s46-self-assessment-toolkit-online by dandanhuanghuang

VIEWS: 1 PAGES: 27

									TNA
Self Assessment Questionnaire for compliance with the revised Records Management
Code of Practice
Guidance on using this tool




This Excel workbook is the latest automated support tool to assist public authorities assess their conformance of
their record management systems to the revised Records Management Code.                                             SKIP to
                                                                                                                    Questionnaire
To perform the self-assessment, the public body should complete each of the nine modules in the assessment
questionnaire.

The questionnaire prompts for answers using either drop down lists or a simple cell for open ended responses.

The drop-down lists show "Please select" as the default entry.


The workbook will use your responses to determine an assessment of risk, and display the results in the "Result
                                                                                                                    SKIP to Results
charts" worksheet of this workbook.

For your own use, you can use the column to the right of responses (Column E) to enter references and evidence
associated with your assessment responses.

The light blue arrow shapes and coloured boxes provide links to modules of the questionnaire, TNA website,
Results sheet and links back to this guide.


After completing the Questionnaire, you may use the "Results charts" to focus attention on your Record
Management functions when consulting with senior managers responsible for governance in your organisation,
and with TNA and other parties interested in the revised Section 46 Code of Practice for Records Management.



                                                                                                                    SKIP to Email
Where this completed questionnaire is to be returned to TNA, then name your file and email back to TNA (you
can use the email hyperlink on the right).


The best settings for viewing the questionnaire on most monitors may be 75% Zoom, and a resolution of 1280 x
800. It has been necessary to use a small font for text in questions and tips, so you may need to increase
magnification to make text more legible.

Support contacts:
                                                                                                                    SKIP to
                                                                                                                    Email for
If you need further guidance and advice on using this assessment tool, or have found a problem, please contact:     HELP or
                                                                                                                    problems
                                     rmadvisory@nationalarchives.gsi.gov.uk
  links
 Contact
 details


Module 1


Module 2


Module 3


Module 4


Module 5


Module 6


Module 7


Module 8


Module 9




Guidance


Results


TNA
                                                                                                                                                        76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                                      Page 3
                                                                                                                                                                                     1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                                                     Management Code issued under section 46 of the Freedom of Information Act 2000. It is intended for the use of all              SKIP to TNA

                                                  TNA                                                                                                                                public authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience
                                                                                                                                                                                     of their record management policies and processes.

                                                                                                                                                                                         2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                                                                    website page

                                                                                                                                                                                                                                                                                                                    SKIP to
                                                                                                                                                                                                                                                                                                                    Guidance
                                                                                                                                                                                         choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                                              Self Assessment Questionnaire for                                     Enter contact details, then                          questionnaire.
                                                             compliance with the revised Records                                   answer questions in Module
                                                                Management Code of Practice                                                     1
                                                                                                                                                                                         3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                                                         worksheet in this workbook.                                                                                                SKIP to
                                                                                                                                                                                                                                                                                                                    Results


                                                                          Contact Details                                                    (your responses below)                                                                                  SKIP to               SKIP to
                                                                                                                                                                                                                                                     Guidance              Results


                                                                                                                            (Please enter)                                                Job title:
                                                                               Questionnaire Completed By (name)                                                                                                                                                                     LINKS TO                CONTACT
                                                                                                                                                                                                                                                                                     MODULES                  details
                                                                                                                            (Please enter)                                                Phone number:
                                                                                                  Your email address                                                                                                                                                                Module 1: Organisational
                                                                                                                                                                                                                                                                                arrangements to support records
                                                                                                                            (Please enter)
                                                                                                   Organisation name                                                                                                                                                             Module 2: Record Management
                                                                                                                                                                                                                                                                                             policy
                                                                                                                            (Please enter)
                                                                 What is your division of the organisation called?                                                                                                                                                             Module 3: Keeping records to meet
                                                                                                                                                                                                                                                                                   corporate requirements
                                                                                                                 1
                                                                Does this self-assessment cover the whole of yor -----PLEASE SELECT------>
                                                                                                         organisation?                                                                                                                                                               Module 4: Records systems

                                                                                                                            (Enter date)
                                                                                             Date of this assessment                                                                                                                                                          Module 5: Storage and maintenance
                                                                                                                                                                                                                                                                                          of records
                                                                                                                            1                                                            Other:
                                                                                                                            -----PLEASE SELECT------>
                                                                                                 Type of Public Body
                                                                                                                                                                                                                                                                                  Module 6: Security and access
                                Contact details




                                                                                                                            1                                                            Other:
                                                                                                                            -----PLEASE SELECT------>
                                                              If a Local Authority, please state the type of Council
                                                                                                                                                                                                                                                                                  Module 7: Disposal of records

                                                                                                                            1
                                                                                                                            -----PLEASE SELECT------>
                                                                                                 Country and Region                                                                                  For any queries or help with                                               Module 8: Records created in the
                                                                                                                                                                                                   completing the self-assessment                                              course of collaborative working or
                                                                                                                            (Please enter)                                                         please contact us at this e-mail
                                                              Name of the Records Manager in your organisation                                                                                                 address                                                        Module 9: Monitoring and reporting
                                                                                                                                                                                                                                                                                 on records and information
                                                                                                                            (Please enter as a number)
                                                                   No. of staff (FTE) employed in the organisation
                                                                          covered by this questionnaire response
                                                                                                                                                                                          rmadvisory@nationalarchives.gsi.gov.uk

                                                                                                                                                                                         TNA tip: Module 1 is designed to elicit if an organisation has recognised the need for a
                                                                                                                                                                                         records and information management function. The function needs to be formally
                                                                                                                                                                                         incorporated into the corporate culture. It should provide both the mechanisms and the
                                                                 Module 1: Organisational                                                                                                requisite resource to support and implement effective records and information
                                                                 arrangements to support                                                                                                 management.

                                                    Q#             records management                                                        (your responses below)
                            links                                                                                                                                                        (your notes and evidence statement)
                                                                                                                            1
                                                                                                                            -----PLEASE SELECT------>
                                     End                        Is the records and information management function                                                                                                                             TNA tip: the issue here is to clarify if the organisation has
                                                             formally recognised within the organisation as a specific                                                                                                                         established an agreed programme for managing records in
                                                                                                                                                                                                                                               accordance with this part of the Code. The records management
                     Contact                          1      corporate programme or activity, either separately or as                                                                                                                          function should not be confused with the separate function of
                     details
                                                                      part of a wider Information Management (IM) or                                                                                                                           management of information technology although the two
                                                                              Knowledge Management (KM) function?                                                                                                                              complement one another.
       Module 1

                                                                                                                            1                                                            (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
       Module 2
                                                             Does the records and information management function
       Module 3                                               bring together responsibilities for records in all formats,                                                                                                                      TNA tip: this issue is analysed further in Module 8 which covers
                                                      2      including paper and electronic records, throughout their                                                                                                                          records created in the course of collaborative working or through
                                                                 life cycle, from planning and creation through to final                                                                                                                       out-sourcing.
       Module 4
                                                                                                               disposal?
       Module 5
                                                                                                                            1                                                            (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
       Module 6                                            Do the arrangements to support the records management
                                                                                                                                                                                                                                               TNA tip: note this issue is analysed further in Module 8 which
                                                               function recognise the need to extend them to records
       Module 7                                       3        managed on behalf of the authority by external bodies
                                                                                                                                                                                                                                               covers records created in the course of collaborative working or
                                                                                                                                                                                                                                               through out-sourcing
                                                                                                such as contractors?
       Module 8

                                                                                                                            1                                                            (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
       Module 9
                                                                                                                                                                                                                                               TNA tip: information and records are a corporate asset and loss
                                                                    Has records and information management been                                                                                                                                of the asset could cause disruption to business. The level of risk
Guidance                                              4    incorporated and explicitly recognised within the corporate                                                                                                                         will vary according to the strategic and operational value of the
                                                                                        risk management framework?                                                                                                                             asset to the authority and risk management should reflect the
                                                                                                                                                                                                                                               probable extent of disruption and resulting damage.
Results

TNA                                                                                                                         1                                                            (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
website
                                                           Has the organisation established a governance framework                                                                                                                             TNA tip: the Records Management Code does not require
                                                                that includes defined roles, lines of responsibility and
l arrangements to support records management




                                                                                                                                                                                                                                               specific objectives but their presence or absence will assist in
                                      Top             5      objectives for the records and information management                                                                                                                             assessing the viability of each organization’s approach to the
                                                                                                             function?                                                                                                                         governance issue.


                                                                                                                            1                                                            (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
                                                                                                                                                                                                                                               TNA tip: even where an organisation has reviewed its structure
                                                               When the structure of the organisation is subjected to                                                                                                                          this should be subject to re- review at appropriate intervals to
                                                            periodic review, does it consider impact of changes upon                                                                                                                           confirm to senior management that organisational changes which
                                                      6          the corporate records and information management                                                                                                                              have occurred since the last review have not compromised its
                                                                                                            function?                                                                                                                          ability to achieve the agreed corporate records and information
                                                                                                                                                                                                                                               management objectives.


                                                                                                                            1                                                            (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
                                                            If applicable, when was the structure last reviewed to see
                                                            what changes might be needed to achieve the objectives
                                                      7           required by the adoption of a corporate records and
                                                                                   information management function?




                                                  Page 3                                                                                                                                                                                                                       76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 1: Organisational arrangements to support reco                                                                                                                          76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                     Page 4
                                                                                                                                                   1                                                        (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                                                    TNA tip: a records and information management champion should
                                                                                                                                                                                                                                                    be senior manager preferably one at management board or
                                                                                  Has lead responsibility for the records and information                                                                                                           equivalent level. The issue here is if the records and information
                                                                                management function been allocated to an individual at a                                                                                                            manager is set at a junior level their ability to influence
                                                                          8         sufficiently senior level to enable them to act as the                                                                                                          management is reduced and the organisation’s ability to comply
                                                                                                        records management champion?                                                                                                                with its own stated strategic function can be compromised. The
                                                                                                                                                                                                                                                    presence of a champion at a senior level together with clear lines
                                                                                                                                                                                                                                                    of communication will address this issue.


                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                       Where a record management champion has been                                                                                                                  TNA tip: just because a “champion” exists, does not mean
                                                                                     identified, do mechanisms exist to ensure that where                                                                                                           anything unless there are processes in place to trigger notification
                                                                          9             necessary the organisation’s record management                                                                                                              to and subsequent discussion of the relevant issue at the Board
                                                                                              practices are raised and considered at senior                                                                                                         level. There have been instances in some organisations where
                                                                                                                                                                                                                                                    the appointment of the “champion” has been notional.
                                                                                                             management team meetings?

                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                                                    TNA tip: in many instances this will come down to the
                                                                                    Has lead responsibility for the records and information                                                                                                         appointment and allocation of dedicated record management staff
                                                                                                                                                                                                                                                    and the allocation of sufficient time for non-dedicated staff to
                                                                                      management function across the organisation been
                                                                        10            defined with responsibility for providing the required
                                                                                                                                                                                                                                                    undertake the required work to support the record manager. In
                                                                                                                                                                                                                                                    some instances it may also refer to secured budgets to pay for
                                                                                      resource to support the necessary operational work                                                                                                            contractors to undertake the work and/ or acquisition of
                                                                                                                                                                                                                                                    appropriate accommodation and equipment.


                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                                                    TNA tip: management here refers to the management of the
                                                                                                                                                                                                                                                    operational activities including training as well as oversight of
                                                                                                                                                                                                                                                    compliance by business units. In this context operational
                                                                                                                                                                                                                                                    responsibility means the work of the Corporate Record Manager
                                                                                          Has operational responsibility for the record and                                                                                                         and team members. The relevant person would possess
                                                                                                                                                                                                                                                    appropriate level of competency required for the role. The
                                                                                    information management function been allocated to a
                                                                        11          member(s) of staff with the necessary knowledge and
                                                                                                                                                                                                                                                    Government Knowledge and Information Management (GKIM)
                                                                                                                                                                                                                                                    Professional Skills Framework provides an insight into the nature
                                                                                                                                     skills?                                                                                                        of the required generic knowledge and skills.

                                                                                                                                                                                                                                                                                                                           Web link
                                                                                                                                                                                                                                                    http://gkimn.nationalarchives.gov.uk/fra
Module 1: Organisational arrangements to support records management




                                                                                                                                                                                                                                                    mework.htm

                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>



                                                                                  Have job descriptions been developed listing the duties,
                                                                                  essential attributes and required level of skill needed for
                                                                        12                  personnel assigned to records and information
                                                                                                                       management roles?




                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                  Has the job description and associated competencies for
                                                                               the person responsible for the operation of the records and                                                                                                          TNA tip: the citation above of BS ISO 15489 and the GKIM
                                                                                    information management function been benchmarked                                                                                                                Professional Skills Framework are to provide relevant illustrative
                                                                        13       against recognised external standards (e.g. the provisions                                                                                                         examples. Depending on the sector within which an authority
                                                                                   within BS ISO 15489 Information and Documentation –                                                                                                              operates there may other standards, competency frameworks and
                                                                                                                                                                                                                                                    codes of practice which are more relevant
                                                                                Records Management Standard or the GKIM Professional
                                                                                                                       Skills Framework?)

                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                                                    TNA tip: the issue here is to ensure that operational and
                                                                                        Is there a mechanism to ensure that any proposed                                                                                                            organisational changes or a major technological change such as
                                                                                                                                                                                                                                                    a web hosting of content) do not inadvertently compromise the
                                                                                structural, organisational or financial changes are subject
                                                                        14      to a risk assessment review in terms of their likely impact
                                                                                                                                                                                                                                                    ability of an organisation to adhere to the Records Management
                                                                                                                                                                                                                                                    Code - this is the short title used for the Code of Practice issued
                                                                                   on the records and information management function?                                                                                                              by the Lord Chancellor under section 46 of the Freedom of
                                                                                                                                                                                                                                                    Information Act 2000 on the management of records.


                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                                                    TNA tip: the issue here is the not just the existence of a
                                                                                             Is there a mechanism to regularly review the                                                                                                           statement that the function will be subject to review to ensure the
                                                                                                                                                                                                                                                    organisation possesses the required resources and skills but also
                                                                        15        organisational arrangements required to implement the                                                                                                             a clear indication of when such reviews will be undertaken and
                                                                                                          records management function?                                                                                                              that the outcome will be subject to formal consideration by senior
                                                                                                                                                                                                                                                    management.


                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                                                    TNA tip: the first issue is to confirm that the organisation has
                                                                               Has the organisation assessed whether there are sufficient                                                                                                           correctly identified the level and quality of the resources required
                                                                        16          resources for effective implementation of records and                                                                                                           to support the implementation of the records management
                                                                                                                information management?                                                                                                             function. The second issue is to clarify if the required resource
                                                                                                                                                                                                                                                    has actually been delivered.


                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                                                    TNA tip:
                                                                                                                                                                                                                                                    This extends to both budgets(s)and personnel e.g. allocation of a
                                                                                                                                                                                                                                                    senior management champion and supporting staff equipped with
                                                                                    Is the records and information management function                                                                                                              the necessary knowledge and skills to undertake the operational
                                                                                                                                                                                                                                                    work required for the records and information management
                                                                        17      formally resourced with adequate resources to achieve its                                                                                                           function. Where the record management duties are combined
                                                                                                           responsibilities and objectives?                                                                                                         with a variety of other obligations this may indicate that
                                                                                                                                                                                                                                                    insufficient resource or priority is assigned to this work. In short
                                                                                                                                                                                                                                                    has the appropriate level of resource been allocated to undertake
                                                                                                                                                                                                                                                    the required work?
sational arrangements to support records management




                                                                                        Does the person responsible for the operation of the 1                                                                (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>                                                                           TNA tip: ideally the same people will be responsible also for
                                                                               records and information management function have direct                                                                                                              compliance with other information legislation and in small
                                                                                      responsibility for, or an organisational connection with,                                                                                                     authorities this may be practicable. Alternatively where this is not
                                                                        18         those responsible for compliance with other information                                                                                                          possible clear lines of communication between those charged with
                                                                                 legislation, for example the Data Protection Act 1998 and                                                                                                          these responsibilities should be established to enable
                                                                                                                                                                                                                                                    collaborative working and liaison as need arises.
                                                                                        the Re-use of Public Sector Information Regulations
                                                                                                                                        2005? 1                                                               (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                                  Is the designated individual with operational responsibility                                                                                                      TNA tip: the Records Management Code is the short title used for
                                                                                for records and information management conversant with                                                                                                              the Code of Practice issued by the Lord Chancellor under section
                                                                        19            the requirements of the revised Records Management                                                                                                            46 of the Freedom of Information Act 2000 on the management of
                                                                                                                                        Code?                                                                                                       records.


                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>
                                                                                        Where authority for record management has been
                                                                                distributed or delegated across an organisation have local
                                                                        20           record managers been appointed for each area of the
                                                                                                                                business?

                                                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                                                   -----PLEASE SELECT------>


                                                                               Where local record managers have been appointed is their
                                                                        21      work and training coordinated and reviewed centrally by a
                                                                                                                senior records manager?




                                                                      Page 4                                                                                                                                                                                                        76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 1: Organisational arrangements t                                                                                                                                     76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                       Page 5
                                                                                                                                                1                                                        (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>                                                                        TNA tip: to clarify if the organisation’s response is adequate it will
                                                                                 Where local record managers have been appointed are                                                                                                             be necessary to ascertain that when job descriptions are reviewed
                                                                                                                                                                                                                                                 mechanisms also exist to ensure, that the review of these job
                                                                        22     their job descriptions reviewed by the Records Manager to                                                                                                         descriptions is done in partnership with the Records Manager or
                                                                                          ensure the duties and priorities are appropriate?                                                                                                      the role charged with this responsibility to confirm they remain
                                                                                                                                                                                                                                                 apposite.

                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>




                                                                                Where local record managers have been appointed have
                                                                        23         communication channels been established for liaison
                                                                                 between the record managers across the organisation?




                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                                                                                                                                                                                                 TNA tip: within the public sector there is growing expectation that
                                                                                                                                                                                                                                                 personnel charged with record, knowledge and information
                                                                                   Where one exists, has the organisational competency                                                                                                           management responsibilities should be developed in accordance
                                                                                framework been compared or validated against external                                                                                                            with professional competency frameworks. Some of these will be
                                                                                    guidance produced by recognised centres of record                                                                                                            sector specific. The GKIM Professional Skills Framework
                                                                        24     management expertise? (e.g. the Government Knowledge                                                                                                              promulgated by the Knowledge Council is a relevant example and
                                                                                                                                                                                                                                                 is available at:
                                                                                       and Information Management Professional Skills
                                                                                                                            Framework)                                                                                                           http://gkimn.nationalarchives.gov.uk/fra
                                                                                                                                                                                                                                                                                                                          Web link
                                                                                                                                                                                                                                                 mework.htm
Module 1: Organisational arrangements to support records management




                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>

                                                                                    Where the organisation has formulated or adopted a
                                                                                 competency framework for records management, does
                                                                        25     the record management team possess the skills set out in
                                                                                                           the competency framework?


                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                                                                                                                                                                                                 TNA tip: this would include opportunities to study for formal
                                                                                    Are records and information management staff given
                                                                        26                    opportunities for professional development
                                                                                                                                                                                                                                                 qualifications such as NVQs, diplomas, and degrees within the
                                                                                                                                                                                                                                                 records and information management discipline.


                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                               Is there provision for the regular review of training needs in
                                                                        27                          records and information management?

                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                                 Is there a process for the review of selection criteria for                                                                                                     TNA tip: the issue here is to ensure the selection and recruitment
                                                                        28     posts with records and information management duties to                                                                                                           criteria for these posts remains apposite and that an appropriate
                                                                                    ensure currency and compliance with best practice?                                                                                                           mechanism exists to ensure review and amendment.


                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>

                                                                               Have senior managers been provided with the appropriate
                                                                                level of records and information management training to
                                                                        29         enable them to fulfill the role allocated to them by the
                                                                                                                              organisation?


                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>


                                                                                   Have existing staff across the organisation been made
                                                                        30       aware of records management issues and practices and
                                                                                            provided with an appropriate level of training?


                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                                       Are existing staff regularly reminded of records                                                                                                          TNA tip: the issue here is to clarify to what extent the organisation
                                                                        31       management issues and practices and provided with an                                                                                                            endeavours to remind and support staff in the performance of
                                                                                          opportunity to undertake refresher training?                                                                                                           record management activities.


                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                                                                                                                                                                                                 TNA tip: the issue here is the presence of an appropriate and
                                                                                     Does the induction training programme for new staff                                                                                                         timely training programme which ensures all newly employed
                                                                        32        include awareness of records management issues and                                                                                                             personnel are aware of the key issues and equipped with the
                                                                                                                             practices?                                                                                                          necessary training and tools to support compliance with the
                                                                                                                                                                                                                                                 organisation’s record management practices.


                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>

                                                                               Are temporary staff and consultants provided with training                                                                                                        TNA tip: appropriate induction training should be extended to
                                                                                       to ensure they are made formally aware of records                                                                                                         temporary staff, contractors and consultants who are undertaking
                                                                        33              management policies, standards, procedures and                                                                                                           work that it has been decided should be documented in the
                                                                               guidelines, and understand their personal responsibilities?                                                                                                       authority’s records.


                                              links                                                                                                                                                        (your notes and evidence statement)
                                                                                                                                                1
                                                                                                                                                -----PLEASE SELECT------>
                                                            End

                                                                                      Do job descriptions across the organisation include
                                    Contact
                                    details
                                                                        34      relevant references to records management obligations?

              Module 1

                                                                                                                                                1                                                          (your notes and evidence statement)
              Module 2                                                                                                                          -----PLEASE SELECT------>

                                                                                       Has the organisation identified the information and
              Module 3
                                                                        35                          business systems that hold records?

              Module 4                                                                                                                                                                                     (your notes and evidence statement)
                                                                                                                                                1
                                                                                                                                                -----PLEASE SELECT------>
                                                                                Has the organisation provided the resources needed to
              Module 5
                                                                        36     maintain and protect the integrity of records holding those
                                                                                              systems and the information they contain?
              Module 6

                                                                                                                                                1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
              Module 7
                                                                               Has the organisation ensured that records and information
              Module 8                                                  37         management issues are considered when planning or
                                                                                                             implementing ICT systems?
              Module 9


Guidance                                                                                                                                        1                                                          (your notes and evidence statement)
                                                                                                                                                -----PLEASE SELECT------>
                                                                               Has the organisation ensured that records and information                                                                                                         TNA tip: this extends beyond using new business systems or
Results                                                                 38      management issues are considered when extending staff                                                                                                            software and should include permissions to access and use
                                                                                                           access to new technologies?                                                                                                           external technology and storage facilities.
TNA
website




                                                                      Page 5                                                                                                                                                                                                     76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                              Page 6
website
                   You've reached the end of Module 1. If you wish to check the Results sheet now, click on the link to Results. If you wish to
   Top
                   start the next module, click on link to Module 2.             Results Module 2




          Page 6                                                                                                         76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                                                  76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                                Page 7
                                                                                                                                                                               1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                                               Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the use of all public SKIP to TNA


                                           TNA                                                                                                                                 authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience of
                                                                                                                                                                               their record management policies and processes.

                                                                                                                                                                               2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                                                        website page

                                                                                                                                                                                                                                                                                                        SKIP to
                                                                                                                                                                                                                                                                                                        Guidance
                                                                                                                                                                               choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                                       Self Assessment Questionnaire for                                        Enter responses below in                       questionnaire.
                                                      compliance with the revised Records                                        answer to questions in
                                                         Management Code of Practice                                                    Module 2
                                                                                                                                                                                  3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                                                  worksheet in this workbook.                                                                                                  SKIP to
                                                                                                                                                                                                                                                                                                               Results




                                                                                                                                                                                  TNA tip: Module 2 is designed to elicit if an organisation has established a records
                                                                                                                                                                                  management policy, to provide a mandate for the records and information management
                                                                                                                                                                                  function and a framework for supporting standards, procedures and guidelines. This can
                                                                                                                                                                                  be in the form of a separate policy or as part of a wider information or knowledge
                                                     Module 2: Record Management                                                                                                  management policy.

                                                                 policy                                                                (your responses below)
                           links
                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                     End                                                                                                                                                                                               TNA tip: – public authorities should have in place a records
                                                         Is there a policy on how the organisation manages its
                                             39                                                      records?
                                                                                                                                                                                                                                       management policy, either as a separate policy or as part of a
                                                                                                                                                                                                                                       wider family of information or knowledge management policies.
                      Contact
                      details

                                                                                                                      1                                                           (your notes and evidence statement)
                                                        Is the policy formally endorsed by senior management          -----PLEASE SELECT------>
           Module 1                          40                                        within the organisation?
                                                                                                                                                                                  (your notes and evidence statement)
           Module 2                                   Does the policy outline the role of records management 1    -----PLEASE SELECT------>
                                             41         and its relationship to the authority’s overall business
           Module 3                                                                                     strategy?
                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
           Module 4                                      Does the policy set out the authority’s commitment to                                                                                                                         TNA tip: - the policy provides a mandate for the records and
                                                                                                                                                                                                                                       information management function and a framework for supporting
                                             42         create, keep and manage records which document its                                                                                                                             standards, procedures and guidelines. The precise form content
           Module 5                                                                         principal activities?                                                                                                                      will depend on the particular needs and culture of the authority.

           Module 6                                                                                                   1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                                       Does the policy fully reflect the statutory and regulatory                                                                                                                      TNA tip: - in this context there is a need to clarify the links
                                                                                                                                                                                                                                       between the records management policy and existing data
           Module 7                          43        environment within which the organisation is required to                                                                                                                        protection, freedom of information and environmental information
                                                                                                        operate?                                                                                                                       disclosure policies maintained by the organisation.
           Module 8
                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
           Module 9                                                                                                                                                                                                                    TNA tip: where relevant the policy should explicitly assert the key
                                                                                                                                                                                                                                       criteria to maintain its ownership of its records which may be
                                                     Does the policy provide for the continuous, unambiguous                                                                                                                           stored on. outsourced contracted storage and retrieval facilities or
    Guidance                                                                                                                                                                                                                           externally-hosted electronic systems. The point here is to provide
                                             44          ownership of its records stored, managed or hosted                                                                                                                            a reference point which should inform any new contract which
                                                                                                   elsewhere?                                                                                                                          may be entered into and a justification for re-examining existing
  Results                                                                                                                                                                                                                              contractual arrangements where ownership may be insufficiently
                                                                                                                                                                                                                                       clear.
  TNA
  website
                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                                                                                                                                                                                                                       TNA tip: whilst most tacitly assume that the organisation
                                     Top                                                                                                                                                                                               automatically owns its records there will be cases where
                                                                                                                                                                                                                                       ownership could be inadvertently alienated through data sharing
                                                                                                                                                                                                                                       protocols or partnership agreements. The policy can be used here
                                                                                                                                                                                                                                       as a reference point when shared access, storage and other
                                                    Does the policy identify and make appropriate connections                                                                                                                          shared services are being considered. In such cases the key
                                             45           to related policies, such as those dealing with email,                                                                                                                       criteria is for the organisation to maintain its ownership of its
                                                                      information security and data protection?                                                                                                                        records which may be stored on. outsourced contracted storage
                                                                                                                                                                                                                                       and retrieval facilities or externally-hosted electronic systems. The
                                                                                                                                                                                                                                       point here is the policy can provide a reference point which
                                                                                                                                                                                                                                       should inform any new contract which may be entered into and a
                                                                                                                                                                                                                                       justification for re-examining existing contractual arrangements
                                                                                                                                                                                                                                       where ownership may be insufficiently clear.


                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>                                                                                        TNA TIP: where applicable account should also be made of the
                                                      Does the policy explicitly include records in electronic or                                                                                                                      use and dependence of the organisation on specialised or
                                                                                                                                                                                                                                       informal communication modes like SMS text messaging, tweets,
                                             46               digital form as well physical form (e.g. paper or                                                                                                                        instant messaging or the use of social computing networks, to
                                                                                                    microform)?
Module 2: Record Management policy




                                                                                                                                                                                                                                       ensure the development of business rules and processes take
                                                                                                                                                                                                                                       account of such technology.

                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                                                                                                                                                                                                                       TNA tip: - it is important to clarify across the business that all
                                                                                                                                                                                                                                       information transactions using correspondence and
                                                                                                                                                                                                                                       communication mediums approved and used by the authority for
                                                                                                                                                                                                                                       business purposes may be considered to part of the official
                                                      Does the policy make explicit that e-mails and any other                                                                                                                         record. Of these e-mail is the most familiar but according to
                                                              form of electronic correspondence used by the                                                                                                                            circumstance it may extend to SMS messaging, instant
                                             47           organisation which are produced or received in the                                                                                                                           messaging and other formats such as Twitter or if applicable the
                                                      conduct of business will be considered to be part of the                                                                                                                         use of social networking applications. In the absence of a clear
                                                                                                                                                                                                                                       some staff can assume that correspondence and information
                                                                                            corporate record?
                                                                                                                                                                                                                                       created and held in these environments are not subject to record
                                                                                                                                                                                                                                       management practices as the medium is considered to be
                                                                                                                                                                                                                                       ephemeral even though they are routinely used to communicate
                                                                                                                                                                                                                                       decisions and official advice.


                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                                    Does the policy define roles and responsibilities to support
                                             48                             the record management function?

                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                                      Does the policy define the responsibility of individuals to
                                             49     document their actions and decisions in the organisation’s
                                                                                                        records?

                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                                                                                                                                                                                                                       TNA tip: it is not anticipated that the policy should provide a
                                                                                                                                                                                                                                       detailed schedule of disposal actions and retention periods but
                                                                                                                                                                                                                                       that the authoritative basis for executing such decisions should be
                                                       Does the policy define high level criteria for disposing of
                                             50            records no longer required for business purposes?
                                                                                                                                                                                                                                       explicit for example that records will be kept until they are either
                                                                                                                                                                                                                                       no longer required for the conduct of business or to discharge
                                                                                                                                                                                                                                       specific legal or regulatory obligations where records have to be
                                                                                                                                                                                                                                       retained for prescribed periods.


                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>                                                                                        TNA tip: - the issue here is that the policy needs to clarify that
                                                        Does the policy assign responsibility for identifying and                                                                                                                      authority for disposal and destruction of records is assigned to a
                                                                                                                                                                                                                                       specific role such as the Record Manager even though the it will
                                             51      disposing of obsolete records in an auditable manner to a                                                                                                                         be necessary to confer with business units’ managers prior to
                                                                                                          role(s)?                                                                                                                     agreeing disposal. The intention here is to emphasise the
                                                                                                                                                                                                                                       corporate nature of this activity.
ecord Management policy




                                                                                                                      1                                                           (your notes and evidence statement)
                                                                                                                      -----PLEASE SELECT------>
                                                                                                                                                                                                                                       TNA tip: - the policy defines the criteria within which record
                                                                                                                                                                                                                                       management practice should develop and flourish. It needs to
                                                             Does the policy provide for the development of a                                                                                                                          provide the corporate authority to enable the developement of an
                                             52          framework of appropriate standards, procedures and                                                                                                                            appropriate framework of procedural guidance. The framework will
                                                                    guidelines to support its implementation?                                                                                                                          need to be adopted, implemented and maintained as part of the
                                                                                                                                                                                                                                       corporate package to ensure effective records management
                                                                                                                                                                                                                                       across the organisation.


                                           Page 7                                                                                                                                                                                                                      76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 2: Record Management po                                                                                                                 76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                        Page 8
                                                                                                                   1                                                        (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>

                                               Is the policy readily available to all staff at all levels of the                                                                                                    TNA tip: the issue here isr the actual availability of the policy to all
                                       53                                                        organisation?                                                                                                      staff for example by publication on the organisation’s intranet.



                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                    TNA tip: the issue here is the presence of a proactive regime to
                                                  Are staff reminded of the existence of the policy and its
                                       54                                location for reference purposes?
                                                                                                                                                                                                                    remind staff periodically of the existence and location of the
                                                                                                                                                                                                                    policy.


                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                               Are newly appointed personnel (including temporary staff
                                       55          and consultants) made formally aware of the policy?

                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                                    Does the policy make provision that all systems and                                                                                                             TNA tip: the issue here is the presence of an authority for the
                                               processes that deal with records incorporate appropriate                                                                                                             establishment of the performance measurement regime
                                                                                                                                                                                                                    advocated within the Records Management Code and which is
                                       56     performance measures to ensure the quality and reliability                                                                                                            examined in Module 9 of this self assessment tool entitled
                                                    of the records to provide a valuable information and                                                                                                            Monitoring and reporting on records and information
                                                        knowledge resource for the whole organisation?                                                                                                              management.


                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                    TNA tip: the issue here is the presence of an authority for the
                                                                                                                                                                                                                    establishment of the performance measurement regime
                                                                                                                                                                                                                    advocated within the Records Management Code and which is
                                                        Does the policy require the development of an                                                                                                               examined in Module 9 of this self assessment tool entitled
                                       57        implementation plan with supporting procedures across                                                                                                              Monitoring and reporting on records and information
                                                                                      the organisation?                                                                                                             management. The issues may vary according to circumstance but
                                                                                                                                                                                                                    the policy needs to establish a key criterion which is is the ability
Module 2: Record Management policy




                                                                                                                                                                                                                    to measure conformance with the policy and its subordinate
                                                                                                                                                                                                                    processes.

                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>

                                              Does the policy mandate the establishment of a dedicated
                                                                                                                                                                                                                    TNA tip: - it is recognised that for very small organisations the
                                                   team to support the role of Records and Information
                                       58       Manager to carry out the record management roles and
                                                                                                                                                                                                                    establishment of a formal team may not be realistic in which case
                                                                                                                                                                                                                    a non applicable response would be appropriate to this question.
                                                    duties identified in the records management policy?


                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                    TNA tip: - for larger or more complex organisations the inclusion
                                                                                                                                                                                                                    of a technical policy establishes the criteria to be applied to the
                                                Does the policy make provision for or links to a technical                                                                                                          technologies that process electronic records. The use of new
                                                                                                                                                                                                                    types of technologies can also be judged against the technical
                                       59       policy to establish the criteria that can be applied to new                                                                                                         policy. These new technologies can then be considered to be
                                                   types of technologies that process electronic records                                                                                                            compliant to the policy and therefore acceptable for electronic
                                                                                                                                                                                                                    records, or not to be compliant and only allowed for working on
                                                                                                                                                                                                                    ephemeral documents.


                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>

                                                                                                                                                                                                                    TNA tip: organisations should seek to preserve electronic records
                                                                                                                                                                                                                    during any change in the infrastructure so that they can still
                                                                                                                                                                                                                    satisfy the original policy requirements. For example preservation
                                                                                                                                                                                                                    needs must be satisfied when there are changes in: - the
                                                                                                                                                                                                                    technology that processes the electronic records how this affects
                                                                                                                                                                                                                    the way records are processed throughout the records’ existence
                                                  Does the policy include provision for the definition of a                                                                                                         - organisational structures and how these are interpreted and give
                                                     preservation or maintenance strategy to ensure that                                                                                                            the records context
                                       60     electronic records are visibly present and maintained in an                                                                                                           - the definition of terms used in the metadata and within the
                                               authentic state for as long as they continue to be required                                                                                                          records themselves
                                                                                                                                                                                                                    - metadata relating to the classification of the electronic records
                                                  regardless of any technology change that may occur?
                                                                                                                                                                                                                    including how the records are grouped and described so that they
                                                                                                                                                                                                                    can be presented in a way consistent with the original
                                                                                                                                                                                                                    understanding of the subject when the record was created. The
                                                                                                                                                                                                                    continuing presence of such metadata with relevant links will be
                                                                                                                                                                                                                    critical to the continued usability and interpretation of the records.




                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
Module 2: Record Management policy




                                                     Does the policy indicate the need to provide for the
                                       61      preservation and secure storage of physical records (e.g.
                                                 paper files) for as long as they continue to be required?

                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>                                                                        TNA tip: - the issue here is to put in place a watching brief to
                                              Does the policy establish a priority for the allocation of the                                                                                                        ensure that electronic records are not put at risk through failure to
                                                                                                                                                                                                                    ensure accessibility and readability over time. The policy should
                                       62     resources needed to preserve electronic records intact for                                                                                                            recognise that this will affect the management of its IT
                                                               as long as they continue to be required?                                                                                                             infrastructure and that expediency should not be permitted to put
                                                                                                                                                                                                                    information of value at risk.

                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                    TNA tip: a registration policy helps the organisation to set
                                                                                                                                                                                                                    minimum conditions for the registration of electronic records, so
                                                                                                                                                                                                                    ensuring a link between the electronic record and its
                                               Does the policy make provision for the establishment of a                                                                                                            administrative roots. It is recommended that registration or
                                       63      registration or classification policy for the management of                                                                                                          indexing of electronic and paper records should follow best
                                                                                                its records?                                                                                                        practice in records management and allow for the users of the
                                                                                                                                                                                                                    records to identify and track particular records and record
                                                                                                                                                                                                                    collections. The provisions within BS ISO 15489 (Information and
                                                                                                                                                                                                                    Documentation) provide a useful guide here.


                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                    TNA tip: - Records need to be classified or indexed to provide
                                                                                                                                                                                                                    relevant contextual information. Some term this as a registration
                                                Does the policy require that electronic records should be                                                                                                           requirement a term which is also recognised by BS ISO 15489.
                                                registered, classified or indexed as a means of providing                                                                                                           The standard defines a minimum registration requirement which it
                                                                                                                                                                                                                    may be helpful to reference. Business classification schemes are
                                       64         an appropriate level of context to provide an integrated                                                                                                          an effective way of managing unstructured records and mapping
                                                     information structure to support access and retrieval                                                                                                          other information assets like databases. However different line of
                                                                           according to the business need?                                                                                                          business systems will display different forms of contextual
                                                                                                                                                                                                                    information sometimes via locally developed controlled
                                                                                                                                                                                                                    vocabularies, specialist thesauri or sector specific taxonomies.


                                                                                                                   1                                                          (your notes and evidence statement)
                                                                                                                   -----PLEASE SELECT------>
                                                                                                                                                                                                                    TNA tip: - physical folders, should clearly display their unique
                                              Does the policy require that where records in physical form                                                                                                           identifying references and the storage location system should
                                               (i.e. paper records) are to be retained that they should be                                                                                                          know their current location and be able to track their movements
                                                                                                                                                                                                                    to and from the store. Search and display systems will vary. For
                                       65          stored in a manner which ensures they can be reliably                                                                                                            example some organisations may use formal registered files
                                                     identified and retrieved to satisfy continuing business                                                                                                        which display agreed titles and/or reference codes/numbers
                                                                                                      needs                                                                                                         drawn from organisational business classification schemes for
dule 2: Record Management policy




                                                                                                                                                                                                                    this purpose.

                                                                                                                   1                                                          (your notes and evidence statement)
                                                Does the policy require that electronic records stored or          -----PLEASE SELECT------>

                                              referenced within a business classification scheme should
                                                  each be provided with a unique title in accordance with
                                       66          agreed naming policies or taxonomies adopted by the
                                                       organisation to ensure accurate classification and
                                                                                                retrieval?




                                     Page 8                                                                                                                                                                                                           76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 2: Record Management po                                                                                                               76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                      Page 9
                                                                                                                 1                                                        (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>


                                                 Does the policy require that audits be undertaken of the
                                                   registration and classification references used by the
                                       67     organisation so that the system makes sense and relevant
                                                records can be found in appropriate search sequences?



                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                   Does the policy require that where relationships exist
                                                 between different sets of records and different types of                                                                                                         TNA tip: some users may require comprehensive overview of
                                              records (e.g. electronic and paper) these relationships are                                                                                                         several sets and different types of records, e.g. teams responding
                                       68     documented by the allocation of meaningful references to                                                                                                            to FOI requests will need access to all related records to inform
                                               ensure these links are readily apparent when undertaking                                                                                                           their decision on whether a disclosure exemption applies.
                                                                         appropriate search sequences?

                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                                                                                                                                                                                  TNA tip: the purpose of providing an access policy to be defined
                                                   Does the policy provide for the definition of an access                                                                                                        is to allow records to be viewed by all relevant parties, and offer a
                                              policy with supporting procedures to control the movement                                                                                                           mechanism for opening up some of the information for use
                                                                                                                                                                                                                  outside this group. The actual controls will depend on many
                                       69           of information in and out of the records management                                                                                                           factors but the general principles can be summarised as records
                                                systems, allowing the records to be created or viewed by                                                                                                          will be made available for continuity of actions but roles or bodies
                                                                            different categories of users?                                                                                                        within the organisation will have to be identified as being able to
                                                                                                                                                                                                                  make an accurate judgement on the sensitivity of the record.


                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                              Does the policy or a clearly associated information security                                                                                                        TNA tip: the issue here is the ability of the organisation to identify
                                                 policy make provision for the establishment of roles or                                                                                                          security risks posed by certain types of records or
Module 2: Record Management policy




                                               bodies within the organisation, which will be able to make                                                                                                         communications which require the application of locally based
                                                                                                                                                                                                                  access controls. The organisation has to establish mechanisms
                                       70         an accurate judgement on the sensitivity of records to                                                                                                          and roles to provide the leadership and take the required
                                                    identify any restrictions and determine the groups or                                                                                                         decisions to ensure information is protected against inappropriate
                                                     individuals within the organisation who should have                                                                                                          disclosure and knowledge of the existence, location and nature of
                                                                                                  access?                                                                                                         such roles or bodies should be disseminated to all staff.


                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>




                                               Does the policy establish the principles by which access to
                                       71     the records or the information they contain may be granted
                                                    in response to requests external to the organisation?




                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                    Does the policy provide for the documentation of the
                                               reasons why records were released or withheld (including
                                                 partial disclosure where information within the record or
                                                                                                                                                                                                                  TNA tip: this may be achieved thorough associated but linked
                                       72        record series was masked or concealed) in response to                                                                                                            policies in those respective areas.
                                              requests for information under the Freedom of Information
                                                          Act 2000; the Data Protection Act 1998 and the
                                                      Environmental Information Regulations 2004(EIR)?

                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>




                                                     Does the policy require that all reasonable steps be
                                                    undertaken to ensure that the electronic records and
                                       73           processes dealing with them are secure and that the
                                                     electronic records are safeguarded from alteration,
                                                                                misinterpretation or loss?
Module 2: Record Management policy




                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                 Does the policy provide an authority for the auditing of
                                       74     compliance with the policy and associated procedures and
                                                                                              guidance?


                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                                                                                                                                                                                  TNA tip: traditionally a custodian would have direct physical
                                                                                                                                                                                                                  control of the records however in the electronic world information
                                                                                                                                                                                                                  can be stored externally or alternatively spread across corporately
                                                                                                                                                                                                                  controlled servers. The establishment of the concept of a trusted
                                                      Does the policy provide for the concept of a trusted                                                                                                        custodian would enable the formulation of roles and business
                                                                                                                                                                                                                  rules whereby certain post holders are provided with super user
                                              custodian to hold or be responsible for the management of
                                       75          inactive records for records in electronic and physical
                                                                                                                                                                                                                  capabilities which when used would prevent uninformed casual
                                                                                                                                                                                                                  deletion, and movement of the records and also uninformed
                                                                                                     form?                                                                                                        modification of access permissions. The role of custodian
                                                                                                                                                                                                                  becomes more significant as records become older as the
                                                                                                                                                                                                                  originating user community may no longer exist or have access to
                                                                                                                                                                                                                  the records. The custodian role can help minimise the risks to the
                                                                                                                                                                                                                  organisation.


                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                        Does the policy provide for the development and                                                                                                           TNA tip: in many cases disposal equates to authorised
                                                  implementation of authorised disposal procedures and                                                                                                            destruction as the records are no longer required but the term
                                                                                                                                                                                                                  disposal also extends to other actions which include identifying
                                                    mechanisms to ensure records can be appropriately
                                       76     disposed of (including to an historical archives institution) in
                                                                                                                                                                                                                  review dates where a future destruction date can be determined
                                                                                                                                                                                                                  and transfer and export to other designated organisations
                                                       an accountable manner when they are no longer                                                                                                              including transfer to specialist archives for permanent
                                                                                                  required?                                                                                                       preservation of selected records on historical or heritage grounds.


                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                    Does the policy require that business continuity plans
                                                   include provisions for the maintenance of records and
                                       77            record management processes to ensure a constant
                                                service is maintained in spite of any technical or strategic
                                                                                   hitches that may occur?

                                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                 -----PLEASE SELECT------>
                                                                                                                                                                                                                  TNA tip: - the policy should actively discourage the creation of
dule 2: Record Management policy




                                                                                                                                                                                                                  duplicate copies especially private working copies as the
                                                                                                                                                                                                                  existence of uncontrolled copies in personal work areas can
                                               Does the policy provide a view on the creation of duplicate                                                                                                        inadvertently lead to breaches of both the Freedom of Information
                                       78      copies generally and in what circumstances may these be                                                                                                            Act 2000 and the Data Protection Act 1998. However in certain
                                                                                               permitted?                                                                                                         circumstances duplicates may make sense as the information is
                                                                                                                                                                                                                  required for more than business purpose and the policy should
                                                                                                                                                                                                                  provide some clarification of the recommended criteria to be used
                                                                                                                                                                                                                  when determining whether to create duplicate records.




                                     Page 9                                                                                                                                                                                                        76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 2: Record Management polic                                                                                                               76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                     Page 10
                                                                                                                    1                                                        (your notes and evidence statement)
                                                                                                                    -----PLEASE SELECT------>
                                                                                                                                                                                                                     TNA tip: the issue here is the provision of a policy imperative to
                                                                                                                                                                                                                     ensure that current IT back-up processes are fit for purpose and
                                                      Does the policy make provision for the creation of back-                                                                                                       that the records management is an element within them. It is
                                                                                                                                                                                                                     especially important that a restored backup provides the content
                                            79        ups to a corporately agreed standard to include updates                                                                                                        with the supporting descriptive metadata to secure access and
                                                                    for new electronic records and metadata?                                                                                                         retrieval It is not expected that the policy will define the business
                                                                                                                                                                                                                     rules but it should provide the authority for the development and
                                                                                                                                                                                                                     implementation of such rules.


                                                                                                                    1                                                          (your notes and evidence statement)
                                                                                                                    -----PLEASE SELECT------>
                                                                                                                                                                                                                     TNA tip: here again the issue is not the formulation of the
                                                                                                                                                                                                                     appropriate rules and procedures but the need to ensure an
                                                                                                                                                                                                                     authorisation to inform the development of such processes and to
                                                      Does the policy require the establishment of an effective                                                                                                      remind the authors of the need to consider the record
                                                                                                                                                                                                                     management element. A relevant example would be checking that
                                            80       back-up restoration regime to ensure that when back-ups                                                                                                         when a back up is restored that any disposal functions which had
                                                              need to be restored they remain fit for purpose?                                                                                                       been applied since the backup was taken should be re-run to
                                                                                                                                                                                                                     avoid the organisation retaining personal information for which it
                                                                                                                                                                                                                     had no need and whose presence on the live system could lead
                                                                                                                                                                                                                     to a possible breach of the Data Protection Act 1998.

                                                                                                                    1                                                          (your notes and evidence statement)
                                                                                                                    -----PLEASE SELECT------>
                                                        Does the policy make provision for a disaster recovery
                                                         plan to be incorporated within the business continuity
                                            81       planning process in the event that electronic systems are
                                                                 compromised or physical records damaged?

                           links                                                                                    1                                                          (your notes and evidence statement)
                                                                                                                    -----PLEASE SELECT------>
                                                    Does the policy define the principle that information held in                                                                                                    TNA tip: - the existence of such a provision within the policy
                                    End                                                                                                                                                                              would inform and facilitate the continuity planning process as
                                                     records which is considered to be vital to the continuity of
                                            82             the business or urgently required in the event of an
                                                                                                                                                                                                                     information held in vital and/or emergency records could be
                      Contact                                                                                                                                                                                        safeguarded in the event of an occurrence of a catastrophic
                      details                          emergency should be identified as a matter of priority?                                                                                                       event.


           Module 1                                                                                                 1                                                          (your notes and evidence statement)
                                                                                                                    -----PLEASE SELECT------>


           Module 2
                                                     Does the policy assign responsibilities for regular reviews
                                            83                                                     of the policy?
           Module 3


           Module 4

                                                                                                                    1                                                          (your notes and evidence statement)
                                                                                                                    -----PLEASE SELECT------>                                                                        TNA tip: - the issue here covers both the timing of such reviews
           Module 5
                                                         Does the policy set criteria for the conduct of a formal                                                                                                    but also the nature of the review process as it may be desirable to
                                            84               review of the records management policy and its                                                                                                         review current procedures mandated by the policy and any
           Module 6                                                                                                                                                                                                  required consequential changes may have an impact on the
                                                                                                implementation?
                                                                                                                                                                                                                     policy itself.
           Module 7                                                                                                                                                            (your notes and evidence statement)
                                                                                                                    1
                                                                                                                    -----PLEASE SELECT------>
                                                         Does the policy include provision for preparation of a                                                                                                      TNA tip: periodic review of policies to confirm relevance is good
           Module 8                                       periodic progress report to ascertain the continuing                                                                                                       practice – the organisation needs to determine the frequency for
                                            85      relevance and efficacy of the policy and for its submission                                                                                                      such a review to be undertaken and ideally this requirement
           Module 9                                                        to senior management for review?                                                                                                          should be incorporated within the policy.


                                                                                                                    1                                                          (your notes and evidence statement)
    Guidance                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                                     TNA tip: - the publication of such polices is considered to be good
                                                                                                                                                                                                                     practice generally and it can also facilitate implementation and
  Results                                   86                                  Has the policy been published?                                                                                                       adherence to the policy by middle managers and end users as
                                                                                                                                                                                                                     public expectation can be an additional driver to support
                                                                                                                                                                                                                     compliance.
  TNA

                                                    You've reached the end of Module 2. If you wish to check the Results sheet now, click on the link to Results. If you wish to
                                    Top
                                                    start the next module, click on link to Module 3.             Results Module 3




                                          Page 10                                                                                                                                                                                                     76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                               Page 11
                                                                                                                                                                                                 1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                                                                 Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the use of all public SKIP to TNA


                                                           TNA                                                                                                                                   authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience of
                                                                                                                                                                                                 their record management policies and processes.

                                                                                                                                                                                                 2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                                                                          website page

                                                                                                                                                                                                                                                                                                                          SKIP to
                                                                                                                                                                                                                                                                                                                          Guidance
                                                                                                                                                                                                 choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                                                        Self Assessment Questionnaire for                                         Enter responses below in                       questionnaire.
                                                                       compliance with the revised Records                                         answer to questions in
                                                                          Management Code of Practice                                                     Module 3
                                                                                                                                                                                                    3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                                                                    worksheet in this workbook.                                                                                                    SKIP to
                                                                                                                                                                                                                                                                                                                                   Results
                                                                     Questionnaire


                                                                                                                                                                                                    TNA tip: Module 3 is designed to elicit if an organisation has put in place the required
                                                                                                                                                                                                    rules and procedures to ensure it keeps the records it will need for business, regulatory,
                                                                        Module 3: Keeping records to                                                                                                legal and accountability purposes.
                                                                        meet corporate requirements                                                      (your responses below)
                                                                                                                                        1                                                           (your notes and evidence statement)
                                      links                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                                                          TNA tip: in this context keeping of records extends to the records
                                                                        Has the organisation established or defined overarching                                                                                                                          an organisation needs to create for business purposes as well as
                                                  End
                                                                        principles or rules for identifying what records should be                                                                                                                       the custody of records it already holds or may receive from third
                                                             87           kept for example which decisions or actions should be                                                                                                                          parties. Realistically this should be supported by each part of the
                              Contact
                                                                                                                        recorded?.                                                                                                                       business with relevant function specific guidance if compliance is
                              details
                                                                                                                                                                                                                                                         to be achieved.

           Module 1
                                                                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                                        -----PLEASE SELECT------>
                                                                             Has the organisation communicated to all staff their
           Module 2                                                      personal responsibility to follow the authority’s business
                                                             88        rules and keep accurate and complete records as part of
           Module 3                                                                                               their daily work?

                                                                                                                                        1                                                           (your notes and evidence statement)
           Module 4                                                                                                                     -----PLEASE SELECT------>                                                                                        TNA tip: - possible elements that might be identified for inclusion
                                                                                                                                                                                                                                                         are: a. the type of information transactions or communications
                                                                     Has the organisation or alternatively the individual business                                                                                                                       which should be captured by the business
           Module 5
                                                                        units defined the requirements that must be met for the                                                                                                                          b. the preferred physical or logical form of the record
                                                             89      records themselves to be considered as a proper record of                                                                                                                           c. the location to be used by each part of the business in a
           Module 6                                                                                                                                                                                                                                      classification system or file-plan
                                                                                                  the activity of the organisation?
                                                                                                                                                                                                                                                         d. key metadata attributes (e.g. author, owner, nature of the
                                                                                                                                                                                                                                                         record – contract, invoice, minutes FOI enquiry etc.
           Module 7

                                                                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                                        -----PLEASE SELECT------>
           Module 8                                                                                                                                                                                                                                      TNA tip: - The actual requirements will vary according to the
                                                                                 Has the organisation defined its classification or                                                                                                                      reason the records were created, the business purpose they
                                                                                                                                                                                                                                                         serve and the limitations of the actual line of business systems in
           Module 9                                          90      registration requirement which should be adhered to when                                                                                                                            place. BS ISO 15489 Records Management Standard provides a
                                                                                               records are created or received?                                                                                                                          relevant example of what constitutes minimum best practice for
                                                                                                                                                                                                                                                         what it terms a registration requirement.
Guidance

                                                                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                                        -----PLEASE SELECT------>
                                                                            Does the organisation require as a minimum that all
Results
                                                                         records created or received by the business should be
                                                             91          classified into series or sets that have meaningful titles
TNA
Module 3: Keeping records to meet corporate requirements




                                                                                             and/or a consistent reference code?

                                                                                                                                        1                                                           (your notes and evidence statement)
                                                   Top                                                                                  -----PLEASE SELECT------>
                                                                                                                                                                                                                                                         TNA tip: - all records have to be indexed if they are to remain
                                                                                                                                                                                                                                                         usable and retrievable by others. The reference to a pre-defined
                                                                         Does the organisation set a responsibility on individuals                                                                                                                       series or record set and if necessary a sub-series or sub-sub-
                                                                                                                                                                                                                                                         series can be something as simple as allocating a record to a
                                                                     forming record items in the course of their work to allocate
                                                             92       them to pre-defined series or records sets provided by the
                                                                                                                                                                                                                                                         case management system organised by citizen name or property
                                                                                                                                                                                                                                                         address or placing it into a relevant named folder within a
                                                                                                         business for their use?                                                                                                                         managed shared work area such as Windows Explorer. The point
                                                                                                                                                                                                                                                         to clarify here is that all staff are required to use the record
                                                                                                                                                                                                                                                         keeping or management systems allocated for their use.


                                                                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                                        -----PLEASE SELECT------>

                                                                                                                                                                                                                                                         TNA tip: this is to clarify the use of sequential references tied to
                                                                                                                                                                                                                                                         business activities, Invoices and purchase orders are one
                                                                                                                                                                                                                                                         example, case reference numbers are another. Paper documents
                                                                                                                                                                                                                                                         may be given one to aid accurate retrieval. Where they exist or
                                                                                                                                                                                                                                                         are required are sequences available to end users to assist them
                                                                     Where appropriate, has the organisation, its business units                                                                                                                         in classifying or registering records in the system designed to
                                                                     and, if relevant, its projects and programmes, established                                                                                                                          receive them? In many cases where objects are stored into
                                                             93        sequences of reference numbers that can cover series                                                                                                                              database systems such ECM and EDRM solutions they will also
                                                                                          with both electronic and paper records?                                                                                                                        automatically receive a unique numerical ID but in some
                                                                                                                                                                                                                                                         instances business units will require the additional application of
                                                                                                                                                                                                                                                         other sequential number references to categorise the record or
                                                                                                                                                                                                                                                         aggregations of associated records. It is emphasised it is not
                                                                                                                                                                                                                                                         expected that in every case a record has to receive a sequential
                                                                                                                                                                                                                                                         number this will be determined by local business requirements.



                                                                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                                                                          TNA tip: records and information management can only be
                                                                       Have the specific responsibilities of managers and heads                                                                                                                          effective if managers understand and accept the obligation to
                                                                                                                                                                                                                                                         ensure their staff know what information within their specific
                                                                     of business units been clarified that they have an obligation
                                                             94         to ensure that adequate records are kept of the activities
                                                                                                                                                                                                                                                         business area has to be kept and in what form to maintain the
                                                                                                                                                                                                                                                         required corporate record. Lack of senior and middle management
                                                                                                for which they are accountable?                                                                                                                          buy-in will otherwise compromise the ability of the organisation to
                                                                                                                                                                                                                                                         adhere to the Records Management Code.


                                                                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                                                                         TNA tip: technically any recorded information created within an
                                                                                                                                                                                                                                                         organisation constitutes a record however in practice most
                                                                                                                                                                                                                                                         organisations distinguish between those communications which
                                                                            Is there guidance within each business unit on what                                                                                                                          document activities and transactions which each part of the
                                                                                                                                                                                                                                                         business must retain in order to discharge its remit and those
                                                                      records should be kept and how they should be treated to
                                                             95          ensure they are held in the appropriate record keeping
                                                                                                                                                                                                                                                         which are purely ephemeral and which do not need to be kept and
                                                                                                                                                                                                                                                         classified within a corporate file-plan. There may also be several
                                                                                                                      systems?                                                                                                                           record keeping systems used by specific business units. These
                                                                                                                                                                                                                                                         may not be formally called record keeping systems but may be a
                                                                                                                                                                                                                                                         line of business applications such as a case management or a
                                                                                                                                                                                                                                                         revenue and benefit transaction system.


                                                                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                                        -----PLEASE SELECT------>

                                                                        Has the organisation clarified where records created or                                                                                                                          TNA tip: - in such cases this may cross business unit boundaries
                                                                      held in one part of the business may be required for other                                                                                                                         and even affect the corporate function of the organisation. The
                                                                                                                                                                                                                                                         Corporate Records Manager needs to clarify where such linkages
                                                             96      business purposes to ensure that the business rules which                                                                                                                           and overlaps exist and negotiate with the relevant business units
                                                                        are developed for their creation and capture support all                                                                                                                         to ensure the full business need is addressed) Where these case
                                                                                                        known business needs?                                                                                                                            arise it would be prudent to capture them within a risk register.



                                                                                                                                        1                                                           (your notes and evidence statement)
meet corporate requirements




                                                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                                                                         TNA tip: this can be particularly important where there is a need
                                                                          Has guidance been provided for end users to indicate                                                                                                                           to capture internal communications. For example if an e-mail is
                                                                                                                                                                                                                                                         generated which contains an explicit authorisation or a formal
                                                             97        which party in an e-mail exchange is responsible for filing                                                                                                                       instruction who should file it - the creator, the recipient or both?
                                                                                                                that exchange?                                                                                                                           The issue to avoid is where neither party files it as responsibility is
                                                                                                                                                                                                                                                         unclear and no record is therefore maintained.

                                                                                                                                                                                                    (your notes and evidence statement)
                                                                       Has the organisation developed and promulgated clearly 1     -----PLEASE SELECT------>

                                                                       defined corporate wide instructions applying to staff at all
                                                             98              levels of the authority, to create, keep and manage
                                                                                                                         records?
                                                           Page 11                                                                                                                                                                                                                        76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 3: Keeping records to meet corporate requir                                                                                                                 76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                      Page 12
                                                                                                                                       1                                                        (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>                                                                         TNA tip: the phrase “necessary and appropriate actions” includes
                                                                                                                                                                                                                                        statutory and regulatory requirements as well as the
                                                                                                                                                                                                                                        organisation’s own administrative and corporate needs for
                                                                       Has each business unit defined what records need to be                                                                                                           accurate information. Each business unit should consider the
                                                                     captured to meet their business need and facilitate access                                                                                                         need to provide additional advice to its staff to ensure the
                                                             99           and use by other functions across the organisation in                                                                                                         appropriate records for that portion of the business are identified
                                                                                  accordance with the corporate instructions?                                                                                                           and retained. Where this additional advice is absent organisations
                                                                                                                                                                                                                                        need to check the guidance on whether the corporate guidance
                                                                                                                                                                                                                                        on what constitutes a record - referred to in question 88 above is
                                                                                                                                                                                                                                        sufficient.

                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                        Is there a process to check that each business unit has        -----PLEASE SELECT------>
                                                                                                                                                                                                                                        TNA tip: This should also include statutes, regulations and
                                                           100          appropriate business rules on what constitutes a record                                                                                                         standards applying to the sector or authority or to particular
                                                                                                 and therefore should be kept?                                                                                                          functions such as finance.

                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                         Has the organisation explicitly identified the risks of not
                                                                           having those records it requires to meet its statutory,
                                                           101           regulatory and business needs within its corporate risk
                                                                                                                           register?

                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>

                                                                        Where an organisation has identified risks of not having                                                                                                        TNA tip: the issue here is if the mitigation measures are too broad
                                                                                                                                                                                                                                        in scope it can be difficult to substantiate their correct application
                                                                       the records it requires to meet all its statutory, regulatory
                                                           102           and business needs, are risk mitigation and monitoring
                                                                                                                                                                                                                                        within specific business units. Each part of the business should
                                                                                                                                                                                                                                        indentify the specific risks and mitigation measures appropriate
                                                                                       measures in place to ensure compliance?                                                                                                          according to their function.



                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                      When responding to requests for information made under
                                                                      the Freedom of Information Act 2000, the Data Protection
                                                                       Act 1998 and the Environmental Information Regulations                                                                                                           TNA tip: the issue here is not the ability of the organisation to
                                                                                                                                                                                                                                        comply with the relevant legislation but its ability to document and
                                                           103       2004(EIR), does your organisation require the reasons why                                                                                                          formally record the activities it had to undertake in compliance
                                                                             records were released or withheld (including partial                                                                                                       with the legal environment.
                                                                        disclosure where information within the record or record
                                                                          series was masked or concealed) to be documented?

                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                                                                                                                                                                                        TNA tip: this principle should be extended to all information
                                                                                                                                                                                                                                        holding systems which contain recorded information e.g. where
                                                                          Has the organisation established business rules for the                                                                                                       applicable this will include Wikis, instant messaging and SMS text
                                                                         capture, management and secure storage of electronic                                                                                                           messaging and any omissions should be identified and subjected
                                                           104         information (e.g. e-mails and other digital record objects)                                                                                                      to a corporate risk assessment The rules should clarify what is to
                                                                                       required as part of the corporate record?                                                                                                        be kept and this would be based on the availability to end users of
                                                                                                                                                                                                                                        corporately controlled storage areas where shared access
Module 3: Keeping records to meet corporate requirements




                                                                                                                                                                                                                                        permissions are applied.


                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                         Has the organisation provided each business unit with                                                                                                          TNA tip: not all business units will require access to all corporate
                                                                        appropriate systems for the capture, management and                                                                                                             record keeping systems but it is essential that each business unit
                                                                      secure storage of electronic information (e.g. e-mails and                                                                                                        is equipped with appropriate systems for the capture and
                                                           105           other digital record objects) into corporately controlled                                                                                                      management of all the electronic information they create, receive
                                                                           storage areas where shared access permissions are                                                                                                            or transact which is considered to be part of the corporate record.
                                                                                                                                                                                                                                        In cases of doubt an audit and gap analysis will be required).
                                                                                                                         applied?

                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                                                                                                                                                                                        TNA tip: this extends to both generic organisation wide guidance
                                                                                                                                                                                                                                        and local business unit based function specific procedures - the
                                                                                                                                                                                                                                        organisation may establish a generic set of obligations, for
                                                                                                                                                                                                                                        example the responsibilities of a sender or recipient of an email or
                                                                                                                                                                                                                                        voicemail but this needs further articulation within each business
                                                                          Do the business rules identify who should keep these
                                                           106                                                        records?
                                                                                                                                                                                                                                        unit or function to specify which employee role has primary
                                                                                                                                                                                                                                        responsibility for creating those records required to document the
                                                                                                                                                                                                                                        work of the relevant business unit. It should be emphasised an
                                                                                                                                                                                                                                        organisation wide injunction that all staff should be responsible for
                                                                                                                                                                                                                                        the keeping of records would be considered insufficient without
                                                                                                                                                                                                                                        supporting local procedures within the business units.


                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                                                                                                                                                                                        TNA tip: for example when drafts of a document should be frozen
                                                                        Do the business rules specify the point in the process or                                                                                                       and kept as a formal record or during a formal workflow there may
                                                           107                    transaction at which records should be kept?                                                                                                          be discrete stages where a record has to be created or validated
                                                                                                                                                                                                                                        before moving to the stage of the process.


                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                                                                                                                                                                                        TNA tip: for example individual records rarely stand alone but
                                                                                                                                                                                                                                        form a chain in series of exchanges or transactions. Has the
                                                                     Has the organisation or its business units established rules                                                                                                       organisation defined where and how related records should be
                                                                                                                                                                                                                                        stored, for example located within a case file accessible to
                                                                          how records should be stored within each designated
                                                           108          record keeping system to provide a logical context and
                                                                                                                                                                                                                                        designated teams? In contrast records held by individuals within
                                                                                                                                                                                                                                        personal drives and personal mail boxes are not normally
                                                                                   corporate access by authorised personnel?                                                                                                            accessible to other colleagues and are effectively hidden from the
                                                                                                                                                                                                                                        corporate memory even though they are in the custody of the
                                                                                                                                                                                                                                        organisation.


                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                     Has the organisation established particular controls as per
                                                                     BS ISO 15489 within its record keeping or record
                                                                     management systems so as to ensure the evidential value
                                                                     of the records can be demonstrated if required by showing
                                                                     them to:                                                                                                                                                           TNA tip: - The organisation will need mechanisms in place to
                                                                                                                                                                                                                                        support attestations that the records they hold are credible and
                                                           109       a) be authentic, that is, they are what they say they are;                                                                                                         authoritative evidence in order to protect the rights of the
                                                                     b) be reliable, that is, they can be trusted as a full and                                                                                                         organisation and any person affected by its actions)
                                                                     accurate record;
                                                                     c) have integrity, that is, they have not been altered since
                                                                     they were created or filed;
                                                                     d) be usable, that is, they can be retrieved, read and used.

                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>

                                                                                                                                                                                                                                        TNA tip: - according to business need there may be a
                                                                                                                                                                                                                                        requirement to provide authenticated or certified copies for
                                                                                                                                                                                                                                        example in cases of legal discovery. Where this applies
                                                                              Where required are there mechanisms in place to
records to meet corporate requirements




                                                                                                                                                                                                                                        organisations should maintain a appropriate mechanism to
                                                                        authenticate records so that they constitute credible and                                                                                                       support the creation of these copies and the process should
                                                           110        authoritative evidential copies in order to protect the rights                                                                                                    generate a record of when such copies were created, by whose
                                                                     of the organisation and any person affected by its actions?                                                                                                        authority, the reason they were issued and the relationship to the
                                                                                                                                                                                                                                        original should be transparent. If some personal information was
                                                                                                                                                                                                                                        redacted in the copy due to its sensitivity the nature and reason
                                                                                                                                                                                                                                        for the redaction should be logged as well,



                                                                                                                                       1                                                          (your notes and evidence statement)
                                                                                                                                       -----PLEASE SELECT------>
                                                                           Has guidance been provided to staff to assist them to                                                                                                        TNA tip: - Staff should also be aware of the need to dispose of
                                                                        identify ephemeral material to avoid the record keeping                                                                                                         ephemeral material on a routine basis. For example, print-outs of
                                                                                                                                                                                                                                        electronic documents should not be kept after the meeting for
                                                           111       system being misused for the storage of information which                                                                                                          which they were printed, trivial emails should be deleted after
                                                                         is trivial and which is not required for the conduct of the                                                                                                    being read, and keeping multiple or personal copies of documents
                                                                                                                         business?                                                                                                      should be discouraged.




                                                           Page 12                                                                                                                                                                                                       76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 3: Keeping records to meet corporate re                                                                                                           76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                      Page 13
                                                                                                                             1                                                        (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                              TNA tip: the existence of private filing systems should be actively
                                                                                                                                                                                                                              discouraged if not prohibited as they raise real risks to the
                                                               Has guidance been provided to staff to advise why the                                                                                                          organisation in terms of information security and hinders effective
                                                                                                                                                                                                                              compliance with both the Freedom of Information Act 2000 and
                                                            practice of creating and holding locally generated copy or
                                                 112          duplicate record sets which are held by individuals as a
                                                                                                                                                                                                                              the Data Protection Act 1998. However where this has become
                                                                                                                                                                                                                              established custom and practice this can be an indication that the
                                                                   supplementary private filing system is problematic?                                                                                                        local business systems are flawed and need improvement and the
                                                                                                                                                                                                                              organisation should use this as an opportunity to identify such
                                                                                                                                                                                                                              shortcomings.


                                                                                                                             1                                                          (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                              TNA tip: - such reminders will help ensure staff continue to be
                                                               Is there guidance on what records should be kept and                                                                                                           aware of their record keeping obligations and of the record
                                                                                                                                                                                                                              keeping systems available to them. Logically such reminders
                                                 113        where they should be stored brought to the attention of all                                                                                                       need to be issued by each business unit as opposed to central
                                                                                                    staff periodically?                                                                                                       directives to ensure the specific business needs for record
                                                                                                                                                                                                                              keeping within each unit continue to be supported.

                                                                                                                             1                                                          (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                              TNA tip: users may need to be surveyed to clarify this. If users
                                                                                                                                                                                                                              are holding material on other drives outside of the system or
                                                             Where an organisation has established, or is planning to                                                                                                         storing the records on personal spaces or in general folders
                                                            establish, a business classification scheme or file-plan for                                                                                                      because there are no appropriate locations for storing some of the
                                                 114            the use of each business activity will this be subject to                                                                                                     records this could be an indication that file-plan requires further
                                                             validation by end users within the relevant business unit?                                                                                                       development. Similarly if areas of the file-plan are unused that
                                                                                                                                                                                                                              may indicate these areas are redundant and should be closed but
                                                                                                                                                                                                                              again such assumptions have to be validated.

                                                                                                                             1                                                          (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                              TNA tip: - end users need to be aware that storing records in the
                                                                                                                                                                                                                              locations designated for them is in part to aid retrieval but also
                                                                                                                                                                                                                              their subsequent disposal in accordance with the retention
                                                            Are the end users made aware of the authority’s disposal                                                                                                          periods required by the business. Records stored inappropriately
                                                                                                                                                                                                                              may not only be difficult to find subsequently but inappropriate
                               links             115          policies and why it is important that certain records are                                                                                                       locations may mean that records are destroyed prematurely or
                                                                         stored in the locations designated for them?                                                                                                         alternatively held for longer than is required – this last point could
                                         End
                                                                                                                                                                                                                              where result in personal data being held beyond the specific
                                                                                                                                                                                                                              business purpose which justified its acquisition and could lead to
                        Contact                                                                                                                                                                                               a data protection breach.
                        details

                                                                                                                             1                                                          (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
         Module 1                                            Does guidance specify that staff creating or filing records                                                                                                      TNA tip: guidance should be developed on what needs to be
                                                                                                                                                                                                                              incorporated into the title description (i.e. the record name) when
                                                 116          should give those records titles that reflect their specific                                                                                                    filing electronic records to ensure accurate retrieval by third
         Module 2                                                     nature and contents so as to facilitate retrieval?                                                                                                      parties within the organisation.

         Module 3                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                              TNA tip: management of e-mail records presents specific
                                                                                                                                                                                                                              problems as e-mails can readily become part of a continuing
         Module 4
                                                                                                                                                                                                                              discussion chain where the subject content changes and this is
                                                               When filing e-mail records is there guidance on how to                                                                                                         not represented in the subject line. It may also be necessary to
         Module 5                                                                                                                                                                                                             capture a number of instances of such communications at
                                                           determine the appropriate title (i.e. the record name) when
                                                 117       more than one instance of an ongoing communication is to
                                                                                                                                                                                                                              various points as a record of key decisions or opinions may need
                                                                                                                                                                                                                              to be captured within the corporate record at the time they were
         Module 6                                                                                              be filed?                                                                                                      communicated. Organisations need to define rules on when
                                                                                                                                                                                                                              various instances within such chain e-mails may need to be
         Module 7                                                                                                                                                                                                             captured and what criteria should determine the title for each
                                                                                                                                                                                                                              captured or filed instance.

         Module 8
                                                                                                                             1                                                          (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                              Is there formal training to enable personnel to adopt the                                                                                                       TNA tip: the issue here is has the organisation adopted any
         Module 9                                118           required record titling or naming conventions and apply                                                                                                        naming conventions and is there a mechanism to ensure staff are
                                                                                          these in a consistent manner?                                                                                                       trained in their use.
Guidance
                                                                                                                             1                                                          (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>

Results                                                     Has formal training been provided to enable personnel to
                                                 119         adopt the required record titling or naming conventions?
TNA
website

                                         Top
                                                           You've reached the end of Module 3. If you wish to check the Results sheet now, click on the link to Results. If you wish to
                                                           start the next module, click on link to Module 4.             Results Module 4




                                                 Page 13                                                                                                                                                                                                       76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                                 76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                               Page 14
                                                                                                                                                              1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                              Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the use of all public SKIP to TNA


                            TNA                                                                                                                               authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience of
                                                                                                                                                              their record management policies and processes.

                                                                                                                                                              2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                                       website page

                                                                                                                                                                                                                                                                                       SKIP to
                                                                                                                                                                                                                                                                                       Guidance
                                                                                                                                                              choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                        Self Assessment Questionnaire for                                   Enter responses below in                          questionnaire.
                                       compliance with the revised Records
                                                                                                             answer to questions in
                                          Management Code of Practice
                                                                                                                    Module 4                                     3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                                 worksheet in this workbook.                                                                                                   SKIP to
                                                                                                                                                                                                                                                                                               Results




                                                                                                                                                                 TNA tip: Module 4 is designed to elicit if organisations have ensured that they have the
                                                                                                                                                                 means to keep, manage and retrieve the records they will need for business, regulatory,
                                                                                                                                                                 legal and accountability purposes. It is aimed to explore the design, implementation and
                                                                                                                                                                 use of a records system as defined within the Records Management Code

                                         Module 4: Records systems                                   (your responses below)
                 links                                                                                                                                           (your notes and evidence statement)
                                                                                                     1
                                                                                                     -----PLEASE SELECT------>
                      End
                                                                                                                                                                                                                      TNA tip: The issue here is to clarify if records exist in unmanaged
                                                                                                                                                                                                                      environments where corporate oversight is limited or absent for
              Contact                                                                                                                                                                                                 example dependence on unstructured shared drives.
              details                                                                                                                                                                                                 Organisations are likely to hold records and other information in a
                                                                                                                                                                                                                      number of different systems. These systems could include a
     Module 1                          Has the organisation established a system or systems to                                                                                                                        dedicated electronic document and records management system,
                            120                         store records and to manage records?                                                                                                                          business systems such as a case management, finance or
                                                                                                                                                                                                                      geographical information system, a website, shared workspaces,
     Module 2                                                                                                                                                                                                         audio-visual material and sets of paper files with related registers.
                                                                                                                                                                                                                      In some cases related records of the same business activities
     Module 3                                                                                                                                                                                                         may be held in different formats, for example digital files and
                                                                                                                                                                                                                      supporting paper material.

     Module 4
                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
     Module 5                                                                                                                                                                                                         TNA tip: it is recognised that even where corporate record
                                                                                                                                                                                                                      keeping systems are established it is likely that some business
                                                                                                                                                                                                                      units may not use any of them or alternatively that proportion of
     Module 6                           What percentage of the organisation’s records are held                                                                                                                        each business unit’s records are held on local systems such as
                            121           within the organisation’s record keeping system(s)?                                                                                                                         unstructured shared drives or personal drives. The issue here is
     Module 7                                                                                                                                                                                                         to clarify what proportion of the organisation’s records fall outside
                                                                                                                                                                                                                      the control of the corporate systems as this will highlight the
                                                                                                                                                                                                                      continuing risk to the organisation.
     Module 8

                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
     Module 9                          Does the record keeping or record management system                                                                                                                            TNA tip: this is to ensure that issues of non compliance clarified
                            122                 take into account the legislative and regulatory                                                                                                                      in corporate risk registers inform the design and management of
                                         environments within which the organisation operates?                                                                                                                         record keeping systems.
Guidance

                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
Results
                                        Where a record keeping system or systems have been                                                                                                                            TNA tip: the issue here is the ability to enforce management rules
                                       established to hold electronic or digital records are there                                                                                                                    and protocols to maintain records of business value to ensure the
TNA                         123        mechanisms in place to protect them from accidental or                                                                                                                         key characteristics of a records as defined in BS ISO 15489 of
                                       unauthorised alteration, copying, movement or deletion?                                                                                                                        authenticity, reliability, integrity and usability.

                      Top
                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
Module 4: Records systems




                                                                                                                                                                                                                      TNA tip: - the issue here is to clarify if the design criteria for the
                                                                                                                                                                                                                      record keeping systems took account of the actual business
                                      Were business needs identified before the record keeping
                            124              system (or systems) was acquired or developed?
                                                                                                                                                                                                                      needs. This is distinct from the next question which aims to clarify
                                                                                                                                                                                                                      where an organisation indentified its business requirements
                                                                                                                                                                                                                      ensured these were adequately reflected in the actual system(s)


                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                      TNA tip: using the system(s) should be an integral part of
                                                                                                                                                                                                                      business operations and processes. They should be easy to
                                           Has the user’s actual experience of using the record                                                                                                                       understand and use and where possible proactively support the
                            125        keeping or record management system(s) demonstrated                                                                                                                            relevant business functions so as to reduce the effort required of
                                        that the authority’s operational requirements were met?                                                                                                                       those who create and use the records within them. Ease of use is
                                                                                                                                                                                                                      an important consideration when developing or selecting a system
                                                                                                                                                                                                                      and this should be reflected in users experience and feedback.


                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>                                                                                        TNA tip: when answering this question organisations should take
                                              Do users feel that the record keeping or record
                                                                                                                                                                                                                      account of the capability of digital systems to include the capacity
                            126        management system enables quick and easy retrieval of                                                                                                                          to search for information requested under the Freedom of
                                                                                 information?                                                                                                                         Information Act 2000.

                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                      TNA tip: There is no requirement in the Records Management
                                                                                                                                                                                                                      Code for records and information to be created and held
                                                                                                                                                                                                                      electronically, but if the authority is operating electronically, for
                                                                                                                                                                                                                      example using email for internal and external communications or
                                         Has the organisation determined a preferred format in
Module 4: Records systems




                            127                          which their records are to be stored?
                                                                                                                                                                                                                      creating documents through word processing software, it is good
                                                                                                                                                                                                                      practice to hold the resulting records electronically. In addition,
                                                                                                                                                                                                                      authorities should note that the EIR require them progressively to
                                                                                                                                                                                                                      make environmental information available to the public by
                                                                                                                                                                                                                      electronic means.


                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
                                       Is the corporate record keeping or management system
                            128         used for the management of current and newly created
                                                                           electronic records?

                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                      TNA tip: - the issue here is to clarify if the organisation actually
                                                                                                                                                                                                                      possesses a system to capture e-mail and their attachments into
                                                                                                                                                                                                                      a corporate space where other authorised users in addition to the
                                       Is the corporate record keeping or management system                                                                                                                           sender and recipient can have access. Absence of such
                            129            used for the management of newly created e-mails?                                                                                                                          environments means the organisation is corporately blind to its
                                                                                                                                                                                                                      own preferred correspondence medium. Dependence on private
                                                                                                                                                                                                                      mail boxes held on corporate servers would not normally be
                                                                                                                                                                                                                      considered an adequate response.


                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>                                                                                        TNA tip: it is recognised that many organisations will have
                                                                                                                                                                                                                      multiple record keeping systems and that a significant portion of
                                                                                                                                                                                                                      older records will be held on paper or other physical medium such
                                       Is the corporate record keeping or management system                                                                                                                           as microform. The point to clarify here is are the physical records
Module 4: Records systems




                            130       used for the management of physical records (e.g. paper                                                                                                                         documented on a corporate record keeping system and if so are
                                                                                        files)?                                                                                                                       they accessible to authorised end users? The absence of such a
                                                                                                                                                                                                                      system implies the organisation has lost sight of critical
                                                                                                                                                                                                                      information assets as users will be unaware of the existence of
                                                                                                                                                                                                                      such records and will not use them when required.

                                                                                                     1                                                           (your notes and evidence statement)
                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                      TNA tip: metadata enables the system to be understood and
                                                                                                                                                                                                                      operated efficiently, the records within the system to be managed
                                       Does the record keeping or record management system                                                                                                                            and the information within the records to be interpreted. It should
                            131        contain both information (i.e. records) and metadata (i.e.                                                                                                                     provide metadata in the form of descriptive and contextual
                                                                information about the records)?                                                                                                                       information about the records as well information which can be
                                                                                                                                                                                                                      used to regulate and document access and information which can
                                                                                                                                                                                                                      be used to execute and document disposal.




                            Page 14                                                                                                                                                                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 4: Records                                                                                                                   76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                     Page 15
                                                                                                        1                                                        (your notes and evidence statement)    TNA tip: in a records management system this can be achieved
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                        by classifying and indexing records within a file plan or business
                                         Do the record keeping or record management systems                                                                                                             classification scheme (or by the adoption of relevant sector
                                        enable the context of each record and its relationship to                                                                                                       specific taxonomies or thesauri) to bring together related records
                            132          other records to be understood (e.g. by relating records                                                                                                       and enable the sequence of actions and context of each
                                        within a corporate business classification scheme or file-                                                                                                      document to be understood. This approach has the added benefit
                                                                                                                                                                                                        of enabling handling decisions, for example relating to access or
                                                                                           plan)?
                                                                                                                                                                                                        disposal, to be applied to groups of records instead of to individual
                                                                                                                                                                                                        records.
                                                                                                                                                                  (your notes and evidence statement)
                                       Does the record keeping or records management system 1       -----PLEASE SELECT------>
                                                                                                                                                                                                        TNA tip: the issue here is to confirm that appropriate access
                                       provide for the definition of relevant roles and groups with                                                                                                     controls and permissions are in place to ensure compliance with
                            133
Module 4: Records systems




                                            appropriate access permissions to be established to                                                                                                         all relevant security procedures and relevant legislation such as
                                                        ensure that data privacy is safe-guarded?                                                                                                       the Data Protection Act 1998.

                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                        TNA tip: electronic record management systems facilitate the
                                                                                                                                                                                                        creation and management of such links. It is possible to do this to
                                                                                                                                                                                                        some extent in a physical paper environment using indexes but it
                                       Does the record keeping or records management system                                                                                                             is far more labour intensive. Relational links can be between
                                       provide for links to associated information held elsewhere                                                                                                       different sets of related electronic records and related sets of
                            134       or on different systems concerning the role and purpose of                                                                                                        physical records. The presence of such links ensures users can
                                               a record set which is not otherwise apparent to the                                                                                                      make fully informed decisions as they then possess the full
                                                                                                                                                                                                        information context. The absence of links to associated
                                             business function which has custody of the records?
                                                                                                                                                                                                        information (where such associations are known to exist) when
                                                                                                                                                                                                        records are being managed electronically may imply the
                                                                                                                                                                                                        organisation is not obtaining the full value of information assets.


                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>                                                                       TNA tip: - most electronic record management systems have the
                                                                                                                                                                                                        ability to create relational links and even provide textual scope
                                      Where the record keeping or records management system                                                                                                             notes to aid users to become aware of related information clusters
                            135                provides for links to associated information is this                                                                                                     however it is possible for the functionality to be present but no
                                                       functionality actually used to any extent?                                                                                                       corporate driver exists to ensure all the information assets are
                                                                                                                                                                                                        fully mapped which would enable the creation and maintenance of
                                                                                                                                                                                                        such links.

                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>                                                                       TNA tip: for example, electronic record management systems
                                       Do the record keeping or records management system(s)                                                                                                            should be able to delete specified information in accordance with
Module 4: Records systems




                            136         enable managed disposal of records as routine records                                                                                                           agreed disposal dates and leave the rest intact whilst
                                                                        management process?                                                                                                             documenting each specific disposal process to provide an
                                                                                                                                                                                                        auditable record of the event.

                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                        TNA tip: Folders, files and similar record assemblies should not
                                                                                                                                                                                                        remain live indefinitely with a capacity for new records to be
                                      Does the organisation have a policy to close record sets to                                                                                                       added to them. They should be closed, that is, have their contents
                                                                                                                                                                                                        frozen, at an appropriate time. The term record set is used here to
                            137         new content, e.g. to freeze a file so that new documents                                                                                                        mean aggregations, assemblies or collections of individual
                                                                                cannot be added?                                                                                                        records which have a logical association e.g. contract files,
                                                                                                                                                                                                        correspondence with individuals or organisations, case records or
                                                                                                                                                                                                        committee records etc.


                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                        TNA tip: The trigger for closure will vary according to the nature
                                                                                                                                                                                                        and function of the records, the extent to which they reflect
                                                                                                                                                                                                        ongoing business and the technology used to store them. For
                                                                                                                                                                                                        example, completion of the annual accounting process could be a
                                                                                                                                                                                                        trigger for closing financial records, completion of a project could
                                       Does the organisation possess the means to prevent new                                                                                                           be a trigger for closing project records, and completion of
                            138            content being added to record sets which have been                                                                                                           formalities following the death of a patient could be a trigger for
                                                 closed in accordance with pre-defined criteria?                                                                                                        closing that person’s health record. Size is a factor and a folder
                                                                                                                                                                                                        should not be too big to be handled or scrutinised easily. For
                                                                                                                                                                                                        electronic or digital records a trigger could be migration to a new
                                                                                                                                                                                                        system. Authorities should decide the appropriate trigger for each
Module 4: Records systems




                                                                                                                                                                                                        records system and put arrangements in place to apply the
                                                                                                                                                                                                        trigger.


                                                                                                                                                                  (your notes and evidence statement)
                                         Where applicable are triggers using pre-defined criteria 1
                                                                                                  -----PLEASE SELECT------>                                                                             TNA tip: the issue here is to clarify if the organisation’s policy to
                            139           used to close record sets (e.g. folders) to prevent new                                                                                                       limit the active life of record sets is being pro-actively supported
                                                            content being added to record sets?                                                                                                         by appropriate procedural mechanisms.

                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                      Does the record keeping or records management system
                                      provide metadata to record the date on which a record set                                                                                                         TNA tip: the absence of such metadata will make it difficult to
                                                                                                                                                                                                        manage the record sets and may compromise appropriate
                            140             was opened, or, if applicable, the creation date of the                                                                                                     disposal where the organisation requires the use of creation date
                                       earliest document/record it contains in order to determine                                                                                                       to drive subsequent disposal.
                                                                the date range of the record set?

                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>

                                       Does the record keeping or records management system                                                                                                             TNA tip: - many record sets are disposed on either the date of
                                      record the dates on which record sets were closed, (i.e. no                                                                                                       closure of the set or folder or on the basis of the date of the last
                                                                                                                                                                                                        item added to the collection or folder. Failure to record or track the
                            141        longer being added to), or, if applicable, the latest current                                                                                                    closure date and/or the latest current date of document/record it
                                               date of the document/record it contains in order to                                                                                                      contains will compromise the ability of the organisation to
                                                     determine the date range of the record set?                                                                                                        implement disposal based on this criteria.


                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
Module 4: Records systems




                                        Where record sets are dormant (i.e. closed or inactive) is                                                                                                      TNA tip: - the status of closed record sets should be transparent
                                                                                                                                                                                                        to users and where relevant knowledge of the existence of such
                            142                  this recorded in the record keeping or records                                                                                                         sets can help inform the creation of relational links to successor
                                                                         management system?                                                                                                             records sets.




                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                        TNA tip: The use of cut-off dates is an effective method to
                                                                                                                                                                                                        manage continuing sequences of records for example .the regular
                                                                                                                                                                                                        date used to separate parts of a continuing record collection for
                                                                                                                                                                                                        management purposes (for example, the end of the financial year,
                                       Where applicable are cut-off dates recorded to determine                                                                                                         annually, calendar year, quarterly, monthly, weekly) Normally the
                            143               the parts of a set of records due for management                                                                                                          application of cut –off dates would be automated as manual
                                                                         processing or disposal?                                                                                                        application can be very onerous and inconsistent. Financial
                                                                                                                                                                                                        management records are perennial within an organisation and
                                                                                                                                                                                                        sequences of such records are normally closed and subsequently
                                                                                                                                                                                                        disposed using the criteria of a cut-off date such as the close of a
                                                                                                                                                                                                        defined accounting period.


                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                        Does the record keeping or record management system
                                      support the creation of new continuation or part files where                                                                                                      TNA tip: completion of the annual accounting process could be a
                                                                                                                                                                                                        trigger for closing a record set of financial records for a particular
                            144          necessary following the closure of a pre-existing record
Module 4: Records systems




                                                                                                                                                                                                        accounting period but it should be clear to anyone looking at a
                                       sets in accordance with a pre-defined trigger such as cut-                                                                                                       record where the story continues, if applicable.
                                                                                         off dates?

                                                                                                        1                                                         (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                        TNA tip: this is to map links and inputs from other systems or
                                                                                                                                                                                                        record sets – in some instances some electronic records can only
                                         Where a set of records are held in electronic form, have                                                                                                       remain viable if the existing inputs from related systems are
                                         dynamic reciprocal links (or relationships to other sets of                                                                                                    maintained. In this context reciprocal links are seen as dynamic
                            145        electronic records or databases) been recorded to identify                                                                                                       as opposed to purely relational links. A simple example would be a
                                              the source and location of these related information                                                                                                      linked spreadsheet which is automatically updated when a
                                                                                                                                                                                                        database field is changed in a linked system. Knowledge of such
                                                                                           assets?
                                                                                                                                                                                                        links supports continuity planning and should form part of an
                                                                                                                                                                                                        organisation’s risk mitigation strategy.




                            Page 15                                                                                                                                                                                                       76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 4: Record                                                                                                          76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                  Page 16
                                                                                              1                                                        (your notes and evidence statement)
                                                                                              -----PLEASE SELECT------>
                              Where a set of records is held in physical form (e.g. paper,
                    146          microform) have relationships to other related physical
                                                                 records, been recorded?

                                                                                              1                                                         (your notes and evidence statement)
                                                                                              -----PLEASE SELECT------>
                              Does the corporate record keeping or record management                                                                                                          TNA tip: to ensure continued access and ultimate disposal an
                    147          system(s) record the physical location of each physical                                                                                                      organisation needs to record the location of records held in
                                         record set (e.g. ranges of physical paper files)?                                                                                                    physical form such as paper files and microfiche.
           links

              End                                                                             1                                                         (your notes and evidence statement)
                                                                                              -----PLEASE SELECT------>
                                                                                                                                                                                              TNA tip: in this context physical location means where electronic
                                Does the record keeping or record management system                                                                                                           or digital records are held, i.e. the computer system, data archive
         Contact
         details
                    148       record the physical location of each electronic record set?                                                                                                     storage and network location and should extend to the location of
                                                                                                                                                                                              back-up/security copies.

   Module 1                                                                                                                                             (your notes and evidence statement)
                                                                                              1
                                                                                              -----PLEASE SELECT------>                                                                       TNA tip: this may be directly by an end-user or by extraction from
                               Does the record keeping or record management system
                                                                                                                                                                                              a larger set of electronic information. For example EDRM
   Module 2                       record the physical hardware and software formats or
                    149       application types in which electronic record collections are
                                                                                                                                                                                              solutions normally will track the software application format of
                                                                                                                                                                                              each record as an independent metadata element within the
   Module 3                                                            created and held?                                                                                                      database.

                                                                                              1                                                         (your notes and evidence statement)
                                                                                              -----PLEASE SELECT------>
   Module 4                                                                                                                                                                                   TNA tip: for electronic or digital systems this includes a capacity
                                Does the record keeping or record management system                                                                                                           to control access to particular information if necessary, for
                                provide secure storage to the level of protection required                                                                                                    example by limiting access to named individuals or by requiring
   Module 5         150            by the nature, contents and value of the information in                                                                                                    passwords. With records held in physical form (e.g. paper files)
                                                                                    them?                                                                                                     this includes a capacity to lock storage cupboards or areas and to
   Module 6                                                                                                                                                                                   log access to them and any withdrawal of records from them.

                                                                                              1                                                         (your notes and evidence statement)
   Module 7                                                                                   -----PLEASE SELECT------>
                                Does the record keeping or record management system
                                 have the ability to provide an audit trail of occasions on
   Module 8         151         which selected records have been seen, used, amended
                                                                               and deleted?
   Module 9
                                                                                              1                                                         (your notes and evidence statement)
                                                                                              -----PLEASE SELECT------>
                                       Is information about the record keeping or record
Guidance                                                                                                                                                                                      TNA tip: contingency and continuity planning should have
                                   management system documented independent of the
                                                                                                                                                                                              identified the key information needed by the organisation about its
                    152             system to facilitate staff training, maintenance of the                                                                                                   records to enable business to resume as soon as possible in
Results                                   system and its reconstruction in the event of an                                                                                                    event of a disaster.
                                                                               emergency?
TNA

                              You've reached the end of Module 4. If you wish to check the Results sheet now, click on the link to Results. If you wish to
              Top
                              start the next module, click on link to Module 5.             Results Module 5




                    Page 16                                                                                                                                                                                                   76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                                                         76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                               Page 17
                                                                                                                                                                                      1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                                                      Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the use of all public SKIP to TNA


                                                TNA                                                                                                                                   authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience of
                                                                                                                                                                                      their record management policies and processes.

                                                                                                                                                                                      2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                                                               website page

                                                                                                                                                                                                                                                                                                               SKIP to
                                                                                                                                                                                                                                                                                                               Guidance
                                                                                                                                                                                      choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                                             Self Assessment Questionnaire for                                         Enter responses below in                       questionnaire.
                                                            compliance with the revised Records                                         answer to questions in
                                                               Management Code of Practice                                                     Module 5                                  3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                                                         worksheet in this workbook.                                                                                                   SKIP to
                                                                                                                                                                                                                                                                                                                       Results



                                                                                                                                                                                         TNA tip: Module 5 is designed to elicit if organisations have ensured that they have the
                                                                                                                                                                                         means to keep, maintain and preserve the records they will need for business, regulatory,
                                                                                                                                                                                         legal and accountability purposes after they cease to be current. It is aimed to explore if
                                                                                                                                                                                         the organisation possesses the information it needs to justify their continued retention
                                                                                                                                                                                         and has put in place appropriate policies and procedures to maintain both the physical
                                                                                                                                                                                         and the electronic records so they continue to be authentic, reliable, with the appropriate
                                                                  Module 5: Storage and                                                                                                  degree of integrity, and above all usable.
                                                                  maintenance of records                                     (your responses below)
                                links                                                                                        1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                                              TNA tip: - in order to plan an adequate maintenance strategy it is
                                         End                                                                                                                                                                                                  critical that the organisation possesses a full overview of its
                                                                                                                                                                                                                                              information assets. This extends beyond just those which may be
                         Contact                                Does the organisation possess an inventory or list of                                                                                                                         cited in a authority’s publication scheme or those information
                         details                                                                                                                                                                                                              assets identified in Information Assets Registers (IARs) as
                                                153        record sets held by the organisation or information assets                                                                                                                         available for re-use although possession of a comprehensive
           Module 1
                                                                                                available for re-use?                                                                                                                         inventory will also support the development of publication
                                                                                                                                                                                                                                              schemes and assist in identifying other information assets which
                                                                                                                                                                                                                                              may merit being incorporated within the IAR and offered for re-
           Module 2
                                                                                                                                                                                                                                              use.

           Module 3                                                                                                                                                                      (your notes and evidence statement)
                                                                                                                             1
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                                              TNA tip: that is, not just those referenced in the formal Publication
           Module 4                                                                                                                                                                                                                           Scheme - the issue here is to establish how comprehensive the
                                                                                                                                                                                                                                              list or inventory of record sets or collections is. If record sets or
                                                               Where an inventory or list of record sets exists does it                                                                                                                       data collections are excluded from the list such omissions
           Module 5                                                                                                                                                                                                                           represent a significant risk to the organisation both in terms of
                                                154          provide a comprehensive overview of all the information                                                                                                                          digital continuity but also in term of compliance with relevant
           Module 6                                                     assets within the custody of the organisation?                                                                                                                        regulation and statutes e.g. Data Protection Act 1998. Also the
                                                                                                                                                                                                                                              term custody has to extend to assets which may not be in the
                                                                                                                                                                                                                                              physical custody of the organisation i.e. records placed in out-
           Module 7
                                                                                                                                                                                                                                              sourced storage should be included.

           Module 8                                                                                                          1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                                              TNA tip: it is assumed that all electronic records held within
           Module 9                                                                                                                                                                                                                           database systems will poses a unique identifier but in the case of
                                                            Do all the records (electronic & physical) held in the sets                                                                                                                       paper files this need not be true especially where there has been
                                                155       recorded in the inventory possess a unique identifier or call                                                                                                                       a culture of relying on personal or local filing systems. In these
Guidance                                                                                                   reference?                                                                                                                         instances the absence of call references (e.g. file registration
                                                                                                                                                                                                                                              numbers) is likely to compromise the ability of the organisation to
                                                                                                                                                                                                                                              locate and retrieve records when they are required.
Results

                                                                                                                                                                                         (your notes and evidence statement)
TNA                                                              Has the organisation’s inventory or list of record sets 1-----PLEASE SELECT------>                                                                                           TNA tip: - to be usable an inventory needs to be more than list of
Module 5: Storage and maintenance of records




                                                                                                                                                                                                                                              record sets it need to include additional information concerning
                                                             identified all the sets of records (physical and electronic)
                                                156         the organisation holds relating to each business function,
                                                                                                                                                                                                                                              the creating body, the data owner, purpose served etc. This
                                          Top                                                                                                                                                                                                 question and those which follow aim to clarify how apposite the
                                                                                 with their covering dates and location?                                                                                                                      inventory is.

                                                                                                                             1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>



                                                          Does the inventory identify the specific formats in which the
                                                157          records are held e.g. paper, video, microform, software
                                                                                         and media storage formats)?



                                                                                                                             1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>

                                                           Where one exists does the inventory or list of record sets,
                                                158         record the business groups responsible for the creation,
                                                                         use and management of each record set?


                                                                                                                             1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                          Are there instances where the business group responsible
                                                                                                                                                                                                                                              TNA tip: – over time the creating business group may no longer
                                                159        for the creation, use and management of each record set                                                                                                                            be the custodian or data owner and custodians.
                                                                                             is not the data owner?


                                                                                                                             1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>

                                                             Have you identified an ‘owner’ as opposed to a creating                                                                                                                          TNA tip: – it is important that this information is held centrally and
                                                160                                group for each record collection?                                                                                                                          is kept up-to-date.



                                                                                                                             1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                                              TNA tip: the effectiveness of records systems depends on
                                                                                                                                                                                                                                              knowledge of what records are held, what information they
                                                            Does the organisation have a record of the reasons why                                                                                                                            contain, in what form they are made accessible, what value they
                                                              specific record sets are required to be maintained (i.e.                                                                                                                        have to the organisation and how they relate to organisational
                                                161       what is the business requirement served by these records)                                                                                                                           functions. Absence of this knowledge means the organisation is
                                                                                                   and for how long?                                                                                                                          unable to apply the controls required to manage the risks
Module 5: Storage and maintenance of records




                                                                                                                                                                                                                                              contained within the records or to dispose of them at the due time
                                                                                                                                                                                                                                              in an appropriate manner.

                                                                                                                             1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                                               TNA tip: locating refers to the means used to reliably identify
                                                                                                                                                                                                                                              without undue difficulty the record or records needed to satisfy
                                                          Are the organisation’s record sets located and described in                                                                                                                         the user’s query. The location within the business classification
                                                                                                                                                                                                                                              schema or file-plan is one aspect but also the issue of appropriate
                                                                   such manner so they can be reliably identified and
                                                162            retrieved in a usable form for business purposes or to
                                                                                                                                                                                                                                              indexes, accurate titling, meaningful nomenclature and the use of
                                                                                                                                                                                                                                              aliases or alternative titling fall into this area. For example
                                                          respond to an information request without undue difficulty?                                                                                                                         collections of paper files for which an organisation does not
                                                                                                                                                                                                                                              possess an index would be effectively irretrievable and represent
                                                                                                                                                                                                                                              a real risk to the organisation.


                                                                                                                             1                                                           (your notes and evidence statement)
                                                                                                                             -----PLEASE SELECT------>
                                                                                                                                                                                                                                              TNA tip: the issue here is the development of an appropriate set
                                                             Does the organisation possess a Digital Preservation or                                                                                                                          of strategies which will implement the organisation’s Digital
                                                163          Maintenance Policy to ensure non current electronic or                                                                                                                           Preservation or Maintenance Policy. The National Archives can
                                                                           digital records remain usable over time?                                                                                                                           provide guidance on the key attributes required to secure
                                                                                                                                                                                                                                              effective preservation and digital continuity.

                                                                                                                                                                                         (your notes and evidence statement)
                                                                    Where one exists does the Digital Preservation or 1  -----PLEASE SELECT------>
                                                                                                                                                                                                                                              TNA tip: digital preservation can be expensive so there needs to
                                                               Maintenance Policy address the strategic alignment of
                                                164            digital preservation to the core functions and business
                                                                                                                                                                                                                                              be clarity about which records shall be subject to the regime and
                                                                                                                                                                                                                                              the overriding principles which need to inform it.
                                                                                         objectives of the organisation?




                                                Page 17                                                                                                                                                                                                                        76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 5: Storage an                                                                                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                      Page 18
                                                                                                                            1                                                        (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
                                                           Where a Digital Preservation or Maintenance Policy exists
                                                         is there a clear mechanism for the systematic review of the
                                               165        Policy in the light of new / future accessions or changes to
                                                                                        the technological environment?

                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>                                                                        TNA tip: it is anticipated that records subject to this regime will be
                                                          Where a Digital Preservation or Maintenance Policy exists                                                                                                          managed on dedicated preservation system(s) and this will have
                                                                                                                                                                                                                             to address the need for management standards for import or
                                                                   does it mandate standards for ingest, including
                                               166            technological and descriptive standards and transfer
                                                                                                                                                                                                                             “ingest” as it is termed of the records into the new storage
                                                                                                                                                                                                                             environment and the need for descriptive metadata which will
                                                                                                  documentation?                                                                                                             augment what already exists to support future attestations of
Module 5: Storage and maintenance of records




                                                                                                                                                                                                                             authenticity.

                                                                                                                                                                                       (your notes and evidence statement)
                                                            Does the organisation possess a Digital Preservation or 1   -----PLEASE SELECT------>
                                                                                                                                                                                                                             TNA tip: The National Archives can provide guidance on the key
                                                           Maintenance Strategy to address the maintenance of the
                                               167       informational, usability and evidential characteristics of the
                                                                                                                                                                                                                             attributes required to secure effective preservation and digital
                                                                                                                                                                                                                             continuity.
                                                                                                             records?
                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>


                                                             Where a Digital Preservation or Maintenance Strategy                                                                                                            TNA tip: this should include technical architecture, security,
                                               168           exists does the strategy specify standards for storage?                                                                                                         replication and media monitoring and refreshing.



                                                                                                                                                                                       (your notes and evidence statement)
                                                              Where a Digital Preservation or Maintenance Strategy 1  -----PLEASE SELECT------>
                                                            exists does the strategy address the planning and timely
                                               169        execution of preservation actions to mitigate technological
                                                                                                      obsolescence?
                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>

                                                              Where a Digital Preservation or Maintenance Strategy
                                                                   exists does the strategy address the auditability of
                                               170       individual preservation actions through provision of specific
                                                           and intelligible audit trails in the preservation solution(s)?


                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>



                                                              Where a Digital Preservation or Maintenance Strategy
                                                                                                                                                                                                                             TNA tip: - this will need to include checksums, virus checking /
                                               171                     exists have standard ingest procedures and                                                                                                            quarantining.
                                                                                  documentation been developed?



                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
                                                                                                                                                                                                                             TNA tip: - electronic or digital records are mutable and can be
Module 5: Storage and maintenance of records




                                                                                                                                                                                                                             easily modified and therefore require a more pro-active regime to
                                                               Where the organisation possesses a list of electronic                                                                                                         ensure they continue to be unchanged and usable. It is also
                                                                                                                                                                                                                             anticipated that over time it will be necessary to migrate records in
                                                            record sets, has a regime been established to apply the
                                               172       required controls needed to manage and mitigate the risks
                                                                                                                                                                                                                             certain formats to alternative formats to ensure readability and
                                                                                                                                                                                                                             such renditions will require the application of equivalent controls
                                                              associated with the continued custody of the records?                                                                                                          to secure subsequent attestations of authenticity. In contrast
                                                                                                                                                                                                                             physical records require secure storage supported by appropriate
                                                                                                                                                                                                                             finding aids to ensure accurate retrieval.).


                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
                                                                                                                                                                                                                             TNA tip: - the issue here is to clarify to what extent the
                                                                                                                                                                                                                             organisation knows what it has in its custody and has an
                                                                Where the organisation has established a corporate                                                                                                           understanding of the risks they present. The term corporate
                                                          control regime in accordance with the Digital Preservation                                                                                                         control regime has refers to the establishment of policies,
                                                          or Maintenance Strategy to manage and mitigate the risks                                                                                                           procedures and resources to implement the required strategy.
                                               173            associated with the continued custody of its electronic                                                                                                        Where a control regime exists but has not been implemented this
                                                           records over time, what percentage of the organisation’s                                                                                                          identifies a real ongoing risk to the organisation as the electronic
                                                                                                                                                                                                                             record sets which are not subject to the regime can be amended
                                                                      information assets are subject to this regime?                                                                                                         without appropriate safeguards which can compromise future
                                                                                                                                                                                                                             attestations of authenticity.

                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>



                                                               Where the organisation has established a corporate
                                                                   control regime to manage and mitigate the risks
                                                              associated with the continued custody of its electronic
                                               174        records over time does it incorporate a strategy to ensure
                                                            records in electronic form are maintained for as long as
                                                                                                  they are needed?




                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>

                                                                                                                                                                                                                             TNA tip: all sound record keeping systems should make provision
                                                               Where the organisation has established a corporate                                                                                                            for controlled disposal and destruction but in the case of
                                                                   control regime to manage and mitigate the risks                                                                                                           electronic records which are subject to a long term maintenance
                                               175            associated with the continued custody of its electronic                                                                                                        or preservation regime it may be necessary to incorporate
Module 5: Storage and maintenance of records




                                                                records over time does it provide for the disposal of                                                                                                        additional functionality and tools to ensure audited disposal
                                                                                                                                                                                                                             occurs on the due date and that all attendant renditions and
                                                                        records when they are no longer required?
                                                                                                                                                                                                                             copies are removed at the same time.



                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>


                                                          Do the storage standards adopted by the organisation for
                                                          preservation of electronic or digital content provide for the
                                               176             protection of record content in its present form from
                                                                                              unauthorised alteration?



                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>

                                                            Has the organisation provided storage for the records to                                                                                                         TNA tip: records and information will vary in their strategic and
                                                                                                                                                                                                                             operational value to the authority, and in their residual value for
                                               177            provide protection to the level required by the nature,                                                                                                        historical research, and storage and preservation arrangements
                                                                     contents and value of the information in them?                                                                                                          reflecting their value should be put in place.



                                                                                                                            1                                                          (your notes and evidence statement)
                                                                                                                            -----PLEASE SELECT------>
                                                                                                                                                                                                                             TNA tip: – Preservation requires trusted intervention in the
                                                                                                                                                                                                                             encoding of information contained in records: it is important that
                                                                     Have mechanisms been established to prevent                                                                                                             the controls applied to current records are maintained especially
                                                            unauthorised modification of electronic records migrated                                                                                                         where the organisation has determined to migrate electronic
                                               178       or rendered to alternative software formats whilst providing                                                                                                        records to a preferred alternative format to ensure preservation of
                                                          for the addition of authorised annotations where required?                                                                                                         the record over time. Records rendered into such formats should
                                                                                                                                                                                                                             normally have the same controls applied to them to avoid the
                                                                                                                                                                                                                             integrity of the maintained record being compromised.




                                               Page 18                                                                                                                                                                                                        76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
records
Module 5: St                                                                                                                                          76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                       Page 19
                                                                                                                          1                                                        (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                             Are there at least two copies of every electronic record
                                                                                                                                                                                                                           TNA tip: unmonitored offline storage on its own carries an
                                                            held at all times and an effective method for comparing
                                               179       and synchronising them correctly where any discrepancy is
                                                                                                                                                                                                                           unacceptable level of risk as the records can degrade to the point
                                                                                                                                                                                                                           they are unreadable.
                                                                                                           detected?

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
Module 5: Storage and maintenance of records




                                                                                                                                                                                                                           TNA tip: - procedures will need to be established to maintain a
                                                                Are there agreed triggers to review existing software                                                                                                      technology watch to take account of software format
                                               180           formats to ensure usability and to avoid obsolescence?                                                                                                        obsolescence which when it becomes apparent may, require the
                                                                                                                                                                                                                           creation of duplicate records in an alternative software format.



                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>                                                                        TNA tip: long term maintenance of electronic or digital records
                                                            Is there an agreed process for choosing the appropriate                                                                                                        requires a preservation regime. This needs to be clearly defined
                                               181          storage method for electronic records and to review the                                                                                                        and should be subject to formal periodic review and proposals to
                                                                                                method over time?                                                                                                          change the methodology should be formally approved before
                                                                                                                                                                                                                           being adopted.

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                          Where an established process exists to determine how to
                                                                choose the appropriate storage method is there a
                                               182           validation mechanism to confirm the chosen method
                                                                                    continues to be appropriate?

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                              Does the organisation’s business continuity or disaster
                                               183               management programme or plan include records
                                                                                                     maintenance?


                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                                                                                                                                                                                           TNA tip: Storage regimes for physical records can be
                                                                                                                                                                                                                           benchmarked against appropriate standards and best practice
                                                              Does the business continuity or disaster management                                                                                                          guidance. Electronic records will probably be stored on servers
                                                                                                                                                                                                                           and may be mirrored or alternatively copies may be held off-line.
                                                              programme or plan identify resource requirements to
                                               184            ensure records continue to be maintained or securely
                                                                                                                                                                                                                           In the latter event the robustness of the data recovery regime
                                                                                                                                                                                                                           using back-ups needs to be regularly evaluated as dependence
                                                                              recovered in the event of a disaster?                                                                                                        on back-ups without regular testing can be very problematic and
                                                                                                                                                                                                                           could compromise the effectiveness of the organisation to restore
                                                                                                                                                                                                                           its records.

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                                                                                                                                                                                           TNA tip: the presence of an incomplete record may compromise
                                                                   Has there been an assessment of the risk to the                                                                                                         the evidential weight of the restored record and there should be a
                                               185             organisation where restored records are incomplete?                                                                                                         method to evaluate this matter when it becomes known and to
Module 5: Storage and maintenance of records




                                                                                                                                                                                                                           document this issue to support future attestations of authenticity.


                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                                    Has there been an assessment of the risk to the                                                                                                        TNA tip: the absence of audit functionality may compromise the
                                                                                                                                                                                                                           evidential weight of the restored record and there should be a
                                               186       organisation where restored records have limited auditable                                                                                                        method to evaluate this matter when it becomes known and to
                                                                                                      functionality?                                                                                                       document this issue to support future attestations of authenticity.

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>                                                                        TNA tip: - this can be especially important when reliance is placed
                                                                                                                                                                                                                           on outsourced third party storage provider. .BS 4783 Storage,
                                                             Has the organisation defined appropriate standards for
                                               187                storing or transporting records in electronic form?
                                                                                                                                                                                                                           transportation and maintenance of media for use in data
                                                                                                                                                                                                                           processing and information storage can be a useful benchmark
                                                                                                                                                                                                                           here.

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>

                                                             Does guidance provide for metadata to be transferred                                                                                                          TNA tip: the quality of the metadata available will vary according
                                                                                                                                                                                                                           to the nature of the system upon which the records are stored.
                                                                 when exporting or transferring electronic records to                                                                                                      For example if the records are held on an ERM or EDRM system
                                                         another organisation (e.g. because of a transfer of function                                                                                                      which supports the e-GMS record management metadata
                                                                 or to preserve the records in a specialist archive) in                                                                                                    standard the quality measure will be the ability of the system to
                                               188              addition to the record content in order to ensure the                                                                                                      export selected records with such metadata. For other systems
                                                                recipient acquires records which can be considered                                                                                                         the rationale will be the ability to export and associate metadata
                                                                                                                                                                                                                           which provides all the information required to place the records in
                                                              authentic, reliable, possess integrity and are usable in                                                                                                     context and enable them to be usable for the purpose required by
                                                                                      accordance with BS ISO 15489                                                                                                         the acquiring institution.


                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                                                                                                                                                                                           TNA tip: - It is unrealistic to assume perfect preservation of all
                                                                                                                                                                                                                           attributes is feasible or cost-effective. ”Significant properties” is a
                                                           Is there a method for evaluating the significant properties                                                                                                     term used to encompass the attributes of records required to be
                                               189                                   of electronic or digital records?                                                                                                     preserved across time and technological change. For different
                                                                                                                                                                                                                           records, it may variously include fixed content, formal structure,
                                                                                                                                                                                                                           appearance, behaviour and / or aspects of usability.


                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                           Are there triggers to identify when migration of electronic
                                               190        records is needed to avoid obsolescence or degradation?

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
Module 5: Storage and maintenance of records




                                                            Are there monitoring mechanisms or other measures to                                                                                                           TNA tip: - this question extends to include back-up copies as part
                                               191            assess whether electronic records are still readable?                                                                                                        of business continuity planning.


                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                          Have minimum information levels been defined within the
                                               192        management audit trail for each maintenance process to
                                                            ensure the maintenance of reliable electronic records?

                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                                                                                                                                                                                           TNA tip: this question is about integrity in the preservation
                                                                                                                                                                                                                           environment and is not the same question as 155. Examples
                                                                                                                                                                                                                           include maintenance of metadata from the creation environment
                                                                  Do the organisation’s descriptive standards for the                                                                                                      in a tightly bound relationship to the digital objects at all times
                                                             management of preserved electronic or digital records                                                                                                         ("tightly bound" may mean relational linkage or encapsulation);
                                               193           include a comprehensive, robust and durable identifier                                                                                                        support for discovery, browse and retrieval of records by
                                                                            system within the preservation solution?                                                                                                       authorised user; linking of newly-migrated record content to
                                                                                                                                                                                                                           contextual metadata, the capturing of descriptive metadata to
                                                                                                                                                                                                                           support and record the preservation and security functions
                                                                                                                                                                                                                           applied to the record(s).


                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>
                                                                                                                                                                                                                           TNA tip: this is to ensure conformance with FOI and Data
                                                         In the event backed-up data is required to be restored onto                                                                                                       Protection requirements. In this context the term "relevant policy”
                                                           a live system, does the relevant policy make provision for                                                                                                      has been used as the specific provision may appear in a variety
                                                          the removal from the back up copies of any records which                                                                                                         of policy or procedural documents depending on the way an
                                               194                were formally destroyed or transferred from the live                                                                                                     organisation has addressed this issue for example it may be the
                                                          system, in accordance with an authorised procedure, after                                                                                                        Record Management Policy itself, the Digital Preservation Plan,
                                                                                                                                                                                                                           or even as a back up procedure detailed within the IT security
                                                                                           the back up was created?                                                                                                        policy of the organisation.


                                                                                                                          1                                                          (your notes and evidence statement)
                                                                                                                          -----PLEASE SELECT------>


                                                                Where the organisation relies on data backed up on
                                                            external media held off-line (e.g. disks and tapes) is this
                                               195            stored at a geographically separate location to ensure
                                                                                  access in the event of a disaster?
                                links




                                               Page 19                                                                                                                                                                                                      76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
M                                                                                                                76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                     Page 20
   End                                                                               1                                                        (your notes and evidence statement)
                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                      TNA tip: authorities should be aware of any specific requirements
                              Has the organisation clarified the various levels of                                                                                                    for records storage that apply to them. For example, the Adoption
  Contact                   protection required for its physical records based on                                                                                                     National Minimum Standards issued by the Department of Health
  details   196            nature, content and value to ensure it can specify the                                                                                                     and the Welsh Assembly Government in 2003 require indexes
                                              appropriate storage requirement?                                                                                                        and case files for children to be securely stored to minimise the
 Module 1                                                                                                                                                                             risk of damage from fire or water.

                                                                                     1                                                          (your notes and evidence statement)   TNA tip: records held in the form of paper files which are no in
 Module 2                                                                            -----PLEASE SELECT------>
                        Is there a comprehensive index or indexes to locate and                                                                                                       current use and stored off-site need to be adequately indexed with
            197                        retrieve physical records upon demand?                                                                                                         unique references to enable accurate retrieval and subsequent
 Module 3                                                                                                                                                                             tracking.

                                                                                     1                                                          (your notes and evidence statement)
 Module 4                                                                            -----PLEASE SELECT------>
                        Are the storage areas allocated to hold physical records
            198                adequate to accommodate anticipated accruals?
 Module 5


 Module 6                                                                            1                                                          (your notes and evidence statement)
                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                      TNA tip: – records which are held temporarily prior to destruction
                                                                                                                                                                                      do not require the rigorous storage regime required for records of
 Module 7
                                                                                                                                                                                      historical value which are of permanent archival value. However
                      Do the storage areas for physical records (e.g. paper files)                                                                                                    all records should be stored to ensure they continue to be usable
 Module 8   199        conform to agreed environmental and security standards                                                                                                         for as long as they are required, are kept securely and are
                                                     for the storage of records?                                                                                                      referenced to ensure rapid retrieval when required. Guidance on
                                                                                                                                                                                      this topic has been published by The National Archives -
 Module 9
                                                                                                                                                                                      Identifying and Specifying Requirements for Offsite Storage of
                                                                                                                                                                                      Physical Records.
Guidance
                                                                                     1                                                          (your notes and evidence statement)
                                                                                     -----PLEASE SELECT------>                                                                        TNA tip: - where semi current records have been stored in the
Results                      Are the storage areas set aside for physical records                                                                                                     care of a third party contractor it is prudent to have established an
            200                                             regularly inspected?                                                                                                      entitlement to periodically visit the premises where the records are
                                                                                                                                                                                      stored.
TNA
website
                      You've reached the end of Module 5. If you wish to check the Results sheet now, click on the link to Results. If you wish to
   Top
                      start the next module, click on link to Module 6.             Results Module 6




            Page 20                                                                                                                                                                                                   76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                                           Page 21
                                                                                                                                                       1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised
                                                                                                                                                       Records Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the                  SKIP to TNA

                                TNA                                                                                                                    use of all public authorities subject to the Act but can also be used by any organisation or body to assess the quality
                                                                                                                                                       and resilience of their record management policies and processes.
                                                                                                                                                                                                                                                                                       website page


                                                                                                                                                          2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                          choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                            Self Assessment Questionnaire for                                     Enter responses below in                questionnaire.
                                           compliance with the revised Records                                     answer to questions in
                                              Management Code of Practice
                                                                                                                                                          3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results
                                                                                                                                                          Chart worksheet in this workbook.                                                                                            SKIP to
                                                                                                                                                                                                                                                                                       Results



                                                                                                                                                          TNA tip: Module 6 is designed to elicit if organisations have ensured that they have
                                                                                                                                                          established effective information security measures for the storage, handling and
                                                                                                                                                          transmission of records together with appropriate access control and recording functions
                                                                                                                                                          to prevent sensitive information from being disclosed both internally and externally.
                                                                                                                                                          Particular care has be taken with personal information about living individuals in order to
                                                                                                                                                          comply with the 7th data protection principle, which requires precautions against
                                                                                                                                                          unauthorised or unlawful processing, damage, loss or destruction
                                           Module 6: Security and access                                (your responses below)
                   links                                                                                1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                          Does the organisation have an information security policy                                                                                                            TNA tip: it is good practice to have an information security
                         End
                                                to ensure that their storage arrangements, handling                                                                                                            policy addressing these points benchmarked on a recognised
               Contact
                                201       procedures and arrangements for transmission of records                                                                                                              standard e.g. BS ISO/IEC 27001:2005/BS 7799-2:2005
               details                              reflect accepted standards and good practice in                                                                                                            Information Technology. Security Techniques. Information
                                                                                                                                                                                                               Security - Requirements.
                                                                                information security?
     Module 1
                                                                                                        1                                                 (your notes and evidence statement)                  TNA tip: This should normally be at senior executive level,
                                                                                                        -----PLEASE SELECT------>
     Module 2                                                                                                                                                                                                  giving a designated individual explicit responsibility for ensuring
                                      Do the organisation’s corporate governance arrangements                                                                                                                  that the organisation handles personal information in a way that
                                                                                                                                                                                                               meets all legal and good-practice requirements. Audit
     Module 3                         on the handling or sharing of personal data (both internally
                                202    and externally) clarify where ownership and accountability
                                                                                                                                                                                                               committees should monitor the arrangements and their
                                                                                                                                                                                                               operation in practice. Such mechanisms are recommended
     Module 4                                                lie within the management structure?                                                                                                              within the Thomas - Walport Data Sharing Review
                                                                                                                                                                                                               Report:http://www.justice.gov.uk/reviews/docs/data-sharing-             Web link
                                                                                                                                                                                                               review-report.pdf.
     Module 5
                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
     Module 6                         Has the organisation established a mechanism to permit a                                                                                                                 TNA tip: Such a review should be conducted on an annual
                                                                                                                                                                                                               basis and a formal report provided to senior management for
                                203    regular periodic review of its systems of internal controls                                                                                                             dissemination to provide evidence of accountability and
     Module 7                                     over using and sharing personal information?                                                                                                                 transparency.

     Module 8
                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>                                                                              TNA tip: Ease of internal access will depend on the nature and
     Module 9                                                                                                                                                                                                  sensitivity of the records. Access restrictions should be applied
                                                                                                                                                                                                               when necessary to protect the information concerned and
                                                                                                                                                                                                               should be kept up to date. Particular care should be taken with
Guidance                                      Have appropriate access controls been established to                                                                                                             personal information about living individuals in order to comply
                                                                                                                                                                                                               with the 7th data protection principle, which requires
                                204          provide and record authorised access to records (in all                                                                                                           precautions against unauthorised or unlawful processing,
Results                                                formats) and prevent unauthorized access?                                                                                                               damage, loss or destruction. Within central Government,
                                                                                                                                                                                                               particular care should be taken with information bearing a
TNA                                                                                                                                                                                                            protective marking. Other information, such as information
                                                                                                                                                                                                               obtained on a confidential basis, may also require particular
                                                                                                                                                                                                               protection.
                         Top
                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                               TNA tip: - this is distinct from merely preventing unauthorised
                                                                                                                                                                                                               access it is about the capability to record unauthorised attempts
                                                                                                                                                                                                               to access records where the user does not possess the
                                                Do the recordkeeping systems used by the authority                                                                                                             relevant access permissions to view content. The need for this
                                                                                                                                                                                                               is only likely to arise where there is a need for an especially
                                205            record attempts of unauthorised access to electronic                                                                                                            rigorous security regime and logically arises where users can
                                                                                          records?                                                                                                             legitimately browse and search on metadata related to the
Module 6: Security and access




                                                                                                                                                                                                               embargoed records but permission to view the content is
                                                                                                                                                                                                               prohibited. Persistent attempts to view embargoed records can
                                                                                                                                                                                                               be used to identify potential security breaches.


                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                               TNA tip: - this question is likely only to be relevant to those
                                                                                                                                                                                                               organisations where protective markings are used to identify
                                                                                                                                                                                                               records subject to the Protective Marking Scheme (e.g. Protect,
                                                  Where applicable do the record keeping or record                                                                                                             Restricted, Confidential, Secret, etc.) The purpose of the
                                             management systems maintained by the organisation                                                                                                                 question is to determine if security protective marking applies to
                                206       record the application of protective markings to individual                                                                                                          an entire record set or collection, or to identify that a security
                                                                              records or record sets?                                                                                                          marking applies to specific records within a record set. Use of
                                                                                                                                                                                                               the full Protective Marking Scheme will normally be confined to
                                                                                                                                                                                                               central government departments and agencies but the use of
                                                                                                                                                                                                               the Protect marking itself is likely to arise in other public bodies.


                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>                                                                              TNA tip: - this refers to a capability to hold as associated
                                                                                                                                                                                                               metadata the nature and date of application of the specific set
                                                  Where applicable do the record keeping or record                                                                                                             of access controls applied to a record. This then enables
                                207           management systems record the nature of the access                                                                                                               authorised staff to subsequently undertake searches to identify
                                            controls applied to each record set or individual record?                                                                                                          records which are subject to certain access controls and review
                                                                                                                                                                                                               their relevance. EDRM systems for example possess this
                                                                                                                                                                                                               functionality.

                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
Module 6: Security and access




                                           Where applicable, what proportion of the record keeping
                                          or management systems maintain a chronological record                                                                                                                TNA tip: - many EDRM systems provide this functionality and in
                                208           of the changes to the access controls that have been                                                                                                             a very security conscious environment this can be a useful tool.
                                                    applied to each record set or individual record?


                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                               TNA tip: - this goes beyond a corporate injunction prohibiting
                                                                                                                                                                                                               the use of local encryption tools or the application of personal
                                               Where applicable does the organisation possess the                                                                                                              passwords to individual records but extends to both the
                                209           capability to ensure continued access to encrypted or                                                                                                            functionality which may prevent this from happening or where it
                                                                      password-protected records?                                                                                                              is exceptionally permitted the existence of a capability to
                                                                                                                                                                                                               remove these controls to ensure continued access by
                                                                                                                                                                                                               authorised users within the organisation)

                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                             Do procedures allow for authorised changes in access
                                210                                        permissions over time?

                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>                                                                              TNA tip: - people change jobs and will have different
                                             Does the organisation maintain a record of the access                                                                                                             permissions over time. In some environments it is desirable to
                                211          permission and role rights given to an individual user?                                                                                                           maintain a record of what permissions were allocated, by whom
                                                                                                                                                                                                               and date of allocation.

                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
Module 6: Security and access




                                          Have procedures been established to effect extraordinary                                                                                                             TNA tip: this question is concerned with the access regime for
                                                                                                                                                                                                               all personnel where there is a need to provide additional
                                             access requests to the records by personnel within the
                                212       organisation to ensure these are appropriately authorised
                                                                                                                                                                                                               extraordinary access rights to an individual as opposed to those
                                                                                                                                                                                                               access rights an individual might possess via the role they are
                                                                                    and managed?                                                                                                               assigned to by the employing organisation.

                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>

                                      Does the organisation possess the capability to create and                                                                                                               TNA tip: depending on the security requirement it may
                                                                                                                                                                                                               necessary to capture a record of each time a record is
                                213          maintain audit trails of instances where records are                                                                                                              accessed and by whom irrespective of the access controls
                                                                  accessed of access to records?                                                                                                               applied to a record.



                                                                                                        1                                                 (your notes and evidence statement)
                                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                               TNA tip: the issue here is where a copy of information held by
                                              Does the organisation have audit trails of provision of                                                                                                          the organisation is taken for presentation, or alternatively
                                214        access to records, to people outside the immediate work                                                                                                             disseminated, to an external audience that a record or audit trail
                                                                                               area?                                                                                                           of these occasions is created. Absence of such protocols
                                                                                                                                                                                                               indicates a heighted risk of undocumented disclosure.


                                Page 21                                                                                                                                                                                                                                76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
ccess
Module 6: Sec
                                                                                                                                        76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                         Page 22
                                                                                                            1                                              (your notes and evidence statement)
                                                                                                            -----PLEASE SELECT------>
                                             When records or the information contained within them
                                                                                                                                                                                                  TNA tip: The intention here is to prevent inadvertent disclosure
                                             are transmitted beyond the organisation’s premises are
                                 215       there procedures in place to ensure prior authorisation is
                                                                                                                                                                                                  or data loss and the method of transmission should be subject
                                                                                                                                                                                                  to risk assessment before a decision is made.
                                                                obtained before the work proceeds?
Module 6: Security and access




                                                                                                            1                                               (your notes and evidence statement)
                                                                                                            -----PLEASE SELECT------>
                                              Does the organisation have procedures to ensure that
                                               where external access to records and information is
                                 216               provided that this is in accordance with relevant
                                                                                        legislation?
                                                                                                                                                            (your notes and evidence statement)
                                             Where applicable does the audit trail provided by the 1   -----PLEASE SELECT------>                                                                  TNA tip: the presence of an audit trail that has this capability
                                            record keeping or record management system permit                                                                                                     provides the means to monitor compliance with the information
                                                                                                                                                                                                  security rules adopted by the organisation and ensures
                                 217   searching on selected criteria from within the audit trail i.e.                                                                                            transparency when accounting for activities subsequently in
                                             selected record(s), user role, date and event such as                                                                                                relation to requests for information under the Freedom of
                                                          creation, viewing, editing and deletion)?                                                                                               Information Act 2000.

                                                                                                            1                                               (your notes and evidence statement)   TNA tip: - to be effective these should be based on known
                                                                                                            -----PLEASE SELECT------>
                                                                                                                                                                                                  specified criteria relevant to the organisation including but not
                                                Where applicable does the audit trail provided by the                                                                                             limited to the following elements individually or in any
                                                                                                                                                                                                  combination:
                                             record keeping or record management system have the
                                 218           capability of generating reports upon demand against
                                                                                                                                                                                                  Title or unique ID of the record
                                                                                                                                                                                                  User name or ID
                                                           selected criteria held within the audit trail?                                                                                         Date range.
                                                                                                                                                                                                  Event (i.e. creation, modification, viewing or other tracked
                                                                                                                                                                                                  activity).

                                                                                                            1                                               (your notes and evidence statement)
                                                                                                            -----PLEASE SELECT------>                                                             TNA tip: - in cases involving the likelihood of substantial
                                                    Does the organisation have a policy to notify the                                                                                             damage or distress, the Thomas- Walport report on the Data
                                 219       Information Commissioner of significant breaches of data                                                                                               Sharing Review recommended that the Commissioner should
                                                                                           security?                                                                                              take into account any failure to notify when deciding what, if
                                                                                                                                                                                                  any, penalties to set for a data breach.
                     links
                                                                                                            1                                               (your notes and evidence statement)
                                                                                                            -----PLEASE SELECT------>                                                             TNA tip: request for information may involve records which are
                           End
                                                 Are external requests for information including data                                                                                             sensitive or subject to disclosure exemptions. It is highly
                                                                                                                                                                                                  desirable a record of these requests is maintained to
                 Contact         220               subject access requests categorised, logged and                                                                                                demonstrate compliance with information legislation e.g.
                 details                                      registered within an auditable system?                                                                                              Freedom of Information Act 2000 and Data Protection Act
                                                                                                                                                                                                  1998.
       Module 1                                                                                                                                             (your notes and evidence statement)
                                                                                                            1
                                                                                                            -----PLEASE SELECT------>
                                                                                                                                                                                                  TNA tip: - this may be captured as additional metadata
                                                                                                                                                                                                  associated with the actual record(s) within the record keeping
       Module 2                               Where an organisation has a request tracking system
                                 221              does it record which information was disclosed?
                                                                                                                                                                                                  systems. In cases of partial disclosure it is desirable to maintain
                                                                                                                                                                                                  a record of what was disclosed for example in the form of a
       Module 3                                                                                                                                                                                   copy of the redacted record which was actually released.

                                                                                                            1                                               (your notes and evidence statement)
       Module 4                                                                                             -----PLEASE SELECT------>                                                             TNA tip: both to ensure and demonstrate consistency in
                                              Where an organisation has a request tracking system                                                                                                 managing enquiries about the same type of information it is
                                                                                                                                                                                                  highly desirable this information is captured. Where refusal
       Module 5                  222          record, does it record which FOI exemption(s) applied                                                                                               notices are appealed at the Information Tribunal it may be
                                                                     when information was withheld?                                                                                               necessary to demonstrate that the organisation has applied
       Module 6                                                                                                                                                                                   exemptions consistently.

                                                                                                            1                                               (your notes and evidence statement)
                                                                                                            -----PLEASE SELECT------>                                                             TNA tip: - some EDRM systems have the capability of creating
       Module 7                           Where some information has been provided and some                                                                                                       a copy of a redacted record combined with a metadata
                                                withheld does the record keeping system have the                                                                                                  association linking to the original record. Such functionality
       Module 8                  223   capability of holding a copy of the redacted instance which                                                                                                provides evidence that the organisation has applied exemptions
                                                                                     was supplied?                                                                                                consistently. Where this is not possible a clear record of what
                                                                                                                                                                                                  was redacted should be created and maintained.
       Module 9
                                                                                                            1                                               (your notes and evidence statement)
                                                                                                            -----PLEASE SELECT------>
                                                                                                                                                                                                  TNA tip: - depending on the nature of the infrastructure it can
Guidance                                   Where an organisation has implemented an electronic                                                                                                    be possible to provide direct links from the information request
                                       record management system (ERMS) is this used to record                                                                                                     tracking system to the actual records held within the record
                                 224       disclosures under the FOI Act by providing links to the                                                                                                keeping system. This can be beneficial if similar requests are
Results
                                                                              disclosed records?                                                                                                  subsequently received as it is possible then to look at what was
                                                                                                                                                                                                  done previously to support a consistent approach.
TNA

                                       You've reached the end of Module 6. If you wish to check the Results sheet now, click on the link to Results. If you wish to
                           Top
                                       start the next module, click on link to Module 7.             Results Module 7




                                 Page 22                                                                                                                                                                                                                 76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                                       76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                               Page 23
                                                                                                                                                                    1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                                    Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the use of all public SKIP to TNA


                                TNA                                                                                                                                 authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience of
                                                                                                                                                                    their record management policies and processes.

                                                                                                                                                                    2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                                             website page

                                                                                                                                                                                                                                                                                             SKIP to
                                                                                                                                                                                                                                                                                             Guidance
                                                                                                                                                                    choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                             Self Assessment Questionnaire for                                      Enter responses below in                        questionnaire.
                                            compliance with the revised Records
                                                                                                                     answer to questions in
                                               Management Code of Practice
                                                                                                                                                                       3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                                       worksheet in this workbook.                                                                                                 SKIP to
                                                                                                                                                                                                                                                                                                   Results




                                                                                                                                                                       TNA tip: Module 7 is designed to elicit if organisations have defined how long they need to
                                                                                                                                                                       keep particular records, the measures and procedures required to dispose of them when
                                                                                                                                                                       they are no longer needed and the ability to explain why records are no longer held.

                                            Module 7: Disposal of records                                  (your responses below)
                    links                                                                                                                                              (your notes and evidence statement)
                                                                                                           1
                                                                                                           -----PLEASE SELECT------>
                          End                                                                                                                                                                                               TNA tip: the key criteria are:
                                                                                                                                                                                                                            a)        Reflect the authority’s continuing need for access to the
               Contact                                                                                                                                                                                                      information or the potential value of the records for historical or
               details                                                                                                                                                                                                      other research;
                                            Has the organisation established a policy for the disposal
                                                                                                                                                                                                                            b)        Are based on consultation between records management
                                225        of its records in accordance with the criteria defined within                                                                                                                    staff, staff of the relevant business unit and, where appropriate,
      Module 1                                               the revised Records Management Code?                                                                                                                           others such as legal advisers, archivists or external experts;
                                                                                                                                                                                                                            c)        Have been formally adopted by the authority;
      Module 2                                                                                                                                                                                                              d)        Are applied by properly authorised staff;
                                                                                                                                                                                                                            e)        Take account of security and confidentiality needs
      Module 3

                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
      Module 4                                      What percentage of the business units within the
                                            organisation possess selection and disposal policies and                                                                                                                        TNA tip: in order to ascertain the risks posed by non compliance it
      Module 5
                                226             accompanying disposal schedules to address all the                                                                                                                          is necessary to clarify the scale of compliance.
                                                      records created or held by each business unit?
      Module 6
                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                                            TNA tip: it is assumed that with the advent of electronic record
      Module 7
                                                                                                                                                                                                                            management that information will increasingly be shared and
                                               Are there disposal schedules for records common to                                                                                                                           accessed laterally across an organisation. In such circumstances
      Module 8                                                                                                                                                                                                              it is likely that an increasing number of disposal schedules would
                                227           several business units? (e.g. financial records, human                                                                                                                        be common to a number of business units as opposed to the
                                                 resources, health and safety and project records).                                                                                                                         maintenance of a large number of unique disposal schedules
      Module 9                                                                                                                                                                                                              which are specific to certain units. Adoption of this approach
                                                                                                                                                                                                                            should ease the management of the organisation’s schedules.
Guidance
                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>

Results
                                           If there is no system to implement disposal in accordance                                                                                                                        TNA tip: the longer the elapsed period before full roll-out
                                                                                                                                                                                                                            increases the risk to the organisation for example full roll out
TNA                             228        with the code, is there a plan and a timetable to introduce                                                                                                                      within 12 months should constitute a minor risk completion of roll-
                                                                                                  one?                                                                                                                      out in say 5 years time would be a major risk.
Module 7: Disposal of records




                          Top


                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                What percentage of the records have no pre-defined
                                229                                                 disposal date?

                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                                            TNA tip: in some instances an overriding business need will
                                                                                                                                                                                                                            require permanent retention of certain types of record for example
                                                                                                                                                                                                                            property deeds and there are also statutory obligations which
                                           Do the selection and disposal policies and accompanying                                                                                                                          require permanent retention of certain types of record. However in
                                                                                                                                                                                                                            addition to these drivers public bodies should also take account
                                230        disposal schedules identify records which should be kept                                                                                                                         of the need to safeguard other records permanently to satisfy
                                                                                       permanently?                                                                                                                         public expectations in respect of the potential value of the records
                                                                                                                                                                                                                            for historical or other research. Such records may need to be
                                                                                                                                                                                                                            transferred into the custody of a specialist archive to secure their
                                                                                                                                                                                                                            preservation.


                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                                            TNA tip: all information held in recorded form has to be subject to
                                            Are electronic records and databases also subject to the
                                231                         application of disposal/retention periods?
                                                                                                                                                                                                                            the organisation’s disposal policies irrespective of the format in
                                                                                                                                                                                                                            which it is held.


                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                 Does the organisation have a mechanism to ensure
                                            existing disposal schedules are kept upto date to reflect
                                232            the relevant statutory and regulatory environment or if
                                          applicable accepted changes in established best practice?
Module 7: Disposal of records




                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>

                                                 Are there mechanisms in place to validate disposal
                                233          schedules to ensure they are apposite and that material
                                                  required for business purposes has not been lost?


                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                                            TNA tip: the Code has an expectation that an organisation should
                                                                                                                                                                                                                            maintain an historic record of the basis for the decision to destroy
                                           Where disposal criteria are changed to reflect changes in                                                                                                                        records to account for perceived deviations from current
                                           the relevant statutory environment does the organisation                                                                                                                         provisions and practice. Retention of this information and the
                                234        maintain information about previous provisions to explain                                                                                                                        dates of subsequent changes will enable an organisation to rebut
                                                       the basis for previous destruction of records?                                                                                                                       claims that a decision to destroy records was inappropriate or
                                                                                                                                                                                                                            unauthorised but was in fact based on a relevant mandate even
                                                                                                                                                                                                                            though that mandate was changed subsequently.


                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                  Where records are not included in existing disposal                                                                                                                       TNA tip: decisions of this nature should be documented and kept
                                                  schedules has the organisation established special                                                                                                                        to provide evidence of which records have been identified for
                                235       arrangements to review them and decide whether they can                                                                                                                           destruction, when the decision was made, and the reasons for the
                                               be destroyed or selected for permanent preservation?                                                                                                                         decision, where this is not apparent from the overall policy.



                                                                                                           1                                                           (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                 Do the criteria for appraisal include ascertaining the
Module 7: Disposal of records




                                              relationship to other sets of records or the support they
                                236              provide to the interpretation and use of other sets of
                                                                                              records?




                                Page 23                                                                                                                                                                                                                     76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
Module 7: Disposal of records                                                                                                          76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                    Page 24
                                                                                                           1                                                        (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                            TNA tip: many records are not subject to statute based defined
                                                                                                                                                                                                            retention periods. In such cases it is essential that the long term
                                              Are disposal schedules developed in consultation with                                                                                                         business needs are identified with the users to ensure records are
                                                                                                                                                                                                            not disposed of before the expiry of the period they still needed by
                                            experts to ensure the disposal period meets the residual
                                237         business needs in addition to those defined by statute or
                                                                                                                                                                                                            the organisation for the conduct of business. The Code requires
                                                                                                                                                                                                            that such decisions be based on consultation between records
                                                                                         regulation?                                                                                                        management staff, staff of the relevant business unit and, where
                                                                                                                                                                                                            appropriate, others such as legal advisers, archivists or external
                                                                                                                                                                                                            experts.


                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                 Are disposal schedules subject to validation by the
                                             corporate record manager and the management of the
                                238                relevant business unit to ensure consistency and
                                                                                         accuracy?

                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                            TNA tip: implementation arrangements should take account of
                                                    Are disposal schedules and disposal decisions                                                                                                           variations caused by, for example, outstanding requests for
                                239           implemented by properly trained and authorised staff?                                                                                                         information or litigation which may require the records to be held
                                                                                                                                                                                                            for a further period beyond that required in the disposal schedule.
Module 7: Disposal of records




                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                            Is there a plan to implement or apply disposal schedules
                                240                   each year with specific targets and timescales?

                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                            TNA tip: many disposal rules are intended to be activated when a
                                                                                                                                                                                                            folder or record set is closed in accordance with various criteria
                                                Have criteria been established and applied to ensure                                                                                                        (e.g. end of contract, end of business year, after a specific
                                                                                                                                                                                                            defined period has elapsed).If there are no mechanisms to ensure
                                241              record sets become inactive (i.e. closed) to enable                                                                                                        closure the disposal schedules are never applied which can result
                                                                   disposal schedules to be applied?                                                                                                        in records being retained beyond what would be prudent and in
                                                                                                                                                                                                            respect of those containing personal information could lead to a
                                                                                                                                                                                                            breach of the Data Protection Act 1998.


                                                                                                           1                                                          (your notes and evidence statement)
                                              Has implementation of the records disposal policy been       -----PLEASE SELECT------>

                                                  incorporated within the organisation’s risk mitigation
                                242        strategy to ensure timely destruction of records when they
                                                are no longer required and continued safeguarding of
                                                               those which merit continued retention?

                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                            TNA tip: records containing personal information about living
                                             Has the organisation established procedures to ensure                                                                                                          individuals should be destroyed in a way that prevents
                                                that records are destroyed in as secure a manner as                                                                                                         unauthorised access (this is required to comply with the 7th data
                                243       required by the level of confidentiality or security markings                                                                                                     protection principle). With digital records it may be necessary to
                                                                                             they bear?                                                                                                     do more than overwrite the data to ensure the information is
                                                                                                                                                                                                            destroyed.
Module 7: Disposal of records




                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>

                                            When destruction is carried out by an external contractor                                                                                                       TNA tip: here the issue is not only identifying where security
                                              does the contract stipulate that the security and access                                                                                                      controls are applied but in defining what needs to be done by the
                                244         arrangements established for the records will continue to                                                                                                       contractor to ensure these conditions are not breached in
                                                        be applied until destruction has taken place?                                                                                                       ignorance.



                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>

                                                                                                                                                                                                            TNA tip: in some cases there will be more than one copy of a
                                                                                                                                                                                                            record. For example, there are likely to be back-up copies of
                                                                                                                                                                                                            digital records, or there may be digital copies of paper records. A
                                                                                                                                                                                                            record cannot be considered to have been completely destroyed
                                            Has the organisation established procedures to manage                                                                                                           until all copies, including back-up copies, have been destroyed, if
                                             scheduled overwriting of back-up copies to ensure that                                                                                                         there is a possibility that the data could be recovered. The
                                245        copies of records which have been formally disposed and                                                                                                          existence of copies on back-ups could lead to an instruction to
                                          destroyed from the live system are not retained on backup                                                                                                         restore the records to satisfy an information request under the
                                                                                                                                                                                                            Freedom of Information Act 2000. The creation of back-ups is a
                                                                       copies for excessive periods?
                                                                                                                                                                                                            prudent information security measure but retention of older copies
                                                                                                                                                                                                            indefinitely is not good practice for the reason stated above and
                                                                                                                                                                                                            where possible it is preferable that back-up copies do not exceed
                                                                                                                                                                                                            12 months in age to reduce the risk to the organisation.



                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                           Does the organisation maintain evidence that, as part of a
                                                                                                                                                                                                            TNA tip: the Code considers this to be a minimum requirement
                                                routine record management process, destruction of a                                                                                                         and states that at the very least retention of evidence of this
                                                specified type of record of a specified age range took
Module 7: Disposal of records




                                                                                                                                                                                                            nature will enable an authority and its staff to explain why records
                                246       place in accordance with the relevant specified provision of                                                                                                      specified in a court order cannot be provided or to defend
                                          the disposal schedule (e.g. invoices older than 7 years are                                                                                                       themselves against a charge under section 77 of the Act that
                                                                                                                                                                                                            records were destroyed in order to prevent their disclosure in
                                              routinely destroyed as specified in the relevant disposal
                                                                                                                                                                                                            response to a request for information”.
                                                                                           schedule)?"

                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                            TNA tip: ideally details of destruction of records should be kept,
                                                                                                                                                                                                            either as part of the audit trail metadata or separately. Ideally,
                                          Does the organisation keep a record of the prior existence                                                                                                        some evidence of destruction should be kept indefinitely because
                                247            of destroyed records and the criteria upon which the                                                                                                         the previous existence of records may be relevant information.
                                                        decision to destroy the records was made?                                                                                                           However, the level of detail and for how long it should be kept will
                                                                                                                                                                                                            depend on an assessment of the costs and the risks to the
                                                                                                                                                                                                            authority if detailed information cannot be produced on request.


                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>                                                                        TNA tip: transfer to a permanent archive should take place in an
                                                 Where records are identified as meriting permanent
                                            preservation are there processes in place to ensure their                                                                                                       orderly manner and with a level of security appropriate to the
                                                                                                                                                                                                            confidentiality of the records. Such transfers should be fully
                                248              subsequent secure transfer to a permanent archival                                                                                                         documented and a record of these should be maintained in the
                                              service which has adequate storage and public access                                                                                                          organisation’s record keeping or record management system
                                                                                           facilities?                                                                                                      subsequently.

                                                                                                           1                                                          (your notes and evidence statement)
                                                                                                           -----PLEASE SELECT------>
                                                                                                                                                                                                            TNA tip: in this context the term archive refers to a specialised
                                                                                                                                                                                                            archival store where records of historical or heritage value are
                                           Where the organisation transfers records to a permanent                                                                                                          preserved not “record centres” where non current or inactive
                                                                                                                                                                                                            records are held by the creating body prior to disposal. Relevant
                    links                 archive is there a procedure to transfer appropriate finding
                                249          aids to ensure identification and retrieval in response to
                                                                                                                                                                                                            examples of an archive in this context include, but are not limited
                                                                                                                                                                                                            to; local authority record offices, county archives, and other
                          End                                   subsequent requests for information?                                                                                                        archival bodies which function as places of deposit appointed
                                                                                                                                                                                                            under the Public Records Act 1958 to receive transfers of records
               Contact                                                                                                                                                                                      from public records bodies.
               details


                                                                                                           1                                                          (your notes and evidence statement)
      Module 1                                                                                             -----PLEASE SELECT------>
                                           Where the organisation transfers records to a permanent
      Module 2
                                            archive is there a procedure for it to prepare a schedule
                                            specifying information which it considers ought not to be
                                250              made immediately available to the public, citing the
      Module 3
                                             relevant exemptions, explaining why they apply and for
                                                                                            how long?
      Module 4




                                Page 24                                                                                                                                                                                                     76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                  76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                     Page 25
                                                                                      1                                                        (your notes and evidence statement)
 Module 5                                                                             -----PLEASE SELECT------>


                      Where the organisation transfers records to a permanent                                                                                                          TNA tip: this can be of critical importance as the archive who has
 Module 6                                                                                                                                                                              accepted the transfer may not possess the specialised knowledge
                            archive and some of the records are still subject to
            251       disclosure exemptions, has it provided a contact point for
                                                                                                                                                                                       to determine if an exemption is applicable and will need to contact
 Module 7                                                                                                                                                                              a centre of expertise to clarify matters before a decision to release
                                         consultation on the access decision?                                                                                                          is made under the Freedom of Information Act 2000.

 Module 8

                                                                                      1                                                          (your notes and evidence statement)
                                                                                      -----PLEASE SELECT------>
 Module 9                   In the event of a disaster necessitating restoration of                                                                                                    TNA tip: to support conformance with Freedom of Information and
                      records from older back-up copies are there mechanisms                                                                                                           Data Protection requirements this is to ensure electronic records
                           in place to alert the record manager to enable him to                                                                                                       which had been previously destroyed and removed from the on-
Guidance    252                arrange for the subsequent re-running of disposal                                                                                                       line system by an authorised auditable process are not
                        schedules, which had been invoked after the backed-up                                                                                                          automatically restored without the knowledge of the record
Results                                                                                                                                                                                manager.
                                                                 copy was taken?
TNA
website               You've reached the end of Module 7. If you wish to check the Results sheet now, click on the link to Results. If you wish to
   Top                start the next module, click on link to Module 8.             Results   Module 8




            Page 25                                                                                                                                                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                               Page 26
                                                                                                                                                 1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                 Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the use of all public SKIP to TNA


TNA         TNA
                                                                                                                                                 authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience of
                                                                                                                                                 their record management policies and processes.

                                                                                                                                                 2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                          website page

                                                                                                                                                                                                                                                                          SKIP to
                                                                                                                                                                                                                                                                          Guidance
                                                                                                                                                 choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                          Self Assessment Questionnaire for                                      Enter responses below in                        questionnaire.
                         compliance with the revised Records                                      answer to questions in
                            Management Code of Practice
                                                                                                                                                    3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                    worksheet in this workbook.                                                                                                SKIP to
                                                                                                                                                                                                                                                                               Results




                          Module 8: Records created in                                                                                              TNA tip: Module 8 is designed to elicit if organisations who share records with other
                           the course of collaborative                                                                                              bodies or have them held on their behalf by other bodies are managed in accordance with
                                                                                                                                                    the Code.
                             working or through out-
   links
                                    sourcing                                            (your responses below)
    End
                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
  Contact                                                                                                                                                                                                TNA tip: ideally an organisation should have developed a policy to
  details                     Does the organisation have a formal commitment to                                                                                                                          ensure that when it works in partnerships with other organisations
              253              agreeing a protocol before sharing information with                                                                                                                       that the specification and adoption of a joint protocol on the
 Module 1                                                   another organisation?                                                                                                                        sharing of information and contributing to a joint records system
                                                                                                                                                                                                         has to be established before the partnership can be implemented.

 Module 2
                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
 Module 3                  Where the organisation works in partnership with other
                         organisations, have protocols been specified and agreed
              254      by all parties on the sharing of information and contributing
 Module 4
                                                           to a joint records system?
 Module 5
                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>

 Module 6
                                                                                                                                                                                                         TNA tip: it should be emphasised that in this context disclosing
                       Has any information been shared in the last year without a
 Module 7
              255                                                      protocol?
                                                                                                                                                                                                         information under the Freedom of Information Act 2000 does not
                                                                                                                                                                                                         count as information sharing.

 Module 8

                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
 Module 9
                                 Do the information sharing protocols specify what
              256      information should be contributed and kept, and by whom?
Guidance

                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
Results
                        Do the information sharing protocols specify what level of
              257                         information security should be applied?
TNA


                                                                                        1                                                           (your notes and evidence statement)
     Top                                                                                -----PLEASE SELECT------>
                         Do the information sharing protocols specify who should
              258      have access to the records within the joint records system?


                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
                       Do the information sharing protocols specify what disposal
              259       arrangements should be in place within the joint records
                                                                         system?
 Module 8




                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
                          Do the information sharing protocols specify which body
              260        holds the information for the purposes of the Freedom of
                                                         Information Act 2000 Act?

                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                         TNA tip: particular protection should be given to confidential or
                       Do the information sharing protocols specify that particular                                                                                                                      personal information. Protocols should specify when, and under
                                                                                                                                                                                                         what conditions, information will be shared or passed, and details
              261          protection has to be applied to personal or confidential                                                                                                                      should be kept of when this information has been shared or
                                                                      information?                                                                                                                       passed. Details should be kept also of how undertakings given to
                                                                                                                                                                                                         the original source of the information have been respected.

                                                                                        1                                                           (your notes and evidence statement)
                       Have records management controls and procedures been             -----PLEASE SELECT------>

   links                  defined and applied to information being shared with or
              262        passed to other bodies to support the implementation of
    End                      the information sharing protocols entered into by the
                                                                    organisation?
  Contact
  details                                                                               1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>


 Module 1
                              Have instructions and training been provided to staff
              263                               involved in collaborative working?
 Module 2


 Module 3
                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
                                                                                                                                                                                                         TNA tip: the Thomas-Walport report on the Data Sharing Review
 Module 4                                                                                                                                                                                                recommended that “Public bodies should publish and maintain
                          Does the organisation publish and maintain details of its
                                                                                                                                                                                                         details of their data-sharing practices and schemes, and should
              264       data-sharing schemes and record their commitment to do                                                                                                                           record their commitment to do this within the publication schemes
 Module 5                                      this within its publication scheme?                                                                                                                       that they are required to publish under the Freedom of Information
                                                                                                                                                                                                         Act”.
 Module 6
                                                                                        1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
 Module 7
                       Does the organisation publish and regularly update a list of
                            those organisations with which its shares, exchanges
              265               personal information, or to which it sells personal
 Module 8
                                    information, including selected third parties?
 Module 9                                                                               1                                                           (your notes and evidence statement)
                                                                                        -----PLEASE SELECT------>
                        Where an organisation’s records are held on its behalf by                                                                                                                        TNA tip: some of an authority’s records may be held on its behalf
                         another body do the protocols or contract terms and any                                                                                                                         by another body, for example a body carrying out work for the
Guidance
              266      supporting procedures require the provisions of the revised                                                                                                                       authority under contract. The authority on whose behalf the
                               Records Management Code to be applied to those                                                                                                                            records are held is responsible for ensuring that the provisions of
Results                                                                                                                                                                                                  the Code are applied to those records.
                                                                         records?

TNA
                       You've reached the end of Module 8. If you wish to check the Results sheet now, click on the link to Results. If you wish to
     Top               start the last module, click on link to Module 9.             Results Module 9




             Page 26                                                                                                                                                                                                                     76ec6e74-ce7b-441e-9f65-9499edd9934d.xls
                                                                                                                                                                                 76ec6e74-ce7b-441e-9f65-9499edd9934d.xls                                                                                                               Page 27
                                                                                                                                                                                                              1. This worksheet is a questionnaire that allows for a comprehensive assessment of compliance to the revised Records
                                                                                                                                                                                                              Management Code issued under section 46 of the freedom of Information Act 2000. It is intended for the use of all public SKIP to TNA


                                                                           TNA                                                                                                                                authorities subject to the Act but can also be used by any organisation or body to assess the quality and resilience of
                                                                                                                                                                                                              their record management policies and processes.

                                                                                                                                                                                                              2. Answers should be entered into the cells in the column D of this worksheet. Most questions require you to simply
                                                                                                                                                                                                                                                                                                                                       website page

                                                                                                                                                                                                                                                                                                                                       SKIP to
                                                                                                                                                                                                                                                                                                                                       Guidance
                                                                                                                                                                                                              choose from the pull-down lists below. Other cells are locked to avoid inadvertent changes to the structure of the
                                                                                        Self Assessment Questionnaire for                                   Enter responses below in                          questionnaire.
                                                                                       compliance with the revised Records                                   answer to questions in
                                                                                          Management Code of Practice                                               Module 9
                                                                                                                                                                                                                 3. Your answers and responses are used to calculate a risk assessment score that can be viewed in the Results Chart
                                                                                                                                                                                                                 worksheet in this workbook.                                                                                                  SKIP to
                                                                                                                                                                                                                                                                                                                                              Results


                                                                                           Module 9: Monitoring and
                                                                                                                                                                                                                 TNA tip: Module 9 is designed to elicit if organisations have established appropriate
                                                                                           reporting on records and                                                                                              performance measurement mechanisms to assess their compliance with the Records
                                                                                           information management                                                                                                Management Code.
                                                                                                                                                     (your responses below)
                                                   links                                                                                                                                                         (your notes and evidence references)
                                                                                                                                                     1
                                                                                                                                                     -----PLEASE SELECT------>
                                                                End                                                                                                                                                                                                   TNA tip: the performance measures could be general in nature,
                                                                                                                                                                                                                                                                      for example that a policy has been issued, or could refer to
                                                                                     Has the organisation identified performance measures for                                                                                                                         processes, such as the application of disposal schedules to
                                        Contact                            267                         information and records management?                                                                                                                            relevant records with due authorisation of destruction, or could
                                        details
                                                                                                                                                                                                                                                                      use metrics such as retrieval times for paper records held off-site
                                                                                                                                                                                                                                                                      that have been requested under the Act.
               Module 1
                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
               Module 2
                                                                                                                                                                                                                                                                      TNA tip: for example, if metrics are to be used, the data from
                                                                                          Has the organisation put in place the means by which                                                                                                                        which statistics will be generated must be kept. Qualitative
               Module 3                                                    268                                performance can be measured?                                                                                                                            indicators, for example whether guidance is being followed, can
                                                                                                                                                                                                                                                                      be measured by spot checks or by interviews.
               Module 4

                                                                                                                                                     1                                                           (your notes and evidence references)
               Module 5                                                                                                                              -----PLEASE SELECT------>                                                                                        TNA tip: monitoring should be undertaken on a regular basis and
                                                                                       Has the organisation put in place mechanisms to ensure
                                                                                                                                                                                                                                                                      the results reported to the person with lead responsibility for
                                                                           269                  regular monitoring of the adopted performance                                                                                                                         records management so that risks can be assessed and
               Module 6                                                                                                            measures?                                                                                                                          appropriate action taken.

               Module 7                                                                                                                              1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                       Where the organisation has established mechanisms to
                                                                                                                                                                                                                                                                      TNA tip: monitoring only makes sense if the results are
                                                                                           ensure regular monitoring, are the results formally
               Module 8                                                    270         recorded in a report together with recommendations for
                                                                                                                                                                                                                                                                      disseminated to management for review and remedial action via a
                                                                                                                                                                                                                                                                      regular reporting mechanism.
                                                                                                               remedial action where required?
               Module 9

                                                                                                                                                     1                                                           (your notes and evidence references)                 TNA tip: assessing whether the records management programme
                                                                                                                                                     -----PLEASE SELECT------>
Guidance                                                                                   Have the performance measures for assessing the                                                                                                                            meets the needs of the organisation is a more complex task and
                                                                                      implementation of the records management programme                                                                                                                              requires consideration of what the programme is intended to
                                                                           271          adopted by the organisation been evaluated to confirm                                                                                                                         achieve and how successful it is being. This requires
Module 9: Monitoring and reporting on records and information management




Results
                                                                                        these measures underpin the organisation’s corporate                                                                                                                          consideration of business benefits in relation to corporate
                                                                                                                                                                                                                                                                      objectives as well as risks and should include consultation
                                                                                                                                  objectives?
TNA                                                                                                                                                                                                                                                                   throughout the authority.

                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                       Where an organisation has identified the risks, within its
                                                                 Top
                                                                                           corporate risk register of not having those records it
                                                                           272        requires to meet all its statutory, regulatory and business
                                                                                                        needs is this subject to regular review?

                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                                                                      TNA tip: this is to confirm that the need to refer to authoritative
                                                                                       Where business units have defined their requirement for                                                                                                                        information about past actions and decisions for current business
                                                                           273          records has this been subject to external assessment?                                                                                                                         purposes has been interpreted correctly in the light of the role of
                                                                                                                                                                                                                                                                      each business unit.

                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                                                                      TNA tip: it is assumed here that guidance has been developed to
                                                                                     Do you have evidence that end users have easy access to                                                                                                                          support implementation of the record management as explored in
                                                                                     the guidance provided in each business unit explaining the                                                                                                                       previous modules. The point here is to confirm the guidance both
                                                                                                                                                                                                                                                                      exists and is readily available to all users. If the guidance is
                                                                           274                type and nature of the communications created or                                                                                                                        prominently available on-line it is not unreasonable to assume that
                                                                                        received which should routinely be captured or filed into                                                                                                                     users can access it provided its existence is drawn to their
                                                                                                              the record management system?.                                                                                                                          attention periodically. If the guidance is held in a manual in a
                                                                                                                                                                                                                                                                      cupboard it is unlikely it is ever referenced.


                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>



                                                                                           Is there evidence that this guidance is brought to the
                                                                           275                            attention of all personnel periodically?



                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                                                                      TNA tip: the issue here is to ascertain if the organisation
                                                                                                                                                                                                                                                                      possesses any means to monitor both the number of occasion
                                                                                        Does the organisation possess the means to record the                                                                                                                         guidance is referred to by staff and also to identify the personnel
                                                                           276            number of occasions the staff access the guidance?                                                                                                                          using the guidance. This is only likely to occur where guidance
                                                                                                                                                                                                                                                                      exists in electronic form and is accessed either via an Intranet
                                                                                                                                                                                                                                                                      facility or where the guidance is held on an EDRM solution.


                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>

                                                                                       Where the organisation possesses the means to record
                                                                           277         the number of occasions the staff access the guidance,
                                                                                               what percentage of staff have made use of it?


                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                                                                      TNA tip: what is being established here relates to the overall
                                                                                        Are spot checks undertaken within each business unit to                                                                                                                       quality of the corporate record. If an organisation has stipulated
                                                                                                                                                                                                                                                                      that certain types of information transactions should be captured
                                                                                     confirm if recently filed records are an adequate reflection
                                                                           278       of what has been created or received and are sufficient for
                                                                                                                                                                                                                                                                      there needs to be periodic assessment that the volume of material
                                                                                                                                                                                                                                                                      captured accords with what would be expected to exist given the
                                                                                                                             business purposes?                                                                                                                       nature and tempo of the business and the requirement of the
                                                                                                                                                                                                                                                                      organisation to capture certain forms of communication.

                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                                                                      TNA tip: the issue here is not just whether the right sort of
                                                                                         Are there mechanisms to permit the Corporate Record                                                                                                                          records have been created but that they have been filed or
                                                                                      Manager and relevant business unit managers check that                                                                                                                          located within the relevant area assigned to them by the business
                                                                           279
cords and information management




                                                                                     the correct records have been allocated to the appropriate                                                                                                                       and that the titles or references are meaningful and conform with
                                                                                      sequence of records and that meaningful titles are used?                                                                                                                        what is required by the organisation to ease identification and
                                                                                                                                                                                                                                                                      subsequent retrieval.


                                                                                                                                                     1                                                           (your notes and evidence references)
                                                                                                                                                     -----PLEASE SELECT------>
                                                                                                                                                                                                                                                                      TNA tip: the issue here is to identify if any user is evading using
                                                                                                                                                                                                                                                                      the system for creation of folders or filing records. Low usage
                                                                                                                                                                                                                                                                      statistics will help identify non-compliant users and focus
                                                                                        Are statistics generated regularly to allow business unit                                                                                                                     supplementary training efforts. High usage statistics can also
                                                                                                                                                                                                                                                                      identify if a user is capturing large volumes of data not required by
                                                                           280            managers to identify if certain users are not using the                                                                                                                     the organisation. Another aspect is filing patterns. In some
                                                                                                                           system appropriately?                                                                                                                      instances a user might only file into their personal area as
                                                                                                                                                                                                                                                                      opposed to the corporate file plan or only into one or two folders.
                                                                                                                                                                                                                                                                      This might imply a lack of confidence or knowledge of the file-
                                                                                                                                                                                                                                                                      plan, which can be addressed by further training.)




                                                                           Page 27                                                                                                                                                                                                                    76ec6e74-ce7b-441e-9f65-9499edd9934d.xls

								
To top