Overview
ISO 18128:2024 - Information and documentation - Records risks - Risk assessment for records management - provides a practical framework for assessing records risks in organizations. The standard sets out methods to identify and document risks related to records, records processes, records controls and records systems; techniques to analyse those risks; and guidelines to evaluate them. ISO 18128:2024 is designed to help records professionals and risk managers ensure that records remain authentic, reliable, complete and usable for as long as required. It complements ISO 31000 and ISO 30300 and does not prescribe risk treatment measures (mitigation is handled by each organization’s risk program).
Key Topics
- Scope and context definition: defining the boundaries for records risk assessment, internal and external context, and criteria for risk description.
- Risk identification: methods and checklists for spotting uncertainties that could affect records, processes and systems.
- Risk analysis techniques: a selection of analytical tools (examples included in the standard) such as Business Impact Analysis (BIA), Human Reliability Analysis (HRA) and Bow Tie analysis to assess consequences and likelihood.
- Risk evaluation: approaches to prioritise assessed records risks, including ALARP (As Low As Reasonably Practicable), Reliability-Centred Maintenance (RCM), risk indices and cost/benefit analysis.
- Tools and annexes: mapping of techniques to IEC 31010 and a checklist of uncertainties to support consistent assessments.
- Normative references: ISO 30300 (records management vocabulary) and ISO 31000 (risk management guidelines).
Applications
ISO 18128:2024 is practical for organizations that need structured records risk assessment to support compliance, continuity and governance. Typical uses include:
- Performing systematic risk identification for paper and digital records, archives and recordkeeping systems.
- Conducting Business Impact Analysis to quantify operational consequences when records are lost or degraded.
- Using Bow Tie or HRA methods to clarify causes, controls and consequences related to records incidents.
- Producing prioritized risk registers to feed into enterprise risk management and audit programs.
Benefits: improved control of record quality and retention, stronger evidence for legal/regulatory requirements, and informed decision-making about records controls and investments.
Who should use it
- Records professionals and archivists
- Information governance and compliance teams
- Internal auditors and risk managers
- IT managers responsible for records systems
- Organizations of any size or sector seeking a consistent approach to records risk assessment
Related standards
- ISO 30300 - Records management: core concepts and vocabulary
- ISO 31000 - Risk management: guidelines
- IEC 31010 - Risk assessment techniques (referenced for technique selection)
Keywords: ISO 18128:2024, records risks, risk assessment for records management, records management, risk identification, risk analysis, records systems.