Wind-downs and transitions
Record retention schedule for a closed company: a template by record type
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A record retention schedule for a closed company lists each record type with its system, the legal or contractual reason to keep it, the custodian, the destroy or review date and whether it may be license-eligible. The rule that prevents costly mistakes: nothing flagged for review is destroyed until counsel and the custodian sign off.
Key takeaways
- A closed company's schedule needs a named custodian and a destroy or review date for every record type, because no operating team remains to decide later.
- Retention minimums come from tax, employment, corporate and contract rules, and the clock usually starts at an event such as the final tax return or the end of a contract.
- Customer contracts and data processing agreements can require deletion, so the schedule must record maximums as well as minimums.
- Mark operational records as Review, not Yes, for licensing until rights and privacy checks are done.
- A legal hold overrides every destroy date in the schedule.
How is a closed company's retention schedule different from an operating policy?#
A closed company's retention schedule differs from an operating policy because it has to work without the people and systems that normally apply it. An operating policy assumes departments, a records manager and live software with retention settings. After closing there may be one custodian, a storage bill and a few encrypted drives.
That changes what the schedule must say. Every row needs an owner after dissolution, a location that survives the last subscription, a trigger event that is already known, and a destroy or review date someone will actually act on. Records kept only because nobody decided are a cost and a privacy exposure, not an asset.
The schedule should also answer a question operating policies rarely ask: which retained records might be licensed rather than simply stored. Archives of support conversations, job histories and quality records can interest AI developers once rights and privacy are cleared, and that option disappears if they are destroyed by default.
The template columns and what to enter#
The template uses one row per record type, not per file or per system, so a single system such as NetSuite may appear in several rows. Use the columns below and keep entries short enough to scan on one screen.
Add a note wherever a system can delete records on its own, because automated rules keep running after the staff who set them leave. Zendesk admins can create ticket deletion schedules that keep deleting matching archived tickets, and deleted tickets cannot be restored. Gong cannot restore calls purged by a shortened retention period. Slack admins on paid plans can set custom deletion periods, and that deletion is permanent. Pause such rules until exports are verified, unless counsel confirms a deletion obligation requires them.
| Column | What to enter | Common mistake |
|---|---|---|
| Record type | A plain name such as payroll registers or support tickets | Grouping unrelated records under one system name |
| Department | Finance, HR, operations, sales, support, engineering or legal | Leaving shared records such as email without an owner |
| System and format | Source system plus the format kept, such as PDF, CSV or PST | Listing a system that will be cancelled as the location |
| Retention basis | The tax, employment, corporate, contract or regulatory reason to keep it | Writing a period with no reason behind it |
| Clock trigger | The event that starts the period, such as final return filed or contract ended | Counting everything from the shutdown date |
| Custodian | A named person or firm, plus a backup | Naming an employee who is about to leave |
| Location after closing | Encrypted archive, records vendor, accountant or counsel | Copies left on personal laptops |
| Destroy or review date | A calendar date, or review on a named event | Open-ended entries that never come due |
| Legal hold | Yes or no, with the matter reference | Destroying records that are under hold |
| Personal data | Types present, such as employee, customer or candidate data | Ignoring personal data inside email and chat |
| License-eligible | No or Review, with the reason | Marking Yes before any rights review |
Template rows by record type#
The rows below give a starting point for a US company that has closed. Retention bases are described rather than given as periods, because periods differ by state, industry and the company's own contracts, and they should be set with counsel and the company's tax adviser.
| Record type | Typical system | Retention basis to confirm | License-eligible |
|---|---|---|---|
| Formation documents, minutes and resolutions | Entity binder or board portal | State corporate law and the dissolution process | No: keep as a corporate record |
| Tax returns and workpapers | Accounting system and CPA files | Federal and state tax limitation periods | No |
| General ledger, payables and receivables | QuickBooks, NetSuite or Sage | Tax, audit and creditor claims | No |
| Payroll and personnel files | ADP, Gusto or an HRIS | Federal and state employment and wage rules | No |
| Benefit plan records | Plan administrator portal | Plan documents; ERISA may apply | No |
| Customer and vendor contracts | Contract repository or CRM attachments | Contract terms plus claim periods | No, but they govern what else can be licensed |
| Support tickets and chat transcripts | Zendesk, Intercom or Freshdesk | Customer contracts, privacy notices and warranties | Review |
| CRM activity and sales notes | Salesforce or HubSpot | Privacy notices and contract terms | Review |
| Engineering issues and code reviews | Jira, GitHub or GitLab | IP ownership and customer code terms | Review |
| Jobs, dispatch and service history | ServiceTitan, Housecall Pro or FieldEdge | Warranty and service obligations | Review |
| Quality records, NCRs and CAPAs | A QMS or the ERP quality module | Product liability, warranty and customer terms | Review |
| Email and team chat | Microsoft 365, Google Workspace or Slack | Legal holds, employment and privacy rules | Review, with a strict privacy screen |
How do you fill in the retention basis without guessing?#
The retention basis is filled in from sources, not memory. Each row should point to the rule or document that requires the record to be kept and name the person who confirmed it, so a later custodian can see why a date was chosen.
Treat this as general information rather than legal or tax advice. Retention rules differ by state, industry and contract, so confirm each row with counsel and the company's tax adviser before relying on it.
- Tax: the tax adviser confirms periods for returns, payroll tax filings and supporting records, including state rules.
- Employment: counsel checks federal and state requirements for payroll, personnel, hiring and safety records.
- Corporate: counsel confirms what the dissolution process requires, including how long records must stay available for claims.
- Contracts: review customer, vendor and lease agreements for retention, audit, return and deletion clauses.
- Industry rules: check any regulator, licensing board or certification body that oversaw the company's work.
- Insurance: read claims-made policies and any tail coverage for record requirements.
- Disputes: list open or threatened claims, each of which can trigger a legal hold.
When a contract requires deletion instead of retention#
A contract that requires deletion sets a maximum, not a minimum, and the schedule must show it. Many software and services agreements, and most data processing agreements, oblige the company to return or delete customer data when the relationship ends, sometimes with a certificate of deletion.
Those obligations can conflict with a wish to keep everything. Where they do, the deletion obligation usually governs customer-owned data, while the company's own internal records about how it did the work may be treated differently. Record each conflict in the notes column and let counsel decide; never resolve it by quietly keeping the data.
Records under a deletion obligation should be marked No in the license-eligible column. That keeps them out of any later fit check and protects the custodian from relying on data the company was required to give up.
How to decide what goes in the license-eligible column#
The license-eligible column records a first view, not a decision. Use No for records that must be kept but have no licensing role, such as tax files, and for records the company must delete. Use Review for operational records the company created in the course of its work, where licensing might be possible after checks.
A Review flag delays destruction until the assessment is done, but it does not extend retention of personal data beyond what is lawful. If an assessment cannot happen before a destroy date, the destroy date wins unless counsel advises otherwise.
| Question | If yes | If no |
|---|---|---|
| Did the company create or control the records in its own operations? | Continue | Mark No: client- or customer-owned |
| Do contracts and notices leave room for use beyond the original purpose? | Continue | Mark No, or flag for counsel |
| Can personal and confidential details be removed while the work stays visible? | Continue | Mark No |
| Is there enough connected history to show requests, decisions and outcomes? | Mark Review | Keep only as long as retention requires |
Illustrative: a mechanical contractor closes with a schedule in place#
Illustrative: a fictional commercial mechanical contractor with a long service history decides to close after its owners retire. It ran ServiceTitan for service and maintenance work, QuickBooks for accounting, Gusto for payroll and Microsoft 365 for email.
The wind-down officer built the schedule with the former controller as custodian and the outside CPA as backup. Tax, payroll and contract rows were marked No and assigned to the CPA's archive. ServiceTitan job histories, equipment records and technician notes were exported to an encrypted archive and marked Review, with customer contact details flagged as personal data.
Email was marked Review with a strict privacy screen, and a pending warranty claim put a legal hold on records for one building owner. The board approved the schedule, subscriptions were cancelled only after exports were verified, and the Review rows went to a metadata-only licensing assessment before any destroy date arrived.
How SourceX uses a retention schedule#
SourceX uses a closed company's retention schedule as the starting map for the Supply step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Rows marked Review become candidates for a metadata-only fit check, and rows marked No stay out entirely.
Rights review then tests the contracts named in the schedule, and the custodian's release decision is recorded in the SourceX Evidence Packet with provenance, permitted use and the privacy record. SourceX does not set retention periods; counsel and the tax adviser do.
Frequently asked questions
Who should be the records custodian after the company closes?
Choose someone who will be reachable for the full retention period and has no conflict, often a former finance officer, the company's CPA, outside counsel or a records storage firm under contract. Name a backup, give both access to the archive and its encryption keys, and record the arrangement in the board's wind-down resolutions.
Can we destroy records early to cut storage costs?
Not records with a retention requirement or a legal hold. For everything else, early destruction is a decision for the custodian with counsel's input, and it should follow the schedule rather than happen ad hoc. Before destroying operational archives marked Review, finish the licensing assessment so the decision is informed.
Does licensing records change how long we must keep them?
A license can add obligations, such as keeping a record of what was delivered and who authorized it, but it does not shorten legal retention periods. Delivered copies are governed by the license terms, while the company's own retained copy still follows the schedule.
Should the schedule be organized by department or by record type?
By record type, with department as a column. A retention schedule organized by department alone tends to miss shared records such as email and chat, and it hides cases where one system holds records with very different retention rules.
What if a legal hold arrives after some records were destroyed?
Counsel should review the hold notice at once and assess what remains. A documented schedule and destruction log show what was destroyed, when and under which rule, which helps counsel respond. Suspend every remaining destroy date that could touch the matter until counsel clears it.
Sources
- Zendesk admins can create ticket deletion schedules that delete archived tickets after a set period; deleted tickets cannot be restored and schedules keep deleting matching tickets. Source
- Once a shortened retention period purges calls, Gong cannot restore them. Source
- Admins can set custom deletion periods, and message and file deletion is permanent. Source
Related resources
- QuestionDo I need customer consent to license support tickets?
- QuestionCan I see a sample contract?
- InsightDo you need client consent to license de-identified RFIs and submittals?
- InsightOpt-in vs opt-out for AI training in B2B SaaS contracts
- InsightCan a distributor license its pricing and quote history?
- IndustryLegal data
See if your company qualifies
A short company assessment. No data uploads are needed.