Consulting/ IG 101

An information governance framework drawn over a lit stone bridge at sunrise: the four building blocks label its piers, the seven goals label its arches. Both are listed in full below.

A primer, the way we teach it

Information Governance 101

Information governance lets an organization meet its legal and technical recordkeeping requirements while maximizing what its information is actually worth. The balance comes from four building blocks — policies, technology, people, and procedures.

What IG is, and what it isn't

Information governance

Records managementKeep, find, and dispose defensibly
Data governanceQuality and usability of structured data
IG sets the scope both of them operate inside.

Records management is a discipline: identifying records, classifying them, holding them for the right length of time, disposing of them defensibly. Information governance is the layer above it — who owns the information, what the organization keeps, where it is allowed to live, and when it goes away.

The distinction matters because the failure modes differ. A records program can be technically sound and still leave you exposed, because nobody decided whether the marketing team's cloud drive was in scope.

IG is broader than data governance, too. Where data governance concerns itself with structured data, IG covers everything you create or receive — contracts, email, chat threads, personnel files, the boxes still in offsite storage.

That breadth is why IG is never one department's job. Legal knows the obligations, IT knows the systems, records knows the schedule, privacy knows the individual's rights. A program living in only one of those places will be accurate and ignored.

The seven goals of IG

These are the outcomes a program is judged against. They pull against each other in practice — which is the point, and the reason the balance has to be deliberate.

Retention

Maintain and preserve records as evidence for audits, investigations, and legal proceedings.

In practice: a regulator asks for seven years of safety inspections and you produce them complete, on their deadline, without standing up a search project to do it.

Compliance

Good-faith compliance with the letter and spirit of applicable laws and regulations.

In practice: obligations rarely arrive as a single rule. One record can be governed by a state statute, a federal regulation, and a customer contract at the same time, and the schedule has to satisfy all three.

Value

Ensure the enterprise and its stakeholders get maximum value from records and information.

In practice: the same inventory that tells you what is safe to delete tells you what you are sitting on and never reused. Governance is usually sold as risk reduction and paid for by what it uncovers.

Security

Minimize and manage the risk of loss, intrusion, unauthorized use, disclosure, or destruction.

In practice: access controls on the system of record do nothing for the copy someone moved to a shared drive three years ago. You can only secure information you know you have.

Sustainability

Practices that preserve the integrity, authenticity, and usability of records over time.

In practice: a document kept for thirty years is only a record if you can still open it in year thirty. Formats age out, vendors fold, and migrations have to be planned before they are urgent.

Integrity

Keep records trustworthy, accurate, authentic, and complete.

In practice: an audit trail showing who touched a record and when is often the thing that makes it admissible. A record nobody can vouch for is a document.

Privacy

Meet legal and ethical obligations whenever personal data is processed.

In practice: privacy and retention pull in opposite directions — hold it for the schedule, delete it on request. Reconciling the two is a drafting problem, and it belongs in the schedule rather than in an email thread.

The building blocks

Four pieces, and a program is only as strong as its weakest one. Most IG efforts fail on the last two, not the first two.

Policies

A retention schedule, and the privacy, security, and records policies around it, written simply enough that people actually adopt them. Adherence is the objective, not shelf-ware.

Technology

Software that applies retention automatically, tracks custody of physical and electronic records, and journals every action — so the policy is enforced, not aspirational.

People

Named owners, an executive sponsor, and training that reaches past the records team. Every failed IG program had a policy and nobody accountable for it.

Procedures

Repeatable steps for each stage of the information lifecycle — capture, classify, hold, dispose — so the program survives reorganization and turnover.

Why IG can't wait

The legal landscape never stops moving. Four pressures reshape recordkeeping obligations faster than most programs adapt to them.

Emerging technology

Cloud platforms, collaboration suites, and generative AI tools create records faster than most retention programs can classify them. The efficiency is real; so is the exposure that comes with it.

Mobile devices

Business now happens on personal phones. Texts, chat threads, and voice notes are official records when they document a business decision — and they sit outside most retention systems entirely.

E-discovery

The decisions you make about data today set the cost of litigation later. Organizations that keep everything pay to collect, review, and produce everything, on someone else's schedule.

Data growth

Storage is cheap until it isn't. Redundant, obsolete, and trivial data raises cost, slows every search, and keeps legal exposure alive long past any business use.

Where a program starts

Nobody builds this in one pass, and the order matters more than the pace. Three moves separate programs that hold up from binders that sit in a shared folder.

Step 01

Find out what you have

Inventory the information and the systems holding it, including the ones nobody put on the org chart. Most programs discover their real scope here, and it is rarely what leadership assumed going in.

Step 02

Write a schedule you can defend

Ground the retention schedule in the laws that actually apply to your industry and jurisdictions, then structure it simply enough that a non-specialist can apply it without calling legal every time.

Step 03

Put it into the systems

Automate what the schedule requires, train the people creating records, and audit the result on a cycle. A schedule nobody executes is not a defense — it is evidence you knew what you should have been doing.

Don't go it alone

Knowing the framework is the easy part.

Building a program that holds up to an audit, a legal hold, or a decade of turnover is the work. Our consultants — JDs, CRMs, IGPs, and CIPPs — do it for a living.

How Zasio consulting works →

Ready to move past 101?

Talk to consulting