Administrative8 min read

Statute of limitations for training providers: up to ten years in fraud cases

Creators of French training organizations (OF) often ask the same question once their activity is up and running: for how long can an invoiced training session still be inspected? The answer just changed. Law n° 2026-534 of 25 June 2026 on combating social and tax fraud — already known for its new administrative sanctions regime and for tightening the grounds for cancelling the NDA — also extends the period during which the administration can reopen an old case. Here is what this means in practice for your archiving and evidence management.

The rule: a three-year statute of limitations

First, it’s worth distinguishing the statute of limitations for control from the plain retention period for administrative documents (see our article on document retention periods). The statute of limitations is the time window during which a control body — DREETS, a CPF funder, an OPCO — can lawfully reopen a training session already delivered and invoiced, to check its compliance, claim a refund, or impose a sanction.

This principle, unchanged by the 25 June 2026 law, remains a three-year period. That’s the “standard” duration applying to the vast majority of situations: a poorly documented session, incomplete attendance evidence, a miscalculated funding rate. Three years after the action was delivered, in principle, the administration can no longer reopen it.

The exception: ten years for fraud or repeated breaches

This is where the 25 June 2026 law changes the picture. According to the legal analyses available so far on this 115-article law — about fifteen of which directly concern professional training and apprenticeship, in the wake of the DGEFP circular on 2026-2027 control priorities — the statute of limitations can now be extended to ten years where fraudulent schemes, repeated breaches, or irregularities that could not have been detected within the normal three-year window are found.

Concretely, a training session invoiced in 2026, if fraud were later established, could in theory remain subject to inspection until 2036. Legal commentators indicate that the measure applies to statute-of-limitations periods expiring on or after 26 June 2026, the day after the law’s publication — meaning it can reach back to sessions predating that date, as long as their standard three-year period had not yet expired. The precise implementing rules, however, still need to be confirmed by forthcoming decrees and administrative guidance: on such a recent topic, caution is warranted before drawing definitive conclusions for any specific case.

Why this measure isn’t just a theoretical tightening

Extending a control period only has a deterrent effect if the providers concerned actually adjust their record-keeping practices — otherwise the measure would remain toothless against files that are already poorly documented. This is exactly what a reference study on the topic shows: Raluca Pavel, Bernur Acikgoz, Jean-Christophe Poudou and Marc Willinger, in “Statute of Limitations for Tax Evasion”, published in 2025 in the journal Kyklos, ran a laboratory experiment varying the length of the tax statute of limitations (0, 1, 3 and 6 years). Their results confirm that a longer statute of limitations improves reporting compliance, by raising the cumulative probability that a given period will eventually be inspected — exactly the logic the legislator applied to professional training (see the study). The practical takeaway for a training provider is direct: the longer the statute of limitations, the more ongoing documentary rigor becomes a protective measure in itself, not just a one-off requirement at Qualiopi audit time.

What this actually changes for your organization

Three practical consequences to factor in now:

  1. Timestamped electronic archiving becomes a habit, not an option. For sessions funded by public or pooled funds (CPF, OPCO, apprenticeship, France Travail) — still the priority target of inspections under the February 2026 circular — keeping evidence beyond the usual three years is a reasonable precaution: attendance sheets, agreements, required Qualiopi documents, evidence of engagement in distance learning.
  2. Good-faith correction remains protective. The law targets fraudulent schemes and repeated breaches, not an isolated error corrected in time. A documented corrective action plan, even a belated one, demonstrates the absence of fraudulent intent.
  3. Regulatory monitoring becomes evidence in itself. Tracking the implementing decrees for this law falls directly under the legal monitoring expected at indicator 23 of Qualiopi — a provider able to show it has followed this issue strengthens its position in the event of an inspection.

How to secure your organization starting now

  • Identify your most exposed sessions: those funded by CPF, an OPCO, or delivered under apprenticeship contracts, the priority targets under the DGEFP 2026-2027 circular.
  • Set up dated digital archiving, distinct from a plain paper binder, for the most sensitive records (attendance, assessments, distance-learning tracking evidence).
  • Don’t let any identified non-conformity linger: a gap corrected within the certifier’s deadline stays, by construction, outside the scope of the “repeated breaches” targeted by the law.
  • Regularly check on the implementing decrees for the 25 June 2026 law, particularly those that will clarify the practical details of the extended statute of limitations.

Take action

Rigorous document management remains the best protection against this extended statute of limitations. The Complete Kit Certif (€297, 14-day guarantee) provides the evidence templates and the legal-monitoring log for indicator 23, to build a solid file year after year. If you’re starting your activity, the ebook “Create your training organization in 30 days” (€67) sets out good archiving practices from the moment you file your activity declaration, and the Complete Pack (€347) bundles both resources.

FAQ

Frequently asked questions

+What is the "délai de reprise" for a training provider?

It's the period during which the administration (DREETS, funding bodies) can go back over a training session already delivered and invoiced to check its compliance, claim a refund, or impose a sanction. It differs from the plain document-retention period, even though the two are linked in practice: without the supporting documents, you cannot respond to an inspection covering an old session.

+Does the ten-year statute of limitations apply to every training provider?

No. The standard rule remains a three-year period. The extension to ten years, introduced by law n° 2026-534 of 25 June 2026, only applies where fraudulent schemes or repeated breaches are found. A provider who makes an isolated mistake and corrects it in good faith stays under the standard three-year regime.

+From when does this new period apply?

According to the legal analyses available so far, the measure targets statute-of-limitations periods expiring on or after 26 June 2026, the day after the law's publication. A session invoiced in 2026 where fraud is later found could therefore, in theory, remain subject to inspection until 2036. The precise implementing rules still need to be confirmed by upcoming regulations.

+Do I need to keep my evidence for ten years for every training session?

This isn't a blanket ten-year retention requirement, but a recommended precaution for sessions funded by public or pooled funds (CPF, OPCO, France Travail, apprenticeship), which are the most exposed to a later inspection. For other documents, our article on document retention periods remains the reference.

Read next