Nothing gets deleted, nothing is produced confidently in an audit, and every later programme, from automation to AI, inherits the mess.
What happens to one document, in order
Governance is usually sold as a policy exercise. It is a pipeline: found, classified, acted on, disposed of, with a record at every step.
What "defensible deletion" actually means
Seven steps, and the separation is the point: whoever proposes a deletion does not approve it, and neither of them is the audit.
Proposal raised
An object past its retention is put forward for disposal.
Approval by a named role
Whoever proposes does not approve. The role is named, not a team.
Owner notified
The information owner learns before anything happens, not after.
Confirmed after the notice period
The deletion stands only once the objection window has passed.
Audited before execution
A third pair of eyes checks scope and authority first.
Deletion executed
Only now does anything leave the estate.
Written to an immutable log
The record of the deletion cannot itself be deleted.
What you walk away with
Four deliverables, each of which keeps working after we leave. That is the test they were written against, because a governance programme that stops when the engagement stops has produced documentation rather than governance.
A classified estate
Every information class that carries a legal obligation, a contractual commitment or a real risk, described once and applied across the systems that hold it. Not a five-year attempt to label everything, which is the shape these programmes take when nobody is willing to say what can be left alone.
Scoping is the decision that makes the rest affordable. An estate with fifty classes and a rule for each is maintainable; an estate with a taxonomy nobody can hold in their head is abandoned within two years and quietly replaced by folder names.
A retention schedule that stays alive
Each class mapped to the obligation that requires it and the period that obligation runs, held by somebody with a name and the authority to change it, rather than by the project that wrote it and then closed.
The distinction matters within a year. A schedule with no owner ages out silently: obligations change, the document does not, and the first anyone notices is when a regulator asks why material was kept past its period or destroyed before it.
A deletion process that survives challenge
Proposal, review and execution held by different people, legal hold checked before anything goes, and an immutable record of what was destroyed, under which rule, on whose authority and when.
Separation is what makes it defensible rather than merely done. A process where one person can decide and delete is one nobody will authorise to run at scale, so it does not run, and the estate keeps growing while a policy says it should not.
Standing audit evidence
A continuous report of everything past its retention period and everything disposed of, produced by the system as it runs rather than assembled when a request arrives.
That is the difference between answering an auditor in an afternoon and answering in six weeks. The evidence exists because the work happened, which is also why it holds up when somebody tests it.
In detail
Three parts of this capability have pages of their own, because each is bought and asked about separately:
- Records management, which documents are records and what has to be provable about them
- Data privacy, personal data as a property of the lifecycle rather than a programme beside it
- Regulations, compliance and acts, the obligations that arrive from outside, run as one piece of work
We start by mapping what you are actually obliged to keep and delete, in writing, before anyone proposes a system to do it. That map is the deliverable, and it is usually the first time the obligations have been in one place.
Information governance, asked plainly
What is information governance?
Deciding what must be kept, for how long, who may reach it, and what happens when it should go, then applying those decisions in the systems rather than in a document. The record that the rules were applied is part of the work, not a by-product of it.
Is a retention policy the same as information governance?
No, and the gap between them is where most programmes sit. A policy states the rule. Governance is the rule being enforced by the systems holding the content, so that it still applies to what arrives next month and after the next reorganisation.
Why do automation and AI programmes stall without it?
Both consume records, and a record with no classification, no owner and no retention rule cannot be used safely or reached reliably. The programme then spends its budget rediscovering that, which is why the same clean-up appears in project after project.
Who should own it?
One accountable owner with authority over both the rules and the systems that apply them. Split between legal and IT with neither able to decide, it produces a policy nobody enforces and an estate nobody is allowed to prune.