Records and Information Management Practitioners Alliance's 2026 Roadshow
Simon Froude
Director-General, National Archives of Australia
Adelaide, SA
2 July 2026
Introduction
Good morning, everyone.
I’m Simon Froude, Director-General of National Archives of Australia.
Thank you to RIMPA, both for the invitation to speak this morning, and for organising today’s roadshow.
I would like to begin by acknowledging the Kaurna people, on whose land we meet today, and by paying my respects to Elders past, present and emerging.
The Kaurna people have cared for, preserved and passed on knowledge of Country for tens of thousands of years, maintaining continuity, accountability and connection over time.
As we talk today about governance, complexity and the stewardship of information, it’s worth recognising that this responsibility – to care for what we hold and to sustain it over time – has deep foundations here on this Country.
That idea of stewardship – of caring for knowledge, maintaining continuity and passing it on with integrity – is something we still grapple with in modern organisations.
The myth of compliance
Compliance is a big word with a heavy burden attached to it – the notion that we must comply or suffer the consequences.
But it is this way of thinking that causes us to fall into any number of traps. We end up ticking the compliance box without asking why or understanding what we are trying to achieve. Compliance for the sake of compliance.
At its core, recordkeeping compliance simply means that our organisations follow the laws and standards for handling records, from creation to disposal.
But how do we view that responsibility?
The light of this lighthouse represents a clear, guiding purpose. It naturally keeps ships – our organisations – on the correct path. The safety of those ships is simply the result of the lighthouse fulfilling its core purpose.
But too often, we treat compliance very differently. We treat it like something we must find – something buried deep within policies, systems and processes.
And in doing so, we turn it into something else entirely: a temple full of traps.
It becomes something to navigate, something to survive, a goal to be achieved, something we hope we’ve cleared without triggering consequences.
But when we focus on the guiding light of our true purpose, we don’t have to survive the traps – or search for the exit. Compliance follows. It becomes the natural result of information that is well managed, visible and trusted.
Today, I’d like to use this time to reframe our role in the compliance sphere.
If there is one message I want you to take away, it is this: when information is governed deliberately and managed with discipline, compliance becomes an outcome, not the thing to strive for.
I will talk about compliance but also about risk and governance and how they are intertwined.
Because of the fear of scrutiny or of possible consequences, compliance becomes the goal. And in doing so, compliance is often treated as a checklist. But checklists don’t tell us whether we are actually prepared to navigate the risks, pressures and scrutiny that we face.
Instead, they give us a false sense of security – the feeling that we’ve mapped the terrain, when in reality we are still walking through it blind. A completed checklist tells us we have a policy or a system, but it says nothing about how effective they are, or whether information can be found, trusted or explained when it matters.
Failures rarely arise from a missing policy. Policy without managed information is aspiration, not governance.
Most major failures don’t begin with an absence of rules – they begin when those rules can’t be operationalised, when they don’t hold under pressure.
The policies may exist, but they are not embedded in daily practice. People don’t know what applies to them or how to apply what they do know.
At the simplest level, they don’t know when to create a record, or where it should be kept, how it should be managed or when it should be disposed of.
Audits and inquiries don’t create failure – they expose it.
And the findings are strikingly consistent. Organisations are unable to produce records in a timely manner, unable to explain why decisions were made, and unable to demonstrate that processes were actually followed.
These failures are generally not about people deliberately doing the wrong thing. They are about fragmented systems, poor metadata, unclear ownership and unmanaged lifecycle controls.
Each one, on its own, feels manageable. But together, they form the traps that organisations fall into.
Risks associated with unmanaged or mismanaged information is the root cause. It emerges when information is not governed as a strategic asset – when it is fragmented across systems, ownership is unclear, retention decisions are inconsistent and context erodes over time.
And the risk is often invisible. It builds quietly, out of sight, until something forces it into view – an audit, an FOI request, litigation or a breach.
And in that moment, what appears to the world as a compliance failure is actually the organisation realising it cannot trust its records or the practices that surround them – it cannot find its way back through the maze.
That is why we need to reframe compliance – not as something we search for, or prove after the fact, but as the outcome of managing information well from the start.
Compliance is not a standalone discipline. It is the result of treating information as a trusted organisational asset through governance, accountability and consistent practices across its lifecycle.
When information is governed with clear responsibilities, findable when needed, reliable and fit for purpose, and managed transparently, compliance largely takes care of itself.
This shifts the question away from a defensive ‘Are we compliant?’ to something far more meaningful: ‘Can we explain how and why decisions were made, can we demonstrate that our information is complete and reliable, and can we defend our actions under audit, inquiry, or scrutiny?’
Because in the end, compliance is not proven by a checklist, a report or an assurance statement.
It is proven by whether an organisation can account for itself – confidently, consistently and credibly.
Information risk: the unseen threat
Most information risk is hidden, or even worse – ignored – until it becomes an enterprise risk.
As practitioners, you’ve all seen information risk in its many forms across the lifecycle – from creation through to retention, disposal and preservation.
It shows up in familiar places: duplicated systems, undocumented decisions and over-retention.
This is where information risk lives day to day – in practice. The issue is not only that it exists – it’s when we allow it to escalate into enterprise‑level risk.
Audit findings continue to reinforce this point. The Australian National Audit Office consistently highlights the importance of government organisations getting the basics right – particularly recordkeeping.
This matters because it reframes recordkeeping. It’s not a back‑office task – it is a core governance control.
The Auditor‑General’s Office and the Australian Public Service Commission are clear that recordkeeping isn’t just procedural – it underpins integrity, accountability and public confidence.
The records we manage are the evidence of decision‑making. When that evidence is incomplete or inconsistent, it doesn’t just create a technical issue – it weakens integrity.
And the consequences go beyond audits.
What audits repeatedly show is a familiar pattern: even where frameworks exist, practice breaks down.
Policies are in place, but the official government record continues to be inconsistent, incomplete or missing.
This is classic information risk.
The problem is not the absence of policy – it’s the practical execution at the records layer.
Compliance doesn’t usually fail loudly. It fails quietly, in small gaps in the practice layer that accumulate over time – until they surface as accountability failures at the governance layer.
The good news is that over the past decade, information risk has increasingly been recognised and included in organisational risk registers.
And that’s important – because once it’s recognised as a risk, it can be actively managed.
The key point here is recognition – seeing information risk for what it is, before it escalates.
Before I move on to the next slide, let’s remember there are 2 sides to the information risk conversation.
On one side, risk is managed through good recordkeeping – records act as governance and assurance controls.
On the other, information management as a practice must be identified and managed like any other enterprise risk.
From reactive to proactive compliance
Once information risk is recognised, the questions become: who owns it, how is it managed, and importantly, why should executives care?
The key point is: information management risk is not an IM problem – it’s an enterprise risk problem.
In reactive organisations, action happens after something goes wrong – after a breach, an audit finding or a failure. Information management then becomes something you fix under pressure.
In proactive organisations, that mindset changes. Information risk is treated the same way as financial, operational or security risk – identified early, owned clearly and managed deliberately.
That shift matters because it changes the conversation. It moves information management out of operational backrooms and into executive decision-making and risk oversight.
In this context, creation, retention, disposal and privacy are not administrative chores – they are risk controls.
So the distinction is simple:
- reactive organisations respond after failures
- proactive organisations manage information risk as part of enterprise risk management
- and mature organisations treat information risk consistently alongside financial and security risks.
National Archives reinforces this through our advice on information management risk.
We position information as central to enterprise risk – both as the evidence that risk is being understood, owned and controlled, and as a risk in its own right – one that when considered properly can combat cyber security issues, data breaches and privacy breaches.
And this is reinforced across the risk landscape, including in the Commonwealth Risk Management Policy, and in ISO and Australian standards for risk management.
The key message here, to take back to your organisation, is this: information risk belongs on risk registers, in board discussions and on executive agendas – not confined within IM teams.
The temple of compliance: common traps
So, what are some of the traps we walk into quietly, every day?
These aren’t always dramatic failures. They’re small, familiar patterns that feel safe at first, but gradually increase risk.
We see this in fragmented systems, where information is spread across platforms with no single source of truth.
We see it in unclear ownership, where everyone touches the information, but no one is accountable for decisions about it.
We see it in ‘just‑in‑case’ retention, where more information than needed is kept, just to feel safe – inadvertently increasing exposure rather than reducing it.
We also see it in disposal avoidance, where destruction is deferred and inaction quietly becomes risk.
And we see it in policy without practice, where governance exists on paper, but daily behaviour drifts elsewhere.
Each of these traps feels manageable in isolation. But together, they increase privacy exposure, FOI burden and reputational risk. And depending on your organisation, they can have real consequences on your customers and on the public that we serve.
Complexity isn’t the danger – gradual slippage is.
One of the biggest challenges that National Archives is currently seeing – and one that fuels many of these traps – is insufficient attention on sentencing and disposal. And this is true of physical and digital records alike. In fact, the problem is heightened when we are dealing with digital.
Large volumes of material that are long overdue for destruction remain in off-site or offline storage, awaiting sentencing decisions.
That’s a lifecycle problem, not just a storage problem. It arises because it is easier to move information off-site or offline, so it’s out of sight and out of mind, rather than tackling the responsibility.
And it means there is heightened risk around privacy and FOI, and in a digital world, around cyber-attacks and data breaches.
After the Optus data breach, many of the conversations were not focused on how the breach occurred, but rather why all of that personal information was retained for so long after it was needed.
It is not all doom and gloom though. Looking through a more positive lens, we are starting to see improvements in practice.
For example, in the federal jurisdiction, some agencies are now using automated approaches to identify information assets and destroy temporary information, reducing both risk and effort. So a technology solution for a technology problem.
But these traps are likely to persist unless we adopt a whole‑of‑lifecycle approach, managing information from creation through to disposal, and unless we address the resource constraints, both human and financial, that undermine consistent, sustainable practice.
Without that, risk and inefficiency simply accumulate out of sight.
Trust is the lynchpin
So, what happens when we fall through the cracks?
When records can’t be found or understood, accountability collapses.
And when accountability collapses, trust is eroded – often long before audits detect a problem.
This is why trust – not compliance – is the lynchpin.
Poor information governance doesn’t just create compliance risk – it quietly undermines trust. And trust, as we all know, is the hardest thing to rebuild.
National Archives’ Building trust in the public record policy is explicit on this point: that effective information management is fundamental to sustaining public trust, particularly in an environment of increasing scrutiny and mis- and dis-information.
Here in South Australia, our friends at State Records have similar policy frameworks.
When trust has been damaged, it isn’t rebuilt through statements of intent. It’s rebuilt through visible, disciplined behaviour over time.
So, what does that look like in practice? What are the signals that trust is being regained?
What you want to see and hear in your organisation are things like this:
- We know what we hold, and we are back in control – trust is rebuilt visibly through consistency.
- Good information management is how we operate, not how we respond to crisis.
- Decisions about information are made deliberately and owned.
- We are shrinking our risk footprint, not normalising it.
These signals matter because they show control, accountability and confidence – not just compliance.
Governance is not a barrier
Not only do we need to send the right trust signals externally, but we also need to send them internally.
That means changing negative perceptions of information management and simplifying what it is actually there to do.
At its core, governance clarifies who decides and why. It makes decisions explainable later, and it protects staff under scrutiny.
Governance doesn’t slow organisations down. It’s what gives us the footing to move faster when conditions change. Governance isn’t the wall – it’s the map.
When governance works well, it acts as a support structure, not an obstacle. Alongside culture and capability, it forms the foundation of good practice – not bureaucratic overhead.
In practice, good governance does 3 simple but critical things:
- it clarifies responsibilities through a legal, regulatory and business lens
- it documents why decisions were made
- and it protects people when scrutiny inevitably arrives.
Without governance, organisations can appear to move faster – right up until they fall into traps they can’t explain their way out of.
That’s why governance matters in information management, and why information management should be seen as a crucial part of an agency’s governance framework.
Not to slow work down, but to make decisions accountable, repeatable and trusted.
Why this matters now
What’s changed over recent years is not our obligations – it’s the scale and speed at which technology, business and user expectations are growing.
Data volumes are growing, and automation, including AI, doesn’t correct poor practice. Instead, it amplifies it.
If you take a bad analogue process and automate it, it is still a bad process.
If information is fragmented, poorly governed or inconsistently managed, automation simply accelerates the problem. Errors move faster. Gaps widen. Exposure increases.
This is why the margin for error is disappearing.
In this environment, the organisations that succeed won’t be the ones with the most tools. They’ll be the ones with the clearest governance, the strongest discipline, and the maturity to manage information deliberately at scale.
Surviving and strengthening the temple
Compliance failures in information management don’t usually begin with bad intent.
They begin with an unmanaged information risk.
Good governance is what enables organisations to survive scrutiny, and to earn trust when it matters most.
Good governance does not eliminate complexity, but it does make it more navigable.
Importantly, information risk is not owned by one role or one team. It’s shared across systems, functions and decisions.
Information management professionals often see risk early. We see fragmentation, drift and weak controls long before those issues surface as audits, breaches or reputational damage.
Our role is not just to manage records. It’s to translate complexity into accountability – to help organisations explain what they did, why they did it, and to stand behind it with confidence.
The real danger isn’t complexity. It’s pretending that information risk is someone else’s problem or accepting that it is no-one’s problem.
When information is governed deliberately, owned collectively and managed with discipline, compliance becomes the outcome, trust becomes sustainable, and the structure holds.
Complexity isn’t going away – if anything, it’s accelerating.
And in that environment, organisations can easily find themselves treating compliance like something to search for – something hidden deep within the temple.
But when the walls start closing in, the problem isn’t that the rules weren’t there. It’s that practice let us down. The record wasn’t created, wasn’t accessible, or was still there when it shouldn’t be.
Because compliance was never the treasure – it’s the result of managing the information we hold well.
And when we get that right, we stop navigating the traps and start building something far more sustainable.
Are we in control?
The simplest way to cut through everything we’ve talked about today is to ask ourselves these 5 questions.
These questions cut to the core of exposure to risk.
- The first question is: Can we find the information we need when it matters? Because if we can’t find it, for all practical purposes, it doesn’t exist.
- Can we trust it? Not just that it’s there – but that it’s complete, accurate and hasn’t lost its context over time.
- Can we explain decisions? Not just what we decided, but why and what information we relied on.
- Can we show who was responsible? Because accountability doesn’t sit in org charts – it sits in records.
- And finally, can we dispose of information with confidence? Not hold onto it ‘just in case’ – but know what should be kept and what shouldn’t.
If any of those answers are unclear – or depend on the system, person or situation – that’s not a future risk. It’s a current one. It just hasn’t been tested yet.
The shift we need to make
And this is the shift we need to make. It’s moving away from compliance as something we search for at the centre of the maze and recognising it as something that emerges from how well we navigate it.
It’s moving away from policy as artefact, to information that gives us a clear line of sight: something complete, reliable and defensible when it matters.
It’s moving away from reacting when the walls close in, to understanding the path ahead and managing information risk before we hit the dead ends.
And most importantly, it’s moving from hidden, unmanaged risk, to something we can clearly see, map and take ownership of.
Because in the end, surviving the temple isn’t about avoiding every trap, or trying to memorise the maze.
It’s about having enough clarity and control to move through it with confidence.
So that when scrutiny comes, we don’t scramble for a way out – instead, we can trace our path, explain our decisions and stand behind them with confidence.
When information is governed deliberately and managed with discipline, compliance takes care of itself.
Thanks for having me here today and thank you for the work that you do.
Media contact
National Archives of Australia Media Team
Phone: 0417 247 157
Email: media@naa.gov.au