← Back to catalogue
Published

Retention / Disposition

vr.wm-xct-035 · wm-xct-035-retention-disposition

Attach accountable retention, hold, disposition and evidence context to an independently mastered subject.

World Models Cross-cutting context XCT.RET

Bundle → Layer → Finding → Questions Filled

3 bundles · 3 layers · 5 findings · 10 questions

Retention rule How long a record must be kept and why.

Schedule and trigger

The retention class, period and the event that starts it.

Retention class

The schedule entry that applies to the record, with its legal or business basis.

  1. Which retention schedule entry applies to this record?
  2. Which law, regulation or business need sets the period?

Trigger and period

The event that starts the retention period and its length.

  1. Which event starts the retention period, such as contract end or case closure?
  2. Has the trigger occurred, and when does the period end?
Holds What suspends disposition.

Legal and other holds

Holds that prevent disposition while they are in force.

Active hold

A legal, audit or investigation hold placed on the record.

  1. Is the record under a legal or audit hold, and who placed it?
  2. When was the hold last reviewed, and has it been released?
Disposition What happens at the end and how it is proven.

Action and evidence

The disposition action and the record that proves it.

Disposition action

Whether the record is destroyed, transferred to an archive or reviewed.

  1. Which disposition action does the schedule prescribe?
  2. Who authorised the disposition?

Disposition evidence

Proof of when and how the disposition was carried out, including copies and backups.

  1. Is there a certificate or log showing when and how the record was disposed of?
  2. Were copies and backups disposed of as well?

Classifiers Filled

Family
World Models
Category
Cross-cutting context
Entry kind
mixin
Navigation path
NAV.XCT.RET
Domain
XCT.RET
Industry
Cross-industry
Tags
retentiondispositionxct.ret

What it is Filled

Retention and disposition govern how long a record or data object is kept and what happens to it at the end: destruction, transfer to an archive or review. A retention rule names a trigger, a period, any legal holds and the evidence that disposition was carried out. It is a cross-cutting pattern applied to records of any kind, not a record type of its own.

In scope

  • Host-specific scope, schedule binding, trigger evidence, cutoff and external eligibility assessments
  • Scoped holds and releases, outcome authority and privacy reconciliation references
  • Transfer acceptance, destruction reports, residual copies, evidence continuity and review obligations

Out of scope

  • Mastering host payloads, schedules, legal cases, reusable rule expressions, generic lifecycle or access-control machinery
  • Running policy or calendar engines, issuing legal decisions or holds, releasing holds, operating freezes, destroying data or media, transferring custody or executing backup remediation
  • Archival arrangement and preservation operations, domain-specific mandatory durations, universal legal precedence and operational handling of controlled items

Why it exists Filled

Attach accountable retention, hold, disposition and evidence context to an independently mastered subject.

Distinguishing features Filled

  • It is a cross-cutting rule applied to records of any type, not a record type itself.
  • A legal hold overrides the schedule and suspends disposition until released.
  • Disposition includes transfer to an archive, not only destruction.
  • The evidence of disposition is kept after the record itself is gone.

What robots and AI may and may not do Filled

Must not

  • Destroy records under a legal or audit hold.
  • Dispose of records without the authorisation the schedule requires.
  • Delete disposition evidence.
  • Keep personal data beyond its retention period without a lawful basis.
  • Change a retention schedule on its own.

Only with a human decision

  • Approving a retention schedule or a change to it.
  • Authorising destruction of records.
  • Placing or releasing a legal hold.

May

  • Assign retention classes to records according to the approved schedule.
  • Compute disposition dates from triggers and periods.
  • Report records that are due for disposition or kept beyond their period.
  • Keep disposition logs.

Moral aspects Filled

  • Keeping personal data too long increases privacy risk, while deleting too early can destroy evidence people need.
  • Destruction of records under hold can obstruct justice.
  • Transfer to archives preserves public memory and accountability.

Who is affected

  • People whose data is held in records
  • Organisations bound by retention duties
  • Courts, auditors and regulators
  • Archives and future researchers

Owners Filled

Steward

The records manager or information governance function that maintains the retention schedule.

Roles

Records steward
Maintain accurate scope and schedule references and route unknown applicability for review.
Competent disposition authority
Approve or refuse outcomes through the external decision process; assess unresolved legal conflicts.
Hold authority
Issue and release notices in the external matter process and define precise covered scope.
Custodian or executor
Acknowledge notices and supply scoped execution or transfer evidence under separate authorization.
Privacy reviewer
Assess purpose, minimisation and erasure exceptions through the applicable qualified process.
Evidence reviewer
Check attestation coverage, partial outcomes and residual copies independently of reported execution where the profile requires.

Master systems

  • Records management system
  • Retention schedule register
  • Legal hold management tool

Links to other meta-models Filled

references

  • WM-REC-001 - Host document or record master. Its content, identity and record lifecycle remain external; a non-document host must supply an equivalent pinned master binding.
  • WM-KNW-013 - Reusable constraint and requirement rule master owns expression, applicability and rule lifecycle. This mixin carries the selected revision and subject operands only.
  • WM-XCT-038 - External policy evaluator owns rule evaluation and explanation. Local functions record its input and output references without implementing its engine.
  • WM-XCT-021 - Generic host lifecycle and transition semantics remain external. Eligibility, hold and execution observations are distinct subject-specific axes.
  • WM-REC-010 - Approval and exception decision master owns authority, rationale and decision revision; attaching a decision does not issue or approve it.
  • WM-REC-015 - Optional archival fonds or collection owns accession, arrangement and preservation. This mixin references transfer scope and accepted custody.
  • WM-REC-011 - Evidence record master owns original attestation and evidence validity; retain only retention-specific links and assessment context here.
  • WM-REC-013 - Operational log master owns event persistence and audit-trail mechanisms. This mixin indexes relevant events without recreating logging infrastructure.
  • wm-rec-001-document-record - Retention rules apply to documents and records.

aligned

  • PROV-O - Conceptual mapping of subject, activity, agent, revision and invalidation references; an invalidation assertion is not a destruction certificate.
  • PREMIS 3.0 - Overview-level preservation object, event, rights and agent alignment. No schema or archival repository conformance is asserted.

neighbor

  • WM-REC-001 - Host document or record master. Its content, identity and record lifecycle remain external; a non-document host must supply an equivalent pinned master binding.
  • WM-KNW-013 - Reusable constraint and requirement rule master owns expression, applicability and rule lifecycle. This mixin carries the selected revision and subject operands only.
  • WM-XCT-038 - External policy evaluator owns rule evaluation and explanation. Local functions record its input and output references without implementing its engine.
  • WM-XCT-021 - Generic host lifecycle and transition semantics remain external. Eligibility, hold and execution observations are distinct subject-specific axes.
  • WM-REC-010 - Approval and exception decision master owns authority, rationale and decision revision; attaching a decision does not issue or approve it.
  • WM-REC-015 - Optional archival fonds or collection owns accession, arrangement and preservation. This mixin references transfer scope and accepted custody.
  • WM-REC-011 - Evidence record master owns original attestation and evidence validity; retain only retention-specific links and assessment context here.
  • WM-REC-013 - Operational log master owns event persistence and audit-trail mechanisms. This mixin indexes relevant events without recreating logging infrastructure.

related

  • wm-xct-021-lifecycle-status - Disposition ends the lifecycle of a record.
  • wm-rec-015-archival-fonds-collection - Records transferred for permanent keeping join archival fonds.

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • A retention rule is identified by its schedule and class code.
  • Holds are identified by the matter or case reference that requires them.
  • Disposition events are identified by the disposition log entry or certificate number.

Direct properties not applicable Not applicable

Not applicable

The subject is an institutional or informational record, not a physical object with measurable properties.

Recognition optional Filled

  • A retention rule names a record class, a trigger, a period and a disposition action.
  • Often confused with backup policies, archival storage tiers or access control.

Capabilities and actions required Filled

  • Disposition dates can be computed from triggers and periods.
  • Holds can suspend disposition for selected records.
  • Disposition can be executed and evidenced in batches.

Hazards and failure modes required Filled

  • Spoliation of evidence by destroying records under hold.
  • Privacy breaches from over-retention.
  • Copies and backups that escape disposition.

Standards and interfaces required Filled

  • ISO 15489 records management concepts.
  • MoReq2010 and DoD 5015.2 for records management system requirements.
  • Legal hold and eDiscovery processes.

Context of use required Filled

  • Data protection laws require storage limitation, while sector laws require minimum retention periods.
  • Applies across public bodies, companies and archives.

Sources Filled

  1. Implementing Schedules - National Archives and Records Administration
  2. Scheduling Records - National Archives and Records Administration
  3. Federal Records Centers Program Freeze Process Overview / FAQ - National Archives and Records Administration
  4. Principle (e): Storage limitation - Information Commissioner's Office
  5. Right to erasure - Information Commissioner's Office
  6. SP 800-88 Rev. 2, Guidelines for Media Sanitization - National Institute of Standards and Technology
  7. PROV-O: The PROV Ontology - World Wide Web Consortium
  8. PREMIS Data Dictionary for Preservation Metadata, Version 3.0 - Library of Congress
  9. ISO 15489-1 Information and documentation - Records management, ISO
  10. General Data Protection Regulation (EU) 2016/679, Article 5(1)(e) storage limitation, European Union

Open questions

  • Reconcile source versions and current consolidated legal rules with each adopting jurisdiction and sector profile, including multiple duties, scoped holds and privacy exceptions.
  • Build nested instance schemas and adversarial fixtures for unknown triggers, calendar boundaries, concurrent holds, partial releases, stale approvals, partial batches, backup restoration and minimal evidence retention.
  • Pin and test host, rule, evaluator, decision, archive and evidence interfaces with loss-aware mappings and authorized execution boundaries.
  • Obtain independent external review before any canonical or publishable-draft promotion.
  • Jurisdiction- and sector-specific schedules, qualified legal precedence and current consolidated law are not supplied.
  • Full NIST sanitization procedures and PREMIS dictionary/schema conformance were not reviewed; no technical destruction recipe is supplied.
  • Nested field schemas, date arithmetic engine, live integrations, pinned neighbor specifications and executable instance fixtures are absent.
  • Actual backup inventories, cryptographic key dependencies, distributed propagation and restore-time remediation need system-specific operational evidence.
  • No independently authored second-provider research exists for this run.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-xct-035-retention-disposition/spec.yaml, ver-cy/world-models/card-supplements/wm-xct-035-retention-disposition.json