Records and Document Management



Similar documents
RECORDS MANAGEMENT POLICY

Scotland s Commissioner for Children and Young People Records Management Policy

Quality Assurance. Policy P7

COUNCIL POLICY R180 RECORDS MANAGEMENT

QUEENSLAND COUNTRY HEALTH FUND. privacy policy. Queensland Country Health Fund Ltd ABN better health cover shouldn t hurt

Bring Your Own Device (BYOD) Policy

Guidelines for the application of advertised Religious Education Coordinator position

9. GOVERNANCE. Policy 9.8 RECORDS MANAGEMENT POLICY. Version 4

West Midlands Police and Crime Commissioner Records Management Policy 1 Contents

Revelian Pty Ltd ABN Privacy Policy Effective 1 September 2014

Graduate Certificate in Internal Auditing

How To Become An Auditor For The Safa Global

Records Disposal Schedule Anti-Discrimination Services Northern Territory Anti-Discrimination Commission

Records and Information Management. General Manager Corporate Services

BLUE BADGE INSURANCE PTY LTD BLUE BADGE COMMUNITY AUSTRALIA PTY LTD PRIVACY POLICY

Daltrak Building Services Pty Ltd ABN: Privacy Policy Manual

CREDIT REPORTING POLICY

POLICY STATEMENT 5.17

Information Classification and. Handling Policy

Best Practice Board Reporting

COURSE INFORMATION BSB50415 Diploma of Business Administration

Boost Financial Performance with Quality Management Systems

Records Management - Council Policy Version 2-28 April Council Policy. Records Management. Table of Contents. Table of Contents... 1 Policy...

Registration for Home Schooling in NSW Information Package

Records Management Policy

State of West Virginia Office of Technology Policy: Information Security Audit Program Issued by the CTO

91516 NSW CERTIFICATE IV IN COMPLIANCE MANAGEMENT. Associate Intensive (AGRCI)

Life Cycle of Records

The kinds of personal information we collect and hold vary depending on the services we are providing, but generally can include:

Records Management Policy

in Compliance Management NSW Associate Intensive (AGRCI)

REHABILITATION MANAGEMENT SYSTEM AUDIT TOOL

ADRI. Statement on the Application of Digital Rights Management Technology to Public Records. ADRI v1.0

DRAFT. Business Services. BSB20115 Certificate II in Business. based on the BSB Business Services Training Package. Effective from Date published

Council Policy. Records & Information Management

Clause 1. Definitions and Interpretation

NSW Government Digital Information Security Policy

Records Management Standards. Records Management Standards for Public Sector Organisations in the Northern Territory

The purpose of this document is to provide a framework for ConnectGroups in dealing with privacy considerations.

Board means the Board of Directors of each of Scentre Group Limited, Scentre Management Limited, RE1 Limited and RE2 Limited.

amaysim Privacy Policy

Community Telco Credit Management Policy

Audit report VET Quality Framework Continuing registration as a national VET regulator (NVR) registered training organisation

AMP Bank. Credit Reporting Policy AMP Bank Limited

Release: 1. ICAPMG601A Establish IT project governance

Privacy Breach Protocol

Complaint management policy About this policy

Home Warranty Insurance - Western Australia Insurance Policy

Pre Course Information Certificate in Work Health & Safety 2012

PRIVATE HEALTH INSURANCE INTERMEDIARIES PRACTICE CODES JUNE 2015 VERSION 2

Guideline for Roles & Responsibilities in Information Asset Management

Information and records management. Purpose. Scope. Policy

APPENDIX 4G CORPORATE GOVERNANCE

Standard of Direct Mail Fundraising Practice

Private Health Insurance Intermediaries. Document 2: Self-Audit Questionnaire. Version 2

Privacy and Cloud Computing for Australian Government Agencies

USE OF INFORMATION TECHNOLOGY FACILITIES

Westpac Business Debit MasterCard Application

1.4 For information about our management of your other personal information, please see our Privacy Policy available at

Records Management Security of University Records Procedures

Information and Compliance Management Information Management Policy

ASPEN AUSTRALIA BRANCH PRIVACY POLICY

OSHC Extras. Overseas Student Health Cover. Policy Document. Effective 1 April 2015

ENTERPRISE RISK M A NAGEMENT POLICY

Document Management in the FIPPA Era

J O B S P E C I F I C A T I O N

RECORDS MANAGEMENT POLICY

Standard 1. Governance for Safety and Quality in Health Service Organisations. Safety and Quality Improvement Guide

Management of Official Records in a Business System

Information Management Advice 50 Developing a Records Management policy

CBHS HEALTH FUND LIMITED PRIVACY POLICY

WEST LOTHIAN COUNCIL RECORDS MANAGEMENT POLICY. Data Label: Public

Privacy Statement. What Personal Information We Collect. Australia

SAAS Notification. September 1, 2015

2016 Grants. Information Booklet

Checklist to establish a Public Company Limited by Guarantee

Signed:... (worker or representative) Guidelines for Claiming Compensation Benefits September 2013 Page 46 of 46

TRAINED CHILDCARE WORKER POSITION DESCRIPTION

Alta Investment Management Financial Services Guide

Cloud Service Contracts: An Issue of Trust

Chester Beatty Library Records Management Policy

WHAT KIND OF PERSONAL INFORMATION DOES NINE COLLECT AND HOW DOES NINE COLLECT IT?

BCPay. Alternative payment process when Online Banking is experiencing Operational Disruptions. Product Disclosure Statement

Belmont 16 Foot Sailing Club. Privacy Policy

Transcription:

Records and Document Management Policy P3 Current: Updated November 2011

Table of Contents Purpose... 3 Scope... 3 Definitions... 3 Policy statement... 4 Responsibility... 4 Legislative context... 5 Associated documents... 5 Implementation... 5 Page 2 of 6

Purpose To establish the requirements for adequate recordkeeping, document management and security of information for the Institute of Internal Auditors Australia (IIA Australia). To ensure academic records of all current and former candidates are managed in an accurate, efficient, comprehensive, secure and timely manner, and in a way which meets the requirements of the Commonwealth and State governments, accreditation bodies, and relevant legislation. Scope This policy is applicable to all staff and volunteers of the IIA Australia and to all corporate records and documents, in any format and from any source. Examples include paper, electronic messages, digital documents and records, video, DVD, and web based content. Definitions P3.1 Document Structured units of information recorded in any format and on any medium and managed as discrete units or objects. Some documents are records because they have been used in a business transaction, or were created to document such a transaction. Conversely, some documents are not records because they do not function as evidence of a business transaction and they can be low level administrative documents. P3.2 Email The transmission of text messages and optional file attachments over a network. P3.3 Records Information created, received, and maintained as evidence by an organisation or person, in pursuance of legal obligations or in the transaction of business. (Source: AS ISO 15489.1 2002, Information and documentation Records management 3.15 now: SAI: AS ISO 15489 (Set) 2004 Records Management Set.) P3.4 Recordkeeping system P3.5 Records management Information system that captures, manages and provides access to records through time. (Source: AS ISO 15489.1 2002, Information and documentation Records management 3.15 now: SAI: AS ISO 15489 (Set) 2004 Records Management Set.) Field of management responsible for the efficient and systematic control of the creation, receipt, maintenance, use and disposition of records, including processes for capturing and maintaining evidence of, and information about, business activities and transactions in the form of records. (Source: AS ISO 15489.1 2002, Information and documentation Records management 3.15 now: SAI: AS ISO 15489 (Set) 2004 Records Management Set.) Page 3 of 6

Policy statement IIA Australia requires all staff and volunteers to ensure: records are managed in a consistent and structured manner records are stored in secure manner reasonable steps are undertaken to protect personal information from unauthorised access, modification or disclosure personal information is destroyed or permanently de identified when no longer required compliance with legal and regulatory requirements on record management (Commonwealth and State governments, accreditation bodies, and relevant legislation) records and documents are managed in accordance with IIA Australia procedures, which include time limitations and method of storage. The IIA Australia aims to provide all of our web users with a safe online experience. Our system encodes credit card and contact details to ensure it is safe to transfer to us. Full details of storage methods and time limits are provided in Procedure R2 Candidate Academic Records Management. Responsibility The CEO is responsible for ensuring that the organisation complies with this policy and delegates this responsibility as follows. The Director Finance and Operations is responsible for establishing policies and procedures for records management and information security and ensuring that staff and volunteers are aware of the policies and procedures. The Director Finance and Operations is responsible for the financial and operational records. The Director of Learning and Development is responsible for the candidate and higher education records. The Executive Officer is responsible for the governance records and for compliance with Privacy Legislation. The Manager Communications and Marketing is responsible for the website, published documents and email templates. IIA Australia managers are responsible for ensuring their area and team comply. Page 4 of 6

Legislative context Commonwealth Copyright Act 1968 Freedom of Information Act 1989 (NSW) Privacy Act 1988 (Cwth) Health Records and Information Privacy Act 2002 (NSW) Workplace Surveillance Act 2005 (NSW) NSW Higher Education Act 2001 Associated documents IIA Australia Policy P12: Privacy and Security of information IIA Australia Procedure R1: Records and Document Management IIA Australia Procedure R2: Candidate Academic Records Management The above documents are available on the website at: www.iia.org.au Implementation The Records and Document Management Policy is implemented throughout the IIA Australia via: publication on the IIA Australia web site email notification to staff email notification to relevant committees of the IIA Australia Board of Directors Module Learning Pack published for candidates of the Graduate Certificate in Internal Auditing. IIA Australia managers are responsible for implementation in their areas. Page 5 of 6

The Institute of Internal Auditors Australia PO Box A2311 Sydney South NSW 1235 Telephone: + 61 2 9267 9155 Facsimile: + 61 2 9264 9240 E mail: governance@iia.org.au Website: www.iia.org.au Level 7 133 Castlereagh Street Sydney NSW 2000 Australia Copyright IIA Australia 2011 ABN 80 001 797 557 Page 6 of 6