# Audit & Evidence File Builder

An audit file should connect each legal or operational claim to the exact evidence that supports it: registrations, representation, PRO participation, packaging facts, classifications, reports, payments, marketplace outcomes, technical documentation and correspondence. The file must also preserve dates, versions, provenance, integrity fingerprints and the rule that controls retention.

> Generated ≠ submitted ≠ accepted ≠ audit passed ≠ legally archived.

Canonical: https://beyogluprofessional.com/templates/audit-evidence-retention

## Legal control layer

Under Regulation (EU) 2025/40, PPWR technical documentation and the EU Declaration of Conformity are retained for five years for single-use packaging and ten years for reusable packaging from placing on the market.

The PPWR ten-day response logic is limited to the relevant reasoned national-authority technical-document request route. It is not a universal deadline for EPR authority, PRO, tax or marketplace audits.

National EPR, PRO, tax, accounting and contractual retention periods are record-specific. This engine leaves a duration unresolved when no verified rule has been stored.

SHA-256 can show whether retained bytes changed. It does not establish the issuer, legal authenticity, submission, acceptance or qualified electronic archiving.

Official EU source: https://eur-lex.europa.eu/eli/reg/2025/40/oj

EU27 country contexts: 27/27
Safety boundaries: generated-not-submitted, response-package-not-authority-accepted, retention-expiry-not-deletion-authorisation, sha256-integrity-not-authenticity, browser-local-not-qualified-legal-archive, marketplace-pro-audit-not-generic-ppwr-ten-day-rule

## How it works

1. **Set the audit scope** — Choose legal entity, Producer, country and reporting period.
2. **Register evidence** — Add the actual files and record issuer, dates, references and claims.
3. **Build lineage** — Preserve supersession and the upstream engine that produced or sourced each record.
4. **Apply retention** — Calculate PPWR 5/10-year rules only where applicable; keep unverified national periods unresolved.
5. **Verify integrity** — Fingerprint retained bytes and separately assess provenance and issuer evidence.
6. **Record the request** — Capture the requesting body, legal route, reference, claims, period and controlling deadline.
7. **Detect gaps** — Find missing files, hashes, provenance, unresolved retention and quantity conflicts.
8. **Apply holds** — Block deletion review for investigations, disputes, corrections or other preservation needs.
9. **Generate the response** — Create an evidence register or a minimized request-specific response package.

## Natural questions

### How long must PPWR records be kept?
For PPWR technical documentation and the EU Declaration of Conformity, Regulation (EU) 2025/40 uses five years for single-use packaging and ten years for reusable packaging from placing on the market. Other EPR, tax, PRO and commercial records may follow different rules.

### Does the five-year PPWR rule apply to every EPR invoice and declaration?
No. The PPWR technical-document retention rule must not be generalized to unrelated national EPR, PRO, tax or accounting records.

### Do I have ten days to answer every EPR audit?
No. The ten-day PPWR logic belongs to the relevant reasoned national-authority technical-document request route. Other requests use their own controlling deadline.

### Does SHA-256 prove a document is authentic?
No. It proves integrity of the retained bytes when compared with the recorded fingerprint. Authenticity and issuer provenance require separate evidence.

### Can I delete evidence when the calculated retention period expires?
Not automatically. Expiry only triggers human review. Open audits, holds, corrections, unresolved rules and other obligations may still require preservation.

### What should an EPR audit file contain?
It should link each claim to its supporting registration, representation, PRO, packaging, reporting, payment, technical and correspondence evidence, with dates, versions and provenance.

### Should I send my entire archive to an authority or PRO?
Normally the response should be scoped to what was actually requested. The engine distinguishes responsive, supporting, potentially irrelevant and sensitive-review evidence.

### What happens after a corrected declaration?
The superseded declaration should remain linked to its replacement so the historical evidence chain explains what was filed, corrected and relied on at each point in time.

### Does a generated Audit Response ZIP mean the authority accepted my response?
No. Package generation is only preparation. Submission and acceptance require real external evidence.

### Is this browser archive a legally qualified electronic archive?
No. The public engine is a browser-local evidence management utility. It does not claim WORM, qualified trust-service or legally certified archive status.
