Somebody entitled to ask will ask. Secure Information Management is being able to answer.
An auditor, a regulator, a court, a counterparty, and lately your own AI. The closest established reference frame is ISO 15489-1.
What Secure Information Management actually is
Every organisation runs on recorded information: contracts, invoices, personnel files, drawings, certificates, the approval somebody gave in an email in March. Secure Information Management is being able to say, at any moment, what you hold, why you hold it, who may see it, and how you would prove all three.
It is not a product and it is not a filing system. It is five layers of work, and most organisations already own pieces of three of them, bought separately, which is why the pieces do not join up.
Bought separately, the five produce a capture tool that files into a store nobody governs, a retention policy nobody enforces, and an AI project that stalls on the records underneath it. That is the ordinary shape of an estate assembled one purchase at a time.
The five layers
Five parts of one discipline. Read downwards: this is the route information takes.
Intelligent Document Processing
Anything arriving is read and labelled on the way in, so it comes already described.
Enterprise Content Management
One governed store, reachable from the applications people already work in.
Information Lifecycle Management
Every record has a lifespan set by the obligation behind it, and goes when that ends.
Information Governance Management
The rules and who owns them: what may be reached, by whom, and the record that it was applied.
Information Value Management
What the governed estate returns, measured through what it enables rather than asserted.
The four questions
Everything this discipline does exists to answer one of them. They are asked in this order because each one is unanswerable until the one before it has been settled, which is also the order the work has to be done in.
01What do you hold?
Layers involved: Intelligent Document Processing, Enterprise Content Management
Documents captured, classified and validated at the point they arrive, so a record is described when it enters rather than described later by whoever needs it. One governed store behind that, not five shadow ones assembled by teams who each solved the problem separately.
Until this is settled, nothing below it can be: you cannot apply a retention rule to a record you cannot enumerate, restrict access to a copy you do not know exists, or evidence the handling of either. The visible symptom is small and the cause is not. Every search returns three versions of the same document and no field distinguishes them, so the question of which one is in force is settled by asking a colleague.
02Why do you hold it?
Layers involved: Information Lifecycle Management, Information Governance Management
Every class of information mapped to the obligation that requires it, kept for exactly as long as that obligation runs, and disposed of on schedule with the disposal evidenced and legal hold respected. The rule is applied at capture rather than reconstructed at audit, which is what makes it survive the next reorganisation.
Without it there is one default and it is "keep everything", because deleting is the only action anyone can be blamed for. That is a cost you pay monthly in storage and once, catastrophically, in a breach: the material that should have gone three years ago is still there to be taken, and the disclosure has to cover it.
03Who may see it?
Layers involved: Information Governance Management
Access defined by role against the classification, enforced by policy rather than by whoever last shared a folder, and readable back on demand: this class, these roles, this is who has actually opened it. Rights that change when a person moves rather than accumulating for the length of their career.
The honest answer in most estates is "probably the right people", and that is not an answer, it is a hope with a governance label on it. It fails in two directions at once. Someone who should have access spends a morning requesting it, and someone who should not has held it since a project that ended in 2019.
04Can you prove all of that?
Layers involved: Information Governance Management, Information Value Management
A record behind each of the three answers above: what was held, under which rule, who reached it, when it was destroyed and on whose authority. Produced as a query rather than assembled as a project, because it is a by-product of the system running rather than a report somebody writes afterwards.
This is the question that separates an organisation with governance from one with a governance policy. Without the trail you have well-founded opinions about your own estate and the person asking has a finding, and which of those two carries more weight is decided by the regulator rather than by you.
The newest asker is your own AI
It puts all four questions at once, millions of times, and the most cited recent finding shows what happens when the answers are missing (Nanda et al., 2025): $30-40 bn of investment surveyed; 95% of organisations reported no measurable profit-and-loss return.
The study designates itself preliminary, its sample is small and not randomly drawn, and its methodology has been criticised since publication. Treat it as directional, not as a measurement.
The direction matches what we see. A model cannot be given access to information whose permissions are unknown, retrieval over three versions of a contract returns three answers, and provenance you cannot establish is provenance you cannot defend. The governance work is the part that determines whether the rest functions.
AI operates inside governance, not above it.
Regulatory horizon
Applying
German B2B e-invoicing
Receipt obligation since 1 January 2025. Issuance from 1 January 2027 above 800,000 euros prior-year turnover, from 1 January 2028 for all.
2026 edition
EN 16931
2026 edition approved 13 February 2026, superseding the 2017 edition; migration period running.
From 2030
ViDA, intra-EU B2B
Mandatory e-invoicing from 1 July 2030; domestic systems aligned by 1 January 2035.
Applying
DORA
In force, applying since 17 January 2025.
Partly applying
EU AI Act
Amended by the Digital Omnibus, in force 27 July 2026. Article 50 transparency obligations applied from 2 August 2026; stand-alone high-risk deferred to 2 December 2027, embedded high-risk to 2 August 2028.
In force
GDPR
In force since 2018.
In force
revFADP (Switzerland)
In force since 1 September 2023.
Varies
NIS2
Transposition varies by member state; check per jurisdiction rather than assuming a common date.
Note what most published summaries miss: parts of the AI Act are already applying. Summaries written before July 2026 generally stop at "high-risk deferred", which is now incomplete.
Most engagements begin with one of the five and pull in the others as the picture clarifies. The first conversation is about working out which one you are actually standing in.
Secure Information Management, asked plainly
What is Secure Information Management?
It is being able to say, at any moment, what recorded information you hold, why you hold it, who may see it, and how you would prove all three. It covers contracts, invoices, personnel files, drawings, certificates and correspondence, and it is a records discipline before it is a technology choice.
How is it different from information governance?
Governance is one of its five layers. Secure Information Management is all five together: capture, the governed store, the lifecycle, the governance rules, and the value the estate returns. Governance decides the rules; the other four are what make the rules apply to anything.
Do we have to build all five layers at once?
No, and almost nobody does. Most engagements begin with one of the five and pull in the others as the picture clarifies. What matters is knowing which one you are standing in, because work done in the wrong order has to be redone.
Is this an IT project or a records project?
It is a records discipline with technology consequences, which is why it fails when it is run purely as either. Bought as software it produces tools nobody governs; run purely as policy it produces rules nobody applies.