These questions arise from Slack threads late on Fridays, hurried hallway conversations before audits, and panicked emails when legal sends a preservation notice. They're the practical, messy questions that don't fit neatly into your Records Control Schedule but determine whether your program actually works.
Here's what practitioners are asking right now, with answers you can use Monday morning.
Q1: "Our retention schedule says 'permanent' for half our record types. Does that really mean forever?"
Not necessarily, and that's often the problem.
"Permanent" on a Records Control Schedule typically means one of three things: the record has enduring legal or historical value, you haven't done the analysis to determine an actual retention period, or you're risk-averse and defaulting to indefinite retention.
Start by separating true permanent records (articles of incorporation, bylaws, capital stock records, meeting minutes) from records you've labeled permanent out of caution. For the latter group, work backward from the triggering event or regulatory requirement. If you're keeping payroll records permanently but the actual requirement is four years after termination, you're creating unnecessary risk exposure and storage costs.
The test: if you can't articulate why a record must be kept forever in terms of a specific legal, fiscal, or operational need, it probably doesn't need permanent retention.
Q2: "We just found out a state law requires longer retention than our federal schedule. Which one wins?"
The longer period wins, always.
Your Records Control Schedule must accommodate the most restrictive requirement that applies to your organization. If HIPAA requires six years for documents containing protected health information but your state medical records law requires ten, you retain for ten.
This is where functional classification becomes critical. Don't build separate schedules for federal vs. state requirements. Instead, map each record series to all applicable regulations, then apply the longest retention period. Document your analysis in the schedule itself so future records managers understand why the finance team's vendor contracts are kept for seven years (SOX audit trail requirements) while HR's employment applications are kept for three (EEOC compliance after a hiring decision).
The harder question: do you apply the longest requirement globally, or jurisdiction-by-jurisdiction? If you operate in multiple states with varying requirements, you'll need to decide whether operational simplicity (one retention period for all locations) outweighs storage costs (keeping California records longer than legally required because Texas law is more stringent).
Q3: "Can we just scan everything and shred the paper? Our lease is up and we need the space."
Only if you've verified that digital copies satisfy your legal and regulatory requirements for each record type.
Some records must be retained in their original format. Real estate documents with original signatures, notarized contracts, and certain financial instruments often require hard copies. Even when digital is acceptable, you need to ensure your scanning process creates legally defensible copies: that means proper resolution (typically 300 dpi minimum), indexing that matches your Business Classification Scheme, and fixity checks to verify file integrity over time.
Here's the workflow that works: before you scan and destroy any record series, document that (1) no regulation requires original format retention, (2) your scanning process meets relevant standards, (3) you've implemented appropriate access controls and backup procedures for the digital copies, and (4) you have a Records Disposition Authority approving the destruction of the originals.
The space pressure is real, but destroying originals before you've verified digital copies are complete and retrievable is how organizations end up explaining to regulators why they can't produce required records.
Q4: "Someone just quit and we need to keep their emails. How long, and do we need to keep everything?"
It depends entirely on what's in those emails, not who sent them.
Employee departure doesn't create a retention requirement. The content does. An email approving a capital expenditure is a financial record (likely seven years under SOX if you're publicly traded). An email confirming a meeting time isn't a record at all.
This is why records declaration matters. If your organization requires employees to file records into a managed repository, you're already capturing business records separately from transitory communications. If you're not doing that, you're stuck with the expensive option: preserving entire mailboxes until you can review them.
For personnel files specifically, retention typically runs three to seven years after termination, depending on your jurisdiction and whether the file contains medical information, I-9 forms, or other regulated content. But the employee's business correspondence should be retained according to the record series it belongs to, not the employment relationship.
Q5: "We're implementing a new document management system. Can we use this as an excuse to clean house?"
You can, but not the way you're thinking.
A system migration is an excellent opportunity to apply your Records Control Schedule rigorously. Records past their retention period and not subject to a Legal Hold can be disposed of rather than migrated. That's defensible and smart.
What you can't do: use the migration as cover for ad-hoc deletion of records still within their retention periods because they're "old" or "probably not important." That's exactly how Morgan Stanley ended up with a $13 million fine in 2017 for destroying records before their required retention periods.
Build a disposition review into your migration plan. Identify record series, apply cutoff dates, get proper Records Disposition Authority, and document everything. The court won't care that you were trying to reduce migration costs if you destroyed records you were required to keep.
Q6: "Legal just issued a preservation notice. Do we stop all scheduled destructions, or just for the relevant records?"
Just the relevant records, but define "relevant" broadly at first.
A Legal Hold suspends normal retention and disposition for records that might be material to the litigation, investigation, or audit. It doesn't freeze your entire Records Control Schedule. Your finance team can still dispose of vendor invoices from 2010 if they're unrelated to the matter.
The practical challenge: determining scope. Work with legal counsel to identify the record series, date ranges, custodians, and keywords that define the hold. Then implement a Records Freeze for those specific records in your system. If your document management system doesn't support granular holds, you'll need to suspend disposition more broadly until you can isolate the responsive records.
Document every hold, every scope decision, and every release. If you're disposing of records during an active Legal Hold period (even unrelated records), make sure your Records Disposition Authority clearly notes that the disposed records were outside the hold scope.
Q7: "Our retention schedule says 'secure destruction required.' What does that actually mean?"
It means you must destroy records in a way that prevents reconstruction or recovery, and you must be able to prove you did it.
For paper records, secure destruction typically means cross-cut shredding to a particle size that makes reassembly impractical. For electronic records, it means overwriting or degaussing (for magnetic media) or physical destruction of storage devices. Simply deleting files or emptying the recycle bin doesn't meet the standard.
The proof matters as much as the method. Professional shredding services provide a certificate of destruction that documents what was destroyed, when, and how. If you're doing destruction in-house, you need equivalent documentation: a destruction log that records the record series, disposition authority, destruction method, date, and the person who performed or witnessed the destruction.
Some industries require witnessed destruction. If you're handling protected health information under HIPAA or consumer financial data under the Gramm-Leach-Bliley Act, verify whether your regulations require an authorized representative to witness the destruction process.
Q8: "We have records stored with three different vendors and two on-premises locations. How do we track retention across all of them?"
You need a single source of truth that's location-agnostic.
Your Records Control Schedule should define retention by record series and function, not by where the records happen to be stored. Build an inventory that maps physical and digital locations back to the schedule. Each storage location (whether it's an off-site facility, a cloud repository, or a file cabinet) should be tagged with the record series it contains, so you can apply disposition consistently.
This is where indexing becomes critical. Off-site storage facilities typically provide inventory management, but you need to ensure their indexing aligns with your Business Classification Scheme. If one vendor calls them "personnel files" and another calls them "HR records" and your schedule calls them "employee records," you'll miss records when it's time for disposition.
The goal: when a record series reaches its retention period, you can identify and dispose of all instances of that series regardless of location, format, or storage vendor. If you can't do that, you don't have retention control; you have record sprawl with a schedule attached.
Where to Go for More
Your Records Control Schedule is a living document. As regulations change and your business evolves, schedule maintenance becomes ongoing work, not a one-time project. Review your schedule annually, document your analysis, and update retention periods when requirements change.
For state-specific retention requirements, consult your state's archives or records management authority. For federal regulations, the specific statute or rule (HIPAA, SOX, GLBA, FERPA) will include retention provisions. And when you're not sure whether you can dispose of something, the answer is always: verify first, delete later.



