In-Place Records Management: Making a case for greater Information Security and Assurance
Emerson Bryan
Senior Records and Research Analyst ·

For decades, electronic records management was built around a simple assumption: records should be transferred from the systems where they were created into a dedicated Electronic Records Management System (ERMS) for long-term governance.
That model served organizations well when records primarily consisted of office documents stored on shared drives. However, today's digital workplace is fundamentally different. Business information now resides across cloud platforms, enterprise applications, collaboration tools, customer relationship management systems, financial applications, messaging platforms, and industry-specific solutions.
In many organizations, there is no longer a single "document repository" to which everything can realistically be transferred.
This shift has given rise to in-place records management—an approach that applies records management controls directly within the systems where records are created, received, and used.
Rather than moving records, organizations bring governance to the records.
The Hidden Risk of Email Attachments
One of the less appreciated benefits of in-place records management is its ability to reduce reliance on email attachments.
For decades, email has been the default method for sharing documents, resulting in countless copies being distributed across mailboxes, personal drives, and unmanaged storage locations. Every attachment represents another version of the same information, making it increasingly difficult to determine which copy is authoritative.
This practice introduces significant records management and information governance risks. Attachments are often retained long after the official record has been updated or disposed of, creating inconsistent retention practices and increasing the volume of information subject to discovery requests, audits, and regulatory investigations. They may also contain sensitive or personal information that is no longer protected by the access controls applied to the original record, increasing the risk of unauthorized disclosure or data breaches.
In-place records management encourages organizations to replace attachments with secure links to the authoritative record stored within the enterprise platform. Users continue to collaborate on a single version of the document while records management controls—including classification, retention, legal holds, access permissions, version history, and audit trails—remain intact. This approach supports the principle of maintaining a single source of truth, reducing duplication, strengthening information security, and improving confidence that decisions are based on the most current and authentic record.
As organizations embrace cloud collaboration platforms and artificial intelligence, the practice of emailing attachments should increasingly be viewed as a legacy habit rather than a best practice.
Sharing links to governed records not only enhances collaboration but also strengthens records management, cybersecurity, and information governance across the enterprise.
What Is In-Place Records Management?
In-place records management enables records to remain within their native business applications while applying policies for classification, retention, legal hold, access control, disposition, and audit through metadata, automation, and governance technologies.
Whether the record exists in Microsoft 365, SharePoint, Salesforce, an enterprise resource planning (ERP) system, a case management platform, or another cloud application, it can be governed without unnecessary duplication or migration.
This approach reflects an important reality: business context is part of the record.
Preserving Authenticity Through Context
One of the greatest strengths of in-place records management is its ability to preserve the characteristics that make records trustworthy.
When records remain in their original environment, they retain:
Original metadata
Version history
Audit trails
Relationships with other records
Business process context
Security classifications
These elements collectively support the authenticity, reliability, integrity, and usability of records—the qualities emphasized in ISO 15489 as essential for trustworthy recordkeeping.
Moving records to another repository may preserve content, but it can also weaken or disconnect the contextual information that gives records their evidential value.
Better Governance Without Burdening Users
One of the long-standing challenges in records management has been user compliance.
Traditional approaches often required employees to manually declare records or transfer documents into dedicated repositories. These additional steps frequently resulted in inconsistent practices and incomplete recordkeeping.
In-place records management reduces this burden by embedding governance into everyday work. Automation can classify records, apply retention schedules, place legal holds, capture metadata, and trigger disposition with minimal user intervention.
The result is improved compliance without disrupting business operations.
Reducing Duplication and Cost
Copying records into separate repositories creates multiple versions of the same information, increases storage requirements, complicates synchronization, and introduces unnecessary administrative overhead.
Managing records where they already exist eliminates much of this duplication.
Organizations benefit from:
Lower storage costs
Reduced migration projects
Simplified system architecture
Fewer integration challenges
More efficient information governance
In an era where organizations generate terabytes of digital information each day, reducing duplication is both a governance and sustainability objective.
Supporting Artificial Intelligence
Artificial intelligence is only as effective as the information it can understand.
Large language models and intelligent search tools depend heavily on metadata, relationships, provenance, and business context. Records that remain connected to their originating systems provide richer information for AI than isolated copies stripped of their operational environment.
In-place records management therefore supports responsible AI adoption by maintaining the contextual integrity that enables trustworthy analysis, retrieval, and decision support.
A Natural Fit for Information Governance
Modern records management no longer exists in isolation.
It increasingly intersects with:
Information governance
Cybersecurity
Privacy
Data governance
Compliance
Digital preservation
Risk management
Managing records in place allows governance policies to operate across the broader information ecosystem rather than within a single repository.
This integrated approach reflects how organizations actually create and manage information today.
Alignment with International Standards
The principles underpinning in-place records management align closely with internationally recognized standards, including:
ISO 15489-1:2016 – Information and documentation — Records management
ISO 16175 – Principles and functional requirements for records in electronic office environments
ISO 30301 – Management systems for records
The approach also resonates with the Records Continuum Model, which views records as existing within an ongoing continuum of creation, capture, organization, and pluralization, rather than progressing through isolated lifecycle stages.
Looking Ahead
As organizations continue their digital transformation journeys, the question is no longer whether records should be governed—it is where that governance should occur.
For many organizations, the answer is increasingly clear.
Instead of relocating digital records into centralized repositories, we should focus on embedding governance where records naturally live. Doing so preserves authenticity, maintains business context, improves compliance, reduces costs, supports artificial intelligence, and strengthens enterprise information governance.
The future of records management is not about moving records.
It is about moving governance.

