Seven years is the number every small firm reaches for when someone asks how long to keep email — copied from a company law default, written into a staff handbook years ago, repeated without anyone checking whether it actually applies. Often it doesn't. Depending on the matter type and who sent the email, the real obligation might be five years, six years, fifteen years, or effectively indefinite.
A financial advice practice found this out the hard way during an ASIC surveillance review of its defined benefit pension transfer advice. The firm had a tidy seven-year email retention policy, deleted correspondence on schedule, and then had to explain why it couldn't produce advice records from a transfer eight years earlier — the kind of advice regulators specifically flag for extended retention because complaints about pension transfers tend to surface a decade or more after the fact. The firm wasn't sloppy. It was following the wrong rule.
Where "seven years" actually comes from
The figure gets its authority from real places, which is exactly why it spreads. In Australia, the Corporations Act 2001 (Cth) s286 requires companies to keep financial records for 7 years. The AML/CTF Act 2006 requires AUSTRAC reporting entities to retain transaction and customer identification records for 7 years. ASIC's requirements under s912G for Australian Financial Services Licensees generally sit at 7 years for advice-related records too. Three genuinely different regimes landing on the same number is how "seven years" became shorthand for "compliant," even for firms and document types none of those rules cover.
But plenty of obligations don't match. The ATO generally requires 5 years for tax records. UK firms regulated by the FCA under SYSC 9.1 typically need 5 years for MiFID business records — except pension transfer advice, where FCA guidance following the defined benefit transfer scandal effectively pushes firms toward indefinite retention, because redress schemes have gone back well beyond a decade. Solicitors in England and Wales work against the Limitation Act 1980, which gives 6 years for most contract claims — except where the client was a minor at the time, in which case the limitation clock doesn't start until they turn 18, meaning a file opened for a 10-year-old client might need to survive for 20+ years. Conveyancing and probate files are routinely kept far longer than any statute technically demands, because latent title and estate disputes surface decades later.
What most small firms actually do
In practice, most firms under 20 people don't have a retention schedule at all — they have a folder structure, some PST files migrated off a departed employee's laptop, and a rule of thumb someone half-remembers from an induction session. Sent mail is usually the weakest link: inboxes get backed up, sent folders don't. This works fine until it doesn't — until a regulator asks for advice records from a matter that closed nine years ago, or a limitation period reopens on a file everyone assumed was safe to purge at year seven. By the time the gap is discovered, the emails are usually already gone.
What good retention actually looks like
An audit-ready archive isn't defined by a single retention number — it's defined by being able to apply the correct number to each category of mail and prove it. That means a few concrete things. Capture has to be continuous and automatic, covering sent mail as well as received, so retention doesn't depend on someone remembering to file a copy. Storage has to be tamper-evident, so a regulator or opposing counsel can trust that what's produced wasn't edited after the fact. Metadata — sender, recipient, timestamps, attachments — needs to be preserved intact, because a stripped-down text export won't satisfy a discovery request or a bar association audit. Retention rules need to be set per category, not per mailbox, so pension advice, minors' matters, and routine admin correspondence can each run on their own clock instead of one blanket setting. And retrieval has to be fast enough to answer a request within days, not weeks of searching through old export files.
This is the gap between "we have the emails somewhere" and "we can produce exactly what was requested, unaltered, within the deadline." Most manual setups fail on at least one of these even when the underlying files still technically exist.
The practical path forward
Start by mapping matter types to actual retention obligations rather than assuming one number covers the firm — this is a one-off exercise, best done with your professional body's current guidance or a compliance-savvy lawyer if the categories are genuinely unclear. Flag the categories that need longer than the default: advice involving minors, pension or superannuation transfers, trust and estate matters, anything with a history of delayed claims in your field. Then fix capture going forward: continuous, automatic archiving of both sent and received mail closes the biggest gap immediately, and tools like AutoArchive Mail handle this by capturing mail as it flows rather than relying on periodic manual exports, applying retention rules by category rather than treating every mailbox the same. You can set this up in under an hour; you can Start Free Trial to see how the category-based rules work against your own retention map before committing to anything. Backfilling historical PSTs and shared-drive exports into a proper archive is the slower part — worth doing, but it's a project, not an afternoon.
This article covers retention periods, not what to do if you've already deleted something you shouldn't have — that's a different conversation, usually with a lawyer, and the right answer depends heavily on jurisdiction and what triggered the gap.
Ready to automate your email archiving?
AutoArchive Mail captures every email automatically — incoming and outgoing — with clean filenames and full .MSG preservation. 14-day free trial, no credit card required.
Start Free Trial See How It Works