This is considered a major change against IAF-1400 SAC v3.0, not errata and will need to be addressed in the next document revision.
Potentially move the retention requirement to more reasonable in SAC core - but ensure that it's covered aligned to NIST requirement in US Federal Additional Criteria. (Part of which set of changes?)
(See http://kantarainitiative.org/pipermail/wg-idassurance/2012-August/001326.html for thread of email discussion)