SlideShare a Scribd company logo
Standing Up A Holistic
And World Class Information
Governance Program
Rafael Moscatel, CRM, IGP
Managing Director, Compliance & Privacy Partners LLC
www.CAPP-LLC.com
Rafael@capp-llc.com
@Rafael_Moscatel
Agenda
In this session, we’ll cover best practices to build,
execute, and deploy a modern IG program including:
/ How to build and automate your Information
Governance strategy using the right policies,
technology, and stakeholders
/ How to recognize the right collaboration opportunities
and strategically partner on the projects most likely to
support and advance your agenda
/ What approaches to take when introducing your plans
to senior leadership and how to effectively manage
the optics around your contributions to your
company’s bottom line
A holistic approach to IG
LESS IS MORE GAPS ARE OPPORTUNITIES
Help reshape the optics around a problem
by encouraging colleagues to help build a
better future state instead of harping on
old pain points and finger pointing.
RELATIONSHIPS MATTER
Focus on facilitating environments and
spirited organic discussions that support IG
dialogue and help determine consensus.
An effective Information Governance
framework must aim to mitigate risks
related to records retention, legal holds,
privacy and other challenges with clear,
digestible policies and well defined
initiatives.
Less is more
“It is not important to make many pictures, but that I have one picture right.”
-Piet Mondrian
When employees are inundated
with information in both their
professional and personal lives,
less is often a more effective
strategy…
Measured program cadence
ASSESSMENT & PLAN
YEAR 1
BUILD TEAM & EXPERTISE
YEARS 1 -2
YEARS 2-3
POLICY & ASSURANCE
YEARS 2-3
INTEGRATED GOVERNANCE
▪ Analysis and Roadmap
▪ Org Realignment
▪ Roadshows
▪ InfoGov Committee
▪ Compliance Manager
▪ Litigation Support Manager
▪ Records Analysts
▪ Records Coordinators
▪ Retention Policy
▪ Retention Schedule
▪ Privacy Policy
▪ Training and Awareness
▪ Compliance Review
▪ Technology Push
▪ Upgrades & AI
Integration
▪ IT Collaboration
Big buckets
The Big Bucket strategy is leveraged to simplify retention challenges while meeting business,
compliance and legal obligations. Yet new privacy laws are increasing pressure on retention
managers to not only better retain records but also defensibly destroy them.
Field Records
Customer
Records
Common
Records
Finance
Government
& Community
Relations
Human
Resources
Information
Technology
Legal &
Compliance
Marketing Operations Product Sales
Common pitfalls
Third party / cloud software retention: Capabilities are still limited but
don’t lose control over your records
Sticky granularity: Balance regulatory frameworks and obligations with
program priorities, risk appetite and board level expectations
Rushing game: IG isn’t a race, it’s a journey
Indecisiveness: May or may not be your problem (wishy/washy)
Overcommitting: Under promise, over deliver – manage expectations
Develop: a practical roadmap with tangible milestones
Implement: simple and easy to follow policies
Apply: big bucket retention schedules
Is less more?
Gaps are opportunities
“A funny thing happened on the road to Albuquerque.”
After the first World War, a young
GI hopped a train to Boston from
California. In a twist of fate, he was
thrown from the train outside of
Albuquerque.
He never quite made it home, but
he sure did make a fortune…
Discovering opportunities in the EDRM model
Cloud based solutions like Legal Hold Pro from Zapproved provide organizations with an
opportunity to enhance technology and refine best practices.
Legal holds and data preservation software example
✓ Issue litigation holds and custodian questionnaires
✓ Track custodian compliance
✓ Trigger data collection of custodians
✓ Built-in metric tracking/reporting
Why does it matter?
✓ Improves defensibility
✓ Efficient
✓ One system for all team members
Automating legal holds (example)
Common pitfalls
Gathering requirements: Don’t expect software vendors to know your
environment better than your own people
Migrations from hell: Lift and shift, shared drives, SharePoint
Retention event triggers: Consider feasibility, impact to metadata
No silver bullets: Even the most successful implementations need
quality assurance and monitoring
Find: critical compliance or legal processes in need
Identify: a toolset that is efficient and defensible
Market: cost and risk mitigation benefits
Fill the gaps
Relationships matter
A lesson from the 1952 Seattle Chieftains
It’s a shame the Seattle
sportswriter, Jack Gordon, isn’t
around anymore to tell his tale
about those 1952 Chieftains…
Source: documentmedia.com
Who is your IG
strategy leader?
Information Governance programs
enable organizations to leverage their
best minds and resources to make
effective decisions, mitigate significant
risks and protect vital assets. But this
relatively new cross-functional
discipline is built on relationships and
communication.
Know your business partners
INTERNAL AUDIT COMPLIANCE FINANCE / TAX INFORMATION TECHNOLOGY
SERVICE OPERATIONS OFFICE OF THE GC COMMUNICATIONS PROJECT MANAGEMENT
Common pitfalls
Undervaluing: the importance of marketing your
message and change management resources
Underestimating: your organizations aptitude for
understanding key concepts around IG
Build: relationships with IT, risk, legal, compliance
Plant: seeds and be the gardener not the flower
Nurture: the right talent to execute the vision
Value your relationships
CONTACT US TODAY TO LEARN MORE
323-413-7432

More Related Content

PDF
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
PDF
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
PPTX
Evolution of Records Management in Law Firms
PPTX
Moving from passive to active data governance
PDF
PDF
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .
PPTX
Architecting the Framework for Compliance & Risk Management
PPTX
Developing & Deploying Effective Data Governance Framework
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
Evolution of Records Management in Law Firms
Moving from passive to active data governance
A Lawyer, a Salesperson and the Operations Guy Walk into a Bar . . .
Architecting the Framework for Compliance & Risk Management
Developing & Deploying Effective Data Governance Framework

What's hot (20)

PPTX
Cyber fraud and Security - What risks does family office's face in today's wo...
PPTX
Big data governance as a corporate governance imperative
DOCX
Article in Techsmart
PPTX
Understanding Regulation Best Interest
PDF
Data Warehouse - a Fit-For-Purpose Approach
PDF
RSA-Iceberg Seminar: Building an effective supplier risk management program
PDF
What is an IANS Connector Event? - Factor 3
PDF
Why data governance is the new buzz?
PDF
Business impact without data governance
PDF
Profiling bank risk DNA: Bcbs 239 infographic
PPTX
Making Advanced Analytics Work for You
DOC
Longo, Dave MULTIPURPOSE RESUME
PDF
7 critical elements of a data strategy.
PPTX
Data governance
PDF
What is Data Governance?
PPTX
Understanding ROI: The Real Impact of Data Quality
DOCX
Highlights of IBM Analytics Research Report
PPTX
How versus what
PDF
How Should You Manage Data Governance During Coronavirus?
PPTX
3 Executive Strategies to Reduce Your IT Risk
Cyber fraud and Security - What risks does family office's face in today's wo...
Big data governance as a corporate governance imperative
Article in Techsmart
Understanding Regulation Best Interest
Data Warehouse - a Fit-For-Purpose Approach
RSA-Iceberg Seminar: Building an effective supplier risk management program
What is an IANS Connector Event? - Factor 3
Why data governance is the new buzz?
Business impact without data governance
Profiling bank risk DNA: Bcbs 239 infographic
Making Advanced Analytics Work for You
Longo, Dave MULTIPURPOSE RESUME
7 critical elements of a data strategy.
Data governance
What is Data Governance?
Understanding ROI: The Real Impact of Data Quality
Highlights of IBM Analytics Research Report
How versus what
How Should You Manage Data Governance During Coronavirus?
3 Executive Strategies to Reduce Your IT Risk
Ad

Similar to Standing Up A Holistic And World Class Information Governance Program (20)

PDF
Automated Compliance: How to Create an IG Program that Manages Itself
PDF
(eBook PDF) Information Governance: Concepts, Strategies, and Best Practices
PPTX
ACEDS Information Governance Webcast 3-11-15
PDF
The Whole is Greater than the Sum of its Parts with IG
PPTX
ACEDS-Zylab 4-3-15 Webcast
PDF
Return on Investment of Diversity and Inclusion Initiatives in Information Go...
PPTX
Become an Information Governance Superhero in 2015 - Lunch Keynote ARMA Houst...
PDF
Information Lifecycle Governance Leader Reference Guide
PDF
Info Gov and Digital Solutions - Digital Brochure - Overview
PDF
Information Governance – What Does a Modern Program Look Like?
PPTX
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
PPTX
Jim Merrifield - Moving Forward: The Application of Information Governance - ...
PPTX
Moving Forward: The Application of Information Governance
PDF
ACEDS Dallas - Back to School Lessons on the EDRM
DOCX
71 Information Governance Policy Development .docx
DOCX
assign - id = exprid - A B Cexpr - id + .docx
PPT
Mwlug Compliance And E Discovery Policies
DOCX
CHAPTER 8INFORMATION GOVERNANCEInformation Governance & .docx
PDF
Cor concepts information governance-protection-of-personal-information-act-popi
PDF
Information Governance Strategy Powerpoint Presentation Slides
Automated Compliance: How to Create an IG Program that Manages Itself
(eBook PDF) Information Governance: Concepts, Strategies, and Best Practices
ACEDS Information Governance Webcast 3-11-15
The Whole is Greater than the Sum of its Parts with IG
ACEDS-Zylab 4-3-15 Webcast
Return on Investment of Diversity and Inclusion Initiatives in Information Go...
Become an Information Governance Superhero in 2015 - Lunch Keynote ARMA Houst...
Information Lifecycle Governance Leader Reference Guide
Info Gov and Digital Solutions - Digital Brochure - Overview
Information Governance – What Does a Modern Program Look Like?
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Jim Merrifield - Moving Forward: The Application of Information Governance - ...
Moving Forward: The Application of Information Governance
ACEDS Dallas - Back to School Lessons on the EDRM
71 Information Governance Policy Development .docx
assign - id = exprid - A B Cexpr - id + .docx
Mwlug Compliance And E Discovery Policies
CHAPTER 8INFORMATION GOVERNANCEInformation Governance & .docx
Cor concepts information governance-protection-of-personal-information-act-popi
Information Governance Strategy Powerpoint Presentation Slides
Ad

Recently uploaded (20)

PPTX
power of team work; how to develop team work
PPTX
Course Overview of the Course Titled.pptx
PPTX
Principles & Theories of Mgt-Master in PM.pptx
PDF
JOB APPLICATION AND RESUME WRITING IN MANAGEMENT
PPTX
2. CYCLE OF FUNCTIONING RIFLE -PP Presentation..pptx
PDF
CHAPTER 14 Manageement of Nursing Educational Institutions- planing and orga...
PDF
CHAPTER 15- Manageement of Nursing Educational Institutions- Staffing and st...
PPT
Project Management - Scope Management.ppt
PPTX
MY GOLDEN RULES la regla de oro jhonatan requena
PDF
ORGANIZATIONAL communication -concepts and importance._20250806_112132_0000.pdf
PPTX
Self-Awareness and Values Development presentation
PPTX
The Sustainable Site: Boosting Productivity in Construction – Pipe Dream or P...
PDF
CISSP Domain 6: Security Assessment and Testing
PDF
1_Corporate Goverance presentation topic
PDF
Phillips model training for evaluation pdf
PPTX
Improved_Leadership_in_Total_Quality_Lesson.pptx
PDF
CISSP - Domain 7: Security Operations - InfoSec Institute
PPTX
INTELLECTUAL PROPERTY LAW IN UGANDA.pptx
PPTX
Human Resource Management | Introduction,Meaning and Definition
PPTX
_ISO_Presentation_ISO 9001 and 45001.pptx
power of team work; how to develop team work
Course Overview of the Course Titled.pptx
Principles & Theories of Mgt-Master in PM.pptx
JOB APPLICATION AND RESUME WRITING IN MANAGEMENT
2. CYCLE OF FUNCTIONING RIFLE -PP Presentation..pptx
CHAPTER 14 Manageement of Nursing Educational Institutions- planing and orga...
CHAPTER 15- Manageement of Nursing Educational Institutions- Staffing and st...
Project Management - Scope Management.ppt
MY GOLDEN RULES la regla de oro jhonatan requena
ORGANIZATIONAL communication -concepts and importance._20250806_112132_0000.pdf
Self-Awareness and Values Development presentation
The Sustainable Site: Boosting Productivity in Construction – Pipe Dream or P...
CISSP Domain 6: Security Assessment and Testing
1_Corporate Goverance presentation topic
Phillips model training for evaluation pdf
Improved_Leadership_in_Total_Quality_Lesson.pptx
CISSP - Domain 7: Security Operations - InfoSec Institute
INTELLECTUAL PROPERTY LAW IN UGANDA.pptx
Human Resource Management | Introduction,Meaning and Definition
_ISO_Presentation_ISO 9001 and 45001.pptx

Standing Up A Holistic And World Class Information Governance Program

  • 1. Standing Up A Holistic And World Class Information Governance Program Rafael Moscatel, CRM, IGP Managing Director, Compliance & Privacy Partners LLC www.CAPP-LLC.com Rafael@capp-llc.com @Rafael_Moscatel
  • 2. Agenda In this session, we’ll cover best practices to build, execute, and deploy a modern IG program including: / How to build and automate your Information Governance strategy using the right policies, technology, and stakeholders / How to recognize the right collaboration opportunities and strategically partner on the projects most likely to support and advance your agenda / What approaches to take when introducing your plans to senior leadership and how to effectively manage the optics around your contributions to your company’s bottom line
  • 3. A holistic approach to IG LESS IS MORE GAPS ARE OPPORTUNITIES Help reshape the optics around a problem by encouraging colleagues to help build a better future state instead of harping on old pain points and finger pointing. RELATIONSHIPS MATTER Focus on facilitating environments and spirited organic discussions that support IG dialogue and help determine consensus. An effective Information Governance framework must aim to mitigate risks related to records retention, legal holds, privacy and other challenges with clear, digestible policies and well defined initiatives.
  • 4. Less is more “It is not important to make many pictures, but that I have one picture right.” -Piet Mondrian When employees are inundated with information in both their professional and personal lives, less is often a more effective strategy…
  • 5. Measured program cadence ASSESSMENT & PLAN YEAR 1 BUILD TEAM & EXPERTISE YEARS 1 -2 YEARS 2-3 POLICY & ASSURANCE YEARS 2-3 INTEGRATED GOVERNANCE ▪ Analysis and Roadmap ▪ Org Realignment ▪ Roadshows ▪ InfoGov Committee ▪ Compliance Manager ▪ Litigation Support Manager ▪ Records Analysts ▪ Records Coordinators ▪ Retention Policy ▪ Retention Schedule ▪ Privacy Policy ▪ Training and Awareness ▪ Compliance Review ▪ Technology Push ▪ Upgrades & AI Integration ▪ IT Collaboration
  • 6. Big buckets The Big Bucket strategy is leveraged to simplify retention challenges while meeting business, compliance and legal obligations. Yet new privacy laws are increasing pressure on retention managers to not only better retain records but also defensibly destroy them. Field Records Customer Records Common Records Finance Government & Community Relations Human Resources Information Technology Legal & Compliance Marketing Operations Product Sales
  • 7. Common pitfalls Third party / cloud software retention: Capabilities are still limited but don’t lose control over your records Sticky granularity: Balance regulatory frameworks and obligations with program priorities, risk appetite and board level expectations Rushing game: IG isn’t a race, it’s a journey Indecisiveness: May or may not be your problem (wishy/washy) Overcommitting: Under promise, over deliver – manage expectations
  • 8. Develop: a practical roadmap with tangible milestones Implement: simple and easy to follow policies Apply: big bucket retention schedules Is less more?
  • 9. Gaps are opportunities “A funny thing happened on the road to Albuquerque.” After the first World War, a young GI hopped a train to Boston from California. In a twist of fate, he was thrown from the train outside of Albuquerque. He never quite made it home, but he sure did make a fortune…
  • 11. Cloud based solutions like Legal Hold Pro from Zapproved provide organizations with an opportunity to enhance technology and refine best practices. Legal holds and data preservation software example ✓ Issue litigation holds and custodian questionnaires ✓ Track custodian compliance ✓ Trigger data collection of custodians ✓ Built-in metric tracking/reporting Why does it matter? ✓ Improves defensibility ✓ Efficient ✓ One system for all team members Automating legal holds (example)
  • 12. Common pitfalls Gathering requirements: Don’t expect software vendors to know your environment better than your own people Migrations from hell: Lift and shift, shared drives, SharePoint Retention event triggers: Consider feasibility, impact to metadata No silver bullets: Even the most successful implementations need quality assurance and monitoring
  • 13. Find: critical compliance or legal processes in need Identify: a toolset that is efficient and defensible Market: cost and risk mitigation benefits Fill the gaps
  • 14. Relationships matter A lesson from the 1952 Seattle Chieftains It’s a shame the Seattle sportswriter, Jack Gordon, isn’t around anymore to tell his tale about those 1952 Chieftains…
  • 15. Source: documentmedia.com Who is your IG strategy leader? Information Governance programs enable organizations to leverage their best minds and resources to make effective decisions, mitigate significant risks and protect vital assets. But this relatively new cross-functional discipline is built on relationships and communication.
  • 16. Know your business partners INTERNAL AUDIT COMPLIANCE FINANCE / TAX INFORMATION TECHNOLOGY SERVICE OPERATIONS OFFICE OF THE GC COMMUNICATIONS PROJECT MANAGEMENT
  • 17. Common pitfalls Undervaluing: the importance of marketing your message and change management resources Underestimating: your organizations aptitude for understanding key concepts around IG
  • 18. Build: relationships with IT, risk, legal, compliance Plant: seeds and be the gardener not the flower Nurture: the right talent to execute the vision Value your relationships
  • 19. CONTACT US TODAY TO LEARN MORE 323-413-7432