What is Records Management?
Records management defined: retention schedules, legal holds, record declaration, disposition and defensible destruction versus ordinary storage.
Records management is the practice of controlling information that must be retained as evidence of a business activity, governing how long it is kept, who may alter it, and how it is disposed of when its retention period ends.
The defining feature is that a record is evidence. That is what separates records management from storage: the purpose is not availability but provable integrity over a defined period.
Records and documents are not the same
Most documents are not records. A draft, a working copy, an internal note and a duplicate are documents. A record is the version that evidences something happened: the signed contract, the submitted return, the approved payment, the issued policy.
The transition is called declaration. At the point a document is declared a record, its handling changes: it typically becomes immutable, its retention clock starts, and deleting it requires authority rather than permission.
Declaration can be manual, where a user marks a document, or automatic, where document classification determines record status from content and context. Automatic declaration is more consistent and is usually the only approach that scales, but it depends on the classification being trustworthy for the categories that carry statutory consequences.
Retention schedules
A retention schedule maps record categories to how long they are kept and what happens afterwards. It is normally derived from statute, regulation, contractual obligation and the organization’s own risk position, and it differs by jurisdiction, which matters for organizations operating across several.
Periods are anchored to a trigger rather than to a creation date. A contract may be retained for a number of years after termination rather than after signature; an employee record after departure rather than after hiring. Systems that only understand creation-date retention cannot implement most real schedules correctly.
Keeping records longer than the schedule requires is not the safe default it appears to be. Over-retention increases the volume discoverable in litigation, expands the surface exposed by a breach, and in some data-protection regimes is itself a violation, since personal data is not to be kept beyond its purpose.
Legal holds
A legal hold suspends disposition for records relevant to actual or anticipated litigation, investigation or audit. It overrides the retention schedule, and it has to override it reliably.
Two properties make a hold defensible. It must be immediate, applying before scheduled destruction can run. And it must be auditable, recording what was held, when, on whose authority, and when it was released.
Destroying records under hold, even by an automated schedule operating as designed, is spoliation. Courts have sanctioned organizations for exactly this, and “the system deleted it automatically” is not a defense.
Disposition and defensible destruction
Disposition is what happens when retention expires: destruction, transfer to an archive, or review for extension.
Defensible destruction means destruction that can be justified afterwards. The requirements are that it followed an approved schedule, that it was not selective, that no hold was in force, and that the event was logged. The last point is the one most often missed: the evidence that a record was properly destroyed is a durable log entry, so the log outlives the record.
Selective destruction is the failure that attracts sanction. Deleting records because they are unhelpful, rather than because a schedule required it, is indefensible regardless of how the deletion was performed.
How it differs from ordinary storage
A document management system can store records, but storage and records management are different obligations. Storage keeps content available. Records management proves that content is what it claims to be, has not been altered, was kept exactly as long as required, and was disposed of properly.
The practical differences: immutability after declaration, retention anchored to events rather than dates, holds that override schedules, disposition that is executed rather than merely configured, and an audit trail sufficient to satisfy a regulator years later.
What commonly goes wrong
The schedule exists on paper only. A retention policy no system enforces provides the appearance of compliance and none of its substance.
Disposition is never run. Retention is configured, expiry passes, and nothing happens, because nobody is willing to authorize deletion. The result is indefinite retention with a policy that says otherwise, which is worse than having no policy.
Holds are managed by email. A hold communicated to administrators rather than applied in the system will eventually be missed.
Backups are forgotten. Records destroyed in the live system but surviving in backups have not been destroyed, and remain discoverable.
Contellect One supports retention, record declaration and audit trails in compliance and records management.
See Contellect One in action
Book a personalized demo tailored to your team and use case.