Skip to main content
Category: Information Governance Principles

Principle of Compliance

Also known as: Compliance Principle
Simply put

The Principle of Compliance is the idea that an organization's recordkeeping should conform to the laws, regulations, standards, and internal policies that apply to it. In broad terms, it means that how records are created, kept, and managed should be able to meet the rules the organization is subject to. The specific obligations vary widely depending on the industry, jurisdiction, and sector in which an organization operates.

Formal definition

As a recordkeeping principle, compliance denotes the requirement that a records management program conform to applicable legal, regulatory, standards-based, and organizational policy obligations governing the creation, capture, retention, and disposition of records. In general usage, compliance refers to conforming to a rule, standard, policy, or law, and regulatory compliance requirements typically vary by industry and jurisdiction. Practitioners often frame it as a systematic, defensible approach to managing recordkeeping so that the organization can demonstrate adherence to relevant legal, ethical, and internal standards. The precise scope of obligations, retention periods, and enforcement mechanisms depends on the applicable jurisdiction and sector and cannot be treated as universal. Note that this principle addresses conformance to obligations and should be distinguished from the intrinsic qualities that make something an authoritative record, such as authenticity, reliability, integrity, and usability.

Why it matters

The Principle of Compliance matters because recordkeeping does not occur in a vacuum; organizations operate within a web of laws, regulations, standards, and internal policies that shape how records must be created, kept, and managed. When a records management program conforms to these obligations, the organization is better positioned to demonstrate that it has met the rules it is subject to. Where recordkeeping falls short of applicable requirements, an organization may struggle to show that it managed records appropriately, with consequences that depend on the jurisdiction, industry, and sector involved.

Because regulatory compliance requirements vary by industry and jurisdiction, the specific obligations an organization faces are not universal. What is required in one sector or country may differ substantially from another, and retention periods, enforcement mechanisms, and the scope of obligations all depend on the applicable legal and regulatory environment. This variability is precisely why the principle is framed in terms of conformance to whatever rules apply, rather than a fixed checklist. A systematic, defensible approach helps an organization keep pace with the standards it is bound by and adapt as those standards change.

It is worth emphasizing that compliance addresses conformance to external and internal obligations, which is distinct from the intrinsic qualities that make something an authoritative record, such as authenticity, reliability, integrity, and usability. An organization can, in principle, hold records with sound evidential qualities yet still fall short of its compliance obligations, or conversely meet formal rules while neglecting record quality. Treating the two as separate concerns helps practitioners diagnose gaps more precisely.

Who it's relevant to

Records managers
Records managers apply the Principle of Compliance when designing and operating programs that govern how records are created, captured, retained, and disposed of. They are typically responsible for ensuring that recordkeeping practices align with the laws, regulations, standards, and internal policies applicable to the organization, which vary by industry and jurisdiction.
Compliance and ethics leads
Those responsible for building and running ethics and compliance programs draw on this principle to put policy into practice. Their work involves establishing a systematic approach so that recordkeeping supports the organization's ability to demonstrate adherence to relevant legal, ethical, and internal standards.
Information governance officers
Information governance officers use the principle within the broader accountability framework they oversee, ensuring that recordkeeping conformance to applicable obligations is coordinated with wider policy, risk, and organizational standards. They should note that this principle addresses conformance rather than the intrinsic qualities of an authoritative record.
Legal and regulatory advisors
Legal and regulatory advisors help organizations interpret which obligations apply and how they bear on recordkeeping. Because the scope of obligations, retention periods, and enforcement mechanisms depends on the applicable jurisdiction and sector, their guidance helps translate a variable regulatory landscape into defensible recordkeeping requirements.

Inside Principle of Compliance

Legal and Regulatory Alignment
The requirement that a recordkeeping program conform to the statutory, regulatory, and other legally binding obligations applicable to the organization. The specific obligations depend on jurisdiction and sector, so the principle is typically expressed as a duty to identify and meet the applicable requirements rather than a fixed set of rules.
Adherence to Organizational Policy
Beyond external law, the principle generally encompasses conformance with the organization's own accepted standards, internal policies, and documented procedures governing records and information. This internal dimension is what distinguishes defensible practice from ad hoc handling.
Demonstrable Conformance
Compliance is not only a state of meeting requirements but the ability to show that they are being met. This often involves documentation, audit trails, and evidence that controls operate as intended, so that conformance can be verified by internal or external parties.
Scope Across the Lifecycle
The principle typically applies to how records are created, captured, classified, retained, and disposed of, since obligations may attach at any lifecycle stage. Disposition here includes transfer or permanent preservation as well as destruction, depending on applicable requirements.
Accountability and Ownership
Compliance generally presupposes assigned responsibility for meeting obligations, so that identified roles are accountable for monitoring requirements and for the program's continued alignment with them.

Common questions

Answers to the questions practitioners most commonly ask about Principle of Compliance.

Does the Principle of Compliance mean an organization only needs to follow external laws and regulations?
No. While the principle does require that a recordkeeping program conform to applicable laws, regulations, and binding external obligations, it typically extends further to include the organization's own internal policies, procedures, and standards. Compliance in this sense is measured against the full set of authorities that govern the program, both external and internal. Treating the principle as concerned only with statutory or regulatory requirements understates its scope and can leave internally mandated controls unaddressed.
Is achieving compliance a one-time event that is complete once policies and controls are put in place?
Not typically. Compliance is generally understood as an ongoing state rather than a fixed milestone. Because the applicable laws, regulations, organizational policies, and operational circumstances can change over time, and because practice can drift from stated policy, the principle usually implies continuous monitoring, periodic review, and adjustment. Establishing controls is a necessary step, but sustaining and demonstrating compliance requires ongoing attention rather than a single implementation effort.
How can an organization demonstrate that its recordkeeping program actually complies with applicable requirements?
Demonstrating compliance generally depends on maintaining evidence that policies exist, are current, and are being followed in practice. This often includes documented policies and procedures, records of decisions, audit trails, monitoring results, and the outcomes of periodic reviews. The specific evidence expected varies by jurisdiction, sector, and organizational policy, so it is advisable to align documentation practices with the particular authorities the program is accountable to rather than assuming a universal standard of proof.
How should an organization identify which requirements its recordkeeping program must comply with?
A common approach is to compile and maintain an inventory of the applicable obligations, drawing on external sources such as laws and regulations relevant to the organization's jurisdictions and sectors, as well as internal sources such as organizational policies and contractual commitments. Because these requirements differ across jurisdictions and sectors and can change, many organizations treat this identification as a recurring exercise supported by legal, privacy, and compliance input rather than a task completed once.
Who is typically responsible for compliance within a recordkeeping program?
Responsibility is often distributed rather than resting with a single role. Records and information governance functions commonly design and administer the controls, while accountability for the overall program frequently sits with senior management. Legal, privacy, security, and compliance functions may contribute to identifying obligations, and staff who create and manage records typically bear day-to-day responsibility for following procedures. The precise allocation depends on organizational structure and policy.
How can an organization detect when its actual practices have drifted from its stated compliance requirements?
Detecting divergence between policy and practice generally relies on monitoring mechanisms such as periodic audits, reviews, and the examination of audit trails or system logs where available. These activities can reveal gaps between what policies require and what is actually occurring, allowing corrective action. The appropriate frequency and rigor of such monitoring depend on the level of risk, applicable requirements, and organizational policy.

Common misconceptions

Compliance means simply obeying the law, and nothing more.
In recordkeeping, the principle typically extends beyond external legal and regulatory requirements to include the organization's own policies, standards, and documented procedures. Meeting statutory obligations alone may leave internal commitments unaddressed.
If records are being retained, compliance is automatically satisfied.
Compliance depends on meeting the applicable requirements, which may govern classification, retention periods, disposition, and destruction, not merely whether records are kept. Retaining records beyond or against requirements can itself be non-compliant, and requirements vary by jurisdiction and sector.
Compliance is a fixed, one-time achievement.
Because legal, regulatory, and organizational requirements change over time and differ across jurisdictions, compliance is generally treated as an ongoing state that must be monitored and demonstrated rather than established once and assumed to persist.

Best practices

Identify and maintain an inventory of the legal, regulatory, and organizational requirements that apply to your records, recognizing that these depend on jurisdiction and sector.
Align internal policies and procedures with the identified requirements so that day-to-day practice is defensible against both external and internal obligations.
Maintain documentation and audit trails sufficient to demonstrate conformance, rather than relying on compliance being assumed or self-evident.
Assign clear accountability for monitoring applicable requirements and for keeping the recordkeeping program aligned as those requirements change.
Review compliance obligations periodically, since requirements and organizational policies may evolve over time.
Ensure controls apply across the full lifecycle, including classification, retention, and disposition, so that compliance is not treated as satisfied merely by retaining records.