Operations teams often keep change logs only as long as the helpdesk needs them — ninety days is common. Auditors reviewing a full financial year will ask for the trail across the entire period. When those two clocks disagree, finance discovers the gap during fieldwork.
Align three calendars
- Statutory period — usually the financial year under audit, plus comparatives if prior-year journals are reopened.
- Internal investigation window — how far back you might need to reconstruct after an incident.
- System default — what your ERP or middleware actually stores before rotation.
Write the shortest of those three into a policy only after confirming the system can honour it. Policies that promise seven years of detailed journal history while the database purges at day 180 create false comfort.
What “retained” must mean
A retained trail should identify the user (or service account), the before/after values for material fields, the timestamp in a clear time zone, and whether an approval step was skipped or overridden. Aggregated counts without user identity rarely satisfy external auditors.
Hong Kong practicality
For groups with regional shared-service centres, confirm whether logs live in the Hong Kong instance or a regional hub — and whether exports can be produced without involving overseas IT queues that miss your close calendar.
If you are unsure whether last year’s overrides still exist in recoverable form, a point-in-time reconstruction will tell you before auditors do.