Skip to content
Singahi

Compliance · guide

ISO 27001 A.5.33: Protection of Records

47 min read

Share
On this page

Quick Reference: A.5.33 in 60 Seconds

AttributeDetail
Control IDA.5.33
TitleProtection of Records
ObjectiveEnsure records are protected from loss, destruction, falsification, unauthorised access, and unauthorised release throughout their lifecycle, in line with legal, regulatory, statutory, and business requirements.
DomainOrganisational controls (A.5)
What You Must DoEstablish and maintain a records protection programme: classify records, define retention and disposal rules, enforce access controls, ensure integrity (WORM/hashing/digital signatures), maintain secure storage, keep chain-of-custody logs, and review against changing legal and business needs.
OwnerCISO / Records Manager / Compliance Officer (with Legal and Department Heads)
Maturity Level 1Ad-hoc records storage; no retention schedule; data kept in personal drives and file cabinets; disposal by deletion/trash.
Maturity Level 2Basic inventory of critical records exists; some retention rules documented; backups performed but not tested; disposal is informal.
Maturity Level 3Formal records protection policy and retention schedule in place; records classified; access controls and backups implemented; secure disposal procedures defined.
Maturity Level 4Automated retention management; WORM / cryptographic integrity protection; role-based access with regular recertification; disposal audited and witnessed; backup restore tested quarterly.
Maturity Level 5Continuous monitoring, predictive analytics for record risks, AI-driven classification, immutable blockchain audit trails, and board-level reporting on records governance.
Audit Red FlagNo records retention schedule; records stored only on local drives; production databases used without masking for historical records; no disposal evidence; unapproved record deletions; inability to retrieve a 3-year-old audit log.
Quick WinCreate a single-page records classification and retention matrix for the top 20 record types, publish it, and assign owners.
Time to Implement4–8 weeks for a basic programme; 12–16 weeks for enterprise-grade records protection with automation.
Related ControlsA.5.1 (Policies), A.5.12 (Classification), A.5.13 (Labelling), A.5.35 (Independent Review), A.5.37 (Documented Operating Procedures), A.8.10 (Information Deletion), A.8.11 (Data Masking), A.8.13 (Information Backup), A.8.16 (Monitoring Activities), A.8.24 (Use of Cryptography)

What the Standard Actually Requires

Figure · Process

What A.5.33 asks you to do

The 7 requirements of ISO 27001 A.5.33, protection of records, in order: establish records management; maintain a records retention schedule; define storage and handling processes; destroy records securely; categorise records; ensure adequate retrieval times; address technology obsolescence.
The 7 things the control expects. Each is expanded in the section below.

ISO 27001:2022 A.5.33 Text

ISO 27001:2022 Annex A 5.33 asks organizations to protect records from loss, destruction, falsification, unauthorized access, and unauthorized release.

ISO 27002:2022 Implementation Guidance (Section 5.33)

ISO 27002:2022 expands A.5.33 into a complete records management framework. The guidance states that organisations should:

  1. Establish records management guidelines that address usability, integrity, authenticity, and reliability of records, supported by topic-specific policies for storage, handling, disposal, and preventing manipulation.
  2. Maintain a records retention schedule specifying how long different record types are kept, linked to their business purpose and legal/regulatory obligations.
  3. Define storage and handling processes that consider prevailing laws for commercial record keeping and societal expectations for responsible information governance.
  4. Destroy records securely as soon as the retention period expires, using methods appropriate to the sensitivity of the information and the media type.
  5. Categorise records according to security risk, retention period, and media type, covering personnel, legal, accounting, and business transaction records.
  6. Ensure adequate retrieval times for records requested internally or by third parties (regulators, auditors, courts).
  7. Address technology obsolescence for electronic records by maintaining cryptographic details, format documentation, and migration plans so records remain recoverable.
  8. Consider media deterioration and follow manufacturer instructions for storing and managing electronic records, including environmental controls and media refresh cycles.

Shall vs. Should Analysis

RequirementWordingInterpretation
ShallThe organization must protect records from loss, destruction, falsification, unauthorized access, and unauthorized releaseMandatory. The organisation must have controls that demonstrably prevent these five risks.
Should"Rules should be established..." / "Records should be categorised..."Strong recommendation. Treat as mandatory for audit purposes unless you can justify an alternative approach.
Must (in ISO 27002 guidance)Retention schedule, secure disposal, retrieval capabilityEffectively mandatory because auditors expect to see these elements as proof of the shall statement.

What Auditors Actually Check

Auditor ActionWhat They Want to See
Review records protection policyDocumented, approved, communicated, and current
Inspect records retention scheduleRecord types, retention periods, legal basis, disposal trigger
Sample physical and electronic recordsClassification labels, storage location, access controls
Verify disposal recordsDestruction logs, certificates of destruction, witness signatures
Check access controlsRBAC, least privilege, recertification, privileged access reviews
Test record retrievalAsk for a specific record from 2–3 years ago and time the retrieval
Verify integrity controlsWORM storage, checksums/hashes, digital signatures, audit logs
Review backup and recoveryBackup schedules, restore tests, off-site/encrypted copies
Interview record owners"Who owns this record?" "How long do you keep it?" "How is it destroyed?"
Check legal and regulatory mappingCitation of IT Act, DPDP Act, RBI, SEBI, Companies Act, tax laws
Review third-party handlingContracts with archiving vendors, cloud storage providers, destruction services
Examine change managementHow records systems are changed without compromising integrity

Why Protection of Records Matters

The Business Risk Narrative

Records are the evidentiary backbone of your organisation. Every invoice, contract, audit log, employee file, customer consent, security incident report, and board resolution is a record that proves what happened, when, and who was responsible. Unlike documents, records are historical evidence, once created, they must not be altered. If records are lost, destroyed, falsified, leaked, or accessed without authorisation, the consequences go far beyond operational inconvenience:

  • Legal and regulatory action: Inability to produce records during litigation, tax assessment, or regulatory inquiry can lead to adverse inference, penalties, or criminal liability.
  • Reputational damage: Customers, investors, and partners lose trust when an organisation cannot account for its own data.
  • Financial loss: Fines, litigation overhead, contract termination, and lost business opportunities can run into crores.
  • Operational paralysis: Without reliable records, business continuity, dispute resolution, and knowledge management break down.

A 2024 study by the Association for Intelligent Information Management (AIIM) found that 47% of organisations have experienced a serious records management failure in the past two years, and 60% of those failures resulted in regulatory, legal, or customer-impact consequences. For Indian organisations, the risk is amplified by overlapping and increasingly stringent regulatory requirements.

Indian Regulatory Context

Indian organisations operate in a layered compliance environment where record protection is not optional:

Regulation / FrameworkRecord-Related RequirementConsequence of Non-Compliance
Digital Personal Data Protection Act, 2023 (DPDP Act)Data fiduciaries must implement reasonable security safeguards, maintain data principal rights records, document consent, and report breaches. Section 8(5) requires deletion of personal data when no longer necessary.Penalties up to for data fiduciary obligations; up to for children's data or breach reporting failures.
IT Act, 2000 (as amended)Section 43A imposes compensation for failure to protect sensitive personal data. Section 67C empowers the government to mandate data retention and preservation.Civil liability, government blocking orders, and criminal penalties for non-compliance with retention directions.
CERT-In Directions, 2022Designated organisations must report specified cyber incidents within 6 hours, maintain ICT asset inventories, user logs, and cyber security records.Non-compliance can lead to blocking of services, prosecution, and reputational damage.
RBI Cyber Security Framework in Banks / NBFCsBoard-approved cyber security policy, incident reporting within 6 hours for serious incidents, independent audit records, transaction logs, and BCP drill records.Monetary penalty, restriction on business, downgrade in ratings, and regulatory restrictions.
SEBI Cybersecurity Circulars (CISI / MIIs)Market infrastructure institutions must maintain cybersecurity records, quarterly reporting, incident logs, and audit trails.Penalties, trading restrictions, and mandatory remedial action.
IRDAI Cyber Security GuidelinesInsurers must maintain records of cyber risk assessments, incident reports, third-party risk assessments, and board reviews.Regulatory censure, fines, and licence implications.
Companies Act, 2013Section 128 mandates books of account and other books and papers be kept in proper manner; Section 221 empowers inspection and seizure. Failure to maintain books can attract penalties and imprisonment.Fines from to and imprisonment up to one year for officers in default.
Income Tax Act, 1961Tax records, invoices, and supporting documents must be retained for specified periods (typically 8 years from the end of the relevant assessment year).Disallowance of expenses, penalties, and prosecution for tax evasion.
GST Act, 2017Records, accounts, and documents must be maintained for 72 months from the due date of filing annual return; electronic records must be authenticated.Penalty up to per instance and cancellation of registration in severe cases.
Prevention of Money Laundering Act, 2002 (PMLA)Records of transactions and client identity must be maintained for 5 years from the date of transaction.Imprisonment up to 5 years and heavy fines for non-maintenance.
Right to Information Act, 2005Public authorities must maintain records in a manner consistent with the RTI Act and publish relevant information proactively.Penalties under Section 20 for destruction of records and disciplinary action.
Factories Act, 1948 / Industrial Employment (Standing Orders) Act, 1946Employers must maintain attendance, wages, leave, and safety records for prescribed periods.Fines and prosecution for failure to maintain statutory registers.
Employee Provident Fund and Miscellaneous Provisions Act, 1952EPF records, contribution statements, and member details must be retained as per EPFO requirements.Penalties and recovery proceedings for non-maintenance.

Specific Retention Periods by Indian Law

Record TypeRetention PeriodLegal Basis
Books of account (companies)Permanent / as prescribedCompanies Act, 2013
Board minutes and resolutionsPermanentCompanies Act, 2013
Annual financial statementsPermanentCompanies Act, 2013
Invoices and bills (GST)72 months from due date of annual returnCGST Act, 2017
Income tax records and supporting documents8 years from end of relevant assessment yearIncome Tax Act, 1961
TDS returns and challans7 yearsIncome Tax Act, 1961
Payroll and salary records7 yearsPayment of Wages Act, 1936; Income Tax Act
Employee provident fund recordsAs long as member is active + thereafterEPF Act, 1952
Gratuity recordsPermanent / 30 years after cessationPayment of Gratuity Act, 1972
Contractual agreementsDuration + 12 years (for simple contract) / limitation periodLimitation Act, 1963
Medical records (hospitals)Outpatient: 3 years; Inpatient: 10 yearsNABH / MCI / Clinical Establishments Act guidelines
Banking transaction logs5 years (varies by record type)RBI Banking Regulation Act, 1949
Cyber incident recordsAs per CERT-In and sectoral requirementsCERT-In Directions, 2022
DPDP consent and rights recordsDuration of processing + prescribed periodDPDP Act, 2023
KYC records (banks / NBFCs)5 years after cessation of relationshipRBI KYC Master Direction

Industry-Specific Consequences

  • Banking and Financial Services: Inability to produce loan documentation, KYC records, or transaction logs can trigger RBI enforcement, customer disputes, and fraud investigations.
  • Healthcare: Loss or tampering of patient medical records violates DPDP Act obligations and can lead to malpractice claims and loss of accreditation.
  • SaaS and Technology: Customer audit logs and consent records are essential for enterprise sales; gaps can block deals and trigger SLA penalties.
  • Manufacturing: IP records, quality control logs, and supplier certifications must be preserved for product liability and export compliance.
  • Government and Public Sector: Citizen service records, grievance records, and audit trails are subject to RTI, CAG audits, and public accountability.

impact of Non-Compliance: Statistics

  • The average impact of a data breach in India reached in 2024 (IBM impact of a Data Breach Report), with regulatory fines and notification overhead rising sharply.
  • DPDP Act penalties can reach **** for failure to implement reasonable security safeguards.
  • Tax and GST disputes where records are missing or incomplete result in disallowance rates exceeding 30% of contested amounts in many cases.
  • Litigation support overhead increase by 40–60% when records are poorly indexed or inaccessible.

Scope and Applicability

What This Control Covers

A.5.33 applies to all records created, received, or maintained by the organisation in the course of business, regardless of form or medium:

  • Digital records: Databases, files, emails, instant messages, audit logs, system logs, configuration files, video recordings, audio files, images, and metadata.
  • Physical records: Paper files, signed contracts, invoices, personnel files, board minutes, cheques, vouchers, and microfilm.
  • Hybrid records: Scanned documents with embedded signatures, printed reports generated from systems, and backup tapes stored off-site.
  • Records held by third parties: Cloud storage providers, archiving vendors, payroll processors, legal counsel, and auditors.

Who It Applies To

Role CategoryResponsibility
Top Management / BoardApprove records protection policy and retention schedule; ensure resources; review compliance.
CISO / Information Security ManagerDesign and oversee technical controls for record integrity, access, and disposal.
Records Manager / Compliance OfficerMaintain retention schedule, coordinate classification, disposal, and audit response.
Legal CounselIdentify legal and regulatory retention obligations; advise on litigation holds.
Department Heads / Record OwnersClassify records in their domain; enforce handling rules; approve disposal.
IT / Cloud AdministratorsImplement access controls, backups, WORM storage, logging, and encryption.
Facilities / AdminSecure physical record storage, manage off-site archives, supervise destruction.
All EmployeesHandle records per policy; report loss or suspected compromise; complete training.

Size-Based Applicability

Organisation SizeFocus Areas
Small (1–50 employees)Focus on financial, tax, HR, and customer records. Use simple cloud storage with versioning, MFA, and a basic retention schedule.
Medium (50–500 employees)Implement a records management policy, classify records into 3–4 levels, define disposal procedures, and use backup plus DLP.
Large (500+ employees)Deploy enterprise content management, automated retention, WORM storage for audit logs, and integration with GRC tools.
Enterprise / RegulatedAdd legal hold workflows, chain-of-custody automation, blockchain/ immutable audit trails, and board-level reporting.

Records That Must Be Protected (Examples)

CategoryExamples
GovernanceBoard minutes, shareholder resolutions, ethics complaints, whistleblower reports
FinancialInvoices, receipts, ledgers, bank statements, GST returns, tax filings, audit reports
HREmployee files, payroll records, background checks, training certificates, exit records
LegalContracts, NDAs, litigation files, IP registrations, trademark records
Customer / SalesOrders, quotations, CRM records, consent forms, complaints, refunds
Information SecurityRisk assessments, audit logs, incident reports, access reviews, penetration test reports
OperationsChange records, backup logs, maintenance records, quality control logs, supplier records
Privacy / DPDPConsent records, data principal requests, breach notifications, DPIA reports
RegulatoryRBI/SEBI/IRDAI filings, CERT-In reports, compliance attestations

Key Definitions and Terminology

TermDefinition
RecordInformation created, received, and maintained as evidence and as an asset by an organisation or person, in pursuit of legal obligations or in the transaction of business.
DocumentA "live" instruction or policy that can be edited. A record is historical evidence that should not be altered.
Retention ScheduleA document specifying how long each record type must be kept, the legal or business justification, and the disposal method.
Disposition / DisposalThe final action taken on records after retention expires, including destruction, transfer to archives, or permanent preservation.
Records LifecycleThe stages through which records pass: creation/receipt, classification, active use, inactive storage, retention, and final disposal.
Chain of CustodyA documented trail that records the sequence of custody, control, transfer, analysis, and disposition of records.
WORM (Write Once Read Many)Storage technology that prevents modification or deletion of data after it is written, used to protect record integrity.
Hashing / ChecksumA cryptographic value computed from record content; any change to the record changes the hash, enabling integrity verification.
Digital SignatureAn electronic signature that provides authentication, integrity, and non-repudiation for digital records.
Legal Hold / Litigation HoldA suspension of normal record disposal for records relevant to actual or anticipated litigation, investigation, or audit.
MetadataData about data, creation date, author, version, classification, retention category, and access history, essential for records management.
AuthenticityThe property that a record is what it purports to be and was created by the person or system it claims.
IntegrityThe property that a record is complete and unaltered since creation or authorised modification.
ReliabilityThe property that a record accurately represents the activity or fact it documents.
UsabilityThe property that a record can be located, retrieved, presented, and interpreted in a timely manner.

Relationship to Other Controls

Upstream Controls (Provide Inputs to A.5.33)

ControlRelationship
A.5.1, Policies for Information SecurityProvides the master policy framework under which the records protection policy sits.
A.5.12, Classification of InformationDefines classification scheme used to categorise records by sensitivity and retention.
A.5.13, Labelling of InformationRequires labels so records can be identified and handled correctly.
A.5.35, Independent Review of Information SecurityProvides audit records that must themselves be protected under A.5.33.
A.5.37, Documented Operating ProceduresProcedures create records (logs, change tickets, incident reports) that need protection.

Downstream Controls (A.5.33 Provides Inputs To)

ControlRelationship
A.8.10, Information DeletionRecords disposal must be secure and irreversible when retention expires.
A.8.11, Data MaskingApplies when production records are used in non-production environments.
A.8.12, Data Leakage PreventionPrevents unauthorised release of records.
A.8.13, Information BackupEnsures records remain available and recoverable.
A.8.16, Monitoring ActivitiesGenerates logs that are records requiring protection.
A.8.24, Use of CryptographyProvides hashing, encryption, and digital signatures for record integrity.

Parallel Controls (Work Together)

ControlRelationship
A.5.15, Access ControlRestricts record access to authorised personnel.
A.5.18, Access RightsEnsures access to records is reviewed and recertified.
A.5.24, Information Security Incident Management PlanningIncident reports are records; A.5.33 ensures they are preserved.
A.6.6, Confidentiality or Non-Disclosure AgreementsEmployees and vendors with record access must be bound by NDAs.
A.8.9, Configuration ManagementConfiguration records must be protected to ensure system integrity.

Detailed Implementation Guidance

Figure · Tiers

Maturity levels for protection of records

  1. RestrictedHighly sensitive information
  2. ConfidentialSensitive business or personal
  3. InternalBusiness information for internal use
  4. PublicInformation that can be freely disclosed
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Establish Governance for Records Protection

Before implementing tools, define who owns records protection and how decisions are made:

  1. Appoint a Records Protection Owner. In most Indian organisations this is the CISO, Compliance Officer, or a dedicated Records Manager. For regulated entities, a Data Protection Officer (DPO) under the DPDP Act also plays a key role.
  2. Form a cross-functional Records Governance Committee with representatives from Legal, IT, HR, Finance, Operations, and Information Security. Meet quarterly.
  3. Publish a Records Protection Policy approved by top management. The policy must mandate the retention schedule, classification, storage, access, integrity, and disposal requirements.
  4. Create a Records Master Index listing all record categories, owners, systems, retention periods, and disposal methods.
  5. Integrate with the ISMS. Records protection must be part of risk assessments, internal audits, and management reviews.

Develop a Records Retention Schedule

The retention schedule is the heart of A.5.33 compliance. It must be:

  • Complete: Cover all record categories across the organisation.
  • Legally grounded: Cite the specific law, regulation, or contract requiring retention.
  • Business justified: When no legal requirement exists, state the business reason.
  • Media aware: Address digital, physical, and hybrid records.
  • Disposal linked: Specify the authorised disposal method for each category.

Example retention schedule excerpt:

Record CategoryExamplesRetention PeriodLegal / Business BasisDisposal Method
Financial ledgerGL entries, trial balance8 yearsIncome Tax Act, 1961Secure erase / shred
Invoices (sales/purchase)GST invoices, credit/debit notes72 months from annual return due dateCGST Act, 2017Secure erase / shred
Payroll recordsSalary slips, PF records, TDS7 yearsIncome Tax Act, 1961; PF ActSecure erase / shred
Employee personnel filesAppointment letters, appraisals, exits7 years after terminationIndustrial Employment Act; DPDP ActSecure erase / shred
Customer contractsMSAs, SOWs, amendmentsDuration + 8 yearsLimitation Act, 1963; contractualSecure erase / shred
Audit logs (security)Login logs, admin actions1–3 yearsISO 27001; CERT-In; RBIWORM / secure erase
Incident reportsSecurity incident records7 yearsRBI/SEBI; businessWORM / secure erase
Board minutesBoard and committee minutesPermanentCompanies Act, 2013Permanent archive
DPDP consent recordsConsent forms, withdrawalsDuration of processing + required periodDPDP Act, 2023Secure erase
Tax returns and filingsITR, TDS returns, GST returns8 years from assessment yearIncome Tax Act; GST ActSecure erase / shred

Classify Records

Use a classification scheme aligned with A.5.12 and A.5.13. For records, classification determines storage, access, encryption, and disposal rigour.

ClassificationDescriptionExamplesHandling Requirements
PublicInformation that can be freely disclosedPress releases, public filingsStandard storage, no special access controls
InternalBusiness information for internal useMemos, internal reportsAccess restricted to employees; standard backups
ConfidentialSensitive business or personal informationFinancial statements, customer data, HR filesEncryption at rest and in transit; role-based access; audit logging
RestrictedHighly sensitive information; unauthorised disclosure causes severe harmBoard minutes, litigation files, security incident details, DPDP special-category dataWORM storage; dual control; encryption; strict need-to-know; witnessed disposal

Protect Record Integrity

Integrity is the assurance that a record has not been altered, corrupted, or tampered with since creation or last authorised modification.

Technical controls for integrity:

  1. WORM Storage: Use WORM-enabled storage for audit logs, financial records, and any record where tamper-proofing is required. Major cloud providers offer WORM/object lock (AWS S3 Object Lock, Azure Immutable Blob Storage, GCP Bucket Lock).
  2. Cryptographic Hashing: Compute SHA-256 hashes for critical records at creation and store hashes separately. Periodically recompute and compare.
  3. Digital Signatures: Apply PKI-based digital signatures to contracts, approvals, and regulatory filings where non-repudiation is required.
  4. Version Control: For records that legitimately have versions (e.g., contract amendments), maintain an immutable version history with audit trail.
  5. Audit Logging: Log every access, modification, copy, move, and deletion of protected records. Logs themselves are records and must be protected.
  6. Time Stamping: Use trusted time sources (NTP with authentication) so record timestamps are reliable and defensible.

Ensure Record Availability and Retrieval

Records must remain usable for as long as they are retained. Availability controls include:

  1. Backup Strategy: Align with A.8.13. Back up records according to criticality: daily for transactional systems, weekly for document repositories, monthly for archives.
  2. Restore Testing: Test backup restoration quarterly for critical records and annually for archives.
  3. Geographic Redundancy: Store copies in multiple availability zones or regions, respecting data localisation requirements under the DPDP Act.
  4. Format and Technology Obsolescence Management: Maintain documentation of file formats, database schemas, encryption keys, and software versions. Plan migrations before formats become obsolete.
  5. Media Refresh: For tapes, optical media, and other degradable media, refresh copies every 3–5 years or per manufacturer guidance.
  6. Search and Indexing: Implement metadata tagging and full-text indexing so records can be retrieved within defined timeframes (e.g., 24 hours for active records, 48 hours for archived records).

Control Access to Records

Access controls for records should be at least as strict as for operational data:

  1. Role-Based Access Control (RBAC): Map roles to record categories. A junior accountant should not access board minutes; a developer should not access HR files.
  2. Least Privilege: Grant minimum access necessary for the job function.
  3. Need-to-Know: Even within a role, access should be justified on a per-record or per-category basis.
  4. Multi-Factor Authentication (MFA): Enforce MFA for all repositories holding Confidential or Restricted records.
  5. Privileged Access Management (PAM): Administrators with access to record storage must use PAM with session recording and approval workflows.
  6. Access Reviews: Recertify access quarterly for Restricted records, semi-annually for Confidential, and annually for Internal.
  7. Logging and Monitoring: Log all record access and generate alerts for anomalous activity (bulk downloads, off-hours access, external sharing).

Secure Storage of Physical Records

Physical records require the same rigour as digital records:

  1. Secure Storage Areas: Use lockable cabinets, access-controlled rooms, and fireproof safes for Restricted records.
  2. Environmental Controls: Maintain appropriate temperature, humidity, and fire suppression for paper and media archives.
  3. Access Logs: Maintain sign-in/sign-out logs for physical files and media.
  4. Transport Security: Use sealed, tamper-evident packaging and tracked courier services for physical records moved off-site.
  5. Off-Site Archives: Use certified records management vendors with contractual security clauses and periodic audit rights.
  6. Media-Specific Handling: Store backup tapes in anti-static cases, away from magnetic fields, and rotate media per manufacturer specifications.

Implement Secure Disposal

Disposal must be secure, irreversible, and auditable:

Digital records:

  • Use cryptographic erasure (erase encryption keys) or secure wipe tools that overwrite data multiple times (e.g., NIST SP 800-88 Clear/Purge/Destroy methods).
  • For cloud records, ensure provider deletion propagates to all replicas, backups, and logs.
  • For SSDs and mobile devices, use vendor-specific secure erase commands.

Physical records:

  • Use cross-cut shredders (DIN P-4 or higher) for Confidential records.
  • Use pulverisation or incineration for Restricted records.
  • Use certified destruction vendors and obtain certificates of destruction.

Disposal workflow:

  1. Retention period expires.
  2. Record owner reviews and approves disposal (unless legal hold applies).
  3. Disposal method selected per classification.
  4. Disposal executed by authorised personnel.
  5. Disposal log updated with date, method, record description, and witness (for Restricted).
  6. Certificate of destruction retained.

A legal hold overrides normal retention and disposal schedules:

  1. Trigger: Litigation, regulatory investigation, audit, or reasonable anticipation of any of these.
  2. Notification: Legal counsel issues a hold notice to record owners and IT.
  3. Suspension: Relevant records are protected from disposal, even if retention expires.
  4. Scope: Hold covers all locations, local drives, email, mobile devices, cloud apps, backups, and physical files.
  5. Monitoring: Track compliance with the hold; document any exceptions.
  6. Release: Disposal resumes only after Legal formally releases the hold.

Address Records in Third-Party Custody

When records are stored or processed by vendors:

  1. Contractual clauses: Require the vendor to protect records per your policy and applicable law.
  2. Right to audit: Include audit rights and incident notification obligations.
  3. Data localisation: Ensure DPDP Act and RBI data localisation requirements are met.
  4. Return and disposal: Define procedures for returning or securely disposing of records at contract end.
  5. Due diligence: Assess vendor security before engagement and periodically thereafter.

Tiered Implementation by Organisation Maturity

MaturityActions
Level 1, InitialCreate emergency inventory of critical records; stop using personal drives for business records; implement basic backups.
Level 2, ManagedDraft retention schedule for top 20 record types; implement MFA on cloud storage; begin secure disposal for paper.
Level 3, DefinedApprove records protection policy; classify all record categories; deploy RBAC; establish disposal logs; integrate with ISMS.
Level 4, QuantitativeAutomated retention workflows; WORM for audit/financial logs; quarterly access recertification; backup restore tests; KPI dashboards.
Level 5, OptimizedAI classification; blockchain/ immutable audit trails; predictive legal hold; board reporting; continuous control monitoring.

Industry-Specific Records Protection Requirements

Records protection requirements vary significantly by industry. The following guidance helps Indian organisations align A.5.33 with sector-specific obligations.

Banking, Financial Services, and Insurance (BFSI)

Record CategorySpecific RequirementControl
Customer KYC recordsRetain for 5 years after account closure; RBI mandates periodic updation and safe storageWORM storage, restricted access, encrypted archives
Transaction logsMaintain detailed audit trails for fraud detection and regulatory reportingImmutable logs, SIEM retention, quarterly review
Loan and credit filesPreserve until repayment + limitation period; support legal recovery actionsDocument management system with legal hold
Cyber incident recordsReport serious incidents to RBI within 6 hours; retain investigation recordsWORM incident repository, chain of custody
Board and committee minutesPermanent retention; support governance and regulatory scrutinyPermanent archive, restricted access

BFSI organisations should map every record category to RBI Master Direction on KYC, RBI Cyber Security Framework, SEBI circulars, IRDAI guidelines, and PMLA obligations. Annual internal audits must verify retention and disposal compliance.

Healthcare and Pharma

Record CategorySpecific RequirementControl
Patient medical recordsOutpatient 3 years, inpatient 10 years; confidentiality under MCI/NABHRestricted access, encryption, access logs
Diagnostic images and reportsLinked to patient records; must remain retrievablePACS with backup, metadata tagging
Clinical trial recordsICH-GCP mandates retention years after trial completionWORM archive, audit trail, sponsor access controls
Drug batch recordsGMP requirements; support recall and pharmacovigilanceImmutable batch records, long-term archive
DPDP consent and health dataConsent records and data principal rights under DPDP ActConsent management system, immutable audit logs

Healthcare providers must balance clinical accessibility with confidentiality. Emergency access procedures should be documented and audited.

SaaS and Technology

Record CategorySpecific RequirementControl
Customer contracts and SLAsDuration + limitation period; support dispute resolutionContract repository, legal hold integration
Audit logs and access recordsEnterprise customers require 1–3 year retention and integrityImmutable log storage, customer-accessible reports
Subprocessor and vendor recordsDPDP Act and customer contracts require vendor accountabilityVendor security assessments, contract clauses
Consent and privacy recordsDPDP Act Section 6 and 8 requirementsConsent management platform, WORM audit trail
Security incident recordsSupport customer audits and regulatory reportingIncident management system, immutable case files

SaaS companies should design records protection into their multi-tenant architecture, ensuring tenant isolation and customer-specific retention rules.

Manufacturing and Industrial

Record CategorySpecific RequirementControl
Quality control recordsISO 9001 and product liability requirementsLong-term archive, tamper-proof storage
Supplier certificationsValidate supplier quality and compliance over timeSupplier record repository, expiry alerts
IP and design filesProtect trade secrets and patent evidenceRestricted access, DLP, watermarking
Environmental and safety recordsFactories Act, environmental clearancesRetention per statute, secure off-site storage
OT/SCADA logsCyber-physical security and incident investigationAir-gapped or segmented log storage

Manufacturers must protect intellectual property records with particular rigour, as these are high-value targets for industrial espionage.

Government and Public Sector

Record CategorySpecific RequirementControl
Citizen service recordsRTI Act and DPDP Act requirementsAccess controls, proactive disclosure logs
Procurement and tender recordsCVC and CAG audit requirementsPermanent archive, integrity protection
Confidential government recordsOfficial Secrets Act and classification rulesPhysical and digital controls per classification
Grievance recordsCitizen charter and accountabilityWorkflow tracking, audit trail

Government organisations must align records protection with the Public Records Act, 1993, and relevant MeitY/NCIIPC directives.


Tools, Technologies, and Solutions

Records Management and ECM Platforms

Vendor / ProductTypeKey FeaturesApproximate licensingBest For
Microsoft Purview Records ManagementCloud-nativeRetention labels, event-based retention, disposition review, legal hold, integration with M365M365-dependent organisations
OpenText Content Suite / DocumentumEnterprise ECMRecords management, workflow, WORM, compliance modulesCustom enterprise licensingLarge enterprises, regulated industries
IBM FileNetEnterprise ECMRecords management, case management, governanceCustom enterprise licensingBanks, insurance, government
M-FilesGrowing-company ECMMetadata-driven, automated workflows, retentionMid-sized Indian companies
Zoho Workdrive / DocsIndian SaaSDocument management, versioning, access controlSMEs, startups
Newgen OmniDocsIndian ECMDocument management, records retention, workflow automationCustom licensingIndian enterprises, BFSI
Veeva VaultLife sciencesValidated records management, eTMF, quality docsCustom licensingPharma, healthcare
SharePoint / Confluence with retention policiesCollaboration platformVersioning, permissions, basic retentionLow incremental overheadSmall and medium organisations

Backup and Archive Solutions

Vendor / ProductTypeKey FeaturesApproximate licensingBest For
Veeam Backup & ReplicationBackupImmutable backups, restore testing, cloud integrationVirtualised environments
Acronis Cyber BackupBackup + cyber protectionImmutable backups, anti-ransomwareSMBs, distributed endpoints
AWS Backup / S3 GlacierCloud backup/archiveVault locks, cross-region copy, lifecycle policiesPay-as-you-goCloud-native organisations
Azure Backup / Archive StorageCloud backup/archiveImmutable storage, long-term retentionPay-as-you-goAzure-centric organisations
Google Cloud Storage / Backup and DRCloud backup/archiveBucket locks, lifecycle, archive tiersPay-as-you-goGCP-centric organisations
CommvaultEnterprise backupData governance, legal hold, e-discoveryCustom enterprise licensingLarge enterprises

WORM and Immutable Storage

SolutionDeploymentNotes
AWS S3 Object LockCloudCompliance or Governance retention modes; legal hold
Azure Immutable Blob StorageCloudTime-based retention and legal hold policies
GCP Bucket LockCloudRetention policies with locked holds
NetApp SnapLockOn-prem / hybridWORM volumes for compliance
Dell EMC Isilon SmartLockOn-prem / hybridEnterprise WORM storage

Data Discovery and Classification

Vendor / ProductTypeBest For
Microsoft Purview Information ProtectionCloud-nativeM365 data classification and labelling
Symantec / Broadcom DLPEnterprise DLPLarge organisations with heterogeneous data
Forcepoint DLPEnterprise DLPRegulated industries
Digital GuardianEndpoint DLPIntellectual property protection
Netwrix AuditorChange and access auditingRecords access logging
Varonis DatAdvantageData governancePermission analysis and access monitoring

Secure Disposal and Destruction Services (India)

Vendor / ServiceCapabilities
Iron Mountain IndiaSecure shredding, media destruction, off-site archiving
** Recall (India)**Document and media destruction, certificates of destruction
Shred-it IndiaOn-site and off-site shredding
Local certified e-waste recyclersHard drive shredding, degaussing, certificate issuance

Open-Source and lightweight Tools

ToolUse Case
sha256sum / md5sumCompute file hashes for integrity verification
VeracryptEncrypt offline record archives
BleachBit / shredSecure file deletion on Linux
DBAN (Darik's Boot and Nuke)Wipe hard drives
CryptomatorEncrypt cloud-stored records

Emerging Technologies for Records Protection

  • AI-Powered Classification: Machine learning models can automatically classify records based on content, reducing manual labelling effort and improving consistency. Tools like Microsoft Purview auto-labelling and third-party AI classifiers are increasingly affordable for growing Indian organisations.
  • Blockchain Audit Trails: For high-integrity requirements (board resolutions, regulatory filings, land records), blockchain or distributed ledger technology can provide tamper-evident timestamping and proof of existence.
  • Federated Search: Unified search across email, SharePoint, databases, and physical archives helps locate records quickly during audits, litigation, or customer requests.
  • Data Loss Prevention (DLP) Integration: Modern DLP tools can enforce records protection policies by blocking unauthorised sharing of classified records via email, cloud apps, or removable media.
  • e-Discovery Platforms: For litigation and regulatory response, e-discovery tools index records across sources and support legal hold, review, and production workflows.

Policy and Procedure Templates

Records Protection Policy (Extract)

RECORDS PROTECTION POLICY
[Organisation Name]
Version: 1.0
Approved by: [CEO / Managing Director]
Date: [Date]
Review Date: [Date + 12 months]
Classification: Internal

1. PURPOSE
This policy establishes the framework for protecting [Organisation Name] records
from loss, destruction, falsification, unauthorised access, and unauthorised release
throughout their lifecycle.

2. SCOPE
This policy applies to all records, in any form or medium, created, received, or
maintained by [Organisation Name], its employees, contractors, and third parties.

3. POLICY STATEMENTS
3.1 All records shall be classified according to the Information Classification Policy.
3.2 A records retention schedule shall be maintained and reviewed annually.
3.3 Records shall be stored securely with access restricted to authorised personnel.
3.4 Confidential and Restricted records shall be encrypted at rest and in transit.
3.5 Critical records (audit logs, financial records, board minutes) shall be stored
      on WORM or otherwise integrity-protected media.
3.6 Records shall be disposed of securely and irreversibly when the retention
      period expires, unless a legal hold is in effect.
3.7 All record disposal shall be logged and, for Restricted records, witnessed.
3.8 Records held by third parties shall be protected by contract and audited.
3.9 Record access, modification, and disposal events shall be logged and monitored.
3.10 Employees shall complete records protection training annually.

4. ROLES AND RESPONSIBILITIES
4.1 CISO / Records Manager: Own the policy, retention schedule, and compliance metrics.
4.2 Legal Counsel: Identify legal and regulatory retention requirements and issue legal holds.
4.3 Department Heads: Classify records in their domain and approve disposals.
4.4 IT: Implement technical controls for storage, access, backup, encryption, and logging.
4.5 All Employees: Handle records per policy and report incidents.

5. COMPLIANCE
Violation of this policy may result in disciplinary action, including termination and
legal proceedings where applicable.

6. REVIEW
This policy is reviewed annually and when significant legal, regulatory, or business
changes occur.

Record Handling Procedure (Extract)

RECORD HANDLING PROCEDURE
[Organisation Name]

1. CREATION / RECEIPT
   • Create records in approved systems or forms.
   • Capture required metadata: title, owner, date, classification, retention category.
   • Do not store business records on personal drives, USB devices, or unapproved cloud services.

2. CLASSIFICATION
   • Apply the classification label at creation: Public, Internal, Confidential, Restricted.
   • For Restricted records, request approval from the record owner and CISO.

3. STORAGE
   • Store records in the designated repository based on classification.
   • Encrypt Confidential and Restricted records at rest.
   • Apply RBAC and MFA to repositories holding Confidential/Restricted records.

4. USE AND SHARING
   • Share records only with authorised recipients using approved channels.
   • External sharing of Restricted records requires encryption and approval.
   • Do not print Restricted records unless approved and physically secured.

5. RETENTION
   • Retain records per the approved retention schedule.
   • Do not delete records before the retention period expires unless authorised.

6. DISPOSAL
   • Review records approaching disposal date.
   • Confirm no legal hold applies.
   • Dispose using the method defined in the retention schedule.
   • Complete the Record Disposal Log.

7. INCIDENT REPORTING
   • Report suspected loss, unauthorised access, or unauthorised disclosure immediately
     to the CISO / Information Security team.

Record Disposal Log Template

Disposal IDRecord CategoryDescriptionRetention ExpiryLegal Hold?MethodExecuted ByWitnessDateCertificate Reference
DSP-001Financial invoicesFY 2017–18 invoices2026-03-31NoCross-cut shredRamesh K.Priya S.2026-04-15CERT-2026-089
DSP-002Security audit logsServer logs Q1 20232026-03-31NoCryptographic eraseIT OpsN/A2026-04-10CERT-2026-090

Risk Assessment and Treatment

Risk Identification

Risk IDRisk DescriptionLikelihoodImpactRisk LevelTreatment
R1Records lost due to hardware failure or ransomware without recoverable backupMediumHighHighImplement immutable backups, test restore quarterly, deploy anti-ransomware controls
R2Records destroyed accidentally or maliciously by insiderLowHighMediumRBAC, privileged access management, audit logging, separation of duties
R3Records falsified or tampered with, undermining audit evidenceLowHighMediumWORM storage, cryptographic hashing, digital signatures, immutable audit logs
R4Unauthorised access to Confidential/Restricted recordsMediumHighHighEncryption, MFA, RBAC, access recertification, DLP, monitoring
R5Unauthorised release of records through email, cloud sharing, or third partyMediumHighHighDLP, data classification, secure sharing policies, vendor controls, training
R6Inability to retrieve records due to obsolete formats or systemsMediumMediumMediumFormat documentation, migration plans, periodic recovery testing
R7Records retained beyond legal requirement, increasing breach exposure and DPDP liabilityMediumMediumMediumEnforce retention schedule, automated disposal workflows, legal hold process
R8Records disposed of prematurely, violating legal hold or retention obligationLowHighMediumApproval workflow, legal hold integration, disposal logs
R9Physical records damaged by fire, flood, or environmental failureLowHighMediumFireproof safes, off-site archives, environmental monitoring, insurance
R10Third-party vendor loses or leaks recordsMediumHighHighContractual security clauses, due diligence, audits, breach notification

Risk Treatment Plan

Risk IDTreatment OptionControl OwnerTarget Date
R1MitigateIT DirectorQ1
R2MitigateCISOQ1
R3MitigateCISOQ2
R4MitigateCISOQ1
R5MitigateCISO + DPOQ1
R6MitigateRecords ManagerQ2
R7MitigateCompliance OfficerQ2
R8MitigateLegal CounselQ2
R9MitigateFacilities ManagerQ2
R10Mitigate + Transfer (insurance)Procurement + LegalQ2

Audit and Compliance Checklist

Auditor Questions and Expected Evidence

#Auditor QuestionExpected EvidenceRed Flag
1Show me your records protection policy.Approved policy, version history, communication recordsNo policy or outdated policy
2Do you have a records retention schedule?Retention schedule with legal citationsNo schedule or generic schedule
3How do you classify records?Classification scheme, labelled records, training recordsNo classification or inconsistent labels
4How do you protect records from unauthorised access?RBAC matrix, MFA evidence, access reviewsOpen access, shared accounts
5How do you prevent record falsification?WORM config, hashing/digital signature evidence, audit logsNo integrity controls
6Can you retrieve a record from 3 years ago?Live retrieval demonstration, retrieval time logCannot retrieve within defined SLA
7How are records backed up and recovered?Backup policy, restore test records, backup logsNo restore testing
8How do you dispose of records?Disposal logs, certificates of destructionNo disposal evidence
9How do you handle legal holds?Legal hold procedure, hold notices, release recordsNo legal hold process
10How do you manage third-party records?Contracts, due diligence reports, audit rightsNo contractual controls
11How do you ensure DPDP Act compliance for personal data records?Consent logs, data principal request records, breach logsMissing consent or breach records
12How do you protect audit logs?WORM/ immutable log storage, log review recordsLogs stored on editable systems
13Show me records access logs.SIEM / repository access logsNo logging or unreviewed logs
14How do you manage records on employee laptops or personal devices?MDM policy, encryption evidence, remote wipeRecords on unencrypted personal drives
15How do you manage physical records?Physical access logs, storage inspection, disposal certificatesUnsecured paper records
16How do you address technology obsolescence?Migration plan, format inventory, recovery test recordsNo plan for obsolete formats
17How do you train staff on records protection?Training records, quiz results, awareness materialsNo training
18How do you review records protection effectiveness?Internal audit reports, KPI dashboards, management review minutesNo review cycle
19Show me disposal approval workflow.Approval emails/tickets, disposal logsDisposal without approval
20How do you protect records during disruption?BCP/DR plan, backup restore tests, alternate site recordsNo DR plan for records

Metrics and KPIs

Figure · Measures

The measures that show A.5.33 is working

  • Records with defined retention period100%Quarterly
  • Records classified100%Quarterly
  • Records access recertification completion100%Quarterly
  • Backup restore success rate100%Quarterly
  • Disposal compliance100%Monthly
Targets and reporting cadence as defined in the table below, where the formula for each is given.
#KPIFormulaTargetFrequency
1Records with defined retention period(Records with retention category / Total records inventory) × 100100%Quarterly
2Records classified(Classified records / Total records) × 100100%Quarterly
3Records access recertification completion(Recertified access / Total access grants) × 100100%Quarterly
4Backup restore success rate(Successful restore tests / Total restore tests) × 100100%Quarterly
5Disposal compliance(Disposals with approved log / Total disposals) × 100100%Monthly
6Records retrieval SLA achievement(Retrievals within SLA / Total retrieval requests) × 100> 95%Monthly
7Records-related incidentsCount of loss, unauthorised access, or release incidents0Monthly
8Records protection training completion(Trained staff / Total staff) × 100100%Annually
9Retention schedule review currencyDays since last retention schedule review< 365 daysAnnually
10Legal hold compliance(Holds acknowledged and enforced / Total active holds) × 100100%Per hold
11Third-party record audit completion(Vendors audited / High-risk vendors) × 100100%Annually
12Integrity check success rate(Records passing hash/integrity check / Total checked) × 100100%Quarterly
13Records stored outside approved repositoriesCount of records on personal drives / shadow IT0Quarterly
14Average record retrieval timeTotal retrieval time / Number of retrieval requests< 24 hours (active), < 48 hours (archive)Monthly
15impact of records management per recordTotal records management overhead / Number of recordsTrend downAnnually

Common Pitfalls / Audit Failures & How to Avoid Them

#Pitfall / FindingCauseFixTimeline
1No records retention scheduleRecords management seen as "filing"Create retention schedule with Legal input; board approve4–6 weeks
2Retention periods not legally groundedSchedule copied from internet without Indian contextMap each category to Indian law and business need2–4 weeks
3Records stored on personal drives / shadow ITLack of central repository and governanceDeploy approved DMS; migrate records; enforce policy8–12 weeks
4No disposal logs or certificatesInformal shredding/deletionImplement disposal workflow and log template2–4 weeks
5Audit logs not protectedLogs treated as operational data, not recordsMove logs to WORM/immutable storage4–6 weeks
6Inability to retrieve old recordsObsolete formats, lost indexes, no backupsCreate format inventory; migrate; test restore8–12 weeks
7Over-retention increasing riskFear of deleting anythingEnforce retention schedule with automated disposition4–8 weeks
8Premature deletion under legal holdLegal not consulted before disposalIntegrate legal hold flag into disposal workflow2–4 weeks
9Weak physical record securityPaper records left unattendedSecure cabinets, access logs, clean desk policy2–4 weeks
10Third-party records not governedAssumption that cloud provider handles everythingAdd contract clauses; conduct vendor audits4–8 weeks
11No integrity checks for critical recordsBelief that storage replication equals integrityImplement hashing/WORM for audit/financial records4–6 weeks
12Records protection not in risk assessmentsISMS treats records as an afterthoughtInclude records in risk register and internal audits2–4 weeks

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Mumbai NBFC, Ransomware Exposes Backup Gap

Background: A mid-sized Non-Banking Financial Company (NBFC) in Mumbai with 400 employees held customer loan records, KYC documents, and transaction logs on on-premise servers and network-attached storage. The company had backups but had never tested restoration.

The Incident: In October 2024, a ransomware attack encrypted the primary file server and spread to the backup server because both were on the same network segment. The attackers demanded . The NBFC discovered that their "daily backups" had been failing silently for six weeks and that no immutable backup copies existed.

Impact:

  • Customer records for the past six weeks were unrecoverable.
  • RBI was notified under the 6-hour serious incident reporting rule.
  • The NBFC had to reconstruct transaction data from email trails and partner statements, and 3 months of effort.
  • RBI issued a supervisory letter citing inadequate records protection and backup controls.

Root Cause Analysis:

  1. Backups were not segregated from production networks.
  2. No immutable or air-gapped backup strategy.
  3. Backup restore testing was not performed.
  4. Records protection was not part of the ISMS risk assessment.
  5. No WORM or integrity protection for critical financial records.

Remediation with Singahi:

  • Week 1–2: Incident response and containment; rebuilt servers from last known good backup.
  • Week 3–4: Deployed immutable backup solution (Veeam with S3 Object Lock) and segregated backup network.
  • Week 5–8: Created records retention schedule aligned with RBI, Companies Act, and Income Tax Act requirements.
  • Week 9–12: Implemented WORM storage for audit logs and transaction records; configured quarterly restore testing.
  • Ongoing: Added records protection to internal audit scope and management review agenda.

Results:

  • Zero unrecoverable record loss in a subsequent simulated ransomware exercise.
  • RBI follow-up inspection passed with no major findings.
  • Backup restore RTO reduced from "unknown" to 4 hours.
  • Records retrieval SLA improved from days to under 4 hours.

Background: A 250-employee SaaS company in Bengaluru provided HR-tech software to Indian enterprises. After the DPDP Act, 2023 came into force, the company needed to demonstrate consent, data principal rights, and breach records to customers and regulators. However, consent records were scattered across CRM, email, and spreadsheet exports.

The Incident: During an enterprise customer audit in January 2025, the company failed to produce a complete audit trail of consent for 12,000 employee records processed on behalf of a client. Consent forms existed but were not version-controlled, some were missing, and withdrawal requests were tracked in personal inboxes. The customer suspended a contract renewal pending remediation.

Impact:

  • Contract renewal delayed by 6 months.
  • DPDP Act compliance gap identified.
  • Potential penalty exposure under Section 8(5) and Section 12 of the DPDP Act.
  • Engineering resources diverted for 4 months to rebuild consent infrastructure.

Root Cause Analysis:

  1. No records protection policy for personal data records.
  2. Consent records were not classified as Restricted records.
  3. No WORM or immutable storage for consent and rights-request logs.
  4. Disposal of old consent records was uncontrolled.
  5. No integration between marketing consent tools and the central records repository.

Remediation with Singahi:

  • Week 1–2: Declared consent records, data principal request records, and breach logs as Restricted records under the Records Protection Policy.
  • Week 3–6: Migrated consent and rights records into a centralised, immutable repository with WORM locks.
  • Week 7–10: Built automated workflows for consent capture, withdrawal, and deletion requests with full audit trail.
  • Week 11–12: Trained customer success, legal, and engineering teams on DPDP record-keeping requirements.
  • Ongoing: Quarterly internal audits of consent record completeness and integrity.

Results:

  • Contract renewal secured with added security commitments.
  • DPDP Act readiness assessment passed.
  • Consent record retrieval time reduced from days to under 30 minutes.
  • No consent-related findings in subsequent ISO 27001 surveillance audit.

Illustrative Scenario 3: Delhi Manufacturing Company, Physical Records Fire and Compliance Penalty

Background: A 600-employee automotive component manufacturer in Delhi maintained a mix of digital ERP records and physical quality control sheets, supplier certifications, and environmental compliance files. Physical records were stored in a basement archive with minimal fire protection and no inventory system.

The Incident: In November 2024, an electrical short circuit caused a fire in the basement archive. Approximately 40% of physical records from the past 8 years were destroyed, including ISO/TS 16949 quality records, supplier audit reports, and environmental audit evidence required by the State Pollution Control Board.

Impact:

  • ISO 9001 and IATF 16949 surveillance audit was suspended pending reconstruction of quality records.
  • A major OEM customer placed the company on probation, threatening a annual contract.
  • The State Pollution Control Board issued a show-cause notice for inability to produce environmental compliance records.
  • Insurance claim was partially denied due to lack of inventory and off-site backup of critical records.
  • Estimated direct and indirect overhead exceeded .

Root Cause Analysis:

  1. No physical records inventory or classification.
  2. No fire suppression, environmental monitoring, or off-site backup for physical records.
  3. Critical records existed only in paper form with no digitisation.
  4. No business impact analysis for records storage.
  5. No periodic review of physical record protection by the ISMS.

Remediation with Singahi:

  • Week 1–2: Emergency salvage and documentation of surviving records; notified insurers, customers, and regulators.
  • Week 3–6: Digitised active quality and environmental records using scanning and OCR; implemented document management system with metadata tagging.
  • Week 7–10: Established fire-resistant archive room, off-site storage with certified vendor, and environmental monitoring.
  • Week 11–14: Rebuilt retention schedule for manufacturing records aligned with ISO 9001, IATF 16949, and environmental laws.
  • Ongoing: Quarterly physical archive inspections and annual fire drill for records storage areas.

Results:

  • ISO surveillance audit completed 5 months later with only minor observations.
  • OEM customer lifted probation after demonstrating digitised records and off-site backup.
  • Pollution Control Board accepted the reconstructed records with an improvement plan.
  • Insurance premium reduced in the following year after demonstrating improved controls.
  • Physical record retrieval time reduced from days to under 2 hours.

Multi-Framework Mapping

ISO 27001:2022SOC 2 Type IIPCI DSS 4.0NIST 800-53 Rev 5CIS Controls v8COBIT 2019GDPR / DPDP Act 2023
A.5.33CC6.1, CC7.23.4.1, 3.5.1, 9.4.5, 12.3.3MP-2, MP-3, MP-4, MP-6, SI-12Control 3, Data ProtectionAPO11.02, APO11.03, APO11.04, APO12.01, BAI09.01GDPR Art. 5(1)(e), Art. 17, Art. 30; DPDP Act Section 8(5), Section 12
A.5.12CC6.13.2.1RA-2Control 3APO12.02GDPR Art. 5; DPDP Act Section 6
A.5.35CC4.1, CC4.212.4.2CA-2, CA-7Control 7MEA01.01GDPR Art. 32; DPDP Act Section 8(5)
A.8.10CC6.13.2.2, 3.3.1MP-6, SI-12Control 3BAI09.03GDPR Art. 17; DPDP Act Section 8(5)(a)
A.8.11CC6.13.4.1, 3.5.1SI-12, SC-28Control 3BAI02.01GDPR Art. 32; DPDP Act Section 8(5)
A.8.13A1.212.3.1, 12.3.2CP-9, CP-10Control 11BAI09.01GDPR Art. 32; DPDP Act Section 8(5)
A.8.16CC7.210.2.1, 10.3.1AU-6, AU-12Control 8MEA01.04GDPR Art. 32; DPDP Act Section 8(5)
A.8.24CC6.1, CC6.6, CC6.73.5.1, 4.2.1SC-13, SC-28Control 3BAI02.01GDPR Art. 32; DPDP Act Section 8(5)

Implementation Roadmap

Figure · Matrix

Comparison: Phase 1: Foundation to Phase 3: Validate

DaysFocus
Phase 1: Foundation1–30Policy, retention schedule
Phase 2: Embed31–60Disposal workflow
Phase 3: Validate61–90Restore tests, retrieval
Condensed from the table below, which carries the full detail for each cell.

Figure · Timeline

Rollout in order

  1. Phase 1: Foun…1–30
  2. Phase 2: Embed31–60
  3. Phase 3: Vali…61–90
Milestones in delivery order. Owners and the evidence each produces are in the table below.

12-Week Implementation Roadmap

WeekPhaseActivitiesDeliverable
1DiscoveryInventory record types and storage locations; identify legal/regulatory requirements; appoint Records Protection Owner.Records inventory v1.0
2GovernanceDraft Records Protection Policy; form Records Governance Committee; define classification scheme.Policy draft, committee charter
3–4Retention ScheduleDevelop retention schedule with Legal; map to Indian laws and business needs; get management approval.Approved retention schedule
5–6Technical ControlsImplement RBAC, MFA, encryption, backups, WORM for critical logs; migrate records to approved repositories.Technical controls deployed
7–8Disposal and Legal HoldCreate disposal workflow, disposal log, and legal hold procedure; train record owners.Disposal process operational
9–10Third-Party and PhysicalReview vendor contracts; secure physical storage; implement off-site archive controls.Vendor controls, physical security improvements
11Testing and TrainingConduct backup restore test; run records retrieval drill; deliver staff training.Test reports, training completion records
12Review and AuditInternal audit of records protection; update risk register; present to management review.Audit report, management review minutes

90-Day Sprint for Regulated Organisations

PhaseDaysFocus
Phase 1: Foundation1–30Policy, retention schedule, inventory, classification, critical records WORM
Phase 2: Embed31–60Disposal workflow, legal holds, third-party controls, physical security
Phase 3: Validate61–90Restore tests, retrieval drills, internal audit, KPI dashboard, management review

FAQ

What is the difference between a document and a record?

A document provides instructions and can be updated (e.g., a policy). A record is historical evidence of an activity and should not be altered after creation (e.g., an audit report, signed contract, or incident log). A.5.33 protects records; A.5.1 protects policies and documents.

Is a records retention schedule mandatory for ISO 27001?

Yes. A.5.33 and ISO 27002:2022 explicitly require a retention schedule that specifies how long records are kept and the basis for retention. Auditors will ask for it.

How long should we keep security audit logs?

The retention period depends on your legal and regulatory environment. In India, RBI/SEBI regulated entities often retain security logs for 1–3 years. CERT-In directions and the DPDP Act also support retention for investigation purposes. Define the period in your retention schedule.

Do we need WORM storage for all records?

No. WORM or immutable storage is typically required for high-integrity records such as audit logs, financial transaction records, board minutes, incident reports, and DPDP consent records. Other records may use standard access controls and backups.

How do we handle records on employee laptops?

Business records should not be stored solely on employee laptops. Use a centralised document management system with MFA, encryption, and remote wipe capability. If local copies are necessary, encrypt the device and synchronise to the approved repository.

A legal hold suspends normal record disposal when litigation, investigation, or audit is anticipated or active. It is issued by Legal Counsel and remains in effect until formally released. Failing to implement a hold can lead to sanctions and penalties.

How do we protect records stored in the cloud?

Use cloud providers with appropriate certifications (ISO 27001, SOC 2). Enable encryption at rest and in transit, MFA, RBAC, immutable backups, and audit logging. Include records protection clauses in contracts and exercise audit rights.

What disposal method is acceptable for physical records?

Confidential paper records should be cross-cut shredded (DIN P-4 or higher). Restricted records should be pulverised or incinerated. Use certified destruction vendors and obtain certificates of destruction.

How does the DPDP Act, 2023 affect records protection?

The DPDP Act requires data fiduciaries to protect personal data, maintain consent records, honour data principal rights, report breaches, and delete data when no longer necessary. These obligations directly map to A.5.33 controls for retention, integrity, access, and disposal.

How often should we review the records protection programme?

Review the policy and retention schedule annually at minimum. Also review after significant legal/regulatory changes, major incidents, mergers/acquisitions, new technology adoption, or audit findings.

Do backup copies also need to follow the retention schedule?

Yes. Backups are records too. Define backup retention periods in the schedule and ensure that backups are disposed of securely when retention expires. For regulatory or audit purposes, you may need to retain certain backup copies even after original production records are deleted.

Can we keep all records forever "just to be safe"?

No. Over-retention increases breach risk, storage overhead, and DPDP Act liability. The DPDP Act requires that personal data not be retained longer than necessary. Keep records only as long as legally or business required, then dispose securely.

How do we protect records in email and chat applications?

Email and chat records should be subject to the same classification and retention rules. Use archiving solutions (e.g., Microsoft Purview, Google Vault, Zoho Mail archival) with retention policies, e-discovery capabilities, and access controls. Prohibit use of personal email for business records.

What is event-based retention?

Event-based retention starts the retention clock from a specific event rather than creation date. For example, employee records may be retained for 7 years from the date of termination, not from the date of creation. This requires tracking the triggering event accurately.

How do we handle records in foreign jurisdictions?

If your organisation operates globally, you may need to maintain records in specific jurisdictions to comply with data localisation laws. In India, the DPDP Act and RBI requirements may restrict cross-border transfers of certain records. Maintain local copies where required and document the legal basis for transfer.

What should a records disposal log contain?

A disposal log should include: disposal ID, record category, description, retention expiry date, legal hold status, disposal method, person who executed disposal, witness (for Restricted records), date, and certificate of destruction reference.

How do we prove record integrity to an auditor?

Provide evidence of WORM configuration, cryptographic hashes, digital signatures, immutable audit logs, access control matrices, and backup restore test results. Demonstrate that critical records cannot be altered or deleted without authorisation and detection.

Are system-generated logs considered records under A.5.33?

Yes. System logs, audit logs, access logs, and security event logs are records. They often require special protection because they provide evidence of system activity and security incidents. Treat them as Confidential or Restricted depending on content.

How does records protection support business continuity?

By ensuring records are backed up, recoverable, and stored in multiple locations, records protection supports rapid recovery from disasters, ransomware, and system failures. It also ensures that critical evidence remains available during investigations and disputes.


References and Further Reading

Standards and Frameworks

  • ISO/IEC 27001:2022, Annex A 5.33, Protection of Records
  • ISO/IEC 27002:2022, Section 5.33, Protection of Records
  • ISO 15489-1:2016, Information and documentation, Records management
  • ISO 23081, Information and documentation, Metadata for records
  • NIST SP 800-88 Rev 1, Guidelines for Media Sanitization
  • NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organisations

Indian Regulations

  • Digital Personal Data Protection Act, 2023
  • Information Technology Act, 2000 (as amended)
  • CERT-In Directions, 2022
  • Reserve Bank of India, Cyber Security Framework in Banks, Master Direction on IT Framework for NBFCs
  • Securities and Exchange Board of India, Cyber Security and Cyber Resilience Framework
  • Insurance Regulatory and Development Authority of India, Cyber Security Guidelines
  • Companies Act, 2013
  • Income Tax Act, 1961
  • Central Goods and Services Tax Act, 2017
  • Prevention of Money Laundering Act, 2002
  • Right to Information Act, 2005

Industry Guidance

  • Association for Intelligent Information Management (AIIM), Records Management Best Practices
  • International Council on Archives, Records Management Principles
  • Indian Institute of Banking and Finance, Cyber Security Guidelines for Banks

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.