Training Records: What UK Providers Must Keep, and For How Long
Training Records: What UK Providers Must Keep, and For How Long
Most training providers keep records because it feels sensible, not because they have checked what is required. That usually means keeping too much of the wrong thing and not enough of the right thing.
Two situations expose this. An awarding organisation or accreditor reviews you and asks for delivery evidence going back three years. Or an employer rings about a certificate you issued in 2023 and asks you to confirm it is genuine. In both cases you need specific records, quickly, and reconstructing them after the fact is not an option.
Here is what to hold and how long to hold it.
What counts as a training record
A training record is the evidence that a specific person completed specific training to a specific standard on a specific date. In practice that breaks into five parts.
The register. Who attended, on what date, at what venue, delivered by whom. This is the foundational record and the one most often kept badly, because a signed paper sheet in a folder does not survive an office move.
The outcome. Whether each learner passed, failed or did not complete, and on what basis. If you assess against learning outcomes, the scores against each outcome belong here. "Attended" is not an outcome.
The certificate record. What was issued, to whom, when, with what certificate number and expiry date. This is what you interrogate when someone asks you to verify a certificate.
The delivery evidence. Session plans, the syllabus version used, trainer qualifications current at the time, and any session documents. This is what an accreditor or awarding organisation asks for, and it is the part providers most often cannot produce.
The communications log. What you sent, to whom, when. Certificates, reminders, feedback requests. This matters more than people expect, because disputes are frequently about whether something was sent rather than whether training happened.
Retention periods
There is no single retention period covering training records, which is why the question is confusing. Several different clocks run at once, and you keep to whichever is longest for a given record.
| Record type | Typical retention | Source of the requirement |
|---|---|---|
| Learner assessment and certification records | 3 years minimum | Awarding organisation centre agreements, passed down from Ofqual conditions. Check your own agreement, some require longer. |
| CPD accreditation delivery evidence | Duration of the accreditation period, commonly 3 years | Accreditor terms |
| General training records for contract purposes | 6 years | Limitation Act 1980, the window for a contractual claim |
| Accident and incident records | 3 years | RIDDOR |
| Health surveillance records | 40 years | COSHH |
| Asbestos medical and exposure records | 40 years | CAR 2012 |
The 40-year categories rarely apply to a training provider's own records, but they do apply to some clients' records, and if you deliver into asbestos or occupational health you should know that the expectation exists.
For most classroom training providers, the practical answer is six years. That covers the awarding organisation minimum with room to spare, and it aligns with the contractual limitation period. Setting a single retention rule is far easier to operate than tracking different clocks per course type.
UK GDPR and learner data
Training records are personal data. Names, contact details, employer, assessment outcomes and sometimes medical declarations all fall under UK GDPR.
The relevant principle is storage limitation: you must not keep personal data for longer than necessary for the purpose you collected it. There is no fixed period in the legislation. You define a retention period, justify it, document it, and stick to it.
Three practical requirements follow from that.
Have a written retention policy. Even a single page. It should state what you keep, for how long, and why. If the ICO ever asks, "we keep everything forever" is not a defensible answer, and neither is "we delete things when we remember to."
Be able to justify the period. Six years justified by the Limitation Act and your awarding organisation agreement is a good answer. Six years because that is what the previous manager did is not.
Be able to respond to a subject access request. A learner can ask for a copy of the personal data you hold about them, and you have one month to respond. If their records are spread across a booking system, an email archive, a filing cabinet and three spreadsheets, that one month gets uncomfortable.
Worth noting: the legitimate interest in retaining certification records to verify certificates is usually a solid basis for keeping them. You do not have to delete a certificate record just because a learner asks, if you need it to verify certificates you have issued. But you do need to have thought about it in advance and written it down.
What an audit actually asks for
Whether it is an awarding organisation quality review, a CPD accreditor renewal, or a corporate client's supplier audit, the questions follow a pattern:
- Show me a course you ran on a specific date. Register, trainer, venue, syllabus version.
- Show me the outcomes for those learners. Not just that they attended, but how you determined they passed.
- Show me the certificate you issued. And confirm the number matches your records.
- Show me the trainer's qualifications as at that date. Current is not enough, it needs to have been current then.
- Show me how you handled a learner who did not pass. This one catches people out. Auditors want to see that "fail" exists as a real outcome in your system, because a provider where everyone always passes is a provider whose assessment is not working.
If you can answer those five in under ten minutes for any date in the last three years, your records are in good shape. If it takes an afternoon of digging, you have a problem that will surface at the worst possible moment.
Common failure points
Paper registers that never get digitised. They get lost, damaged or boxed up during a move. The information exists nowhere else.
Certificate numbering that is not sequential or unique. If you cannot look up a certificate by its number, you cannot verify it, and you cannot prove you did not issue a fake.
Trainer qualification records kept as "current" only. When a trainer's FAW certificate renews, the old record gets overwritten. Two years later you cannot prove they were qualified on the date they delivered.
No record of what was sent. A learner claims they never received their certificate. Without a send log, you cannot contradict them, and you reissue for free.
Records held by one person. The training coordinator who knows where everything is leaves, and takes the map with them.
A workable minimum
If you are starting from spreadsheets, this is the shape to aim for:
- One record per course date, holding date, venue, trainer, syllabus version and attached session documents
- One record per learner per course date, holding outcome, scores against your learning outcomes, and any notes
- A unique, sequential certificate number tied to that learner record, with issue and expiry dates
- A log of every certificate and reminder email sent, with date and recipient
- A stated retention period, applied consistently, with a documented reason
That is the same data set an audit asks for and the same data set that lets you verify a certificate on a phone call. It is not complicated. It just has to be somewhere other than in someone's head.
Train Aid Solutions keeps outcome scores, session documents and a full email log against every course date, with public QR verification for any certificate you have issued. From £40 per month, live in minutes. Read the compliance notes.
Related reading: How long do UK training certificates last? and Training management software: what you actually need.