Standards and Frameworks

Become A MemberGet Involved

The management of various aspects of information and records management can be achieved through various British and International standards. Some are specific to the UK (usually marked BS) and some have been agreed internationally (usually marked ISO). The IRMS has a role in some of these standards and below is a full list of a wide range of standards for your reference.

While this is not currently an exhaustive list, it is growing as we become aware of more and as more are developed. Whichever framework you wish to utilise is your decision and many members can share their experiences of it with you if asked (and they are willing to, of course).

The links below will take you to a third-party site where you can purchase a copy of the standard or get more information on it.

Please be aware any links below will take you to another website where you can access relevant information.

Information and Records Management

ISO15489 – Records management

ISO/TS16175 – Processes and functional requirements for software for managing records

ISO/TR21965 – Records management in enterprise architecture

ISO/TR22428 – Managing records in cloud computing environments

ISO30301 – Management systems for records — requirements

ISO30302 – Management systems for records — guidelines for implementation

ISO13008 – Digital records conversion and migration process

ISO17068 – Trusted third party repository for digital records

ISO18128 – Records risks – assessment for records management

ISO23081 – Metadata for records (in 3 parts)

ISO26122 – Work process analysis for records

BS10008 – Evidential weight and legal admissibility of electronically stored information, specification

BS10010 – Information classification, marking and handling

BS10012 – Specification for a personal information management system

NHS RM Code of Practice – Records Management Code of Practice for health and social care

IRMS Local Government Functional Classification Scheme (LGFCS)-IRMS developed scheme for classifying records of organisations in the public sector

Data Protection and Privacy

General Data Protection Regulation (GDPR) – Use and management of personal data

Data Protection Act 2018 (UK)– Use and management of personal data for the United Kingdom and Northern Ireland

ICO Accountability Framework – A framework produced by the ICO to help implement accountability within an organisation

ICO Children’s Design Code – A legal code of conduct for producing online products and services aimed at children

Data Sharing Code – A code of practice for conducting sharing of personal data

Data Protection Act (Republic of Ireland)– Use and management of personal data for Ireland

Data Protection Act (Isle of Man)– Use and management of personal data for the Isle of Man

Data Protection Act (Bailiwick of Jersey) -Use and management of personal data for the Bailiwick of Jersey

Open Government

Freedom of Information Act 2000 – Disclosure of information held by public authorities in the UK (excl. Scotland)

Freedom of Information Act 2000 (Section 46 Records Management Code of Practice) – A code of practice for the management of public authority records

ICO FOI Self-assessment Toolkit – A self-assessment questionnaire to benchmark compliance with FOIA against

Freedom of Information (Scotland) Act 2002 -Disclosure of information held by public authorities in Scotland

Environmental Information Regulations 2004 – Disclosure of environmental information held by public authorities in the UK

Re-use of Public Sector Information Regulations 2015 – Rules regarding the use of public sector data by other entities

Information Security

ISO/IEC 27000 – Overview and vocabulary

ISO/IEC 27001 – Information security management system requirements

ISO/IEC 27002 – Security management systems – requirements

ISO/IEC 27017 – Information security controls for cloud services

ISO/IEC 27031 – Information security controls on business continuity

eIDAS (Standards on trust services) – A legal framework for the use of electronic trust services offered within the UK and recognise equivalent services offered in the EU.

NIS Regulations 2018 – A legal framework for providing online marketplaces, search engines and cloud software.

Be part of the IRMS community

A big thank you to our partners and supporters for helping to deliver great services to our members

Contact Us

    Required fields are marked with an asterisk.