Already a subscriber? Free Trial
Sign up for a 3 day free trial to explore the interface, PLUS access the
2009 International Building Code to see how it all works.
If you like to setup a quick demo, let us know at
or +1 800.798.9296 and we will be happy to schedule a webinar for you.
Security check
Please login to your personal account to use this feature.
Please login to your authorized staff account to use this feature.
Are you sure you want to empty the cart?

20/30415094 DC BS 10025. Records management. Code of practice, 2020
- 30415094_Form 36.pdf
- 30415094.pdf [Go to Page]
- Introduction
- 1 Scope
- 2 Normative references
- 3 Terms and definitions [Go to Page]
- 3.1 capture
- 3.2 IT application and/or system
- 3.3 IT infrastructure
- 3.4 jurisdiction
- 3.5 legal entity
- 3.6 organization
- 3.7 top management
- 3.8 worker
- 4 Principles of good practice for the management of records
- 5 Policy statements [Go to Page]
- 5.1 The top management of the organization should set a clear direction and demonstrate support for, and commitment to, the management of records, and its place in the organization’s business strategy, through the issue, endorsement and maintenance of...
- 5.2 A policy for the management of records should as a minimum specify:
- 5.3 The organization should set out how the policy is to be managed, including:
- 5.4 The organization should attach to the policy business rules for:
- 5.5 The policy and the attached business rules should be based on consultation with:
- 5.6 The policy and the attached business rules should be:
- 5.7 The policy and the attached business rules should be kept up-to-date so that they reflect the current needs of the organization. They should be reviewed at agreed intervals, for example annually, and after major organizational or technological cha...
- 5.8 The organization should publish its policy so that stakeholders to whom they are accountable can see the basis on which the organization manages its records.
- 6 Organizational arrangements [Go to Page]
- 6.1 The organization should recognize the management of records as a core corporate function, either separately or as part of a wider function that covers information security, business continuity, data protection or a combination of these and other r...
- 6.2 The organization should include the management of records in the risk management framework of the organization.
- 6.3 The organization should have a governance framework for the management of records that includes defined roles and responsibilities.
- 6.4 The organization should instruct workers to create, capture and manage records, as appropriate to their roles and responsibilities. These instructions should be applied to workers at all levels of the organization.
- 6.5 The organization should embed the management of records in their project and change management processes. In particular, there should be processes in place to manage records when:
- 6.6 The organization should provide training to make workers aware of the organization’s policy, business rules, standards, procedures and guidelines for the management of records and to understand their personal responsibilities.
- 6.7 The organization should develop, maintain and implement approved plans for delivering management of records in accordance with this British Standard. They should monitor and report progress (see Clause 13). The organization should build their plan...
- 7 Identifying, creating and capturing records to meet an organization’s requirements [Go to Page]
- 7.1 Identifying requirements for creation and capture [Go to Page]
- 7.1.1 The organization should establish what records it is likely to need to create about its activities, and the risks of not having those records, considering the need to:
- 7.1.2 Having established its broad requirements, the organization should establish:
- 7.1.3 The organization should determine whether any records should be subject to particular controls in order to be able to demonstrate that they:
- 7.1.4 Where a need has not otherwise been identified, the organization should establish criteria for what other records to capture; for example, records that are:
- 7.1.5 The organization should provide guidance on the management of records to be treated as ephemeral (records which are of little or no value), or which should be discarded as soon as they no longer need to be retained for the purpose for which they...
- 7.1.6 The organization should specify where records should be captured [for example, in a specific records system (see 8.2.1) or a particular file, folder or similar unit in a records system (see 8.2.3)].
- 7.2 Creating and capturing the records it has decided should be kept [Go to Page]
- 7.2.1 The organization should produce business rules covering requirements for creation and capture (see 7.1). They should be based on consultation with:
- 7.2.2 The business rules covering requirements for creation and capture should be:
- 7.2.3 The organization should make its workers aware of:
- 7.2.4 The organization should make workers creating or capturing records aware of the need to:
- 7.2.5 Managers within the organization should check and monitor that workers in the areas for which they are responsible are creating, capturing and managing the agreed records of their activities and they are available for use by the organization.
- 7.3 Making changes to records [Go to Page]
- 7.3.1 The organization should establish business rules for making changes to records and records systems (see 8.2.1). The rules should make it clear that some records are not allowed to be changed (see 7.1.3). Where changes can be made, the rules shou...
- 7.3.2 The business rules for changing records should be based on consultation with:
- 7.3.3 The business rules for changing records should be:
- 8 Organizing records for retrieval and management [Go to Page]
- 8.1 Building frameworks for effective retrieval and management [Go to Page]
- 8.1.1 The organization should create, maintain and use classification schemes when organizing records that reflect the actions of the organization, its objectives, functions, activities, processes and the steps taken to achieve its objectives. Classif...
- 8.1.2 The organization should structure and label their records to support and enable:
- 8.1.3 The organization should create and maintain a records metadata schema which sets out the records’ metadata elements, descriptions of each and how they are related.
- 8.2 Grouping records together into manageable units [Go to Page]
- 8.2.1 The organization should create and maintain records systems (or, alternatively, records series) and manage the records in them. Each records system should consist of records which have five common elements:
- 8.2.2 Records systems should be organized and structured to:
- 8.2.3 Within each records system, the organization should create units in which to accumulate records that are related or need to be managed together.
- 8.3 Keeping track of what records are held
- 9 Storing and maintaining records [Go to Page]
- 9.1 General recommendations for storage [Go to Page]
- 9.1.1 The organization should decide the media and format in which its records are to be stored and maintained. Where an organization creates and captures records electronically, they should hold the resulting records electronically unless there is a ...
- 9.1.2 The organization should determine if there is a need to create electronic versions of physical records, typically by using scanning technologies, to provide for:
- 9.1.3 Where records are held in a number of different media, formats, buildings and locations, organizations should have a method to connect them, for example a unique reference code such as an employee, customer or contract number.
- 9.1.4 The organization should develop and maintain business continuity plans which include actions to identify, protect and recover the records that are essential to the:
- 9.2 Managing storage of physical records (or the IT infrastructure containing records) [Go to Page]
- 9.2.1 The organization should provide storage that gives protection appropriate for the nature, contents and value of the records and IT infrastructure containing records.
- 9.2.2 The organization should assess and manage the potential hazards of a storage location (for example, the risk of flooding) and follow accepted standards for building construction, temperature and humidity control, and fire detection and extinguis...
- 9.2.3 The organization should regularly monitor records to check that they are still readable.
- 9.2.4 The organization should determine the need to move records that are no longer required for frequent reference from current IT applications and systems or office areas to off-line and/or off-site storage. When records are moved, they should conti...
- 9.3 Managing IT applications and systems [Go to Page]
- 9.3.1 The organization should design, develop and build IT applications and systems that they use to capture and hold records to support the :
- 9.3.2 The organization should put in place a strategy for the continuing maintenance of IT applications and systems to keep records intact, reliable and usable for as long as is required. The strategy should provide for updating of IT applications and...
- 9.3.3 The organization should assess the security risks to IT applications and systems and put appropriate safeguards in place (see Clause 10).
- 9.3.4 The organization should keep and maintain back-up copies of IT applications and systems to support the organization’s capacity to recover from system failures and major disasters. The organization should keep back-up copies securely in a separat...
- 10 Managing security and controlling access [Go to Page]
- 10.1 The organization should put in place arrangements for storage, handling and transmission of records that reflect accepted good practice in information security.
- 10.2 The organization should classify, label and manage their records to reflect their contents, value, criticality and sensitivity to unauthorized disclosure, modification and associated security risks.
- 10.3 Based on its security classification, the organization should apply restrictions on storage access, transfer and transmission when necessary to protect records. These should cover all types of communications and be kept up-to-date.
- 10.4 The organization should put in place access controls on IT infrastructure and IT applications and systems based on the nature and sensitivity of the records which include:
- 10.5 The organization should determine the need for and benefits of cryptography or other related techniques to protect the confidentiality and integrity of records in transit and storage.
- 10.6 The organization should put in place arrangements to prevent unauthorized physical access, damage and interference to buildings and IT infrastructure. This should include secure perimeters to protect areas that contain either sensitive or critica...
- 10.7 To ensure that workers fulfil their information security responsibilities and are suitable for their roles, the organization should:
- 10.8 The organization should follow sound security design principles when developing and modifying IT applications and systems such that they are built to be secure and reliable. IT applications and systems should be tested throughout their life, to i...
- 10.9 The organization should maintain an audit trail of access to records, to a level of detail proportionate to the sensitivity and value of the records in question.
- 10.10 The organization should manage and maintain their IT infrastructure to mitigate risks, including the use of measures such as:
- 10.11 The organization should establish and maintain an approach to responding to and managing security-related concerns, incidents and events. They should log them, investigate them in a timely manner, proportionate to the sensitivity and value of th...
- 11 Managing retention and organizing disposal [Go to Page]
- 11.1 Establishing and documenting how long records need to be retained [Go to Page]
- 11.1.1 The organization should produce retention schedules (or, alternatively, retention and disposal schedules) that cover the records of the whole organization. They should set out how long records are needed for:
- 11.1.2 Retention schedules should contain sufficient details to enable the relevant records to be easily identified and the disposal action applied to them on a routine and timely basis.
- 11.1.3 Retention schedules should be kept up-to-date. They should be amended if a relevant statutory provision or business need changes, to fill any identified gaps in coverage or where there is a lack of clarity in what record types fall within speci...
- 11.2 Organizing the disposal of redundant records [Go to Page]
- 11.2.1 The organization should define and operate rules for regular and systematic disposal of their records. These should cover:
- 11.2.2 The organization’s retention schedules (see 11.1) and business rules for disposal of records (see 11.2.1) should be based on consultation with:
- 11.2.3 The retention schedules and business rules for disposal should be:
- 11.3 Destroying redundant records and the IT infrastructure on which they are stored [Go to Page]
- 11.3.1 The organization should destroy records and the IT infrastructure on which they are stored in as secure a manner as required by the level of sensitivity or confidentiality or their security classification (see 10.2). Where records or IT infrast...
- 11.3.2 When destruction is carried out by an external contractor, the contract should stipulate that the security and access arrangements established for the records would continue to be applied until destruction has taken place.
- 11.3.3 Before records are marked as destroyed, all copies and parts of an aggregated record where the parts are stored in different IT application or systems and/or locations should have been destroyed with no possibility that the records could be rec...
- 11.3.4 Evidence of destruction should be kept indefinitely because the previous existence of records can be useful information. The level of detail and for how long it should be kept depends on an assessment of the costs and the risks to the organizat...
- 11.3.5 The organization should be able to provide evidence that destruction of a specified type of record of a specified age range took place in the daily course of business, in accordance with the provisions of the retention schedules and business ru...
- 11.4 Transferring records for permanent preservation
- 12 Managing an organization’s records held by another organization [Go to Page]
- 12.1 Records managed on behalf of the organization [Go to Page]
- 12.1.1 When the organization plans to have parts of the management of its records undertaken by another organization, it should define and document the scope of the areas covered.
- 12.1.2 Having established the requirements, the organization should establish that prospective organizations have the necessary skills, infrastructure and experience to deliver them as required.
- 12.1.3 When a supplier organization has been selected that meets the organization’s requirements, the applicable records requirements should form part of the contract.
- 12.1.4 The organization should undertake regular checks during the term of a contract to establish that the other organization continues to manage the records appropriately and in accordance with the contractual terms and specified service levels. At ...
- 12.2 Records produced as part of collaborative working [Go to Page]
- 12.2.1 When working in partnership with another organization, sharing records or contributing to a joint project, the organization should, before starting any arrangement, agree with all parties:
- 12.2.2 The organization should provide workers involved in collaborative working with instructions and appropriate training.
- 12.2.3 The organization should apply appropriate controls to records shared with or passed to another organization so that the records continue to be managed in accordance with this British Standard.
- 13 Monitoring and reporting on the management of records [Go to Page]
- 13.1 The organization should identify performance measures that reflect their needs for records, set out in the policy and business rules (see Clause 5), and the risks that non-compliance with this British Standard would present to the organization, i...
- 13.2 The performance measures should include that:
- 13.3 The organization should evaluate the benefits of automating monitoring using monitoring, analysis and reporting tools, either within IT applications or systems or independent data analysis tools.
- 13.4 The organization should apply qualitative measures, for example whether guidance is being followed. These can be measured by spot checks or by interviews.
- 13.5 To measure improvement, baseline measures should be undertaken prior to any improvement action being undertaken, and targets for improvement agreed.
- 13.6 The organization’s monitoring and compliance should be based on consultation with all parts of the organization and cover the whole organization, including any of the organization’s records held by another organization (see Clause 12).
- 13.7 Monitoring should be undertaken on a regular basis and results reported to the person with lead responsibility for the management of records in the governance structure (see 6.3), so that risks can be assessed, and appropriate action taken. [Go to Page]