Skip to main content
Category: Information Governance Principles

Principle of Integrity

Simply put

In records management, the Principle of Integrity refers to the expectation that records can be trusted as accurate and complete representations of the activities they document, and that they have not been altered or corrupted in unauthorized ways. It concerns whether a record remains reliable evidence over time, so that people can depend on it. Note that the evidence available here describes integrity mainly as a general moral or ethical concept rather than in a recordkeeping-specific sense, so this definition should be treated as provisional and confirmed against authoritative recordkeeping sources.

Formal definition

The Principle of Integrity is commonly understood in recordkeeping as a requirement that records maintain their completeness and unaltered state throughout their lifecycle, such that any authorized change is controlled, documented, and traceable, and unauthorized alteration or loss is prevented or detectable. It is typically treated as one of the properties that distinguish an authoritative record from mere information, alongside authenticity, reliability, and usability. The evidence packet provided does not contain records management or information governance sources defining this term in a technical sense; the supplied sources address integrity as a moral or organizational virtue rather than as a recordkeeping property. Practitioners should therefore verify the precise definition against recognized recordkeeping standards and frameworks, which fall outside the scope of the evidence available here.

Why it matters

The Principle of Integrity underpins the evidential value of records. If a record cannot be trusted as an accurate and complete representation of the activity it documents, its usefulness as evidence is diminished, regardless of how well it is stored or how quickly it can be retrieved. Integrity is one of the properties that distinguishes an authoritative record from mere information, a draft, or a copy, and it is closely bound up with the related concepts of authenticity, reliability, and usability. Without confidence in integrity, organizations cannot reliably demonstrate what occurred, when, and on whose authority.

The broader evidence available here frames integrity primarily as a moral or organizational virtue, emphasizing that trust, credibility, honesty, and transparency sit at its heart. While this ethical framing is not a substitute for a recordkeeping-specific definition, it does illuminate why the principle matters: recordkeeping integrity ultimately serves the same end of establishing trust, only applied to records rather than to individuals. When records maintain their completeness and unaltered state, stakeholders, auditors, regulators, and courts can depend on them; when they do not, the organization's ability to account for its actions is compromised.

Because the evidence packet provided does not contain records management or information governance sources defining this principle in a technical sense, the operational specifics of maintaining recordkeeping integrity should be confirmed against recognized recordkeeping standards and frameworks. Practitioners should treat the recordkeeping application described here as provisional and verify it against authoritative sources rather than relying solely on the general ethical treatments referenced.

Who it's relevant to

Records managers
Those responsible for controlling records across their lifecycle rely on integrity as a core property that helps distinguish an authoritative record from a copy, a draft, or transitory information. The precise controls used to preserve integrity should be confirmed against recognized recordkeeping standards, which are outside the scope of the evidence available here.
Information governance officers
Because integrity is often treated as one of several recordkeeping properties within a wider accountability framework, governance leads may position it alongside authenticity, reliability, and usability when setting policy. The general evidence here frames integrity in ethical terms, so its application to governance policy should be verified against authoritative recordkeeping sources.
Compliance and audit professionals
Where records serve as evidence of what occurred, the ability to demonstrate that records have not been altered in unauthorized ways can be central to defensibility. Requirements bearing on integrity typically depend on jurisdiction and sector, and specific obligations fall outside the scope of the evidence available here.
Archivists
For those managing records intended for long-term retention or permanent preservation, maintaining integrity over time is essential so that records remain trustworthy evidence well beyond their active use. The detailed preservation practices involved should be confirmed against recognized archival and recordkeeping standards.

Inside Principle of Integrity

Assurance of Authenticity
The Principle of Integrity, as expressed within recordkeeping frameworks such as the Generally Accepted Recordkeeping Principles, concerns providing reasonable assurance that records and information are authentic, meaning they are what they purport to be and were created or received by the person or process claimed. This underpins the evidential value of a record.
Verifiable Reliability and Trustworthiness
Integrity supports confidence that a record can be relied upon as an accurate representation of the activity, transaction, or decision it documents. This typically depends on controls over how records are created, captured, and maintained rather than on the content alone.
Completeness and Unaltered State
A record demonstrating integrity is complete and has not been altered in an unauthorized or undetected manner over time. Integrity is generally concerned with detecting and preventing improper change, not with preventing all change, since authorized updates and versioning may occur under controlled conditions.
Auditability and Chain of Custody
Integrity is often demonstrated through mechanisms that show how a record has been handled across its lifecycle, such as audit trails and metadata capturing custody, access, and changes. These mechanisms allow an organization to attest to a record's condition when its trustworthiness is questioned.
Metadata Supporting Integrity
Contextual and structural metadata typically accompanies a record to support claims about its origin, format, and handling. Such metadata is often as important as the record content in establishing that integrity has been maintained.

Common questions

Answers to the questions practitioners most commonly ask about Principle of Integrity.

Does the Principle of Integrity guarantee that a record can be proven authentic?
Not by itself. The Principle of Integrity concerns the completeness and unaltered state of a record and the metadata that documents its context. Integrity is one property that supports a claim of authenticity, but authenticity, reliability, and usability are distinct qualities. A record may retain its integrity yet still require additional evidence, such as audit trails, provenance metadata, and consistent recordkeeping controls, to support an assertion that it is what it purports to be.
Is the Principle of Integrity the same as information security or access control?
No, though they overlap. Information security measures such as access controls, encryption, and intrusion protection are among the means that can help protect integrity, but the Principle of Integrity is a recordkeeping objective focused on ensuring records remain complete and unaltered, with changes documented, across their lifecycle. Security is broader in some respects, covering confidentiality and availability, and narrower in others, since integrity in the recordkeeping sense also depends on classification, metadata management, and controlled disposition rather than technical safeguards alone.
How can an organization demonstrate that records have retained their integrity over time?
Organizations typically rely on a combination of documented controls: audit trails that capture who did what and when, version and change management, protected metadata, and defensible processes for capture, migration, and disposition. The specific evidence expected often depends on the sector, the applicable jurisdiction, and organizational policy. The general aim is to show that the record is complete, that any authorized changes are recorded, and that unauthorized alteration is prevented or detectable.
What controls help maintain integrity when records are migrated to new systems or formats?
Migration and format conversion introduce risk to integrity because content and context can be lost or altered. Common practices include validating that content and essential metadata are carried over, documenting the migration process, retaining evidence of the source and target states, and performing quality checks or reconciliation. The goal is to preserve the record's completeness and the context needed for it to remain usable, and to document any changes that occur so that the chain of custody is defensible.
How does the Principle of Integrity apply to routine, authorized changes such as edits or annotations?
Integrity does not require that records never change; it requires that changes be authorized and documented. Where amendments, annotations, or corrections are permitted by organizational policy, the recordkeeping system should typically capture the fact of the change, its author, and its timing, often while preserving prior versions. The distinction is between controlled, recorded change and undocumented or unauthorized alteration, which undermines integrity.
What is the relationship between integrity and disposition activities like transfer or destruction?
Integrity should be maintained throughout the lifecycle, including during disposition. When records are transferred to another custodian or to permanent preservation, controls are typically needed to confirm that they arrive complete and unaltered, with context intact. When records are destroyed under an authorized disposition process, integrity considerations shift to documenting that destruction occurred as authorized. Depending on organizational policy and applicable jurisdiction, evidence of disposition actions is itself often retained to support accountability.

Common misconceptions

Integrity means a record can never be changed.
Integrity is concerned with ensuring that changes are authorized, controlled, and detectable, rather than prohibiting all change. Records may be updated, versioned, or migrated under governed processes; what matters is that unauthorized or undocumented alteration can be prevented or identified.
Integrity and authenticity are the same thing.
The two are related but distinct properties. Authenticity concerns whether a record is what it claims to be and comes from its claimed source, while integrity concerns whether the record remains complete and unaltered in an authorized state. A record generally needs both, alongside reliability and usability, to serve as trustworthy evidence.
Applying the Principle of Integrity is purely a technical or IT security task.
While technical controls such as access management and audit trails contribute, integrity in a recordkeeping sense also depends on policy, defined responsibilities, metadata practices, and lifecycle governance. It is an organizational accountability matter, not solely a system configuration.

Best practices

Maintain audit trails and lifecycle metadata that record how records are created, accessed, modified, and moved, so the condition and custody of a record can be demonstrated when its trustworthiness is questioned.
Implement controlled processes for authorized change, including versioning and documented approvals, rather than attempting to make records wholly immutable, so that legitimate updates remain distinguishable from unauthorized alteration.
Apply access and authorization controls that limit who can alter records and under what conditions, ensuring that any change is attributable and traceable.
Capture and preserve contextual and structural metadata alongside record content, since such metadata often carries much of the evidence that integrity has been maintained.
Assign clear responsibilities and policies for maintaining record integrity, treating it as an organizational accountability supported by, but not reducible to, technical measures.
Verify integrity during high-risk activities such as format migration, system decommissioning, or transfer, so that completeness and the unaltered state of records can be confirmed through the change.