How to Write a Document Retention Policy That Holds
11 October 2026
A document retention policy is a short document that answers three questions about every other document your organisation holds: how long it is kept, who decides, and what happens when the term runs out. Most organisations have one. Rather fewer have one that survives contact with an actual inspection.
The difference is rarely the wording. It is whether the policy names things that exist, and whether anything enforces it.
What belongs in the policy
Categories, not documents
A policy that lists document types one by one is out of date the week it is signed. A policy that defines categories, with a rule for assigning a new document to one, survives. Contracts, personnel files, accounting records, correspondence, project documentation: five or six categories cover most of an organisation.
A term per category, with its source
Every term needs the rule it comes from written next to it: a law, a regulator's requirement, a contract, or an internal decision. Terms without a source are the first thing an auditor pulls, because nobody can defend them and nobody dares shorten them. That is how organisations end up keeping everything forever.
Who decides and who signs
Name roles, not people. Who approves the policy, who approves a change to a term, who signs a disposal report, who may extend a term for a specific case because of litigation. If a single name appears anywhere, the policy breaks when that person leaves.
What happens at expiry
Two outcomes, and both have to be described: destruction, or transfer to a permanent archive. Say which categories go which way, what evidence each produces, and how long that evidence itself is kept.
Legal hold
One paragraph, and it has to override everything above. When a dispute or an investigation starts, affected cases stop expiring until someone lifts the hold. A policy without this clause quietly destroys exactly the documents that matter most.
How long is long enough
There is no universal answer, and anyone selling you one is selling you a product. Terms come from your jurisdiction, your industry and your contracts, and they differ for the same document in two countries. What is universal is the shape of the answer: a term, a source, and a start date rule.
The start date is the part that gets forgotten. Seven years from what, exactly: from the date the contract was signed, from the date it ended, or from the end of the financial year in which it ended? Three readings, three different disposal dates, and only one of them is defensible.
Why most policies are not followed
Three failures, and all three are mechanical rather than moral.
- The policy lives in a document, the files live in a system, and nothing connects them. People would have to open a PDF, find the category, work out the term and act on it by hand. Nobody does this.
- Nothing prevents early deletion. If a record can be deleted a year before its term expires and nobody notices, the policy is a wish.
- Disposal leaves no trace. When destruction is somebody emptying a folder, you cannot prove later what was destroyed, when, or under which rule.
A retention policy becomes real when the terms sit on the cases in the system, expiry is a date the software knows, and disposal produces a signed report. That is the job of records management software, and it is the difference between a rule and a published intention.
Writing one in a week
The long version of this project takes a year and usually dies. The short version is finishable.
- Day one. List the categories you actually have, by walking through one department rather than theorising.
- Day two. For each category, find the term and write its source next to it. Where there is no source, write "internal decision" and a number, and be honest about it.
- Day three. Decide destruction or transfer for each, and what evidence each produces.
- Day four. Write the legal hold clause and the roles.
- Day five. Put it in front of the people who will have to sign disposal reports, and change whatever they say is unworkable.
Then attach the terms to real cases in the archive and run one disposal cycle end to end. A policy that has survived one real destruction, with the report filed, is worth more than a perfect document nobody has tested.
Where this sits in our products
The terms and the disposal evidence live in records management software; the storage underneath it is our document archiving software, built on the electronic document archive module. If the documents sit in Microsoft 365, the same terms apply through SharePoint archiving.
FAQ
Is a document retention policy a legal requirement? In many industries and jurisdictions some retention terms are set by law, and having a written policy is either required or strongly expected. The safe reading is that the terms are not optional even where the document describing them is.
Who should own the policy? Usually legal or compliance owns the content and the archive or IT owns the enforcement. The split matters: a policy owned only by IT tends to describe what the system can do rather than what the rules require.
What is legal hold? A suspension of expiry on specific cases because of an actual or expected dispute, investigation or audit. While the hold is on, those records cannot be destroyed even if their term has run out, and lifting it is a decision somebody signs.
How often should the policy be reviewed? Once a year is the usual rhythm, plus immediately after any change in the law that touches a term, and after any merger or new line of business that introduces categories the policy does not cover.
Related reading. what document archiving is, the six stages of a document, archiving a SharePoint site.
Put the terms where the documents are. Talk to us and we will show how retention runs on your own categories rather than on a sample.
Read next
How to Archive a SharePoint Site Without Losing the Rules
How to archive a SharePoint site: what Microsoft 365 Archive does, the four options available, and why retention is a separate decision from storage.
Document Lifecycle Management: Six Stages, One Owner Each
Document lifecycle management explained: the six stages a document passes through, who owns each one, and where handovers between them usually break.
Document Version Control: Rules That Survive Real Work
Document version control explained: why file names fail, what check-out and a version history actually give you, and how to keep one authoritative copy.
What Is Document Archiving? File Plans, Terms, Disposal
Document archiving explained: what it is, how it differs from document management, and what a document archiving system has to do with terms and disposal.

Digital HR Document Management for the Largest Retail Chain
How the largest Ukrainian retail chain Avrora digitized HR document workflows with softXspace – QES, ERP integration, 1300+ stores.

Banking Processing Automation and Centralisation
Streamline your banking operations with soft Xpansion's Low-Code/No-Code solutions. Manage documents, automate lending processes, optimize board meetings, and centralize data storage with eArchive and Back Office modules.


