Recordkeeping and ICT
This guidance is for ICT and data managers, business system owners and Chief Information Officers to explain how to consider and address records management as part of system lifecycle management.
Public offices in NSW have records management obligations under the State Records Act 1998. These include:
- making and keeping records that fully and accurately document their business activities
- preserving records and protecting them from neglect, loss, damage and unauthorised alteration, deletion or transfer
- maintaining accessibility to equipment and technology-dependent records.
Records exist in business systems, SaaS platforms, messaging systems, collaboration tools and AI systems, as well as in files and dedicated records management systems. Decisions made when planning, designing, acquiring, managing, changing and decommissioning systems and service environments directly affect an organisation’s ability to comply with its records management obligations under the State Records Act.
This guidance is for:
- ICT managers and ICT service owners
- data managers
- business system owners
- enterprise and solution architects
- ICT project and delivery managers
- Chief Information Security Officers (CISO)
- Chief Information Officers (CIO).
It explains how to consider and address records management as part of system lifecycle management, including when making decisions about:
- system configuration / controls that affect the creation, capture, access, use and sharing of records, information and data
- security, privacy and protective measures
- the acquisition, implementation or upgrade of business systems or collaboration tools, including SaaS
- the migration of records, information and data between systems or environments
- the decommissioning of systems, platforms or storage environments
- the deletion of records, information and data.
Where ICT and records and information management requirements are not aligned, NSW public offices may experience:
- systems that do not create or keep full and accurate records of business activities
- systems that cannot support records, recordkeeping processes, information and data retention, disposal or access rules
- increased privacy, security and regulatory risk
- an inability to show compliance during audits, reviews or legal discovery
- data silos and poor information quality
- accidental or malicious destruction of records, information and data
- data loss or corruption during migration or decommissioning
- increased long‑term costs from over retention of records, information and data.
Strong collaboration between ICT, business system owners and RIM professionals enables:
- compliance with the State Records Act and the Standard on Records Management
- improved quality, reliability and accessibility of records, information and data
- better information governance across collaboration platforms such as Microsoft 365
- defensible disposal of records, information and data
- reduced risk of over retention of personal information in records and business systems
- reduced legacy system burden
- more efficient and lower‑risk system transitions (migration and decommissioning)
- security and protection of the records, information and data held in systems, platforms, and digital tools.
Collaboration is also needed in the event of a data breach or cyber event, or the unauthorised disposal of records, information or data. RIM professionals must be alerted to such events, which must be notified to State Records NSW, and involved in developing and implementing mitigation strategies.
ICT staff and business system owners make technical and operational decisions for systems, platforms and digital tools. RIM professionals determine recordkeeping requirements and authorise disposal under the State Records Act. Neither group can meet compliance obligations in isolation.
Responsibilities and decision-making powers
| Role | Responsible for… | Collaborate with RIM professionals to… |
|---|---|---|
| ICT managers and ICT service owners |
|
|
| Data managers |
|
|
| Business system owners |
|
|
| Enterprise and solution architects |
|
|
| ICT project and delivery managers |
|
|
| CISOs |
|
|
| CIOs |
|
|
Data in systems is a recordData created or received by a NSW public office during official business and kept as evidence is a record, regardless of:
Structured data, system logs, emails, documents and metadata are State records under the State Records Act if they are created or received during official business and kept as evidence. |
Records disposal must be authorised‘Disposal’ includes:
Under the State Records Act, disposal of records must be authorised. Authorised disposal includes:
System storage limits or vendor constraints do not override retention obligations. Consult with RIM staff before disposing of any records, information or data. |
Metadata is essential for authoritative and trustworthy recordsQuality metadata ensures records, information and data are trustworthy, reliable and useful. Systems must capture and maintain sufficient metadata to meet minimum requirements for authoritative records and information. |
Backup systems are not recordkeeping systemsBackups support disaster recovery and continuity. Public offices must not use backups as recordkeeping systems or to meet retention requirements. Managing backup systems is a specialist role for ICT staff. Refer to Backup systems for advice on using backups to maintain the integrity of records, information and data. The State Records Regulation 2024 permits the disposal of system backups in accordance with NAP. |
‘Archive’ vs ‘archives’In ICT to ‘archive’ data often means moving data to lower-cost, slower storage tiers, reducing costs and freeing up space in primary, high-performance systems. Data is often archived when it is inactive or rarely accessed. In recordkeeping, ‘archives’ are records with enduring value that will be kept permanently. These concepts serve different purposes and must not be confused. If data is archived to lower-cost, slower storage tiers, it must remain accessible until relevant minimum retention periods have been met and it is accountably disposed of. If data is required as a State archive under an approved retention and disposal authority, it must be transferred to Museums of History NSW when no longer required for business purposes. |
Project initiation
Public offices must ensure that records and information management is a designed component of all systems and service environments where high risk and/or high value business is undertaken (Standard on Records Management, requirement 2.3).
Recordkeeping requirements should be defined at project initiation. Public offices should:
- include recordkeeping requirements in systems specifications
- define requirements for metadata to support records identification and context, access controls and security, and search, discovery and use
- embed RIM approval checkpoints in project governance and assurance processes.
Work with RIM professionals to:
- define recordkeeping and metadata requirements
- identify applicable retention and disposal authorities
- undertake recordkeeping risk assessments.
Further resources:
- Checklist for assessing business systems for recordkeeping
- Minimum requirements for metadata for authoritative records and information
- Cloud computing: implications for records management
- Identifying and managing high value and high risk records
- Records, information and data risks
System acquisition and configuration
Public offices must ensure that records and information management safeguard records, information and data (Standard on Records Management, requirement 2.5). Records, information and data must be managed to ensure they are reliable and trustworthy (requirement 3.2), identifiable, retrievable and accessible for as long as they are required (requirement 3.3), and protected from unauthorised or unlawful access, destruction, loss, deletion or alteration (requirement 3.4).
System acquisition and configuration decisions determine whether a public office can comply with the State Records Act. Public offices should:
- ensure systems, including SaaS platforms, can export useable records and metadata
- ensure systems, including SaaS platforms, prevent uncontrolled and unauthorised data deletion
- embed information security, privacy and protection mechanisms into systems and processes to protect records, information and data
- ensure metadata capture, indexing and search functionality meets requirements and business needs
- configure retention rules, audit trails, disposal triggers and defensible disposal workflows.
Work with RIM professionals to:
- assess recordkeeping risks in SaaS contracts and hosting arrangements
- develop and apply tailored metadata schema
- establish standards for naming, version control and record structure
- implement security classifications (DLMs), including business rules and handling procedures
- conduct RIM validation testing and user acceptance reviews.
Further resources:
- Cloud computing: implications for records management
- Minimum requirements for metadata for authoritative records and information
- Information security
System operation and maintenance
Records, information and data must be routinely created, captured and managed as part of normal business practice (Standard on Records Management, requirement 3.1), managed to ensure they are reliable and trustworthy (requirement 3.2) and kept for as long as they are needed for business, legal and accountability requirements, then disposed (requirement 3.6).
Ongoing system management must continue to support recordkeeping compliance. Public offices should:
- actively manage access controls, user permissions and security roles
- establish governance for platforms such as Microsoft 365, including Purview
- only dispose of records, information and data when authorised and in consultation with the RIM team. Housekeeping or optimisation activities must not result in unauthorised disposal.
Work with RIM professionals to:
- implement and maintain recordkeeping controls in business systems and collaboration tools, like Microsoft 365
- conduct regular system audits and health checks to test controls (including security) and verify records, information and data integrity and trustworthiness
- establish, monitor and review policies, procedures and business rules to ensure accuracy and quality of records, information and data
- manage change and configuration updates without undermining recordkeeping.
Further resources:
- State Records Regulation 2024 and normal administrative practice for public offices
- Digital disposal
- Microsoft 365 and recordkeeping
- Microsoft 365 as a records management system
System change, migration and decommissioning
Records, information and data must be sustained through system and service transitions by strategies and processes specifically designed to support business and accountability (Standard on Records Management, requirement 2.6) and kept for as long as they are needed for business, legal and accountability requirements, then disposed (requirement 3.6).
System change and decommissioning present a high risk to State records. Public offices should:
- plan migrations to maintain record integrity, context and useability
- meet the conditions of the general authority for source records that have been migrated (GA48)
- identify and fulfill retention and disposal requirements for records, information and data before systems are turned off
- avoid uncontrolled ‘bulk transfers’ that lose metadata or structure.
Work with RIM professionals to:
- identify records which must be kept and therefore migrated, and records which can be deleted when systems are decommissioned
- authorise disposal of eligible records
- map source and target systems, including metadata
- transfer records required as State archives to Museums of History NSW.
Further resources:
- Migrating digital records
- Guidance for decommissioning systems
- Decommissioning websites
- AS 5393:2025 Records and information management – Migration of authoritative data, information and records between systems
Microsoft 365 is used to create, capture and manage records but must be configured, governed and monitored to meet compliance requirements. RIM professionals must be involved in design decisions, configuration changes and ongoing monitoring to ensure compliance with the State Records Act and the Standard on Records Management.
Work with RIM staff to:
- establish rules for where records are created, stored and managed (e.g. SharePoint, OneDrive, or EDRMS)
- design SharePoint and Teams site structures that reflect business functions and activities
- agree on naming conventions, taxonomy, and versioning settings
- define mandatory and optional metadata aligned to business classification schemes
- define retention policies and labels that align with authorised records retention and disposal authorities
- implement technical controls to prevent indefinite retention of records, information and data
- establish authorised disposal processes, including retaining evidence of destruction
- define access rules for records, including for sensitive or high‑value records
- mitigate oversharing and unintended AI exposure risks.