Information governance is the set of policies and accountability rules that decide how information should be handled; information management is the day-to-day practice of actually organising, storing and retiring it. Governance sets the rules, management carries them out.

Governance sets the rules, management carries them out

Information governance and information management get used interchangeably often enough that it’s worth drawing a clear line between them. Information governance is the set of policies and accountability rules that decide how information should be handled: what counts as a record, how long it’s kept, who’s allowed to access it, and who’s responsible if something goes wrong. Information management is the day-to-day practice of actually organising, storing and retiring that information according to those rules. Put simply: governance decides what’s allowed; management makes it happen.

The distinction matters because a lot of small businesses do management without realising they lack governance. Someone’s organised the shared drive sensibly, files get saved in roughly the right place, and things generally work, until a staff member leaves, a new hire joins and has no idea what the “roughly right place” actually is, or a regulator asks for a documented policy rather than just evidence that things are tidy.

What governance actually answers

Governance is the layer that answers questions like: what personal information are we allowed to collect and for how long can we keep it? Which records are legally required, and which are just habit? Who’s accountable if a record goes missing or gets accessed by the wrong person? These aren’t questions a folder structure can answer on its own. They need a decision, written down, that the folder structure then reflects.

What management actually answers

Management is the layer that answers the more practical, everyday questions: where does this document live? How do I find last month’s version rather than an outdated one? What’s the process for saving a new contract so it ends up in the right place automatically, rather than depending on someone remembering? Good management makes good governance easy to follow and without governance behind it, management tends to drift over time as different people make slightly different judgement calls.

Which to set up first

For most small businesses, a lightweight governance policy should come before further investment in management tooling. It doesn’t need to be complex. Even a single page covering what you keep, where, for how long, and who’s accountable is enough to start. That page then becomes the reference point for every management decision that follows: how folders are structured, what naming convention is used, and when something should be archived or deleted.

This also tends to be exactly what regulators and auditors actually want to see. The Office of the Australian Information Commissioner, for instance, is generally more interested in evidence of a documented policy than in how tidy your shared drive looks on the day of a review. Good habits without a written policy behind them are hard to demonstrate after the fact, even if they’re genuinely being followed day to day.

A practical starting point

If you’re not sure whether your business has governance or just management, ask yourself one question: if a new person joined tomorrow and asked “what are we actually supposed to do with this kind of document?”, could you point them to something written down, or would you be explaining it from memory? If it’s the latter, that’s your starting point. Not a new system, just a short, honest policy that captures the decisions your business has already been making informally.

How this shows up day to day

Take a common scenario: a client sends over a signed contract by email. Management is the part where that contract gets saved somewhere sensible, named consistently, and is easy for someone else to find later. Governance is the part that decided, in advance, that signed contracts get kept for seven years, that only certain people can access them, and that they need to be stored somewhere with proper backup rather than left sitting in one person’s inbox as the only copy that exists.

Without governance behind it, management tends to drift as different people make their own reasonable-sounding judgement calls. One person decides contracts should live in a ‘Legal’ folder; another creates a ‘Contracts’ folder instead, not realising one already exists. Neither decision is wrong on its own, but multiplied across a growing team, this is exactly how businesses end up with the scattered, duplicated mess that most information management projects start by cleaning up.

Where governance connects to broader risk

Information governance doesn’t sit in isolation from the rest of your business’s risk profile. The same questions it answers (what do we hold, who can access it, how long do we keep it) are also central to cybersecurity and compliance frameworks like the Essential Eight or ISO 27001. A business with clear information governance already in place generally finds it considerably easier to work through a cyber risk assessment, simply because the groundwork of knowing what it holds and who’s accountable for it has already been done.

Quick facts

  • Governance answers ‘what are we allowed to keep, and for how long?’
  • Management answers ‘where does it live, and how do we find it?’
  • Small businesses often do management without realising they lack governance until an audit or breach exposes the gap.
Curious how this looks in practice? Explore our approach to Information Management.

Book A Call