Consulting and recruiting
How long should consulting firms keep engagement files?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Consulting firms should keep engagement files for the longest period set by the client contract, the professional liability exposure, statutes of limitation and tax or employment rules, then return, destroy or de-identify them. There is no single number. Split client-owned files from firm-owned records, because they follow different rules and only firm records have a useful life after the engagement.
Key takeaways
- No single retention period fits every engagement file; the longest applicable driver usually sets the floor.
- Client contracts can require return or destruction, which overrides the firm's wish to keep files.
- Liability exposure means keeping enough to show what was asked, what was delivered and what the client decided.
- Firm-owned records such as proposals, staffing plans and review memos can be kept longer for business value.
- A legal hold suspends deletion for affected files until counsel releases it.
What decides how long to keep engagement files?#
Engagement file retention is decided by four drivers: the client contract, the firm's professional liability exposure, the law governing specific record types, and the firm's own business needs. The safe period for a given file is usually the longest of those that apply to it.
Contracts come first because they bind the firm directly. An MSA may require the firm to return or destroy client materials at the end of the engagement, to keep them for a minimum audit period, or both, often with an exception for one archival copy held under continuing confidentiality.
Liability is the second driver. Claims about advice can surface long after an engagement closes, and the firm's defense depends on showing what it was asked to do, what it delivered and what the client decided. Statutes of limitation and repose vary by state and claim type, so counsel should set that tail rather than a template.
Law and business need fill in the rest. Invoices and time records follow tax and accounting rules, staffing records follow employment rules, and engagements for clients in regulated industries can bring sector-specific record duties through the contract. Business value is the only driver that argues for keeping a record after every obligation has ended.
Retention drivers by engagement file type#
Retention drivers differ by file type, so a single folder-level rule rarely works. The table pairs each common engagement file with the driver that usually controls it, any client-return obligation, and a practical archive note.
| File type | Contract or insurer driver | Client-return obligation | Archive notes |
|---|---|---|---|
| Signed MSA, SOWs and change orders | Liability defense; contract disputes | None; this is the firm's own copy | Keep for the relationship plus the liability tail counsel sets |
| Client-provided data and documents | MSA confidentiality and data terms | Often return or destroy at termination | Keep only what the contract allows and document any archival carve-out |
| Final deliverables | Liability defense; client ownership terms | Client may own them; firm may keep a record copy | Store as a locked final with the delivery date |
| Working papers and analyses | Insurer and counsel expectations | Depends on ownership clauses | Separate client data inside them from firm analysis |
| Correspondence and meeting notes | Liability defense | Usually none unless they carry client materials | Keep decisions and approvals; prune routine scheduling |
| Time entries and invoices | Tax and billing disputes | None | Follow finance retention rules set with your accountant |
| Proposals and staffing plans | Business value | None unless they hold client confidential detail | Keep longer if useful; review for client detail |
Where client-return obligations bite#
Client-return obligations bite hardest on files that mix client material with firm work. A working paper that combines the client's raw cost data with the firm's analysis cannot be returned in part without splitting it, and many firms never split it while the engagement is live.
The fix is structural. Store client-provided material in a dedicated folder or library per engagement, keep firm analysis separately, and record the end-of-engagement action taken: returned, destroyed with a certificate, or retained under an archival carve-out. Those three words in a close-out log save hours when a client or insurer asks later.
Destroy, keep or de-identify: the upside question#
The upside question is whether firm-owned records are worth keeping once their defensive period ends. Proposals with win or loss outcomes, staffing plans, project review memos and lessons-learned write-ups show how the firm actually works, and they are the records most useful for internal AI search, proposal drafting and, in some cases, licensing to AI developers.
Destroying them on a fixed schedule is simple but loses that history. Keeping them indefinitely raises discovery and privacy exposure. A middle route is to de-identify records that have passed their defensive period: remove client names and identifying facts, reduce employee details to roles, and keep the workflow. Counsel should confirm that de-identified versions fall outside contract and privacy obligations before originals are destroyed.
- Proposals linked to win or loss outcomes and client feedback.
- Staffing plans showing planned and actual allocation.
- Project review and quality review memos.
- Methodology updates and internal training drawn from engagements.
- Post-engagement retrospectives and close-out reports.
Making platforms enforce retention#
Retention periods written in a policy document change nothing until the platforms apply them. Most document platforms, including SharePoint, Google Drive and Box, support retention labels or policies, but features differ by plan, so check your subscription tier and the vendor's documentation before designing around a feature.
Apply retention at the engagement level where possible, triggered by the engagement close date in the PSA or CRM rather than by file creation date. That keeps a long engagement's early files from expiring while the work is still active. Email, Slack and Teams need their own settings, because chat and mail retention are configured separately from document libraries.
Two blind spots catch most firms. Backups and archived mailboxes of departed partners often hold copies that the retention policy never touches, and personal cloud folders used during remote work sit outside every policy. Include both in the schedule, or the firm will certify destruction it cannot fully prove.
When a legal hold applies#
A legal hold suspends normal deletion for the engagement files, custodians and systems it names. When a dispute, investigation or claim is reasonably anticipated, deletion stops for the relevant engagement files, including email and chat, until counsel releases the hold.
Holds also freeze any plan to reuse records. Files under hold should not be de-identified, moved or licensed without counsel's approval, because altering them can create spoliation risk.
Keep a hold register that names each hold, the engagements and custodians it covers, the date issued and the date released. Without one, holds linger for years after the matter closes, or are lifted before every system was covered.
Illustrative: an organizational change consultancy cleans up its file share#
Illustrative: a fictional organizational change consultancy keeps engagement files across a legacy file share, a newer SharePoint site and partners' mailboxes. It has never applied a retention schedule, and its insurer's renewal questionnaire asks for one.
The firm sorts files into client-owned, firm-owned and mixed. Client data from closed engagements with return-or-destroy clauses is destroyed and certified. Signed contracts and final deliverables stay under the liability tail counsel set. Proposals, staffing plans and review memos are de-identified and kept as a firm knowledge archive, which later feeds an internal proposal search tool and a metadata-only licensing fit check.
How SourceX views retained engagement records#
SourceX considers only firm-owned or properly cleared records for licensing, and it never asks a firm to keep files it is obliged to return or destroy. The first conversation is a metadata-only fit check covering systems, years of accessible history and known restrictions.
Where records proceed, the Rights step of the SourceX five-step transaction checks client contracts and legal holds before any preparation, and the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization.
Frequently asked questions
Should we keep engagement files forever to be safe?
Usually not. Indefinite retention enlarges what must be searched and produced in disputes, raises privacy exposure and may breach return-or-destroy clauses. Set periods by file type with counsel, then destroy or de-identify on schedule.
Does our insurer set retention requirements?
Some professional liability policies and insurer risk guides include record-keeping expectations, and renewal questionnaires often ask about them. Read your policy and ask your broker, since expectations vary by carrier and practice area.
Who should own the retention schedule in a consulting firm?
Usually one senior person, often the COO or the firm's general counsel, who gathers views from finance, IT and the practice heads. That owner approves exceptions, works with counsel to release holds and signs off on destruction certificates, so decisions are traceable later.
Do employee details in engagement files change the rules?
They can. Staffing plans, timesheets and evaluations contain employee information that employment and privacy laws may govern. Handle those fields under your HR retention rules, even when they sit inside an engagement folder.
Can we keep an archival copy after returning client files?
Only if the contract allows it. Many MSAs permit one archival copy for legal or compliance purposes, subject to continuing confidentiality. Record where that copy lives, who can open it and when it will be destroyed.
Related resources
- QuestionDo I need customer consent to license support tickets?
- QuestionHow do I tell my employees about data licensing?
- InsightWhat compliance checks do insurance carriers and TPAs need before licensing data to AI companies?
- InsightDo you need client consent to license de-identified RFIs and submittals?
- InsightCan a distributor license its pricing and quote history?
- IndustryLegal data
See if your company qualifies
A short company assessment. No data uploads are needed.