Overview
ISO 24143:2022 - Information and documentation - Information Governance - Concept and principles - defines high-level concepts and guiding principles for Information Governance across an organisation’s past, current and future information assets. Applicable to organisations of all sizes and sectors (public, private, government, not‑for‑profit), the standard positions information as a strategic corporate asset and describes how governance should align with business objectives, legal obligations and digital transformation goals.
Key topics and principles
This standard is conceptual and principle‑based rather than prescriptive. Major contents include:
- Scope and definitions: core terms such as information, information asset, authenticity, integrity, digital continuity, disposition and e‑discovery.
- Benefits of Information Governance: strategic and operational advantages like value maximisation, legal compliance, improved decision‑making and risk reduction.
- Principles that organisations should adopt, including:
- Recognise information as a strategic corporate asset
- Integrate Information Governance into overall governance frameworks
- Secure senior management leadership and commitment
- Align governance with business objectives and compliance requirements
- Support information security, privacy, quality and integrity
- Adopt a risk‑based approach and govern information across its lifecycle
- Foster collaboration, knowledge sharing, corporate culture and sustainability
- Supporting material: annex with concept diagrams and bibliography of related publications.
Practical applications and users
ISO 24143 is intended for leaders and practitioners responsible for organising and safeguarding information value and compliance:
- Governing bodies, executive management and boards
- CIOs, information governance leads and enterprise architects
- Records managers, archivists, data protection officers and information security teams
- Compliance, legal and regulatory teams, and knowledge/data management professionals
Typical use cases:
- Framing an organisation‑wide Information Governance strategy to support digital transformation
- Aligning records management, data protection, and information security efforts
- Designing retention/disposition policies and processes (including e‑discovery readiness)
- Ensuring digital continuity and interoperability across systems and formats
- Creating a collaborative governance model for AI, big data, blockchain and other information technologies
Related standards
ISO 24143 complements and integrates with other management system and information standards, including:
Adopting ISO 24143 helps organisations create a coherent, strategic framework that aligns information assets, risk management, compliance and operational needs for sustainable business outcomes.