Contellect glossaryCapture and understand

What is Information Governance?

Policy, ownership and disposal authority across every system that holds information.

Information governance is the framework of policies, ownership and controls that determines how an organization classifies, retains, protects and disposes of the information it holds, and who is accountable for each of those decisions.

The defining feature is accountability. A policy that names no owner is a statement of intent, and information governance is the discipline of turning intent into decisions someone is answerable for.

Governance, management and data governance are not the same scope

The three terms are used interchangeably and cover different ground.

Information governance sets the rules: what categories of information exist, how long each is kept, who may see it, who may authorize its destruction, and what evidence is retained about those acts. It is deliberately system-agnostic, because the same obligation applies whether the content sits in a repository, a mailbox, a file share or a chat history.

Information management executes those rules in specific systems. A document management system enforces versioning, permissions and retention for the content inside it. It cannot enforce anything about content held elsewhere, which is why governance is scoped above any single platform.

Data governance conventionally addresses structured data: schemas, lineage, quality, master records. The obligations overlap where a document contains personal data and both regimes apply, but the failure modes differ. Data governance worries about accuracy and lineage; information governance worries about retention, access and defensible disposal.

What a framework actually contains

A governance framework that functions, rather than one that exists as a document, has a small number of concrete parts.

An information inventory. What categories exist and which systems hold them. Governance cannot cover content nobody has enumerated, and the systems that get missed are usually mailboxes, collaboration tools and departmental file shares.

A classification scheme. Categories that determine handling, with few enough of them that people apply them correctly. Schemes with dozens of categories are applied inconsistently, and inconsistent classification is worse than coarse classification because it produces false confidence.

Named ownership per category. A person or role who decides on access exceptions, retention extensions and disposal authority. Ownership assigned to a committee is ownership assigned to nobody.

A retention schedule. Covered in depth under records management, because retention is where governance becomes enforceable.

An access model. Who may read, edit and share each category, expressed in terms the systems can actually implement.

Disposal authority. Who is permitted to approve destruction, and what record of that approval survives the content.

Where governance meets the lifecycle

Governance describes the rules; document lifecycle management describes the stages those rules are applied at. The two are usually written by different teams, and the gap between them is where obligations go unmet: a retention rule that exists in policy but is anchored to no lifecycle transition never fires.

The same gap appears around format obsolescence. A governance framework that mandates a twenty-year retention period without a corresponding digital preservation plan has committed to an outcome it has no mechanism to deliver.

What commonly goes wrong

Policy without enforcement. The most common failure. A framework is approved, published and never wired into a system that could apply it. It provides the appearance of governance and none of its effect, and it is worse than no policy because it creates a documented standard the organization is measurably failing.

Classification left to users. Where correct classification depends on individual judgment at the moment of filing, it degrades steadily. Automated classification is more consistent, though it shifts the problem to whether the classifier is trustworthy for the categories that carry statutory consequences.

Governance that stops at one repository. Content governed carefully in a managed system and ignored in email, chat and personal drives is not governed. The ungoverned copy is the one that surfaces in discovery.

Retention as a maximum, never a minimum. Teams read a schedule as permission to keep things and rarely as an obligation to destroy them. Over-retention expands the volume exposed in litigation and breach, and under some data-protection regimes is itself the violation.

No evidence of the decision. Governance is judged after the fact, usually by someone hostile. An access grant, a retention extension or a disposal approval with no durable record cannot be defended later, regardless of how correct it was at the time.

Contellect One applies classification, retention and audit trails against content rather than against policy documents, in compliance and records management.

Put the definition to work

See how Contellect One governs content from capture to action

Request a demo