Risk fundamentals for records
- View
Risk is the effect of uncertainty on objectives - the definition carried by ISO 31000, the international standard for risk management. For records and information professionals, those objectives are the qualities that make a record trustworthy: authenticity, reliability, integrity and usability, as set out in ISO 15489-1. A records risk is therefore anything that could compromise the ability of a record to serve as evidence of a business activity for as long as it is needed.
Treating records risk as a distinct discipline matters because information failures rarely announce themselves. A corrupted file, a lost retention rule or an unauthorised deletion may go unnoticed for years, surfacing only when the record is needed for litigation, audit or accountability - the moment when it can no longer be recreated.
What is actually at risk
Records carry value along several axes, and a threat to any one of them is a records risk:
- Evidential value - the record's capacity to prove what happened, underpinned by a documented chain of custody.
- Availability - the right people can find and access the record when required.
- Integrity - the content and its metadata remain complete and unaltered, or changes are controlled and logged.
- Compliance - retention, disposal and privacy obligations are met, avoiding both premature destruction and illegal over-retention.
A shared vocabulary
Aligning terms with ISO 31000 and its companion vocabulary ISO Guide 73 keeps a programme coherent. A threat or event is a potential occurrence; a vulnerability is a weakness it can exploit; likelihood and consequence combine into the level of risk; and a control is a measure that modifies risk. This vocabulary connects records work to enterprise risk and to ISO 27001 information security management, so records risk is not siloed.
Key takeaways
- Records risk is the effect of uncertainty on authenticity, reliability, integrity and usability (ISO 15489 within the ISO 31000 frame).
- Value sits in evidence, availability, integrity and compliance - a threat to any one is a records risk.
- Use ISO 31000 / Guide 73 vocabulary so records risk integrates with enterprise and information-security management.