Compliance & Security
Document retention policies: build a schedule you can actually run
A retention policy is only as good as the schedule behind it and whether anything enforces it. Here is a worked sample schedule, the federal periods it rests on, and how to make disposal happen on its own.
Ademero Team6 min read

Most companies have a retention policy. Far fewer have one that runs. The policy says “keep invoices seven years”, and meanwhile invoices from 2009 sit on a file share because deleting them is nobody’s job. This guide is for the controller, HR lead or office manager who owns the problem. It builds a schedule you can run, using a sample company, and then shows how to make the schedule enforce itself.
What the policy must say
- Each record type, named the way your staff name it (“vendor invoice”, not “AP source document”).
- How long to keep it, and from when: the trigger that starts the clock.
- Why: the law, contract or business reason. This is what lets you defend the period later.
- What happens at the end: destroy, archive or keep permanently, and how paper and files are destroyed.
- Who owns each record type, and who can suspend disposal for a legal hold.
A sample schedule for a 150-person company
Here is a starting schedule for a US distributor with an HR team, an AP team and a warehouse. Rows marked rule come from a federal regulation; rows marked policy are common practice that you set with counsel. State law can require longer, so treat this as a draft, not advice.
| Record type | Keep for | Starts when | Basis |
|---|---|---|---|
| Form I-9 | 3 years after hire or 1 year after employment ends, whichever is later | Hire and termination dates | Rule: immigration regulations |
| Payroll and employment tax records | At least 4 years | Tax due or paid date | Rule: IRS employment tax records |
| Applications and hiring records | At least 1 year | Record made or action taken | Rule: EEOC |
| FMLA leave records | At least 3 years | Record made | Rule: Department of Labor |
| OSHA injury and illness logs | 5 years | End of the calendar year | Rule: OSHA recordkeeping |
| Employee exposure records | At least 30 years | Record made | Rule: OSHA |
| Vendor invoices, POs and payment support | 7 years | End of fiscal year | Policy |
| Contracts | Term plus 6 years | Contract ends | Policy, tied to your state limitation periods |
| General correspondence | 2 years | Date sent or received | Policy |
| Board minutes, bylaws, deeds | Permanently | Not applicable | Policy |
Healthcare organizations add one more rule: HIPAA policies, risk assessments and related documentation are kept six years from creation or the date they were last in effect. See our HIPAA guide for patient documents.
Triggers, not just periods
“Seven years” means nothing until you know seven years from what. The trigger is where most schedules break:
- Event triggers such as “employment ends” or “contract expires” need a date stored on the document, or the clock can never start.
- Whichever-is-later rules, like the I-9, need two dates. Store both, or calculate the disposal date when the employee leaves.
- Year-end triggers are the easiest to run: everything from fiscal 2018 goes at once.
Legal holds
When a lawsuit, audit or investigation is reasonably expected, disposal of related records must stop, whatever the schedule says. A hold needs three things: a way to mark exactly which documents it covers, assurance that nothing marked can be destroyed, and a record of who placed and released it. Counsel decides when it starts and ends. Destroying records to obstruct a federal investigation is a crime under the Sarbanes-Oxley Act, so this is the part of the policy to test first.
Running it in software
- 01
Give every document a type when it arrives
Retention attaches to the type. Capture software that recognizes document types sets it at scanning, so nothing lands untyped. - 02
Set the period and the destruction schedule per type
For example, Vendor Invoice: 7 years, with destruction run monthly on the first Sunday night. - 03
Watch what is coming due
A list of documents and their time remaining lets the owner see next month's disposals before they happen. - 04
Override with a reason, and record who did it
Keep one document longer, or hold it indefinitely for a legal matter. The override should be a permission, not something anyone can do.

In Content Central, each document type has a retention period in days, weeks, months, quarters or years and its own destruction schedule. A Retention Policies page lists documents with the time remaining, and those pending removal show in red. People with the override permission can set a document to be kept for longer, kept indefinitely, or removed from its policy, and each override records who made it. Keeping a document indefinitely is how a legal hold is placed. All of it runs next to the audit trail, in the cloud or on your own servers. CapturePoint 6 recognizes document types as pages are scanned, so each one arrives with the type its retention depends on.
Getting from zero to a schedule
Weeks 1 and 2: list what you have
Walk each department and list the record types they create or receive, and where each one lives today. Expect 30 to 60 types in a mid-size company.
Weeks 3 and 4: assign periods and triggers
Start from the sample above and our records retention policy template. Have counsel review the periods and add state rules.
Weeks 5 to 8: configure and test
Set up document types and retention in your system. Run the schedule against last year’s documents in a test copy and check the disposal list line by line.
Then: dispose of the backlog once, with sign-off
The first run will want to destroy years of old files. Get written sign-off from each owner, place any holds first, then let it run.
Free live demo
See retention schedules and legal holds run on their own.
Book a free demo and we will show you around, answer your questions and run your real paperwork through it. No cost, no pressure.
- A live tour of the products that fit your work
- Your own documents, set up and shown working
- Your workflow and process, mapped with you
- Straight answers from people who build it
