Skip to main content
Category: Roles and Governance

Records Custodian

Also known as: COR, Custodian of Records, Custodian, Medical Records Custodian
Simply put

A records custodian is a person, entity, or department assigned responsibility for looking after records on behalf of an organization. This typically includes keeping records secure, storing them properly, providing access when appropriate, and, where authorized, disposing of them. The specific duties and legal obligations attached to the role vary by jurisdiction, sector, and organizational policy.

Formal definition

A records custodian is an individual, entity, or organizational unit charged with the care of records, which may exist in paper or other formats. The role commonly encompasses responsibilities such as the security, storage, dissemination or provision of access, and authorized destruction of records held in the custodian's charge. In many regulated contexts the custodian's duties are defined by specific statutory or regulatory requirements; for example, custodial obligations for criminal offender record information or for patient health records are established under applicable law and can differ significantly across jurisdictions and sectors. Custodianship generally denotes responsibility for the safekeeping and handling of records rather than ownership of them, and it should be distinguished from the broader accountability for records policy and governance, which may rest with other roles depending on organizational structure.

Why it matters

The records custodian role is central to ensuring that records remain secure, accessible when appropriate, and handled in accordance with applicable requirements throughout the period they are held. Because the custodian is typically the person or unit with day-to-day charge of records, the effectiveness of an organization's recordkeeping often depends on how clearly the role is defined and how consistently its duties are carried out. Where custodial responsibilities are ambiguous, records may be inadequately secured, improperly disclosed, or destroyed without authorization, any of which can expose an organization to legal, regulatory, or reputational consequences depending on jurisdiction and sector.

The role carries particular weight in regulated contexts, where custodial obligations may be established by statute or regulation. For example, the handling of criminal offender record information and the maintenance of patient health records are governed by specific legal requirements in some jurisdictions, and these requirements can differ significantly from one jurisdiction or sector to another. In such settings the custodian is often the point of accountability for meeting defined obligations around security, provision of access, and authorized destruction, which makes correct assignment and understanding of the role a matter of compliance rather than mere administrative convenience.

It is important not to overstate what the role encompasses. Custodianship generally denotes responsibility for the safekeeping and handling of records rather than ownership of them, and it is distinct from the broader accountability for records policy and information governance, which may rest with other roles depending on organizational structure. Treating the custodian as the owner of records, or as the party responsible for setting overarching governance policy, can create gaps in accountability. Organizations typically benefit from documenting where custodial duties end and where policy, governance, or ownership responsibilities begin.

Who it's relevant to

Records managers and information governance officers
These professionals often assign, oversee, or coordinate custodial responsibilities and need to distinguish custodianship from the broader accountability for records policy and governance. Clear delineation helps ensure that safekeeping duties are covered without conflating them with ownership or policy-setting functions.
Compliance and legal teams
In regulated sectors, custodial obligations may be established by statute or regulation, and these teams are typically concerned with ensuring that the custodian's duties around security, access, and authorized destruction meet applicable requirements. Because such requirements differ by jurisdiction and sector, legal review is often needed to confirm the correct scope of the role.
Healthcare administrators and medical records staff
Custodianship of patient health records carries specific responsibilities for maintaining, safeguarding, and providing appropriate access to those records. In some jurisdictions, rules also address who assumes custodianship in particular circumstances, such as the transfer of a physician's records, so those responsible for medical records need to understand the applicable local requirements.
Personnel handling sensitive or regulated record types
Staff responsible for records such as criminal offender record information may be accountable for the security, storage, dissemination, and destruction of that information under applicable law. Understanding the boundaries of custodial authority, including when access and destruction are permitted, is important for those in these roles.

Inside COR

Physical or Technical Control
The records custodian holds day-to-day responsibility for the storage, maintenance, and physical or technical safekeeping of records, whether those records exist in paper, hybrid, or electronic form. This role is typically operational rather than one of ultimate accountability.
Distinction from Records Owner
Custodianship is generally separate from ownership. A records owner or accountable business unit often retains authority over decisions such as classification, access, retention, and disposition, while the custodian executes the safekeeping and handling of the records on the owner's behalf. The precise division depends on organizational policy.
Preservation of Record Properties
A custodian is typically expected to help maintain the authenticity, reliability, integrity, and usability of records under their care, so that the records remain trustworthy evidence of the activity they document. This may involve controls over access, handling, and environmental or system conditions.
Lifecycle Handling
Custodians often carry out or facilitate lifecycle actions such as capture, storage, transfer, and the execution of authorized disposition, which may include destruction, transfer to another body, or permanent preservation. Authority to trigger these actions usually rests elsewhere; the custodian carries them out as directed.
Delegated and Third-Party Custody
Custody may be held internally by a records unit, IT function, or business area, or delegated externally to a third party such as an offsite storage provider or cloud service. Delegation of custody does not typically transfer accountability, which generally remains with the organization or records owner depending on contractual and policy arrangements.

Common questions

Answers to the questions practitioners most commonly ask about COR.

Is the records custodian the same as the records owner?
No. The custodian and the owner are typically distinct roles, though they are often confused. The records owner generally holds accountability for the records as a business asset, including decisions about classification, access rights, and disposition authorization. The custodian, by contrast, usually has physical or operational responsibility for holding and maintaining the records on the owner's behalf. Depending on organizational policy, one person or unit may perform both roles, but the responsibilities remain conceptually separate, and it is often good practice to document them separately.
Does being a custodian mean you have the authority to destroy or dispose of records?
Not typically. Custody concerns holding and maintaining records, not authorizing their disposition. In many organizations, disposition, including transfer, permanent preservation, or destruction, must be authorized by the records owner or another accountable party in line with an approved retention schedule. A custodian often carries out disposition actions once they are properly authorized, but the authority to decide generally rests elsewhere. Organizations should make this separation explicit in policy to avoid unauthorized destruction.
How should custodial responsibilities be documented within an organization?
Custodial responsibilities are often set out in role descriptions, records management policies, or custody registers that identify who holds which records and on what terms. Depending on organizational policy, documentation may specify the scope of holdings, the maintenance obligations, access arrangements, and the point at which custody transfers to another party. Clear documentation supports accountability and helps demonstrate that records have been maintained under controlled conditions.
What should happen to custody when records are transferred between units or to an archive?
Transfer of custody typically involves a documented handover so that responsibility passes clearly from one custodian to another. This often includes recording what is transferred, when, and to whom, and confirming that the receiving custodian accepts the maintenance obligations. Where records move to an archive as part of disposition, custody may change while ownership arrangements are settled separately. Maintaining a clear chain of custody helps preserve the authenticity and integrity of the records over time.
How does a custodian help preserve the authenticity and integrity of records?
A custodian generally contributes to authenticity and integrity by maintaining records under controlled conditions, protecting them from unauthorized alteration or loss, and keeping evidence of how they have been handled. This often includes managing access, applying appropriate security measures, and maintaining an unbroken chain of custody. These practices support the ability to rely on records as evidence, though the specific controls applied usually depend on the sensitivity of the records and organizational policy.
How does the custodian role interact with legal holds?
When a legal hold is in place, a custodian often plays a practical part in ensuring that the affected records are preserved and not disposed of, even where a retention schedule might otherwise permit disposition. The authority to impose or lift a hold typically rests with legal or compliance functions rather than the custodian, and the specific obligations depend on jurisdiction and sector. The custodian's role is generally to give effect to the hold by safeguarding the relevant records until it is released.

Common misconceptions

The records custodian owns the records and decides their fate, including when they are destroyed.
Custodianship and ownership are usually distinct. Custodians typically hold and safeguard records but act under the authority of a records owner or accountable body, who commonly determines classification, retention, and disposition decisions. The custodian generally executes rather than authorizes these actions, though the exact allocation depends on organizational policy.
Outsourcing storage to a third-party provider transfers responsibility for the records to that provider.
Delegating physical or technical custody, for example to an offsite or cloud provider, does not typically transfer accountability for the records. Responsibility for ensuring records remain authentic, accessible, and appropriately managed generally stays with the organization, subject to contractual terms and applicable jurisdictional requirements.
A custodian's role is limited to passive storage, so record quality is not their concern.
Custody is often more than passive holding. Custodians are commonly expected to help preserve the integrity, authenticity, and usability of records, which can require active controls over access, handling, and system or storage conditions rather than mere retention of the items.

Best practices

Document the boundary between custodianship and ownership in policy, making explicit which decisions (such as classification, retention, and disposition) the custodian executes versus authorizes.
Where custody is delegated to a third party such as an offsite or cloud provider, use contractual terms to define safekeeping obligations and confirm that accountability arrangements are clearly recorded, recognizing these should be reviewed against applicable jurisdictional and sector requirements.
Implement and monitor controls that support the authenticity, reliability, integrity, and usability of records held in custody, including access restrictions and appropriate handling or system conditions.
Execute disposition actions only on documented authorization from the records owner or accountable body, and retain evidence that transfer, destruction, or permanent preservation was carried out as directed.
Maintain accurate custody records or metadata that track where records are held, who holds them, and any transfers of custody over the lifecycle.
Coordinate with records owners and information governance functions so that legal holds and any jurisdiction-dependent retention obligations are respected before any disposition is carried out.