While records management may not be the top of everyone’s priority list in the workplace, it is one of the key responsibilities of the Company Board. Not only does it underpin good corporate governance, it is integral gaining public trust and confidence in companies and the people who run them.
The Corporations Act 2001 (Cth) lists records management as a key responsibility directors and company secretaries to which they are held accountable by the Australian Securities and Investments Commission (ASIC) who has the power to prosecute.
Non-complaint records management can potentially expose company directors of corporations to penalties of up to a 5-year jail term and a $200,000 financial penalty.
Some examples of recent ASIC enforcement activities include:
- In 2014 a Perth director was sentenced to 14 months in jail after pleading guilty to three counts of providing false and misleading information to the Australian Securities Exchange.
- In 2018 a NSW former director and CFO was sentenced to 3 years jail after he was found guilty of intentionally falsifying financial documents.
- A Queensland director is currently on bail awaiting sentence for providing false information to company auditors.
Three ways to make sure you are protected
1. Manage your records in-place
The majority of organisations can effectively and compliantly manage their records within existing business systems such as Microsoft 365, finance systems and CRMs. With some planning and use of out-of-the-box functionality, there is no longer the need to invest in a dedicated records management system or eDRMS.
2. Focus your efforts on the high-value and high-risk records
This will minimise your risk exposure. For corporations theses are financial and board records, for service-based organisations this will include your client records, for resource and construction these include your safety records.
3. Have a current records management policy
Policies should be principles-based to ensure they are easily understood by all staff. They should also include requirements from relevant legislation, clear roles and responsibilities and be underpinned by detailed procedures. Policies should be reviewed every 2 years and don’t forget to communicate it to staff!

Conclusion
Records management risk rarely comes from a single failure—it builds up quietly over time through inconsistent practices, unclear ownership, and a lack of visibility. When information is hard to find, out of date, or stored in the wrong place, organisations are exposed not only to compliance and legal risk, but also to operational inefficiency and loss of trust.
The good news is that most records management risks are avoidable. With clear governance, well‑defined responsibilities, and the effective use of tools already available in platforms like Microsoft 365, organisations can regain control of their information. Taking a proactive approach to records management doesn’t just reduce risk—it makes information easier to manage, easier to trust, and easier to use.
If records management feels complex or overwhelming, that’s often a sign that it’s time to reassess—not delay. The longer the risks go unaddressed, the harder they become to unwind.




