Audit Retention Policy Template for Canada
Generate a bespoke document
What is a Audit Retention Policy?
The Audit Retention Policy serves as a crucial governance document for organizations operating in Canada, establishing standardized procedures for maintaining and managing audit-related records. This policy becomes necessary when organizations need to ensure systematic retention of audit documentation in compliance with Canadian regulatory requirements, including but not limited to the Income Tax Act, PIPEDA, and provincial regulations. The policy addresses retention periods, storage methods, security protocols, and disposal procedures for various types of audit records, both physical and electronic. It is designed to help organizations maintain proper documentation for regulatory compliance, protect against legal challenges, and support efficient audit processes while meeting the minimum retention requirements set by Canadian authorities.
Trusted by high-performance teams
About the Audit Retention Policy
An audit retention policy is a critical governance document that establishes how your organization will manage, store, and dispose of audit-related records. In Canada, this policy ensures you comply with federal and provincial regulatory requirements while protecting your organization from legal risks and supporting efficient audit processes.
When do you need this document?
You need an audit retention policy when your organization undergoes regular audits, whether internal or external. This includes publicly traded companies subject to securities regulations, private corporations with complex financial structures, non-profit organizations receiving government funding, and businesses with significant tax obligations. The policy becomes essential when you're preparing for regulatory inspections, managing large volumes of financial records, or implementing corporate governance frameworks. Organizations often develop this policy following audit findings that highlight record-keeping deficiencies or when expanding operations across multiple provinces with varying regulatory requirements.
Key legal considerations
Your audit retention policy must address several critical legal elements to ensure comprehensive compliance. The policy should clearly define what constitutes audit records, including financial statements, working papers, correspondence with auditors, and supporting documentation. You must establish specific retention periods for different document categories, ensuring they meet or exceed minimum legal requirements. The policy should include secure storage protocols for both physical and electronic records, with appropriate access controls and backup procedures. Consider including provisions for litigation holds that suspend normal disposal schedules when legal proceedings are anticipated. Your policy should also address the transition between different storage formats and establish clear procedures for authorized destruction of records at the end of retention periods.
Legal requirements in Canada
Canadian law imposes specific audit record retention obligations through multiple federal and provincial statutes. Under the Income Tax Act, you must retain all books and records for at least six years from the end of the last tax year to which they relate, including audit working papers and supporting documentation. The Canada Business Corporations Act requires corporations to maintain adequate accounting records and preserve them at the registered office or another designated location. PIPEDA mandates that personal information in audit records be protected through appropriate safeguards and retained only as long as necessary for identified purposes. Provincial securities regulators may impose additional requirements for public companies, including specific retention periods for audit committee communications and external auditor reports. Employment-related audit records must comply with provincial employment standards legislation, which typically requires retention of payroll and employment records for specified periods. Your policy must also consider provincial privacy legislation in jurisdictions like Quebec, British Columbia, and Alberta, which may impose stricter requirements than federal law.
GOVERNING LAW
Applicable law
This Audit Retention Policy is drafted to comply with Canada law. Key legislation includes:
Canada Business Corporations Act (CBCA): Specifies corporate record retention requirements, including maintaining adequate accounting records, minutes of meetings, and other corporate documentation for prescribed periods.
Personal Information Protection and Electronic Documents Act (PIPEDA): Governs the collection, use, and disclosure of personal information, requiring organizations to protect personal information in their records and maintain transparency about their information handling practices.
Employment Insurance Act: Requires employers to maintain employment records and related documentation for at least 6 years from the end of the relevant year.
Canada Labor Code: Mandates retention of specific employment-related records for periods ranging from 3 to 6 years, including payroll records, hours of work, and other employment documentation.
Goods and Services Tax (GST)/Harmonized Sales Tax (HST) Legislation: Requires retention of all GST/HST records and supporting documents for 6 years from the end of the year to which they relate.
Canadian Generally Accepted Auditing Standards (GAAS): Professional standards that guide audit documentation requirements and retention periods for audit working papers and related materials.
Provincial Business Corporations Acts: Various provincial acts that may impose additional or specific record-keeping requirements depending on the province(s) where the business operates.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

