Records Management Policy

Similar documents
Information Governance and Records Management Policy March 2014

Information Governance Policy

Records Management Plan

Stellenbosch University Records Management Policy

Marketing Best Practice Records Management. Kemal Hasandedic MBII GDDM MRMA National President RMAA

Information Governance Management Framework

Data protection (GDPR) policy

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

Humber Information Sharing Charter

BOARD CHARTER JUNE Energy Action Limited ABN

INFORMATION GOVERNANCE POLICY

OFFICER USE ONLY. 2. Position No: Title of Immediate Supervisor: University Secretary 3. Level: 10

Records Disposal Schedule Charles Darwin University Procurement Services Charles Darwin University

Aligning Records Management with ICT/ e-government and Freedom of Information in East Africa

INFORMATION AND RECORDS MANAGEMENT POLICY

Data Protection Policy

Freedom of Information (FOI) Policy

Thomson House School Freedom of Information Policy

Network Rail Limited (the Company ) Terms of Reference. for. The Audit and Risk Committee of the Board

Data Protection Policy

Burton Hospitals NHS Foundation Trust. On: 22 January Review Date: December Corporate / Directorate. Department Responsible for Review:

IBL LTD AUDIT AND RISK COMMITTEE TERMS OF REFERENCE

STATE OWNED ENTERPRISES REMUNERATION GUIDELINES

DePaul University Records Management Manual October 1, 2016

DPKO and DFS Policy Directive. Records Management

Freedom of Information Act Publication Scheme for Academies

INFORMATION GOVERNANCE STRATEGY. Documentation control

RISK AND AUDIT COMMITTEE TERMS OF REFERENCE

Freedom of Information: Guide to information available from Brentford School for Girls under the Model Publication Scheme

version 1 / 96 R Green Stars Hotel Environmental Management System

NHSLA Risk Management Standards for NHS Trusts Providing Community Services 2011/12

Protocol for Developing Multi-Stakeholder Group Terms of Reference and Internal Governance Rules and Procedures

Moorfields Eye Charity

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead

SAFEGUARDING GOOD SCIENTIFIC PRACTICE

Information Lifecycle Policy (Records Management)

GROUP AUDIT COMMITTEE TERMS OF REFERENCE

Audit Committee of the Board of Directors Charter CNL HEALTHCARE PROPERTIES II, INC.

IG01 Information Governance Management Framework

Corporate policy. Business Continuity Management Policy. Issue sheet

ARTICLE 29 DATA PROTECTION WORKING PARTY

Security Operations. BS EN ISO 9001: 2008 Issue 1.2: 21/10/2016. Quality Manual. Managing Director. Controlled / Uncontrolled when printed

Bank of Botswana Internal Audit Charter March 18, 2013 INTERNAL AUDIT CHARTER BANK OF BOTSWANA

EKSO BIONICS HOLDINGS, INC. Corporate Governance Guidelines

1. Each employee is responsible for managing college records in a responsible and professional manner.

Government of Rwanda records and archives management policy

ARCHIVES AND RECORDS MANAGEMENT SERVICES (ARMS) Quality Improvement Framework for Archives and Records Management Services in Scotland

Internal Audit Annual Assertion on Internal Auditing. for Financial Year

Data Protection. Policy

3410N Assurance engagements relating to sustainability reports

Records have a Life-cycle.

Data Protection/ Information Security Policy

Corporate Governance in the NHS. Code of Conduct Code of Accountability

Guidelines on the management body of market operators and data reporting services providers

FRIENDS OF ELTON SCHOOL

Records Management Policy. EPA Classification No.: CIO CIO Approval Date: 02/10/2015. CIO Transmittal No.: Review Date: 02/10/2018

King IV Application Register

ISO 14001: 2015 Environmental Gap Analysis

UNLOCKING THE WHY, THE HOW AND THE WHO OF POPI

Paperless recorders and 21 CFR part 11 compliance Videographic recorders

NHSLA Risk Management Standards for NHS Trusts Providing Acute Services 2011/12. Milton Keynes Hospital NHS Foundation Trust Level 1

SUNEDISON, INC. AUDIT COMMITTEE CHARTER (Adopted October 29, 2008)

HARROW & HILLINGDON EARLY INTERVENTION SERVICE JAMERSON AND GOODALL DIVISION JOB DESCRIPTION. Clinical Team Leader Harrow & Hillingdon EIS

DATATRAK INTERNATIONAL, INC. AUDIT COMMITTEE CHARTER. (As Adopted on April 20, 2004)

Compensation Committee Charter

VOLUNTARY CODE OF CONDUCT IN RELATION TO EXECUTIVE REMUNERATION CONSULTING IN THE UNITED KINGDOM

6. Cross-Cutting Issues Indicators

COMMUNICATIONS STRATEGY

Quality Manual Revision: C Effective: 03/01/10

Colleges and public authority status under data protection legislation

Changes To the Public Sector Internal Audit Standards April 2017

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

Complaints Handling Policy

JOB DESCRIPTION. Agenda for Change Band 8a equivalent

Information Governance Strategy and Management Framework

ISO/IEC 27001:2005 BASED INFORMATION SECURITY MANAGEMENT SYSTEM INFORMATION SECURITY MANAGEMENT SYSTEM MANUAL

Data Protection Audit Self-assessment toolkit

Harbinger Escrow Services Backup and Archiving Policy. Document version: 2.8. Harbinger Group Pty Limited Delivered on: 18 March 2015

Loch Lomond & The Trossachs National Park Authority. Annual internal audit report Year ended 31 March 2015

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector

ISTA Accreditation Standard for Seed Testing and Seed Sampling

The Committee of Ministers, under the terms of Article 15.b of the Statute of the Council of Europe,

Risk Management Strategy, Policy and Guidance

HUMAN RESOURCES COMMITTEE CHARTER

Government Services BUSINESS PLAN ACCOUNTABILITY STATEMENT THE MINISTRY

Records Management An Introduction

Park Hall Academy FOI Policy & Publication Scheme

QUALITY MANAGEMENT SYSTEM QUALITY MANUAL ISO 9001:2008

Customer Advocacy. Complaints Management Policy

A02 Assessment Rating Guide Revision 2.9 August 21, 2016

CORPORATE GOVERNANCE KING III COMPLIANCE REGISTER 2017

JOB DESCRIPTION. Divisional Director of Operations Jameson

Ewyas Harold Group Parish Council. Freedom of Information Policy

The Audit Committee of the Supervisory Board of CB&I

RELM WIRELESS CORPORATION (the Company ) CODE OF BUSINESS CONDUCT AND ETHICS

Charter of the Audit Committee of the Board of Directors of Novo Nordisk A/S. CVR no

JOB DESCRIPTION. JOB TITLE: Communications Project Manager (STP) PAY BAND: Band 7. DEPARTMENT/DIVISION: Communications

IoD Code of Practice for Directors

Transcription:

Records Management Policy Responsible Officer Author Business Planning & Resources Director Corporate Office Date effective from December 1999 Date last amended December 2015 Review date October 2018 1

Introduction 1 The National Institute for Health and Care Excellence (NICE) is dependent on its records to operate efficiently and account for its actions. This policy defines a structure for the Institute to ensure adequate records are maintained and they are managed and controlled effectively and at best value, commensurate with legal, operational and information needs. Background 2 NICE records are its corporate memory, providing evidence of actions and decisions and representing a vital asset to support daily functions and operations. They support policy formation and managerial decision-making, protect the interests of NICE and its partners, the rights of its staff and members of the public with whom it has dealings. They support consistency, continuity, efficiency and productivity and help NICE deliver its services in consistent and equitable ways. 3 Records are any piece of recorded information, captured and stored in any medium or format. 4 Records management, through the proper control of the content, storage and volume of records, reduces vulnerability to legal challenge or financial loss and promotes best value in terms of human and space resources through greater coordination of information and storage systems. 5 All NICE records are Public Records under the Public Records Acts 1967 and must be kept in accordance with following statutory and NHS guidelines: Public Records Acts 1958 and 1967 Limitation Act 1980 Data Protection Act 1998 Freedom of Information Act 2000 HSC 1999/053 For the Record Audit Commission, Setting the Record Straight, 1995 International Standard on Records Management (ISO 15489) 2

Scope 6 This policy relates to all records held by NICE relating to information created or received in the course of business, and captured in a readable form in any medium, providing evidence of the functions, activities and transactions of the organisation. They include: Administrative records (including personnel, financial and accounting records, contract records, litigation and records associated with complaint-handling) Records in all digital formats Personal data as defined by the Data Protection Act 1998 7 They do not include copies of documents created by other organisations such as the Department of Health, kept for reference and information only. Objectives 8 The seven main objectives of this policy are: - Accountability that adequate records are maintained to account fully and transparently for all actions and decisions in particular: To protect legal and other rights of staff or those affected by those actions To facilitate audit or examination To provide credible and authoritative evidence - Quality that records are complete and accurate and the information they contain is reliable and their authenticity can be guaranteed - Accessibility that records and the information within them can be efficiently retrieved by those with a legitimate right of access, for as long as the records are held by the organisation - Security that records will be secure from unauthorised or inadvertent alteration or erasure, that access and disclosure will be properly controlled and audit trails will track all use and changes. Records will be held in a robust format which remains readable for as long as records are required - Retention and disposal that there are consistent and documented retention and disposal procedures to include provision for permanent reservation of archival records - Training that all staff are made aware of their record-keeping responsibilities through generic and specific training programmes and 3

guidance and where significant new systems are introduced, tailored training programmes are put in place to guide staff through the process of change. - Performance measurement that the application of records management procedures are regularly monitored against agreed indicators and action taken to improve standards as necessary. Standards to be maintained 9 This policy will be implemented by a series of programmes of work which will deliver clear policies, practice and procedures to include: Records creation - Creation of adequate records to document essential activities; - Structured information (content management, version control) to facilitate shared systems based on functional requirements; - Referencing and classification for effective retrieval of accurate information; - Documented guidelines on creation and use of record systems Records maintenance - Assignment of responsibilities to protect records from loss or damage over time; - Access controls to prevent unauthorised access or alteration of records; - Defined security levels for access to records and procedures to amend access authorisations as appropriate when staff move - Tracking systems to control movement/audit use of records; - Identification and safeguarding key or vital records; - Arrangements for business continuity; - Training and guidance Records disposal - Systematic retention and disposal schedules and procedures for consistent and timely disposal; - Central storage systems for records requiring long-term retention to include electronic archiving systems; - Mechanisms for regular transfer of records designated for permanent preservation to appropriate archives Training and guidance - Inclusion of records management functions in job processes where appropriate; 4

- Generic and specific guidance on record-keeping standards and procedures; - Training programmes Performance measurement - Development of effective indicators and review systems to improve records management standards. Responsibilities 10 The Chief Executive has overall responsibility for ensuring that records are managed responsibly within NICE. 11 NICE s Records and Information Manager is responsible for day to day coordination of records management in the organisation, identifying key records and providing guidance and advice on their management and retention. 12 The Senior Management Team is responsible for ensuring that the policy is implemented in their individual teams. They will identify the most suitable person within their teams willing to take on the responsibility to be nominated as departmental representative and who will then liaise with the Records and Information Manager on the management of records in that team. Preservation of records for The National Archives (Public Records Office) 13 As indicated in this policy, all the records produced by the Institute, in any media, are public records and, as such, are subject to the Public Records Act 1958. However, not all public records are worthy of permanent preservation after their administrative usefulness has ended. 14 The National Archives (TNA) has advised NICE that it will accept the record set of NICE Board Papers as well as a selection of any notable, precedent or notorious cases which were considered by the Institute. These records are likely to warrant permanent preservation in The National Archives. This collection policy will, of course, need to be kept under review as the functions of NICE develop in the future. 5