Skip to content

Free template

Records retention policy template

The rules around your retention schedule: who owns records, how legal holds work, how records are destroyed and logged, and how the whole thing is audited. Copy it, fill it in and have counsel review it.

For records managers, office managers and IT admins · Free, no sign-up · Copy it or print it · Updated October 2026

See the template

How to use this template

  1. 01

    Name the people first

    Decide who owns the policy, who can issue a legal hold and who approves destruction. Without names, nothing in the policy happens.

  2. 02

    Build the schedule separately

    Keep periods in Appendix A, not in the policy text. Start from our retention schedules or the generator, then have counsel confirm each one.

  3. 03

    Decide what happens to paper after scanning

    Choose whether the scan becomes the official copy and when originals are shredded. It is the question people ask most.

  4. 04

    Get counsel to review, then train

    This is not legal advice. Have counsel review the policy and periods, then walk each department through it.

The template

Records retention policy

Text in [brackets] is yours to fill in. Copy pastes with headings and tables into Word or Google Docs, and as Markdown into plain-text tools.

Records retention policy

Organization: [Organization name]
Policy owner: [Records manager] · Approved by: [Executive sponsor] · Effective: [YYYY-MM-DD] · Version: [1.0]
Starting point only, not legal advice. Have counsel review this policy and the retention periods before you adopt them.

1. Purpose

This policy sets how [Organization name] keeps records for as long as the law and the business need them, protects them while they are kept, and disposes of them securely and on schedule when they are no longer needed.

2. Scope

  • Applies to all employees, contractors and volunteers, and to all [departments, locations and entities].
  • Covers records in every format: paper, scanned images, electronic files, email, databases, and records held for us by vendors and cloud services.
  • A record is any information created or received in the course of business that documents a decision, a transaction, an obligation or an activity.
  • A non-record (drafts, duplicates, reference copies, routine notices) is kept only as long as it is useful and is not covered by the schedule.

3. Definitions

TermMeaning in this policy
Retention periodHow long a record is kept, counted from its trigger event
Trigger eventWhat starts the clock: for example creation, fiscal year end, contract end, termination of employment, or account closure
Record ownerThe department responsible for keeping the official copy of a record type
Legal holdAn instruction to keep records that may be relevant to litigation, an audit or an investigation, overriding the schedule
DispositionWhat happens at the end of the retention period: secure destruction, transfer to an archive, or review

4. Roles and responsibilities

RoleResponsibilities
[Records manager]Owns this policy and the retention schedule, approves destruction, runs the yearly review and audit
[Legal counsel]Confirms retention periods, issues and releases legal holds
Department records coordinatorsKeep their department's records in line with the schedule, run disposition, answer audit questions
[IT]Applies retention and deletion in systems, protects backups, supports legal holds in email and file storage
All staffFile records where they belong, follow legal hold notices, never destroy records outside this policy

5. Retention schedule

  • Retention periods are set in the retention schedule in Appendix A, not in this policy. The schedule lists each record type, its owner, its trigger event, its retention period, the rule or business reason behind it, and its disposition.
  • Where more than one rule applies to a record type, the longest period wins.
  • The record owner keeps the official copy for the full period. Other copies are non-records.
  • Changes to the schedule are approved by [the records manager] and [legal counsel], dated and kept.

Build Appendix A from the common US periods at ademero.com/resources/retention-schedules or the retention policy generator, then have counsel confirm every period for your state and industry.

6. Storage and format

  • Records are stored in [approved systems and locations] only, with access limited to people who need them.
  • Scanned records are [the official copy once checked for quality / kept alongside the paper original]. Paper originals of scanned records are destroyed after [a set period] unless the schedule or a legal hold requires the original.
  • Electronic records stay readable for their full retention period. Long-term records are kept in [PDF/A or another archival format].
  • Records containing personal, health or financial information are protected as set out in [the information security policy].

7. Legal holds

  1. When litigation, an audit or an investigation is reasonably expected, [legal counsel] issues a written legal hold notice.
  2. The notice names the matter, the record types, the date range and the people who hold relevant records.
  3. Recipients confirm in writing that they received and understood the notice.
  4. All scheduled destruction of records covered by the hold stops at once, in every format and location, including email and backups where needed.
  5. Only [legal counsel] releases a hold, in writing. Records then return to their normal schedule.
  6. [The records manager] keeps a log of every hold: matter, date issued, scope, recipients and date released.

8. Destruction and disposition

  • Records are reviewed for disposition [every quarter] once their retention period ends.
  • Before destruction, the record owner confirms that no legal hold applies and [the records manager] approves.
  • Paper is destroyed by [cross-cut shredding or a bonded shredding vendor that provides a certificate of destruction].
  • Electronic records are deleted from the system of record. Copies in backups expire on the backup schedule.
  • Every destruction is logged: record type, date range, quantity or location, method, date, and who approved it. The log itself is kept [permanently].

Swipe the table sideways to see every column.

DateRecord typeDate rangeQuantity or locationMethodApproved by
[YYYY-MM-DD][AP invoices][FY2018][4 boxes, Room 102][Shredding vendor, certificate #][Name]

Destruction log. The row above is an example.

9. Audits and review

  • [The records manager] audits [two departments] each year: are records where the schedule says, are expired records disposed of, are holds respected?
  • The policy and schedule are reviewed [every year], and whenever laws, systems or the business change.
  • Findings and corrective actions are reported to [the executive sponsor].

10. Training and compliance

  • New staff are trained on this policy within [30 days] of starting, and all staff [every year].
  • Destroying, hiding or changing records outside this policy, or ignoring a legal hold, may lead to disciplinary action.
  • Questions go to [records manager name, email].

11. Appendix A: Retention schedule

Swipe the table sideways to see every column.

Record typeOwnerTrigger eventRetention periodRule or reasonDisposition
[Vendor invoices][Accounts payable][End of fiscal year][Confirmed period][Rule or business reason][Destroy]
[Personnel files][HR][Termination][Confirmed period][Rule or business reason][Destroy]
[Board minutes][Corporate secretary][Creation][Confirmed period][Rule or business reason][Archive]

Add one row per record type. Fill in periods only after counsel confirms them.

Policy and schedule: two documents, two jobs

The policy says how retention works: who decides, how holds are issued, how destruction is approved and logged. It changes rarely. The schedule says how long each kind of record is kept and why. It changes whenever a rule or a record type changes. Keeping them apart means a new tax rule is a one-row edit, not a policy rewrite.

You needUse
Common US periods with the rule behind each oneRetention schedules by record type
A schedule built for your industry and record typesRetention policy generator
The rules around the scheduleThis template

Common mistakes

  • Keeping everything forever. It feels safe, but every record you keep is one you may have to search, produce and protect.
  • Destroying without a log. If you cannot show what was destroyed, when and under which rule, routine destruction looks like something else.
  • A legal hold nobody can follow. A hold that does not reach email, shared drives and scanned files is a hold on paper only.
  • Forgetting the trigger event. "Seven years" means nothing until you say seven years from what.
  • Policy on the shelf. If the system that holds the records does not enforce the schedule, it will drift within a year.

How Content Central enforces it

Content Central keeps records on your own servers and applies the schedule for you, document type by document type.

In the policyIn Content Central
Retention scheduleA retention period per document type, in days, weeks, months, quarters or years, plus a destruction schedule (how often, which day, what time).
Legal holdsAny document can be set to Retain Indefinitely, which overrides its schedule until the hold is lifted. Overrides need the Allow Retention Overrides permission, and each one records who made it.
Disposition reviewA Retention Policies page lists documents and the time each has left. Documents pending removal show in red.
Destruction logThe audit trail records deletions along with views, downloads, changes and approvals, filtered by user, action and date.
Storage and formatScans become searchable PDFs, with PDF/A-1b output for long-term records.
AccessPermissions by document type and even by field value, with an optional reason required to open sensitive records.

Workflow can also archive or delete documents once they reach a set age. The help library walks through both:

Next step

Let the system keep the schedule.

Book a free Content Central demo and see retention by document type, legal holds, the time-remaining view and the audit trail, set up around your own records.