Skip to main content
Category: Systems and Technology

ISO 16175

Also known as: ISO 16175-1:2020, ISO/TS 16175-2:2020, Principles and functional requirements for records in electronic office environments
Simply put

ISO 16175 is an international standard that sets out what software should be able to do in order to manage digital records properly. It offers a model set of functional requirements along with guidance for choosing, designing, and running such systems. Rather than being a law, it acts as a reference point that organizations can use when they want software to handle records reliably.

Formal definition

ISO 16175 is a multi-part international standard, published in the Information and documentation domain, addressing functional requirements and guidance for software applications intended to manage digital records. In its 2020 revision, Part 1 (ISO 16175-1:2020) provides model, high-level functional requirements together with explanatory information and usage guidance for software applications, while Part 2 (ISO/TS 16175-2:2020, issued as a Technical Specification) offers guidance for decision making and the processes associated with the selection, design, implementation, and maintenance of such software. Earlier iterations included ISO 16175-2:2011, applicable to products commonly termed electronic records management systems (ERMS) or enterprise content management (ECM) systems, and ISO 16175-3:2010, which specified general requirements and guidelines for records management and for the identification and management of records. The standard should be understood as a functional-requirements and guidance framework rather than a certifiable management-system standard (compare ISO 30301) or the broader records management principles of ISO 15489; adoption and applicability depend on organizational policy and system context. Practitioners should verify the currently in-force parts and editions against the official ISO catalogue, as the numbering and status of individual parts have changed over successive revisions.

Why it matters

Digital records are only trustworthy if the systems that create, capture, and manage them can preserve their authenticity, reliability, integrity, and usability over time. ISO 16175 matters because it gives organizations a shared, vendor-neutral vocabulary for describing what recordkeeping software should be able to do. Instead of every organization drafting functional requirements from scratch, or accepting a vendor's own claims at face value, procurement and records teams can point to a recognized model set of requirements as a reference baseline. This helps reduce the risk of acquiring systems that store content but do not actually manage it as records.

The standard also supports defensibility. When decisions about system selection, design, or configuration are grounded in an internationally recognized functional-requirements framework, organizations are better positioned to demonstrate that they considered recordkeeping needs deliberately rather than incidentally. It should be understood, however, that ISO 16175 is guidance rather than a legal instrument. It does not by itself satisfy statutory retention, freedom of information, or privacy obligations, which vary by jurisdiction and sector, and conformance to its functional requirements is not the same as compliance with any particular regulatory regime.

Because the standard has been revised over successive editions, with the numbering and status of individual parts changing over time, its practical value depends on working from the currently in-force parts and editions. Practitioners are advised to verify the applicable parts against the official ISO catalogue rather than relying on legacy references, since older parts addressing electronic records management systems and enterprise content management systems have been reorganized in later revisions.

Who it's relevant to

Records managers and information governance officers
Those responsible for ensuring that digital records remain authentic, reliable, and usable can use the standard's model requirements to articulate recordkeeping needs to technical and procurement colleagues, and to check that proposed or existing systems support proper records control rather than mere content storage.
Procurement and system selection teams
Teams evaluating recordkeeping software can draw on the functional requirements and the guidance on selection and decision making as a reference baseline when comparing products, including those often described as electronic records management systems or enterprise content management systems, though claims should still be tested against organizational context.
IT and solution architects
Those designing, implementing, or maintaining systems that manage digital records can use the standard's guidance to inform design and configuration decisions, keeping recordkeeping functionality in view across the system's operational life rather than treating it as an afterthought.
Compliance and audit professionals
Practitioners concerned with defensibility can reference the standard as evidence that recordkeeping requirements were considered deliberately, while recognizing that alignment with ISO 16175 is not equivalent to meeting statutory or regulatory obligations, which depend on jurisdiction and sector.
Software vendors and developers
Suppliers building or enhancing recordkeeping software can use the model functional requirements to inform product capabilities and to communicate with customers in a shared vocabulary, while being careful not to overstate conformance, since the standard is a functional-requirements framework rather than a certification scheme.

Inside ISO 16175

Functional requirements focus
ISO 16175 is broadly concerned with articulating functional requirements for software and systems that manage digital records. Rather than prescribing a single product design, it describes the capabilities that records systems should typically support to maintain records as reliable evidence.
Principles and generic requirements
The standard tends to combine high-level principles for managing records in digital environments with more granular sets of requirements. These generally address how records should be captured, controlled, and managed across their lifecycle within business systems.
Records lifecycle controls
It typically covers capabilities associated with creation and capture, classification, metadata, retention scheduling, and disposition. Note that disposition here should be understood broadly, potentially including transfer or permanent preservation as well as destruction, depending on organizational policy and applicable requirements.
Metadata and integrity
The standard commonly emphasizes recordkeeping metadata and controls intended to support the authenticity, reliability, integrity, and usability of records over time, which are the properties that distinguish an authoritative record from mere information, a copy, or a draft.
Applicability across systems
ISO 16175 is generally intended to be applied not only to dedicated electronic records management systems but also to business applications and line-of-business systems that create and hold records, reflecting the reality that records are often managed within diverse environments.
Relationship to the wider standards landscape
It is often positioned alongside broader records management standards such as ISO 15489 and management-system standards such as ISO 30301, and it has conceptual overlap with other functional-requirements frameworks. The precise structure, part numbering, and edition details should be confirmed against the published standard rather than assumed.

Common questions

Answers to the questions practitioners most commonly ask about ISO 16175.

Does ISO 16175 certify or approve records management software as compliant?
No. ISO 16175 sets out functional requirements and principles rather than operating as a certification scheme. It provides a reference against which systems and their capabilities can be assessed, but it does not itself confer approval on a product. Some vendors describe their systems as aligned with or informed by ISO 16175, yet such statements typically reflect self-assessment or design intent rather than formal certification under the standard. Organizations should evaluate any such claims against their own requirements and, where independent assurance is needed, look to their own testing or to whatever conformance mechanisms apply in their jurisdiction and sector.
Is ISO 16175 only concerned with dedicated electronic records management systems?
Not solely. While the standard addresses functional requirements relevant to systems that manage records, its guidance is often framed around records functionality that may reside in a range of environments, including business applications and other systems that create or hold records, rather than only in a standalone records management product. The emphasis is on the recordkeeping functionality needed, which can be delivered through different technical arrangements. The specific coverage and structure depend on the version and part of the standard being referenced, so scope should be confirmed against the applicable text.
How does ISO 16175 relate to other recordkeeping standards such as ISO 15489?
ISO 16175 is generally understood to sit within a broader family of recordkeeping standards and to complement management-level guidance such as ISO 15489, which addresses records management principles and practice more broadly. Where ISO 15489 concerns the overall approach to managing records, ISO 16175 tends to focus more specifically on functional requirements for systems and recordkeeping functionality. The precise interrelationships and any cross-references depend on the current editions of each standard, so practitioners should consult the documents directly to confirm how they are intended to be used together.
Can ISO 16175 be used to develop system requirements for a procurement?
It can serve as a useful starting reference. The functional requirements described in the standard are often drawn upon when organizations articulate recordkeeping needs for procurement or system design. In practice, requirements typically need to be tailored to the organization's own business context, risk profile, and jurisdictional obligations rather than adopted wholesale. Practitioners commonly treat the standard as a baseline to be selected from and supplemented, and should verify that the requirements they cite match the applicable version of the standard.
Does adopting ISO 16175 satisfy an organization's legal or regulatory retention obligations?
Not on its own. ISO 16175 concerns functional requirements and principles for recordkeeping systems and functionality, whereas retention obligations arise from statute, regulation, and organizational policy that vary by jurisdiction and sector. A system aligned with the standard may support the enforcement of retention and disposition rules, but the substantive retention periods and legal requirements must be determined separately and reflected in the organization's retention schedules. Alignment with the standard should therefore be seen as supporting compliance rather than establishing it.
How should an organization approach assessing an existing system against ISO 16175?
A common approach is to map the standard's functional requirements against the capabilities of the system in question, identifying where requirements are met, partially met, or unmet. Because not all requirements will be equally relevant to every organization, this typically involves selecting and prioritizing requirements according to business needs, risk, and applicable obligations before assessing them. Any assessment should reference the specific version and parts of the standard being applied, and results are generally more defensible when documented alongside the rationale for which requirements were treated as in scope.

Common misconceptions

ISO 16175 is a certification standard that a product can be formally certified against.
It is generally framed as a set of functional requirements and guidance rather than a conformity-assessment or certification scheme. Vendors may claim alignment with its requirements, but such claims should be evaluated critically and, where certification is implied, verified against what the standard actually supports. Management-system certification is more commonly associated with standards such as ISO 30301.
Meeting ISO 16175 functional requirements is sufficient to ensure good records management.
System functionality is only one element. Effective recordkeeping also depends on policy, classification schemes, retention and disposition authorities, staff practices, and governance, many of which sit within the broader information governance framework. A capable system does not by itself guarantee that records retain their authenticity, reliability, integrity, and usability.
The standard prescribes specific retention periods, legal holds, or disposition rules.
It typically describes the functional capability to apply and enforce such controls rather than dictating the substantive rules themselves. Retention periods, legal hold obligations, and permissible disposition actions depend on jurisdiction, sector, and organizational policy, and must be determined from those sources.

Best practices

Consult the published version of ISO 16175 directly to confirm its current structure, scope, and requirements rather than relying on secondary summaries, and note that part numbering and editions may change over time.
Use the standard's functional requirements as an evaluation baseline when assessing electronic records management systems and other business applications that capture records, while adapting requirements to your organizational and jurisdictional context.
Ensure the system supports the full range of disposition outcomes, including transfer and permanent preservation as well as destruction, rather than treating disposition as destruction alone.
Combine ISO 16175 with complementary standards and guidance, such as ISO 15489 for records management principles and ISO 30301 where a management-system approach is required, to address governance dimensions the functional requirements alone do not cover.
Verify vendor claims of alignment against the actual requirements and, where feasible, test capabilities such as metadata capture, classification, retention scheduling, legal hold, and audit controls before procurement.
Configure retention, disposition, and legal hold functionality to reflect authorities and obligations that are specific to your jurisdiction and sector, treating the standard as a capability framework rather than a source of substantive retention rules.