Articles

Document retention policy: the real US periods, not the 7-year myth

Document retention policy periods for US businesses: how long to keep tax, payroll, HR and audit records, the statute behind each, and when the clock starts.

Document retention policy: the real US periods, not the 7-year myth

What a document retention policy is, and who checks it

Someone just asked whether they can shred the 2019 invoices. If the honest answer is "probably, I think so," you don't have a document retention policy. You have a habit.

A document retention policy is the written rule saying how long each class of record stays, where it lives, and who signs off before anything is destroyed. The record retention schedule is the table inside it: record type, period, legal basis, disposition. Retention is the slice of document management with statute numbers attached.

The periods aren't yours to pick. They belong to whoever can demand the record later: the IRS on tax, the Department of Labor on wages and hours, OSHA on exposure and medical files, the EEOC on hiring decisions. None of them coordinate. One employee's file can carry a one-year clock, a three-year clock and a thirty-year clock at once.

Getting it wrong hurts both ways. Destroy early and you lose the document that would have closed the dispute. Keep everything forever and you pay to store personal data you can no longer justify holding.

Key figures

The four periods that settle most US retention questions, each with the rule that sets it. They come from two different agencies and were never designed to line up, which is why a single company-wide number cannot be right.

Tax returns and supporting records
3 years

The general IRS period, counted from the date the return is filed (Publication 583).

Income understated by over 25%
6 years

The longer window when a return leaves out more than a quarter of gross income (Publication 583).

Worthless securities or a bad debt
7 years

The only ordinary business record the seven-year folk rule actually fits (Publication 583).

Employee exposure records
30 years

OSHA's outlier; medical records run employment plus thirty (29 CFR 1910.1020).

Tax records: the IRS clock

Everything here is counted by the IRS, and the clock almost always starts at the filing date rather than the tax year.

Record typeRetention periodAuthorityClock starts

Tax returns and supporting records

3 years

26 U.S.C. 6001; IRS Pub. 583

Date the return is filed, or the due date if later

Tax records, income underreported by over 25%

6 years

IRS Pub. 583, Table 3

Date the return is filed

Worthless-securities or bad-debt deduction claims

7 years

IRS Pub. 583, Table 3

Date the return is filed

Fraudulent return filed

No limit

IRS Pub. 583, Table 3

Not applicable

No return filed

No limit

IRS Pub. 583, Table 3

Not applicable

Employment tax records

At least 4 years

IRS Pub. 583; IRS recordkeeping guidance

Date the tax is due or paid, whichever is later

Employment records: DOL, EEOC, OSHA and the states

No single agency owns this group, and the clock starts at an employment event, a hire, a termination, the last entry in a payroll book, rather than at a filing date.

Record typeRetention periodAuthorityClock starts

Payroll records, sales and purchase totals, CBAs, employment contracts

3 years

FLSA, 29 CFR 516.5

Last date of entry, or last effective date

Time cards, wage-rate tables, schedules, shipping and billing records

2 years

FLSA, 29 CFR 516.6

Last date of entry, or last effective date

Form I-9

3 years after hire, or 1 year after termination, whichever is later

8 CFR 274a.2(b)(2)(i)

Hire date or termination date

FMLA leave records, notices and certifications

At least 3 years

29 CFR 825.500

Ongoing, no single trigger

Personnel records: applications, promotion, transfer, layoff, pay, training selection

1 year, extended to final disposition if a charge is filed

EEOC, 29 CFR 1602.14

Date the record is made or the action taken, whichever is later

Employee exposure records

30 years

OSHA, 29 CFR 1910.1020(d)

Record creation

Employee medical records

Employment plus 30 years

OSHA, 29 CFR 1910.1020(d)

Creation, running through employment

California payroll records, held in-state

At least 3 years

CA Labor Code 1174(d)

Ongoing

Audit and securities records: SOX and the SEC

These bind the auditor and the broker-dealer rather than the company being audited, and the clock usually starts when an engagement, an account or a job ends.

Record typeRetention periodAuthorityClock starts

Audit and review workpapers kept by an issuer's auditor

5 years

SOX 802, 18 U.S.C. 1520

End of the fiscal period in which the audit or review concluded

Audit records: workpapers plus memoranda, correspondence and communications holding conclusions or financial data

7 years

SEC Reg. S-X Rule 2-06, 17 CFR 210.2-06

Conclusion of the audit or review

Broker-dealer blotters, general ledgers, stock records, customer account records

6 years, first 2 easily accessible

SEC Rule 17a-4, 17 CFR 240.17a-4

Record creation

Broker-dealer records in most other categories: communications, agreements, trial balances, bank records

3 years, first 2 easily accessible

SEC Rule 17a-4

Record creation

Broker-dealer account records

6 years

SEC Rule 17a-4

Account closure

Broker-dealer organizational documents: articles, bylaws

Life of the enterprise

SEC Rule 17a-4

Not applicable

Broker-dealer personnel records

3 years

SEC Rule 17a-4

Termination date

Document retention periods by record type

The tables are the answer. What follows is what they cannot show you.

Payroll is two rows rather than one. 29 CFR 516.5 gives payroll registers, collective bargaining agreements and employment contracts three years, while 29 CFR 516.6 gives the time cards and wage-rate tables behind them only two, and both sit in the same folder. Most companies keep everything for three and stop thinking about it.

Property records run from the wrong end. The clock starts in the year you dispose of the asset, not the year you bought it, which can put a purchase invoice under a twenty-year obligation.

Personnel records look brief. 29 CFR 1602.14 sets one year, and then a discrimination charge freezes everything relevant until final disposition. The Form I-9 clock under 8 CFR 274a.2 turns on a date that has not happened yet when you fill the form in.

Contracts have no federal retention period of their own. The driver is the term plus your state's statute of limitations, and our guide to types of business contracts covers which agreements those are.

Three years is the default, not seven

IRS Publication 583 puts the general period at three years from the date you file, and the tiles above carry the exceptions. Two cases have no end at all: file a fraudulent return, or none, and the period never closes. A third sits outside the tax return entirely, since employment tax records get at least four years from the date the tax is due or paid, whichever is later. Those are the three rows people leave out of a policy.

How to count a document retention period

A period nobody can date is a period nobody can enforce. "Three years" means nothing until you name the day it starts, and the triggers differ by agency.

Tax periods run from the filing date, or from the due date when you file early. Wage records under 29 CFR 516.5 run from the last date of entry or the last effective date, so a contract amended in year four starts a fresh clock on the amendment. I-9s run from the later of two dates, one of which hasn't happened yet when you fill the form in. OSHA exposure records run from creation.

"Whichever is later" deserves a rule of its own: calculate both dates and diary the later one.

Two things stop the clock rather than start it. A discrimination charge under 29 CFR 1602.14 freezes everything relevant until final disposition, and a legal hold does the same for litigation or an investigation that is pending or reasonably expected. If you already track obligation dates the way our contract management guide describes, retention dates belong in the same calendar.

Building the schedule, in six steps

Six steps, sized for a company with no records manager. Each ends in something written down, because a step that leaves no artifact quietly stops happening.

  1. Inventory what you actually hold

    Walk the shared drive, the mail archive, the filing cabinet and the two laptops nobody has opened since 2021. List classes, not files: payroll, signed contracts, tax returns, I-9s, safety records. Most companies find a category they had forgotten they were keeping.

  2. Split into record series

    A record series is a group sharing one period and one fate. Payroll registers are a series. Time cards are a different one, even though they sit in the same folder, because the FLSA gives them two years against payroll's three.

  3. Attach a period and a citation to each series

    Every row gets a number and the rule it came from. If you can't name the authority, the period is a guess. Write "no statutory period, business rule" where that is the truth, and say who set it. Auditors accept a documented business rule.

  4. Decide where each series lives

    Match the storage to the length. Anything on a thirty-year OSHA clock can't sit in a departing employee's mailbox. Access rules belong here too, since a record you keep for decades is one you should restrict for decades, and role-based access is the cheap version of that control.

  5. Give every date an owner and a reminder

    A schedule with no calendar behind it gets written once and never read again. Set the review annually, assign it by name rather than by department, and put destruction dates where renewal dates already live, in your contract management system.

  6. Destroy on schedule, and log it

    Consistency is the defense. Destroy on the date, by the method the policy names, and record what went, when, under which series and on whose authority. Selective destruction, where the awkward files vanish, is what gets a company into trouble.

Storing records electronically so they still count

Scanning a box doesn't automatically satisfy record retention requirements. Federal law attaches conditions, stricter than most people assume.

Under 15 U.S.C. 7001(d), the ESIGN Act, an electronic record satisfies a legal retention requirement on two conditions: it accurately reflects the original, and it stays accessible for the whole required period in a form capable of accurate reproduction. Both run for the life of the record, not for the day you scanned it. UETA section 12 sets the same test in state law and allows a third party to do the storing.

Read that against a folder of unindexed scans on a drive nobody backs up. Accurate, probably. Accessible in year seven, when the format is obsolete and whoever named the files has left? That condition fails quietly, and it fails in three ordinary ways: a proprietary format nobody licenses any more, an encryption key that left with an administrator, and a naming scheme only its author could read. None of the three announces itself. You find out on the day somebody asks for the file.

SEC Rule 17a-4 goes further for broker-dealers, offering a choice between non-rewriteable storage and a time-stamped audit trail of every change and deletion. Nobody else is bound by it, though an electronic signature audit trail does that job for signed documents.

Choosing storage comes down to narrow questions. Can it hold a document for the longest period in your document retention policy? Can it export in a readable format if you leave? Does it log access and changes? Chaindoc keeps the executed document with its identity check and trail together, and pricing lists the plans.

Document retention policy schedule pinned beside labeled archive boxes with a destruction date written on each lid

A schedule works when the date is on the box. It fails when the date lives in a file nobody opens.

What changed for document retention policies in 2025 and 2026

Not much, and that's the honest answer. No federal retention period in the tables above moved in 2025 or 2026. The IRS figures in Publication 583 are the same three, six, seven and unlimited as ever, and the FLSA, EEOC, OSHA and I-9 periods are unchanged. If your schedule was right in 2024, every period in it is still right.

Enforcement is where the movement is. In December 2021 the SEC fined JPMorgan Securities $125 million, with $75 million more from the CFTC, because employees ran business communications through WhatsApp, texts and personal email that never reached the firm's records. In September 2022 it announced penalties above $1.1 billion across sixteen firms for the same failure. Those are broker-dealer cases, so read the pattern rather than the numbers: what goes missing is what nobody classified.

Which is the practical 2026 question for a document retention policy. The periods held steady. Your schedule probably hasn't kept up with where the work now happens.

Both directions cost money

Shredding early is the obvious failure: the exposure record you destroyed at year seven had twenty-three years left on it, and OSHA won't accept a filing convention as an excuse. Keeping everything forever is the quieter failure. Every extra year of personal data is another year of storage cost, a wider pool for discovery, and a deletion request you can't answer.

Destruction, deletion requests and your document retention policy

Retention law tells you what to keep. Privacy law tells you what to get rid of, and the two reach the same file from opposite ends.

State consumer privacy statutes give residents a right to ask a business to delete personal information held about them. Those laws carry exceptions for information a company must retain under other law, which is why the citation column of a document retention policy earns its place: it's the evidence that a refusal to delete rests on a legal obligation rather than inertia. Without a documented period, "we still need it" is an assertion, and a weak one.

A legal hold cuts the other way. Once litigation, an audit or an investigation is pending or reasonably anticipated, the schedule stops for anything relevant and stays stopped until counsel lifts it. Destroying on schedule during a hold is worse than having no schedule at all.

The destruction record is the part everyone skips. Log the series, the date range, the method, the date and the person who authorized it. When somebody asks in three years what happened to the 2022 files, that log is the answer.

Records that stay readable for as long as the law wants them

Keep the executed document, the identity check and the audit trail in one place, with access rules that outlast the people who set them.

See contract management

Where to start your document retention policy, by company size

Under ten people, you don't need a records retention program. You need one page. List the six or seven classes you actually hold, put the statutory period beside each, name the person who authorizes destruction, and set an annual reminder to reread it. Ninety minutes, once.

Between ten and a hundred, the failure mode changes. Records now sit in more places than one person can see, and the risk is a category nobody owns. Split payroll from time cards, put the I-9 clock on a calendar instead of in someone's memory, and pick storage that will still open its own files in fifteen years.

Above a hundred, or in any regulated sector, the schedule needs an owner with authority to enforce it, a written legal-hold procedure legal can trigger in an afternoon, and a destruction log somebody reviews.

Whatever the size, build the document retention policy around the citation. A period you can trace to 29 CFR 516.5 or Publication 583 survives an audit. A round number picked because it felt safe doesn't.

One-page document retention policy on a desk listing record types, retention periods and the statute cited for each

The one-page version: classes, periods, citation, owner. Everything after that is elaboration.

Sources

Every period in the schedule above traces to one of these documents, listed in the order the article uses them. Where an agency's own page blocked retrieval, the official regulation text is cited instead.

  1. 1.Publication 583, Starting a Business and Keeping Records · Internal Revenue ServiceTable 3: three years, six for understated income, seven for a bad-debt claim, no limit for a fraudulent or missing return.
  2. 2.29 CFR § 1910.1020 — Access to employee exposure and medical records · Cornell Legal Information InstituteThirty years for exposure records, employment plus thirty for medical ones.
  3. 3.29 CFR § 516.5 — Records to be preserved 3 years · Cornell Legal Information InstitutePayroll registers, collective bargaining agreements, employment contracts.
  4. 4.29 CFR § 516.6 — Records to be preserved 2 years · Cornell Legal Information InstituteTime cards, wage-rate tables, schedules, shipping and billing records.
  5. 5.29 CFR § 1602.14 — Preservation of records made or kept · Cornell Legal Information InstituteOne year, extended to final disposition once a charge is filed.
  6. 6.8 CFR § 274a.2 — Verification of identity and employment authorization · Cornell Legal Information InstituteForm I-9: three years after hire or one year after termination, whichever is later.
  7. 7.15 U.S.C. § 7001 — ESIGN, general rule of validity · Cornell Legal Information InstituteSubsection (d) is the electronic-retention test: accuracy plus accessibility.
  8. 8.17 CFR § 240.17a-4 — Records to be preserved by certain exchange members and brokers · Cornell Legal Information InstituteThe WORM-or-audit-trail choice for electronic storage.
  9. 9.SEC charges JPMorgan for widespread recordkeeping failures · US Securities and Exchange CommissionThe December 2021 $125 million penalty.
  10. 10.SEC charges 16 Wall Street firms with widespread recordkeeping failures · US Securities and Exchange CommissionThe September 2022 action and the $1.1 billion in combined penalties.
FAQ

Frequently Asked Questions

Answers to popular questions about Chaindoc and secure document workflows.

It's the written rule setting how long your business keeps each class of record, where those records live, who may reach them, and who authorizes destruction. The retention schedule is the table inside it, listing record types against periods and legal citations. A policy with no schedule is a statement of intent. A schedule with no policy has nobody accountable for changing it.

It depends entirely on the record. The IRS baseline for tax returns and their supporting material is three years from filing, stretching to six years if income was underreported by more than 25%, seven for a worthless-securities or bad-debt claim, and indefinitely if a return was fraudulent or never filed. Employment tax records run at least four years. Payroll under the FLSA is three years and its supporting records two. EEOC personnel records are one year. OSHA exposure records are thirty. No single number covers all of them.

Far fewer than the folk rule suggests. Seven years is the IRS period for a claim for loss from worthless securities or a bad debt, and separately the period in SEC Regulation S-X Rule 2-06 for accountants auditing public companies. Neither reaches an ordinary small business's general records. Applied across the board, seven years keeps some files years too long and destroys OSHA exposure records twenty-three years too early.

The policy governs; the schedule operates. The policy explains why periods exist, who approves changes and how destruction is authorized. The schedule is the working table: record series, period, citation, disposition. Plenty of organizations call the schedule the policy, which is harmless until someone asks who signed off on a change.

Yes, on conditions. ESIGN, at 15 U.S.C. 7001(d), accepts an electronic record if it accurately reflects the original and remains accessible for the full required period in a form that can be accurately reproduced. UETA section 12 sets the same test in state law and allows a third party to store the records. Accessibility is the condition that fails in practice: obsolete formats and departed employees break retrievability long before the period ends.

Related Content

More e-signature and blockchain guides

Practical guides on electronic signatures, blockchain audit trails, and secure document management — handpicked to build on what you just read.