Skip to main content

Bank statement extraction software: checks for accountants

By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026 · 7 min read

Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.

Short answer

Bank statement extraction software reads PDF or scanned bank statements and turns each transaction into a row. Before choosing one, check five things: a balance check (opening balance plus extracted lines equals closing balance), an exceptions list, a member of staff approving entries before they post, where the data is processed, and how long it is kept.

This page is for UK accounting practices that receive client bank statements as PDFs or photographs and are choosing software to read them. It matters now because Making Tax Digital for Income Tax started on 6 April 2026 for sole traders and landlords with qualifying income over £50,000, who keep their records in compatible software and send quarterly updates. While building Filyst, our case management product for immigration firms, we made the server reject an approval by the person who did the work; the approval step below follows the same rule. The sections cover what the software does, the checks to ask for, approval, Xero, where data goes, data protection impact assessments (DPIAs) and retention.

What is bank statement extraction software?

Bank statement extraction software is a tool that reads a bank statement and turns each transaction (date, description, money in, money out and running balance) into structured rows that an accounting system can import. It is also called a bank statement converter.

In the workflow on this page, AI reads the statement layout, and rules then test the extracted rows against the statement’s own totals. A member of staff approves the result before anything reaches the ledger.

Bank statement extraction with a balance check and staff approvalSix steps: the client uploads a statement as a PDF or photo; AI extracts each transaction; a balance check confirms that the opening balance plus the extracted transactions equals the closing balance; any line that fails a check goes to an exceptions list; a member of staff approves or corrects the result; and approved transactions post to the ledger with a log entry.UploadPDF or photofrom the clientExtractAI reads eachtransactionBalanceOpening + lines= closingExceptionsFailed checksflaggedApproveStaff accept orcorrectPostTo the ledger,with a log
The balance check flags missed or misread amounts before a person looks.

What should you check before choosing a tool?

Check five things before choosing bank statement extraction software: how it proves the numbers, how it shows failures, who approves, where the data goes and how long it is kept. The table gives the question to put to each supplier. We do not compare named products here, because we have not tested them.

CheckQuestion to ask the supplierWhy it matters
Balance checkDoes the tool reconcile opening balance plus extracted lines to the closing balance, and flag statements that fail?An unbalanced statement means a missed, doubled or misread amount
Exceptions listAre failed lines shown first, beside the statement image?The reviewer's time goes to the lines that need it
Staff approvalCan a member of staff approve or correct entries before they post, and is each approval logged with a name and time?Xero bank transactions have no draft status, so approval has to come before posting
Where data goesWho processes the statements, in which countries, using which sub-processors, under what written contract?UK GDPR Article 28 sets what the supplier contract must cover
Retention and deletionHow long does the tool keep statement images and extracted rows, and will it delete or return them when the contract ends?UK GDPR Articles 5(1)(e) and 28(3)(g)

How does the software prove the extracted data is right?

The software proves the extraction by testing the rows against figures printed on the statement itself. The balance reconciliation is the main test: the opening balance, plus credits, minus debits, must equal the closing balance. The other four tests narrow down where an error sits.

CheckRuleCatches
Balance reconciliationOpening balance + credits − debits = closing balanceMissed, doubled or misread amounts
Running balanceEach line's balance follows from the previous lineThe exact line where an error starts
PeriodEvery date falls inside the statement periodMisread dates and wrong-year entries
PagesPages read = pages in the documentSkipped pages
DuplicatesNo transaction already imported from an earlier statementOverlapping uploads

What should happen to lines that fail a check?

Lines that fail a check go to an exceptions list, which the reviewer sees first, beside the statement image. A clean statement needs a quick check; the reviewer’s time goes on the exceptions.

The running-balance check points to the first line where the balance stops following, which is where to start. Every correction and approval is logged against the client file.

Who approves the entries before they post?

A member of staff approves extracted transactions before they post. Where that person corrected lines, we recommend a second person approves them. In Filyst, the server rejects an approval by the person who did the work, and the same four-eyes rule suits corrected bank lines.

For practices on Xero, where the approval happens matters. Xero’s Accounting API bank transactions endpoint, the interface that software uses to write spend and receive money entries into Xero, accepts three statuses for a bank transaction in Xero’s published API specification: AUTHORISED, DELETED and VOIDED. There is no DRAFT status for bank transactions, although invoices and bills can be DRAFT or SUBMITTED. A tool that writes bank transactions to Xero therefore cannot leave them waiting for approval inside Xero, so the approval has to happen in the tool’s review screen before posting. How approved data then reaches each client organisation, and what the API costs, is covered in Xero API limits and integration for practices.

Where does the statement data go?

Statement data goes to the tool supplier, who processes it on the practice’s behalf as a processor under UK GDPR, the UK’s data protection law. The practice is the controller, the party that decides why and how the data is used. UK GDPR Article 28 sets four duties that apply here:

  • Article 28(1): the controller uses only processors providing sufficient guarantees of appropriate technical and organisational measures;
  • Article 28(2): the processor engages another processor (a sub-processor) only with the controller’s prior written authorisation;
  • Article 28(3): a binding contract sets out the processing and requires, among eight points, that the processor acts only on documented instructions, including on transfers to a third country, and deletes or returns the data at the end of the service (28(3)(g));
  • Article 28(9): the contract is in writing, which includes electronic form.

Data minimisation also applies: Article 5(1)(c)requires personal data to be “adequate, relevant and limited to what is necessary” for the purpose. Send the tool the statements the job needs, not the whole client file. The full list of contract terms is in what a UK GDPR Article 28(3) processor contract must say.

Does an AI extraction tool need a DPIA?

Plan for one. The Information Commission, the UK data protection regulator that took over from the Information Commissioner on 30 September 2026 and still publishes as the ICO, requires a DPIA when AI is combined with a high-risk criterion, and highly personal financial data is one of those criteria.

A DPIA, sometimes called a privacy impact assessment, is the review UK GDPR requires before processing that is likely to result in a high risk to individuals. The ICO list of high-risk processing, which is marked as under review after the Data (Use and Access) Act 2025, says that for innovative technology, “including AI”, a DPIA is required where it is combined with any criterion from the European guidelines (ICO, When do we need to do a DPIA?).

One of those criteria is “sensitive data or data of a highly personal nature”. The European guidelines, known as WP248, give “financial data that might be used for payment fraud” as an example. We read bank statements, which hold account and payment details, as falling within that example, so an AI tool reading them meets the ICO’s test. Article 35(1), quoted on the ICO page, requires the assessment “prior to the processing”. When a DPIA applies and what it contains is set out in DPIA for AI tools: when a UK firm needs one.

How long must bank statements be kept?

Bank statements are part of the accounting records, so HMRC’s record-keeping periods apply to them. The period depends on the client’s business type. GOV.UK’s company records guidance names bank statements among the records a limited company must keep.

WhoHow longLonger when
Limited companies6 years from the end of the last company financial year they relate toThe records show a transaction covering more than one accounting period; the company bought something it expects to last more than 6 years; the Company Tax Return was sent late; or HMRC has started a compliance check into the return
Sole traders and partnersAt least 5 years after the 31 January submission deadline of the relevant tax yearIf the return is sent more than 4 years after the deadline, keep records for 15 months after sending it

The company rule and its four extensions are on GOV.UK, Company and accounting records; the sole trader and partner rule is on GOV.UK, How long to keep your records. The tool supplier’s own copies are a separate question: Article 5(1)(e) (storage limitation) requires personal data to be kept in identifiable form for no longer than the purpose needs, which is why the deletion terms in the checklist matter.

When is an off-the-shelf tool enough?

An off-the-shelf tool is enough when the practice only needs statements read and pushed to the ledger, and the tool passes the five checks above. A custom workflow suits practices where extraction feeds other steps, such as onboarding or Making Tax Digital records, or where the practice wants its own checks and approval log.

Bank statement extraction is one use of AI in a practice; the wider picture, including which tasks suit AI and where a person signs off, is in AI for accountants in the UK: safe uses and review steps. How we build connected systems for practices is on software for accounting practices.

Frequently asked questions

How accurate is AI bank statement extraction?

Accuracy varies by document, so test every statement with rules: opening balance plus extracted transactions must equal the closing balance, and a member of staff approves the result before anything posts.

Should extracted transactions post automatically?

No. A member of staff approves them first, with each approval logged. In Xero, bank transactions have no draft status, so the approval happens in the extraction tool before posting.

How long must a limited company keep bank statements?

At least 6 years from the end of the last company financial year they relate to, and longer in some cases, for example a late Company Tax Return or an open HMRC compliance check.

Does using AI on client bank statements need a DPIA?

Plan for one. The ICO's list requires a DPIA where AI is combined with a high-risk criterion, and the European guidelines give financial data that might be used for payment fraud as an example of highly personal data.

Sources

  1. GOV.UK, Company and accounting records
  2. GOV.UK, How long to keep your records (self-employed)
  3. UK GDPR Article 5 (principles), legislation.gov.uk
  4. UK GDPR Article 28 (processor), legislation.gov.uk
  5. ICO, When do we need to do a DPIA?
  6. Article 29 Working Party, Guidelines on DPIA (WP248 rev.01)
  7. Xero, Accounting API: Bank Transactions
  8. Xero, Accounting API OpenAPI specification (BankTransaction status)
  9. GOV.UK, Check if you're eligible for Making Tax Digital for Income Tax
  10. HMRC, Quarterly updates for Making Tax Digital

Start with two weeks and £950.

You get a map of your systems and a fixed price to fix them. If you build with us, the £950 comes off.