Aligning data governance with records and information management
This advice aims to help NSW public offices understand how records, information and data relate to each other, and how information governance, records and information management, and data governance intersect to support compliance, efficiency and accountability.
Records and information management (RIM) and data professionals share a common goal: to ensure that an organisation’s information assets are well managed, reliable and trustworthy, and enable the organisation to meet its decision-making and compliance needs. Collaboration between data and RIM professionals ensures that records, information and data are holistically managed.
This advice aims to help NSW public offices understand how records, information and data relate to each other, and how information governance, RIM and data governance intersect to support compliance, efficiency and accountability. It is aimed at staff responsible for recordkeeping, information management, data management, digital transformation, and governance functions.
Foundational concepts
| Information governance is the strategic framework for governing information assets across an entire organisation to support business outcomes and manage risks. Information governance relies on the strategic interaction of RIM and data professionals. |
| Records and information management (RIM) focuses on ensuring public offices make and keep evidence of their decisions and actions, and that evidence is stored securely and managed appropriately for as long as needed. |
| Data governance focuses on structured data quality, integrity, ownership and accessibility, to ensure data is accurate, consistent and trusted for business decision-making. |
| Data is a set of characters or symbols to which meaning is or could be assigned (AS/NZS ISO 30300: 2020). Data means any facts, statistics, instructions, concepts or other information in a form that is capable of being communicated, analysed or processed (whether by an individual or by a computer or other automated means). (Data Sharing (Government Sector) Act 2015, s. 4) |
| Information is data in context with a particular meaning (AS/NZS ISO 30300:2020). Data becomes information when it is structured and contextualised. |
| Records are information created, received and maintained as evidence and as an asset by an organisation, in pursuit of legal obligations or in the transaction of business (AS/NZS ISO 15489:2016). Records may contain both information and data. |
| Information assets are information that has value to the relevant stakeholder (ISO 24143). The term ‘information assets’ is commonly used to describe records, information and data. |
Figure 1, below, demonstrates how the concepts of data, information and records relate to each other, noting the role of factors like context and evidentiality.

Information assets created and kept by public offices as evidence of business transactions, decisions or activities are subject to the State Records Act 1998 and the Standard on Records Management. Public offices must create, maintain and protect information assets. Public offices must also provide public access to information assets that are 20 years or older unless they are subject to a closed to public access direction, and in some cases transfer them into the custody of Museums of History NSW as State archives.
Obligations also apply to:
- how information assets are collected, used, shared and disclosed as per the Privacy and Personal Information Protection Act 1998 and Health Records and Information Privacy Act 2002
- the release of government information under the Government Information (Public Access) Act 2009
- how information assets are protected (see the NSW Cyber Security Policy, the NSW Government Cloud Policy and the NSW Government Information Classification, Labelling and Handling Guidelines).
As records, information and data are interrelated and their requirements overlap, RIM and data professionals must collaborate to ensure that information assets are well managed and protected, and to ensure all requirements are met.
The differences between records and information management and data governance
The differences between records and information management (RIM) and data governance are most apparent in the day-to-day activities performed to manage information assets:
Data governance | RIM |
Focused on:
Supports:
| Focused on:
Supports:
|
RIM and data governance both support:
- managing records, information and data as assets – that is, ensuring they are understood, shared, protected and used effectively
- public offices in having reliable, trustworthy information assets to support business goals and decision-making
- compliance with legislative and regulatory requirements, such as the State Records Act 1998.
RIM and data governance share similar enablers. To execute effectively, both require:
- a whole-of-organisation, cross-functional approach to strategy and planning
- a focus on information assets that matter most to the organisation
- a risk management perspective
- clear accountabilities, roles and responsibilities
- an organisational culture that is information- and data-driven.
Integration between data governance and RIM ensures information assets are consistently and equally well managed. It reduces duplication of effort, fragmentation of approach and supports whole-of-government interoperability and digital transformation. It also enhances trust, transparency and service delivery.
Recordkeeping considerations for data governance
In addition to supporting business decisions, records support accountability and transparency in government when they can be relied upon as evidence of decisions and activities.
To ensure that public offices create and capture trustworthy records, the State Records Act requires public offices to conform with the Standard on Records Management. The Standard outlines principles and minimum requirements for effective RIM. Data governance functions should consider how to incorporate these minimum requirements in any system capturing, creating or storing records to comply with the Standard.
| Minimum recordkeeping compliance requirement | Examples of how data governance functions can incorporate minimum recordkeeping requirements |
| Records and information management is a designed component of all systems and service environments where high risk and/or high value business is undertaken (requirement 2.3) | Consider if high risk and/or high value records potentially reside in data platforms and ensure that system capabilities include metadata creation and capture needed to support records capture, protection, useability and discovery. High risk and/or high value records should be identified in the public office’s Information Asset Register. |
| Records and information management safeguard records, information and data, including records with a long-term retention (requirement 2.5) | Ensure that:
|
| Records, information and data are kept for as long as they are needed for business, legal and accountability requirements, then disposed (requirement 3.6) | Ensure that:
|
Overall, data governance functions can facilitate compliance with the Standard on Records Management by ensuring that:
- RIM and data management functions collaborate
- high risk and/or high value records and systems are documented
- systems have the capabilities to create, capture, store and retrieve records for as long as necessary
- records are protected from unauthorised or unlawful access, destruction, loss, deletion or alteration
- decisions about sharing data are made in collaboration with RIM
- there are processes in place to manage retention and lawful disposal when systems are decommissioned, data is migrated or whenever data is to be destroyed.
Aligning RIM and data governance
Public offices can proactively align RIM and data governance functions by:
- establishing governance and reporting structures
- integrating relevant policies and frameworks
- delivering training which addresses both RIM and data governance requirements.
Below is an overview of changes a public office could make to support stronger collaboration between data governance and RIM.
Establish Clear Governance Structures | |
| Establish a cross-organisation group which makes strategic and operational decisions for the public office where records, information and data is concerned (e.g. Records, Information and/or Data Governance Groups, or Audit, Risk & Improvement Committees (ARICs)) | It should be empowered to:
For more details, see the section on ‘Organisational structures’ in the NSW Data Governance Toolkit, Establishing effective information management and ISO 24143:2022. |
Define roles and responsibilities for information asset management for:
| Team members should understand how data and RIM policies, standards, frameworks, business rules and procedures relate to their day-to-day role. For more on recordkeeping roles and responsibilities, see the section on ‘Recordkeeping responsibilities’ on the Recordkeeping in government page, as well as the Standard on Records Management with which public offices must comply. For more on data governance roles and responsibilities, see the section on ‘Assigning roles and responsibilities’ in the NSW Data Governance Toolkit. |
Implement Integrated Policies and Frameworks | |
Develop or update policies to ensure alignment of:
| Define how:
For more on recordkeeping roles and responsibilities, see the section on ‘Recordkeeping responsibilities’ on the Recordkeeping in government page. For more on data governance roles and responsibilities, see the section on ‘Assigning roles and responsibilities’ in the NSW Data Governance Toolkit. |
| Align risk management processes to ensure all records, information and data risks are appropriately managed | Align risk roles with data and RIM roles and responsibilities. Consider reporting records, information and data risks to the same cross-organisation body. |
| Align relevant processes to support collaboration and ensure all information assets are managed from creation through to disposal | For example:
|
Workforce capabilities, training and awareness | |
| Team members should understand how to support good information and governance practice in their day-to-day roles, and how to identify and escalate risks. | Business and system owners should understand the interrelationship between records, information and data, and how the requirements of each relate to the systems they own and work in. |