ISO 16175
ISO 16175 is an international standard that sets out what software should be able to do in order to manage digital records properly. It offers a model set of functional requirements along with guidance for choosing, designing, and running such systems. Rather than being a law, it acts as a reference point that organizations can use when they want software to handle records reliably.
ISO 16175 is a multi-part international standard, published in the Information and documentation domain, addressing functional requirements and guidance for software applications intended to manage digital records. In its 2020 revision, Part 1 (ISO 16175-1:2020) provides model, high-level functional requirements together with explanatory information and usage guidance for software applications, while Part 2 (ISO/TS 16175-2:2020, issued as a Technical Specification) offers guidance for decision making and the processes associated with the selection, design, implementation, and maintenance of such software. Earlier iterations included ISO 16175-2:2011, applicable to products commonly termed electronic records management systems (ERMS) or enterprise content management (ECM) systems, and ISO 16175-3:2010, which specified general requirements and guidelines for records management and for the identification and management of records. The standard should be understood as a functional-requirements and guidance framework rather than a certifiable management-system standard (compare ISO 30301) or the broader records management principles of ISO 15489; adoption and applicability depend on organizational policy and system context. Practitioners should verify the currently in-force parts and editions against the official ISO catalogue, as the numbering and status of individual parts have changed over successive revisions.
Why it matters
Digital records are only trustworthy if the systems that create, capture, and manage them can preserve their authenticity, reliability, integrity, and usability over time. ISO 16175 matters because it gives organizations a shared, vendor-neutral vocabulary for describing what recordkeeping software should be able to do. Instead of every organization drafting functional requirements from scratch, or accepting a vendor's own claims at face value, procurement and records teams can point to a recognized model set of requirements as a reference baseline. This helps reduce the risk of acquiring systems that store content but do not actually manage it as records.
The standard also supports defensibility. When decisions about system selection, design, or configuration are grounded in an internationally recognized functional-requirements framework, organizations are better positioned to demonstrate that they considered recordkeeping needs deliberately rather than incidentally. It should be understood, however, that ISO 16175 is guidance rather than a legal instrument. It does not by itself satisfy statutory retention, freedom of information, or privacy obligations, which vary by jurisdiction and sector, and conformance to its functional requirements is not the same as compliance with any particular regulatory regime.
Because the standard has been revised over successive editions, with the numbering and status of individual parts changing over time, its practical value depends on working from the currently in-force parts and editions. Practitioners are advised to verify the applicable parts against the official ISO catalogue rather than relying on legacy references, since older parts addressing electronic records management systems and enterprise content management systems have been reorganized in later revisions.
Who it's relevant to
Inside ISO 16175
Common questions
Answers to the questions practitioners most commonly ask about ISO 16175.