Compliance Training

Training records retention requirements by US rule, in one table

OSHA's bloodborne pathogens rule says 3 years, HIPAA says 6, Chicago says 5, and the forklift rule names no period at all. Here is every period, the fields each rule demands, and the source.

Training records retention cover illustration: a document with a checkmark representing a verified, audit-ready training record

The short answer: US training records retention requirements run from one year to six, depending on the rule. OSHA bloodborne pathogens training records: 3 years. HIPAA training documentation: 6 years. California harassment training: 2 years. NYC: 3 years with a signed acknowledgment. Chicago: 5 years. When several rules apply, keep each record for the longest period that covers it, and confirm the policy with counsel.

In LMS Advisor, the evidence those periods protect is captured as you train: assignments carry due dates, overdue reports show who was late, audit logs record who changed what, and data retention settings let you match the purge schedule to your policy.

The periods are the easy part. Each rule starts its clock at a different moment, several name the exact fields a record must hold, and a few say what to keep without ever saying for how long. Below is the table with a source for every row (we opened each one in September 2026), then how to keep those records intact inside an LMS. Rules get amended, so check the current text of your state or city rule before you set a policy. This is a map, not legal advice.

How long do you have to keep training records under each US rule?

These are the federal, state and city rules we get asked about most. Where a rule is silent on retention, the cell says so rather than guessing.

RuleWho and how oftenWhat the record must showHow long to keep it
OSHA bloodborne pathogens, 29 CFR 1910.1030(h)(2)Workers with occupational exposure. At initial assignment, then annuallySession dates, contents or a summary, names and qualifications of the trainers, names and job titles of all attendees3 years from the date the training occurred
OSHA powered industrial trucks, 29 CFR 1910.178(l)(6)Forklift operators. Evaluation at least every three years, refresher after an accident, near miss or unsafe operationOperator name, date of training, date of evaluation, identity of the person(s) who trained or evaluatedNo period stated. Keep the current certification for every active operator
OSHA respiratory protection, 29 CFR 1910.134(m)(2)Respirator users. Training annually and when changes make it obsoleteFit test records: employee, test type, respirator make, model and size, date, resultFit test records until the next fit test. Paragraph (m) sets no period for training records
DOT hazmat employee training, 49 CFR 172.704(d)Hazmat employees. Within 90 days of hire or job change, then every three yearsName, latest completion date, description or location of materials, trainer name and address, certification of training and testingA record covering the preceding 3 years of training, kept while the person works as a hazmat employee and for 90 days after
MSHA Part 46 training, 30 CFR 46.9Miners at Part 46 operationsFull name, type, duration and date of training, the competent person who gave it, mine ID, and a signed certificationDuring employment (refresher records 2 years), plus 60 days after leaving
HIPAA Privacy Rule, 45 CFR 164.530(b) and (j)All workforce members of a covered entity. New members within a reasonable period, affected members after a material policy changeDocumentation that the training was provided, in written or electronic form6 years from creation or from the date it was last in effect, whichever is later
FFIEC BSA/AML Examination Manual, training sectionBoard, senior management and all personnel whose duties require BSA knowledgeTraining and testing materials, session dates, attendance, failures to take training on time, corrective actionsThe manual sets no period. Many banks borrow the 5 years that 31 CFR 1010.430(d) sets for required BSA records, though that rule does not name training records
EEOC recordkeeping, 29 CFR 1602.14Employers covered by Title VII, the ADA and GINAPersonnel records, including selection for training or apprenticeship1 year from the record or action, and until final disposition if a charge is filed
California harassment prevention, Gov. Code 12950.1 and 2 CCR 110245+ employees. 1 hour for staff, 2 for supervisors, within six months of hire or promotion, then every two yearsNames, date, sign-in sheet, certificates issued, type of training, copy of all materials, training providerAt least 2 years
Cal/OSHA workplace violence prevention, Labor Code 6401.9 (SB 553)Most California employers (the law lists exemptions). Initially, then annually, with interactive Q&APer Labor Code 6401.9(f)(2): training dates, contents or a summary, names and qualifications of trainers, names and job titles of attendeesAt least 1 year (hazard and incident log records: 5 years)
NYC Stop Sexual Harassment Act15+ employees in the prior calendar year. Annual training for staff who work more than 80 hours and at least 90 days in a calendar yearA record of all trainings, including a signed employee acknowledgment (electronic is fine)At least 3 years
New York State harassment preventionEmployers in New York State. Training at least once per yearNo required fields. The state encourages keeping a signed acknowledgment and training recordsNo period stated
Maine, 26 M.R.S. 80715+ employees. New hires within one yearWhich employees received the training, using the state's compliance checklistAt least 3 years, available for inspection
Chicago Municipal Code 6-10-040Every employer, no size threshold in the text. Annually: 1 hour for employees, 2 for supervisors, plus 1 hour of bystander trainingThe written policy, the trainings given to each employee, and records showing complianceAt least 5 years, or longer while a claim or investigation is pending

Notice that "how long" is only half the requirement. OSHA, DOT, MSHA, California and Cal/OSHA all name the fields a record must contain, and a completion date alone satisfies none of them.

How do you apply training records retention requirements when rules overlap?

Keep each record for the longest period of any rule that applies to it. That sounds simple until you notice the clocks start at different moments:

  • From the training date: OSHA bloodborne pathogens (3 years).
  • A minimum with no stated start date: Cal/OSHA workplace violence (1 year), California harassment (2 years), NYC and Maine (3 years each). Count from the training date to be safe.
  • From creation or the date last in effect, whichever is later: HIPAA (6 years).
  • Tied to employment: DOT hazmat (while employed as a hazmat employee plus 90 days), MSHA Part 46 (during employment plus at least 60 days).
  • Extended by disputes: Chicago (length of any pending claim) and the EEOC rule (until final disposition of a charge).

Take an outpatient clinic group with a Chicago site. Its bloodborne pathogens records need 3 years, its Chicago harassment records 5, and its HIPAA records 6 from the later of creation or last effective date. The simplest policy for that group is one house rule, something like "keep every mandatory training record for at least 6 years after the later of completion or the employee's departure, and suspend deletion for any open claim". One rule people actually configure beats five precise ones they don't.

The trade-off: longer retention means more personal data on hand and more to produce in discovery. If your privacy team is strict about data minimization, set periods per record type instead. Either way, write the choice down and have counsel sign it off.

What does a defensible training record contain?

A defensible training record answers who was trained, on what, when, by whom and with what result, without a follow-up email. Combine the fields the rules above name and you get this list:

  1. Identity. Full name, a unique employee ID and job title at the time of training. OSHA and Cal/OSHA name job title explicitly, and titles change.
  2. Content. Course name, version and a summary or copy of the materials. California requires a copy of all written or recorded materials. Keep every version you ran.
  3. Dates. Session or completion date, and for evaluations (forklift, hazmat testing) the evaluation date as a separate field.
  4. Trainer. Name and qualifications of the person who delivered it, or the provider's name and address for DOT hazmat. For e-learning, record the qualified person learners could reach for questions.
  5. Result. Test score, pass or fail, attempts and the date of the passing attempt. DOT wants certification that the employee was trained and tested.
  6. Acknowledgment. A signed acknowledgment where the rule asks for one (NYC) or where your policy does.
  7. Certificate. The certificate issued, its ID and any expiry date. California lists copies of certificates in the required file.

One detail catches teams out. OSHA's bloodborne pathogens standard and Cal/OSHA's workplace violence law both require an opportunity for interactive questions and answers. A self-paced module with no route to a qualified person does not meet that on its own. Pair the module with a scheduled live session or a named contact, and record that the option was offered.

Are electronic training records and e-signatures acceptable?

Generally yes, with conditions. In a 1997 letter that still appears on osha.gov, OSHA said no OSHA standard requires the employee's signature on a training record, and that an electronic method (a scanned ID badge, in that case) is fine if safeguards make sure the ID belongs to the person being trained. HIPAA's documentation standard explicitly allows "written or electronic" records. The NYC Commission on Human Rights says the signed acknowledgment may be electronic.

The condition is the one OSHA named: identity. In LMS terms that means:

  • One account per person, never a shared "warehouse" login that a supervisor uses to click through a crew.
  • An audit log that shows who changed a completion, score or date, and when. A manually marked completion should be visible as manual.
  • For in-person sessions, attendance captured per person (a roster, or a QR check-in each attendee scans) instead of a trainer typing names afterwards.

Where a rule wants someone else's signature, like MSHA's certification by the person responsible for training, keep that signed form with the record.

Do you need records of people who missed training?

Banks do, and everyone else should. The FFIEC manual's BSA/AML training section expects documentation of any failures of personnel to take required training on time, plus the corrective actions taken. That record shows the gap and what management did about it. Build three things into the process:

  • Assignments with due dates. You cannot prove someone was late unless the system knew when the training was due.
  • An overdue report you save on a schedule. A dashboard shows today, but an auditor asks about last March. Export the overdue list monthly and keep it as long as the completions.
  • A corrective-action note. Reminder sent, manager escalation, access suspended, completion date.

Outside banking, the same file answers the hard question after an incident: was this person overdue, and did anyone notice?

How do you set retention in an LMS without deleting evidence early?

In our experience, lost training records are rarely destroyed on purpose. They disappear as a side effect of routine clean-up. From years of LMS migrations and rebuilds, these are the failure modes we see most:

  • Deleting a user deletes their history. Deactivate leavers instead.
  • Deleting or replacing a course orphans its completions. Retire old versions, do not delete them.
  • Certificates are regenerated, not stored. A certificate rendered from the current template shows this year's wording on last year's completion. Keep the issued PDF or its ID and issue date.
  • A migration moves the courses but not the history. Our LMS migration checklist covers how to export and archive completion history before the old contract ends.
  • A privacy deletion request runs without a retention check. A GDPR or CCPA request may not cover records you are legally required to keep. Check the retention map first.

Here is the order we recommend for setting it up:

  1. List every mandatory course and map it to the rules in the table above.
  2. Pick the retention period and the clock trigger for each (completion date, policy end date, employment end).
  3. Set the LMS data retention settings to match, and check exactly what a purge removes: accounts, activity logs, completions or all three.
  4. Turn off hard deletion of users and courses for admins who do not need it.
  5. Add a legal hold step: when a claim or investigation opens, suspend deletion for the people involved.
  6. Deactivate a test user and confirm their completions, scores and certificate still appear in exports.

Hosting matters too. With a cloud LMS, ask how long data stays available after you cancel and in what format. With a self-hosted LMS, the database sits on your server and your backup policy becomes part of your retention policy. Each puts the risk in a different place.

What should an audit-ready training export include?

Auditors and inspectors usually ask for evidence on a named group over a date range. Build the export once and test it before anyone asks:

  • Employee name, unique ID, job title, department and location
  • Course name and version, plus the rule it satisfies
  • Assigned date, due date, completion date and status (including overdue and not started)
  • Score, pass or fail and number of attempts
  • Trainer name and qualifications, and attendance for in-person sessions
  • Certificate ID, issue date and expiry date
  • Acknowledgment status and date, where required
  • Copy of the course materials for the version the employee took
  • Audit log entries for any manual change to the above
  • Saved overdue reports and corrective actions for the period

Export to a format that opens without the LMS: CSV or Excel for data, PDF for certificates and materials.

How to keep audit-ready training records in LMS Advisor

Our team spent years migrating LMS platforms, and their training history, before building LMS Advisor, so the record fields above map to settings it already has:

Record elementHow LMS Advisor captures it
IdentityOne account per person through SAML SSO and SCIM provisioning, with passkeys and two-factor authentication, so a completion belongs to the person who did it
Dates and overdue historyOrganization course assignments with due dates and mandatory flags, and an overdue report you can export monthly and file
ResultScored quizzes in courses and standalone exams in the Test Center, with result pages per candidate
AcknowledgmentA block marked required in an interactive module, so the acknowledgment has its own dated completion
AttendanceManual attendance or a QR check-in each attendee scans for instructor-led sessions
CertificateIssued automatically on completion or pass, with an optional validity period, an expiring-soon status and a public verification page
Changes and retentionAudit logs, data retention settings and a GDPR/CCPA data request queue, so you can check the retention map before acting on a deletion request
ExportReports export to CSV, Excel or PDF, and the REST API feeds an archive or BI tool

Self-hosting is the other lever. Run LMS Advisor on your own server and the database, backups and retention schedule all sit under your policy rather than a vendor's cancellation terms.

What it does not do: it does not tell you which retention period applies, it holds no compliance certification of its own, and it ships no library of ready-made OSHA or harassment courses, so you upload your own or a vendor's SCORM packages. Test what a retention purge removes on a test user before you rely on it. The certificates and compliance page has the details, and the compliance training solution page shows how assignments, certificates and reports fit together.

To check your own retention map in practice, start a trial, load one mandatory course and run the export checklist above against it.

Frequently asked questions

How long should I keep employee training records if no rule applies?

Treat one year as the floor. If you have 15 or more employees, the EEOC's rule already covers records about selection for training for one year, and longer once a charge is filed. How much longer to go depends on how long claims could be brought against you, which is a question for counsel. Whatever you pick, apply it consistently and write it down.

Does OSHA require employees to sign training records?

No. OSHA's 1997 interpretation letter says no standard requires the employee's signature, and electronic records are fine with safeguards that tie them to the trainee. Some standards, like forklift certification, require the employer to certify the training.

How long must HIPAA training records be kept?

HIPAA training documentation must be kept for 6 years from the date it was created or the date it was last in effect, whichever is later. Keep the policy version the training covered alongside the completion record.

Do I have to keep a copy of the training content itself?

Under several rules, yes. California's harassment regulation requires a copy of all written or recorded materials, OSHA bloodborne pathogens and Cal/OSHA require the contents or a summary, and DOT hazmat requires a description, copy or location of the materials. Keep every version you ran, not just the latest one.

Can LMS Advisor keep audit-ready training records?

Yes, LMS Advisor records the evidence most of these rules ask for: due dates and overdue history, scores, QR or manual attendance, required acknowledgments, certificates with a public verification page, and audit logs of changes. Data retention settings and CSV, Excel or PDF exports cover the keeping and the producing. You still decide the retention period for each record type with counsel, and self-hosting puts the data under your own backup policy.

Are online training certificates enough proof for an auditor?

Usually not on their own. A certificate proves completion, but most rules also ask for dates, content, trainer details or attendance. Pair it with the underlying record and an audit log.

Swati Priyadarshani
· Founder & CEO at LMS Advisor

I'm Swati Priyadarshani, Founder & CEO of LMS Advisor and Co-Founder of WorldWin Coder Pvt. Ltd. (est. 2019). Over the last 10+ years, I've helped enterprises build learning platforms that actually get used - not just deployed.

Keep reading

See LMS Advisor with your own use case

A product specialist walks you through authoring, a proctored exam, certificates and the AI tools, using the programs you actually run.