Risk is the effect of uncertainty on objectives - the definition carried by ISO 31000, the international standard for risk management. For records and information professionals, those objectives are the qualities that make a record trustworthy: authenticity, reliability, integrity and usability, as set out in ISO 15489-1. A records risk is therefore anything that could compromise the ability of a record to serve as evidence of a business activity for as long as it is needed.

Treating records risk as a distinct discipline matters because information failures rarely announce themselves. A corrupted file, a lost retention rule or an unauthorised deletion may go unnoticed for years, surfacing only when the record is needed for litigation, audit or accountability - the moment when it can no longer be recreated.

What is actually at risk

Records carry value along several axes, and a threat to any one of them is a records risk:

  • Evidential value - the record's capacity to prove what happened, underpinned by a documented chain of custody.
  • Availability - the right people can find and access the record when required.
  • Integrity - the content and its metadata remain complete and unaltered, or changes are controlled and logged.
  • Compliance - retention, disposal and privacy obligations are met, avoiding both premature destruction and illegal over-retention.

A shared vocabulary

Aligning terms with ISO 31000 and its companion vocabulary ISO Guide 73 keeps a programme coherent. A threat or event is a potential occurrence; a vulnerability is a weakness it can exploit; likelihood and consequence combine into the level of risk; and a control is a measure that modifies risk. This vocabulary connects records work to enterprise risk and to ISO 27001 information security management, so records risk is not siloed.

In practice. Because ISO management-system standards share the common Annex SL structure, a records risk register can plug straight into an organisation's existing ISO 27001 or ISO 9001 risk process. Use the same scales and reporting lines rather than inventing a parallel system that leadership will ignore.

Key takeaways

  • Records risk is the effect of uncertainty on authenticity, reliability, integrity and usability (ISO 15489 within the ISO 31000 frame).
  • Value sits in evidence, availability, integrity and compliance - a threat to any one is a records risk.
  • Use ISO 31000 / Guide 73 vocabulary so records risk integrates with enterprise and information-security management.

Check your understanding

Last modified: Saturday, 1 August 2026, 10:37 AM