Audit Retention Policy Template for Australia
Generate a bespoke document
What is a Audit Retention Policy?
The Audit Retention Policy is a critical governance document that establishes mandatory requirements for maintaining and managing audit-related records within Australian organizations. This policy is essential for ensuring compliance with Australian regulatory requirements, including the Corporations Act 2001, which mandates a minimum 7-year retention period for financial records, and other relevant legislation such as the Privacy Act 1988 and the Electronic Transactions Act 1999. The policy provides comprehensive guidance on retention periods, storage methods, access controls, and disposal procedures for both physical and electronic audit records. It is designed to protect the organization's interests, support good governance, and ensure availability of necessary documentation for internal control, external audit purposes, and potential legal proceedings.
Trusted by high-performance teams
About the Audit Retention Policy
An Audit Retention Policy is a comprehensive governance document that establishes mandatory procedures for storing, managing, and disposing of audit-related records within your organization. This policy ensures your business maintains proper documentation to meet Australian regulatory requirements while providing clear guidelines for staff responsible for record management and audit compliance.
When do you need this document?
You need an Audit Retention Policy if your organization undergoes internal or external audits, maintains financial records, or handles sensitive data that requires regulatory compliance. This includes publicly listed companies subject to ASIC oversight, private companies with complex financial structures, government agencies, and organizations processing personal information. The policy is particularly crucial during audit preparation, regulatory investigations, or when implementing new record management systems. Without proper retention procedures, your organization risks non-compliance penalties, loss of critical evidence during legal proceedings, and operational inefficiencies when locating historical records.
Key legal considerations
Your Audit Retention Policy must clearly define retention periods for different types of records, ensuring compliance with the longest applicable legal requirement. The policy should establish secure storage procedures that protect confidentiality while ensuring authorized access for legitimate business purposes. You must include provisions for electronic record management, data backup procedures, and secure disposal methods that prevent unauthorized access to sensitive information. The policy should designate specific roles and responsibilities for record custodians, including training requirements and accountability measures. Consider including provisions for litigation holds that suspend normal disposal schedules when legal proceedings are anticipated or commenced.
Legal requirements in Australia
Under the Corporations Act 2001, your organization must retain written financial records for at least seven years, including audit working papers and supporting documentation. The Income Tax Assessment Act 1997 requires retention of tax-related documents for five years from assessment date, though business records supporting financial statements may need longer retention. If your organization processes personal information, the Privacy Act 1988 governs retention and disposal of personal data collected during audits, requiring secure destruction when no longer needed. The Electronic Transactions Act 1999 provides the framework for electronic record validity, allowing digital storage provided records remain accessible and authentic. Government organizations must also comply with the Archives Act 1983, which may require permanent retention of certain records or approval before disposal. Your policy must address the intersection of these laws and establish retention periods that satisfy the most stringent applicable requirement.
GOVERNING LAW
Applicable law
This Audit Retention Policy is drafted to comply with Australia law. Key legislation includes:
Income Tax Assessment Act 1997: Requires retention of tax-related documents for 5 years from the date of assessment. For business records, this includes documents that support tax returns and financial statements.
Privacy Act 1988: Governs how personal information should be collected, stored, used, and disposed of, including retention periods for personal data collected during audits.
Electronic Transactions Act 1999: Provides framework for electronic record-keeping and determines the validity of electronic records for audit purposes.
Archives Act 1983: Relevant for government agencies and contractors, specifying requirements for record-keeping and disposal of official documents.
Australian Standards on Records Management (AS ISO 15489): Provides guidelines for record-keeping practices and systems, including retention schedules and disposal procedures.
ASIC Regulatory Guide 218: Provides guidance on audit documentation requirements and retention for registered company auditors.
Auditing and Assurance Standards Board (AUASB) Standards: Sets requirements for audit documentation retention, particularly ASA 230 which requires retention of audit documentation for 7 years.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

