Skip to main content
Category: Audit and Assessment

Records Management Review

Also known as: Records Management Assessment, Recordkeeping Review
Simply put

A records management review is a structured examination of how an organization creates, controls, and maintains its records to see whether current practices meet requirements and work as intended. It typically looks at the people, processes, and systems involved and identifies problems or areas for improvement. The scope and depth of a review can vary depending on organizational policy and the requirements that apply.

Formal definition

A records management review is an evaluative activity, conducted internally or by an oversight body, that assesses recordkeeping practices, controls, and systems against applicable policies, standards, and requirements across the record lifecycle. Reviews commonly examine the people, process, and systems or technology dimensions of managing records and information, and may result in observations, findings, and recommendations for corrective action. Depending on organizational policy and jurisdiction, such reviews may involve establishing metrics and benchmarks (for example, to compare hard-copy and electronic records management costs) and may be linked to broader oversight and reporting functions; the specific scope, criteria, and authority behind a review vary by organization, sector, and jurisdiction. Note that a records management review, as an assessment activity, is distinct from lifecycle actions such as retention or disposition review, which concern decisions about how long individual records are kept and their eventual disposition.

Why it matters

A records management review provides organizations with structured evidence about whether their recordkeeping practices actually meet the requirements that apply to them, rather than relying on assumptions that controls are working as intended. Because records serve as evidence of activity, gaps between stated policy and actual practice can undermine an organization's ability to demonstrate authenticity, reliability, and integrity when records are needed. Reviews surface these gaps as observations, findings, and recommendations, giving decision-makers a defensible basis for corrective action. The depth and formality of a review vary considerably depending on organizational policy, sector, and the requirements in force in a given jurisdiction.

Reviews can also be linked to broader oversight and reporting functions. Some oversight bodies compile recurring themes, key observations, and recommendations from the reviews they conduct, which can help organizations understand common weaknesses and priorities for improvement. Where reviews establish metrics and benchmarks, for example, comparing the cost of managing hard-copy versus electronic records, they can support more informed resourcing and planning decisions. The value of a review generally depends on the clarity of the criteria against which practices are assessed and the authority behind any resulting recommendations.

It is worth distinguishing a records management review, as an assessment activity, from lifecycle actions such as retention or disposition review. The former evaluates how well recordkeeping practices, controls, and systems perform against applicable requirements; the latter concerns decisions about how long individual records are kept and their eventual disposition. Conflating the two can lead organizations to treat a broad practice assessment as if it were a routine disposition decision, or vice versa.

Who it's relevant to

Records managers
Records managers use reviews to test whether the practices, controls, and systems they oversee are working as intended and meeting applicable requirements. Findings and recommendations help them prioritize corrective action and, where reviews establish metrics and benchmarks, support decisions about resourcing across hard-copy and electronic records.
Information governance officers and compliance leads
For those responsible for accountability, policy, and risk, a records management review offers evidence of whether recordkeeping practices align with organizational policy and applicable requirements. This can inform broader governance decisions, though the scope of any single review may be narrower than the full information governance framework.
Oversight and reporting bodies
Oversight bodies may conduct reviews and consolidate recurring themes, key observations, and recommendations across the organizations they assess. This helps them identify common weaknesses and communicate priorities for improvement, subject to the authority and mandate that applies in their jurisdiction.
Archivists
Archivists have an interest in reviews because assessment findings can bear on whether records retain the authenticity, reliability, integrity, and usability needed for their eventual disposition, which may include transfer or permanent preservation rather than destruction.

Inside Records Management Review

Scope and objectives
A records management review typically begins by defining what is being assessed and why. This often includes the business units, record types, systems, and processes within scope, along with the goals of the review, such as evaluating compliance, identifying risk, or supporting improvement. Scope boundaries should be stated explicitly so that stakeholders understand what falls outside the exercise.
Assessment against policy and standards
Reviews commonly compare current practices against an organization's own records management policies and, where relevant, against recognized frameworks. Standards such as ISO 15489 and management system standards in the ISO 30300 series are often used as reference points for good practice, though a review should describe their general purpose rather than assert specific clause-level conformance unless verified.
Lifecycle coverage
A thorough review examines controls across the records lifecycle, including creation, capture, classification, retention, disposition, transfer, and destruction. It is important to treat these stages as distinct; for example, assessing whether disposition decisions correctly distinguish destruction from transfer or permanent preservation.
Retention and disposition controls
This component evaluates whether retention schedules are current, applied consistently, and aligned with business, legal, and regulatory requirements. It also considers whether disposition is authorized, documented, and defensible. Because statutory retention periods vary by jurisdiction and sector, findings should be qualified accordingly.
Record integrity and authoritative status
A review often assesses whether records retain the properties that make them trustworthy, such as authenticity, reliability, integrity, and usability. This may include checking whether authoritative records are distinguishable from copies, drafts, and transitory information, and whether controls preserve these qualities over time.
Findings, risks, and recommendations
Reviews typically conclude with documented findings, an assessment of associated risks, and recommendations for remediation or improvement. These outputs may feed into broader information governance activities, though the review itself is generally narrower, focused on recordkeeping controls rather than the full accountability framework spanning privacy, security, and information value.

Common questions

Answers to the questions practitioners most commonly ask about Records Management Review.

Is a records management review the same as a records audit?
Not necessarily, though the terms are sometimes used loosely and interchangeably. A records management review is typically a broader assessment of how well recordkeeping practices, controls, and policies are functioning against organizational and, where relevant, external requirements. An audit often carries a narrower, more formal connotation of testing compliance against defined criteria, sometimes by an independent party. Depending on organizational policy, a review may be less formal, more advisory, and oriented toward improvement rather than verification. Because usage varies across organizations and sectors, it is advisable to clarify the intended scope and formality before treating the two as equivalent.
Does conducting a records management review mean records will be destroyed as a result?
Not inherently. A review assesses recordkeeping practices and may identify records due for disposition, but disposition is not synonymous with destruction. Depending on retention schedules and applicable requirements, the appropriate disposition action may be transfer to another custodian, permanent preservation, or destruction. A review may recommend such actions, but the review itself is an assessment activity and is generally distinct from the execution of any disposition decision, which typically follows its own authorized process.
How often should a records management review be conducted?
There is no single universal interval, as the appropriate frequency depends on organizational policy, sector, risk profile, and any applicable regulatory expectations. Many organizations schedule reviews periodically and also trigger them in response to specific events, such as significant changes to systems, business processes, or regulatory obligations. The cadence often reflects the level of risk associated with the records concerned, with higher-risk holdings typically reviewed more frequently.
Who should be involved in a records management review?
This depends on the review's scope and the organization's structure. Reviews often involve records management staff alongside stakeholders such as information governance leads, compliance or legal functions, information security, privacy officers, and representatives of the business units whose records are in scope. Where independence is important, an internal audit function or external reviewer may be engaged. Involving those who understand both the recordkeeping requirements and the operational context typically supports more accurate and actionable findings.
What areas might a records management review examine?
Scope varies by organization, but a review may examine areas across the records lifecycle, including creation and capture, classification, retention scheduling, disposition practices, and the controls that support record authenticity, reliability, integrity, and usability. A review might also consider alignment of policies and procedures with organizational needs and, where relevant, external requirements. The precise scope should be defined at the outset, and it is good practice to state explicitly what falls outside the review.
How should the findings of a records management review be documented and acted upon?
Findings are typically documented in a manner that supports accountability, which may itself constitute a record of the review activity. Depending on organizational policy, documentation often includes observations, identified gaps or risks, and recommendations. Acting on findings commonly involves assigning ownership, prioritizing actions according to risk, and tracking remediation over time. Follow-up or subsequent reviews may be used to confirm whether recommended actions have been implemented, though the specific approach depends on the organization's governance framework.

Common misconceptions

A records management review is the same as an information governance assessment.
The two are related but distinct. A records management review generally focuses on the control of records as evidence of activity across their lifecycle. Information governance is a broader accountability framework encompassing policy, risk, privacy, security, and the value of information. A records review may inform information governance work but typically has a narrower scope.
The review mainly checks that old records are being deleted on schedule.
Deletion is only one possible outcome. Disposition is broader than destruction and, depending on the applicable schedule and jurisdiction, may include transfer to another custodian or permanent preservation. A review commonly examines the full lifecycle, not just destruction, and evaluates whether disposition decisions are properly authorized and documented.
A review can confirm full compliance with a given standard by citing its clauses.
Reviews should describe the general purpose and scope of standards such as ISO 15489 rather than assert clause-level conformance unless that has been rigorously verified. Compliance also depends on organizational policy and on jurisdictional and sector-specific requirements, so findings are usually best expressed in qualified terms.

Best practices

Define and document the review's scope, objectives, and explicit boundaries at the outset, so stakeholders understand which business units, systems, and record types are and are not covered.
Assess controls across the full records lifecycle, treating creation, capture, classification, retention, disposition, transfer, and destruction as distinct stages rather than collapsing them together.
Reference relevant standards and frameworks by their general purpose and scope, and avoid asserting clause-level conformance or specific figures that have not been verified.
Qualify findings related to retention and legal obligations by noting that statutory periods and regulatory requirements depend on jurisdiction, sector, and organizational policy.
Verify that records retain the properties that make them trustworthy, such as authenticity, reliability, integrity, and usability, and check that authoritative records are distinguishable from copies, drafts, and transitory information.
Produce documented findings, a risk assessment, and prioritized, actionable recommendations, and clarify how any results feed into, but do not substitute for, broader information governance activities.