Skip to main content
Category: Information Governance Principles

Generally Accepted Recordkeeping Principles

Also known as: GARP, The Principles, Generally Accepted Recordkeeping Principles (The Principles)
Simply put

The Generally Accepted Recordkeeping Principles, often referred to as The Principles, is a framework developed by ARMA International that describes the qualities of a sound recordkeeping program. It sets out a set of guiding principles intended to help organizations manage their records to support both current and future business needs. Rather than prescribing specific technical steps, it offers a high-level standard for how records should be created, organized, secured, maintained, and used.

Formal definition

Generally Accepted Recordkeeping Principles (GARP), promoted by ARMA International as a widely leveraged global framework, articulates a set of principles identifying the hallmarks of an effective records and information governance program. The framework is commonly described in terms of principles including Accountability, Transparency, Integrity, Protection, Compliance, Availability, Retention, and Disposition, which collectively address how records must be created, organized, secured, maintained, and used across their lifecycle. It functions as a maturity-oriented reference model for evaluating and improving recordkeeping practices rather than as a certifiable technical specification; organizations typically apply it alongside, not in place of, jurisdiction- and sector-specific legal, regulatory, and standards requirements. Note that the precise number, naming, and current wording of the individual principles may vary by publication version, and details beyond the evidence provided here should be confirmed against ARMA source material.

Why it matters

Many recordkeeping programs develop unevenly, with strong practices in some areas, such as retention scheduling, and weaker practices in others, such as accountability or transparency. The Generally Accepted Recordkeeping Principles offer organizations a common, high-level vocabulary for describing what a sound recordkeeping program should look like, which helps records managers, compliance leads, and executives discuss program quality in consistent terms rather than relying on ad hoc or purely local definitions. Because the framework addresses the full span of concerns, from accountability and transparency through integrity, protection, compliance, availability, retention, and disposition, it can surface gaps that a narrower, purely operational view might miss.

The framework's value lies partly in its principle-based rather than prescriptive character. It describes the qualities of good recordkeeping without dictating specific technologies or procedures, which makes it applicable across sectors and organizational sizes. This generality is also a limitation to keep in mind: the framework is a reference model for evaluating and improving practices, not a certifiable technical specification, and it does not by itself satisfy jurisdiction- or sector-specific legal, regulatory, or standards obligations. Organizations typically apply it alongside those requirements rather than as a substitute for them.

Professionals should also treat the specific enumeration of principles with appropriate caution. The framework is commonly described in terms of principles such as Accountability, Transparency, Integrity, Protection, Compliance, Availability, Retention, and Disposition, but the precise number, naming, and current wording can vary by publication version. Where exact wording matters, such as in policy documents or audit criteria, the current ARMA International source material should be consulted directly.

Who it's relevant to

Records and Information Managers
Records managers can use the framework as a common reference for assessing the overall quality of a recordkeeping program and for communicating strengths and gaps in consistent terms. Because it spans the lifecycle from creation through retention and disposition, it helps ensure that program reviews consider accountability and transparency alongside more operational concerns.
Information Governance Leads
For those responsible for the broader accountability framework, the principles offer a structured way to evaluate how recordkeeping practices align with governance goals across areas such as protection, compliance, and availability. They can serve as a high-level benchmark, understanding that the framework complements rather than replaces jurisdiction- and sector-specific obligations.
Compliance and Audit Professionals
Compliance leads and auditors may use the principles as an evaluative reference model when reviewing a program's maturity. Because the framework is not a certifiable specification and its wording can vary by version, audit criteria drawn from it should be tied to current ARMA source material and supplemented with the specific legal and regulatory requirements that apply to the organization.
Executives and Program Sponsors
Executives sponsoring records and information governance initiatives can use the framework's principle-based language to understand and discuss program quality at a strategic level without needing to engage with detailed technical procedures, helping frame investment and improvement decisions around recognized qualities of sound recordkeeping.

Inside GARP

Principle of Accountability
The expectation that an organization assigns responsibility for its recordkeeping program to a senior individual or role, supported by governance oversight and documented policies. This principle emphasizes that someone must own the program and answer for its effectiveness, rather than treating recordkeeping as an unassigned or purely operational task.
Principle of Integrity
The expectation that records and the systems managing them are trustworthy, such that the authenticity and reliability of records can be reasonably assured. Integrity here concerns the ability to demonstrate that a record is what it purports to be and has not been improperly altered, though the specific controls used depend on organizational policy and risk.
Principle of Protection
The expectation that records are protected in a manner appropriate to their sensitivity, including considerations of privacy, confidentiality, and security. The degree and nature of protection typically vary with the record's content and applicable obligations, which differ across jurisdictions and sectors.
Principle of Compliance
The expectation that the recordkeeping program conforms to applicable laws, regulations, and the organization's own policies. Because statutory and regulatory requirements vary by jurisdiction and industry, compliance is assessed against the specific obligations that apply to a given organization rather than a universal standard.
Principle of Availability
The expectation that records can be located and retrieved in a timely and efficient manner when needed for business, legal, or other purposes. Availability concerns usability and accessibility over time, distinct from mere storage or retention.
Principle of Retention
The expectation that records are kept for an appropriate length of time, reflecting legal, regulatory, fiscal, operational, and historical requirements. Retention as addressed here concerns duration and justification; the specific periods depend on jurisdiction, sector, and organizational policy.
Principle of Disposition
The expectation that records are given secure and appropriate final disposition once their retention requirements are satisfied. Disposition is a broader concept than destruction and may include secure destruction, transfer of custody, or preservation, depending on the record's value and applicable requirements.
Principle of Transparency
The expectation that the organization's recordkeeping processes and activities are documented in a way that is understandable and available to appropriate personnel and, where relevant, to auditors or oversight bodies. Transparency supports the demonstrability of the other principles.
Maturity model orientation
GARP is commonly associated with a maturity-model approach that allows organizations to assess how well each principle is implemented, typically along a graduated scale. This is intended as a self-assessment and improvement framework rather than a certifiable compliance standard.

Common questions

Answers to the questions practitioners most commonly ask about GARP.

Are the Generally Accepted Recordkeeping Principles a formal standard like ISO 15489 that can be certified against?
No. GARP is generally understood as a set of high-level principles articulating what sound recordkeeping should achieve, rather than a formal, certifiable standard in the manner of the ISO recordkeeping standards. It is more accurately described as a framework of guiding principles used to assess and communicate the qualities of good recordkeeping. Organizations may reference GARP alongside standards such as ISO 15489 or ISO 30301, but the principles themselves are typically not treated as a specification against which formal certification is granted. Where certification or conformity assessment is required, professionals would usually look to the relevant ISO or sector-specific standards rather than to GARP.
Does adopting GARP by itself make an organization legally compliant with its retention and disposition obligations?
Not on its own. GARP describes general principles intended to promote defensible recordkeeping, but legal and regulatory obligations relating to retention, disposition, privacy, and disclosure depend on jurisdiction and sector. Aligning practices with GARP may support a defensible position, yet it does not substitute for identifying and meeting the specific statutory, regulatory, and contractual requirements that apply to a given organization. Compliance typically requires mapping applicable obligations in the relevant jurisdictions and reflecting them in retention schedules and policies, with GARP serving as a framing tool rather than a source of legal requirements.
How can an organization use GARP to assess the maturity of its recordkeeping program?
GARP is often used as a lens for evaluating current practice against a set of desirable qualities, and it is commonly paired with a maturity model that describes levels of capability from ad hoc through to more systematic or optimized states. In practice, an organization might review each principle in turn, gather evidence of how it is currently addressed, and place its practices at a maturity level. This assessment can help identify gaps and prioritize improvements. The approach depends on organizational context, and results are generally most useful when treated as a qualitative diagnostic rather than a precise score.
Which roles should be involved in applying GARP within an organization?
Because the principles span accountability, transparency, integrity, protection, compliance, availability, retention, and disposition, applying them typically involves collaboration across several functions. Records managers and information governance officers often coordinate the effort, working with legal or compliance staff on regulatory and retention questions, with privacy and security professionals on protection, and with IT on systems that create and maintain records. Senior accountability is generally important given the emphasis on governance and oversight. The precise division of responsibilities depends on organizational structure and existing governance arrangements.
How do the GARP principles relate to the records lifecycle in day-to-day operations?
The principles touch on qualities relevant across the lifecycle, from creation and capture through classification, retention, and disposition. In operational terms, principles concerning integrity and protection tend to bear on how records are captured and maintained so that authenticity and reliability are preserved, while principles addressing retention and disposition inform how long records are kept and how they are transferred, preserved, or destroyed at the end of their retention. It is worth noting that disposition under these principles is not limited to destruction, since it may include transfer or permanent preservation depending on the record and applicable policy.
How can an organization demonstrate that it is putting the GARP principles into practice?
Demonstrating application generally rests on documented policies, procedures, and evidence that they are followed. Organizations often maintain approved retention schedules, classification schemes, records of disposition decisions, access and security controls, and assigned accountabilities, and they may conduct periodic reviews or audits. Aligning such documentation to each principle can help show intent and practice. The specific evidence that is appropriate or expected depends on jurisdiction, sector, and organizational policy, so the emphasis is usually on defensible, consistently applied practice rather than any single prescribed form of proof.

Common misconceptions

GARP is a formal standard or certification comparable to an ISO standard.
GARP is generally understood as a set of guiding principles for recordkeeping accountability rather than a certifiable technical standard. It is often used as a framework for self-assessment and program improvement, and it differs in nature from formalized standards such as those in the ISO family, which serve distinct purposes.
The Disposition principle is essentially about destroying records.
Disposition under GARP encompasses appropriate final handling, which may include secure destruction, transfer to another custodian, or long-term preservation. Treating disposition as synonymous with destruction overlooks the range of legitimate outcomes for records that have met their retention requirements.
Adopting GARP satisfies an organization's legal and regulatory obligations.
GARP provides principles to guide a program, but compliance with law and regulation is assessed against the specific obligations that apply to an organization, which vary by jurisdiction and sector. Aligning with the principles supports good practice but does not by itself establish or guarantee legal compliance.

Best practices

Assign clear, senior-level accountability for the recordkeeping program and document the roles and responsibilities that support it, in line with the Accountability principle.
Use the principles as a maturity self-assessment to identify gaps between current practice and desired program capability, and prioritize improvements based on organizational risk.
Document recordkeeping processes and decisions so that the program's integrity, transparency, and compliance can be demonstrated to auditors, oversight bodies, or other stakeholders as needed.
Define retention and disposition in policy that reflects applicable legal, regulatory, operational, and historical requirements for your jurisdiction and sector, and treat disposition as encompassing destruction, transfer, or preservation as appropriate.
Apply protection controls proportionate to the sensitivity and confidentiality of records, and periodically review them against evolving privacy and security obligations.
Test that records remain retrievable and usable over their required lifespan, supporting the Availability principle beyond the act of storing records.