Training records retention requirements by US rule, in one table
OSHA's bloodborne pathogens rule says 3 years, HIPAA says 6, Chicago says 5, and the forklift rule names no period at all. Here is every period, the fields each rule demands, and the source.

The short answer: US training records retention requirements run from one year to six, depending on the rule. OSHA bloodborne pathogens training records: 3 years. HIPAA training documentation: 6 years. California harassment training: 2 years. NYC: 3 years with a signed acknowledgment. Chicago: 5 years. When several rules apply, keep each record for the longest period that covers it, and confirm the policy with counsel.
In LMS Advisor, the evidence those periods protect is captured as you train: assignments carry due dates, overdue reports show who was late, audit logs record who changed what, and data retention settings let you match the purge schedule to your policy.
The periods are the easy part. Each rule starts its clock at a different moment, several name the exact fields a record must hold, and a few say what to keep without ever saying for how long. Below is the table with a source for every row (we opened each one in September 2026), then how to keep those records intact inside an LMS. Rules get amended, so check the current text of your state or city rule before you set a policy. This is a map, not legal advice.
How long do you have to keep training records under each US rule?
These are the federal, state and city rules we get asked about most. Where a rule is silent on retention, the cell says so rather than guessing.
| Rule | Who and how often | What the record must show | How long to keep it |
|---|---|---|---|
| OSHA bloodborne pathogens, 29 CFR 1910.1030(h)(2) | Workers with occupational exposure. At initial assignment, then annually | Session dates, contents or a summary, names and qualifications of the trainers, names and job titles of all attendees | 3 years from the date the training occurred |
| OSHA powered industrial trucks, 29 CFR 1910.178(l)(6) | Forklift operators. Evaluation at least every three years, refresher after an accident, near miss or unsafe operation | Operator name, date of training, date of evaluation, identity of the person(s) who trained or evaluated | No period stated. Keep the current certification for every active operator |
| OSHA respiratory protection, 29 CFR 1910.134(m)(2) | Respirator users. Training annually and when changes make it obsolete | Fit test records: employee, test type, respirator make, model and size, date, result | Fit test records until the next fit test. Paragraph (m) sets no period for training records |
| DOT hazmat employee training, 49 CFR 172.704(d) | Hazmat employees. Within 90 days of hire or job change, then every three years | Name, latest completion date, description or location of materials, trainer name and address, certification of training and testing | A record covering the preceding 3 years of training, kept while the person works as a hazmat employee and for 90 days after |
| MSHA Part 46 training, 30 CFR 46.9 | Miners at Part 46 operations | Full name, type, duration and date of training, the competent person who gave it, mine ID, and a signed certification | During employment (refresher records 2 years), plus 60 days after leaving |
| HIPAA Privacy Rule, 45 CFR 164.530(b) and (j) | All workforce members of a covered entity. New members within a reasonable period, affected members after a material policy change | Documentation that the training was provided, in written or electronic form | 6 years from creation or from the date it was last in effect, whichever is later |
| FFIEC BSA/AML Examination Manual, training section | Board, senior management and all personnel whose duties require BSA knowledge | Training and testing materials, session dates, attendance, failures to take training on time, corrective actions | The manual sets no period. Many banks borrow the 5 years that 31 CFR 1010.430(d) sets for required BSA records, though that rule does not name training records |
| EEOC recordkeeping, 29 CFR 1602.14 | Employers covered by Title VII, the ADA and GINA | Personnel records, including selection for training or apprenticeship | 1 year from the record or action, and until final disposition if a charge is filed |
| California harassment prevention, Gov. Code 12950.1 and 2 CCR 11024 | 5+ employees. 1 hour for staff, 2 for supervisors, within six months of hire or promotion, then every two years | Names, date, sign-in sheet, certificates issued, type of training, copy of all materials, training provider | At least 2 years |
| Cal/OSHA workplace violence prevention, Labor Code 6401.9 (SB 553) | Most California employers (the law lists exemptions). Initially, then annually, with interactive Q&A | Per Labor Code 6401.9(f)(2): training dates, contents or a summary, names and qualifications of trainers, names and job titles of attendees | At least 1 year (hazard and incident log records: 5 years) |
| NYC Stop Sexual Harassment Act | 15+ employees in the prior calendar year. Annual training for staff who work more than 80 hours and at least 90 days in a calendar year | A record of all trainings, including a signed employee acknowledgment (electronic is fine) | At least 3 years |
| New York State harassment prevention | Employers in New York State. Training at least once per year | No required fields. The state encourages keeping a signed acknowledgment and training records | No period stated |
| Maine, 26 M.R.S. 807 | 15+ employees. New hires within one year | Which employees received the training, using the state's compliance checklist | At least 3 years, available for inspection |
| Chicago Municipal Code 6-10-040 | Every employer, no size threshold in the text. Annually: 1 hour for employees, 2 for supervisors, plus 1 hour of bystander training | The written policy, the trainings given to each employee, and records showing compliance | At least 5 years, or longer while a claim or investigation is pending |
Notice that "how long" is only half the requirement. OSHA, DOT, MSHA, California and Cal/OSHA all name the fields a record must contain, and a completion date alone satisfies none of them.
How do you apply training records retention requirements when rules overlap?
Keep each record for the longest period of any rule that applies to it. That sounds simple until you notice the clocks start at different moments:
- From the training date: OSHA bloodborne pathogens (3 years).
- A minimum with no stated start date: Cal/OSHA workplace violence (1 year), California harassment (2 years), NYC and Maine (3 years each). Count from the training date to be safe.
- From creation or the date last in effect, whichever is later: HIPAA (6 years).
- Tied to employment: DOT hazmat (while employed as a hazmat employee plus 90 days), MSHA Part 46 (during employment plus at least 60 days).
- Extended by disputes: Chicago (length of any pending claim) and the EEOC rule (until final disposition of a charge).
Take an outpatient clinic group with a Chicago site. Its bloodborne pathogens records need 3 years, its Chicago harassment records 5, and its HIPAA records 6 from the later of creation or last effective date. The simplest policy for that group is one house rule, something like "keep every mandatory training record for at least 6 years after the later of completion or the employee's departure, and suspend deletion for any open claim". One rule people actually configure beats five precise ones they don't.
The trade-off: longer retention means more personal data on hand and more to produce in discovery. If your privacy team is strict about data minimization, set periods per record type instead. Either way, write the choice down and have counsel sign it off.
What does a defensible training record contain?
A defensible training record answers who was trained, on what, when, by whom and with what result, without a follow-up email. Combine the fields the rules above name and you get this list:
- Identity. Full name, a unique employee ID and job title at the time of training. OSHA and Cal/OSHA name job title explicitly, and titles change.
- Content. Course name, version and a summary or copy of the materials. California requires a copy of all written or recorded materials. Keep every version you ran.
- Dates. Session or completion date, and for evaluations (forklift, hazmat testing) the evaluation date as a separate field.
- Trainer. Name and qualifications of the person who delivered it, or the provider's name and address for DOT hazmat. For e-learning, record the qualified person learners could reach for questions.
- Result. Test score, pass or fail, attempts and the date of the passing attempt. DOT wants certification that the employee was trained and tested.
- Acknowledgment. A signed acknowledgment where the rule asks for one (NYC) or where your policy does.
- Certificate. The certificate issued, its ID and any expiry date. California lists copies of certificates in the required file.
One detail catches teams out. OSHA's bloodborne pathogens standard and Cal/OSHA's workplace violence law both require an opportunity for interactive questions and answers. A self-paced module with no route to a qualified person does not meet that on its own. Pair the module with a scheduled live session or a named contact, and record that the option was offered.
Are electronic training records and e-signatures acceptable?
Generally yes, with conditions. In a 1997 letter that still appears on osha.gov, OSHA said no OSHA standard requires the employee's signature on a training record, and that an electronic method (a scanned ID badge, in that case) is fine if safeguards make sure the ID belongs to the person being trained. HIPAA's documentation standard explicitly allows "written or electronic" records. The NYC Commission on Human Rights says the signed acknowledgment may be electronic.
The condition is the one OSHA named: identity. In LMS terms that means:
- One account per person, never a shared "warehouse" login that a supervisor uses to click through a crew.
- An audit log that shows who changed a completion, score or date, and when. A manually marked completion should be visible as manual.
- For in-person sessions, attendance captured per person (a roster, or a QR check-in each attendee scans) instead of a trainer typing names afterwards.
Where a rule wants someone else's signature, like MSHA's certification by the person responsible for training, keep that signed form with the record.
Do you need records of people who missed training?
Banks do, and everyone else should. The FFIEC manual's BSA/AML training section expects documentation of any failures of personnel to take required training on time, plus the corrective actions taken. That record shows the gap and what management did about it. Build three things into the process:
- Assignments with due dates. You cannot prove someone was late unless the system knew when the training was due.
- An overdue report you save on a schedule. A dashboard shows today, but an auditor asks about last March. Export the overdue list monthly and keep it as long as the completions.
- A corrective-action note. Reminder sent, manager escalation, access suspended, completion date.
Outside banking, the same file answers the hard question after an incident: was this person overdue, and did anyone notice?
How do you set retention in an LMS without deleting evidence early?
In our experience, lost training records are rarely destroyed on purpose. They disappear as a side effect of routine clean-up. From years of LMS migrations and rebuilds, these are the failure modes we see most:
- Deleting a user deletes their history. Deactivate leavers instead.
- Deleting or replacing a course orphans its completions. Retire old versions, do not delete them.
- Certificates are regenerated, not stored. A certificate rendered from the current template shows this year's wording on last year's completion. Keep the issued PDF or its ID and issue date.
- A migration moves the courses but not the history. Our LMS migration checklist covers how to export and archive completion history before the old contract ends.
- A privacy deletion request runs without a retention check. A GDPR or CCPA request may not cover records you are legally required to keep. Check the retention map first.
Here is the order we recommend for setting it up:
- List every mandatory course and map it to the rules in the table above.
- Pick the retention period and the clock trigger for each (completion date, policy end date, employment end).
- Set the LMS data retention settings to match, and check exactly what a purge removes: accounts, activity logs, completions or all three.
- Turn off hard deletion of users and courses for admins who do not need it.
- Add a legal hold step: when a claim or investigation opens, suspend deletion for the people involved.
- Deactivate a test user and confirm their completions, scores and certificate still appear in exports.
Hosting matters too. With a cloud LMS, ask how long data stays available after you cancel and in what format. With a self-hosted LMS, the database sits on your server and your backup policy becomes part of your retention policy. Each puts the risk in a different place.
What should an audit-ready training export include?
Auditors and inspectors usually ask for evidence on a named group over a date range. Build the export once and test it before anyone asks:
- Employee name, unique ID, job title, department and location
- Course name and version, plus the rule it satisfies
- Assigned date, due date, completion date and status (including overdue and not started)
- Score, pass or fail and number of attempts
- Trainer name and qualifications, and attendance for in-person sessions
- Certificate ID, issue date and expiry date
- Acknowledgment status and date, where required
- Copy of the course materials for the version the employee took
- Audit log entries for any manual change to the above
- Saved overdue reports and corrective actions for the period
Export to a format that opens without the LMS: CSV or Excel for data, PDF for certificates and materials.
How to keep audit-ready training records in LMS Advisor
Our team spent years migrating LMS platforms, and their training history, before building LMS Advisor, so the record fields above map to settings it already has:
| Record element | How LMS Advisor captures it |
|---|---|
| Identity | One account per person through SAML SSO and SCIM provisioning, with passkeys and two-factor authentication, so a completion belongs to the person who did it |
| Dates and overdue history | Organization course assignments with due dates and mandatory flags, and an overdue report you can export monthly and file |
| Result | Scored quizzes in courses and standalone exams in the Test Center, with result pages per candidate |
| Acknowledgment | A block marked required in an interactive module, so the acknowledgment has its own dated completion |
| Attendance | Manual attendance or a QR check-in each attendee scans for instructor-led sessions |
| Certificate | Issued automatically on completion or pass, with an optional validity period, an expiring-soon status and a public verification page |
| Changes and retention | Audit logs, data retention settings and a GDPR/CCPA data request queue, so you can check the retention map before acting on a deletion request |
| Export | Reports export to CSV, Excel or PDF, and the REST API feeds an archive or BI tool |
Self-hosting is the other lever. Run LMS Advisor on your own server and the database, backups and retention schedule all sit under your policy rather than a vendor's cancellation terms.
What it does not do: it does not tell you which retention period applies, it holds no compliance certification of its own, and it ships no library of ready-made OSHA or harassment courses, so you upload your own or a vendor's SCORM packages. Test what a retention purge removes on a test user before you rely on it. The certificates and compliance page has the details, and the compliance training solution page shows how assignments, certificates and reports fit together.
To check your own retention map in practice, start a trial, load one mandatory course and run the export checklist above against it.
Frequently asked questions
How long should I keep employee training records if no rule applies?
Treat one year as the floor. If you have 15 or more employees, the EEOC's rule already covers records about selection for training for one year, and longer once a charge is filed. How much longer to go depends on how long claims could be brought against you, which is a question for counsel. Whatever you pick, apply it consistently and write it down.
Does OSHA require employees to sign training records?
No. OSHA's 1997 interpretation letter says no standard requires the employee's signature, and electronic records are fine with safeguards that tie them to the trainee. Some standards, like forklift certification, require the employer to certify the training.
How long must HIPAA training records be kept?
HIPAA training documentation must be kept for 6 years from the date it was created or the date it was last in effect, whichever is later. Keep the policy version the training covered alongside the completion record.
Do I have to keep a copy of the training content itself?
Under several rules, yes. California's harassment regulation requires a copy of all written or recorded materials, OSHA bloodborne pathogens and Cal/OSHA require the contents or a summary, and DOT hazmat requires a description, copy or location of the materials. Keep every version you ran, not just the latest one.
Can LMS Advisor keep audit-ready training records?
Yes, LMS Advisor records the evidence most of these rules ask for: due dates and overdue history, scores, QR or manual attendance, required acknowledgments, certificates with a public verification page, and audit logs of changes. Data retention settings and CSV, Excel or PDF exports cover the keeping and the producing. You still decide the retention period for each record type with counsel, and self-hosting puts the data under your own backup policy.
Are online training certificates enough proof for an auditor?
Usually not on their own. A certificate proves completion, but most rules also ask for dates, content, trainer details or attendance. Pair it with the underlying record and an audit log.