Overview - ISO/TR 15801:2017 (Document management, ESI trustworthiness and reliability)
ISO/TR 15801:2017 provides recommendations for implementing and operating information management systems that store and make available electronically stored information (ESI) in a trustworthy and reliable way. It applies to any organization that uses systems to retain ESI - including page-based documents, databases, and audio/video - and covers the combination of policies, procedures, technology and audit requirements needed to maintain the integrity and authenticity of stored ESI over time. The technical report focuses on ensuring that outputs from the system are true and accurate reproductions of the ESI once stored; it does not prescribe how to evaluate trustworthiness before import.
Key technical topics and requirements
The standard addresses practical elements across the ESI lifecycle, including:
- Information management policy: scope of ESI covered, roles and responsibilities, security classification, storage media, file formats, retention and disposal schedules, outsourcing and compliance.
- Duty of care and information security: trusted system principles, controls, segregation of roles, risk assessment, security policy and business continuity planning.
- Procedures and processes: documented procedures, capture (creation/import), metadata management, version control, date/time stamping, and auditability.
- Document image and data capture: preparation of paper documents, batching, scanning, image quality control, rescanning and image processing considerations.
- Database and indexing considerations: schema, master data management, transactional vs. updating systems, manual and automatic indexing, index accuracy and amendment controls.
- Preservation and retention: preservation strategies, retention schedules, authenticated output procedures and destruction controls.
- Operational resilience: backup and system recovery, system maintenance, storage media considerations, access levels, encryption key handling, and system integrity checks.
- Use of contracted services: managing outsourcing, transport of paper records, and trusted third-party considerations.
Practical applications and who uses it
ISO/TR 15801:2017 is practical for organizations implementing or auditing ESI storage systems, including:
- Records managers and archivists
- IT and systems administrators
- Information security and compliance teams
- Legal and e-discovery professionals
- Business continuity planners
- Service providers offering scanning, archiving or trusted third‑party custody
Use cases include designing trustworthy ESI repositories, drafting information management policies, defining capture/scanning workflows, ensuring reliable authenticated output for legal/regulatory needs, and preparing for audits.
Related standards (commonly used together)
Organizations often align ISO/TR 15801:2017 with other standards for records, information security and digital preservation such as ISO 15489 (records management), ISO/IEC 27001 (information security management) and digital preservation guidance - to build a comprehensive, compliant ESI governance program.
Keywords: ISO/TR 15801:2017, electronically stored information, ESI, document management, trustworthiness, information management policy, scanning, metadata, retention, preservation, backup.