The complete ESA vendor record matrix
A folder full of PDFs is not automatically an audit trail. Each record has a different job. The matrix below separates identity, transaction, delivery, review and cash evidence so a reviewer—or your own staff—can follow the transaction without assumptions.
| Record group | Keep | What it proves | Common failure |
|---|---|---|---|
| Provider approval | Approval notice, provider ID, accepted categories, locations and effective dates | The business was authorized for the program and offering | Saving a portal login but not the approval scope |
| Business identity | Legal name, tax identity, address, payout account confirmation and changes | The invoice and deposit belong to the approved entity | Invoice name differs from portal or bank record |
| Credentials | License, certificate, attestation, background check or staff qualification when required | The rendering provider qualified for that service on that date | Only the practice credential is saved when an individual credential is required |
| Authorization | Family approval, purchase order, award/category approval or required preauthorization | The account holder and program permitted the expense | Assuming general eligibility equals approval for every charge |
| Invoice/order | Exact submitted version, number, issue date, line items, service dates, units, rates and total | What the provider asked the program to pay | Overwriting the submitted file after a correction |
| Delivery evidence | Attendance/service log, delivery confirmation, fulfillment record or category-specific support | The billed product or service was actually delivered | Treating the invoice itself as proof of delivery |
| Submission/review | Portal reference, timestamp, attachments, status changes, requests and decisions | What the reviewer received and how the decision developed | Saving only the final approval and losing the correction request |
| Payment | Approved gross amount, adjustments, fees, payout ID, payment date and bank deposit | The approved amount reconciled to actual cash | Marking paid from a portal status without matching the deposit |
| After payment | Refund, credit, cancellation, chargeback, duplicate resolution or appeal outcome | The final financial result, not just the first payment event | Leaving an open credit disconnected from the original invoice |
Records change with the payment path
“Paid with ESA funds” can describe several workflows. Do not use one checklist blindly. Identify the payment path first, then preserve the evidence that path creates.
Direct provider payment
Link the provider invoice to the family’s approval, portal transaction, review decision, payout reference and deposit. If the family initiates Pay Vendor, preserve the provider’s submitted document and the reference the family returns.
Family reimbursement
The provider normally supplies an invoice and, after payment, a separate receipt. The family controls the reimbursement request. Keep your commercial record, but do not claim a family reimbursement is approved until the program says so.
Marketplace/order
Preserve the approved listing or SKU, order, fulfillment or service evidence, status, cancellation/refund events, marketplace adjustment and net payout. Match listing identity to what was actually delivered.
ClassWallet describes DirectPay as connecting users directly with approved service-provider vendors and describes reimbursement as a submission-to-payment workflow for participants and vendors. Its public materials also emphasize invoice scanning, line-item categorization, supporting documentation and status visibility. Those platform capabilities do not replace the underlying program’s eligibility and documentation rules. See the ClassWallet vendor guide for the state-versus-platform distinction.
A filing system that answers the audit questions
Organize around the transaction, not the file type. A single invoice record should point to the provider, student or account, program, expense category, payment mode and deposit. If invoices live in one folder, service logs in another and deposits in a spreadsheet with no shared identifier, the provider has documents but not a traceable record.
Use a stable identifier
Give each invoice or order a unique identifier and carry it through the filename, portal note, correction, payout reconciliation and internal record. Never use a student’s full name as the only identifier in a broadly shared filename. A practical pattern is program-invoice-number-document-type-version-date.
Use explicit statuses
Separate drafted, submitted, held, rejected, corrected, approved, paid, partially paid, refunded and closed. “Done” hides who owns the next action. A held request needs information; an approved request may still await a deposit; a paid portal item still needs reconciliation.
Keep a source register
For every operational rule, record the program, document or official URL, section, verification date and the decision it controls. Rules change. A dated source lets staff distinguish “this was valid when submitted” from “this is the current requirement.” GetESAPaid’s rules verification log provides official starting points, but the named program remains authoritative.
Corrections need version history, not silent replacement
When a reviewer requests a change, preserve the evidence of both the original decision and the remedy. Save the original submitted document read-only. Create a new revision with a new version label, record the requested correction, identify the fields or attachments changed, and tie the new submission confirmation to that revision. If the invoice number itself must change, link both numbers.
- Capture the exact reason. Save the portal message, email or case reference. Do not paraphrase it into a generic “rejected.”
- Diagnose the smallest valid correction. Determine whether the problem is identity, eligibility, category, line-item detail, date, credential, proof of payment, arithmetic or workflow.
- Create a revision. Preserve the original file and make the changed version obvious. Record who made the change and when.
- Prevent duplicate payment. Follow the program’s correction path rather than creating an unrelated second charge for the same service.
- Close the loop. Save the final decision and reconcile the correct approved amount to the deposit.
The same principle applies to cancellations, refunds and partial approvals. A complete history explains the final amount without editing away the earlier events. The authenticated GetESAPaid workspace preserves invoice versions, attachments, correction reasons, submission checks and reconciliation as one chain.
Keep enough evidence without creating a privacy problem
Payment documentation can contain student names, account-holder details, addresses, service dates and professional credentials. Therapy and disability-related services can also tempt staff to attach clinical detail that the payer did not request. Apply data minimization: include the information the authorized recipient needs to decide and pay the transaction, and keep unrelated educational, clinical or family information in its proper protected system.
Usually appropriate in the payment record
- Provider and approved business identity
- Student/account identifiers required by the program
- Service/product, date, units, rate and total
- Required credential and educational purpose
- Submission, decision, correction and payment evidence
Keep elsewhere unless specifically required
- Clinical session narratives and treatment notes
- Unrelated diagnoses or assessment results
- Other students’ or customers’ records
- Staff identity documents beyond the authorized need
- Passwords, shared login credentials or complete bank credentials
Restrict access by role, not convenience. Staff who create invoices may not need bank administration; bookkeepers may not need clinical records; outside contractors should not inherit access to every student. Review access when staff roles change, preserve backups, and test restoration rather than assuming a synchronized folder is a complete backup.
How long should ESA vendors keep records?
There is no reliable one-number answer for every ESA vendor. A retention period can come from the state program, payment platform agreement, provider participation agreement, tax rules, professional licensing rules, privacy obligations, insurance contract, dispute window or another law. These clocks may not match.
Use a retention schedule that names the record class, controlling source, trigger date, minimum period, deletion hold and owner. The trigger matters: invoice date, service date, payment date, end of award year, contract termination and age of majority can produce different results. If two applicable rules conflict, obtain qualified advice and document the decision. Do not copy a retention number from a different state or provider type simply because it appears in a search snippet.
Deletion is part of record keeping. When the authorized retention period ends and no audit, dispute, refund, tax or legal hold applies, dispose of records securely and consistently. Keeping sensitive student information forever “just in case” increases exposure without necessarily improving compliance.
How to answer an ESA record request or audit
Start by preserving the request and deadline. Identify the program, account, transaction range, requested fields, submission channel and person responsible. Freeze routine deletion for the affected records if needed. Then build a response index before sending files.
- Confirm scope. Clarify ambiguous dates, programs or record categories through the official support path.
- Export the transaction index. List invoice/order, student or account reference, service period, amount, status and deposit reference.
- Attach the evidence chain. Provider approval, authorization, exact invoice, delivery evidence, review trail, correction history and payout.
- Check completeness. Recalculate totals, verify files open, confirm dates and remove unrelated records accidentally included.
- Transmit securely. Use the named portal or approved channel, not an improvised public link or a staff member’s personal account.
- Save what was sent. Preserve the response package, timestamp, recipient, confirmation and subsequent questions.
Do not “clean up” history by altering an old submitted invoice. If an error exists, explain it through a dated correction or response note. An honest, traceable correction is stronger evidence than a document whose history cannot be explained.
The 30-minute monthly ESA records close
Small providers reduce audit work by closing records while the service and payment are still familiar. At month end, review every open invoice and marketplace order.
- ✓ Every delivered service has a matching log or fulfillment record.
- ✓ Every submitted invoice has an immutable submitted copy and portal reference.
- ✓ Held and rejected items have a named owner, reason and next action.
- ✓ Approved items are reconciled to gross amount, fees, adjustment and bank deposit.
- ✓ Credentials and approval dates have renewal reminders before expiry.
- ✓ Access, backups and deletion holds are reviewed for material changes.
Turn the checklist into a working record
Keep invoices, evidence, corrections and payouts in one traceable workspace
GetESAPaid ties the state rule source, submission preflight, private attachments, immutable versions and payout reconciliation to the invoice—so the record is built during the work instead of reconstructed for an audit.
Six visual checks
The audit-ready ESA record chain in six visuals
Use these as a sequence: verify the source, pass every eligibility layer, confirm the expense, assemble the packet, follow the transaction status, then match the deposit. Each visual summarizes a separate decision and the official program still controls.
ESA vendor record-keeping FAQ
What records do ESA vendors need to keep?
Keep the approved provider identity and credentials, the exact invoice submitted, line-item and service evidence, family or portal authorization, supporting attachments, submission confirmation, review messages, correction history, payout reference, fees, refunds and the final bank deposit. The program and expense category can require additional records.
How long should an ESA vendor keep records?
There is no single national ESA retention period. Preserve the complete transaction while it can still be reviewed, corrected, audited, refunded or disputed, then follow the longest applicable state-program, tax, contract, licensing and privacy requirement. Record the source and review date for the rule you apply instead of relying on a generic online number.
Can ESA vendor records be digital?
Usually, a controlled digital copy is the most practical working record, but the program decides acceptable formats. Keep files readable, searchable where possible, backed up, access-controlled and tied to the correct invoice. Preserve an original submitted version rather than repeatedly overwriting one file.
Does an invoice count as proof that a service happened?
Not by itself. An invoice asks for payment. A service or attendance log supports that the billed session occurred, while a receipt or bank record may prove that money moved. Keep the documents linked but do not treat them as interchangeable.
Should I keep student diagnoses or clinical notes with an ESA invoice?
Only when an authorized program specifically requires that information and your privacy obligations permit it. Use data minimization: keep payment evidence with the invoice and richer educational or clinical records in the appropriate protected system. More sensitive detail is not automatically better evidence.
What should I do when an ESA invoice is corrected?
Keep the original submitted invoice, save the corrected version as a new revision, record what changed and why, preserve the review message that requested the change, and make the final paid version obvious. Never silently replace the only copy of a submitted document.
How do I prepare for an ESA vendor audit?
Start with a transaction index, then produce the requested provider approval, invoice, supporting service or fulfillment evidence, authorization, submission confirmation, corrections and payout reconciliation. Respond to the stated request rather than exporting every student or customer record.
What is the easiest ESA filing system for a small provider?
Use a stable record per invoice or order with links to the student, program, payment path and bank deposit. Standardize filenames, statuses and required attachments; review open items monthly; and restrict staff access by role. A binder should answer who, what, when, why, approval and payment without reconstruction.
Method and official starting points
This guide separates an invoice, delivery evidence, review history and payment because official program and platform workflows treat them as different artifacts. Requirements vary by program and category. The links below are primary starting points; use the handbook, participation agreement and portal instruction that governs the actual transaction.
Start with a working register
Download the blank and completed invoice tracking templates →Product walkthrough
Match a payment CSV to an invoice
Import a fictional payment allocation and check the linked invoice history.
Recorded in the application with fictional records and synthetic narration. No real payments or program submissions are made.