Governance

Under review. Expected release date by July 2027.

6.1.1 Governance framework

6.1.1.1 PSOs must establish governance frameworks to ensure records and information are managed in accordance with the requirements of the regulatory environment in which the PSO operates.

  • The regulatory environment can consist of legislation and regulations; mandatory standards of practice; voluntary codes of practice; and community expectations regarding sector specific accountability and organisational behaviour.
  • A risk management approach should be taken to allow the sharing and re-use of records and information within government, the community and industry.
  • Records and information management processes and systems should be regularly monitored and reviewed to ensure compliance with business needs and the regulatory environment.
  • Records and information are managed in a manner which preserves their evidential integrity through system migrations and machinery of government changes.

6.1.1.2 Records must document the complete range of business undertaken by the organisation.

6.1.1.3 A custodian must be identified as the responsible officer for the management of record and information assets.

6.1.2 Policies and procedures

6.1.2.1 The records governance framework must include the development and implementation of policies and procedures which control the creation, capture, management and disposal of records.

  • Records and information management policies and procedures are approved by the PSO Chief Executive Officer or appropriate delegate.
  • Records management responsibilities are described, assigned and promoted to all personnel. Appropriate records management training is provided to all Personnel.
  • Records and information management requirements are integrated into standard operating procedures, systems and business practices to ensure records which meet the recordkeeping obligations of the organisation are created in the normal course of business.
  • Responsibility for ensuring that records and information management is integrated into work processes, systems and services is allocated to business owners, business units and their managers.

6.1.2.2 Contractual arrangements which a PSO enters into must include records and information management requirements, with provision for any sub-contractors to be subject to the same, where the contractor handles NTG records.

  • Agreements with service providers ensure full control and ownership by the NTG of any records or information for which a PSO is the responsible organisation.
  • Agreements with service providers include provisions which establish management and handling conditions of NTG records and information.

6.1.2.3 All contractual arrangements which relate to the handling of personal information must hold contractors and sub-contractors to the Information Privacy Principles as defined by the Information Act.

6.1.2.4 All contractual arrangements which relate to the handling of sensitive or security classified information must hold contractors and sub-contractors to the same security requirements that PSOs must adhere to.

6.1.3 Records management systems (RMS)

6.1.3.1 A PSO must capture and maintain records of its business into RMS and incorporate metadata with the record at the time of the activity or shortly afterwards.

  • RMS may incorporate a combination of automated and manual systems. These systems may be centralised or decentralised.
  • RMS are capable of using and supplying metadata to manage records in an accountable and effective way, regardless of the system or combination of systems being used, including details of hard-copy records

6.1.3.2 Disaster recovery and other back-up systems are not RMS and must not be used or relied on to provide evidence of the activities or operations of an organisation.

6.1.3.3 The organisation must define minimum metadata requirements for the capture and management of its records appropriate to the regulatory, business or industry environment in which it operates. (5)

  • Business systems being used as RMS should be designed to capture relevant metadata automatically.
  • Metadata is properly managed and preserved over time, including through system changes, upgrades and decommissioning.

6.1.3.4 RMS must have documented policies, assigned responsibilities and formal methodologies for their management.

  • Compliant RMS are managed to meet all requirements of the regulatory environment and arising from business and stakeholder expectations.

6.1.3.5 RMS must not allow unauthorised modifications to any records (including metadata), and where authorised modifications are performed, they must be fully documented.

6.1.3.6 When decommissioning or upgrading RMS a PSO must develop a strategy for the extraction and preservation of records in an appropriate format for migration or storage for later extraction.

  • System upgrades need to be planned and implemented methodically to safeguard the retention and usability of records for the full period of time they need to be retained.
  • It is important to properly plan and test migration processes for records requiring long-term retention to mitigate the effects of technological obsolescence.

6.1.3.7 The RMS must incorporate business rules that avoid duplication of records.

6.1.3.8 Recordkeeping must occur in all environments in which the organisation carries out its business.

  • Business systems which hold the only evidence or record of the business activity they transact should be considered a records management system for the purposes of this standard and be managed as a records management system.

6.1.3.9 PSOs must assess and document existing business systems to address risk associated with any lack of recordkeeping functionality.

  • Business systems, having been designed and built principally to automate a particular business process, may not have all the functionality of a purpose built records management system. (6)
  • Records held in business systems do not all have the same risk profiles. Business systems managing high-value/high-risk records should undergo a more extensive risk assessment than systems managing low-value/low-risk records.

6.1.3.10 When new business systems are being designed and implemented, or existing systems upgraded, incorporation of records management functionality must be considered.

  • PSO Records Managers should be consulted to determine system recordkeeping requirements.
  • Risk assessment of the level of evidence required to properly document the transactions in the business system should be used to identify any opportunities to improve records management functionality.

Read about the business system records management assessment questions for things to consider.

6.1.3.11 RMS must provide sufficient security for the long term storage and access of records.

6.1.3.12 RMS holding high-value/high-risk records must monitor and log access and event history.