Download the City of Dixon records retention schedule.pdf), the Independent Sector nonprofit policy, and the NYSBA law-office sample first. None of them will fit your organization out of the box, so you'll need to adapt the schedule, get formal sign off, and lock the final version before you distribute it. Below you'll find a checklist to vet whichever PDF you pick, a retention-period reference table, legal-hold guidance, and copy-paste clauses to speed up the edit.
TL;DR:
- Most retention periods are based on legal or regulatory minimums, with seven years being standard for tax and accounting records to cover IRS audit windows.
- When adjusting a sample policy, organizations should inventory their records, assign owners, and verify retention triggers and legal minimums based on specific jurisdictional rules.
- A legal hold suspends scheduled destruction immediately upon suspicion of litigation or investigation, requiring detailed tracking and written authorization before resuming disposal.
- Proper archive formatting includes flattening PDFs, running OCR for searchability, and maintaining metadata to ensure long-term integrity and ease of discovery.
- Document access controls should mirror record sensitivity, and exceptions, review cycles, and responsible personnel must be clearly documented to minimize legal risk.
Table of Contents
- Where to download trusted document retention policy PDF templates
- What must a document retention policy include?
- How long should you keep different types of business records?
- How to adapt a sample policy to your organization
- Legal holds, exceptions, and litigation risk
- File format and preservation best practices for PDF records
- Editable clauses and a sample retention-schedule row
- Balancing cost, privacy, and legal defensibility
- Prepare, flatten, and secure your final policy PDF with LawtonPDF
- Useful primary sources and authoritative PDFs
- Sources
- FAQ
Where to download trusted document retention policy PDF templates
You don't need to write a records retention policy from scratch. Four public and professional sources publish free, well-structured PDFs that cover the major building blocks: purpose, schedule, legal holds, and destruction procedures. Each serves a different kind of organization, so pick the one closest to your situation and treat it as a first draft, not a final document.
- Independent Sector Records Retention Policy — built for nonprofits, with language around board minutes, grant records, and donor documentation that a for-profit template usually skips.
- NYSBA Sample Law Office File Retention/Destruction Policy — written for law firms, this one is unusually direct about client-file destruction, including how to handle files when a client can't be located and what to do with original documents versus copies.
- WSBA Sample Document Retention Policy — another law-focused sample, slightly more generic than the NYSBA version, which makes it a decent fit for professional-services firms (accounting, consulting) that want legal-grade rigor without law-firm-specific clauses.
Professional-services firms that need a corporate model rather than a legal one often gravitate toward internal accounting-firm retention schedules that apply a seven-year rule broadly, then attach a detailed schedule as an exhibit rather than burying every rule in the body text. That structure, a short policy plus a longer schedule attached as an exhibit, is worth copying regardless of which template you start from, since it lets you update the schedule without reopening the whole policy for approval every time.
A quick note on usage: these PDFs are published as public examples, not licensed templates, so you're generally free to adapt the language for internal use. That said, keep the source's name out of your final version, don't republish the file itself on your own site, and treat any law-firm sample as a starting draft that your own counsel should review, since retention obligations vary by state and industry. If you're a public-safety agency, a guide to compliant recordkeeping for public safety agencies covers schedule issuance and compliance nuances that generic templates don't address.
None of these documents anticipate every retention category. If your organization handles health records, financial audit files, or export-controlled data, you'll be adding rows the source template never considered. That's normal. Treat the download as your skeleton, not your finished skeleton key.
What must a document retention policy include?
A downloaded PDF only earns your trust once you've checked it against the components regulators and courts actually expect to see. Missing any of these six items is the fastest way to end up with a policy that looks official but collapses the first time it's tested in a legal hold or an audit.
- Purpose and scope statement. State why the policy exists (compliance, risk reduction, storage cost control) and which entities, departments, and record formats it covers. Vague scope language is the single most common weakness in adapted templates, especially ones borrowed from a different industry.
- Definitions, particularly record versus non-record. A record documents a business decision, transaction, or legal obligation. A non-record, a draft, a duplicate, a routine internal email, doesn't need to be scheduled at all. The University of Wisconsin's authorized-user training draws this line clearly and recommends a periodic purge cycle for non-records specifically because leaving them undefined creates unnecessary discovery exposure later.
- The retention schedule itself, organized by category, with a defined trigger event (contract termination, employee separation, fiscal year end) and a specific retention period tied to that trigger, not to the calendar date the policy was signed.
- Legal hold process and authority. Name who can issue a hold, how it suspends normal destruction, and how it gets formally lifted.
- Disposition method and destruction authorization. Shredding, secure deletion, or degaussing, whichever applies, plus a signed form documenting what was destroyed, when, and by whose authority. The City of Dixon's manual builds this authorization step directly into its schedule, which is worth copying regardless of your industry.
- Role assignments, review cadence, and access controls. Someone, often titled a Records Management Officer, owns the schedule. Records owners flag exceptions. IT enforces document access control on systems that store retained files, and the whole policy gets reviewed on a set cycle rather than left to drift.
Pro Tip: Before you adapt any downloaded PDF, print the schedule section and cross out every category that doesn't apply to your organization. What's left tells you how much of the template is actually reusable, and it usually surprises people how little survives the first pass.
Access controls deserve more attention than most templates give them. A retention schedule that says "keep personnel files for six years" is incomplete if it doesn't also say who can open those files during those six years. File access permissions should mirror the sensitivity of the record, HR and legal for personnel files, finance and audit for tax records, and the policy should say so explicitly rather than leaving it to IT's default settings. Documenting any deviation from the schedule, an early destruction, an extended hold, matters just as much: an undocumented exception is exactly the kind of gap that turns into legal exposure if a regulator or opposing counsel ever asks why a specific record wasn't where the schedule said it should be.
How long should you keep different types of business records?
Retention periods aren't arbitrary. Most trace back to a statute of limitations, a specific regulation, or an audit window, which means the "right" answer depends on the document type, not a single company-wide rule. The table below reflects commonly cited minimums; always confirm against your own state requirements and industry regulator before finalizing a schedule.
| Document type | Typical minimum retention | Legal basis / note |
|---|---|---|
| Tax returns and supporting documents | 3–7 years | The U.S. Chamber of Commerce recommends at least seven years for federal tax returns and supporting accounting records, since the IRS can look back further in cases of substantial underreporting. |
| Payroll records | 3 years | The federal Fair Labor Standards Act sets a 3-year minimum, though some states extend this. |
| Personnel and hiring records | 3–6 years | Varies by statute; separated-employee files often get held longer for unemployment or discrimination claim windows. |
| Contracts and executed agreements | 3 years past contract life, or longer | Extend the period if the contract includes indemnification or warranty terms that outlive the base term. |
| Board minutes and corporate governance records | Permanent | Treated as long-term archival records with no destruction date; agencies with genuinely historical records may also consult NARA guidance on permanent retention scheduling. |
The seven-year figure for tax and accounting records shows up more consistently across sample policies than almost any other number in this table, largely because it comfortably covers the IRS's standard three-year audit window plus the extended six-year window that applies when a taxpayer underreports income by more than 25%.
When two rules point to different retention lengths for the same document, don't split the difference. Apply what's called a high-water mark: document the longer period and note which authority drove that decision. If your state requires five years on a given record but a federal rule requires seven, your schedule says seven, and it says why.

How to adapt a sample policy to your organization
Turning a downloaded PDF into a policy your organization will actually follow takes more than a find-and-replace on the company name. Here's the sequence that works.
- Inventory your records and assign owners. Walk through each department and list what they actually generate and store, physical files, shared drives, email archives, SaaS platforms. Assign an owner to each category, someone accountable for knowing where it lives and applying the schedule to it.
- Map your business processes to the schedule lines. A generic template's "financial records" row needs to become your specific categories: accounts payable, expense reports, bank reconciliations. Generic labels are where enforcement breaks down later.
- Apply legal and regulatory minimums using the high-water mark approach. For every category touching tax, employment, or contract law, check your state's specific statute rather than assuming the sample PDF's number applies to you.
- Write or revise retention triggers and disposition events. Decide what starts the clock, contract execution, fiscal year close, employee termination, and what happens at the end: secure deletion, physical shredding, or transfer to archive.
- Define the approval workflow. Name who signs off (often legal counsel plus a senior operation leader), how version changes get tracked, and how the approved policy gets distributed and acknowledged.
- Document exceptions, set a review cycle, and name a point of contact. Annual review is standard; anything longer risks the schedule drifting out of sync with new regulations or new systems.
Pro Tip: Keep a running exceptions log separate from the policy document itself. When someone asks why a specific file was kept two years past its scheduled destruction date, you want a dated entry with a business justification, not a scramble to reconstruct the reasoning months later.
Some organizations resolve schedule ambiguity by defaulting to the longer retention period and using a signed client or employee representation to permit earlier destruction when appropriate, an approach Paychex outlines for employee records specifically. It's a reasonable middle ground when your legal counsel isn't certain which of two overlapping rules controls.
Legal holds, exceptions, and litigation risk
A legal hold overrides your retention schedule the moment litigation, a government investigation, or a regulatory audit becomes reasonably likely, not just after a lawsuit is filed. Once that trigger hits, scheduled destruction on any relevant record stops immediately, regardless of what the schedule says.
- Trigger events include a demand letter, a subpoena, a regulator's inquiry, or even internal knowledge that a dispute is brewing.
- Suspension is immediate and total for any record that could be relevant, including records currently mid-cycle for scheduled destruction that week.
- Custodians must be notified and tracked, and someone needs to document who received the hold notice, what records they control, and when the hold gets formally lifted.
- A written release from counsel should be required before destruction resumes, not a verbal all-clear from whoever issued the hold.
The RISD document retention and records management policy lays this sequence out clearly: implement the hold, track custodians and preserved data, then require formal written release from counsel before anything moves back to routine disposition. Getting this wrong carries real consequences. Spoliation, the destruction of evidence that should have been preserved, can result in adverse inference instructions from a judge, monetary sanctions, or in severe cases a default judgment against the organization that destroyed the records. A computer forensics guide to legal hold practices covers the practical mechanics of preserving digital evidence once a hold is issued, worth a look if your organization handles email archives or shared drives across multiple custodians.
Internally, name who has the authority to issue a hold, usually legal counsel or a compliance officer, and who's accountable for tracking it to release. A policy that's silent on this point leaves the door open for a hold to get issued informally and then forgotten.
File format and preservation best practices for PDF records
A retention schedule is only as good as the file sitting at the end of it. Records that are unreadable, unsearchable, or missing their metadata when someone actually needs them defeat the purpose of keeping them at all.
- Archive final versions as flattened PDFs. Flattening locks form fields, comments, and layers into a single static image layer, so the archived copy can't be accidentally altered after it's been finalized and signed.
- Run OCR on scanned documents so archived records are text-searchable rather than locked inside an image, which matters enormously if you ever need to search years of files during discovery.
- Preserve original metadata (creation date, author, revision history) when a record's authenticity might matter later, rather than stripping it during conversion.
- Plan for format migration. PDF/A is designed for long-term archival stability, but confirm your archive tool can still open decade-old files as software changes; periodic integrity checks catch corruption before it becomes a crisis.
- Keep highly sensitive records on local infrastructure rather than a cloud service when confidentiality is a priority, since local processing removes the exposure that comes with routing sensitive files through a third-party server.
Pro Tip: Flattened, OCRed archival copies reduce production risk during discovery specifically because you're not scrambling to search unindexed scans under a court deadline, you're running a text search that returns results in seconds.
Teams handling privileged or regulated files often prefer keeping the entire retention workflow on local hardware. A private, offline PDF editor built for business teams lets you flatten, redact, and finalize archival copies without ever uploading a sensitive file to a third-party server, which matters more than most policies acknowledge when the records in question involve client data, health information, or unreleased financial results.
Editable clauses and a sample retention-schedule row
Copy these directly into your draft and adjust the bracketed language to match your organization.
Sample purpose and scope clause:
"This policy establishes guidelines for the retention, storage, and disposition of records created or received by [Organization Name] in the course of business. It applies to all employees, contractors, and departments, and covers records in physical, electronic, and cloud-based formats. Nothing in this policy overrides retention obligations imposed by federal, state, or local law."
Sample retention-schedule row:
| Document type | Retention trigger | Retention period | Disposition method |
|---|---|---|---|
| Signed client engagement letters | Engagement termination | 7 years | Secure shredding (physical) / permanent deletion (electronic) |
Sample destruction authorization language:
"Records reaching the end of their scheduled retention period may be destroyed only upon written authorization from the Records Management Officer. Destruction must be documented on the Destruction Authorization Form, including record category, date range, method of destruction, and authorizing signature."
Sample legal-hold notice language:
"Upon issuance of a Legal Hold Notice, all scheduled destruction of records relevant to the identified matter is immediately suspended. Custodians must preserve all responsive records in their possession until the hold is formally released in writing by legal counsel."
For the full source language these clauses draw from, go back to the NYSBA law office sample, the WSBA sample, or the City of Dixon schedule for a full department-by-department breakdown.
Balancing cost, privacy, and legal defensibility
Most organizations overthink retention length and underthink documentation. My honest read after working through these templates: default to the legal minimum for each category, then require a written business justification for anything you want to keep longer. That single rule resolves most of the debate that stalls policy drafts for months.
Longer retention makes sense in specific, identifiable situations, tax records where an audit window might extend, client engagement files in litigation-prone practice areas, anything tied to an active or foreseeable dispute. Outside those cases, holding data longer than the law requires just expands your exposure surface without a corresponding benefit. ACC's guidance makes this point well: sync your privacy retention limits with your records schedule, document why you're keeping anything past the minimum, and don't let convenience become the default justification.
Whatever posture you land on, get it signed by someone with actual authority, and put a review date on the calendar. A policy nobody re-reads for five years is a policy that's already out of date.
— Lawton
Prepare, flatten, and secure your final policy PDF with LawtonPDF
Once your policy is drafted and approved, the last mile matters more than most teams expect: comparing revisions, locking the final version, and distributing it without exposing sensitive schedule details to a cloud service. LawtonPDF handles that last mile entirely on your own machine, with no file ever leaving your device.

If your policy went through multiple legal reviews, PDF compare lets you see exactly what changed between draft and final without manually scanning both versions line by line. Once the policy is approved, flatten it so employees can't accidentally alter form fields or embedded comments in the archived copy, then password-protect the distribution version so only authorized staff can open it. All of this runs locally, which matters if your retention schedule references sensitive categories like personnel files or client engagement details that shouldn't touch a third-party server. Start by reviewing the full document and PDF processing toolset and pick the tools that match your rollout, compare, flatten, and protect, before you send the final policy out for company-wide acknowledgment.
Useful primary sources and authoritative PDFs
- Independent Sector Records Retention Policy — nonprofit-specific template covering board and donor records.
- NYSBA Sample Law Office Retention/Destruction Policy — client-file destruction language for legal practices.
- WSBA Sample Document Retention Policy — professional-services-friendly retention structure.
- U.S. Chamber of Commerce retention guide — practical breakdown of retention periods by document category.
- ACC data retention and privacy guidance — syncing privacy rules with records schedules.
Sources
FAQ
How do I create a document retention policy?
Start from an authoritative sample PDF, inventory your actual records, assign owners, apply legal minimums using the high-water mark approach, and route the draft through formal legal and leadership sign off before distribution.
What documents need to be kept for 7 years?
Federal tax returns and supporting accounting documents are commonly retained for at least seven years, and many law-office sample policies apply the same seven-year period to closed client engagement files.
What is the 7-year retention policy?
It's a common practice standard, not a single universal law, that keeps tax and accounting records for seven years to comfortably cover the IRS's extended six-year audit window for substantial underreporting.
What are the legal requirements for document retention?
Legal requirements vary by document type and jurisdiction: payroll records carry a federal 3-year minimum under the FLSA, tax records are commonly kept 3 to 7 years, and litigation or an audit can trigger a legal hold that suspends any scheduled destruction regardless of the underlying schedule.
Can Lawtonpdf help prepare a retention policy for distribution?
Yes. Lawtonpdf lets you compare policy drafts, flatten the final version so it can't be altered, and password-protect the distributed copy, all processed locally on your own computer rather than through a cloud service.
