Skip to main content
All articles

Compliance

Building a retention schedule that survives an audit

Most retention policies are a document. A schedule that survives audit is a configuration, enforced by the system and evidenced automatically.

Written by
Ruth Adeyemi
Compliance Consultant, Datacoll8
Published
Reading time
6 minutes

There is a difference between a retention policy and a retention schedule. A policy is a statement of intent, usually a well-written document that has been reviewed by the right people and lives on the intranet. A schedule is a set of rules the system enforces without anyone remembering to. Audits go badly when a firm has the first and assumes it has the second.

Start from matter type, not document type

Retention obligations rarely attach to a document in isolation. They attach to the matter it belongs to, its jurisdiction, and sometimes the client relationship behind it. A schedule built only on document type will over-retain in some places and destroy too early in others, which is the worse of the two failures.

Model the rule as a combination: matter type, jurisdiction, document class, and the trigger event that starts the clock. Closure of the matter, end of a limitation period and the date of last activity are all different triggers, and using the wrong one is the most common defect we find.

Make destruction evidenced, not silent

An auditor is rarely satisfied by the absence of a record. They want to see that the record existed, that a rule applied to it, that the rule was executed on a date, and that someone with authority approved the class. That means destruction needs to leave a certificate behind: what was destroyed, under which rule, when, and on whose sign-off.

Hold rules have to be stronger than the schedule

  • A legal hold must override every retention rule, without exception and without manual intervention
  • Applying and releasing a hold must be logged with a named user and a reason
  • Held records must be visibly marked wherever they appear, not just flagged in a back-end table
  • Release of a hold should return the record to its schedule rather than restarting the clock

If a hold can be defeated by an automated deletion job, you do not have a hold. This is worth testing deliberately rather than assuming, and it is the single check we recommend running before any audit.

The practical test for a schedule is simple. Ask for every document of a given class due for destruction next quarter, along with the rule that applies and the evidence that similar records were destroyed correctly last quarter. If answering that takes more than a few minutes, the schedule is still a policy.

Written byRuth AdeyemiCompliance Consultant, Datacoll8

Book a demo

See it run against your own documents

Bring three or four representative agreements to the demo. We will run them through classification, extraction and verification live, and tell you plainly where the pipeline would need tuning for your paper.

Demos run Monday to Friday, 08:30 to 18:00 GMT