How to Keep Credential Records That Survive an Audit

Why this matters

An audit does not test your register. It tests whether a claim you made about a person on a date is backed by a document somebody else issued, that is legible, that clearly falls inside the period in question, and that you can put in front of the requester in the time they gave you. Shops routinely have all of that and still fail, because the document lives in a phone gallery, or the person is filed under a nickname, or the only copy is a photo where the expiry line is blurred.

The register is the index. This is about the evidence behind it. Building the register itself is a separate job. See related: How to Build a Credential Register for a Small Shop.

Step 1: Decide what counts as a record

A record is the issuer's artifact. Your spreadsheet row is not a record, it is a claim about one. So is a calendar entry, a note in a job file, and an email from a tech saying they passed.

This distinction sounds pedantic until the day someone asks for proof and you discover the only thing you have is your own assertion. Every row in the register either points at an issuer-produced artifact or it is a gap, and it should be visibly marked as a gap so it can be closed rather than quietly counted as covered.

Four properties make an artifact hold up. Sourced: issued by the certifying body, the authority, or an approved provider, with their identifying marks intact. Legible: every field readable, especially names, dates and any certificate or licence number. Period-anchored: the dates on it place it inside the window the requester is asking about. Retrievable: someone other than the person who filed it can produce it on demand.

The fifth property is not on the artifact, it is between artifacts: consistent with your other records. More on that in step 8.

Step 2: Capture at the source, in the moment

The capture path decides the quality, and there is no repairing a bad capture six months later when the tech has lost the original.

Route provider and authority emails to one address that is not a person's inbox. A certificate that arrives at a tech's personal email is not in your possession.

For a physical card, photograph it flat, in even light, filling the frame, and then read the expiry back off the photo before you file it. If you cannot read it on a phone screen at normal zoom, neither can an auditor.

For a portal-held credential, print to PDF rather than screenshotting, and make sure the URL and the retrieval date print on the page. That combination is what makes a portal record self-authenticating: it shows where it came from and when you pulled it.

Step 3: Name and store on one convention

Retrieval time is what fails audits, not existence. Adopt one filename convention and one location, and apply it with no exceptions: person, credential type, issue date, expiry date. Legal name, not the name people call them.

One location means one. A credential class split between a shared drive, an email folder and a filing cabinet is three retrieval paths, and under time pressure someone will search the wrong two first.

Two naming rules that look fussy and are not. Use an unambiguous date format consistently, because a mixed set of day-first and month-first filenames is unsortable and quietly mis-sorts the very rows you filter on. And put the expiry in the filename even though it is also in the register, so a folder listing sorted by name is itself a readable expiry report when the register is unavailable, which is exactly the moment somebody needs it.

Step 4: Keep the record immutable once a request arrives

Normal operation is one thing; the moment an authority, a customer's lawyer, or an insurer asks for records, the rules change.

Stop editing. Do not tidy a file, correct a typo, re-scan a blurry certificate, or reorganise a folder after a request or a notice lands. A record altered after notice is a far worse fact than the messy record it replaced, because it moves the conversation from "your paperwork is untidy" to "your paperwork changed after we asked", and the second question is one you cannot answer well.

What you may do is add, clearly marked as added and dated. If a certificate genuinely exists but was not filed, retrieve it from the issuer, and note where it came from and when. Sourcing a replacement from the issuing body is repair; recreating one yourself is not, ever, in any circumstance.

The practical requirement behind all this is that your storage keeps a modification history you do not control. A shared drive or document system with version history satisfies it. A folder on a laptop does not, and neither does a system where anyone can overwrite a file in place with no trace. Set the access so that a small number of named people can add, and check once that deletion leaves a record.

Step 5: Anchor continuing education to periods, not dates

Continuing education records carry a requirement the others do not: the artifact has to establish two facts at once. That the hours fell inside the authority's reporting period, and that the provider was approved for that period.

Provider approval is the one that bites, because approval lists change between cycles and a provider approved last cycle is not automatically approved this one. Check the list at booking, not at completion, and file the evidence of approval alongside the certificate. A completed course from an unapproved provider is not partial credit, it is zero, and you find out at the worst moment. See related: Continuing Education That Pays Off.

Step 6: Keep the superseded versions

Counterintuitive and important: do not delete the expired one when the renewal arrives.

What an auditor or a customer's counsel asks is rarely "are they current". It is "were they current on this date", where the date is when a particular job happened. Answering that requires the certificate that was in force then, not the one in force now. A file holding only current credentials can prove today and nothing else.

The same set proves continuity across a renewal boundary, which is the question that matters when someone alleges a gap. Two certificates whose date ranges abut are proof; one certificate plus your word is not.

Step 7: Set retention by the longest clock touching the record

Do not set one retention rule for everything. Identify the clocks and keep to the longest that applies.

The clocks are typically your licensing authority's own audit lookback, your contract requirements with GCs and property managers, any statute of limitations or repose that could reach back to work performed, and where a federal record rule applies, that rule. On the last one, be precise about scope: 29 CFR 1910.1020 requires employee exposure records be kept for 30 years and employee medical records for the duration of employment plus 30 years, and that applies to those record types, not to trade credential certificates, which have no equivalent federal retention rule. Do not let a long federal number for one record class silently become your policy for a different one, and do not assume the absence of a federal rule means a short retention is safe, because the contract and repose clocks are usually the binding ones anyway.

Step 8: Reconcile against payroll and dispatch once a year

Consistency is the property no filing discipline produces on its own, because it lives between systems.

Two directions, both necessary. From payroll to credentials: every person paid as a field technician during the period should appear in the register with the credentials their role requires, including anyone who left mid-year. Leavers are the reliable gap, because nobody files a certificate for someone who is gone. From dispatch to credentials: every job involving a task that requires a credential should map to a person who held that credential on the job date. That is the direction that catches the real exposure, which is not a missing certificate but a job assigned to someone who should not have been on it.

Where the two disagree, the disagreement itself is the finding. Fix the underlying assignment practice, not just the file.

Worked example: the timed retrieval drill

The only honest test of a records system is someone other than its owner producing an item under a clock.

The rule being tested. Any single requested artifact must be retrievable in under 10 minutes by someone who did not file it, measured per item, on a sample of at least 8 items drawn at random from the register. The drill fails if more than 1 of the 8 exceeds the target, OR if any item cannot be produced at all. When it fails, the step change is to consolidate that one credential class into the single canonical location before the next drill, not to re-file everything.

First drill. The owner drew 8 rows and handed them to the office person, who had filed roughly half of them. 6 of the 8 were produced inside the 10-minute target. 2 exceeded it. Of those 2, one was eventually found and one could not be produced at all: the register row existed, the artifact behind it never had.

Scored: 6 of 8 within target, 75%. 7 of 8 producible at all, about 88%.

Run that against the rule as written. 2 of 8 exceeded, which is more than 1, so the drill fails on the first limb. And 1 item could not be produced, so it fails on the second limb independently. Both limbs trip, which is worth stating because the rule is an OR and only one needed to.

The two failures, diagnosed. The item found late was filed under a nickname, so the searcher's name query returned nothing and they went to email. The item that did not exist was a wallet-card photo taken on a personal phone and never transferred, and the card holder had since replaced the phone.

Fixes. Legal names only, applied retroactively to every file in that class. And card photos captured to the shared location at the moment of capture, verified legible before the tech leaves the counter.

Second drill, 8 fresh rows. All 8 produced inside the target. One point worth reporting rather than smoothing over: the slowest came in at 9 minutes 40 seconds, inside the 10-minute target but only just, and it sat in a shared folder nobody had opened in months. Under the rule as written that is a pass, and it is a pass with a signal. A near-miss on retrieval time is a location problem that has not caused a failure yet, and the fix is to move it before it does.

What would change the target. If your authority or your largest customer specifies a response window, use theirs. A 21-day audit response makes 10 minutes per item generous; a GC's gate demanding proof before a truck rolls makes it slow.

How to verify you got this right

Run the drill twice a year, and have someone different run it each time. A drill run by the person who built the system tests the system's builder, not the system.

Then check the two things a drill cannot see. Pull a random job from twelve months ago and ask what credentials the assigned tech held on that date, which tests period-anchoring rather than currency. And confirm your retention clocks are written down somewhere other than in one person's head, because retention is the property that fails silently, years later, when the person who knew the rule has moved on.

References

  • Occupational Safety and Health Administration, 29 CFR 1910.1020 (employee exposure and medical record retention; scope is those record types, not trade credentials)
  • Your state or local licensing authority, for audit lookback periods and acceptable proof formats
  • See related: How to Build a Credential Register for a Small Shop; The Records a Licensing Authority Typically Expects; Continuing Education That Pays Off