This is a ready-to-use certificate of destruction. It is the one document in a records-retention program that closes an irreversible act, so it is built to make that act deliberate: nothing on this form can be completed until the retention clock has genuinely lapsed and a legal hold check has cleared. Replace every <<FILL: ...>> placeholder with your own specifics, set your form number under document control, and route it through your normal review and approval. A worked filled specimen follows the blank form so you can see how a completed version reads. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Form title | Certificate of Destruction |
| Form number | <<FILL: FORM-ID, e.g. FRM-QA-041-02>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Linked SOP | <<FILL: SOP-ID for records retention, archival, and retrieval, or for decommissioning>> |
| Page | <<FILL: page of pages>> |
When to use this form
Complete one certificate per destruction event: a defined set of records of the same type, reaching eligibility for disposal at the same time, destroyed by the same method on the same date. Do not use one certificate to cover a mixed batch of record types with different retention bases; each record type’s eligibility has to be shown separately, because the fact that one record type has lapsed proves nothing about another. This form is generated at the end of the disposition sequence: retention determination, then the migrate-versus-archive-versus-destroy decision, then, only for records dispositioned to destroy, this certificate.
Field table
| Field | Format | Required | Who completes it | When |
|---|---|---|---|---|
| Record type(s) and identifiers or ranges destroyed | Text, specific enough to reconstruct scope later (batch range, date range, system of origin) | Yes | Records owner / archivist | At initiation |
| Volume | Count or size (record count, file count, or physical volume) | Yes | Records owner / archivist | At initiation |
| Retention basis and clock-start event | Text, citing the schedule row and the event that started the clock | Yes | Records owner, from the retention schedule | At initiation |
| Retention lapse date | Date | Yes | Records owner | At initiation |
| Legal hold check result | Yes / No hold applies, with checker name and date | Yes | Legal | Before authorization |
| Authorization | Name, role, signature, date | Yes | Quality Assurance and Legal (both) | Before execution |
| Destruction method | Text (secure data wipe, cryptographic erasure, physical media destruction, shredding) and standard followed | Yes | Executing function (IT / records management) | At execution |
| Execution date and operator | Date, name, signature | Yes | Executing function | At execution |
| Verification of completeness and irrecoverability | Text describing how completeness was confirmed | Yes | Independent verifier, not the executing operator | After execution |
| Certificate retention | Duration and location the certificate itself is kept | Yes | Records owner | At closure |
Instructions
- Confirm the record type’s retention period has genuinely lapsed against the current records retention and disposition schedule; cite the specific schedule row, not a general recollection of the period.
- Route the legal hold check to Legal before doing anything else. Legal confirms, in writing on this form, that no active hold, inspection, investigation, litigation, or recall touches any record in scope. A hold on any part of the scope stops the whole certificate; do not destroy the unheld portion and defer the rest without splitting the certificate into two, one per disposition outcome.
- Obtain authorization from both Quality Assurance and Legal before execution. Neither signs on behalf of the other; both are required.
- Execute destruction using the method stated, appropriate to the medium (electronic media, paper, or a hybrid) and to any applicable privacy or security requirement.
- Have a person who did not execute the destruction verify and document that it was complete and unrecoverable. This is a segregation-of-duties control, not a formality; self-verified destruction defends nothing.
- Sign and issue the certificate. Do not backdate any field; if execution slips past the planned date, record the actual date.
- File the completed certificate as a controlled GxP record in its own right.
The certificate
| Field | Entry |
|---|---|
| Certificate number | <<FILL>> |
| Record type(s) destroyed | <<FILL>> |
| Identifiers or ranges | <<FILL>> |
| System(s) of origin | <<FILL>> |
| Volume | <<FILL>> |
| Retention schedule reference | <<FILL: schedule row / record type ID>> |
| Retention basis and clock-start event | <<FILL>> |
| Retention lapse date | <<FILL>> |
| Legal hold check | No hold applies / Hold applies (stop) |
| Legal hold checked by (name, signature, date) | <<FILL>> |
| Quality Assurance authorization (name, signature, date) | <<FILL>> |
| Legal authorization (name, signature, date) | <<FILL>> |
| Destruction method | <<FILL>> |
| Standard followed (if applicable) | <<FILL>> |
| Execution date | <<FILL>> |
| Executed by (name, signature) | <<FILL>> |
| Verification method | <<FILL>> |
| Verified by (name, signature, date, independent of executor) | <<FILL>> |
| Result | Complete and unrecoverable / Exception noted: <<FILL>> |
Retention
Retain this certificate as a controlled GxP record indefinitely, or for the period set by <<FILL: records retention policy reference>>, whichever your policy specifies. The certificate is the permanent proof that disposal was lawful; do not apply the destroyed record’s own retention period to the certificate that documents its destruction.
Acceptance criteria
A certificate is acceptable when the record type’s retention has genuinely lapsed against the current schedule, the legal hold check was performed by Legal and documented before authorization, both Quality Assurance and Legal authorized the destruction, the method used was appropriate and stated, destruction was verified as complete and unrecoverable by someone other than the person who executed it, and the certificate itself is retained as a controlled record.
References
21 CFR 211.180 and 211.194 (records retention and availability; destruction is only appropriate once these periods and any longer applicable period have lapsed). 21 CFR Part 11 and EU GMP Annex 11 (electronic records; controlled disposal as part of the record lifecycle). EU GMP Chapter 4 (Documentation), retention and disposal expectations. MHRA GxP Data Integrity Guidance and Definitions (March 2018). PIC/S PI 041, Good Practices for Data Management and Integrity.
Confirm the current version and clause numbers of each reference before issue. This form does not itself set retention periods; it executes disposition decisions already made under the records retention and disposition schedule and the legal hold register.
Filled specimen
The following shows the certificate completed for an example laboratory instrument log whose retention lapsed after a legacy system’s archive was confirmed and no hold applied. Company, system, and numbers are illustrative; replace them with your own.
| Field | Entry |
|---|---|
| Certificate number | DST-2027-011 |
| Record type(s) destroyed | Instrument configuration exports, non-GxP-decision reference data, from a retired chromatography data system archive |
| Identifiers or ranges | Configuration snapshot set CFG-CDS-04-2014 through CFG-CDS-04-2019 |
| System(s) of origin | Legacy CDS archive ARC-QC-04 |
| Volume | 1,860 files |
| Retention schedule reference | RT-045, Instrument configuration exports (non-GxP-decision) |
| Retention basis and clock-start event | Company policy, configuration snapshot date plus 7 years; not tied to any batch or product retention clock because the data is non-decision reference only |
| Retention lapse date | 04 March 2027 |
| Legal hold check | No hold applies |
| Legal hold checked by | M. Okafor, Legal, signed, 10 March 2027 |
| Quality Assurance authorization | R. Gomez, signed, 12 March 2027 |
| Legal authorization | M. Okafor, signed, 12 March 2027 |
| Destruction method | Cryptographic erasure of the storage volume, per the company’s approved media sanitization standard |
| Standard followed | Company media sanitization standard MSS-IT-02, aligned to NIST SP 800-88 sanitization categories |
| Execution date | 15 March 2027 |
| Executed by | D. Ferreira, IT Operations, signed |
| Verification method | Post-erasure read-attempt confirming no recoverable content, performed on a sample of the affected volume and on the erasure log |
| Verified by | J. Alvarez, IT (independent of execution), signed, 16 March 2027 |
| Result | Complete and unrecoverable |
In this example, the destroyed data was explicitly non-decision reference material with its own shorter, policy-set clock, kept separate on this certificate from the GxP release data in the same archive, whose 30-year clock had not lapsed and was not touched. The legal hold check and both authorizations predate execution, and verification was performed by someone other than the person who ran the erasure. That sequence, eligibility to hold check to dual authorization to execution to independent verification, is what a reviewer expects to see.
Common inspection findings this form prevents
- Records destroyed with no documented proof of what was destroyed, when, by whom, or under what authority.
- A whole system or archive wiped in one action, sweeping up record types whose individual retention clocks had not lapsed.
- No legal hold check performed, or the check performed by the same person requesting the destruction rather than by Legal.
- Only one function (commonly IT alone, or Quality alone) authorized a destruction that required both Quality and Legal sign-off.
- Destruction “verified” by the same person who executed it, with no independent confirmation of irrecoverability.
- The certificate itself was not retained, so years later there is no proof the earlier disposal was lawful.
How to adapt this form
- Set your form number, linked SOP, and effective date in the header.
- Point the retention schedule reference field at your actual records retention and disposition schedule, not a restated period.
- Confirm your legal hold register is the single source Legal checks against before completing the hold-check field.
- Adjust the destruction method options to the media types you actually handle (electronic, paper, hybrid, physical devices).
- If your organization uses a single combined Quality/Legal sign-off role, document that as a compensating control rather than silently dropping one signature line.
- Confirm every regulation in the references against the current published version before issue.