Records and Documentation

Retention schedules, compliance records, supporting documentation, secure storage, destruction, and responding to records requests.

Find a section

Home / For CRAs / Records and Documentation

Recordkeeping is part of nearly every CRA function, from client credentialing and vendor oversight to research, disputes, and compliance. Good documentation also provides a record of the CRA’s actions and procedures when responding to audits, client reviews, regulatory inquiries, or litigation.

Records and documentation practices determine what a CRA retains, how long it keeps it, how it is protected, and how it is produced when needed.

Retention Schedules

A retention schedule states how long each type of record is kept and what happens to it afterward.

The FCRA does not set a general retention period for a CRA’s business records. Retention is instead driven by the period during which a claim may be brought, by client agreements, by state law, and by accreditation requirements. Under FCRA § 1681p, an action may generally be brought within 2 years after the date the plaintiff discovers the violation, or within 5 years after the date the violation occurred, whichever is earlier.

  • Set the schedule in writing. Identify each category of record, the retention period that applies to it, and the method of disposal at the end of that period.
  • Consider all applicable retention requirements. Retention periods may be affected by legal requirements, client agreements, accreditation standards, and the period during which a claim may be brought. The CRA’s retention schedule should account for each requirement that applies.
  • Apply the schedule consistently. Records disposed of on an ad hoc basis are difficult to explain later, particularly when the missing records relate to a matter in dispute.
  • Suspend disposal when a claim is anticipated. Once litigation, a regulatory inquiry, or a serious dispute becomes reasonably foreseeable, routine destruction of related records should stop until the matter is resolved.
  • Review the schedule periodically. New services, new data sources, and new client requirements all create record types the existing schedule may not address.

Worth Knowing: Retention and disposal are separate decisions from whether information may still be reported. A record may be retained in a file long after it has passed a reporting limit. Retention determines what the CRA holds, not what it may furnish.

Compliance Records

Compliance records document that the CRA’s procedures exist and that they are followed.

These records help demonstrate that the CRA maintains reasonable procedures under FCRA § 1681e(b), and that its established compliance practices are being followed.

  • Retain current and superseded policies. A superseded policy establishes what the procedure required at the time of the conduct in question, which the current version cannot show.
  • Keep client credentialing and certification files. These document who was authorized to receive reports and for what purpose.
  • Keep vendor due diligence and audit records. These document the standards applied to work the CRA did not perform itself.
  • Keep quality control results. Reviews and samples that identified no errors belong in the record alongside those that did.
  • Keep dispute files. Retain the dispute, the reinvestigation performed, the outcome, and the notice sent to the consumer.
  • Keep training records. Identify who was trained, on what material, and on what date.

See Policies, Training and Audits for developing the policies and training these records document.

Supporting Documentation

Supporting documentation records how an individual report was researched, verified, and produced.

When a report is questioned, these records help establish what sources were searched, what information was reviewed, and how reporting decisions were made.

  • Record the source of each item. Identify the court, agency, or other source, the date searched, and the method used.
  • Record the identifiers used to match each record. Documentation should show which identifiers supported the decision that a record belonged to the consumer.
  • Record verification attempts. Include the date, time, method, party contacted, and outcome, including attempts that produced no response.
  • Record research that was ordered and what it returned. Additional court research, case file retrieval, and vendor escalations all belong in the file.
  • Document records reviewed and not reported. When appropriate, note records that were reviewed and excluded and the reason they were not reported.
  • Retain the report as furnished. Keep the version the client actually received, along with any corrected version issued later.

Good Practice: Capture documentation as the work is performed rather than reconstructing it afterward. Details such as who provided information, when a source was contacted, and what was confirmed may be difficult to recreate later.

Secure Storage

Records held by a CRA contain identifiers, criminal history, and other sensitive information about consumers who are not the CRA’s customers.

  • Limit access to those who need it. Access should reflect the person’s role, and it should be removed when the role changes or the person leaves.
  • Encrypt consumer information. Apply encryption to stored data and to data in transit, including files exchanged with clients and vendors.
  • Control physical records. Paper files, printed reports, and portable media should be stored in a secured location rather than at individual workstations.
  • Maintain access logs. Record who accessed consumer information and when, so that unusual access can be identified.
  • Maintain backups and test restoration. Backups should be tested periodically to confirm that records can be successfully restored when needed.
  • Establish a breach response process. Determine in advance who is notified, in what order, and within what timeframe, and identify the state notification laws that apply.

Worth Knowing: Data breach notification requirements are primarily governed by state law and may vary based on the affected consumers, the information involved, and the circumstances of the incident. Therefore, a CRA operating nationally may be subject to notification requirements in many states from a single incident.

Destruction and Disposition

Consumer information must be disposed of in a manner that protects against unauthorized access or use.

FCRA § 1681w directs the disposal of records containing consumer report information, and the FTC Disposal Rule at 16 CFR Part 682 implements it. The rule requires reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.

  • Destroy rather than discard. Reasonable measures include burning, pulverizing, or shredding paper records, and destroying or erasing electronic media so that the information cannot be reconstructed.
  • Apply the same standard to vendors. Where disposal is contracted out, the rule identifies due diligence in selecting the contractor as part of reasonable measures.
  • Account for copies in other locations. Disposal procedures should consider consumer information stored in backups, archived systems, working files, email, and other locations.
  • Document what was destroyed. Record the categories of records, the date, the method, and who performed or witnessed the destruction.
  • Address disposition at the end of a relationship. When a client or vendor relationship ends, determine what is returned, what is destroyed, and what must be retained despite the termination.

Responding to Records Requests

Records are requested by consumers, clients, regulators, and parties to litigation, and each type of request carries different obligations.

Under FCRA § 1681g, a CRA must disclose to a consumer, on request and after proper identification, all information in the consumer’s file at the time of the request, the sources of that information, and identification of each person that procured a report during the applicable period. For reports furnished for employment purposes, that period covers the 2 years preceding the request.

  • Verify identity before disclosing. File disclosure to the wrong person is itself a disclosure to someone not authorized to receive the information.
  • Disclose the file rather than the report. The consumer’s file is broader than any single report furnished from it.
  • Treat client requests separately. A client’s right to receive supporting documentation may depend on the service agreement, the nature of the records requested, and other applicable requirements.
  • Review legal and regulatory requests carefully. Subpoenas, court orders, and regulatory demands should be reviewed by the appropriate person or legal counsel before records are produced.
  • Log every request and response. Record who asked, what was requested, what was provided, and on what date.

Good Practice: Test the retrieval process before a request arrives. Records should be organized so that a specific consumer file, compliance record, or supporting document can be located and produced within a reasonable time.

See Dispute Resolution Standards for the records a reinvestigation produces and the notices it requires.

Download the Records Retention Checklist

What to retain, how long to keep it, how to store it, and how to dispose of it.

Download PDF