Aratohu whakahaere
Implementation guide
We’ve created this guide to help your organisation understand and apply the requirements of the Information and records management standard.
The Chief Archivist issued the Information and records management standard (16/S1) (the Standard) on 22 July 2016.
The purpose of the Standard is to ensure that business is supported by sound integrated information and records management in complex business and information environments. This approach better reflects the way most organisations now manage their information assets.
Formats covered by the Standard
The Standard covers information and records in any format. It’s designed to support digital recordkeeping as the public sector continues transitioning to digital business processes.
Earlier standards
This Standard is the result of consolidating and streamlining requirements from these Archives New Zealand standards:
Records Management Standard for the New Zealand Public Sector 2014
S4 Access Standard 2006
S5 Digital Recordkeeping Standard 2010
AS/NZS ISO 13028: 2012, Information and documentation – Implementation Guidelines for digitization of records.
These standards have been revoked as standards issued by the Chief Archivist and incorporated into this Standard. Note, this does not mean revoked as an International Standards Organisation (ISO) standard or any other standard issued by another authority or legislation.
Further requirements for local authorities and approved repositories
Local authorities and approved repositories must follow the:
How to implement the Standard
The Standard sets out 3 principles.
Principle 1 — Organisations are responsible for managing their information and records.
Principle 2 — Information and records management supports business.
Principle 3 — Information and records are well managed.
Under each principle are listed:
the minimum compliance requirements
an explanation for each requirement, and
key guidance for implementing the requirements.
This guidance will be regularly added to.
Other guidance to use
Public offices and local authorities should use our Information Management Maturity Assessment and user guide to assess the strengths and weaknesses of their information and records management programmes. This helps determine where improvements are most needed.
Principle 1 - Organisations are responsible for managing information and records
To ensure information and records can support all business functions and operations, organisations must establish a governance framework. This framework will help you to:
develop strategies and policies to direct how information and records will be managed
assign responsibilities and allocate resources
establish provisions for information and records management in outsourcing and service delivery arrangements
monitor information and records management activities, systems and processes.
1.1 Information and records management must be directed by strategy and policy, and reviewed and monitored regularly
Governance frameworks are critical to the achievement of effective information and records management. Your organisation must set a high-level strategy and policy for managing its information and records. The Administrative Head of your organisation must adopt it.
Your strategy and policy should include:
appointment of an Executive Sponsor to oversee information and records management – requirement 1.2
clear requirements for the creation, capture and management of information and records – requirement 3.1
setting an information security policy – requirement 3.4
identifying and assigning responsibilities of senior management for information and records management – requirement 1.2
identifying the need for information and records management staff or skills (do this through performance plans and/or service agreements) – requirement 1.4
identifying business owners responsible for including information and records management in all systems and processes – requirement 1.5
setting information and records management responsibilities for staff and contractors – requirement 1.6
addressing information and records management in all service arrangements – requirement 1.7
implementing an information security policy and appropriate security mechanisms – requirement 3.4
implementing policies (and business rules and procedures) to ensure that information and records are kept for as long as they are required and to identify how their disposal is managed – requirement 3.6
implementing policies to identify how to manage the disposal of information and records – requirement 3.7.
Key guidance
1.2 Information and records management must be the responsibility of senior management. Senior management must provide direction and support to meet business requirements as well as relevant laws and regulations
Ultimate responsibility for information and records management lies with your organisation’s Administrative Head and senior management. They must provide direction and support, and ensure:
information and records management meets business requirements, the law and regulations
responsibility for information and records management cascades down throughout the organisation, through various levels of management
responsibilities are identified and assigned in strategy and policy.
This requirement mirrors legislative obligations — for example in the Public Service Act 2020 (s.52) and the Local Government Act 2002 (s.42(2)). It also reinforces the need for the Administrative Head and senior management to provide high-level direction and support — including ensuring adequate resourcing for information and records management.
Key guidance
1.3 Responsibility for the oversight of information and records management must be allocated to a designated role (the Executive Sponsor)
Thisrequirement clarifies what was implicit in the previous standards.
Your Executive Sponsor oversees information and records management. They must be a senior manager with organisation-wide influence and appropriate strategic and managerial skills. Their role is to:
provide oversight of information and records management within your organisation— including monitoring of information and records management — to ensure it meets the needs of the organisation
ensure responses to monitoring and reporting requests from us.
Include the establishment of this role in your policies and strategies for information and records management. The Executive Sponsor’s role should be incorporated into their performance plan. You must advise us of your Executive Sponsor, including when they’re appointed and when the role changes hands.
Key guidance
1.4 Organisations must have information and records management staff, or access to appropriate skills
Your organisation must have staff with information and records management skills — or be able to access this expertise.
Each organisation’s information and records management strategy will likely need a range of different levels of responsibility and skills. Reflect this in job descriptions.
You must be able to access information and records management skills through recruitment, service providers and by networking with other organisations.
You must identify and assign staff responsibilities through strategy and policy, performance plans or service agreements.
Key guidance
1.5 Business owners and business units must be responsible for ensuring that information and records management is integrated into business processes, systems and services
This requirement clarifies what was implicit in the previous standards.
You must identify business and system owners who are responsible for ensuring information and records management is included in all systems and processes used.
Those owners must be aware that information and records management requirements are needed when your organisation:
moves to a new service environment
develops new business processes, systems or services, or
changes existing business processes, systems or services.
These responsibilities must be identified and assigned in policies and within performance plans.
Business owners must demonstrate that they’ve considered information and records management requirements and assessed risks as part of any migration, development or improvement of systems or processes.
This requirement places responsibilities more broadly within your organisation. It reflects the need for business managers to have a detailed understanding of the information and records produced by — and necessary to perform — their work, and their role in ensuring its management.
Cascading responsibility to different business areas of your organisation enables business unit staff and information and records staff work together to ensure information and records management is integrated into all business processes, systems and services.
Key guidance
- Integrated information and records systems ⟩
- Microsoft 365 ⟩
- Information and records management strategy ⟩
- Information assets overview ⟩
- Information assets - Identification ⟩
- Information assets – Management ⟩
- Managing websites as records ⟩
- Web archiving ⟩
- Information Asset Catalogue Template | NZ Digital government ⟩
- ISO 15489-1 Information and documentation - Records Management Part 1: Concepts and principles ⟩
- AS/NZS ISO 30302 Information and documentation – Management systems for recordkeeping – Guidelines for implementations ⟩
1.6 Staff and contractors must understand the information and records management responsibilities of their role. They must understand relevant policies and procedures
All staff of your organisation — including contractors — must understand their information and records management responsibilities.
Policies, business rules and procedures must include clear requirements for staff when creating and managing information and records.
Your organisation may contract external service providers to perform specified tasks. Information and records produced and managed in their performance of the contracted services need to be covered by your organisation’s policies and procedures. And contractors must know their information and records management responsibilities and the relevant policies and procedures.
Information and records management responsibilities must be identified and assigned in policies. Skills, capabilities and responsibilities must be assigned in role descriptions and performance plans.
Key guidance
1.7 Information and records management responsibilities must be identified and addressed in all outsourced and service contracts, instruments and arrangements
This requirement clarifies what was implicit in the previous standards.
Your organisation must ensure information and records management is addressed in all service contracts, instruments and arrangements.
Your organisation’s strategy and policy must include responsibilities to ensure information and records requirements are identified and addressed. You must undertake risk assessments and address information and records management requirements in contracts, instruments and arrangements your organisation agrees to.
Service contracts, instruments and arrangements may include:
functions, activities, or services outsourced to an external provider
functions, activities, or services moved to cloud services or other service providers (internal or external to the New Zealand public sector).
You must ensure the portability of your organisation’s information and records and associated metadata is assessed and appropriately addressed in any outsourced and service contracts, instruments and arrangements.
Key guidance
1.8 Information and records management must be monitored and reviewed to ensure that it is accurately performed and meets business needs
Your organisation must regularly monitor its information and records management activities, systems and processes to ensure they’re meeting your needs and conforming to any legislative requirements. You must address any issues identified through this monitoring in a corrective action plan.
You must monitor activities such as process and system audits of systems that are high-risk, high-value, or both. You should integrate any system of assurance for information and records management into your wider organisational assurance processes.
Your Executive Sponsor has responsibility for overseeing this monitoring.
Key guidance
Principle 2 - Information and records management supports business
Information and records management ensures the creation, usability, maintenance and sustainability of the information and records needed for your organisation’s business operations. It also ensures these operations meet government and community expectations.
By appraising your organisation’s business activities, you can define its key information and records requirements. Appraisal is an analysis process used to plan, design and embed information and records management into business processes and systems.
Taking a planned approach to information and records management means:
considering all operating environments
ensuring all service and systems arrangements consider the creation and management of information and records needed to support business.
2.1 Information and records required to support and meet business needs must be identified
This requirement provides the foundation for managing information and records in all environments.
By analysing your organisation’s functions, activities and risks, you can identify what information and records it needs to support business. This analysis can also identify other requirements, including te Tiriti o Waitangi Treaty of Waitangi obligations, and government and community expectations.
This analysis work provides the foundation for understanding what information and records to keep. It identifies what systems and business processes are high-risk and high-value for your organisation, and the information and records required to support these.
You should incorporate this analysis into comprehensive and authorised disposal authorities for your organisation’s information and records.
Decisions about what information and records are required should be documented in your organisation’s business rules, policies and procedures. These decisions must also be reflected in specifications for systems and metadata schema.
Key guidance
- High value and high risk information and records ⟩
- Appraisal of information and records ⟩
- Information assets overview ⟩
- Information assets - Management ⟩
- Information assets - Identification ⟩
- Disposal authorisation ⟩
- Te Tiriti o Waitangi settlements and government records ⟩
- Information and records management policy development ⟩
- Information Asset Catalogue Template | NZ Digital government ⟩
- ISO 15489-1 Information and documentation - Records management Part 1 - Concept and principles, section 7 ⟩
- Association of Local Government Information Management (ALGIM) - Information Management Toolkit ⟩
2.2 High risk and high value areas of business, and the information and records needed to support them, must be identified and regularly reviewed
Your organisation must identify the areas of high risk, high value, or both of its business. This allows you to better prioritise how you manage, maintain the information and records they need.
You must identify the likely or potential risks to information and records and manage or mitigate them. This includes protecting the systems that manage information and records that are high-risk, high-value, or both, from loss and damage.
You should set up appropriate security measures and business continuity strategies and plans.
By identifying high-risk and high-value information and records at creation, your organisation can better manage and use these core assets.
Key guidance
- High value and high risk information and records ⟩
- Information assets overview ⟩
- Information assets - Identification ⟩
- Information assets – Management ⟩
- Information Asset Catalogue Template | NZ Digital government ⟩
- Data.govt.nz New Zealand Data and Information Management Principles ⟩
- NZ Digital government Security ⟩
- NZ Digital government Privacy ⟩
- SA/SNZ HB 436 Risk management guidelines – Companion to AS/NZS ISO 31000 ⟩
- AS/NZS 5050 Business continuity: managing disruption-related risk ⟩
- ISO 15489-1 Information and documentation - Records Management Part 1: Concepts and principles ⟩
- SA/SNZ TR 18128 Information and documentation - Risk assessment for records processes and systems ⟩
- Association of Local Government Information Management (ALGIM) - Information Management Toolkit ⟩
2.3 Information and records management must be design components of all systems and service environments where high-risk/high-value business is undertaken
This requirement clarifies what was implicit in the previous standards.
In complex business and systems environments, it is important to design information and records management from the start. This is particularly important where the business involved is high-risk, high-value, or both.
Include information and records management requirements when you design or update systems and service environments which manage high-risk and/or high-value information and records. This will enable you to better manage and use the information and records.
Your organisation must also consider at the start how to make system maintenance, migrations and decommissioning easier. In taking a ‘by design’ approach, you must ensure systems specifications include:
requirements for managing information and records that are high-risk, high-value, or both
requirements for minimum metadata needed to support information and records identification, usability, accessibility and context
documentation about systems design, configuration and any changes made over time.
Migrating and decommissioning systems can be expensive and time-consuming. Your organisation may hold insufficient documentation about:
the information and records held in the systems
the configuration of the systems
the disposal requirements for information and records held in the systems.
Key guidance
- Integrated information and records systems ⟩
- Metadata for information and records ⟩
- Minimum requirements for metadata ⟩
- Authority to retain public records in electronic form only ⟩
- Destruction of source information after digitisation ⟩
- Effective information and records management ⟩
- Taonga Tuku Iho ⟩
- Managing websites as records ⟩
- Web archiving ⟩
- AS/NZS 5478 Recordkeeping metadata property reference set ⟩
- ISO 15489-1 Information and documentation - Records Management Part 1: Concepts and principles ⟩
- AS/NZS ISO 13028 Information and documentation - Implementation guidelines for digitization of records ⟩
2.4 Information and records must be managed across all operating environments
Physical information and records are only part of your organisation’s ‘operating environment’ and this requirement widens the Standard to better cover digital information and records.
If you know what information and records assets your organisation has — and where they’re located and managed — you can better control them. By maintaining visibility of information and records, no matter what system is used or where the information and records are stored, your organisation can better protect these assets.
Information and records assets can be held in diverse systems environments, including third-party systems in the cloud, by service providers, and in a range of physical locations.
By identifying where your information and records are held, you can better manage them across diverse systems, storage environments or physical locations — and control their appropriate access.
Key guidance
- Integrated information and records systems ⟩
- Authority to retain public records in electronic form only ⟩
- Destruction of source information after digitisation ⟩
- Managing information and records during administrative change ⟩
- Cloud services ⟩
- Best practice guidance on digital storage and preservation ⟩
- Text messages and other communications ⟩
- Storage of physical records ⟩
- Information assets overview ⟩
- Information assets - Identification ⟩
- Information assets – Management ⟩
- Managing websites as records ⟩
- Web archiving ⟩
- Audiovisual storage ⟩
- Care of motion picture film ⟩
- Data.govt.nz New Zealand Data and Information Management Principles ⟩
- NZ Digital government Security ⟩
- NZ Digital government Privacy ⟩
- AS/NZS ISO 13028 Information and documentation - Implementation guidelines for digitization of records ⟩
- Association of Local Government Information Management (ALGIM) - Information Management Toolkit ⟩
2.5 Information and records management must be designed to safeguard information and records with long-term value
This requirement ensures that your organisation identifies which systems and service environments hold information and records with long-term business value. This requirement builds on Requirements 2.1 and 2.2.
Once you know what information and records your organisation needs long-term and where they’re kept, you can safeguard and manage them.
Information and records required for the long term will outlive both the systems in which they’re managed, as well as any outsourcing arrangements or contracts with service providers. You must ensure you plan and manage the protection of long-term information and records during any system transitions or service changes.
Your organisation must protect its long-term information and records during changes in administration and through changes in the machinery of government. This includes when information and records are transferred between organisations with functions.
To help with identifying long-term information and records, you should refer to your organisation’s authorised disposal authorities.
Key guidance
2.6 Information and records must be maintained through systems and service transitions by strategies and processes specifically designed to support business continuity and accountability
This requirement makes the Standard’s focus more explicit to include both physical and digital information and records.
Your organisation must ensure that information and records are managed appropriately through system migrations and service transitions — including upgrades of systems and services offered in cloud environments.
You must have documented migration strategies and appropriate planning and testing processes. These must ensure information and records are not ‘left behind’ or disposed of unlawfully.
You must use a managed process to migrate information and records and associated metadata from one system to another. The process must be managed to deliver information and records that are accessible, reliable and trustworthy. Maintaining appropriate system documentation will help to make migration strategies successful.
You must use migration and decommissioning processes that ensure information and records are kept for as long as needed for business, legal requirements (including in line with authorised disposal authorities), and government and community expectations.
This requirement builds on requirements 2.2 and 2.5. These require that information and records that are high-risk, high-value, and/or of long-term value, are supported and migrated appropriately.
The portability of information and records and associated metadata must be assessed in any outsourced or service arrangements your organisation has. Such arrangements must include provisions for transferring the information and records back to your organisation.
Key guidance
Principle 3 - Information and records are well managed
Effective management underpins trustworthy and reliable information and records that are accessible, usable, shareable and maintained. This management extends to information and records in all:
formats (and associated metadata)
business environments
types of systems
locations.
3.1 Information and records must be routinely created and managed as part of the normal business practice
Policies, business rules and procedures must inform staff in your organisation their responsibilities for creating, capturing and managing information and records.
Your organisation must regularly monitor and assess or audit its information and records management practices to demonstrate that these business rules, procedures and systems are operating routinely.
You must identify, resolve and document any exceptions affecting the creation, integrity, accessibility and usability of your organisation’s information and records.
Your organisation’s staff and contractors must conform to these policies, business rules and procedures, to ensure information and records are routinely created and managed.
The Executive Sponsor is responsible for overseeing this monitoring. This requirement builds on the earlier principles in the Standard.
Key guidance
3.2 Information and records must be reliable and trustworthy
Your organisation’s information and records must have enough metadata to ensure they are reliable and trustworthy.
Information and records must be accurate, authentic and reliable as evidence of your organisation’s transactions, decisions and actions. This requirement ensures information and records have appropriate minimum metadata to provide meaning and context — including te reo Māori terms — and that this metadata remains associated or linked.
You must undertake regular assessments or audits to demonstrate your management controls of business rules, procedures and systems are operating correctly. This provides assurance of the integrity of the information and records created and managed by your organisation.
This requirement builds on the earlier principles in the standard.
Key guidance
- Metadata for information and records ⟩
- Minimum requirements for metadata ⟩
- Checksums overview ⟩
- AS/NZS 5478 Recordkeeping metadata property reference set ⟩
- ISO 15489-1 Information and documentation - Records Management Part 1: Concepts and principles ⟩
- ISO 23081-1 Metadata for records - Principles ⟩
- AS/NZS ISO 23081-2 Metadata for records - Conceptual and implementation issues ⟩
- AS/NZS ISO 23081-3 Managing metadata for records - Self assessment method ⟩
- Association of Local Government Information Management (ALGIM) - Information Management Toolkit ⟩
3.3 Information and records must be identifiable, retrievable, accessible and usable for as long as they are required
Your organisation’s information and records must be identifiable, retrievable from storage (physical or digital), and accessible, usable and reusable for as long as required.
To maintain the accessibility and usability of physical information and records, you must store them in appropriate storage areas and conditions.
To maintain the accessibility and usability of digital information and records, you must ensure they are regularly migrated or moved from one system or platform to another.
You must associate or link appropriate minimum metadata (including te reo Māori terms) to information and records to ensure they can be identified, retrieved and shared.
Your organisation must regularly test all systems holding information and records. You must also perform assessments or audits to demonstrate these systems can locate and produce information and records that people can read and understand.
This requirement builds on the earlier principles in the standard.
Key guidance
- Public access to information and records ⟩
- Care of motion picture film ⟩
- Audiovisual storage ⟩
- Storage of physical records ⟩
- Best practice guidance on digital storage and preservation ⟩
- Metadata for information and records ⟩
- Minimum requirements for metadata ⟩
- Maintenance of public archives ⟩
- data.govt.nz - Open data toolkit ⟩
- NZ Digital government Security ⟩
- NZ Digital government Privacy ⟩
- ISO 15489-1 Information and documentation - Records Management Part 1: Concepts and principles ⟩
- Association of Local Government Information Management (ALGIM) - Information Management Toolkit ⟩
3.4 Information and records must be protected from unauthorised or unlawful access, alteration, loss, deletion and/or destruction
Your organisation must protect its information and records.
You must implement an information security policy and appropriate security mechanisms. The policy must cover information and records held physically or digitally, or both.
Security measures must include:
access and use permissions in all systems holding information and records
processes to protect information and records no matter where they are located — including in transit and outside the workplace
secure physical storage facilities.
Undertaking regular assessments or audits will help you verify that access controls have been implemented appropriately and are working.
Key guidance
- Maintenance of public archives ⟩
- Physical storage and preservation of protected information ⟩
- Access decisions ⟩
- Public access to information and records ⟩
- Storage of physical records ⟩
- NZ Digital government Security ⟩
- NZ Digital government Privacy ⟩
- Ombudsman - Official information guides ⟩
- ISO 15489-1 Information and documentation - Records Management Part 1: Concepts and principles ⟩
- Association of Local Government Information Management (ALGIM) - Information Management Toolkit ⟩
3.5 Access to, use of, and sharing of information and records must be managed appropriately in line with legal and business requirements
This requirement builds on the requirements in Part 3 of the Public Records Act 2005.
Your organisation must ensure that access to, use and sharing of information and records are in line with legal requirements including:
the Official Information Act 1982
the Local Government Official Information and Meetings Act 1987
the Privacy Act 2020
the Health Information Privacy Code 1994
organisational policies, business rules and procedures.
Undertaking regular assessments or audits of systems holding information and records will help you verify that access to, use and sharing of these information and records is managed in line with business requirements, legal obligations and the Government ICT Strategy or Action Plan (where appropriate).
Key guidance
3.6 Information and records must be kept for as long as needed for business, legal and accountability requirements
Your organisation must implement policies, business rules and procedures to ensure information and records are kept for as long as required — and to identify how their disposal or final fate is managed.
These policies, business rules and procedures must be in accordance with the requirements of the Public Records Act 2005 (the Act) and authorised disposal authorities.
Your physical and digital information and records must be sentenced and disposed of in line with the instructions set out in disposal authorities authorised under the provisions of section 20 of the Act. This includes information and records located in business systems, in outsourced or service arrangements, or in offsite storage.
Information and records of permanent value identified as public or local authority archives must be transferred to us, an approved repository or a local authority archive, when authorised and no longer needed for business purposes.
Key guidance
- List of protected records for local authorities ⟩
- List of protected records for local authorities - Explanatory notes ⟩
- Download GDA6 and GDA7 ⟩
- Authority to retain public records in electronic form only ⟩
- Disposal sentencing ⟩
- Destruction of source information after digitisation ⟩
- Methods of destruction ⟩
3.7 Information and records must be systematically disposed of when authorised and legally appropriate to do so
This requirement builds on the earlier principles in the Standard.
Your organisation must implement policies, business rules and procedures that identify how the disposal or final fate of information and records is managed. This includes:
assigning responsibility for sentencing and disposal of information and records (sentencing is the action of using a disposal authority to decide whether to keep, destroy or transfer information and records)
applying disposal authorisation processes
implementing disposal actions
deleting metadata
decommissioning systems
documenting the disposal of information and records.
You must be able to account for the disposal of your information and records in business systems, outsourced arrangements and offsite storage. This includes maintaining evidence that the disposal of information and records is permitted and authorised under disposal authorities and legal obligations — including the Public Records Act 2005.