Back to Blog

Compliance

Audit Trail Retention Requirements Explained

Jess Wright
Jess WrightProduct Experience and Growth Specialist
8 min read
Audit Trail Retention Requirements Explained

Audit trail retention requirements explained: how to keep defensible evidence, set practical retention rules and stay ready for inspection at any site.

When an inspector, client or investigator asks who completed a check, what was changed, and when a manager knew about an issue, the answer cannot be buried in an inbox. Audit trail retention requirements determine whether your organisation can produce credible evidence at that moment - across every site, asset, policy and person involved.

For facilities and compliance teams, retention is not simply a records-management task. It is the control that preserves the story behind a decision. A completed fire-door inspection matters. So does the date it was completed, the defects found, the photos attached, the corrective action raised, the person who closed it, and any later amendments. Without that chain, a record may show activity but fail to prove control.

Learn MoreIssue Reporting & RequestsHow a defect found on inspection becomes an owned action, with the photos and closure staying on the record.

Audit trail retention requirements: what they cover

An audit trail is the chronological history of an action or record. In a compliance environment, it should show enough context to reconstruct what happened without relying on someone’s memory. It is different from the document itself.

A risk assessment, for example, is the current controlled document. Its audit trail records who created it, who reviewed it, which version was approved, what changed between versions, and when it was distributed. The same principle applies to inspection forms, maintenance records, incident reports, training records, contractor documentation and policy acknowledgements.

Learn MoreDocuments & PoliciesHow version history shows who approved a policy or assessment, and which copy was in force.

Retention requirements are rarely governed by one universal number. The right period depends on the record type, the regulatory regime, contractual commitments, insurer expectations, limitation periods for potential claims, and the operational risk involved. A multi-site operator may also need to account for different rules across jurisdictions, client estates or regulated activities.

That means a blanket instruction to “keep everything for seven years” is easy to administer but often weak in practice. It may retain personal data longer than necessary, obscure high-value evidence in a mass of old files, and leave teams unable to explain why the period was selected. Equally, deleting records as soon as a job is closed can remove evidence needed for a later claim or investigation.

The objective is defensible retention: keep the right evidence, in a usable form, for a justified period, with controlled disposal when that period ends.

Start with the event, not the folder

Fragmented systems make audit trails unreliable. An inspection may sit in one application, remedial work in a maintenance tracker, competency records in a training platform and approval emails in individual mailboxes. Each system may hold part of the evidence, but no one owns the complete chain.

Start by mapping the operational events that create compliance exposure. Typical examples include planned inspections, statutory tests, reactive maintenance, risk assessments, accidents and near misses, policy changes, contractor onboarding and training completion. For each event, identify the evidence generated before, during and after the work.

A weekly emergency-lighting check may produce a scheduled task, a completed form, a timestamp, an operative’s identity, photos, an exception, a work order, contractor correspondence, a completion certificate and a manager’s verification. If the exception is later linked to an incident, the retention decision should cover the full connected record, not just the original checklist.

This event-led approach also exposes gaps. If a corrective action can be closed without a completion date, supporting image or accountable person, the issue is not just poor data quality. It is a break in the audit trail.

Set a retention schedule that teams can operate

A retention schedule translates legal and operational obligations into workable rules. It should not be a static policy that only the legal team can interpret. Site managers need clear instructions about what is retained, where it sits, who owns it and what happens when a retention period expires.

For every record category, define the business purpose, relevant obligation, minimum retention period, trigger date, record owner, storage location and disposal method. The trigger date matters. A training record might run from completion or expiry; an incident file may need to run from case closure; asset documentation may be linked to disposal of the asset or the end of a building’s occupation.

Use categories that reflect real workflows, rather than broad labels such as “health and safety”. Separate records where the risk and lifecycle differ. Inspection evidence, accident records, maintenance certificates, competence records and contractor approvals are not interchangeable, even if the same team manages them.

Where the rule is uncertain, document the rationale and obtain appropriate legal or specialist advice. Compliance teams should not invent retention periods from habit. A recorded decision is easier to defend and review than an assumption carried forward from an old spreadsheet.

Build in legal holds and exceptions

Normal disposal rules must pause where a record may be relevant to litigation, an enforcement matter, an insurance claim, a grievance, a serious incident or a formal investigation. This is commonly known as a legal hold, although the process may also be described as a retention suspension.

The key control is not merely a note on a file. The affected records must be protected from automated deletion, and the organisation must know who can release the hold. Include connected evidence: inspection histories, versions, maintenance actions, messages, photographs and relevant training records.

A retention schedule also needs a process for sites that close, contracts that end and systems that are replaced. Data migration is a common point of failure. If timestamps, user identities, version history or attachments are lost during transfer, the new system may preserve documents but not their evidential value.

What a defensible audit trail looks like

A good audit trail is complete enough to explain the record and controlled enough to resist casual alteration. It should capture the actor, action, date and time, affected item, previous and new value where relevant, and the reason or workflow context behind the change.

For high-risk records, add approval status, comments, linked actions, attachments and evidence of notification. A policy acknowledgement should show which version was issued, who received it, when they acknowledged it and any reminders or escalations. A maintenance closure should show the reported defect, priority, work undertaken, evidence supplied and who verified completion.

Learn MoreDistribution & ReviewsHow a policy is issued to the right groups, with the version they acknowledged kept on the record.

Immutability is valuable, but it needs nuance. Teams must be able to correct mistakes. The control is that corrections create a new, traceable entry rather than overwriting the original. Restrict editing rights according to role, retain version history, and make sure administrators cannot silently remove critical evidence.

Accessibility matters too. Records held for ten years are of little use if no one can retrieve them quickly, search by site or asset, or export a readable package for an auditor. Test retrieval regularly. Ask a practical question: could a new manager assemble the evidence for a specific incident, inspection or asset within a working day?

Make retention part of the workflow

Retention works best when it is automatic. Asking busy site teams to name files correctly, move them into the right folders and remember deletion dates creates predictable inconsistency. The system should apply retention rules based on the record type, site, status and event date, while maintaining an auditable log of archive and disposal actions.

Centralising operational work also reduces double entry. When a failed inspection creates a corrective action, the evidence should remain connected. When that action requires a contractor, contractor competence and completion documents should be available in the same record trail. When a manager reviews the result, their approval becomes part of the evidence rather than a separate email.

CalmCompliance is designed around this connected model: physical sites, compliance requirements and people records are held in one operational view. That makes it easier to move from a standard or obligation to the live checks, documents, actions and audit history that demonstrate control.

Governance still matters. Assign ownership for the retention schedule, review it at least annually and whenever regulations, contracts, systems or risk profiles change. Monitor failed integrations, incomplete forms, deleted attachments and user-permission changes. These are often early warnings that the audit trail is weakening.

Common retention failures to avoid

The most expensive failures are usually ordinary process failures repeated over time. Teams retain final certificates but not the inspection that triggered the work. They save a revised risk assessment but lose the approval history. They archive records after a site closure without preserving a means to search and retrieve them. Or they hold everything indefinitely because nobody is authorised to dispose of anything.

Avoid treating retention as storage alone. Storage answers where a file lives. Retention answers why it exists, how long it remains available, what evidence must stay attached and when it can be securely destroyed. The distinction is central to both audit readiness and data protection discipline.

A clear retention model gives teams something more useful than a full archive: confidence that each critical activity leaves evidence which can be found, understood and trusted when scrutiny arrives.

Health and SafetyComplianceFacilities ManagementRisk ManagementMaintenanceCalmCompliancefacilitiescaremanufacturingleisureconstructionofficeseducation

Keep reading

Get the next article before everyone else

Join the weekly brief for new posts, product updates, and guides you can use on site straight away.

  • New posts
  • Product Updates
  • Practical guides
Weekly in your inbox

We care about your data. Read our privacy policy.