Records, Accountability and Democracy

 A Contribution Culminating From Forty Years of Practice

Nigel Carruthers-Taylor

After more than forty years of using, designing and implementing document and records management systems for some of the most highly governed organisations in Australia, I find myself with an opportunity to put down in writing something I have always  believed, and something many records managers know but often forget: that records management is not merely an administrative discipline. It is, at its deepest level, a cornerstone of democracy. It is the mechanism by which a society insists that power must be visible, that decisions must be traceable, and that those who govern must be held accountable - not just today, but in the years and decades to come.

I have watched this profession evolve from the age of paper files and metal filing cabinets through the era of early electronic document management systems, through the explosion of enterprise content platforms, and now into the age of Artificial Intelligence (AI), cloud computing, and the ubiquitous Microsoft 365 environment that has become the daily working reality for millions of public servants and corporate employees worldwide. Through all of this change, one truth has remained constant: without sound, structured, accessible and defensible records, accountability is a fiction.

This essay is the culmination of forty years of contribution to the profession. It is written not as a technical manual, nor as a product guide, but as a reflection - and, I hope, a provocation - for those who will carry this work forward. I write it because the confusion I have witnessed in recent years concerns me deeply. We are living through a period of genuine crisis in records management, even as the tools available to us have never been more powerful. We are failing to capture the record of how decisions are made, failing to maintain the contextual integrity of those records, and in doing so, we are quietly undermining the very transparency frameworks on which democratic governance depends.

Deep gratitude and thanks to Adelle Ford, Director, Recordkeeping Innovation Consulting for her peer review, and Dwayne Stocks, Solutions Architect, Kapish, for his expert review of the AI autoclassification section. Importantly, thanks to my darling wife, Caronne for all her love and support over many, many years, and for her expert writing reviews.

Abstract

Records management stands at a crossroads. After more than forty years of using, designing and implementing records systems for some of Australia’s most highly governed organisations, this essay argues that the profession’s central challenge is not technological but democratic: without complete, authentic, and accessible records, the accountability that democratic governance demands becomes impossible to enforce. The essay examines the modern records management crisis - the fragmentation of organisational memory across multiple digital platforms, the risks of AI-driven autoclassification when applied without adequate information architecture, and the compliance limitations of manage-in-place models when adopted as complete solutions. It honestly assesses Microsoft Purview as the commonly desired go-to for autoclassification and manage-in-place, recognising its genuine value while identifying its structural limitations for high-value recordkeeping. The core argument is that a hybrid approach - combining the centralised Duranti model, the Bearman process-embedded model, and managed-in-place governance - offers the practical path to meeting both the scale demands of modern digital work and the evidentiary standards that accountability requires. Foundational to this hybrid approach is a well-designed information architecture, built around real business activities and used to train AI classifiers before deployment. Six principles for practitioners guide the conclusion, alongside a call to the profession: as the tools of records management change, the democratic function they serve does not.

Keywords: records management, democracy, accountability, artificial intelligence, hybrid records management, information architecture, Microsoft Purview, manage-in-place


I. Records as the architecture of democratic life

Let me begin with what should be self-evident but is, in practice, dangerously overlooked or forgotten: records are infrastructure. Not in the mundane sense of cables and servers, but in the civic sense - the same sense in which we speak of courts, elections, and a free press. They are the means by which the actions of institutions are made knowable to those outside them. They are the raw material of accountability.

Consider what it means for a citizen to live in a democracy. It means, among other things, the right to ask: what did the government decide, on what basis, at whose direction, and with what outcome? It means the ability to access, through freedom of information legislation, the documents that record the internal deliberations of public bodies. It means the capacity of a parliamentary committee to call for the papers, to examine the audit trail, to follow the thread of a decision back to its origins. It is also the means in which we preserve our history and define the truth of our origins. All of this depends - entirely and without exception - on records having been made, kept, and preserved in a form that is authentic, reliable, complete and accessible.

When records fail, democracy does not merely become inconvenient. It becomes, in a very practical sense, inoperable. We have seen this play out in real political life with disturbing frequency in recent years. Across the globe, in mature democracies that regard themselves as exemplars of good governance, we have witnessed the failure of recordkeeping infrastructure on a scale that would have been unimaginable to earlier generations. Politicians who judiciously redact information to highlight their version of the truth. Ministers who cannot produce documents showing how decisions were made. Public health authorities whose pandemic-era deliberations are unrecoverable. Procurement processes where the evidentiary trail of how contracts were awarded has been scattered across personal email accounts, encrypted messaging apps, and shared drives with no access controls. These are not mere administrative failures. They are democratic failures, and they are being produced, in large part, by the collapse of records management discipline in the age of digital communications.

The paradox of our era is that we have never created more information, and we have never had a harder time finding any of it. The very productivity of modern digital work environments - the ease with which emails are sent, documents are created, messages are exchanged on Teams and social comms - has produced what I think of as the frictionless trap. When creating a document costs nothing, saving a file takes a single click, and every message is automatically retained somewhere, the natural response is to create more, save more, and organise nothing. The result is an explosion of information objects that are simultaneously everywhere and nowhere - in dozens of locations, in multiple versions, with inconsistent metadata, no authoritative provenance, and no mechanism for establishing which version is the authentic record of a transaction.

The consequences of this are most acutely felt when accountability is demanded. A freedom of information request that ought to produce a clear set of records instead generates weeks of manual searching across dozens of repositories. A royal commission discovers that the documents it seeks are legally unproducible because they were held in collaboration tools that retain no metadata, or in personal accounts outside corporate governance, or because the disposal of those records - whether deliberate or accidental - cannot be proved either way. The system becomes, in the most literal sense, un-auditable. And an un-auditable system of government is not a democracy in any meaningful sense. It is a managed fiction.

II. The changed risk landscape and the inadequacy of old responses

The risk landscape for records management has changed fundamentally in the last decade, and the profession has not yet fully recalibrated. The frameworks that served us well in the era of centralised electronic document management - retention schedules, disposal authorities, classification schemes, file plans - remain necessary, but they are no longer sufficient. They were designed for an environment in which records were created and stored in a relatively small number of controlled locations, by people who understood that creating a record was a specific, intentional act. That environment no longer exists.

Today, a single business transaction - a decision to procure a contract, to approve a policy, to resolve a complaint - may be documented across Microsoft Teams messages, Outlook emails, SharePoint documents, OneDrive personal storage, Salesforce records, SAP system entries, and mobile phone messages or photos. No retention schedule, however comprehensive, was designed to manage this reality. No classification scheme, however detailed, can apply itself automatically and correctly to content scattered across so many platforms and repositories. The professionals who have inherited these tools are working heroically, but they are working with instruments designed for a different age.

This mismatch between the tools of the profession and the reality of the modern digital workplace has generated enormous pressure to find new approaches. The profession has responded with two powerful tools: AI for automated classification at scale and manage-in-place management to apply governance without disrupting existing workflows. Both are genuine advances, and both have an important role to play, as this essay argues in detail below. But both are also, when adopted as complete solutions rather than as carefully bounded components of a broader strategy, capable of making the democratic accountability problem significantly worse than the one they set out to solve.

III. What the evidence tells us: lessons from practice and research

I have spent much of the last several years working through these questions in practice, not merely in theory, and I want to draw together the conclusions that practice has forced upon me. What follows is a synthesis of arguments I have made in previous writing (Carruthers-Taylor, 2024a, 2024b, 2025), grounded in academic research, industry surveys, standards bodies, and direct organisational experience. I offer them here as the foundation on which any serious strategy for modern records management must be built.

Artificial Intelligence: promise, peril, and the conditions for success

AI has arrived in records management with enormous fanfare, and much of the excitement is justified. The ability to automatically classify large volumes of records, to identify content requiring retention controls, to surface related materials during discovery - these are genuine capabilities that address real bottlenecks in the profession. For any medium-to-large organisation, the volume of information produced each day has long since exceeded manual classification and control capability. In that sense, AI is not a luxury. It is a practical necessity. But the uncritical adoption of AI as a complete solution carries risks that are not yet widely understood, and which the profession ignores at its peril.

The central technical risk is hallucination - the well-documented tendency of large language models to generate plausible but incorrect outputs when the quality of their training data is insufficient. Research from Cornell University has found that AI systems hallucinate at rates ranging from 69 to 88 percent of the time on complex tasks, and up to 50 percent even on relatively simple ones. (Dahl et al., 2024) In a records management context, this is not merely an inconvenience. A system that mis-classifies a record - applying a short-term retention schedule to a high-value document or failing to identify that a cluster of emails constitutes the evidential record of a significant decision - is not just operationally inefficient. It is potentially destroying evidence that accountability will one day require.

The root cause of AI hallucination in records management is, almost invariably, inadequate context. An AI classifier that cannot determine the business transaction to which a document belongs, or which cannot see the full thread of communications that constitute a decision-making process, cannot make accurate judgements about that document's significance, its relationship to other records, or its appropriate retention period. This is not a problem that will be solved by better algorithms alone. It is a structural problem, produced by the fragmentation of records across multiple unconnected repositories - and it is a problem that manage-in-place, if uncritically adopted, makes significantly worse.

Consider a procurement transaction in a government department - an example that mirrors reality in organisations of all kinds. The officer managing the procurement communicates formally through Outlook and informally through Teams. Working documents are drafted in a Teams channel. Standard templates are stored on a shared network drive. Colleagues draw down their own copies to OneDrive and make independent amendments. When the contract is finalised, an in-place AI classifier examines each of these items in isolation, applies retention labels based on content characteristics, and records the transaction as managed. The system reports compliance. But when a question later arises about how a particular contract price was determined, no one can reconstruct it. 

The AI classified each fragment according to its surface features - a draft as a working document, an email thread as routine correspondence, a template as a non-record. It had no means of understanding that together, these fragments constituted the complete evidentiary record of a significant decision. Some were marked for short-term retention and disposed of accordingly. The AI did not hallucinate in the conventional sense. It did something more insidious: it made technically accurate classifications of individual items while comprehensively misunderstanding their collective significance. That is precisely the failure mode that inadequate context produces - and it is a failure mode that, in a public accountability setting, has consequences that long outlast the transaction itself.

But acknowledging these risks must not become a justification for avoiding AI altogether. The answer is not to dismiss autoclassification - it is to create the conditions under which it can function reliably. Those conditions begin with something that is neither new nor glamorous, but which remains the foundation of every effective records management program: a well-designed information architecture, grounded in the actual business activities of the organisation, supported by a coherent metadata structure, and applied with genuine commitment to training the AI on the resulting classifications.

This sounds straightforward. In practice, it is where organisations most commonly fail - and where the consequences of cutting corners are most severe. I experienced this directly while developing an information architecture for a government organisation to be applied across their Microsoft 365 environment. The organisation’s initial suggestion was to take their existing Business Classification Scheme (BCS) and use it, largely unchanged, as the structural basis for their M365 configuration. I argued against this - and persuaded them that the existing scheme, built around the language of records professionals, was not the language their staff used or related to. A better approach was to analyse the actual business activities of each section of the organisation, build an architecture that supported how people genuinely worked, and then map that architecture to the formal records classifications. This two-step approach had an additional benefit: because the resulting information categories reflected real business activities, the content within them would be far better structured and more internally consistent - which meant the AI training process would be substantially more effective. The classifications would make sense to the AI for the same reason they made sense to the staff: they corresponded to the actual shape of the work.

What happened next is instructive, and I recount it because I suspect it is not unique. Once the architecture was defined, I explained that the classifications would need to be reviewed and validated with each section of the organisation, and that a meaningful investment of effort would then be required to train the autoclassification AI against the resulting structure. At that point, the organisation's IT team declared the process too complex and 'old school.' The 'new way,' in their assessment, was to point the AI at the existing information in its existing structure and let it classify what it found, then correlate that to the current BCS. By this time my architecture was delivered and my contract scope complete, so I withdrew from the engagement; sometime later I heard, through professional channels, that very little progress had been made.

This experience crystallised something I had suspected for years but had not previously articulated so clearly: the information architecture is not preliminary work that precedes the records management strategy. It is the records management strategy. Get it right, and AI classification becomes a powerful, scalable tool for applying that strategy at the volume that modern organisations require. Get it wrong - or worse, skip it entirely in favour of applying AI to an unanalysed, unstructured information landscape - and the AI does not solve the records problem. It embeds it, at speed and at scale, with a false veneer of automated compliance. 

This is not a theoretical concern. In a widely-shared ARMA webinar, Kaan Volkan made precisely this warning: organisations where large language models, applied without adequate information architecture to facilitate good AI training, fall dangerously short for records programs – and what that can cost organisations that fail to heed the warning. His presentation title said it plainly: “LLMs Destroyed My Records.” The warning is timely, and the profession would do well to heed it. (Volkan, 2025)

A government or institution that claims its records are being managed by an AI system - but whose underlying information architecture has never been analysed, whose classifications have never been validated with the business, and whose AI has never been properly trained - is not better governed than one that acknowledges its records management is manual and imperfect. It is worse governed, because it has substituted the appearance of control for the reality of it. Defining a solid information classification and architecture, and investing the time required to train your AI against it, is not old school. It is the prerequisite for everything else that follows - and it is, as I will argue below, the foundation that gives organisations the flexibility to apply different records management models appropriately across different record classifications and types.

The in-place model: real value, real limitations

Manage-in-place - the approach of applying records controls to content where it resides, rather than moving it to a dedicated records repository - has become the dominant paradigm of the Microsoft 365 era. It has real virtues. It reduces the friction of recordkeeping for end users who would otherwise resist engaging with records systems. It scales to the volumes of content that modern organisations produce. It integrates with the tools that people actually use. These are not trivial advantages.

But academic research is clear about its limitations. As Lappin, Jackson, Matthews and colleagues argued in Archival Science, 'the in-place model involves acceptance of sub-optimal structure/schemas, so in circumstances where it is possible to optimise the efficiency of a structure/schema of a corporate records system, we should reject that model.'(Lappin et al., 2021) This is not a call to abandon in-place management; it is a call to be honest about what it can and cannot achieve.

What it cannot achieve is the maintenance of full contextual integrity for complex, high-value records. The Australasian Digital Recordkeeping Initiative's Functional Requirements for Managing Records in Microsoft 365 makes this explicit: records management in M365 must ensure that 'contextual relationships between records must be maintained - mechanisms must connect records and information relating to the same body of work, assign version controls, and connect records across systems.' (Australian Digital Recordkeeping Initiative, 2021) This is a requirement that a pure in-place model, by its very nature, struggles to meet. When a record can exist simultaneously in a person's Outlook folder, their team's SharePoint site, and a shared OneDrive location - in potentially different versions, with different access permissions and without a clear mechanism for determining which version is authentic - the contextual integrity of that record is compromised.

There are also practical cost consequences that are often overlooked in the enthusiasm for in-place approaches. Content that remains in high-cost primary storage long after it has ceased to be actively used drives up operational expenditure.(Tolson, 2021) Multiple repositories increase the cost and complexity of responding to freedom of information requests and legal discovery, because every location must be searched, every version evaluated, and every copy accounted for. Security and privacy controls must be applied and maintained separately across every repository, increasing both cost and risk. The apparent efficiency of manage-in-place frequently conceals significant hidden costs that only become visible when accountability is demanded.

Microsoft Purview: promise, reality and the case for integration

This brings the discussion to Microsoft Purview - the suite of governance, risk, compliance and information management tools embedded within the Microsoft 365 environment that everyone wants to start using. Purview represents Microsoft's primary answer to the records management challenge in the M365 ecosystem, and understanding both its genuine capabilities and its fundamental limitations is essential for any practitioner designing a records strategy in the current environment.

The surprising reality, despite Purview having been available for over five years and the concept of in-place management having existed since the mid-2000s, is that uptake has been remarkably limited. A global study by IG World found that use of Purview for governance had actually declined, from 50 percent to just 40 percent of organisations, with 94 percent reporting significant challenges and most using only a fraction of available features. (IG World Magazine, 2024) This is not, primarily, a failure of education or marketing. It reflects a genuine and rational assessment by experienced practitioners that Purview, taken on its own, is not adequate for full records management (Brown, 2025) - particularly in government and other highly regulated sectors where evidentiary defensibility is not optional.

Purview is, at its core, a collection of tools - a Meccano set spanning information governance, risk management, security monitoring and compliance functions - rather than a unified, purpose-built records management application. Its architecture is technically complex, requiring practitioners to understand the underlying mechanics of Microsoft 365's repository structures, security configurations, and authentication systems. Most records managers do not have this knowledge, and the investment required to acquire it is substantial.

More fundamentally, Purview's object-centric model - applying retention at the level of individual items rather than at the level of business transactions, cases, or folders - undermines contextual integrity. It cannot, by design, readily aggregate the related items that constitute the full evidentiary record of a decision. When records are disposed of through Purview, their metadata is destroyed along with the content, making it impossible to demonstrate that a record existed and was disposed of in compliance with an approved schedule. For organisations that depend on defensible disposal - and for democratic accountability, every government organisation should (National Archives of Australia, n.d.) - this is not a minor technical limitation. It is a critical compliance failure.

Purview's AI-driven classification capabilities, while genuinely useful for broad governance at scale, tend to apply retention labels at a high level of abstraction, with limited granularity. This creates the risk that high-value records are inadvertently classified as low-value, and that records managers are left with insufficient confidence in the system's outputs to rely on them without manual verification - which negates the efficiency gains that AI was meant to deliver. (Volkan, 2025). Other in-place platforms, such as Castlepoint and OpenText products, face analogous constraints: they deliver real value in discovery and classification, but achieve best practice only when complemented by a system capable of providing evidentiary assurance, structured metadata, and defensible lifecycle management.

My recommendation: the hybrid model

The way forward that I have arrived at, through years of practical implementation and careful reading of the academic and professional literature, is neither the centralised EDRMS model nor the manage-in-place model in isolation. It is a deliberate and principled combination of both - what I think of as a hybrid approach - drawing on three distinct traditions in records management.

The first is the Duranti model, associated with Dr Luciana Duranti of the University of British Columbia, which advocates for moving records from business applications into a centralised repository whose structure and schema are optimised for recordkeeping. This model provides the greatest assurance of contextual integrity, authenticity, and evidentiary defensibility, and remains the appropriate approach for the most significant categories of records - legal and compliance documents, financial records, human resources records, client and project records, and strategic business data. In the Australian Government context, traditional EDRMS’ have long represented the pre-eminent implementation of this tradition, and their track record of meeting the most demanding regulatory requirements remains unmatched.

The second is the Bearman model, developed by archivist David Bearman, which takes a different approach: rather than moving records to a separate repository, it intervenes in business applications themselves to ensure that their functionality and schema are optimised for recordkeeping. This model is best suited to contexts with clearly defined, repeating business processes and limited record types - transactional records, compliance-driven workflows, high-frequency operational records - where the overhead of centralised capture would be disproportionate. The Bearman approach, properly implemented, ensures that even routine operational records are captured in context, without placing excessive demands on end users.

The third tradition is the manage-in-place model, which - for the right categories of records - offers genuine advantages in terms of user adoption, scale, and integration with everyday working tools. General administrative records, drafts and working documents, routine internal communications, non-sensitive training materials: these are legitimate candidates for manage-in-place governance, and Purview is a reasonable tool for applying that governance at scale, provided its limitations are understood and mitigated.

The practical implementation of this hybrid approach is, at its core, straightforward: apply the model to the record according to its value, its complexity, and the accountability requirements it must serve, and apply the right technology at the right point. Low-value and short-term records remain in place, governed through the likes of Purview or similar in-place tools. Systems supporting single or a small number of record types use the Bearman model, assuming the application creating these records supports it – otherwise integrate it to an EDRMS or an independent in-place system. High-value records - identified through the autoclassification labelling capabilities, whether applied manually or through machine learning - are uplifted into an EDRMS for stronger lifecycle management, contextual integrity, and defensible disposal. In some cases, the record may still be 'managed in place' within its originating system, but with the EDRMS applying robust classification, retention, and disposal controls. In others, it is physically moved into the EDRMS to sit within the appropriate business context alongside the other records of that transaction.

In practical terms, solutions that enable seamless synchronisation between a centralised EDRMS and Microsoft 365, allowing autoclassification labelling to trigger the EDRMS’ more rigorous compliance and disposal processes - represent the actual realisation of this hybrid vision. Organisations such as Wodonga TAFE illustrates what this looks like in practice. Faced with over 1,600 unused SharePoint and Teams sites accumulated during the rapid digital expansion of the COVID-19 pandemic, the organisation used their EDRMS to archive and manage the cleanup of those inactive sites, while setting up manage-in-place controls for 456 active sites - all without disrupting the daily working environment of its staff. 'This easy integration has allowed us to manage some sites as 'manage in place' and others we finalise and can delete / archive,' their Records Management Specialist noted - a simple statement that describes, precisely, what best practice looks like. (Carruthers-Taylor, 2024b).

What this model achieves, above all, is the alignment of records management effort with records management risk. Not every record demands the full rigor of centralised lifecycle management, and insisting that it does is a recipe for non-compliance through user rejection. But every record of significant decisions, significant transactions, or significant accountability must be held to the highest standard - not because of administrative convention, but because democracy requires it.

IV. What this means for strategy going forward

For the records managers who will carry this profession forward, I want to offer not a set of prescriptions but a set of principles - ways of thinking about the strategic choices they will face that I believe are robust enough to survive further technological change.

The first principle is that records management must be understood as a governance function, not an administrative or technology function. The choice of platform, the configuration of retention labels, the integration of AI classifiers - these are implementation details. The fundamental questions are: what decisions is our organisation making, who is authorised to make them, what evidence of those decisions must we preserve, for how long, and where are these decisions created, used and managed? Technology and administrative processes serve those questions. They do not answer them.

The second principle is to invest in the information architecture before the algorithm. No AI classification system can perform reliably if the information it is applied to has not first been analysed and structured in a way that reflects how the organisation actually conducts its business. This means engaging with your business to understand what records they create and why; defining information categories that map to real activities rather than inherited classification schemes that staff do not recognise or use; and committing the time required to validate those categories with the business before training any AI against them. This work is unglamorous and it will always face pressure to be abbreviated or bypassed in favour of a faster, technology-first approach. Resist that pressure. As the evidence from practice shows - including Kaan Volkan’s documented warning in his ARMA webinar (Volkan, 2025) - the price of skipping it is an AI that classifies confidently and incorrectly, disposing of records at scale that should be kept and creating a compliance record that is, at best, unreliable. The information architecture is not overhead. It is the strategy itself.

The third principle is to match the model to the record. A single records management approach - whether centralised, Bearman-integrated, or managed in place - is unlikely to be the right answer for every record in every context. The hybrid model is not a compromise; it is a recognition of genuine complexity. The skill lies in the analysis: understanding which records carry accountability significance, which are transactional, and which are genuinely ephemeral, and then applying the appropriate level of governance to each. A records solution must be capable of supporting all three models -and organisations that choose tools that lock them into a single approach are accepting unnecessary risk.

The fourth principle is never to mistake classification for preservation. Applying a retention label - whether manually or through AI - is not the same as ensuring that a record is authentic, complete, contextually intact, and retrievable. Classification is a necessary first step; it is not the whole answer. The records profession must resist the pressure - and it will come, increasingly, from technology vendors and from internal officers looking for simple solutions - to treat AI classification as a substitute for the harder work of ensuring that the classified records are, in fact, in good order.

The fifth principle is to be honest about what in-place management can and cannot do. It can capture records at scale. It can reduce user burden. It can integrate governance into the flow of everyday work. What it cannot reliably do - without integration with a more structured system - is maintain the contextual integrity of complex, multi-system transactions, provide defensible proof of disposal, easily preserve records in accountable way, or ensure that the full evidential record of a significant decision is available when accountability is demanded. Organisations that treat manage-in-place as the complete answer to their records management challenges are, in most cases, accepting a level of risk that they have not fully assessed.

The sixth, and perhaps most important principle is this: remember what records are for. They are not for the records manager. They are not even, primarily, for the organisation that creates them. They are for the future - for the auditor who will need to reconstruct a decision ten years from now, for the citizen who will exercise their right to information, for the commission of inquiry that will need to follow the thread of events back to their origins, for the court that will need to establish what was known and when. Records managers are the custodians of institutional memory, and institutional memory is the currency of democratic accountability.

V. A final word

I am retiring at a moment when the profession faces challenges it has never previously encountered, and opportunities it has never previously had. Artificial intelligence will, over the next decade, transform the mechanics of records management in ways that none of us can fully anticipate. It will automate tasks that have consumed enormous professional effort and time. It will surface relationships and patterns in large volumes of content that human reviewers could never find. It will make some aspects of compliance monitoring faster, cheaper, and more consistent.

But it will not - it cannot - substitute for the human judgement that lies at the heart of records management as a profession. The judgement about what matters. The judgement about what constitutes an authentic record of a decision or a collective evidence of an outcome. The judgement about whether an organisation's records management practice is genuinely serving the accountability functions that democracy requires, or merely creating the appearance of governance while the substance goes unrecorded.

The world is producing governments and institutions that are increasingly comfortable with opacity - that are, at some level, content to operate in environments where the record of how decisions were made is inaccessible, incomplete, or simply non-existent. The records management profession exists, in part, to resist that tendency. It exists to insist - through the design of systems, the training of practitioners, the development of standards, and the implementation of solutions - that the exercise of power must leave a trace. That trace must be findable, readable, trustworthy, and preserved.

After forty years of this work, I remain convinced - perhaps more than ever - that records management is one of the most important professions a democratic society can have. It may not be the most glamorous. It rarely receives the recognition it deserves. But without it, the promise of democratic accountability is hollow.

To those who carry this work forward: hold the line. The tools will change. The platforms will change. The vocabulary will change. But the fundamental question - can the exercise of power be seen, examined, and held to account? - will not. That question is yours to answer, through the work you do every day.

Yes, this essay was created with the assistance of AI, as you would expect, but the thoughts, principles, experience and selection of reference material are my own. All content has been reviewed, edited, and approved by myself.

Nigel Carruthers-Taylor is the retired founder, Executive Director and Principal of iCognition, acquired by Kapish in April 2026. iCognition operated for 23 years primarily to implement information governance solutions, such as EDRMS, for highly regulated organisations, particularly government. Prior to founding iCognition Nigel was an IT advisor for central agencies in the Australian Government. He is the author of a series of practitioner articles on hybrid records management, AI in records practice, and the use of Microsoft Purview and enterprise document and records management systems in the Microsoft 365 environment.

References

1.     Carruthers-Taylor, N. (2024, February). Will AI and in-place management solve my records problem? iCognition. https://idm.net.au/article/0014662-will-ai-and-place-management-solve-my-records-problem

2.     Carruthers-Taylor, N. (2024, September). Hybrid records management: combining approaches. iCognition. https://idm.net.au/article/0014934-which-way-forward-case-hybrid-records-management-strategy

3.     Carruthers-Taylor, N. (2025, August). Why aren’t people taking up Microsoft Purview? iCognition. https://idm.net.au/article/0015309-why-aren-t-people-taking-microsoft-purview

4.     Dahl, M., Magesh, V., Suzgun, M., & Ho, D. E. (2024, January). Large legal fictions: Profiling hallucinations in large language models. arXiv:2401.01301v1 [cs.CL]. https://arxiv.org/abs/2401.01301

5.     Volkan, K. (2025). LLMs destroyed my records – all you need to know about AI! ARMA Partner Webinar, 25 September 2025. https://community.arma.org/browse/recent-community-events/event-description?CalendarEventKey=3c38f359-9332-4213-96aa-0197f5348221

6.     Australian Digital Recordkeeping Initiative. (2021). Functional requirements for managing records in Microsoft 365 (Version 1.0). Council of Australasian Archives and Records Authorities (CAARA). 

7.     Brown, S. (2025, May 8). Evaluating Microsoft Purview. https://idm.net.au/article/0015149-evaluating-microsoft-purview-critical-assessment-its-records-management

8.     IG World Magazine. (2024). The role of Purview in information governance: Global survey. IG World Magazine. 

9.     Lappin, J., Jackson, R., Matthews, B., et al. (2021). Rival records management models in an era of partial automation. Archival Science. 

10.  National Archives of Australia. (n.d.). Compliant destruction of government information. National Archives of Australia. 

11.  Tolson, B. (2021, April). Why in-place information management is not a complete solution. Archive360. https://idm.net.au/article/0013387-why-place-information-management-not-complete-solution

 

Comments