Many organisations in Kenya keep records because they know they should. Fewer have a clear policy explaining what must be kept, how long it should be retained, where it should be stored, who can access it, and when it should be securely destroyed.

A document retention policy gives structure to this process. It helps organisations stay compliant, reduce risk, save space, and respond confidently during audits, disputes, donor reviews, or regulatory checks.

For businesses, NGOs, law firms, accounting firms, banks, and insurers, proper records retention is no longer just an administrative task. It is a core part of governance and risk management.

What is a document retention policy?

A document retention policy is a formal framework that defines how an organisation manages its records throughout their lifecycle.

It sets out:

  • which documents must be kept
  • how long each category of record should be retained
  • who is responsible for managing them
  • where records should be stored
  • who is allowed to access them
  • when and how records should be securely destroyed

A good policy should cover both physical and digital records, including paper files, scanned documents, emails, cloud files, accounting records, and electronic invoices.

Why Kenyan organisations need one

Kenyan organisations operate in a complex compliance environment. KRA may request tax records during audits. The Data Protection Act requires responsible handling of personal data. NGOs may need to produce documents for donor audits. Law firms and corporates may need records to support legal claims or defend disputes. Banks and insurers face strict compliance and due diligence obligations.

Without a formal retention policy, organisations often fall into one of three problems: they keep too much, destroy records too early, or cannot find documents when they are needed.

Each of these creates risk. Keeping unnecessary records increases storage costs and data exposure. Destroying records too soon can weaken audit or legal defence. Poor retrieval systems can delay operations and damage credibility.

What documents should the policy cover?

A strong document retention policy should cover all major categories of organisational records.

Corporate and legal records
These include certificates of incorporation, CR12 or CR13 documents, shareholder registers, beneficial ownership records, board minutes, resolutions, contracts, and agreements.

Tax and financial records
These include tax returns, invoices, receipts, audited accounts, bank statements, payroll records, KRA correspondence, and payment confirmations.

HR and employment records
These include employment contracts, disciplinary records, leave records, payroll files, PAYE records, pension records, NSSF records, and SHIF or NHIF records.

Client and operational records
These include client files, project documents, procurement records, supplier agreements, insurance documents, and internal reports.

NGO and donor records
For NGOs, the policy should cover grant agreements, donor reports, procurement files, monitoring and evaluation records, beneficiary data, and compliance documentation.

Digital records
Modern retention policies must also include emails, scanned files, cloud documents, system exports, electronic invoices, and eTIMS records.

How long should records be kept?

Retention periods vary depending on the type of document, legal requirements, and organisational risk.

Tax records in Kenya generally need to be retained for at least five years. However, some documents should be kept longer, especially where there may be audit exposure, fraud concerns, litigation risk, donor requirements, or long-term contractual obligations.

Corporate records such as ownership documents, board resolutions, and shareholder registers may need to be retained for the life of the company. Personal data, on the other hand, should not be kept longer than necessary under data protection principles.

A good retention policy should therefore balance legal minimums with practical risk. The question is not only “how long does the law require this?” but also “how long might we need this to protect the organisation?”

Physical vs digital records

Many Kenyan organisations now operate in a hybrid environment, with both paper and digital records. A retention policy must address both.

For physical records, the policy should define where files are stored, how they are indexed, who can access them, and how they are protected from fire, floods, pests, theft, or tampering.

For digital records, the policy should cover access controls, backups, audit trails, file naming conventions, version control, and cybersecurity risks.

Digitisation can make retrieval faster and reduce reliance on paper, but it must be done carefully. Scanned documents should be properly indexed, backed up, and linked to retention rules.

Who should be responsible?

Document retention should not sit with one department alone. Finance, legal, HR, compliance, IT, operations, and senior management all have a role to play.

The organisation should assign clear responsibility to a records owner, records committee, or compliance lead. This person or team should oversee implementation, monitor compliance, approve destruction decisions, and review the policy regularly.

Without ownership, even a well-written policy can fail in practice.

How to implement a document retention policy

A practical implementation process should include the following steps:

  1. Conduct a full records audit across all departments.
  2. Categorise records by type, department, and risk level.
  3. Identify legal, tax, donor, and regulatory retention requirements.
  4. Create a retention schedule for each document category.
  5. Decide which records should be digitised, stored, archived, or destroyed.
  6. Move inactive paper files to secure off-site storage.
  7. Train staff on access, filing, retrieval, and destruction procedures.
  8. Review the policy annually or when laws and business needs change.

This process gives organisations control over their records and reduces reliance on informal filing habits.

Common mistakes to avoid

Many organisations make avoidable mistakes when managing records. These include keeping everything indefinitely without structure, destroying documents without approval, storing sensitive files in unsecured offices, failing to include digital records, and relying on individual staff members to know where documents are kept.

Another common mistake is failing to document destruction. When records are destroyed, the organisation should retain proof that destruction was authorised, secure, and compliant.

How The Filing Room can help

The Filing Room helps organisations across Kenya create practical, secure, and compliant records management systems.

Our services include records audits, secure off-site storage, digitisation and indexing, scan-on-demand retrieval, retention schedule support, certified destruction, and long-term archive management.

For organisations with large volumes of paper records, moving inactive files off-site can free up valuable office space while improving security and retrieval. For organisations transitioning to digital systems, indexing and digitisation help ensure that records remain accessible and traceable.

However, we also recognise that outsourcing document storage is not always the right immediate solution for every organisation. Some businesses need to keep frequently referenced records on-site. Others may maintain their own archive facilities for historical, operational, or space-related reasons.

For these organisations, The Filing Room offers Registry Management and Consultancy. This service is designed to help clients manage their own records properly while benefiting from professional records management expertise.

Our Registry Management and Consultancy services include:

  • embedded archivists on long or short-term assignments
  • registry and inventory creation
  • best practice consultancy
  • support with organising, indexing, and controlling existing records
  • guidance on retention schedules and document access procedures

This allows organisations to maintain control over their records while ensuring that their filing systems are structured, secure, and compliant.

Final thoughts

A document retention policy gives your organisation control over its records. It helps you know what to keep, what to destroy, and how to retrieve critical documents when they matter most.

In an environment shaped by tax audits, data protection requirements, donor compliance, legal disputes, and regulatory reviews, records management is no longer optional.

The Filing Room helps Kenyan organisations build systems that are secure, practical, and defensible, turning records from a liability into a strategic asset.

info@filingroomkenya.com
+254 20 2663263
filingroomkenya.com