Skip to content
97.5% of teams see value from GC AI before month oneSee how

Records Retention Policy: How to Build One With AI


Caitlin PricePublished

On a recent episode of CZ and Friends, GC AI's podcast about AI, risk, and where legal work is headed, host and CEO Cecilia Ziniti was trading risk stories with BetterUp General Counsel Sarah Binder and Silicon Valley Bank Managing Director Sophie McNaught. Cecilia told them about a former colleague, a onetime US attorney who prosecuted drug dealers and would not put anything in writing that could stay unwritten. The company they worked at went further. They set Slack to delete itself after 30 days. “They wanted Slack to just be musty,” Cecilia said. “And that's all it was.” That is a records retention policy doing its job.

A records retention policy is the document that tells your organization what to keep, how long to keep it, where to keep it, and when to destroy it, with a legal basis for every line. For in-house counsel, it is one of the highest-leverage governance documents you own, because it controls litigation risk, regulatory exposure, storage cost, and privacy obligations all at once.

GC AI is an enterprise-grade legal AI platform purpose-built for in-house counsel, used by 2,200+ legal teams across 50+ countries as of October 2026, including the legal departments at Hitachi, Liquid Death, Snyk, Columbia Sportswear, TIME, and Riot Games, plus 300+ public companies.

Cecilia built it after owning this exact document three times over, as general counsel at Anki, Bloomtech, and Replit. For a records retention policy, that means the platform researches the statute behind each retention period and drafts the policy, the schedule, and the legal-hold notice.

What Makes a Records Retention Policy Defensible

A records retention policy is a written rule set that assigns a retention period to every category of business record, states the legal or regulatory authority for each period, and defines who is responsible for keeping and destroying records on schedule. It has two working parts: the policy itself (the rules, roles, and the legal-hold override) and the retention schedule (the table that maps each record type to a number of years and a citation).

Courts punish companies for destroying records inconsistently, or after a duty to preserve has kicked in. Routine, even-handed destruction on a schedule is lawful housekeeping. A policy that is applied evenly, top to bottom, is what turns deletion into “ordinary course of business” and keeps it out of “spoliation.”

A policy is only defensible if the company and its employees consistently follow it, straight from the Association of Corporate Counsel's Ten Tips for Creating an Effective Document Retention Policy.

The case every in-house lawyer should know here is Arthur Andersen. As the SEC closed in on Enron in October 2001, Andersen's in-house counsel reminded the audit team to comply with the firm's document retention policy, and tons of Enron paper went into the shredders. A jury convicted the firm of obstruction in 2002.

The Supreme Court unanimously reversed in Arthur Andersen LLP v. United States (2005), holding the jury instructions were too broad, and confirmed there is nothing inherently unlawful about a retention policy designed to keep documents out of an adversary's hands. The reversal arrived three years after the firm had already collapsed.

The lesson is timing. A retention policy protects you when it runs on schedule in quiet months. Invoked for the first time the week an investigation starts, it reads as obstruction, whatever a court says later.

The goal is a schedule you can defend, suspend when you have to, and prove you followed.

How to Build a Records Retention Policy in Six Steps

Building a records retention policy follows six steps:

  1. Inventory and categorize your records
  2. Set retention periods against the law
  3. Write the retention schedule
  4. Build the legal-hold override
  5. Assign roles and responsibilities
  6. Enforce, train, and review

Inventory and Categorize Your Records

Start by grouping what you have, because you cannot assign a retention period to a file you have not named. Walk the business function by function: finance, HR, legal, sales, product, IT. For each function, list the record categories it generates: accounts payable, signed customer contracts, employee personnel files, board minutes, tax filings, email and chat, marketing assets.

Group at the category level. “Vendor invoices” is a category the schedule can govern; “invoice from Acme dated March 4” is a file inside it. Twenty to forty categories covers most mid-sized companies.

Set Retention Periods Against the Law

Each category gets a retention period, and each period needs an authority. This is the step generic templates skip, and it is the step that makes your policy defensible instead of arbitrary. Some periods come straight from statute or regulation. Others are a judgment call tied to the statute of limitations for likely claims.

A few federal anchors most US companies share:

  • Tax records: The IRS recommends keeping records that support income or deductions until the period of limitations runs, generally three years, and seven years for records tied to bad-debt or worthless-securities claims. Keep employment tax records at least four years.
  • Wage and hour records: The Department of Labor requires payroll records to be kept for three years under the Fair Labor Standards Act, and records used to compute pay for two years.
  • Employee records: The EEOC requires personnel and employment records to be kept for one year, extended through the resolution of any charge or lawsuit.
  • Employment eligibility records: USCIS requires Form I-9 to be kept for three years after the date of hire or one year after employment ends, whichever is later.
  • Benefit plan records: ERISA Section 107 requires records supporting Form 5500 filings and participant disclosures to be kept for six years after the filing date.
  • Safety and exposure records: OSHA requires employee exposure and medical records to be kept for the duration of employment plus 30 years under 29 CFR 1910.1020, and OSHA 300 injury and illness logs for 5 years after the calendar year they cover under 29 CFR 1904.33.

State law, industry regulation (HIPAA's 6-year documentation rule under 45 CFR 164.316, SEC Rule 17a-4's communications rules for broker-dealers, plus SOX, GLBA, and FINRA), and contractual commitments stack on top of the federal floor. When two authorities apply, the longer period wins. When no authority applies, set the period to the longest plausible statute of limitations for a claim that record might support, then add a buffer.

Verifying “how long must we keep this record in this jurisdiction” used to mean a call to outside counsel or an afternoon in a treatise. This is exactly the kind of bounded research question GC AI's Research feature is built for: you describe the record category and jurisdiction, and it returns the governing statute or regulation with a citation you can drop straight into the schedule's authority column. You still apply judgment on the close calls. You start from primary law instead of a blank cell.

Write the Retention Schedule

The schedule is the asset. It is a table, one row per record category, with five columns:

  • Record category (what it is)
  • Retention period (how long, in years or “permanent”)
  • Legal or regulatory basis (the citation)
  • Storage location and format (where it lives, paper or digital)
  • Disposition (destroy, archive, or anonymize at end of life)

A few categories almost always run permanent: formation documents, board and shareholder minutes, intellectual property registrations, and audited financial statements. Most operational records run three to seven years. The schedule is where those decisions live in one place, which is also what makes the policy auditable.

Copy the starter schedule below and adapt it. The categories, periods, and authorities here reflect federal floors most US companies share. Layer your state, industry, and contractual requirements on top, and remember the longer period always wins when two authorities apply.

Record CategoryRetention PeriodLegal or Regulatory BasisDisposition
Tax records supporting income or deductions3 years (7 if tied to a bad-debt or worthless-securities claim)IRS period of limitationsDestroy
Employment tax records4 years after the tax is due or paidIRSDestroy
Payroll records3 yearsFair Labor Standards Act (DOL)Destroy
Records used to compute pay (time cards, wage-rate tables)2 yearsFair Labor Standards Act (DOL)Destroy
Personnel and employment records1 year, extended through resolution of any charge or lawsuitEEOC recordkeeping ruleDestroy
Form I-9 (employment eligibility)3 years after hire or 1 year after employment ends, whichever is laterUSCIS Form I-9 rulesDestroy
Employee benefit plan records (Form 5500 support)6 years after the filing dateERISA Section 107Destroy
Employee exposure and medical recordsDuration of employment plus 30 yearsOSHA, 29 CFR 1910.1020Archive, then destroy
OSHA 300 injury and illness logs5 years after the calendar year coveredOSHA, 29 CFR 1904.33Destroy
Email and chat messages (Slack, Teams)Set by policy per category; document the rationalePolicy judgment; DOJ compliance guidance expects a stated rationale (SEC Rule 17a-4 if regulated)Destroy (auto-delete)
Signed customer and vendor contractsTerm plus the limitations period for breach (commonly 4 to 6 years)State statute of limitationsArchive, then destroy
Formation documents and corporate bylawsPermanentCorporate governanceArchive
Board and shareholder minutesPermanentCorporate governanceArchive
Intellectual property registrationsPermanentAsset protectionArchive
Audited financial statementsPermanentCorporate governanceArchive

Add a fifth column for storage location and format (where each category lives, paper or digital) once you map the table to your own systems. The contract-record range above is a statute-of-limitations judgment call, so confirm your governing state's limitations period before you set it.

This is the clause that does the heavy lifting, and the one weak policies leave out. A legal hold (also called a litigation hold) is an instruction that suspends scheduled destruction for any records relevant to anticipated or pending litigation, investigation, or audit. The moment your company reasonably anticipates a dispute, the duty to preserve attaches, and routine deletion has to stop for the affected records.

Get the interplay right and it reads like this: records destroy on schedule by default, except the schedule freezes the instant a legal hold issues. Under Federal Rule of Civil Procedure 37(e), a party that fails to preserve electronically stored information it had a duty to keep can face curative measures, and if the loss was intentional, an adverse-inference instruction or dismissal. The stakes run higher than sanctions. Destroying records with intent to obstruct a federal investigation is a felony under 18 U.S.C. § 1519, carrying up to 20 years, a provision Congress wrote into Sarbanes-Oxley with Enron's shredders in mind.

Cecilia's “musty Slack” anecdote works precisely because the 30-day auto-delete ran in the ordinary course, before any duty to preserve attached. Run that same deletion after a hold should have issued and it stops being housekeeping and becomes spoliation.

Your policy needs to state, in writing, who can issue a hold (commonly the GC or a designee), how the hold notice reaches custodians, how IT suspends auto-deletion for the affected systems, and how the hold is released when the matter closes.

GC AI's research and drafting can stand up the underlying legal document review and preservation workflow and draft the hold notice itself, so the override is a process people can run, with a hold notice in custodians' inboxes the same day. The legal hold always overrides the retention schedule. Write that sentence into the policy in those words.

Assign Roles and Responsibilities

A schedule without owners is a wish. Name them. The policy owner (typically the GC or a records manager) maintains the schedule and reviews it annually. Department heads classify their own records against the categories. IT executes the technical disposition, the auto-deletion rules, and the hold suspensions. Every employee follows the schedule and routes preservation questions to legal.

Spell out who approves destruction, and name a contact for the records that do not obviously fit a category. Those one-off judgment calls are where policies drift.

Enforce, Train, and Review

A policy you do not enforce is worse than no policy, because it documents a standard you then failed to meet. Enforcement means three things: scheduled destruction happens on cadence, employees are trained on the policy and retrained when it changes, and the schedule is reviewed at least annually against new laws and new record types your business has started generating.

Document the destruction. A short destruction log, what was destroyed and when, is the record that proves you ran the policy in the ordinary course. That destruction log is your best friend the day opposing counsel asks why a 2019 record no longer exists.

Slack, Texts, and Auto-Delete: The Messaging Retention Clause

Business communications in Slack, Teams, text, and WhatsApp are records, and your retention policy needs to say how long they live and why. This is the section most policies written before 2022 skip entirely, and it is where regulators now look first.

Two enforcement waves changed the math. In September 2022, the SEC fined 16 Wall Street firms $1.1 billion for business conversations conducted on personal devices and messaging apps that were never captured in firm records, and the CFTC added $710 million against overlapping firms the same day.

By the time the SEC signaled the sweep was winding down, the total had passed $2 billion across more than 100 firms.

Most in-house teams sit outside SEC Rule 17a-4, but the second wave reaches everyone: the Department of Justice updated its Evaluation of Corporate Compliance Programs in 2023 to ask what messaging apps a company permits, what deletion settings it runs, and the rationale for those settings, and DOJ and FTC guidance in January 2024 made clear that failing to preserve and produce messaging data can worsen the outcome of an enforcement action. The preservation duty belongs to the company, and no platform setting discharges it for you.

The fix is four working rules, written into the policy:

  1. Pick each window deliberately. Thirty days for casual chat and seven years for finance-relevant channels can both be right, as long as someone chose the window and owns it.
  2. Write the rationale down. “Chat is informal collaboration; documents of record live in the contract repository” is a sentence a regulator can accept. Silence is a sentence they write for you.
  3. Confirm IT can suspend auto-delete per custodian and per channel within hours. A legal hold that takes a week to reach Slack is a spoliation timeline.
  4. Decide where business happens. Ban business communications on personal apps, or capture them if your industry requires it. The SEC cases were about the channel nobody archived.

Cecilia's old employer chose 30 days on purpose, enforced it evenly, and could have suspended it the day a hold issued. That is the difference between a defensible window and a liability with a timer.

Records Retention vs Document Retention vs Data Retention

These three terms get used interchangeably, and the differences are worth thirty seconds. A records retention policy is the broadest: it covers all business records regardless of format, paper and digital. A document retention policy is the same instrument under an older name, with “document” emphasizing files over structured data. A data retention policy narrows to electronically stored data: the privacy and IT rules for customer data, logs, and backups under regimes such as GDPR and CCPA, where keeping personal data longer than necessary is itself a violation.

For most in-house teams, one master records retention policy with a schedule that addresses both physical records and electronic data is cleaner than three overlapping documents. Fold the privacy obligations into one comprehensive schedule, and you maintain a single policy instead of three.

How GC AI Helps In-House Teams Build and Maintain the Policy

For records retention specifically, GC AI handles the two slowest parts of the build.

First, the legal research: ask GC AI's Research “how long must a SaaS company keep signed customer contracts in California, and what is the authority,” and it returns the answer with a citation you can paste into the schedule's basis column. For the rows that turn on limitations periods or on how courts treat spoliation, US Case Law, GC AI's case-law research released in June 2026, searches 13M+ US court opinions and returns cited answers with treatment flags, so you confirm an authority is still good law before it anchors a schedule row.

Second, the drafting: GC AI produces the policy document, the retention schedule, the legal-hold notice, and the employee-facing summary, calibrated to your company through Custom Company Profile, GC AI's feature that stores your company's facts and standards, so the language matches how your team writes. When the law changes, you update the affected rows instead of rebuilding from scratch. Watch the full workflow in a GC AI demo.

Trisha Mauer, VP of Legal at Tonal, described the working pattern:

I go straight to GC AI for everything from research requests to litigation responses. I've compared against ChatGPT, GC AI gives more comprehensive responses appropriate for a lawyer to use. After six months of use, I'm sure I've saved hundreds of hours.

Research requests and litigation responses are the two ends of this exact document: the authority column on the front end, the hold workflow when a dispute lands. In-house teams run Trisha's ChatGPT comparison for themselves constantly; the GC AI vs ChatGPT page lays the two side by side, and the AI legal document review field guide walks through the research-and-draft loop end to end.

Because a retention policy governs sensitive records all the way through destruction, the security posture underneath matters: GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with its model providers wherever feasible, and AES-256 encryption.

Research the authority, draft the schedule, and stand up the legal-hold override, and you own a policy your team runs every day.

Build Your Records Retention Policy

Start with the schedule. Populate the categories your business generates, and verify the legal basis for each period before you set it in stone.

GC AI researches the authorities, drafts the policy and the legal-hold override, and keeps the schedule current as the law moves, so the first working draft of your policy can exist before the end of the week.

Frequently Asked Questions

How Long Should a Company Keep Business Records?
Most business records should be kept three to seven years, with some categories permanent. Tax records generally run three years per the IRS, extending to seven for bad-debt claims, while formation documents, board minutes, and IP registrations are kept permanently. The correct period for any category is the longest of the applicable statute, regulation, contractual commitment, or relevant statute of limitations, which is why a records retention schedule lists the legal basis next to each period.
Is a Records Retention Policy Legally Required?
A records retention policy is required in substance for most companies, because specific records must be kept for set periods under tax, employment, and industry regulations. While no single law mandates one master policy, regulators including the IRS, Department of Labor, and EEOC each impose retention obligations, and a written policy is the standard way to prove you meet them consistently and in the ordinary course of business.
How Long Should a Company Keep Emails and Slack Messages?
For most companies, no single federal statute sets an email or chat retention period; the window is a policy judgment that should be documented, with anything from 30 days to several years defensible depending on the channel's business function. Regulated industries carry specific duties, such as SEC Rule 17a-4 communications recordkeeping for broker-dealers, and the SEC's off-channel enforcement sweep has produced more than $2 billion in penalties since December 2021. Whatever window a company chooses, its legal-hold process must be able to suspend auto-deletion the day a duty to preserve attaches.
How Long Do You Have to Keep OSHA Records?
OSHA requires employee exposure and medical records to be kept for the duration of employment plus 30 years under 29 CFR 1910.1020, because some work-related illnesses surface decades after exposure. OSHA 300 injury and illness logs run 5 years after the calendar year they cover under 29 CFR 1904.33. Both periods sit well beyond the three-to-seven-year window most business records use, so safety records get their own line on the schedule.
How Long Should a Company Keep Employee Records?
Employee record retention runs on several clocks at once: payroll records for three years under the FLSA, personnel and employment records for one year under EEOC rules (extended through any charge or lawsuit), Form I-9 for three years after hire or one year after employment ends, whichever is later, and employee exposure and medical records for the duration of employment plus 30 years under OSHA. The safest structure is a separate schedule line for each employee record type with its authority. When two rules cover the same record, the longer period controls.
Which Employee Records Must a Company Keep Permanently?
Formation documents, corporate bylaws, board and shareholder minutes, intellectual property registrations, and audited financial statements are typically kept permanently. These records prove the company's legal existence, ownership, and governance decisions, and their legal relevance never expires, so a retention schedule marks them permanent and routes them to archive.
Can AI Help Build a Records Retention Policy?
Yes. A legal AI platform built for in-house counsel can research the governing retention period for each record category with a citation, draft the policy and schedule, and generate the legal-hold notice. GC AI handles all three and calibrates the drafting to your company through Custom Company Profile, so the policy reads in your team's voice while you keep judgment over the close calls.
SOC 2 certification badgeSOC 2
SOC 3 certification badgeSOC 3
GDPR badgeGDPR

Take the first step now

Let's explore about how we can make your life as an in-house lawyer a whole lot easier.

What to expect:

  • A walkthrough of the platform, tailored to your team's use cases.
  • Q&A session about security, integrations, and onboarding.
  • A 14-day free trial if the platform looks like a fit for your team.

Book a Demo

Dial code +1 (United States)

By submitting, you agree to our Terms and Privacy Policy.

Keep up with the latest content