ISO 15489 is the international standard for records management — Information and documentation — Records management. Its current core part, ISO 15489-1:2016 (Concepts and principles), defines what a record is, what makes a record trustworthy, and the policies and processes an organization needs to create, capture, and manage records over time. It is maintained by ISO/TC 46/SC 11, the ISO subcommittee responsible for archives and records management.
For a research institution, ISO 15489 is easy to confuse with the research-data-management standards CASRAI covers elsewhere — data management plans (DMPs), the FAIR principles, the research data lifecycle — because both areas talk about “lifecycle,” “retention,” and “metadata.” They are not the same thing. ISO 15489 governs records: the evidence an institution creates in the course of doing business, including running research — grant applications and award files, IRB/IACUC approvals, financial and effort-reporting documentation, contracts, correspondence, and compliance certifications. Research data management standards govern the datasets and outputs a study produces. A single research project generates both, and they are frequently managed by different offices under different retention rules, but they are governed by different bodies of standards.
What ISO 15489 actually defines
ISO 15489-1:2016 does not prescribe a specific software system or a fixed retention schedule. Instead, it sets out the concepts and principles an organization uses to build its own records program:
- What counts as a record. The standard defines a record as information created, received, and maintained as evidence and as an asset by an organization or person in pursuit of legal obligations or in the transaction of business. Format is irrelevant — a signed paper consent form, a PDF grant agreement, and an email approving a budget revision can all be records if they meet this test.
- Characteristics of an authoritative record. A record should be authentic (it is what it purports to be, created by the person/process it claims), reliable (it can be trusted as a full and accurate representation of the transaction it documents), have integrity (it is complete and unaltered), and be usable (it can be located, retrieved, and interpreted for as long as it is needed).
- Metadata for records. Records need structural and contextual metadata — who created them, when, under what business process, and what has happened to them since — distinct from the descriptive metadata (title, subject, creator) more familiar from research-data cataloguing standards like Dublin Core.
- Records systems and processes. The standard describes the processes a records system needs to support: capture (bringing a record into the system with its metadata intact), classification (organizing records against the business activities that produced them), access and security controls, and disposition.
Retention, appraisal, and disposition
The part of ISO 15489 most relevant to institutional research administration is disposition: the range of processes associated with implementing retention, destruction, or transfer decisions, documented in disposition authorities or retention schedules. The standard’s principle is that retention decisions should be made systematically, through appraisal — evaluating a class of records against legal, regulatory, fiscal, and evidential/historical value — rather than case-by-case at the point someone wants to delete something. An institution’s records retention schedule is the practical artifact this produces: a table mapping record types (grant files, IRB protocols, financial ledgers, HR files) to a minimum retention period and a disposition action once that period ends.
For research administrators specifically, ISO 15489’s appraisal-and-schedule approach has to sit alongside, not replace, funder-specific retention rules. In the United States, 2 CFR §200.334 requires that financial records, supporting documentation, and statistical records related to a federal award be retained for three years from the date the final financial report is submitted (or from a quarterly/annual report date for continuing awards), with that clock extended if litigation, a claim, or an audit begins before the three years expire, or if the federal or pass-through agency notifies the recipient of an extension in writing. Property and equipment records must be kept three years after final disposition. An institutional records-management program built on ISO 15489 principles is what operationalizes rules like this in practice: the retention schedule sets the floor at whatever the strictest applicable requirement is — often the funder’s rule, sometimes a longer institutional or statutory requirement — and the records system enforces it consistently across every award rather than leaving retention to individual PIs’ own filing habits.
How this differs from the research-data standards CASRAI already covers
| Standard / framework | What it governs | Typical owner |
|---|---|---|
| ISO 15489 | Institutional records as evidence of business/administrative activity — award files, approvals, financial documentation, correspondence, compliance certifications | Records/information management office, general counsel, sponsored programs |
| Data Management Plan (DMP) | How a specific project’s research data (not administrative records) will be organized, stored, shared, and preserved | PI, with support from a data steward or curator |
| FAIR Principles | Whether shared research data is Findable, Accessible, Interoperable, and Reusable by others | Data repositories, researchers |
| DCC Curation Lifecycle Model | The stages research data moves through, from conception to reuse | Data stewardship function, research data lifecycle generally |
In practice, a single sponsored project touches both worlds: its data management plan and dataset are governed by the research-data standards above, while the award notice, budget documents, progress reports, IRB approval, and correspondence that accompany that same project are institutional records governed by ISO 15489 concepts as implemented in the institution’s retention schedule. CASRAI’s existing dictionary entry for retention period in a DMP addresses the data-specific commitment a plan makes; ISO 15489 is the broader standard behind the institutional records program that retention commitment often has to align with.
Related standards worth knowing
- ISO 30300 series (Management systems for records) applies management-system principles — similar in structure to ISO 9001 or ISO 27001 — to a records program, giving an organization a framework for continual assessment and improvement of its records management, rather than a one-time policy document.
- ISO 16175 (Processes and functional requirements for software supporting records management) is the companion standard institutions and vendors use when evaluating or building electronic document and records management systems (EDRMS) to actually implement ISO 15489’s principles in software.
- ISO 15489-1:2016 superseded the original 2001 edition, which was itself based on Australian Standard AS 4390 and developed with input from the International Council on Archives (ICA) before being adopted as an ISO standard.
Why this matters for research administrators
Institutional research-records management is not a back-office archiving detail; it is what makes an institution able to answer an audit, a public-records request, a misconduct inquiry, or a sponsor’s post-award review years after a project closed, with documentation that can be trusted as authentic and complete. A records program built on ISO 15489’s concepts — clear classification of research-related record types, appraisal against real legal and funder requirements, a documented retention schedule, and defined disposition once the retention period lapses — is what keeps an institution from either destroying records it was legally required to keep or holding records indefinitely with no defensible reason, both of which carry real risk. Research administrators do not usually own the institution’s records-management program, but grant files, compliance documentation, and effort/financial records that flow through sponsored programs offices are exactly the kind of record class an ISO 15489-aligned retention schedule has to account for.
Frequently asked questions
Is ISO 15489 the same as a data management plan requirement?
No. ISO 15489 governs institutional records — evidence of business and administrative activity such as award files, approvals, and financial documentation. A DMP governs a specific project’s research data. Both can apply to the same sponsored project simultaneously, covering different material.
Is ISO 15489 certifiable, like ISO 9001?
ISO 15489 itself is a guidance standard (concepts and principles), not a certifiable management-system standard. The related ISO 30300 series applies management-system structure (which organizations can be assessed and certified against) to records management specifically.
How does ISO 15489 relate to a university’s records retention schedule?
A retention schedule is the practical output of applying ISO 15489’s appraisal and disposition concepts: it lists record types (grant files, IRB protocols, financial records, and so on) alongside a minimum retention period and disposition action, set at whatever the strictest applicable legal, regulatory, or funder requirement demands.
Does ISO 15489 apply to research data itself?
ISO 15489’s concepts can be applied to any information asset, including datasets, but in practice research data at most institutions is governed instead by data-specific standards and requirements — DMPs, funder data-sharing policies, FAIR, and repository preservation commitments — while ISO 15489-based records programs typically focus on the administrative and evidentiary records surrounding a project rather than the dataset itself.







