Risk identification is the step that finds, recognises and describes the things that could affect records objectives. You cannot assess or treat a risk you have not named, so this stage aims for breadth: cast widely across people, process, technology and environment before narrowing. ISO 31000 places identification at the front of the assessment process, and for records it is best done against the full information lifecycle - creation, capture, use, maintenance and disposition.

Sources of records risk

Structured prompts stop identification from drifting to only the obvious threats. Work through recognised categories:

  • Physical - fire, flood, pests, poor storage climate, theft and handling damage to paper, film and objects.
  • Digital preservation - format obsolescence, bit rot, media decay and broken dependencies, the very risks OAIS (ISO 14721) and PREMIS preservation metadata exist to manage.
  • Security - unauthorised access, ransomware, insider misuse and weak access control, the domain of ISO 27001 Annex A.
  • Governance - missing or unenforced retention schedules, orphaned systems, undocumented custody and shadow repositories.
  • Human and metadata - misfiling, poor description, and thin or inconsistent metadata that leaves records unfindable even when preserved.

Techniques that surface them

Combine several methods, because each has blind spots. Process walkthroughs and system inventories reveal where records live; interviews and workshops capture tacit knowledge; incident and audit logs show what has already failed; and a records survey mapped to ISO 16175 (principles for records in digital systems) exposes systems creating records with no controls at all.

Describing a risk well

A useful risk statement names the source, the event and the consequence - for example, "unmanaged retention in a legacy line-of-business system (source) could lead to illegal over-retention of personal data (event), triggering regulatory penalty and loss of trust (consequence)". Vague entries like "data loss" cannot be assessed or assigned an owner.

In practice. Run identification as a facilitated workshop with records, IT, legal and a business unit in the room together. The IT team knows where the servers are; the business knows which records actually matter and why - neither group can build a complete picture alone.

Key takeaways

  • Identify risks across the whole lifecycle using category prompts: physical, digital preservation, security, governance and human/metadata.
  • Blend techniques - walkthroughs, inventories, interviews, incident logs and an ISO 16175-mapped survey.
  • Write each risk as source-event-consequence so it can be owned, assessed and treated.

Check your understanding

Last modified: Saturday, 1 August 2026, 10:37 AM