Professional Examiners Trained to APA Standards
140+ Professional Testing Locations Across the U.S. & Canada
Trusted by 10,000+ Clients, Attorneys & Organizations
LieDetectorTest.com Private & Confidential Polygraph Provider

Polygraph Examiner Record-Keeping: APA Compliance Guide

Complete guide to polygraph record-keeping: APA retention standards, state requirements, HIPAA compliance for PCSOT, digital security protocols, and destruction procedures.

Published March 26, 2026 Updated July 26, 2026 22 min read All articles

Careful record-keeping protects both examiner and examinee, and this compliance guide covers the documentation standards behind every lie detector test.

A comprehensive resource covering exactly what examination records polygraph examiners must retain, for how long, in what format, and how to securely store and ultimately destroy records according to APA Standards of Practice, state laws, federal requirements, and HIPAA obligations for therapeutic contexts.

3+ YearsAPA Min. Retention
HIPAACompliance Required (PCSOT)
~25 StatesWith Licensing Laws
AES-256Encryption Standard
2,700+APA Members

TL;DR — The Short Version

  • APA Standards of Practice require polygraph examiners to maintain all examination records — including reports, test questions, data, recordings, and documents — for a minimum of three (3) years, or as otherwise required by law.
  • Audio or video recordings of all examination phases must be retained for a minimum of one (1) year as part of the examination file.
  • When polygraph testing occurs in therapeutic contexts (particularly PCSOT), HIPAA requires compliance documentation be retained for at least six years, and state medical record laws may impose even longer periods.
  • Electronic records should be encrypted to AES-256 standards, backed up with redundancy, and protected with role-based access controls and multi-factor authentication.
  • The Employee Polygraph Protection Act (EPPA) independently requires employers and examiners to retain polygraph records for a minimum of three years from the examination date.
  • State licensing board requirements frequently exceed APA minimums — Virginia requires one year, while some states and federal agencies mandate much longer retention periods. Always comply with the most stringent applicable requirement.

Who This Guide Is For

  • Licensed polygraph examiners maintaining examination archives
  • PCSOT examiners working within sex offender treatment teams who handle sensitive therapeutic records
  • Polygraph practice owners and administrators responsible for compliance infrastructure
  • New examiners building their record-keeping systems from the ground up
  • Quality assurance directors at polygraph firms conducting internal audits
  • Attorneys advising polygraph examiners on retention obligations
  • Continuing education providers developing compliance training curricula

Why Record-Keeping Matters for Polygraph Examiners

Professional Accountability and Legal Protection

Record-keeping is the bedrock of professional accountability, legal protection, and scientific defensibility for polygraph examiners. Every polygraph examination generates evidence that may later be scrutinized by courts, licensing boards, quality assurance reviewers, appellate attorneys, or treatment teams. Without complete, organized, and properly secured records, an examiner's work product is effectively unverifiable.

The American Polygraph Association (APA), established in 1966, has progressively strengthened its record-keeping requirements, recognizing that the credibility of the profession depends on transparent, auditable documentation practices Verified State Regulations and Their Influence on Polygraph Licensing
Confirms approximately 25 states have specific licensing requirements for polygraph examiners per APA survey
, each with its own record-keeping obligations. These frameworks do not always align.

An examiner conducting pre-employment testing for a federal agency faces different requirements than one performing PCSOT examinations for a treatment provider, even though the core APA standards apply to both. This guide addresses the full lifecycle of polygraph examination records: what must be created, what must be retained, how it must be stored and secured, how long it must be kept, and how it must ultimately be destroyed.

APA Standards of Practice: Record-Keeping Requirements

The APA Framework

The APA Standards of Practice (SOP) serve as the foundational record-keeping framework for polygraph examiners worldwide. The current Standards of Practice, effective August 23, 2024, require all examinations to be conducted in compliance with governing local, state, and federal regulations and laws Verified Florida Polygraph Licensing - Chapter 493
Confirms Florida licenses polygraph examiners and the FPA offers professional certifications
. Examiners must undergo training and adhere to ethical standards. The state's general records schedules establish minimum retention periods for criminal justice agencies.

California: Multiple authoritative sources confirm that California does not require polygraph examiners to obtain a state license [22]Verified State-by-State Breakdown of Polygraph Licensing Requirements
Confirms California does not require polygraph examiners to obtain a state license
[23]Verified State-by-State Polygraph Rules in the US
Confirms California does not require state polygraph license; New Mexico Private Investigations Board licenses polygraphers
. The California Association of Polygraph Examiners (CAPE) maintains professional standards for its members on a voluntary basis, and APA standards serve as the primary governance framework for member examiners.

New Mexico: The New Mexico Private Investigations Advisory Board is responsible for licensing all polygraph examiners within the state [24]Verified New Mexico Administrative Code 16.48.6.8 - Continuing Education
Confirms New Mexico polygraph licensees must complete 10 hours of continuing education per year
. Polygraph licensees must complete a minimum of 10 hours of continuing education credit per year [25]Verified DCMA Manual 4501-04 Volume 2: Records Retention Schedule
Confirms DoD investigation records including polygraph tests may require 25-year retention after case closure
.

Examiners who operate across multiple state jurisdictions face the most complex compliance landscape. The safest approach is to identify the longest applicable retention period across all jurisdictions where the examiner is licensed or practices and apply that universally to all records. For a comprehensive overview of career requirements, see our Polygraph Examiner Career Path guide.

Federal Agency and Contract Requirements

Examiners working under federal contracts or for federal agencies face retention requirements that are often significantly longer than APA minimums. Department of Defense investigation records, including polygraph tests, may be subject to NARA-approved retention schedules requiring destruction 25 years after report/case closure, or later if still considered relevant [26]Verified DoDI 5210.91 - Polygraph and Credibility Assessment Programs
Confirms DoD Instruction governing polygraph and credibility assessment programs, quality control, and record retention
. DoD Instruction 5210.91 governs Polygraph and Credibility Assessment programs, requiring comprehensive quality control processes and record retention in accordance with component reporting requirements [27]Verified Employee Polygraph Protection Act - APA Summary
Confirms EPPA requires 3-year record retention for all polygraph examination records
.

The Employee Polygraph Protection Act (EPPA), enacted December 27, 1988, independently requires employers and polygraph examiners to retain required records for a minimum of three years from the date the polygraph examination is conducted, or from the date the examination is requested if no examination was conducted [3]Verified Employee Polygraph Protection Act (EPPA) - Employment Law Guide
Confirms EPPA requires 3-year record retention from date of polygraph examination or request
[28]Verified Lafayette Instrument Acquires Limestone Technologies
Confirms Lafayette Instrument Company acquired Limestone Technologies in August 2022
. This federal baseline applies to all EPPA-governed examinations regardless of state requirements.

For examiners performing examinations under federal sex offender management frameworks, retention requirements may be tied to the offender's supervision period, which can be indefinite in some cases. The DoD Polygraph Institute history provides context for the evolution of federal polygraph program requirements.

PCSOT-Specific Retention Considerations

PCSOT records present unique retention challenges because the testing relationship may extend over many years. The current best practice recommendation for PCSOT records is to retain all examination files for the longer of:

The APA or state minimum retention period. The duration of the offender's supervision period plus additional years. Any period specified in the treatment provider contract or court order.

Given that sex offender supervision can extend for life in some jurisdictions, this can effectively create indefinite retention obligations. Examiners should plan their storage infrastructure accordingly and factor long-term storage costs into their fee structures.

Storage Formats: Paper, Digital, and Hybrid Systems

The Shift to Digital

The polygraph profession has undergone a major transition from paper-based to digital record-keeping. Modern polygraph instruments — such as Limestone's ParagonX system, which delivers 625 samples per second per channel [29]Verified NIST SP 800-88 Rev. 1 - Guidelines for Media Sanitization
Confirms NIST SP 800-88 provides authoritative guidance for media sanitization with Clear, Purge, and Destroy methods
— produce digital chart data natively, and most contemporary practice management involves digital report generation, electronic communication, and cloud-based storage. Understanding polygraph system lifespan is critical for format obsolescence planning.

The APA does not mandate a specific storage format. Both paper and digital records are acceptable, provided they satisfy the core requirements of completeness, accuracy, accessibility, and security. However, the practical advantages of digital systems — searchability, space efficiency, backup capability, encryption options, and remote accessibility — make them the overwhelming choice for contemporary practices.

Digital Storage Platform Requirements

When selecting a digital storage platform for polygraph examination records, examiners should evaluate candidates against these requirements:

Encryption at rest: All stored data must be encrypted using AES-256 or equivalent standards. If the physical storage medium is compromised, the data remains unreadable without the encryption key.

Encryption in transit: Data moving between systems must be encrypted using TLS 1.2 or higher to prevent interception during upload, download, or synchronization.

Access controls: The platform must support role-based access controls restricting who can view, modify, or delete records. Multi-factor authentication (MFA) should be required for all users.

Audit logging: Every access to, modification of, or deletion of records must be logged with timestamps and user identification. These logs must be immutable and retained for the full record retention period.

Backup and redundancy: The platform must maintain geographically distributed backups protecting against catastrophic data loss from equipment failure, natural disaster, or cyberattack.

Data sovereignty: For HIPAA-covered records, data must be stored within the United States unless explicit authorization for foreign storage exists.

Export capability: The platform must allow complete data export in standard formats to prevent vendor lock-in and enable migration.

HIPAA-compliant storage platforms that meet these criteria include certain tiers of Microsoft 365, Google Workspace (with BAA), and Amazon Web Services (with appropriate configuration). Free consumer cloud services (standard Google Drive, Dropbox Basic, iCloud) do not meet these requirements and must not be used for examination records.

HIPAA Considerations for Therapeutic Contexts (PCSOT)

When HIPAA Applies to Polygraph Examiners

When polygraph testing is conducted as part of therapeutic treatment — particularly PCSOT — examiners may be considered covered entities or business associates under HIPAA, requiring additional safeguards. The HIPAA Privacy Rule does not itself establish medical record retention periods; rather, state laws generally govern how long medical records are retained [2]Verified HIPAA Retention Requirements
Confirms HIPAA requires 6-year retention for compliance documentation; HIPAA Privacy Rule does not mandate medical record retention periods
. However, HIPAA does require that all compliance-related documentation be retained for a minimum of six years from the date of creation or from the date the document was last in effect, whichever is later [2]Verified HIPAA Retention Requirements
Confirms HIPAA requires 6-year retention for compliance documentation; HIPAA Privacy Rule does not mandate medical record retention periods
.

This six-year requirement applies to privacy and security policies, business associate agreements, risk analyses, training records, sanctions documentation, breach notification records, and patient authorization forms [2]Verified HIPAA Retention Requirements
Confirms HIPAA requires 6-year retention for compliance documentation; HIPAA Privacy Rule does not mandate medical record retention periods
. For PCSOT examiners operating as business associates under a treatment provider's umbrella, this means that HIPAA documentation obligations often exceed both APA and state polygraph record retention minimums.

Examiners should execute Business Associate Agreements (BAAs) with any treatment providers or agencies that share protected health information (PHI). The BAA should specify record-keeping responsibilities, breach notification procedures, and data return or destruction obligations upon termination of the agreement.

Security Requirements and Encryption Standards

Physical Security for Paper Records

Examiners maintaining paper records must implement physical security measures that prevent unauthorized access. At minimum, this requires locked filing cabinets rated for security storage (not standard office furniture), restricted access to the storage area with documented access permissions, fireproof and water-resistant storage containers (especially for original documents that cannot be recreated), and an access log documenting who accessed the records storage area and when.

Digital Security Architecture

Digital record security requires a multi-layered approach addressing storage, transmission, access, and endpoint security. Storage encryption should use full-disk encryption on all devices. Transmission encryption should use TLS 1.2 or higher for all data in transit. Access must be controlled through multi-factor authentication, and all access events must be logged.

For examinations involving forensic standards, additional chain-of-custody documentation for digital evidence may be required. Password policies should require strong, unique passwords with regular rotation, and endpoint protection should include up-to-date antivirus, anti-malware, and firewall software on all devices that access examination records.

Secure Record Destruction Protocols

When and How to Destroy Records

Records cannot simply be deleted or discarded. APA standards and state laws require documented, verifiable destruction methods. Before destroying any records, the examiner must verify that all applicable retention periods have expired, confirm no pending litigation holds or legal proceedings require record preservation, and document the destruction in a permanent log.

For paper records: Cross-cut shredding (not strip-cut) to a particle size of 2mm x 15mm or smaller is the recommended method. Alternatively, incineration by a certified document destruction service may be used. All destruction must be documented with dates, methods, and the identity of the person performing the destruction.

For electronic records: NIST Special Publication 800-88 provides the authoritative guidance for media sanitization. Originally published in 2006 and revised in December 2014 as Rev. 1, NIST SP 800-88 was superseded by Rev. 2 in September 2025 [30]Verified NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization
Confirms NIST SP 800-88 Rev. 2 superseded Rev. 1 effective September 26, 2025
[31]Verified NIST 800-88 vs DoD 5220.22-M Comparison
Confirms DoD 5220.22-M has not been updated recently and does not apply to modern technologies like SSDs; NIST 800-88 is the current standard
. The guidelines define three categories of sanitization: Clear, Purge, and Destroy [30]Verified NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization
Confirms NIST SP 800-88 Rev. 2 superseded Rev. 1 effective September 26, 2025
. For modern hard drives and SSDs, a single overwrite using the Clear method is generally sufficient to render data unrecoverable, and NIST has de-emphasized the older DoD 5220.22-M multi-pass overwriting standard, which has not been updated for modern storage technologies [32]Verified EDA Primer for Polygraph Examiners
Foundational research relevant to polygraph data recording and retention - electrodermal response is the most robust signal in polygraph testing
.

NIST SP 800-88 covers all kinds of storage media, including hard drives, solid state drives, optical discs, flash memory, and paper media [30]Verified NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization
Confirms NIST SP 800-88 Rev. 2 superseded Rev. 1 effective September 26, 2025
. For solid-state drives (SSDs), manufacturer-specific Secure Erase or cryptographic erase commands are recommended over simple overwriting due to wear-leveling algorithms.

All electronic destruction must be verified and documented with certificates of destruction.

Audit Readiness and Self-Assessment

Building a Compliance Infrastructure

Proactive compliance management is far less costly than reactive remediation. Examiners should conduct periodic self-assessments of their record-keeping practices, ideally at least annually. Key areas to evaluate include:

Completeness: Are all required file components present for every examination? Retention compliance: Are records being retained for the longest applicable period? Security: Are physical and digital security measures functioning properly? Access controls: Are only authorized personnel accessing records? Backup verification: Are backups current and restorable? Destruction documentation: Are expired records being destroyed according to protocol with proper documentation?

Maintaining a written record-keeping policy that addresses all of these areas — and training all staff on its requirements — provides the foundation for audit readiness. For firms conducting corporate fraud investigations, demonstrating robust record-keeping practices enhances the credibility and admissibility of examination results.

Common Record-Keeping Violations and How to Avoid Them

Pitfalls and Prevention

The most common record-keeping violations observed in quality assurance reviews and disciplinary proceedings include:

Incomplete files: Missing consent forms, incomplete question lists, or absent scoring sheets. Prevention: Use a standardized checklist for every examination file.

Inadequate retention: Destroying records before the applicable retention period expires. Prevention: Implement a calendar-based retention tracking system that accounts for the longest applicable period.

Insecure storage: Using unencrypted cloud storage, leaving paper files in unsecured areas, or failing to implement access controls. Prevention: Conduct annual security audits of all storage systems.

Format obsolescence: Storing digital records in proprietary formats that become unreadable when software is discontinued. Prevention: Maintain current software licenses, periodically verify file accessibility, and keep export copies in widely-supported formats.

Failure to document destruction: Destroying records without maintaining a destruction log. Prevention: Maintain a permanent destruction register that is never itself destroyed.

Inadequate post-test documentation: Failing to contemporaneously document admissions or disclosures made during post-test interviews. Prevention: Record all phases of the examination as recommended by APA standards [1]Verified APA Standards of Practice (Effective August 23, 2024)
Confirms current APA Standards of Practice including 3-year minimum record retention (Section 1.7.9.1) and 1-year minimum for audio/video recordings (Section 1.7.5/1.7.9.2)
.

For examiners concerned about meeting the required standards, pursuing additional polygraph training focused on documentation and compliance best practices is strongly recommended. Research consistently shows that proper training directly impacts examiner proficiency and examination quality [17]Verified Main Features of Polygraph Examiners Training
Identifies core elements essential for effective polygraph examiner training programs including documentation requirements
[18]Verified Federal Psychophysiological Detection of Deception Examiner Handbook
Official policy manual for all federal polygraph programs covering standardized testing procedures, scoring methods, and quality assurance requirements
.

Frequently Asked Questions

How long must polygraph examiners retain examination records under APA Standards?

The current APA Standards of Practice (effective August 23, 2024) require that polygraph examiners maintain all polygraph reports, test questions, data, recordings, information, and documents related to the examination for a minimum of three (3) years, or as otherwise required by law [1]Verified APA Standards of Practice (Effective August 23, 2024)
Confirms current APA Standards of Practice including 3-year minimum record retention (Section 1.7.9.1) and 1-year minimum for audio/video recordings (Section 1.7.5/1.7.9.2)
. Audio or video recordings must be retained for a minimum of one (1) year [1]Verified APA Standards of Practice (Effective August 23, 2024)
Confirms current APA Standards of Practice including 3-year minimum record retention (Section 1.7.9.1) and 1-year minimum for audio/video recordings (Section 1.7.5/1.7.9.2)
. However, state laws, federal contracts, and HIPAA obligations may require significantly longer retention periods, and examiners must always comply with the most stringent applicable requirement.

Does the Employee Polygraph Protection Act (EPPA) have its own record retention requirements?

Yes. Under the EPPA, employers and polygraph examiners must retain required records for a minimum of three years from the date the polygraph examination is conducted, or from the date it was requested if no examination was conducted [3]Verified Employee Polygraph Protection Act (EPPA) - Employment Law Guide
Confirms EPPA requires 3-year record retention from date of polygraph examination or request
[28]Verified Lafayette Instrument Acquires Limestone Technologies
Confirms Lafayette Instrument Company acquired Limestone Technologies in August 2022
. This federal requirement applies independently of APA or state requirements and covers all opinions, reports, charts, written questions, and other records relating to polygraph tests administered under EPPA exemptions.

What additional record-keeping requirements apply to PCSOT examinations?

PCSOT examinations require additional documentation including supervision or probation conditions authorizing testing, treatment provider referral forms, specific PCSOT informed consent documents, pre-test coordination documentation with the treatment team, sexual history disclosure documents, and restricted report distribution records. When PCSOT falls under HIPAA, compliance documentation must be retained for at least six years [2]Verified HIPAA Retention Requirements
Confirms HIPAA requires 6-year retention for compliance documentation; HIPAA Privacy Rule does not mandate medical record retention periods
. Best practice is to retain PCSOT records for the duration of the offender's supervision period plus additional years.

Does HIPAA require polygraph examiners to retain records for a specific period?

HIPAA does not establish medical record retention periods — state laws govern those [2]Verified HIPAA Retention Requirements
Confirms HIPAA requires 6-year retention for compliance documentation; HIPAA Privacy Rule does not mandate medical record retention periods
. However, HIPAA does require that all compliance-related documentation (policies, procedures, risk analyses, training records, business associate agreements, and breach notifications) be retained for a minimum of six years from creation or from when last in effect, whichever is later [2]Verified HIPAA Retention Requirements
Confirms HIPAA requires 6-year retention for compliance documentation; HIPAA Privacy Rule does not mandate medical record retention periods
. PCSOT examiners who function as business associates must comply with these requirements.

What encryption standards should be used for digital polygraph records?

Electronic polygraph records should be encrypted using AES-256 or equivalent encryption standards for data at rest. Data in transit should be protected using TLS 1.2 or higher. Storage platforms must support role-based access controls, multi-factor authentication, immutable audit logging, and geographically distributed backups. Free consumer cloud services do not meet these requirements and should not be used for examination records.

How should polygraph records be destroyed when the retention period expires?

Paper records should be cross-cut shredded to a particle size of 2mm x 15mm or smaller, or incinerated by a certified destruction service. Electronic records should be sanitized following NIST SP 800-88 guidelines, which define Clear, Purge, and Destroy methods depending on media type and data sensitivity [30]Verified NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization
Confirms NIST SP 800-88 Rev. 2 superseded Rev. 1 effective September 26, 2025
. NIST SP 800-88 has been updated to Rev. 2 (September 2025) [31]Verified NIST 800-88 vs DoD 5220.22-M Comparison
Confirms DoD 5220.22-M has not been updated recently and does not apply to modern technologies like SSDs; NIST 800-88 is the current standard
. For modern hard drives, a single-pass overwrite is generally sufficient. For SSDs, manufacturer-specific Secure Erase or cryptographic erase commands are recommended. All destruction must be documented in a permanent destruction log.

What are the record retention requirements in Virginia for polygraph examiners?

Under Virginia Administrative Code 18VAC120-30-250, polygraph examiners must maintain for a period of one year from the date of each administered polygraph examination a complete and legible copy of all documents relating to the examination, including examination questions, results, conclusions drawn, and written or electronic reports [4]Verified Virginia Administrative Code 18VAC120-30-250 - Maintenance of License
Confirms Virginia requires 1-year record retention for polygraph examination documents under 18VAC120-30-250
. Federal contracts or court orders may require longer retention. All recordings must be made available to the department, the examinee, or the examinee's attorney upon request.

What records should be included in a compliant polygraph examination file?

A compliant file must include: pre-test documentation (informed consent, rights advisements, referral letters), complete test question documentation for each chart, all physiological data (charts) in native digital format, numerical scoring sheets identifying the methodology used, the final examination report, post-test documentation including any admissions, audio/video recordings of all examination phases, and administrative records such as fee agreements and correspondence. For PCSOT cases, additional documentation regarding supervision conditions and treatment team coordination is required.

Sources & References

1

Confirms current APA Standards of Practice including 3-year minimum record retention (Section 1.7.9.1) and 1-year minimum for audio/video recordings (Section 1.7.5/1.7.9.2)

2
HIPAA Retention Requirements
HIPAA Journal (2026) — HIPAA Journal
Verified

Confirms HIPAA requires 6-year retention for compliance documentation; HIPAA Privacy Rule does not mandate medical record retention periods

3

Confirms EPPA requires 3-year record retention from date of polygraph examination or request

4

Confirms Virginia requires 1-year record retention for polygraph examination documents under 18VAC120-30-250

5

Confirms APA established 1966, 2,700+ members, promotes highest professional standards

6

Confirms APA established 1966, approximately 2,800 members, establishes minimum standards for education and training

7

Confirms Fleiss kappa of.61 for inter-rater agreement and 95.4% mean decision agreement for ESS scoring

8

Foundational reliability study demonstrating high inter-rater reliability for experienced examiners using structured scoring methods

10

Confirms Donald Krapohl served as APA President in 2006, authored 100+ publications, was Editor-in-Chief for APA publications

11

Confirms APA Board approval of amended Standards of Practice in 2007 under Krapohl's presidency

12

Demonstrates that interrogative examiner approaches compromise polygraph validity, supporting the importance of proper documentation practices

13
Limestone Technologies - About Us
Limestone Technologies (2024) — Limestone Technologies
Verified

Confirms Limestone Technologies Inc. is a subsidiary of Lafayette Instrument Company, a polygraph instrument manufacturer

14

Confirms Lafayette is world's leading manufacturer of polygraph instrumentation with 70+ years experience

15
The Accuracy and Consistency of Polygraph Examiners' Diagnoses
Frank Hunter, Philip Ash (1973) — Journal of Police Science and Administration
Verified

Confirms examiner accuracy of 92.4% for deceptive and 95.5% for truthful subjects using structured scoring methods

16

Confirms Polygraph Professional Suite is a real software product by Limestone Technologies/Lafayette for conducting and analyzing polygraph examinations

17

Identifies core elements essential for effective polygraph examiner training programs including documentation requirements

18

Official policy manual for all federal polygraph programs covering standardized testing procedures, scoring methods, and quality assurance requirements

19
Texas Department of Licensing and Regulation - Polygraph Examiners
Texas TDLR (2024) — Texas Department of Licensing and Regulation
Verified

Confirms TDLR regulates polygraph examiners in Texas including 400-hour training requirement

20
Virginia Polygraph Examiners Advisory Board
Virginia DPOR (2024) — Virginia Department of Professional and Occupational Regulation
Verified

Confirms Virginia DPOR administers polygraph examiner licensing through the Polygraph Examiners Advisory Board

22

Confirms California does not require polygraph examiners to obtain a state license

23
State-by-State Polygraph Rules in the US
British Polygraph Society (2025) — British Polygraph Society
Verified

Confirms California does not require state polygraph license; New Mexico Private Investigations Board licenses polygraphers

24

Confirms New Mexico polygraph licensees must complete 10 hours of continuing education per year

25

Confirms DoD investigation records including polygraph tests may require 25-year retention after case closure

26

Confirms DoD Instruction governing polygraph and credibility assessment programs, quality control, and record retention

27

Confirms EPPA requires 3-year record retention for all polygraph examination records

28

Confirms Lafayette Instrument Company acquired Limestone Technologies in August 2022

29

Confirms NIST SP 800-88 provides authoritative guidance for media sanitization with Clear, Purge, and Destroy methods

30

Confirms NIST SP 800-88 Rev. 2 superseded Rev. 1 effective September 26, 2025

31

Confirms DoD 5220.22-M has not been updated recently and does not apply to modern technologies like SSDs; NIST 800-88 is the current standard

32

Foundational research relevant to polygraph data recording and retention - electrodermal response is the most robust signal in polygraph testing

33
A Validation Study of Polygraph Examiner Judgments
Philip J. Bersh (1969) — Journal of Applied Psychology
Verified

Pioneering field validity study finding 92% agreement between polygraph results and panel verdicts

34

Found electrodermal measures provided the most diagnostic information, supporting multi-channel recording requirements

35

Addresses ethical and documentation considerations for polygraph testing in international contexts

Need to book now? Our online booking system is open 24/7. Speak directly with our team about your test or booking.