Audit log retention for UK transport compliance

For regulated transport organisations in the UK, the minimum audit log retention period is the legally required minimum for safety inspections, defect reports and repair records, as set out in the DVSA Guide to Maintaining Roadworthiness. Other record categories, including driver licence checks, tachograph downloads, case files and user activity logs, commonly require longer retention under operator licence guidance, local licensing conditions and GDPR obligations.

The core record categories this article covers are:

  • Safety inspections, defect reports and repair records
  • Driver checks, driver hours and working time records
  • Case files, supporting evidence and correspondence
  • User activity logs and exportable audit trails from your compliance platform

TLDR action plan: Confirm your current retention settings against the 15-month minimum for safety inspections, defect reports and repair records, verify that your audit trail exports are tamper-evident and time-stamped, and schedule a policy review within 30 days.


Table of Contents

What do DVSA and operator licence guidance require?

The DVSA Guide to Maintaining Roadworthiness sets the legally required minimum period for safety inspection records, defect reports and repair documentation, including any assessment or rectification details. That figure is the floor, not the target.

Operator licence guidance separates retention requirements by record type. Driver hours records and working time records carry their own retention obligations, and the guidance recommends keeping MOT certificates and driver licence checks for longer periods as best practice. Local licensing conditions add a further layer: private-hire operator conditions, such as those issued by Coventry City Council, require journey, vehicle and driver records to be retained for at least 12 months and to be immediately accessible to authorised officers.

What regulators actually look for during operator compliance audits is a clear, linked audit trail connecting inspections, defect reports and repair sign-off, not simply a drawer of documents. Absence of producible records is treated the same as having no records at all.

Pro Tip: Retain ‘nil’ defect reports for at least three months. They are a positive audit artefact, demonstrating that drivers are completing walkaround checks even when no defects are found, and they support evidence of active management oversight.


Retention schedule by record type

The table below maps each record category to its legal minimum, a recommended retention band and the trigger for extending beyond that band.

Record type Legal minimum Recommended retention Extension trigger
Safety inspections, defect reports and repair records 15 months 15 months Incident, prosecution or public inquiry
‘Nil’ defect reports 3 months 3 months No standard extension
MOT certificates No statutory minimum 2 years Retrospective investigation
Driver licence checks No statutory minimum 3 years Disciplinary case or licence revocation
Tachograph downloads 12 months (EU rules) 2 years DVSA investigation or prosecution
Working time records 2 years 3 years Employment tribunal or audit
Training and CPC records Duration of employment 3 years post-employment Regulatory inquiry
Case files and supporting evidence Duration of case 6 years Litigation or public inquiry
User activity logs and audit trails Policy-defined 3 years Investigation or subject access request
Financial and insurance records 6 years (Companies Act) 6 years Tax investigation

Practitioners advise retaining MOT certificates for two years and driver licence checks for at least three years to cover comprehensive audits and retrospective investigations. For case files, the six-year band aligns with the Limitation Act 1980 for civil claims.

Pro Tip: Apply event-based retention triggers in your policy. When an incident, complaint or investigation is opened, freeze deletion for all related records until the matter is formally closed and any appeal period has expired.


How to write a retention policy that passes inspection

A compliant retention policy states, in its opening line, the scope, purpose and named owner: for example, “This policy governs the retention and disposal of all compliance records held by [Organisation], owned by the Compliance Manager, and applies to all record types listed in Schedule A.”

A policy checklist for inspection readiness should include:

  1. Scope statement covering all record types and systems in scope
  2. Retention schedule referencing the table above, with legal basis for each period
  3. Roles and responsibilities naming the record owner, the DPO and the system administrator
  4. Exceptions and legal holds describing how deletion is suspended during investigations
  5. Review cadence specifying an annual review and a triggered review after any incident
  6. Disposal rules detailing the destruction method and the certificate of destruction requirement

Operators responsible for hired or leased vehicles must extend the policy to cover those vehicles explicitly. The DVSA is clear that roadworthiness responsibility persists for vehicles hired or leased, and operators must hold copies of inspections carried out while the vehicle was under their control.


How do you preserve chain of custody for case evidence?

An admissible evidence chain requires documentation of who captured each item, when, where it was stored, and who accessed it at every stage. For digital records, the core controls are:

  • Time-stamping at the point of capture, not at the point of export
  • Digital authentication confirming the identity of the user who created or modified the record
  • Role-based access restricting who can view, edit or delete case evidence
  • Tamper-evident storage so any modification is logged and visible
  • Immutable export copies produced at the time evidence is submitted or disclosed

When converting paper records to digital, document the conversion: record the date, the person who scanned the document, the equipment used and a confirmation that the digital copy is a true and complete reproduction.

Pro Tip: For hired or leased vehicles, request inspection copies from the leasing company at the point of handover and log their receipt in your case management system. Waiting until an audit to locate those records creates an avoidable gap in your evidence chain.

The DVSA permits fully electronic inspection records provided they are complete, tamper-proof, time-stamped and capable of producing hard copies on request. Meeting those four criteria is the minimum bar for any compliance document management system.


Implementing retention rules in a cloud compliance platform

Configuration should be completed before records accumulate, not retrospectively. Work through the following steps:

  1. Define a retention policy per record type, mapped to the schedule in Section 3.
  2. Configure legal hold controls so that deletion is blocked automatically when a case is opened.
  3. Set automated archival rules to move records to read-only storage at the end of their active period.
  4. Apply retention labels to exported files so the period and disposal date are embedded in the file metadata.
  5. Confirm export formats produce time-stamped, tamper-evident copies in a format auditors can open without specialist software.

For export testing, run a sample export covering at least four scheduled PMI periods, verify that date and time stamps are present and accurate, confirm that user activity history is visible in the export, and produce a tamper-evident copy to verify integrity.

Platform features that matter most to auditors include human-reviewed alerts (which reduce false positives and prevent automatic enforcement actions), role-based workflows that create a structured evidence trail, and structured case evidence management that links inspections, defect reports and repair sign-off into a single, auditable record.

Pro Tip: Extended retention periods increase storage volume. Review your storage allocation annually and model the growth rate before extending any retention band, particularly for high-frequency records such as daily defect reports and tachograph downloads.


Are you ready for an unannounced DVSA inspection?

DVSA compliance audit sample sizes range from all vehicles for fleets of 1 to 3, down to 10% of vehicles for fleets of 50 or more. Maintenance sample periods should cover at least four scheduled PMIs. Your mock inspection plan should mirror those parameters.

Readiness task Frequency Owner
Export test covering four PMI periods Monthly Compliance Manager
Verify time-stamps and user activity logs Monthly System Administrator
Review legal hold status for open cases Monthly Compliance Manager
Full policy review Annual DPO and Compliance Manager
Mock inspection against DVSA sample matrix Every 6 months Compliance Manager

For remote inspections, auditors accept scanned hard copies and screen-share sessions, but each document must be complete and legible. Granting live system access carries risk: a user error during the session could alter a record. Prepare a read-only export package in advance.

Pro Tip: For an unannounced visit, have a pre-prepared folder containing the last 15 months of safety inspection, defect report and repair records, the current PMI schedule, the last four defect report exports and a printed user activity log. Producing records within minutes signals management control.


GDPR and data protection obligations for retained records

The lawful basis for retaining compliance records is typically a combination of legal obligation (Article 6(1)© UK GDPR) and legitimate interests (Article 6(1)(f)), depending on the record type. Safety inspection records held to meet DVSA requirements sit clearly under legal obligation. Case evidence held beyond the regulatory minimum for litigation purposes relies on legitimate interests, which requires a documented balancing test.

DPO action items when updating a retention policy:

  1. Complete a Data Protection Impact Assessment for any new retention rule that extends beyond the regulatory minimum.
  2. Apply data minimisation: retain only the fields necessary for the compliance purpose.
  3. Confirm that access controls restrict personal data in case files to named roles.
  4. Schedule automated deletion checks at the end of each retention period.
  5. Document the retention justification in the policy, referencing the lawful basis for each record type.

Subject access requests for case evidence require careful handling. Where disclosure would prejudice an ongoing investigation, the exemption under Schedule 2, Part 3 of the Data Protection Act 2018 may apply. Record the decision and the legal basis for any partial or full refusal.


How should you review and dispose of records securely?

Annual policy reviews should be supplemented by triggered reviews after any incident, enforcement action or change in regulatory guidance. For record audits, sample at least 10% of records approaching their disposal date each quarter.

Secure disposal checklist:

  • Digital records: overwrite to at least HMG Infosec Standard 5 (IS5) baseline or use certified deletion software.
  • Physical records: cross-cut shredding to DIN 66399 Level P-4 or higher, with a certificate of destruction retained for three years.
  • Cloud-hosted records: obtain a written confirmation of deletion from the platform provider, referencing the specific record types and date range.
  • Legal holds: before any disposal run, check the legal hold register and exclude all records flagged for active cases or investigations.

Pro Tip: Maintain a disposal log recording the record type, date range, destruction method and the name of the person who authorised disposal. That log is itself a compliance record and should be retained for at least three years.

Disposal trigger Action required Documentation
Retention period expired, no hold Schedule for secure disposal Disposal log entry
Active legal hold Freeze deletion, review quarterly Hold register update
Investigation closed Lift hold, restart retention clock Case closure note
Policy change extends period Update retention label, defer disposal Policy amendment record

Key takeaways

Regulated transport organisations must anchor their log retention policies to the DVSA legal minimum retention period for maintenance records, extend retention for higher-risk categories, and maintain a demonstrable, linked audit trail that auditors can verify on demand.

Point Details
DVSA 15-month minimum Safety inspections, defect reports and repair records must be kept for at least 15 months.
Extend for higher-risk records MOT certificates warrant 2 years; driver licence checks warrant at least 3 years of retention.
Audit trail over documents Regulators assess the linked chain from inspection to repair sign-off, not isolated files.
GDPR lawful basis required Each retention period must be mapped to a documented lawful basis in your policy.
Velocerta for implementation Velocerta provides configurable retention policies, legal hold controls and tamper-evident exports for regulated fleets.

Why retention policy is where most operators fall short

The 15-month rule is well known. What is less understood is that meeting the minimum is not the same as demonstrating management control. An auditor who finds 15 months of records stored in a folder with no linked defect history, no repair sign-off trail and no user activity log will not conclude that the operator is compliant. They will conclude that the operator cannot prove it.

The organisations that consistently pass compliance audits are not those with the longest retention periods. They are the ones whose records link together: walkaround check to defect report, defect report to repair instruction, repair instruction to sign-off, sign-off to the next scheduled inspection. That chain is what the DVSA’s operator compliance audit guidance is actually testing.

Platform-controlled retention matters because it removes the human variable. When retention periods, legal holds and disposal rules are configured in the system rather than managed by individual staff, the audit trail is consistent regardless of staff turnover or workload pressure. Human-reviewed alerts add a further layer: they prevent automatic enforcement actions triggered by data errors, which is a real risk when compliance monitoring runs at scale across a large fleet.

The evidence chain of custody is not a bureaucratic formality. It is the mechanism by which a transport organisation proves, in an enforcement or legal context, that its records are complete, unaltered and produced by the person who claims to have produced them.


Velocerta supports retention, audit trails and inspection readiness

Regulated transport organisations that need configurable audit log retention, legal hold controls and tamper-evident exports built into their compliance workflow will find those capabilities in Velocerta. The platform is designed specifically for local authorities, taxi and private-hire operators and commercial fleet managers, with retention policies configurable per record type, automated archival, role-based access and structured case evidence management that links inspections, defect reports and repair sign-off into a single, auditable trail.

Every alert in Velocerta undergoes human review before any enforcement action is taken, reducing the risk of automatic suspensions caused by data errors. Case workflows capture the full evidence chain, and exports are time-stamped and tamper-evident, meeting the DVSA’s electronic records requirements. To see how the platform manages retention and audit readiness for your fleet, request a demonstration or review the solution pages at velocerta.co.uk.


Primary sources and further reading

  • Guide to Maintaining Roadworthiness: commercial goods and passenger carrying vehicles — DVSA, GOV.UK
  • Operator compliance audits — DVSA, GOV.UK
  • Goods vehicle operator licensing guide — GOV.UK
  • Private hire operator licence conditions (Coventry) — Coventry City Council
  • Evidence chain of custody: a guide for regulated transport — Velocerta
  • Compliance document management for regulated fleets — Velocerta

Recommended