Skip to content

Manufacturing

Records retention schedule template for manufacturers

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A records retention schedule for manufacturing lists every record class, its system of record, the event that starts the clock, what sets the period and who owns disposal. Set each period by the strictest driver: law, customer contract, quality standard or liability exposure. Add a reuse column, because retained quality data may support AI licensing within customer limits.

Key takeaways

  • Organize the schedule by record class rather than by department or system, so one rule covers every copy.
  • Each row needs a trigger event, such as fiscal year end, end of production for a part or termination of employment.
  • When several drivers apply to one record, the longest period wins.
  • A legal hold overrides the schedule for every record it covers until counsel releases it.
  • A reuse column flags which retained records could be licensed and which carry customer or privacy limits.

What a manufacturing retention schedule has to cover#

A manufacturing retention schedule has to cover every record class the company creates, from tax files to historian data, and state how long each is kept, where the authoritative copy lives and how it is destroyed. Many manufacturers run without one and rely on whatever the ERP and file servers happen to keep, which leaves too much in some places and too little in others.

This template is general information, not legal advice. Retention periods come from federal and state law, customer contracts, quality standards and liability exposure, and they differ by company, product and location. Have counsel set or confirm every period before the schedule is adopted.

  • Record class and examples, so staff can recognize what falls under each row.
  • System of record, so everyone knows which copy is authoritative.
  • Trigger event that starts the retention clock.
  • Period source: the law, contract or standard that sets the period.
  • Period, filled in and approved by counsel.
  • Owner responsible for keeping and disposing of the records.
  • Disposal method and proof, such as a certificate of destruction.
  • Reuse note covering internal analytics and possible licensing limits.

Template: business records#

The business-records part of the schedule covers finance, people, contracts and governance. These rows are mostly driven by tax, employment and corporate law, and they tend to be the best documented already, often because the outside accountant asked.

Template: business records
Record classExamplesSystem of recordTrigger eventPeriod source
Accounting and taxGeneral ledger, AP and AR, fixed asset register, tax returnsERP, tax filesEnd of fiscal year or filing dateIRS: until the limitation period for the return ends, generally 3 years, 6 or 7 years in some cases; property records until it ends for the year of disposal. Confirm with counsel and CPA
Payroll and timekeepingPay records, time punches, withholding formsPayroll system, time clocksEnd of pay year or terminationIRS: employment tax records at least 4 years after the tax is due or paid, whichever is later; wage-hour and state rules may differ
Personnel filesApplications, I-9 forms, reviews, disciplineHRIS, paper filesTermination of employmentEmployment and immigration rules
Benefit plansPlan documents, enrollment, pension service recordsBenefits administratorPlan termination or final participant payoutBenefits law, often very long
ContractsCustomer terms, quality agreements, NDAs, purchase ordersContract repository, ERPExpiry plus any survival periodContract terms and limitation periods
Corporate recordsFormation documents, minutes, equity recordsLegal filesKept while the entity existsCorporate law

Template: plant and product records#

Plant and product records are where manufacturers' schedules usually fall short. Their periods are driven less by statute and more by customer agreements, certification standards and product liability, so the rows need input from quality, engineering and EHS as well as legal.

Template: plant and product records
Record classExamplesSystem of recordTrigger eventPeriod source
ProductionWork orders, travelers, routings, MES transactionsERP, MESWork order close or last shipment of the partCustomer contracts, business need
QualityInspection data, SPC, NCRs, CAPAs, MRB decisionsQMS, MESEnd of production for the part numberQuality standard, customer quality agreement, liability exposure
TraceabilityLot and serial genealogy, material certs, certificates of conformanceERP, QMSEnd of product life in serviceCustomer and sector requirements, liability exposure
CalibrationGauge records, calibration certificatesCalibration softwareGauge retirementQuality standard, customer audits
EngineeringDrawings, ECOs, PPAP or first article filesPDM, QMSPart obsolescenceCustomer contracts; customer-owned designs follow customer terms
MaintenanceWork orders, PM history, equipment manualsCMMSEquipment disposalBusiness need, warranty and insurance; equipment cost records follow the IRS property rule
Safety and healthInjury logs, exposure monitoring, medical surveillanceEHS software, occupational health providerRecord date or end of employmentOSHA: 300 Log, 301 forms and annual summary for 5 years after the calendar year covered (29 CFR 1904.33); exposure records at least 30 years and medical records for employment plus 30 years (29 CFR 1910.1020)
EnvironmentalPermits, monitoring reports, waste manifestsEHS filesPermit closure or report dateFederal and state environmental rules
Plant dataHistorian tags, alarm logs, machine logsHistorian, SCADADate recordedBusiness need unless a rule or customer requires more

How to set the trigger and the period#

The trigger event matters as much as the period. A quality record counted from its creation date may be destroyed while the part is still shipping, so plant records usually count from end of production, end of product life in service or equipment disposal instead.

When more than one driver applies, the longest wins. A customer quality agreement, an IATF 16949 or AS9100 requirement, a sector rule and your own product liability exposure may each point to a different period for the same NCR. Record every driver in the period source column so a reviewer can see why the period was chosen.

Legal holds sit above the schedule. When litigation, an investigation or an audit is reasonably anticipated, counsel issues a hold and disposal stops for the covered records, whatever the schedule says, until counsel lifts it.

Where retention meets reuse#

Retention and reuse are separate decisions, and the schedule is a practical place to connect them. Retained inspection data, SPC history, NCRs and CAPAs support internal analytics, and some AI developers license quality and maintenance records linked to outcomes. A reuse column records which classes are candidates and which limits apply.

Retention can also be a ceiling. Privacy laws may require personal data to be deleted once its purpose ends, and a possible future license is not a reason to keep personal data longer. The usual approach is to keep operational records under the schedule and remove personal details before any outside use, with counsel deciding what is allowed.

Where retention meets reuse
Record classReuse potentialCommon limit
NCRs, CAPAs and MRB decisionsLinked defect, cause and disposition historyCustomer quality agreements may restrict disclosure
Inspection and SPC dataMeasurement history showing drift and capabilityCustomer part numbers and drawings removed or excluded
Maintenance work ordersSymptom, repair and outcome sequencesTechnician names and hosted vendor terms
Customer drawings and specificationsGenerally none outside the customer relationshipCustomer-owned, with return or destroy obligations
HR, payroll and medical recordsNone for licensingPersonal and health data, kept out of scope

Illustrative: a gear maker writes its first schedule#

Illustrative: a fictional gear manufacturer runs Epicor, a separate QMS and a CMMS, and has never had a formal retention policy. The CFO learns that the ERP has never purged anything while the file server deletes old folders whenever it fills, so some quality history is already gone while old payroll exports sit in shared folders.

The CFO and outside counsel build a schedule from this template, with the quality manager filling in customer requirements part family by part family. They set quality and traceability records to count from end of production, move HR exports into the HRIS with access controls, and add a reuse column that flags NCRs, inspection data and maintenance work orders as candidates and customer drawings as excluded.

The outcome is one approved schedule, certificates of destruction for records past their period, and a clear list of retained records the company could assess for licensing without touching personal data or customer designs.

How SourceX uses a retention schedule#

A retention schedule speeds up the Rights and Preparation steps of the SourceX five-step transaction. It shows which records exist, where the authoritative copy lives, which legal holds apply and which classes are already excluded, so the scope of any package rests on documented decisions rather than memory.

The SourceX Evidence Packet then records provenance, licensing rights, permitted use, the privacy record and release authorization for anything licensed. Licensing never replaces retention: the company's original records stay under its schedule, and the licensed copy is governed by the license terms.

Frequently asked questions

Can we keep records longer than the schedule says?

You can, but extended retention should be a documented decision rather than a habit. Records you keep can be requested in litigation, and personal data may be subject to minimization rules. If a class has continuing business or reuse value, change the schedule with counsel's approval instead of quietly skipping disposal.

Does the schedule cover email, Teams and Slack messages?

It should. Messages often hold quality decisions, customer instructions and engineering changes, so classify them by content where possible or set rules by mailbox and channel. Check which retention settings your email and chat platforms actually apply, since defaults may delete or keep messages regardless of the written policy.

Who should approve a manufacturing retention schedule?

The CFO or general counsel usually owns the schedule, with outside counsel confirming periods. Quality, EHS, HR, engineering and IT should each sign off on their rows, since they know where records live and which customer and certification requirements apply. A named owner keeps it current.

How should we handle records from an acquired plant?

Map the acquired plant's record classes to your schedule, but check its customer contracts, legacy systems and legal holds first. Acquired plants often keep records in systems scheduled for retirement, so export what the schedule requires before shutdown and document what was migrated, archived or destroyed.

How often should the schedule be reviewed?

Review it on a regular cycle and whenever something changes: a new law, a new customer quality agreement, a certification, an acquisition or a system migration. Each review should confirm periods with counsel, update system names and check that disposal is actually happening as written.

Sources

  • IRS: keep records until the limitation period ends (generally 3 years, 6 or 7 years in some cases); employment tax records at least 4 years; property records until the period ends for the year of disposal. Source
  • 29 CFR 1904.33: OSHA 300 Log, privacy case list, annual summary and 301 forms are saved for five years following the end of the calendar year covered. Source
  • 29 CFR 1910.1020: medical records of exposed employees preserved for at least the duration of employment plus 30 years unless a specific standard provides otherwise. Source
  • 29 CFR 1910.1020: exposure records retained at least 30 years; background laboratory data one year if results, plan, methods and summary are kept 30 years. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify