Records Retention Policy: How to Build One With AI
Caitlin PricePublished
On a recent episode of CZ and Friends, GC AI's podcast about AI, risk, and where legal work is headed, host and CEO Cecilia Ziniti was trading risk stories with BetterUp General Counsel Sarah Binder and Silicon Valley Bank Managing Director Sophie McNaught. Cecilia told them about a former colleague, a onetime US attorney who prosecuted drug dealers and would not put anything in writing that could stay unwritten. The company they worked at went further. They set Slack to delete itself after 30 days. “They wanted Slack to just be musty,” Cecilia said. “And that's all it was.” That is a records retention policy doing its job.
A records retention policy is the document that tells your organization what to keep, how long to keep it, where to keep it, and when to destroy it, with a legal basis for every line. For in-house counsel, it is one of the highest-leverage governance documents you own, because it controls litigation risk, regulatory exposure, storage cost, and privacy obligations all at once.
GC AI is an enterprise-grade legal AI platform purpose-built for in-house counsel, used by 2,200+ legal teams across 50+ countries as of October 2026, including the legal departments at Hitachi, Liquid Death, Snyk, Columbia Sportswear, TIME, and Riot Games, plus 300+ public companies.
Cecilia built it after owning this exact document three times over, as general counsel at Anki, Bloomtech, and Replit. For a records retention policy, that means the platform researches the statute behind each retention period and drafts the policy, the schedule, and the legal-hold notice.
What Makes a Records Retention Policy Defensible
A records retention policy is a written rule set that assigns a retention period to every category of business record, states the legal or regulatory authority for each period, and defines who is responsible for keeping and destroying records on schedule. It has two working parts: the policy itself (the rules, roles, and the legal-hold override) and the retention schedule (the table that maps each record type to a number of years and a citation).
Courts punish companies for destroying records inconsistently, or after a duty to preserve has kicked in. Routine, even-handed destruction on a schedule is lawful housekeeping. A policy that is applied evenly, top to bottom, is what turns deletion into “ordinary course of business” and keeps it out of “spoliation.”
A policy is only defensible if the company and its employees consistently follow it, straight from the Association of Corporate Counsel's Ten Tips for Creating an Effective Document Retention Policy.
The case every in-house lawyer should know here is Arthur Andersen. As the SEC closed in on Enron in October 2001, Andersen's in-house counsel reminded the audit team to comply with the firm's document retention policy, and tons of Enron paper went into the shredders. A jury convicted the firm of obstruction in 2002.
The Supreme Court unanimously reversed in Arthur Andersen LLP v. United States (2005), holding the jury instructions were too broad, and confirmed there is nothing inherently unlawful about a retention policy designed to keep documents out of an adversary's hands. The reversal arrived three years after the firm had already collapsed.
The lesson is timing. A retention policy protects you when it runs on schedule in quiet months. Invoked for the first time the week an investigation starts, it reads as obstruction, whatever a court says later.
The goal is a schedule you can defend, suspend when you have to, and prove you followed.
How to Build a Records Retention Policy in Six Steps
Building a records retention policy follows six steps:
- Inventory and categorize your records
- Set retention periods against the law
- Write the retention schedule
- Build the legal-hold override
- Assign roles and responsibilities
- Enforce, train, and review
Inventory and Categorize Your Records
Start by grouping what you have, because you cannot assign a retention period to a file you have not named. Walk the business function by function: finance, HR, legal, sales, product, IT. For each function, list the record categories it generates: accounts payable, signed customer contracts, employee personnel files, board minutes, tax filings, email and chat, marketing assets.
Group at the category level. “Vendor invoices” is a category the schedule can govern; “invoice from Acme dated March 4” is a file inside it. Twenty to forty categories covers most mid-sized companies.
Set Retention Periods Against the Law
Each category gets a retention period, and each period needs an authority. This is the step generic templates skip, and it is the step that makes your policy defensible instead of arbitrary. Some periods come straight from statute or regulation. Others are a judgment call tied to the statute of limitations for likely claims.
A few federal anchors most US companies share:
- Tax records: The IRS recommends keeping records that support income or deductions until the period of limitations runs, generally three years, and seven years for records tied to bad-debt or worthless-securities claims. Keep employment tax records at least four years.
- Wage and hour records: The Department of Labor requires payroll records to be kept for three years under the Fair Labor Standards Act, and records used to compute pay for two years.
- Employee records: The EEOC requires personnel and employment records to be kept for one year, extended through the resolution of any charge or lawsuit.
- Employment eligibility records: USCIS requires Form I-9 to be kept for three years after the date of hire or one year after employment ends, whichever is later.
- Benefit plan records: ERISA Section 107 requires records supporting Form 5500 filings and participant disclosures to be kept for six years after the filing date.
- Safety and exposure records: OSHA requires employee exposure and medical records to be kept for the duration of employment plus 30 years under 29 CFR 1910.1020, and OSHA 300 injury and illness logs for 5 years after the calendar year they cover under 29 CFR 1904.33.
State law, industry regulation (HIPAA's 6-year documentation rule under 45 CFR 164.316, SEC Rule 17a-4's communications rules for broker-dealers, plus SOX, GLBA, and FINRA), and contractual commitments stack on top of the federal floor. When two authorities apply, the longer period wins. When no authority applies, set the period to the longest plausible statute of limitations for a claim that record might support, then add a buffer.
Verifying “how long must we keep this record in this jurisdiction” used to mean a call to outside counsel or an afternoon in a treatise. This is exactly the kind of bounded research question GC AI's Research feature is built for: you describe the record category and jurisdiction, and it returns the governing statute or regulation with a citation you can drop straight into the schedule's authority column. You still apply judgment on the close calls. You start from primary law instead of a blank cell.
Write the Retention Schedule
The schedule is the asset. It is a table, one row per record category, with five columns:
- Record category (what it is)
- Retention period (how long, in years or “permanent”)
- Legal or regulatory basis (the citation)
- Storage location and format (where it lives, paper or digital)
- Disposition (destroy, archive, or anonymize at end of life)
A few categories almost always run permanent: formation documents, board and shareholder minutes, intellectual property registrations, and audited financial statements. Most operational records run three to seven years. The schedule is where those decisions live in one place, which is also what makes the policy auditable.
Copy the starter schedule below and adapt it. The categories, periods, and authorities here reflect federal floors most US companies share. Layer your state, industry, and contractual requirements on top, and remember the longer period always wins when two authorities apply.
| Record Category | Retention Period | Legal or Regulatory Basis | Disposition |
|---|---|---|---|
| Tax records supporting income or deductions | 3 years (7 if tied to a bad-debt or worthless-securities claim) | IRS period of limitations | Destroy |
| Employment tax records | 4 years after the tax is due or paid | IRS | Destroy |
| Payroll records | 3 years | Fair Labor Standards Act (DOL) | Destroy |
| Records used to compute pay (time cards, wage-rate tables) | 2 years | Fair Labor Standards Act (DOL) | Destroy |
| Personnel and employment records | 1 year, extended through resolution of any charge or lawsuit | EEOC recordkeeping rule | Destroy |
| Form I-9 (employment eligibility) | 3 years after hire or 1 year after employment ends, whichever is later | USCIS Form I-9 rules | Destroy |
| Employee benefit plan records (Form 5500 support) | 6 years after the filing date | ERISA Section 107 | Destroy |
| Employee exposure and medical records | Duration of employment plus 30 years | OSHA, 29 CFR 1910.1020 | Archive, then destroy |
| OSHA 300 injury and illness logs | 5 years after the calendar year covered | OSHA, 29 CFR 1904.33 | Destroy |
| Email and chat messages (Slack, Teams) | Set by policy per category; document the rationale | Policy judgment; DOJ compliance guidance expects a stated rationale (SEC Rule 17a-4 if regulated) | Destroy (auto-delete) |
| Signed customer and vendor contracts | Term plus the limitations period for breach (commonly 4 to 6 years) | State statute of limitations | Archive, then destroy |
| Formation documents and corporate bylaws | Permanent | Corporate governance | Archive |
| Board and shareholder minutes | Permanent | Corporate governance | Archive |
| Intellectual property registrations | Permanent | Asset protection | Archive |
| Audited financial statements | Permanent | Corporate governance | Archive |
Add a fifth column for storage location and format (where each category lives, paper or digital) once you map the table to your own systems. The contract-record range above is a statute-of-limitations judgment call, so confirm your governing state's limitations period before you set it.
Build the Legal-Hold Override
This is the clause that does the heavy lifting, and the one weak policies leave out. A legal hold (also called a litigation hold) is an instruction that suspends scheduled destruction for any records relevant to anticipated or pending litigation, investigation, or audit. The moment your company reasonably anticipates a dispute, the duty to preserve attaches, and routine deletion has to stop for the affected records.
Get the interplay right and it reads like this: records destroy on schedule by default, except the schedule freezes the instant a legal hold issues. Under Federal Rule of Civil Procedure 37(e), a party that fails to preserve electronically stored information it had a duty to keep can face curative measures, and if the loss was intentional, an adverse-inference instruction or dismissal. The stakes run higher than sanctions. Destroying records with intent to obstruct a federal investigation is a felony under 18 U.S.C. § 1519, carrying up to 20 years, a provision Congress wrote into Sarbanes-Oxley with Enron's shredders in mind.
Cecilia's “musty Slack” anecdote works precisely because the 30-day auto-delete ran in the ordinary course, before any duty to preserve attached. Run that same deletion after a hold should have issued and it stops being housekeeping and becomes spoliation.
Your policy needs to state, in writing, who can issue a hold (commonly the GC or a designee), how the hold notice reaches custodians, how IT suspends auto-deletion for the affected systems, and how the hold is released when the matter closes.
GC AI's research and drafting can stand up the underlying legal document review and preservation workflow and draft the hold notice itself, so the override is a process people can run, with a hold notice in custodians' inboxes the same day. The legal hold always overrides the retention schedule. Write that sentence into the policy in those words.
Assign Roles and Responsibilities
A schedule without owners is a wish. Name them. The policy owner (typically the GC or a records manager) maintains the schedule and reviews it annually. Department heads classify their own records against the categories. IT executes the technical disposition, the auto-deletion rules, and the hold suspensions. Every employee follows the schedule and routes preservation questions to legal.
Spell out who approves destruction, and name a contact for the records that do not obviously fit a category. Those one-off judgment calls are where policies drift.
Enforce, Train, and Review
A policy you do not enforce is worse than no policy, because it documents a standard you then failed to meet. Enforcement means three things: scheduled destruction happens on cadence, employees are trained on the policy and retrained when it changes, and the schedule is reviewed at least annually against new laws and new record types your business has started generating.
Document the destruction. A short destruction log, what was destroyed and when, is the record that proves you ran the policy in the ordinary course. That destruction log is your best friend the day opposing counsel asks why a 2019 record no longer exists.
Slack, Texts, and Auto-Delete: The Messaging Retention Clause
Business communications in Slack, Teams, text, and WhatsApp are records, and your retention policy needs to say how long they live and why. This is the section most policies written before 2022 skip entirely, and it is where regulators now look first.
Two enforcement waves changed the math. In September 2022, the SEC fined 16 Wall Street firms $1.1 billion for business conversations conducted on personal devices and messaging apps that were never captured in firm records, and the CFTC added $710 million against overlapping firms the same day.
By the time the SEC signaled the sweep was winding down, the total had passed $2 billion across more than 100 firms.
Most in-house teams sit outside SEC Rule 17a-4, but the second wave reaches everyone: the Department of Justice updated its Evaluation of Corporate Compliance Programs in 2023 to ask what messaging apps a company permits, what deletion settings it runs, and the rationale for those settings, and DOJ and FTC guidance in January 2024 made clear that failing to preserve and produce messaging data can worsen the outcome of an enforcement action. The preservation duty belongs to the company, and no platform setting discharges it for you.
The fix is four working rules, written into the policy:
- Pick each window deliberately. Thirty days for casual chat and seven years for finance-relevant channels can both be right, as long as someone chose the window and owns it.
- Write the rationale down. “Chat is informal collaboration; documents of record live in the contract repository” is a sentence a regulator can accept. Silence is a sentence they write for you.
- Confirm IT can suspend auto-delete per custodian and per channel within hours. A legal hold that takes a week to reach Slack is a spoliation timeline.
- Decide where business happens. Ban business communications on personal apps, or capture them if your industry requires it. The SEC cases were about the channel nobody archived.
Cecilia's old employer chose 30 days on purpose, enforced it evenly, and could have suspended it the day a hold issued. That is the difference between a defensible window and a liability with a timer.
Records Retention vs Document Retention vs Data Retention
These three terms get used interchangeably, and the differences are worth thirty seconds. A records retention policy is the broadest: it covers all business records regardless of format, paper and digital. A document retention policy is the same instrument under an older name, with “document” emphasizing files over structured data. A data retention policy narrows to electronically stored data: the privacy and IT rules for customer data, logs, and backups under regimes such as GDPR and CCPA, where keeping personal data longer than necessary is itself a violation.
For most in-house teams, one master records retention policy with a schedule that addresses both physical records and electronic data is cleaner than three overlapping documents. Fold the privacy obligations into one comprehensive schedule, and you maintain a single policy instead of three.
How GC AI Helps In-House Teams Build and Maintain the Policy
For records retention specifically, GC AI handles the two slowest parts of the build.
First, the legal research: ask GC AI's Research “how long must a SaaS company keep signed customer contracts in California, and what is the authority,” and it returns the answer with a citation you can paste into the schedule's basis column. For the rows that turn on limitations periods or on how courts treat spoliation, US Case Law, GC AI's case-law research released in June 2026, searches 13M+ US court opinions and returns cited answers with treatment flags, so you confirm an authority is still good law before it anchors a schedule row.
Second, the drafting: GC AI produces the policy document, the retention schedule, the legal-hold notice, and the employee-facing summary, calibrated to your company through Custom Company Profile, GC AI's feature that stores your company's facts and standards, so the language matches how your team writes. When the law changes, you update the affected rows instead of rebuilding from scratch. Watch the full workflow in a GC AI demo.
Trisha Mauer, VP of Legal at Tonal, described the working pattern:
I go straight to GC AI for everything from research requests to litigation responses. I've compared against ChatGPT, GC AI gives more comprehensive responses appropriate for a lawyer to use. After six months of use, I'm sure I've saved hundreds of hours.
Research requests and litigation responses are the two ends of this exact document: the authority column on the front end, the hold workflow when a dispute lands. In-house teams run Trisha's ChatGPT comparison for themselves constantly; the GC AI vs ChatGPT page lays the two side by side, and the AI legal document review field guide walks through the research-and-draft loop end to end.
Because a retention policy governs sensitive records all the way through destruction, the security posture underneath matters: GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with its model providers wherever feasible, and AES-256 encryption.
Research the authority, draft the schedule, and stand up the legal-hold override, and you own a policy your team runs every day.
Build Your Records Retention Policy
Start with the schedule. Populate the categories your business generates, and verify the legal basis for each period before you set it in stone.
GC AI researches the authorities, drafts the policy and the legal-hold override, and keeps the schedule current as the law moves, so the first working draft of your policy can exist before the end of the week.






