Assess your records management program with the risk profiler

Risk Profiler for Records and Information Management

Making the Grade

In these times of stricter regulations - whether in the form of laws such as the Sarbanes-Oxley Act or international privacy laws - records management may well be one of the most powerful weapons in the compliance arsenal. The effectiveness of this tool, however, is directly proportional to the quality and success of the records management program. A solid records and information management program documents the organization's good faith and commitment to compliance.

Unfortunately, many organizations lack effective policies and procedures for systematic control of recorded information. They may therefore be

  • storing some records too long, not long enough, or not at all
  • prematurely destroying or retiring certain vital documents
  • losing information needed for proper SEC reporting
  • failing to properly safeguard and protect information and records from hackers or unauthorized insiders

All of which risk penalties for non-compliance with recordkeeping regulations, a tarnished reputation, and possible legal liability

  • Solid records information management (RIM) controls are needed to demonstrate vigilance and to help satisfy compliance efforts pertaining to corporate governance regulations such as Sarbanes-Oxley.
  • Proactive records management processes can reduce litigation defense costs with regard to expensive electronic discovery in litigation proceedings.
  • Records information management systems demonstrate a prudent level of due care essential to mitigating corporate risk resulting from events that can lead to liability exposure.
Assessing Your RIM Program

The first step to determining whether your records management program is an asset or potential liability is to conduct a self-assessment. To assist you, ARMA International in conjunction with NetDiligence, has developed an online assessment solution.

This Web-based tool allows you to assess and document your records management program against ARMA-interpreted best practices in the spirit of ISO 15489, the international records management standard. The standard is recognized worldwide as establishing the baseline for excellence in records management programs.

Back to MenuTop

How It Works

The assessment is a user-friendly, automated, guided self-assessment tool that provides a diagnostic analysis of your RIM program’s strengths and weaknesses.

The assessment consists of approximately 90 questions (yes, no, and text response), developed by a team of experienced RIM professionals, spanning the following categories:

  • Policies and procedures
  • Program structure
  • Classification plan effectiveness
  • Records security and protection
  • Active program effectiveness
  • Inactive program effectiveness
  • Monitoring and training

Once you have completed the questionnaire, you will receive:

  • a summary report card with your scores for each section, including a brief summary of the pertinent best practices
  • a copy of the questions and your answers with best practice comments
  • suggested resources for helping you to improve your program’s score in each section

Sample Report
NetDiligence Privacy Policy
Risk Profiler for Records and Information Management Terms and Conditions

Back to MenuTop

How to Register

The Assessment is available for purchase in the ARMA International Bookstore with a valid credit card. If you are a member of ARMA International, be sure to have your member ID number and password ready to receive the member discounts.

Within 48 hours of registering, you will receive an invitation e-mail from NetDiligence advising you that your personal and private assessment domain has been established. The e-mail will provide a direct link to your test site.

It is not necessary to complete the assessment in one sitting. You may save and return to it if needed. Similarly, your online assessment report will remain active for 45 days.

The registration fees are as follows:

Regular Rates: $395 ARMA members / $795 nonmembers

 ARMA/NetDiligence Risk Profiler for Records and Information Management

Back to MenuTop

How to Prepare

Your organization may have already established policies and procedures that address some of the questions in the Risk Profiler Self-Assessment . Collecting the documents listed below before starting the evaluation, will make it easier to complete.

  • Records management strategic plans
  • Established goals/objectives for the program
  • List of documentation that supports your program (i.e., policies/procedures, retention schedules, classification plans, standards, metrics)
  • Defined roles/responsibilities for all employees regarding the records management program.
  • Laws, regulations, etc., that have been followed in establishing records management programs

NOTE: We encourage you to take a team-approach to the Risk Profiler for Records and Information Management, working with IT and legal to answer the questions that pertain to their areas, to ensure as accurate an evaluation as possible.

Back to MenuTop

The Development Team

The Records and Information Management questions used in the Risk Profiler tool were created by a group of experienced RIM professionals, some of whom are actively involved in developing records management standards in the United States and internationally. All of the professionals were certified records managers.

Back to MenuTop

Attention Certified Records Managers
The Institute of Certified Records Managers (ICRM) has pre-approved this assessment tool for 2.5 CEU.

About NetDiligence

Net Diligence
NetDiligence provides cyber risk and network security assurance services to help corporate and financial institution clients better protect their computer network resources and information assets, and mitigate potential network liability risk.

NetDiligence Web Site

Questions?
If you have questions about the Risk Profiler for Records and Information Management, contact Nathan Armstrong, ARMA International, 1.800.457.7984.

Back to MenuTop

ISO is the short name for the International Organization for Standardization. Neither ARMA International, NetDiligence nor this Risk Profiler for Records and Information Management is affiliated with or endorsed by the International Organization for Standardization.

   

Advertisement: 3M Banner B - im5

Advertisement: Anacomp
Advertisement: Kodak - Butler Till
 
     
 

© 2008, ARMA International