Data Retention for Upstream Oil & Gas Operators

Featured image for Data Retention for Upstream Oil & Gas Operators

Keep at least six years of records for every Federal and Indian oil and gas lease, and start a records inventory with an immediate audit hold today if any ONRR or BLM review is open or possible. That six-year floor, established by 30 U.S.C. § 1713, is the baseline. Several record types carry shorter or longer statutory periods, and an open audit or investigation suspends the clock entirely until you receive a written release.

The core categories to retain:

  • Drilling records (90 days after operations complete)
  • Pressure and BOP tests, real-time monitoring data (2 years)
  • Completion records (until permanent plugging or assignment to successor)
  • Production measurement and royalty support (6 years minimum; 7 years for Federal leases under BLM)
  • Financial, tax, and cost records (6 years minimum; match to applicable state rule if longer)
  • Environmental and GHG support documentation (6 years minimum)
  • Digital system artifacts: meter/SCADA logs, automated files, processing scripts, and system configuration used to generate any report submitted to ONRR or BLM

If you have not already inventoried your records by well and lease, that is the single action to take this week.

Key Takeaways

Federal retention rules for upstream oil and gas operators set a six-year baseline under ONRR and a seven-year period for Federal leases under BLM, with specific records requiring permanent retention until well disposition and all periods suspended during open audits.

Key Takeaways — overview diagram

Point Details
ONRR/BLM baseline periods ONRR requires 6 years; BLM requires 7 years for Federal leases; both extend until written release during audits.
Record-specific exceptions Drilling records: 90 days. Pressure tests: 2 years. Completion records: until plug or assignment.
Chain-of-custody requirement Retain source measurement data, processing scripts, and system configs alongside final reports.
Audit hold rule An audit or investigation notice suspends the standard clock; hold all affected records until released in writing.
Wellsmanager Links documents to wells at creation, automates holds, and produces per-well export bundles for auditor delivery.

Table of Contents

Quick reference: common upstream record types and retention periods

The table below maps typical record categories to the applicable U.S. retention horizon and the governing rule. Rows marked HOLD require retention beyond the standard period whenever an audit or investigation is open.

Record Type Standard Retention Governing Rule Notes
Drilling records retained for a short period after operations 30 CFR § 250.741 BSEE/OCS; onshore analogs vary
Pressure & BOP tests 2 years 30 CFR § 250.741 Includes real-time monitoring data
Completion records Until plug or assignment 30 CFR § 250.741 Permanent retention until well disposition
Well logs, directional surveys Submit within 30 days; retain 2 years near field 30 CFR § 250.1619 Near-field office copy required
Production measurement & royalty support subject to minimum retention periods by applicable authorities 30 CFR Part 1212; 43 CFR § 3170.7 HOLD if audit open
Financial/royalty computations 6 years 30 U.S.C. § 1713 HOLD until written release
System artifacts (scripts, configs, automated files) Same as the report they support 30 CFR Part 1212 Must be available for inspection
Title, assignment, and lease documents Life of lease + 6 years State/BLM/ONRR Varies by jurisdiction

Key rule: An audit or investigation notice suspends the standard retention clock. Records must be held until ONRR or BLM releases the operator in writing, regardless of whether the standard period has expired.

Which U.S. rules create your retention obligations

Three federal agencies set the primary floor. Knowing which one governs a given record determines how long you keep it and what an auditor can demand.

ONRR / 30 CFR Subpart 1212. The Office of Natural Resources Revenue requires lessees, operators, and revenue payors to maintain records for six years from the date the transaction was recorded. Under 30 U.S.C. § 1713, the Secretary holds broad authority to require records, reports, and information for any Federal or Indian lease. ONRR can inspect records at your business location during normal business hours and must give you a reasonable period to produce historical files. The moment you receive written notice of an audit or investigation, the six-year clock stops and records must be held until you receive a written release.

BLM / 43 CFR 3170.7. For Federal onshore leases, BLM sets a seven-year retention period for records used to determine production quality, quantity, and disposition. Indian lease records follow a six-year period. Combined unit or communitization agreement records may carry different periods depending on the mix of lease types in the unit. BLM also requires that every source record carry the FMP/lease number, unique equipment identifier, and originator company name so auditors can trace data from the field to the royalty computation.

BSEE / 30 CFR Part 250. For offshore and certain onshore operations, BSEE specifies record-by-record retention periods. Drilling records: 90 days. Pressure and BOP tests: 2 years. Completion records: until plugging or assignment. Well logs and directional surveys must be submitted within 30 days of operations and retained at a nearby field office for two years under 30 CFR § 250.1619.

The practical implication: when a single well touches ONRR royalty reporting, BLM production measurement, and BSEE well records, all three agencies can show up. Build your retention schedule around the longest applicable period for each record type.

State and tribal variations you must check before disposal

Federal rules are the floor, not the ceiling. Texas Railroad Commission rules, Louisiana DNR requirements, and tribal regulations from nations such as the Navajo Nation or Osage Nation can impose longer or different retention periods for the same records.

  • When a lease or unit spans Federal, Indian, and state authority, adopt the longest applicable retention period across all jurisdictions and document that decision in writing.
  • Tribal sovereignty means tribal regulations operate independently of BLM and ONRR rules. Coordinate with the relevant tribal agency before disposing of any records tied to Indian leases.
  • State oil and gas commissions in Texas and Louisiana typically require production and financial records for five to seven years, but some categories (title documents, environmental compliance records) run longer.
  • Mixed-jurisdiction units are the highest-risk scenario. A single unit can include Federal, state, and fee acreage, each with a different governing rule.

Pro Tip: Tag every record at creation with a jurisdiction field (Federal, Indian, State, Fee) and the lease/unit ID. When a disposal date is calculated, the system applies the correct rule set automatically rather than relying on someone to remember which rule governs which file.

What actually counts as a “record” in upstream retention

The regulatory definition is broader than most operators expect. Under ONRR’s Subpart 1212, records include source measurement data, meter and tank logs, SCADA outputs, financial reports, computer programs, automated files, and the supporting systems documentation used to produce any report or tape submitted to ONRR. That last category is the one operators most often miss.

A complete audit trail requires:

  • Raw sensor outputs (meter readings, tank gauges, SCADA logs) tied to a specific FMP/lease ID and unique equipment ID
  • Aggregated production reports and the processing scripts or ETL logic that created them
  • Royalty computation files and the source data that fed them
  • Chain-of-custody logs showing who accessed, modified, or exported each file and when
  • System configuration snapshots for any software that generated a submitted report

Auditors will interpret a gap in chain-of-custody as potential non-compliance. If you can produce the final royalty report but not the meter log that underlies it, the audit does not close cleanly. Per 43 CFR § 3170.7, source records must include FMP/lease numbers and unique equipment identifiers so every data point can be traced back to a specific piece of field equipment.

A single-source-of-truth approach that centralizes per-well data makes this traceability practical rather than aspirational.

How to build a defensible retention schedule

  1. Inventory records by well, lease, and FMP. List every record type your operation generates, where it lives (field office, server, cloud, paper), and which well or lease it belongs to. A single well can generate terabytes of sensor data and dozens of document types, each with a different retention obligation.
  2. Map each record to the governing statute and retention period. Use the reference table above as a starting point. Flag records that fall under multiple agencies.
  3. Assign retention metadata and legal-hold flags. Every record needs a retention expiry date, a jurisdiction tag, and a hold status field. Records under an open audit get a hold flag that blocks deletion.
  4. Automate retention and deletion rules. Manual tracking fails at scale. Configure your document management or operations platform to enforce retention periods and send notifications before any record approaches its disposal date.
  5. Test retrieval and run mock audits. Pull a per-well bundle for a randomly selected well and time how long it takes. If it takes more than a few hours, your retrieval process needs work before a real auditor arrives.

Roles matter too. Field staff own the accuracy of source measurement records. Operations and IT own storage, access controls, and system artifact retention. Finance and legal own the hold process and written release tracking.

Pro Tip: Start with the highest-risk records: production measurement files, royalty computations, and title/assignment documents. Get those under a defensible system first, then expand to secondary categories.

Technical requirements for audit-ready records

Every record submitted to or supporting a filing with ONRR or BLM needs a minimum metadata set:

  • FMP/lease ID and well ID
  • Unique equipment ID (specific meter, tank, or SCADA node)
  • Creation timestamp and originator (person or system)
  • Checksum or version hash to detect tampering
  • Retention expiry date and hold status

Beyond metadata, retain the system configuration and processing scripts that generate aggregated reports. If an auditor asks how a monthly production volume was calculated, you need to reproduce the computation from raw inputs, not just show the output. Write-once/read-many (WORM) storage for immutable records, encryption at rest, and access logs covering every read and export are the minimum security controls for records subject to federal inspection. Disaster recovery planning should target a recovery point objective short enough that no more than one day of field data is at risk.

The equipment downtime tracking discipline applies here: operational events need to be preserved and linked to cost and production records so the field-to-finance chain is unbroken.

What to do when an auditor requests records

  1. Acknowledge the request in writing within 24 hours. Confirm receipt, identify the lead custodian, and note the scope of records requested.
  2. Immediately apply a legal hold to all records within the audit scope. Notify IT and field staff to suspend any scheduled deletions.
  3. Identify all custodians who have or had access to the relevant records, including third-party vendors.
  4. Assemble per-well bundles. Group source files, aggregated reports, and chain-of-custody logs by well and lease. Include system export manifests that map each source file to the report it supports.
  5. Deliver records or provide remote access within the timeframe the agency specifies. ONRR and BLM expect records to be available at your business location during normal business hours and will give a reasonable period for historical files, but “reasonable” is not unlimited.

Include a chain-of-custody log, a system export manifest, and a written mapping of source files to reports with every production. That documentation is what separates a clean audit response from one that generates follow-up questions.

Frequent mistakes that create compliance risk

  • Deleting records at the statutory minimum without checking for open audits. The most common and most avoidable error. Always query your hold register before any disposal run.
  • Missing source files. Keeping the royalty report but not the meter log that supports it leaves an unverifiable gap. Retain both raw data and the pipeline that processed it.
  • Inconsistent IDs across systems. When the well ID in your production system does not match the ID in your financial system, auditors cannot trace the data. Standardize identifiers at the point of record creation.
  • Poor vendor data handling. Third-party field service providers often hold measurement data that qualifies as your record. Your contracts should require vendors to retain and deliver that data on request.
  • No litigation-hold process. An informal “we’ll remember to hold it” approach fails when staff turn over. The hold must be systematic and documented.

Short-term fix for each: apply a manual hold immediately and notify all custodians. Long-term fix: assign a named records manager, implement a hold-tracking register, and audit vendor contracts for data delivery obligations. Legal or compliance should own the remediation project, with a 90-day target to close the most critical gaps.

How Wellsmanager addresses retention and audit readiness

Wellsmanager is built around the per-well record structure that federal retention rules require. Key capabilities:

  • Per-well document linkage. Every file, from a meter ticket to a royalty computation, attaches to a specific well and lease record. Pull a complete per-well bundle in minutes rather than hours.
  • Retention metadata and legal-hold automation. Set retention periods by record type and jurisdiction. When an audit notice arrives, trigger a hold that blocks deletion across all affected records automatically.
  • Immutable audit trail. Every access, edit, and export is logged with a timestamp and user ID, giving auditors the chain-of-custody documentation they expect.
  • Compliance notifications. The platform alerts you before a retention period expires or a hold is about to be breached, so disposal decisions are never made by accident.
  • Field-to-finance traceability. The invoice approval workflow and production tracking modules preserve the full data lineage from field measurement through royalty computation.

Pro Tip: Use Wellsmanager’s per-well export feature to run a mock audit quarterly. Select a well, export the full bundle, and verify that every source file maps to its corresponding report. If the bundle has gaps, you find them before an auditor does.

The feature-to-regulation mapping is direct: per-well linkage satisfies BLM’s FMP/lease ID traceability requirement; immutable logs satisfy ONRR’s chain-of-custody expectation; automated holds satisfy the audit-notice extension rule under 30 U.S.C. § 1713.

The compliance habit that actually holds

Retention discipline breaks down at the field level, not the policy level. The operators who stay audit-ready share one habit: they verify incoming records weekly and run a retention audit monthly. Weekly verification catches missing meter tickets and incomplete SCADA exports before they become a six-month gap. Monthly audits catch hold-register mismatches before a disposal run removes something it should not. The cultural shift is simple: treat a missing source file the same way you treat a missing safety inspection. Both are gaps with consequences, and both get fixed before the next review.

Wellsmanager cuts the time from audit notice to record production

Most operators spend days assembling records when an ONRR or BLM request arrives. Wellsmanager changes that to hours. The platform links every document to its well and lease at creation, enforces retention periods automatically, and logs every access for chain-of-custody compliance.

Wellsmanager

When you request access, the demo covers per-well retention mapping, a live legal-hold test, and an export bundle walkthrough so you can see exactly how your records would look to an auditor. Data handling follows the policies outlined at Wellsmanager, and the platform is built for the regulatory environment U.S. upstream operators actually operate in. Visit Wellsmanager to get started.

Sources

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Recommended