Quarterly Records Retention Controls for County and City IT

A records governance checkpoint for clerks, records officers, legal counsel, department custodians, IT, security, and vendors.

Updated

Records obligations follow the information and its business context, not the logo on the application that stores it. A quarterly checkpoint helps county and city leaders connect approved retention schedules, public records access, legal holds, security, disposition, and technology changes before a departure or system migration exposes a gap.

This guide is an operating framework, not legal advice. North Carolina local governments should use the retention and disposition schedules that apply to them and have the clerk, records officer, legal counsel, and other authorized leaders interpret requirements for specific records. Federal NARA resources can offer useful electronic-records practices, but they do not replace North Carolina or local authority.

Maintain one records control register

The control register connects policy to systems and owners. It should be detailed enough to locate and produce records, apply a hold, and carry out authorized disposition without relying on one employee's memory.

For each record series or operational record group, capture:

  • Business purpose, creating department, responsible custodian, and alternate owner.
  • Applicable retention schedule, item citation, cutoff event, retention period, and disposition authority as confirmed by the records owner.
  • Systems, shared drives, email, messaging, mobile, paper, removable media, archives, and vendor platforms where copies may exist.
  • Record format, required metadata, access restrictions, sensitivity, and approved production or export method.
  • Active legal hold, audit, investigation, public records request, or other suspension of normal disposition.
  • Last sample date, known exceptions, migration status, and next owner action.

A backup inventory is not a records register. Backups support recovery; they do not automatically provide classification, search, retention, legal-hold handling, or defensible disposition.

Assign authority across records and technology

  • Clerk or designated records officer: coordinates the records program, approved schedules, training, and documented disposition process.
  • Legal counsel and authorized leadership: advise on public records requests, holds, disputes, confidentiality, and local authority.
  • Department custodians: identify the business context, record copy, cutoff event, access needs, and operational exceptions.
  • IT: maps systems and data locations, maintains access and export capability, implements approved controls, and preserves technical evidence.
  • Security and privacy owners: protect records, investigate inappropriate access, and coordinate restrictions without silently changing retention.
  • Procurement and system owners: require vendors to support search, export, hold, ownership, security, termination, and disposition obligations.

No single group should silently decide that data is no longer a record, that a retention period has expired, or that a legal hold can be released. Document the authority and approval path.

Run the quarterly checkpoint in six passes

  1. Inventory change: identify new applications, integrations, message channels, devices, forms, digitization projects, vendors, departments, and departed employees.
  2. Schedule mapping: reconcile new or changed information to the applicable approved schedule and record unresolved interpretations for authorized review.
  3. Access and production: sample whether an authorized person can locate, export, preserve metadata, and produce a usable record without depending on the original employee.
  4. Hold reconciliation: compare active holds with custodians, accounts, systems, backups, exports, and planned disposition. Confirm that release requires documented authority.
  5. Disposition control: review eligible records, approvals, exceptions, destruction method, vendor action, and the evidence retained after authorized disposition.
  6. Leadership decisions: escalate platform limitations, unfunded migrations, ownerless records, inaccessible formats, and policy conflicts before the next quarter.

Inspect the places where records escape controls

Email, text, chat, and collaboration

Classify content by function rather than assuming a message type has one retention period. Confirm how official messages are captured, searched, exported, and held, including messages on approved mobile or collaboration platforms. Address prohibited channels through policy, training, and technical controls rather than pretending they are not used.

Cloud and software-as-a-service platforms

Verify ownership of data and metadata, administrator access, search behavior, export formats, audit logs, retention settings, hold capability, deletion behavior, subcontractors, and access after termination. A vendor's standard retention setting may not match the government's schedule.

Employee transfers and departures

Before disabling or reassigning an account, identify record ownership, active requests and holds, shared access, local files, mobile content, encryption keys, and who will become custodian. Do not treat mailbox ownership transfer as the entire records handoff.

Scanned and born-digital records

Confirm that digitization preserves the content, context, usability, and metadata the authorized owner requires. Record whether paper may be disposed of and under which approved process; scanning alone should not trigger automatic destruction.

Backups, replicas, and test data

Document how routine disposition interacts with recovery copies and when records in backup media can be restored, searched, held, or aged out. Avoid promising immediate deletion from every immutable recovery copy when the architecture does not support it; have authorized leaders approve a documented, risk-aware process.

Exercise a request during a system change

Use this scenario: a department is replacing a SaaS platform while an employee leaves. During the migration, the government receives a public records request and counsel directs that related material be preserved. The legacy vendor contract is near termination, some attachments are stored outside the main application, and the replacement platform imports only selected metadata.

Have the team demonstrate, rather than describe:

  • Which record series, custodians, systems, messages, exports, and paper files are in scope.
  • Who can issue and release preservation instructions and how receipt is acknowledged.
  • How records and metadata are exported, validated, secured, and searched after the legacy account closes.
  • How normal disposition is suspended for held material without freezing unrelated records indefinitely.
  • Who approves migration acceptance, contract termination, eventual disposition, and the retained evidence.

Record missing permissions, undocumented storage, incomplete exports, conflicting schedule interpretations, and dependencies on the departing employee. Assign each finding to an authorized owner.

Build the quarterly evidence packet

  • Versioned control register and a change log for systems, series, schedules, owners, and exceptions.
  • Current hold register with authority, scope, custodians, systems, acknowledgement, and release status.
  • Sample search and export results, including metadata and validation by the department custodian.
  • Disposition approvals, item lists, methods, dates, vendor confirmations, and retained certificates or logs where applicable.
  • Access reviews, audit evidence, security incidents, and corrective actions affecting records.
  • Migration and termination evidence, including reconciled counts, exceptions, accepted loss decisions, and final export location.

Report decisions and exceptions, not only volume. Useful indicators include record groups without schedule mapping, systems without an alternate custodian, holds not reconciled to platforms, exports that failed validation, disposition actions awaiting authority, and vendor gaps past due.

Questions leadership should answer before next quarter

  • Which platform cannot meet an approved records requirement, and what is the treatment plan?
  • Which data location or communication channel has no accountable custodian?
  • Can the government retrieve usable records after a vendor outage, termination, or employee departure?
  • Which disposition is blocked by a hold, unclear schedule mapping, missing approval, or technical limitation?
  • What policy, procurement, staffing, or budget decision is needed now?

Primary guidance to use

Related Cloud Core guides

Make records controls demonstrable

Book a discovery call if your county or city needs help connecting records ownership, retention decisions, technical controls, vendor requirements, and quarterly evidence.

Want help applying this to your environment?

Start with a short discovery call and we will help you sort the practical next step without overcomplicating it.