Glossary
Information governance
Also called: IG
Information governance is the framework of accountability, policies and controls determining how an organisation creates, uses, retains and disposes of its information. Records management and data protection are components of it rather than alternatives to it or to each other.
Information governance explained
What it covers
Ownership of information, classification, retention and disposal, access and security, quality, and the accountability for each. It is the layer above the individual disciplines, and its purpose is to stop them being solved in isolation — which is how organisations end up with a retention schedule that conflicts with their privacy notice.
Where the disciplines overlap
Data protection requires personal data not be kept longer than necessary. Records management requires records be kept as long as required and then disposed of. Security requires access be limited to those who need it. All three are answered by a retention schedule, a classification scheme and a permission model — the same three artefacts, requested by three functions.
Organisations that recognise this build them once. Organisations that do not build three overlapping versions that disagree.
Why it fails
Almost always ownership. A framework owned by a committee is a framework nobody updates, and the most common failure is not a wrong policy but an unmaintained one. A named individual with authority to decide is the single strongest predictor of whether a programme works.
The honest measure
Not how much is classified correctly, but how much is not — unclassified records, unowned policies, and shares nobody has reviewed. Those numbers are uncomfortable and they are the ones worth reporting.
FAQ
Information governance: common questions
Is information governance the same as data governance?
They overlap heavily; data governance usually emphasises structured data, quality and lineage, while information governance emphasises documents, records and retention. In practice the distinction matters less than having one owner for both.
Who should own it?
One named person with authority, reporting somewhere senior enough that a decision they make sticks. A committee can advise; it cannot own.
Related terms
- Audit trailAn audit trail is an append-only record of every action taken on a document — views, downloads, edits, approvals, permission changes and deletions — with the acting user, timestamp and affected version.
- Chain of custodyChain of custody is the documented, unbroken record of who has held, accessed or altered an item of evidence, and when.
- DispositionDisposition is what happens to a record when its retention period expires: destruction, transfer to an archive, or a decision to extend.
- Document controlDocument control is the discipline of ensuring only approved documents are in use, superseded ones cannot be mistaken for current, and every change is authorised and recorded.
- Legal holdA legal hold suspends the routine destruction of records that may be relevant to litigation, an investigation or an audit.
- Records managementRecords management governs how long a document is kept and what happens at the end of that period.
Última revisión: 28 de agosto de 2026. Browse the full glossary.