Skip to main content
Category: Audit and Assessment

Records Management Self-Assessment

Also known as:
Simply put

The Records Management Self-Assessment (RMSA) is an annual exercise in which U.S. federal agencies evaluate their own records management practices and report the findings to the National Archives and Records Administration (NARA). Its purpose is to help determine whether agencies are meeting the records management requirements set out in law and regulation. The self-assessment typically gathers information through a set of questions covering various aspects of an agency's recordkeeping.

Formal definition

The RMSA is a NARA-administered, annual self-reporting instrument through which U.S. federal agencies assess and report on the state of their records management programs against applicable statutory and regulatory requirements. Conducted as a structured data collection, it typically comprises questions addressing recordkeeping practices, and in some cycles has included questions relating to the administration of Freedom of Information Act obligations. As a compliance-assessment and reporting mechanism specific to the U.S. federal context, its scope is limited to evaluating and documenting an agency's own program performance for submission to NARA; it does not itself constitute records classification, retention, or disposition activity, and its applicability is jurisdiction-specific to U.S. federal agencies rather than a general recordkeeping standard.

Why it matters

For U.S. federal agencies, records management is a legal obligation rather than a discretionary practice, and the RMSA functions as one of the principal mechanisms through which NARA gauges whether agencies are meeting their statutory and regulatory recordkeeping requirements. Because the assessment is conducted annually and reported centrally, it provides a recurring point of accountability, allowing both the agency and NARA to identify gaps in program performance over time. Without such a reporting instrument, an oversight body would have limited visibility into how consistently agencies were maintaining records as reliable evidence of their activities.

The RMSA also matters because it consolidates attention on the health of an agency's records program at a defined moment each year, encouraging agencies to review practices that might otherwise go unexamined. In some cycles the data collection has extended to questions concerning the administration of Freedom of Information Act obligations, reflecting the practical connection between sound recordkeeping and an agency's ability to respond to information requests. It should be understood, however, that the RMSA is a compliance-assessment and reporting exercise; it documents the state of a program rather than performing the underlying records work, and its findings depend on the accuracy of each agency's own self-reporting.

Who it's relevant to

Agency Records Officers and Records Management Staff
These professionals are typically responsible for coordinating their agency's participation in the RMSA, gathering the information needed to answer the assessment questions, and ensuring the findings submitted to NARA accurately reflect the state of the program. The exercise directly shapes how they review and document recordkeeping practices each year.
NARA and Records Management Oversight
As the administrator of the RMSA, NARA relies on the submitted findings to gauge whether federal agencies are meeting statutory and regulatory records management requirements. The self-assessment provides NARA with recurring, agency-level information to support its oversight role.
FOIA and Information Access Personnel
Because some RMSA cycles have included questions about the administration of Freedom of Information Act obligations, staff involved in FOIA compliance may have an interest in the assessment where it touches on the recordkeeping practices that underpin an agency's ability to respond to requests.
Agency Leadership and Compliance Functions
Officials accountable for an agency's compliance posture may use RMSA findings as an indicator of program strengths and gaps. The annual reporting cadence offers a point of reference for assessing whether the agency is meeting its recordkeeping responsibilities, though the value of that reference depends on the accuracy of the self-reported data.
Records Management Professionals Outside the U.S. Federal Sector
For practitioners in other jurisdictions or in the private sector, the RMSA is relevant chiefly as a model of a structured, recurring self-assessment approach to program evaluation. Its specific requirements are jurisdiction-specific to U.S. federal agencies and should not be treated as a general recordkeeping standard applicable elsewhere.

Inside RMSA

Structured Questionnaire
A set of standardized questions or criteria through which an organization evaluates its own recordkeeping practices. The scope, wording, and rating scales typically vary depending on the sponsoring body and the jurisdiction or sector in which the assessment is applied.
Assessment Scope and Program Elements
The areas of a records management program under review, which often include policy, roles and responsibilities, classification, retention scheduling, disposition, and access controls. The precise elements covered depend on organizational policy and the framework being used.
Maturity or Compliance Rating
A method of scoring or grading responses to indicate how developed or compliant a program is against defined expectations. Rating approaches differ across frameworks; some emphasize maturity levels while others emphasize compliance against specific requirements.
Evidence and Documentation
Supporting materials, such as policies, schedules, and system records, that substantiate the self-reported responses. The degree of evidence expected typically depends on the rigor of the assessment and the purpose for which results are used.
Findings and Improvement Actions
Identified gaps, risks, or strengths arising from the assessment, often accompanied by recommended actions. These outputs are generally intended to inform program improvement rather than to serve as a formal certification.

Common questions

Answers to the questions practitioners most commonly ask about RMSA.

Is a records management self-assessment the same as a formal audit?
No. A self-assessment is typically an internal, self-reported evaluation conducted by an organization to gauge its own recordkeeping practices, often against a set of criteria or maturity indicators. A formal audit, by contrast, is generally an independent examination, sometimes conducted by an external or arm's-length party, that provides a higher level of assurance. Self-assessments may inform or precede an audit, but they usually do not carry the same independence or evidentiary weight. The distinction depends on organizational policy and, in some jurisdictions, on regulatory or oversight expectations.
Does completing a self-assessment mean an organization is compliant with its recordkeeping obligations?
Not necessarily. A self-assessment measures perceived or reported performance against chosen criteria at a point in time; it does not by itself establish compliance with statutory, regulatory, or contractual obligations, which vary by jurisdiction and sector. The results indicate areas of strength and weakness and can support improvement planning, but demonstrating compliance typically requires evidence of actual practice, and in some cases independent verification. Treating a completed self-assessment as proof of compliance can create a false sense of assurance.
How often should an organization conduct a records management self-assessment?
Frequency depends on organizational policy, risk profile, and any applicable oversight requirements. Many organizations conduct self-assessments on a recurring cycle, such as annually or biennially, to track change over time, while others align them with significant events such as system migrations, reorganizations, or changes in regulatory expectations. There is no single universal interval; the appropriate cadence is usually determined by the level of risk, the pace of change in the recordkeeping environment, and available resources.
Who should be involved in completing a self-assessment?
Participation typically extends beyond the records management function. Depending on organizational structure, input may be sought from information governance, IT, legal, privacy, security, and relevant business units, since recordkeeping practices are often distributed across an organization. Involving a range of stakeholders can improve the accuracy and completeness of responses and help surface gaps between policy and practice. The specific roles engaged depend on organizational policy and the scope of the assessment.
What criteria or framework can a self-assessment be based on?
Self-assessments are often structured around an established recordkeeping framework, maturity model, or set of principles, and may draw on standards or guidance issued by national archives or standards bodies. The choice of criteria depends on the organization's context, sector, and jurisdiction. Whatever basis is selected, it is generally useful to document the criteria and the interpretation applied so that results can be understood and compared consistently over time.
How should self-assessment results be used after completion?
Results are typically used to identify gaps, prioritize areas for improvement, and inform action planning, and they may feed into broader information governance reporting. To be useful, findings often need to be interpreted in context, supported by follow-up where reported practice and actual practice diverge, and revisited in subsequent cycles to measure progress. The way results are handled, escalated, and retained depends on organizational policy and any applicable reporting expectations.

Common misconceptions

An RMSA is an independent audit that certifies compliance.
A self-assessment is, by definition, self-reported and internal. It differs from an independent audit or external certification, and its findings typically depend on the honesty and completeness of the responses rather than verified external attestation. Depending on organizational policy, results may still be used to inform, but not replace, external review.
A high RMSA score means records management and information governance obligations are both fully met.
An RMSA generally focuses on records management practices, the control of records as evidence across their lifecycle. It does not necessarily address the broader information governance accountability framework spanning privacy, security, risk, and value. A strong records management result does not by itself demonstrate mature information governance.
The same RMSA can be applied unchanged across all organizations and jurisdictions.
Recordkeeping requirements, including retention obligations and legal or regulatory expectations, differ across jurisdictions and sectors. An assessment instrument often needs to be scoped or tailored to the applicable legal and organizational context, and results from one setting should not be assumed to transfer directly to another.

Best practices

Define the scope of the assessment explicitly at the outset, stating which program elements and which parts of the organization are included and what falls outside the review.
Where feasible, support self-reported responses with documentary evidence such as policies, retention schedules, and system records, so findings can be substantiated rather than relying on assertion alone.
Tailor the assessment criteria to the applicable jurisdictional and sector-specific requirements, since retention and legal obligations vary and a generic instrument may not reflect local expectations.
Treat the results as a basis for identifying gaps and prioritizing improvement actions, rather than as a formal certification or a substitute for independent audit.
Distinguish clearly between records management practices and broader information governance concerns when interpreting results, so that gaps in privacy, security, or value are not masked by strong recordkeeping scores.
Repeat the assessment periodically and record changes over time, using qualified interpretations of the findings to track program development while acknowledging the limits of self-reported data.