{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-3067f31619e508f8","slug":"2011-04-01-record-integrity-in-relation-to-digital-records-continuity","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2011-04-01","last_modified_date":"2011-04-01","title":"Record integrity in relation to digital records continuity","summary":"Sets out the scope, decision criteria and evidential basis relevant to record integrity in relation to digital records continuity.","category":{"code":"STANDARDS_INTERPRETATION","label":"Standards Interpretation"},"article_type":"Standards interpretation","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"Information preservation during disruption","reference_authority":"Relevant public authorities and official international sources","sections":[{"heading":null,"paragraphs":["Current consideration of record integrity in relation to digital records continuity is informed by the information preservation during disruption, with consequences for governance, evidence and the treatment of affected learners. For the issue under review, a standard is effective only when its terms lead to consistent decisions without displacing professional judgement or applicable law.","The circumstances described by the information preservation during disruption are developing and may differ materially between locations. Decisions on the stated expectation should therefore be based on verified information available for the affected community and should be reviewed as conditions change. Temporary measures require recorded authority, learner communication and an end or review point; urgency does not remove the need to preserve safety, fair treatment and reliable records.","The system and institutional dimensions of the relevant requirement should be considered together. The analysis of the assurance question proceeds on the basis that education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period. In relation to record integrity in relation to digital records continuity, the allocation of responsibility should prevent gaps between system oversight and institutional operation."]},{"heading":"Applicable scope","paragraphs":["The technical issue within record integrity in relation to digital records continuity concerns the basis on which a conclusion is reached. In reviewing the assurance question, a reliable record should identify what occurred, when it occurred, who was responsible, the authority for the action and any later correction. Records should remain protected against unauthorised alteration while legitimate amendments remain visible. A conclusion should identify both its evidential basis and the part of the stated scope for which assurance cannot be given.","Responsibility for the issue under review should be visible at the point where consequential decisions are made. In reviewing the relevant requirement, a provider should be able to trace the expectation from approved policy through implementation, monitoring, identified exceptions and corrective action. Incomplete evidence, unmanaged conflict, absent learner groups or material learner impact require a higher level of review."]},{"heading":"Implementation and evidence","paragraphs":["The principal risks in relation to record integrity in relation to digital records continuity are collection without a defined educational or legal purpose, retention beyond an identified need, secondary use without adequate authority, and inaccurate data affecting decisions. The risks are interdependent; failure of one control may conceal or disable another. In relation to record integrity in relation to digital records continuity, review should follow the sequence of decisions and records rather than assess documents in isolation."],"bullets":["Assign accountable data owners.","Test incident and recovery arrangements.","Provide accessible correction and complaint routes.","Control third-party processing.","Verify accuracy where information affects learners."]},{"heading":"Assessment of conformity","paragraphs":["Evidence should be selected against a clearly defined question. For record integrity in relation to digital records continuity, the most relevant material is likely to include data-quality and correction controls, a register of information assets and purposes, supplier and transfer arrangements, and role-based access and access reviews. Each source has limitations; confidence depends on corroboration between independent records and transparent treatment of uncertainty.","A proportionate method is available for the stated expectation. For the stated expectation, the reviewer should specify mandatory fields, source ownership, access rights, retention and correction procedures. Test a sample from creation through use, amendment, reporting and disposal, including records created during disruption or by a delivery partner. The review record should preserve exceptions capable of showing a weakness in design, implementation or coverage.","The final record on the assurance question should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. If an alternative method is accepted, the record should demonstrate that it achieves the same required outcome. No complete conclusion should be recorded while a material evidential limitation remains."]},{"heading":"Review and corrective action","paragraphs":["The analysis of record integrity in relation to digital records continuity should remain within the limits of the evidence. The analysis of the relevant requirement proceeds on the basis that the volume of documentation is not a measure of conformity. Relevance, integrity and coverage are more important than the number of records produced. For the issue under review, security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed.","Records relating to the assurance question should preserve both the conclusion and its limits. A changed evidential position should be applied to the affected scope, including prior decisions that may no longer be reliable. The correction process should identify prior users and decisions where published information has had material effect.","For the control, governing bodies should receive a concise account of the intended result, affected scope, principal risks, evidence limitations and unresolved exceptions. Management should assign each material action to an accountable owner and completion date. Evidence of outcome, rather than completion of tasks, should determine whether corrective work can close.","The measure of progress on the assurance question is not the amount of policy or documentation produced."]}],"word_count":824,"content_hash":"sha256-7abdd473f33bb80a9a967a1a0492c1f3510b09bb79669ddc5e5bf5b559975ade","seo_keywords":["record integrity in relation to digital records continuity","education quality standards","education quality","ICEQC"],"schema_type":"TechArticle"}
