the trial protocol, the ethics submission, the pre-stated endpoint, the randomisation or allocation records, and the statistical analysis plan.
The pre-specified endpoint also matters for exclusions. A structured study measuring a clinical or behavioural endpoint against a pre-stated hypothesis is not market research, even when it runs on A/B infrastructure. The same experiment measured on conversion, churn or revenue is excluded under s 355-25(2)(a).
Expenditure records: proving the dollars
The ATO's question is narrower and more mechanical: for each claimed dollar, which registered activity did it relate to, and how did you work out the amount?
Core expenditure records:
- Time records. Payroll data plus a record of hours or percentage of time each employee spent on each registered activity, split core versus supporting.
- Apportionment method. A written explanation of how you separated R&D from non-R&D time and cost, and why the method is reasonable.
- Contractor documentation. Contracts and invoices describing the R&D work performed, not just "consulting services".
- Associate payments. Proof of cash payment by the end of the income year. Accrual alone does not make an associate amount claimable in that year.
- Overheads and depreciation. The allocation basis for apportioned overheads and the extent-of-use working for depreciating assets.
In Tier Toys and Ozone Manufacturing, two decisions the ATO cites in its own guidance, the absence of contemporaneous records meant the taxpayer could not show that the R&D expenditure was anything more than normal business expense. That is the shape of the expenditure failure: not a dispute about eligibility, a dispute about whether the money can be traced.
Worked example: what weak apportionment costs
A base-rate entity with aggregated turnover under $20M claims a $180,000 engineer at 60% R&D time, giving $108,000 of notional R&D deductions. At the refundable rate of 43.5% (the 25% company tax rate plus 18.5 percentage points), that is a $46,980 refundable offset.
On review, the company has no time logs, only a retrospective estimate. The ATO accepts 30% based on the limited artefacts available. Notional deductions fall to $54,000 and the offset to $23,490.
The activity was identical in both scenarios. The $23,490 reduction in the offset is purely a record keeping outcome, before any interest or penalties.
How long do you need to keep R&D records?
At least five years from the date you lodge the return containing the claim, consistent with the general ATO record keeping rules for business. Keep them longer if a review, amendment or objection is on foot, and until it is finally resolved.
Two practical consequences. First, the retention clock is long enough that engineers who did the work will have left, so records must be self-explanatory without them. Second, if you migrate issue trackers or repositories, export the history rather than losing the timestamps that make it evidence.
Records mapped to the registration form
The AusIndustry registration in the online customer portal (current form version released 15 August 2025) is a field-by-field questionnaire structured as projects, then core activities, then supporting activities. A core activity is not one narrative. It is split across separate fields, each with its own character minimum.
| Registration field | The record behind it |
|---|---|
| Sources investigated | Prior-art, literature and patent search results, dated before the activity |
| Why a competent professional could not know the outcome | Expert statements, literature gaps, background research |
| Hypothesis | Dated experimental plan or note stating the hypothesis |
| Experiment | Test protocols, run sheets, commits and tickets covering the build and test cycles |
| Observation | Raw results, logs, test reports |
| Evaluation and conclusions | Analysis notes, including negative results and the next hypothesis |
| New knowledge | Comparison of the conclusion against the pre-existing state of knowledge |
Draft each field to its own requirement, and point it at evidence that already exists. If a field has no record behind it, that is the gap to fix, not a prompt for better prose. See how to document R&D activities for AusIndustry for the drafting detail.
Registration itself is due 10 months after the end of the income year, 30 April for a 30 June year end. It is a hard statutory deadline and registration must precede claiming the offset. See registration deadlines.
Common record keeping failures
The same handful of failures recur across every sector and every decided case.
- No literature or prior-art review. Without it there is no demonstrated knowledge gap, which was fatal in Absolute Vision Technologies.
- A commercial goal dressed as a hypothesis. "Build a faster pipeline" is not capable of validation or invalidation. GQHC rejected exactly this.
- Records that do not match the registration. If the registered activity says one thing and the tickets say another, the discord itself is a finding.
- Missing observation and evaluation. Companies record what they built and never record what they measured or concluded.
- Estimated time with no underlying source. A spreadsheet of percentages with nothing beneath it.
- Volume without allocation. Thousands of commits with no allocation to a named core activity is volume, not evidence.
One caution on precedent: Moreton Resources Ltd v ISA [2019] FCAFC 120 read "experimental activities" broadly, so applying existing technology at a new site or in a new context can qualify and novelty of context can support eligibility.
Coal of Queensland [2021] FCAFC 54 is the counter-precedent. Applying known methods without a genuine unknown outcome and a documented systematic progression still fails, so Moreton is never a free pass on the four-part test or on the evidence behind it.
A minimum viable record keeping system
You do not need a document management programme. You need six habits that produce dated artefacts as a by-product of the work.
- Open each core activity with a written knowledge gap. One page: what we searched, what we found, what remains unknown, the hypothesis, how we will test it. Date it, store it where it cannot be silently edited.
- Tag work to the activity, not the sprint. Use a label in the issue tracker so every ticket and pull request carries its core activity identifier.
- Write the result into the ticket. What was measured, what the number was, what you concluded, what you tried next. Two sentences at close is enough.
- Log R&D time weekly. Employee, hours, activity, date, linked to the work item. Weekly beats a June reconstruction by an enormous margin.
- Keep negative results. An abandoned approach with a recorded reason is some of the best evidence you will ever have of a genuine unknown outcome.
- Reconcile once a quarter. Do the registered activities still match what the team is actually doing? Split or merge streams while the year is open, not after it closes.
This is where tooling earns its place. Rand builds the claim from the engineering and clinical evidence a team already generates, mapping commits, tickets and time logs to registered core activities so the nexus exists before anyone asks for it.
Retrofitting records after the year has closed
If the year has closed and the records are thin, you are not automatically out. You are, however, limited to what already exists.
What you can legitimately do: mine existing artefacts (commit history, tickets, design documents, emails, test outputs, invoices, calendar entries), reconstruct a defensible time apportionment from those artefacts, and write a dated note explaining the method and its basis. Label estimates as estimates.
What you cannot do: create documents and present them as if they were written at the time. That is the exact conduct that failed in Absolute Vision Technologies, and backdating carries consequences well beyond a denied claim.
Be realistic about the result. Retrofitted records will support a narrower claim than contemporaneous ones would have. Scope the registration to the activities the surviving evidence can actually carry, and fix the system for the current year.
Checklist by claim stage
| Stage | Records to have in place |
|---|---|
| Before an activity starts | Prior-art and literature search, statement of the knowledge gap, dated hypothesis, experimental plan, project plan showing R&D purpose |
| During the year | Timestamped tickets and commits tagged to the activity, test protocols and results, weekly time logs, contractor invoices describing R&D work, ethics or trial protocol documents where relevant |
| At year end | Associate amounts paid in cash, apportionment method documented, cost allocation table tying spend to each activity |
| At registration (by 30 April for a 30 June year) | Per-field content for each core activity, each pointing to existing evidence, supporting activities grouped and linked to a named core activity |
| On review | Consolidated evidence pack per activity, reconciliation between registration wording and underlying records, apportionment workings |
For what actually triggers a review and how the process runs, see ATO R&D tax incentive reviews. For the classification question that determines which records you need, see core versus supporting activities, and for engineering artefacts specifically, using GitHub commits as evidence.
Record keeping is the part of the R&D Tax Incentive that cannot be fixed at the deadline. If your evidence is generated as a by-product of the work rather than assembled in April, the claim is far easier to defend. That by-product approach is what Rand automates.
This article explains the rules; it is not tax advice, and your own circumstances will determine what applies.
