Identifying records risks
- View
Risk identification is the step that finds, recognises and describes the things that could affect records objectives. You cannot assess or treat a risk you have not named, so this stage aims for breadth: cast widely across people, process, technology and environment before narrowing. ISO 31000 places identification at the front of the assessment process, and for records it is best done against the full information lifecycle - creation, capture, use, maintenance and disposition.
Sources of records risk
Structured prompts stop identification from drifting to only the obvious threats. Work through recognised categories:
- Physical - fire, flood, pests, poor storage climate, theft and handling damage to paper, film and objects.
- Digital preservation - format obsolescence, bit rot, media decay and broken dependencies, the very risks OAIS (ISO 14721) and PREMIS preservation metadata exist to manage.
- Security - unauthorised access, ransomware, insider misuse and weak access control, the domain of ISO 27001 Annex A.
- Governance - missing or unenforced retention schedules, orphaned systems, undocumented custody and shadow repositories.
- Human and metadata - misfiling, poor description, and thin or inconsistent metadata that leaves records unfindable even when preserved.
Techniques that surface them
Combine several methods, because each has blind spots. Process walkthroughs and system inventories reveal where records live; interviews and workshops capture tacit knowledge; incident and audit logs show what has already failed; and a records survey mapped to ISO 16175 (principles for records in digital systems) exposes systems creating records with no controls at all.
Describing a risk well
A useful risk statement names the source, the event and the consequence - for example, "unmanaged retention in a legacy line-of-business system (source) could lead to illegal over-retention of personal data (event), triggering regulatory penalty and loss of trust (consequence)". Vague entries like "data loss" cannot be assessed or assigned an owner.
Key takeaways
- Identify risks across the whole lifecycle using category prompts: physical, digital preservation, security, governance and human/metadata.
- Blend techniques - walkthroughs, inventories, interviews, incident logs and an ISO 16175-mapped survey.
- Write each risk as source-event-consequence so it can be owned, assessed and treated.