Skip to main content
Category: Information Governance Principles

Information Governance Implementation Model

Also known as: IGIM, ARMA IGIM, IGIM 2.1
Simply put

The Information Governance Implementation Model (IGIM) is a framework published by ARMA International to help organizations put an information governance program into practice. It is intended to connect the different stakeholders who participate in that program, so that policy, risk, privacy, and related responsibilities are coordinated rather than handled in isolation. It has been released in successive versions, including an initial beta and a later version described as IGIM 2.1.

Formal definition

The IGIM is a practitioner-oriented implementation framework developed by ARMA International to structure and align an organization's information governance program across its participating stakeholders. According to ARMA's materials, it is positioned as a tool to bridge gaps among the parties involved in an IG program and to support the connection of governance activities across the organization. It was first issued as a beta version (documented from around 2019) and has since been revised, with a version identified as IGIM 2.1 described in later commentary as supporting the development of governance programs concerned with data quality, accessibility, and related aims. Note that IGIM should not be conflated with records management as such: information governance is the broader accountability framework spanning policy, risk, privacy, security, and value, while records management concerns the control of records as evidence across their lifecycle. The evidence available here does not permit a reliable, source-verified enumeration of the model's specific domains or components, so those details are not asserted in this entry; practitioners should consult ARMA International's published IGIM documentation directly for the authoritative domain taxonomy and any maturity dimensions.

Why it matters

Information governance programs frequently falter not because organizations lack policies, but because responsibility for information is dispersed across functions that operate in isolation. Legal, privacy, security, records management, IT, and business units may each hold a piece of the accountability picture without a shared structure to coordinate their efforts. The IGIM matters because it is explicitly positioned by ARMA International as a tool to bridge the gaps among the stakeholders who participate in an organization's information governance program, addressing a common failure mode in which governance activities are fragmented rather than aligned.

For practitioners, the value of a named, published implementation model lies in its ability to give a program a common reference point. Rather than negotiating roles and connections ad hoc, an organization can use a recognized framework to structure how its participants relate to one another and to the broader governance objectives. This is particularly relevant given that information governance is a broader accountability framework than records management alone, spanning policy, risk, privacy, security, and value; coordinating these concerns requires an intentional structure rather than assuming they will cohere on their own.

Because the IGIM has been issued in successive versions, including an initial beta and a later revision described as IGIM 2.1, organizations should be attentive to which version they are working from, as later commentary associates the 2.1 revision with governance aims such as data quality and accessibility. Practitioners should consult ARMA International's published IGIM documentation directly for the authoritative structure, since the specific domain taxonomy and any maturity dimensions should be drawn from the source material rather than secondary summaries.

Who it's relevant to

Information governance officers and program leads
Those responsible for establishing or maturing an information governance program may find the IGIM useful as a structured reference for coordinating the many stakeholders involved. Because the model is explicitly designed to bridge gaps among IG participants, it speaks directly to the coordination challenges these roles face across policy, risk, privacy, security, and value.
Records managers
Records managers should note that the IGIM addresses information governance as a broader accountability framework, of which records management is one part concerned specifically with the control of records as evidence across their lifecycle. The model can help situate recordkeeping responsibilities within a wider governance structure, but it does not replace records management practice or standards.
Privacy, compliance, and legal professionals
Professionals whose remit touches privacy, compliance, or legal risk are among the stakeholders an IG program is meant to connect. A published implementation model can offer these roles a shared structure for aligning their obligations with other governance functions, though specific legal and regulatory requirements remain dependent on jurisdiction and sector and fall outside the scope of the model itself.
IT and data governance teams
Later commentary associates the IGIM 2.1 revision with governance aims such as data quality and accessibility, which makes the model potentially relevant to teams responsible for data governance and supporting technology. These teams may use the framework as a point of connection between technical stewardship and the broader information governance program.

Inside IGIM

Scope and purpose
A structured model, associated with ARMA International, intended to help organizations plan and implement information governance in a coordinated way. It frames information governance as a multi-domain undertaking rather than a single function, and is often discussed alongside maturity assessment. Practitioners should consult ARMA's own published materials for the authoritative and current articulation of the model, as details may be refined across versions.
Domain-based organization
The model is generally organized around a set of interrelated domains that together describe the elements needed to establish and sustain an information governance program. The specific domains and their names should be taken from ARMA's current documentation; the model has been publicly described since its beta release and refined in later revisions, so the authoritative naming and count of domains reside with ARMA rather than being paraphrased loosely here.
Relationship to maturity assessment
The IGIM is frequently used in connection with maturity evaluation, allowing organizations to gauge how developed each domain is and to identify priorities for improvement. Maturity assessment describes the state of capabilities; it does not by itself perform records management or disposition.
Distinction from records management
As an information governance model, the IGIM addresses the broader accountability framework spanning policy, risk, privacy, security, and value across information assets. Records management, concerned specifically with controlling records as evidence of activity across their lifecycle, typically sits within this broader scope rather than being coextensive with it.

Common questions

Answers to the questions practitioners most commonly ask about IGIM.

Is the IGIM the same thing as a records management maturity model?
Not precisely. The IGIM addresses information governance as a broad accountability framework spanning policy, risk, privacy, security, and value across an organization, rather than focusing narrowly on the control of records as evidence of activity. Records management is typically one contributing discipline within the wider scope the model addresses. Treating the IGIM as merely a records management tool understates its intended breadth, though the two areas overlap considerably in practice.
Does the IGIM lack a defined structure, leaving organizations to design their own components?
No. The model's structure is publicly documented rather than indeterminate. It is organized around a defined set of domains, and organizations are expected to work within that established taxonomy rather than invent their own. Where uncertainty exists, it typically concerns how an individual organization interprets and applies the domains to its own context, not whether the domains themselves are specified.
How should an organization begin using the IGIM in practice?
Many organizations begin by orienting themselves to the model's domains and assessing current practice against each. This often starts with securing sponsorship and a governing body to steer the effort, then reviewing existing authorities, supporting resources, processes, and infrastructure. The starting point depends on organizational maturity, sector, and the drivers prompting the initiative, so approaches vary.
Who typically needs to be involved when applying the IGIM?
Because the model spans multiple governance concerns, participation typically extends beyond records and information staff to include roles associated with risk, privacy, security, legal, IT, and business functions. Cross-functional involvement and a coordinating body are commonly regarded as important, since no single function usually holds accountability for the full breadth of information governance. The exact composition depends on organizational structure and policy.
How can an organization use the IGIM to prioritize improvement efforts?
Organizations often use an assessment against the model's domains to identify areas of comparative strength and weakness, then prioritize based on risk, regulatory exposure, and business value. Priorities generally depend on jurisdiction, sector, and the organization's own risk appetite, so the model informs prioritization rather than prescribing a fixed order of work.
How does the IGIM relate to standards and other frameworks an organization may already use?
The IGIM is intended to complement rather than replace existing standards and frameworks. Organizations that already apply recognized records management or information governance standards can often map their existing controls to the model's domains. How the model aligns with any specific standard depends on the frameworks in use and the organization's governance environment, and such mapping is generally an interpretive exercise carried out locally.

Common misconceptions

The IGIM is a records management framework.
The model addresses information governance broadly, encompassing policy, risk, privacy, security, and the value of information across multiple domains. Records management is one contributing discipline within that wider scope, so treating the IGIM as solely a recordkeeping framework understates its intended breadth.
The IGIM and a maturity model are the same thing.
The IGIM is an implementation-oriented model, and while it is commonly used together with maturity assessment, describing the current state of capabilities across domains is a distinct activity from the model's structural depiction of what an information governance program comprises.
The model's structure is loosely defined or undocumented.
ARMA International has publicly documented the model's domains since its initial beta release and refined them in subsequent versions. Practitioners should rely on ARMA's current published materials for the authoritative domain set and naming rather than on informal paraphrases.

Best practices

Consult ARMA International's current published documentation for the authoritative domain set, terminology, and version of the IGIM before applying it, since the model has been revised over time.
Use the model's domains to map existing capabilities and identify gaps across policy, risk, privacy, security, and value, rather than treating information governance as a single function.
Keep the distinction clear between information governance breadth and records management specificity, ensuring lifecycle controls, retention, and disposition remain properly addressed within the wider program.
Pair the model with maturity assessment to prioritize improvement efforts, while recognizing that assessing current state is separate from the model's description of program components.
Adapt the model to your jurisdictional and sectoral context, since privacy, retention, and disclosure obligations vary and no single regime applies universally.
Engage cross-functional stakeholders, including legal, privacy, security, and business owners, so that accountability for each domain is assigned and sustained rather than concentrated in one team.