Skip to main content
Prevent audit chaos: HR legal-hold and records-retention checklist with retrieval SLAs and index templates

Prevent audit chaos: HR legal-hold and records-retention checklist with retrieval SLAs and index templates

A practical way to map record types to owners, freeze the right data fast, and export defensible HR files without a two-week scramble

Most HR teams don't discover their records problem until legal counsel sends the email that starts with "We need everything related to..." That's the moment you find out whether your records actually exist where you think they do, whether anyone owns them, and whether you can pull them in a defensible form before opposing counsel starts asking why documents went missing after a hold was supposed to be in place.

The gap almost always isn't intent. HR records tend to live across eight different systems, retention is set by whoever configured each tool three years ago, and "legal hold" is a phrase people say without anyone knowing exactly which button freezes what. This post is about closing that gap — with a retention matrix, a legal-hold runbook, retrieval SLAs, and export templates that hold up when someone challenges them.

The scenario that exposes the whole problem

A former employee files a discrimination claim tied to a termination that happened 14 months ago. Legal issues a litigation hold. Now HR has to preserve and eventually produce:

  1. The applicant's original resume and interview scorecards
  2. Performance reviews and any PIP documentation
  3. Manager notes, Slack/Teams messages, and email threads
  4. The investigation file (if there was one)
  5. Comp history and any adjustment approvals
  6. Termination paperwork and the offboarding checklist

Here's where it falls apart in real operations. The interview scorecards were in the ATS, which was migrated to a new vendor eight months ago — and nobody's sure the old scorecards came over intact. Performance reviews live in the HRIS. Manager notes are scattered across email and one manager's personal OneNote. The investigation file is a folder on a shared drive with inconsistent naming. And the Slack messages? IT's retention policy auto-deleted anything older than 90 days back in Q2.

That last one is the nightmare. Auto-deletion that continues after a hold is triggered is how organizations end up facing spoliation sanctions. The records didn't disappear because someone destroyed them maliciously — they disappeared because a routine retention rule kept running while nobody flipped it off.

Why HR records fail the audit test

A few patterns show up repeatedly when teams get caught flat-footed:

No one owns the record type, only the system. People will say "that's in Workday" or "that's in Greenhouse." But a system isn't an owner. When the system gets reconfigured, sunset, or migrated, the record type quietly loses its custodian. If you can't name a person accountable for interview records — not a platform — you don't really have retention control.

Retention is set by default, not by decision. Most tools ship with a default retention period, and most teams never change it. So you end up with resumes kept for seven years because that was the vendor default, while termination documentation gets purged at 12 months because a different vendor defaulted differently. Retention should map to legal requirement and litigation risk, not to whatever the software vendor decided.

Legal hold isn't wired into the actual systems. The hold gets communicated as an email — "please preserve all records related to X" — and everyone nods. But an email doesn't stop the HRIS auto-archive, doesn't suspend the messaging platform's deletion policy, and doesn't lock the shared drive from edits. A defensible hold has to touch the systems, not just the inboxes.

Retrieval has no clock. When the request comes, there's no agreed timeline for who pulls what. People chase records ad hoc, and by the time the file is assembled, it's incomplete and nobody documented what was searched.

This is the same territory covered in HR data governance for HR teams — if your access-control and data-lineage foundations are weak, your legal-hold response will be too, because you won't even know where the records live or who touched them.

Start with a retention matrix that names systems AND owners

The core artifact here is a retention matrix. Not a policy document — a working table that maps each record type to where it lives, who owns it, how long it's kept, and what triggers a hold. Keep it boring and specific.

Record typeSystem of recordHuman ownerRetention periodLegal-hold action
Applications & resumesATSTalent Acquisition Lead3 yrs post-decisionSuspend auto-purge; export snapshot
Interview scorecardsATSTA Lead3 yrs post-decisionLock records; verify migration integrity
Performance reviews / PIPsHRISHRBP for that BUDuration of employment + 4 yrsSuspend HRIS archive rule
Investigation filesSecure case system / shared driveEmployee Relations7 yrs post-closureFreeze folder; restrict edit access
Comp & adjustment approvalsHRIS + Finance systemComp AnalystEmployment + 4 yrsExport approval trail
Manager notes / IMEmail, Slack, TeamsPeople OpsPer messaging policySuspend deletion policy immediately
Termination & offboardingHRISHRBPEmployment + 4 yrsLock records

The two columns most teams skip are Human owner and Legal-hold action. Without a named owner, retrieval turns into a scavenger hunt. Without a defined hold action per record type, you're relying on people to remember which switches to flip under pressure — and messaging platforms are almost always the switch that gets forgotten.

Assign a single human owner for each record type — accountability beats assumptions in a crisis.

One practical note: retention periods vary by jurisdiction and record type (EEOC, FLSA, ADA, state law all have different clocks). Don't invent these — get them confirmed by counsel and lock them into the matrix. The matrix is the durable artifact; the legal review is what makes it defensible.

The legal-hold runbook: freeze first, communicate second

When a hold triggers, sequence matters. The most common failure is spending the first three days writing a carefully worded hold notice while auto-deletion keeps chewing through messaging logs. Freeze the systems before you polish the communications.

  1. Trigger and scope. Legal defines who and what is in scope — custodians, date ranges, record types. Write this down verbatim; the scope definition is itself a discoverable document.
  2. Suspend auto-deletion everywhere, immediately. This is the emergency step. Messaging platforms, HRIS archive rules, ATS purge schedules, backup rotation. Get IT on the phone the same day. Every hour of continued deletion is exposure.
  3. Identify custodians and systems from the matrix. Because you built the retention matrix, this is a lookup, not an investigation.
  4. Issue the written hold notice to every custodian and their manager. Require acknowledgment — an unacknowledged hold is a weak hold.
  5. Lock and preserve. Restrict edit access on shared folders. Snapshot the ATS and HRIS records in scope so a later migration or reconfiguration can't corrupt them.
  6. Log everything. What was frozen, when, by whom, and what was communicated. This log is often more important than the records themselves when spoliation gets argued.
  7. Track reminders and release. Holds go stale. Send periodic re-acknowledgments, and formally release the hold in writing when legal clears it.

A quick visual of the runbook helps teams follow the freeze-first sequence.

Process diagram

The freeze communication itself

> You are receiving this because you may have records relevant to a legal matter. Effective immediately, do not delete, modify, or discard any documents, emails, messages, files, or notes related to [scope]. This includes content in email, Slack/Teams, shared drives, and personal notes. Normal deletion and retention schedules are suspended for these records. Reply to acknowledge you've read and understand this notice. The two lines people leave out — "personal notes" and "normal retention schedules are suspended" — are exactly the two that get argued in court later. Include them.

Retrieval SLAs so production doesn't drag for weeks

Once records are frozen, someone has to actually pull, index, and hand them over. Without agreed timelines, this is where a 3-week response becomes a 9-week one. Attach an SLA to each phase.

  1. Acknowledge the request

    same business day

  2. Confirm scope with legal

    within 1 business day

  3. Systems frozen / auto-deletion suspended

    within 1 business day (non-negotiable)

  4. Custodian hold notices issued

    within 2 business days

  5. Initial index of located records

    within 5–7 business days

  6. Full retrieval and export in defensible format

    within 10–15 business days depending on volume

These aren't universal — high-volume matters need more runway — but the point is that each phase has an owner and a clock. When you can show a documented, followed SLA, you demonstrate good faith and diligence, which matters enormously if completeness is later challenged.

The index: the boring artifact that saves you

An index sounds like busywork until you actually need it. It's the map of what you found, where, and in what form. A usable index captures, per record:

  1. Record type and description
  2. Source system and exact location
  3. Custodian
  4. Date range covered
  5. Format (native, PDF, export)
  6. Date preserved and by whom
  7. Any gaps or known limitations (e.g., "Slack messages prior to [date] unavailable due to prior policy")

That last field — documenting gaps honestly — is what separates a defensible response from a risky one. If messages were auto-deleted before the hold, saying so plainly with dates is far stronger than pretending the record is complete and getting caught later.

Export templates that hold up

The way you export matters as much as what you export. A few practical rules that keep files defensible:

  1. Preserve metadata. Export dates, authorship, and edit history where the system supports it. A stripped PDF with no metadata invites questions about authenticity.
  2. Keep native format where possible, with PDFs as the readable layer. Don't retype or summarize — reproduce.
  3. Maintain chain of custody. Who exported it, when, from which system, and where the export is stored.
  4. Standardize file naming. [MatterID][RecordType][Custodian][DateRange] beats finalv2_USE THIS ONE.pdf every time.
  5. Bundle the index with the export. The package is records + index + custody log, not just a folder of files.

The package is records + index + custody log, not just a folder of files.

When to formalize this — and when it's overkill

This full runbook makes sense when you have more than a handful of employees, records spread across multiple systems, any history of employment disputes, or you operate in a jurisdiction with aggressive discovery expectations. If you've migrated HR tech recently, you especially need the migration-integrity checks baked into the matrix.

It's lighter-touch when you're a very small team on a single all-in-one HRIS with clear retention settings and almost no message-based decision-making. You still need the basics — named owners, suspended auto-deletion, a written hold — but you won't need a seven-phase SLA.

Who should never skip the messaging-platform step: any team where hiring and termination decisions get discussed in Slack or Teams. That's where the discoverable, unflattering, and easily-auto-deleted content lives. It's the single most common spoliation trap in modern HR operations.

A short real scenario

A mid-market services company, roughly 400 employees, got hit with a wrongful-termination claim. Their first hold attempt was email-only. It took close to seven weeks to assemble the file, and during that scramble they discovered that about four months of relevant Teams messages had been auto-purged after the hold should have been active. Counsel spent real money and goodwill managing that gap.

Afterward they built a retention matrix with named owners and wired an immediate deletion-suspension step into their runbook. The next hold, about a year later, looked completely different: systems frozen within a day, an initial index in under a week, full defensible export in roughly two weeks. No gaps, no spoliation argument. The difference wasn't a bigger team — it was knowing exactly which switches to flip and who owned each record type.

Where to start this week

You don't need to build the whole thing at once. In order of impact:

  1. List your record types and where they actually live — not where you assume they live. Verify the ATS migration actually carried scorecards over.
  2. Assign a human owner to each record type. No orphans.
  3. Find every auto-deletion rule across HRIS, ATS, and messaging platforms, and document how to suspend each one fast.
  4. Write the one-page hold notice now, so you're not drafting it under pressure.
  5. Set the SLA clocks and confirm retention periods with counsel.

The organizations that survive an audit or litigation hold without chaos aren't the ones with the most records — they're the ones who mapped record types to systems and owners before the request came in, and who knew the first move is always to stop the deletion, not perfect the memo. Build the matrix while things are quiet. The quiet is exactly when this work is possible.

The organizations that survive an audit or litigation hold without chaos aren't the ones with the most records — they're the ones who mapped record types to systems and owners before the request came in, and who knew the first move is always to stop the deletion, not perfect the memo. Build the matrix while things are quiet. The quiet is exactly when this work is possible.

Built for HR Teams Tailored tools for recruitment, onboarding, and employee management
Save Time Automate workflows and reduce manual HR tasks
Engage Employees Boost retention with continuous feedback and development tracking
Ensure Compliance Stay up-to-date with labor laws and reporting requirements