Almost every conversation about SYSC 10A record-keeping is a conversation about the start of the record's life: capture it, index it, retain it, be able to produce it. What gets far less attention is the other end of the clock — the point at which the retention obligation is satisfied and the record is no longer required to be kept. Firms plan meticulously for keeping data and barely at all for stopping.
That asymmetry isn't an accident. Retention is the part with a regulator attached to it, so it gets a project, a budget line, and a named owner. Deletion has no equivalent pressure pointed at it from the compliance side — and from the engineering side, deleting is simply harder to get right than storing, so it tends to be the thing quietly deferred. The result, in a lot of firms, is a records estate that grows monotonically: nothing is ever confidently removed, because nobody can say with certainty that removing it is safe.
The gap between "no longer required" and "safe to delete"
The retention rule sets a floor, not a ceiling — it says how long a firm must keep relevant records, not how long it may. Once that floor is cleared, other obligations can still apply: a live dispute, an ongoing investigation, a litigation hold, or simply a firm's own broader document retention policy written for reasons unrelated to SYSC 10A. Treating "the five years are up" as a trigger to auto-delete, without checking those other holds first, is its own kind of failure — one that looks the same from the outside as never having a deletion process at all, right up until it destroys something a court or the regulator wanted preserved.
Meanwhile the opposite failure mode is just as common and much quieter: data protection law expects personal data to be kept no longer than necessary for the purpose it was collected for, which sits in tension with a compliance instinct to retain everything indefinitely "just in case." A firm that never deletes anything isn't being more careful — it's carrying an unmanaged data protection liability on top of the regulatory one, usually without having made that trade-off deliberately. Firms should work through the specifics of how their retention and data protection obligations interact with their own advisers rather than assume either obligation simply overrides the other.
Deletion needs its own audit trail
The practical fix looks a lot like the fix for retrieval, which is really the same discipline pointed in the other direction: deletion has to be a designed, logged event, not an assumption. That means a defined trigger per record class, a check against any active hold before it fires, and — critically — a record that the deletion happened: what was removed, when, under what policy, and who or what authorised it. Without that trail, a firm can't actually demonstrate compliance with either side of the obligation. It can't prove records were kept for the required period, and it can't prove they were removed once that period passed and no hold applied.
There's a secondary trap worth naming: primary systems are rarely the only copy. Backups, vendor archives, and export files generated for a past audit request all tend to outlive the record they were taken from, quietly extending the real retention period well past the one written in policy. A deletion process that only touches the system of record while leaving three older copies untouched elsewhere hasn't actually closed the loop — it's just made the primary store look clean.
None of this is a reason to delete aggressively or on a rigid timer without judgement. It's a reason to treat disposal with the same structure as capture, rather than as an afterthought nobody owns. A firm that can show exactly when a record was created, exactly when it was produced on request, and exactly when and why it was removed has a complete answer to a records question. A firm that can only show the first two has half of one — and won't find out which half is missing until someone asks for the record it no longer has, or finds the copy it thought was gone.