When legal asks why a set of contracts no longer exists, you don't want to be piecing together an answer from memory. You want a destruction certificate that shows exactly what was destroyed, when, who authorized it, and under which retention rule. This template gives you that documentation.
Purpose of the Template
A destruction certificate creates a permanent record of each disposition action your organization takes. It's not optional bureaucracy. It's the primary evidence that you followed your retention schedule consistently and that deletions weren't arbitrary or suspicious. When litigation or an audit surfaces questions about missing records, your destruction certificates turn "we deleted those" into "here's exactly what we did and why."
Use this template every time you destroy records, whether you're deleting digital files, shredding paper, or wiping backup media. One certificate per destruction event. The certificate itself becomes a permanent record that you retain indefinitely.
Prerequisites
Before you use this template, ensure you have:
- An approved Records Control Schedule that defines retention periods and trigger events for each record type.
- A documented disposition process specifying who can authorize destruction and what review steps are required.
- Confirmation that no Records Freeze or Legal Hold applies to the records you're about to destroy.
- A method to verify that the records you're destroying meet the eligibility criteria (retention period expired, trigger event occurred, no active holds).
If any of these pieces are missing, pause. Destruction without this foundation isn't defensible.
The Template
DESTRUCTION CERTIFICATE
Certificate Number: [Unique identifier, sequential or system-generated]
Date of Destruction: [YYYY-MM-DD]
Method of Destruction: [Secure shredding / Secure deletion / Degaussing / Incineration / Other]
RECORDS DESTROYED
Record Series Title: [From your Records Control Schedule]
Record Series Number: [From your Records Control Schedule]
Date Range of Records: [Oldest to newest record in this batch]
Physical/Digital Location: [Where records were stored before destruction]
Volume: [Number of boxes / File count / GB / Other measure]
Retention Rule Applied: [Cite specific rule from your schedule]
Trigger Event: [What started the retention clock]
Trigger Date: [When that event occurred]
Retention Period: [How long records were held after trigger]
Eligibility Date: [When records became eligible for destruction]
AUTHORIZATION AND VERIFICATION
Requested By: [Name, title, department]
Date Requested: [YYYY-MM-DD]
Hold Check Performed By: [Name, title]
Hold Check Date: [YYYY-MM-DD]
Hold Status: [No active holds / Holds reviewed and records excluded / Other]
Destruction Authorized By: [Name, title]
Authorization Date: [YYYY-MM-DD]
Destruction Performed By: [Name, title, or vendor name]
Destruction Completion Date: [YYYY-MM-DD]
Vendor Certificate Attached: [Yes/No, if third-party destruction used]
NOTES
[Any exceptions, partial destructions, issues encountered, or relevant context]
CERTIFICATION
I certify that the records described above were destroyed in accordance with the organization's Records Control Schedule, that no Legal Hold or Records Freeze applied to these records at the time of destruction, and that this destruction was carried out in the normal course of business.
Signature: ___________________________
Name: [Records manager or authorized signatory]
Title: [Title]
Date: [YYYY-MM-DD]
Customizing the Template
Certificate numbering: Choose a system that works at your scale. Small programs can use sequential numbers (DEST-2024-001). Larger organizations might need location codes, department identifiers, or system-generated IDs. Whatever you pick, make it consistent and trackable.
Record series fields: Your Records Control Schedule should already define series titles and numbers. Use those exactly as written. Don't paraphrase or abbreviate. If your schedule doesn't assign numbers, add them. They make auditing and cross-referencing much easier.
Trigger events: This is where many certificates fall apart. "Seven years" isn't enough. You need the specific event that started the clock: contract execution date, project completion, fiscal year end, employee termination. If your team can't identify the trigger date, the records probably shouldn't be destroyed yet.
Hold check: Don't skip this. Even if you're confident no holds apply, document that you verified it. Include the name of the person who checked, the date they checked, and what they checked against (your hold register, legal's tracking system, whatever your process requires). If you find that some records in the batch are under hold, remove them and note the exclusion.
Vendor destruction: If you use a third-party vendor for shredding or digital media destruction, attach their certificate of destruction to yours. Your certificate documents the decision and authorization. Their certificate documents the execution. You need both.
Notes section: Use this for anything that deviates from routine. Maybe you destroyed 95% of the batch but held back 5% because a new matter came in. Maybe the destruction was delayed by two weeks because of a system issue. Document it. Gaps and exceptions aren't problems if they're explained.
Validation Steps
After you complete each certificate:
Cross-check the retention rule against your current Records Control Schedule. Make sure the rule you cited is still active and that you applied it correctly. Schedules change. Old certificates sometimes reference outdated rules.
Verify the math. If your trigger date was March 15, 2017, and your retention period is seven years, your eligibility date should be March 15, 2024. Simple errors here raise questions about whether you're actually following a consistent process.
Confirm the hold check happened. Don't sign off until you've seen evidence that someone verified hold status. This is the step that protects you from destroying records you shouldn't have.
Store the certificate permanently. These certificates are permanent records. They don't expire. File them where you can retrieve them quickly, because when someone asks about a deletion from three years ago, you need to produce the certificate without delay.
Review a sample of certificates quarterly. Pull a random selection and check for completeness, consistency, and accuracy. Are people filling out every field? Are they using the right retention rules? Are dates logical? Spot-checking catches drift before it becomes a pattern.
When your destruction process is working, certificates should look similar across time and across different people. Consistency is the point. If every certificate is formatted differently or key fields are routinely left blank, your process isn't being followed. Fix that before someone outside your organization starts reviewing your documentation.
Your destruction certificates won't prevent every question about missing records. But they will turn those questions into routine responses instead of credibility problems.



