Skip to main content
Category: Information Governance Principles

Information Management

Also known as:
Simply put

Information management is the practice of collecting, organizing, storing, and maintaining information from one or more sources so that it can be found and used when needed. It covers the handling of information across its life, from creation and capture through dissemination and eventual archiving or destruction. The aim is to keep information accurate, accessible, and useful to support the work and decisions of an organization.

Formal definition

Information management (IM) is the discipline concerned with the collection, organization, storage, curation, dissemination, and disposition of information and information-bearing materials such as documents, images, and drawings, drawn from one or more sources, so that the information remains accurate, accessible, and usable for organizational and decision-making purposes. It typically spans the full information lifecycle, including archiving and destruction. IM is broader than records management, which specifically governs records as evidence of activity; not all information handled under IM constitutes a record, and IM does not necessarily impose the evidential controls (authenticity, reliability, integrity) that recordkeeping requires. IM should also be distinguished from the wider accountability framework of information governance and from adjacent fields such as document management, data management, and knowledge management, though these areas frequently overlap in practice depending on organizational scope.

Why it matters

Information management matters because organizations depend on their information being accurate, accessible, and usable to support day-to-day work and decision-making. When information is poorly organized, difficult to find, or allowed to accumulate without control across its lifecycle, the cost is felt in wasted effort, unreliable decisions, and the risk of retaining material long past its useful life. Effective IM aims to keep the right information available to the right people when it is needed, from the point of creation and capture through dissemination and eventual archiving or destruction.

Because IM spans the full information lifecycle, it also provides the practical foundation on which more specialized controls can be built. Records management, information governance, and privacy or security obligations all rely on information first being collected, organized, and maintained in a manageable way. Where IM is weak, downstream disciplines struggle: it becomes harder to identify which materials are records requiring evidential controls, harder to apply retention and disposition consistently, and harder to demonstrate that information is being handled responsibly.

At the same time, it is important not to overstate what IM alone achieves. IM does not necessarily impose the evidential controls, such as authenticity, reliability, and integrity, that recordkeeping requires, and not all information handled under IM constitutes a record. Treating IM as if it were equivalent to records management or to the broader accountability framework of information governance can leave gaps in exactly the areas where organizations face the greatest risk.

Who it's relevant to

Information governance officers
IM provides much of the operational groundwork that governance frameworks rely on. Governance officers should understand where IM ends and the broader accountability framework of information governance begins, so that policy, risk, privacy, and value considerations are addressed rather than assumed to be covered by information handling alone.
Records managers
Records managers need to distinguish records, which require evidential controls such as authenticity, reliability, and integrity, from the wider body of information handled under IM. Not all information managed under IM is a record, and records managers often work to identify which materials require recordkeeping controls within a broader IM environment.
Archivists
IM explicitly includes archiving as part of the information lifecycle. Archivists have an interest in how information is collected, organized, and maintained upstream, since these practices affect what is eventually transferred for continued retention or preservation and in what condition.
Compliance and data protection leads
Because IM covers information across its life through to disposition, it intersects with retention, privacy, and security obligations that vary by jurisdiction and sector. Compliance and data protection professionals should be aware that IM does not by itself guarantee that such obligations are met, and that additional controls typically depend on organizational policy and applicable requirements.

Inside IM

Governance and Policy Framework
The set of policies, roles, accountabilities, and standards that direct how information is created, handled, and controlled across the organization. Information management typically sits within, and is guided by, a broader information governance accountability framework spanning policy, risk, privacy, security, and value.
Information Lifecycle Handling
The coordinated treatment of information from creation and capture through use, storage, and eventual disposition. In recordkeeping terms this includes creation, capture, classification, retention, disposition, transfer, and destruction, though information management as a whole extends beyond formally declared records to include broader information holdings.
Classification and Organization
The structuring of information so it can be located, retrieved, and used effectively, often through classification schemes, metadata, and taxonomies. This overlaps with records management practice but, in the wider information management context, may apply to information that is not managed as an authoritative record.
Access, Security, and Privacy Controls
Measures governing who may access information and under what conditions, reflecting security and privacy obligations. These obligations typically vary by jurisdiction and sector, so controls are usually shaped by applicable legal and regulatory requirements rather than a single universal standard.
Retention and Disposition Provisions
Arrangements determining how long information is kept and what happens to it afterward. Retention is not identical to archiving, and disposition is broader than destruction, since disposition may also include transfer or permanent preservation depending on organizational policy and applicable requirements.
Value and Quality Considerations
Attention to the reliability, integrity, and usability of information so that it remains fit for its intended purposes. Where information is intended to serve as evidence, properties such as authenticity, reliability, integrity, and usability become particularly important in distinguishing an authoritative record from a copy, draft, or transitory information.

Common questions

Answers to the questions practitioners most commonly ask about IM.

Is information management the same as records management?
No, though the two are related and often overlap in practice. Records management is concerned specifically with the control of records as evidence of activity across their lifecycle, including their authenticity, reliability, integrity, and usability. Information management is broader, encompassing the handling of information assets generally, much of which may never qualify as a record. Records management can be understood as a discipline that operates within, and contributes to, the wider scope of information management, but the two are not interchangeable.
Does information management mean the same thing as information governance?
Not quite, and the distinction matters. Information management typically refers to the operational and functional handling of information across its lifecycle, including capture, organization, storage, retrieval, and use. Information governance is generally the broader accountability framework spanning policy, risk, privacy, security, and value, under which information management activities are directed and held to account. In many organizations, information management is one of the functions governed by an information governance framework rather than a synonym for it.
How should an organization begin establishing an information management approach?
A common starting point is to understand what information the organization holds, where it resides, and how it supports business activities. From there, organizations often develop policies, classification approaches, and roles and responsibilities that align with their broader governance framework. The specific approach typically depends on organizational size, sector, and applicable legal and regulatory obligations, which vary by jurisdiction, so it is generally advisable to scope the effort against the organization's own risk profile and requirements rather than adopting a generic template.
Who is typically responsible for information management within an organization?
Responsibility is often shared across several roles rather than resting with a single function. Depending on organizational structure, this may include information management or records management staff, IT, privacy and security teams, legal or compliance functions, and business unit owners who create and use the information. Many organizations assign overall accountability at a senior level, sometimes to a designated officer, while day-to-day handling remains distributed. The precise allocation of roles depends on organizational policy and size.
How does information management relate to retention and disposition decisions?
Information management provides the operational context in which retention and disposition are applied, but it is important to distinguish the terms. Retention concerns how long information is kept, while disposition refers to the actions taken when a retention period ends, which may include transfer, permanent preservation, or destruction rather than destruction alone. Effective information management supports these decisions by ensuring information is identifiable, classified, and controlled, but the retention periods and disposition rules themselves are typically driven by legal, regulatory, and business requirements that vary by jurisdiction and sector.
What role do standards play in shaping information management practices?
Standards and frameworks can offer useful reference points for structuring information management, describing general principles and practices rather than prescriptive rules for every context. Some standards address recordkeeping specifically, while others speak to broader management systems or governance principles. Organizations often draw on such guidance selectively, adapting it to their own operating environment. It is generally advisable to treat standards as a source of good practice to be applied in light of the organization's circumstances and applicable obligations rather than as universal requirements.

Common misconceptions

Information management and records management are the same thing.
They overlap but diverge. Records management concerns the control of records as evidence of activity across their lifecycle, while information management is generally broader and addresses information holdings that may or may not be managed as authoritative records. Information governance, in turn, is a still broader accountability framework.
All information managed by an organization is a record.
Not all information is a record. Records are typically distinguished by properties such as authenticity, reliability, integrity, and usability, and there is a meaningful difference between an authoritative record, a copy, a draft, and transitory information. Information management commonly encompasses material that does not meet the threshold of a record.
Managing information to the end of its retention period means destroying it.
Retention and disposition are distinct concepts, and disposition is not synonymous with destruction. Depending on organizational policy and applicable requirements, disposition may involve transfer or permanent preservation as well as destruction, and retention itself should not be conflated with archiving.

Best practices

Position information management within a defined governance framework, clarifying roles and accountabilities and its relationship to the broader information governance framework spanning policy, risk, privacy, security, and value.
Distinguish clearly between authoritative records and other information holdings, applying stronger controls where authenticity, reliability, integrity, and usability are required for information to serve as evidence.
Apply consistent classification, metadata, and organization so information can be reliably located, retrieved, and used across its lifecycle.
Define retention and disposition provisions that treat disposition as broader than destruction, explicitly accommodating transfer and permanent preservation where appropriate.
Align access, security, privacy, and retention controls to the legal and regulatory requirements applicable to the relevant jurisdiction and sector rather than assuming a single universal regime.
Review policies and controls periodically to confirm that information remains fit for purpose and that lifecycle handling continues to reflect current organizational needs and obligations.