Governance
Document Retention Policy Guide
A document retention policy states, for each class of record, how long it is kept, what event starts the clock and what happens at the end. The trigger event is the field organisations most often omit, and its absence is what makes a schedule unimplementable in practice.
Document Retention Policy Guide
Most retention policies fail in the same way. They are written carefully, approved, circulated, and then cannot be applied — because they describe record classes the system cannot identify, or they state periods without saying what starts the clock.
This guide is about writing one that survives contact with a system and an auditor.
What a retention policy has to contain
For every class of record: a period, a trigger event, and a disposition action. Three fields. Most published schedules contain the first and the third.
The period comes from statute, a limitation period, a contractual obligation or a risk judgement. The disposition action is review, destroy or transfer. And the trigger is the event from which the period runs.
Why the trigger is the field that matters
"Seven years" is not a rule. Seven years from what?
Consider a five-year service agreement with a six-year retention period. Triggered at signature, it is disposed of one year after the contract ends — and if the term was extended, possibly while it was still in force. Triggered at termination, it is retained for six years after the last obligation could give rise to a claim, which is what the period was for.
The same error appears elsewhere and is consistently large. Customer due diligence records run five years from the end of the relationship, not from creation. Employment records run from the end of employment. Batch records run from batch expiry or certification. Pupil and safeguarding records run from the subject's date of birth or the age of majority. Occupational exposure records run from the date of last exposure — which is not the end of employment, and conflating the two can shorten a forty-year period to seven.
A schedule that does not state the trigger will be implemented with whatever trigger the system defaults to, which is almost always the creation date.
Write it against classes a system can identify
Archival schedules are often written in terms of record series — "correspondence of continuing value", "operational records of transitory significance". Those are precise in archival practice and unimplementable in software, because nothing in a document system can decide whether a piece of correspondence is of continuing value.
Write the schedule against document types instead: the same list that drives mandatory metadata and approval paths. Where an existing schedule uses record series, the reconciliation between the two vocabularies is the real work of a records project, and it is worth doing deliberately rather than automating.
Disposition: review rather than delete
The most requested feature in records management is automatic deletion at the end of a period. It is also the one worth resisting.
Retention periods are judgements about legal exposure made years before the expiry date, and circumstances change. More importantly, an automated deletion cannot evidence who authorised it, and "the system deleted it on schedule" is not an answer to a regulator or a court.
Raising a review costs minutes per record and converts an irreversible automated action into a defensible human decision with a name and a date attached. Automatic destruction is reasonable for high-volume, low-risk classes as a deliberate exception — not as the default.
What a defensible disposal leaves behind
A record of the disposal itself: which records, under which schedule item, authorised by whom, on what date, and confirmation that no legal hold was in force. In the public sector a destruction certificate is frequently mandatory and retained permanently, which is the correct instinct — evidence of authorised destruction should outlive the records it describes.
The audit trail should therefore survive the document. Questions about a disposal arrive after the disposal.
Legal holds override everything
The duty to preserve arises when litigation becomes reasonably anticipated, which can be a complaint letter or a regulatory enquiry rather than a filed claim. From that point, routine destruction of potentially relevant records must stop, regardless of what the schedule says.
A hold therefore has to take precedence automatically rather than depending on someone remembering to suspend a rule. It should be applied by scope — a matter, a date range, a set of custodians — rather than by listing files, and it must not be releasable by the people whose records it covers.
Where retention and erasure collide
A right to erasure does not automatically defeat a statutory retention obligation, and in a document system the conflict is routine rather than exceptional. An employment record, a financial record or a clinical record held under a prescribed period generally cannot be deleted on request.
The workable approach is to surface the retention rule and any hold at the point deletion is attempted, so the conflict is visible before the decision. Then record the decision and its reasoning — that record is the evidence if the requester complains to a regulator.
The measure of whether it is working
Not the proportion of records correctly classified. The number with no retention class at all.
That figure is the honest measure of programme completeness, and it identifies the material that will accumulate indefinitely because nobody is willing to be the person who deleted it. Report on it monthly and it stays small; report on it never and it becomes the archive.
A note on keeping everything
Some organisations conclude that storage is cheap and retention is a distraction. It is a coherent position and it has costs that are easy to overlook: a larger discovery surface in litigation, tension with data protection storage limitation, a bigger haystack for every access request, and an eventual migration in which nothing can be left behind because nothing was ever classified.
Keeping everything postpones the decision rather than avoiding it, and it postpones it to a moment when there is more of it and less institutional memory about what any of it is.
In summary
The sequence, in short
Step 1: List the record classes you actually hold
Work from document types the system can identify rather than archival categories. A class that cannot be identified in software cannot have a rule applied to it.
Step 2: Find the period for each
From statute, limitation periods, contractual obligations or sector guidance. Where nothing prescribes a period, set one from risk and record the reasoning.
Step 3: State the trigger event explicitly
Creation, closure, termination, end of employment, expiry, or the subject reaching the age of majority. A period without a trigger cannot be applied consistently.
Step 4: Decide the disposition action
Review, destroy or transfer to archive. Default to review; automated destruction cannot evidence who authorised it.
Step 5: Assign an owner and a review date
One named person, and a date by which the schedule itself is revisited. An unmaintained schedule fails more quietly than a wrong one.
FAQ
Questions this raises
How long should we keep documents?
It depends entirely on the record class and your jurisdiction, and any single number offered as a general answer is wrong. Start from the statutory and limitation periods that apply to each class, then add a margin, then record why.
Can we just keep everything?
It is a coherent strategy and an increasingly expensive one. Over-retention increases discovery scope in litigation, conflicts with data protection storage limitation, and means every erasure request meets a larger haystack. It also postpones rather than avoids the decision.
What if two obligations conflict?
The longer retention obligation generally prevails over a shorter one, and a legal hold prevails over both. Where a retention obligation conflicts with an erasure right, the decision has to be made deliberately and recorded — that record is what you produce if it is challenged.
Who should own the retention schedule?
One named individual with authority to decide. A schedule owned by a committee is a schedule nobody updates, and the most common failure in records management is an unmaintained schedule rather than a wrong one.
About the author
Written and reviewed by the DocumentMS product and compliance team.
Zuletzt geprüft: 27. August 2026