Skip to main content
Category: Information Governance Principles

Information Governance Reference Model

Also known as: IGRM, IGRM Model
Simply put

The Information Governance Reference Model (IGRM) is a framework, developed by EDRM.net, that helps organizations coordinate how they govern their information. It illustrates the relationship between the value that information holds for an organization and the duties, such as legal and regulatory obligations, attached to it. It is intended as a governance and decision-making aid rather than a piece of software or a compliance checklist.

Formal definition

The IGRM is a conceptual reference model developed through the EDRM.net community to frame and support a unified, cross-functional approach to information governance. It depicts the linkage between the value of information assets and the duty owed to them, providing a common structure for aligning stakeholders around governance and decision-making. As described in the evidence, it is characterized as a governance and decision-making framework rather than a software architecture or a compliance checklist. The IGRM is associated with, but distinct from, the broader Electronic Discovery Reference Model (EDRM), within which information governance and identification appear as related activities. The available evidence does not detail the model's specific components or stakeholder categories, so those elements are outside the scope of this definition.

Why it matters

Information governance often fails not because individual functions lack competence, but because they operate in isolation. Legal, records management, IT, privacy, security, and business units frequently hold differing and sometimes conflicting views about the same information, what it is worth, how long it should be kept, and what obligations attach to it. The IGRM matters because it offers a shared reference point for framing these discussions, helping stakeholders see the relationship between the value information holds for the organization and the duty owed to it, such as legal and regulatory obligations. In many organizations, this alignment is a precondition for defensible and consistent governance decisions.

Because the IGRM is a governance and decision-making aid rather than a software product or a compliance checklist, its value lies in structuring conversation and coordination rather than in prescribing specific controls. This distinction is important: adopting the model does not, on its own, satisfy any statutory or regulatory requirement, which will depend on jurisdiction, sector, and organizational policy. Instead, the model can support the reasoning that underpins such decisions by making trade-offs between value and duty more explicit.

The IGRM emerged from a stated interest within the EDRM.net community in having a common model to frame the discussion of information governance. Its association with the broader Electronic Discovery Reference Model reflects the practical reality that governance decisions made upstream, such as what to retain and how to classify it, often shape the burden and risk encountered later in activities like identification for electronic discovery. Organizations that treat governance as a coordinated, cross-functional concern are typically better positioned than those that address it only reactively.

Who it's relevant to

Information governance officers and governance leads
Those accountable for coordinating governance across functions may find the IGRM useful as a shared reference point for aligning legal, IT, privacy, security, and business stakeholders. Its framing of value against duty can help structure decisions that would otherwise be fragmented across separate teams.
Records managers
Records managers concerned with retention, classification, and disposition can use the model as a discussion aid when negotiating with other stakeholders about the value and obligations attached to information. It does not replace records management practice or standards, but may help situate recordkeeping decisions within a broader governance conversation.
Legal and eDiscovery practitioners
Because the IGRM is associated with the broader Electronic Discovery Reference Model, legal teams and eDiscovery practitioners may find it relevant for understanding how upstream governance decisions relate to later activities such as identification. Governance choices about retention and classification often influence the scope and burden of discovery, though specific obligations depend on jurisdiction and matter.
IT, privacy, and security professionals
Professionals responsible for systems, data protection, and security can use the model to articulate their obligations and constraints alongside those of other functions. Its cross-functional framing is intended to surface where the duty owed to information and its value to the organization intersect, though it prescribes no particular technical controls.

Inside IGRM

Stakeholder-oriented framework
The IGRM is typically presented as a visual model that maps the relationships among the various stakeholders who have a role in governing information across its lifecycle, rather than prescribing a single technical process. It is intended to promote a shared understanding across functions.
Cross-functional participants
The model generally identifies distinct groups with interests in information governance, such as legal, records and information management, IT, business units, and privacy or security functions. It emphasizes that governance is a collaborative responsibility rather than the concern of any single department.
Duty, value, and asset perspectives
The IGRM commonly frames information in terms of the obligations attached to it (duty), the business or evidential value it holds (value), and its treatment as an organizational asset. These perspectives help balance competing drivers when making governance decisions.
Information lifecycle orientation
The model situates governance decisions across the lifecycle of information, from creation and use through retention and eventual disposition. Note that within recordkeeping, disposition may include transfer or permanent preservation and is not synonymous with destruction.
Policy-to-practice linkage
The IGRM is intended to help connect high-level governance policy and accountability to operational handling of information, encouraging alignment between what is required and what is actually done.

Common questions

Answers to the questions practitioners most commonly ask about IGRM.

Is the IGRM the same thing as a records management program or lifecycle model?
No. The IGRM is a conceptual reference model that illustrates how the various stakeholders and duties involved in information governance relate to one another; it is not itself a records management program, nor is it a records lifecycle model. Records management concerns the control of records as evidence of activity across their lifecycle, whereas the IGRM depicts the broader accountability framework in which recordkeeping sits alongside legal, risk, privacy, security, business, and IT interests. Organizations typically use the model to visualize relationships and responsibilities rather than as a step-by-step operational procedure. Lifecycle activities such as creation, capture, classification, retention, and disposition fall within what the model helps coordinate, but the model does not replace the detailed policies and schedules that govern those activities.
Does adopting the IGRM mean an organization has a complete, ready-to-use information governance standard?
Not on its own. The IGRM is a reference model intended to aid understanding and communication about how stakeholders and their obligations interconnect; it is generally not a prescriptive standard that dictates specific controls, retention periods, or compliance requirements. It does not substitute for formal standards, internal policy, or the jurisdiction- and sector-specific legal and regulatory obligations an organization must meet. Depending on organizational policy, teams often use the model as a framing device alongside other frameworks, standards, and their own governance documentation, rather than treating it as a self-contained solution.
How can an organization use the IGRM to clarify roles and responsibilities across teams?
The model is often used to map which stakeholders hold which interests in information, helping distinguish, for example, business owners who use and create information, legal and risk functions concerned with obligations and exposure, and IT functions responsible for storing and securing it. By making these relationships explicit, organizations can use the model as a starting point for discussions about accountability and hand-offs. It is typically most effective as a communication and alignment tool; the specific allocation of duties still depends on organizational structure, policy, and applicable requirements, which vary by jurisdiction and sector.
Where does the IGRM fit alongside other frameworks and standards an organization may already use?
The IGRM is generally positioned as a high-level conceptual model that can complement, rather than replace, other frameworks and standards. Many organizations use it to frame relationships among stakeholders while relying on separate instruments for detailed guidance, such as recordkeeping standards for the control of records or principles-based frameworks for broader accountability. Because it operates at a relational and conceptual level, it can often coexist with more prescriptive or operational tools. Organizations should confirm how any such framing aligns with their own policies and with obligations specific to their jurisdiction and sector.
What practical first steps help a team begin applying the IGRM?
A common starting point is to identify the relevant stakeholders and the interests each holds in the organization's information, then use the model to visualize how those interests intersect. Teams often follow this by examining where responsibilities overlap or where gaps exist, and using that view to prompt conversations about ownership, retention, disposition, and value. Because the model is conceptual, these steps typically feed into, rather than substitute for, the development of concrete policies, retention schedules, and controls. The specifics depend on organizational policy and applicable legal and regulatory requirements.
What are the limits of relying on the IGRM when planning governance activities?
Because the IGRM is a conceptual reference model, it does not by itself specify retention periods, disposition rules, security controls, or compliance obligations, all of which depend on jurisdiction, sector, and organizational policy. It illustrates relationships and responsibilities but does not resolve the detailed decisions that operational recordkeeping and governance require. Organizations should treat it as an aid to understanding and communication and pair it with authoritative policies, schedules, and standards to address specific requirements. Relying on the model alone to demonstrate compliance would generally overstate its purpose and scope.

Common misconceptions

The IGRM is a records management system or a technical standard that can be implemented directly.
The IGRM is generally understood as a conceptual reference model for aligning stakeholders and perspectives, not a records management application or an implementable technical specification. It informs how governance responsibilities are understood rather than dictating a specific system configuration.
Information governance, as represented by the IGRM, is the same thing as records management.
Information governance is the broader accountability framework spanning policy, risk, privacy, security, and value, while records management concerns the control of records as evidence of activity across their lifecycle. The IGRM reflects this broader framing by bringing multiple functions together; records management is one contributing discipline within it, not the whole.
The IGRM assigns governance responsibility to a single owner, typically IT or legal.
The model typically emphasizes that governance is shared across multiple stakeholder groups. It is intended to clarify overlapping interests and responsibilities rather than to concentrate accountability in one function.

Best practices

Use the IGRM as a tool to convene and align stakeholders across legal, records management, IT, privacy, security, and business functions, rather than treating it as a system to be installed.
Frame governance decisions using the duty, value, and asset perspectives so that legal and regulatory obligations, business value, and asset management are weighed together instead of in isolation.
Map governance responsibilities to the full information lifecycle, taking care to distinguish retention from disposition and to recognize that disposition may include transfer or permanent preservation, not only destruction.
Apply the model to link governance policy to operational practice, checking that stated obligations are reflected in how information is actually handled.
Recognize jurisdictional and sector variation when applying the model, since obligations such as retention, privacy, and legal holds depend on the applicable regime rather than a single universal standard.
Revisit stakeholder roles and responsibilities periodically, as organizational functions, regulatory expectations, and information holdings change over time.