Thoughts on Information Management
What we see
This may or may not be reassuring, but in our experience in the 250 municipalities across Canada that we have worked with, most struggle with Information Management.
It’s a difficult area to master in all sectors and every time I meet an IM expert I probe to find out who is doing this well in the private or public sector. I will be honest, I never got a satisfactory answer. No one, as far as I can see, is doing this really well.
Of course, municipalities are inherently complex. They rarely operate as a single cohesive organization they are dozens of separate business units operating somewhat independently. This makes achieving consistent Information and Data Management practices incredibly difficult to achieve.
Further compounding the challenge is that Information Management responsibilities and accountabilities in a municipality rarely sit with any one owner. Of course, the arrangement varies from organization to organization, but a common pattern that we observe is that Clerks may drive IM policy, FOI, and privacy compliance, records and document management, retention, paper record management processes, Council documents, and archives. IT commonly manages storage, backups, structured databases, collaboration, M365 and cybersecurity. Business solutions management may be managed by IT but may also be somewhat distributed as more services move to the cloud. While departments manage processes and procedures in various digital and non-digital ways and managers and staff want to keep “stuff” forever, “just in case”.
While everybody has opinions, there may be turf wars, or buck passing. No one is happy and there is no clear ownership or leadership.
It doesn’t help that municipal departments are extremely busy … and records management compliance is simply not high on their list of day-to-day priorities.
At the same time, the number of systems keeps growing. Data as a strategy sits all over the organization, often rarely owned by anyone. GIS, business intelligence, and a range of other tools each hold their own slice of the organization’s information. And everyone is coming at the expectations from a different direction.
Microsoft 365 lands right in the middle of all of it. Too often SharePoint, Teams and OneDrive have been layered on top of existing systems with limited guidance, making document and records management more complex and confusing – not less.
And now AI adds a whole new set of pressures on top. AI Tools can only work as well as the structures and controls beneath them, and AI has the potential to expose just how much those structures and access controls have been taken for granted. When AI can surface anything it’s allowed to see, “who can see what” becomes a much more pressing issue to address and thus good IM and data practices become one, of many, foundations for good AI.
Let’s just say that we feel your pain. This is complex, multi-stakeholder, silo-busting stuff, that is akin to herding particularly unruly cats, and nobody has an easy button – despite the 100 emails a day you receive telling you that vendor X has that easy button.
For years municipalities could live with the mess, because most of its cost was invisible. Death by a thousand cuts – an inability to find a file, a slow FOI response, 23 copies of the same document stored in different places.
But something has changed. AI removes the ability to live with the mess. AI has the potential to turn every unowned folder, every outdated document, every stale permission and every undefined retention rule into a potential exposure – the wrong answer to a question or the wrong decision based on an outdated policy.
The mess doesn't stay hidden anymore – hence the imperative to look more closely at IM.
Our take on Municipal Information Management
Our take on Information Management strategy is that it's fundamentally about tying together all of these loose ends. Not by appointing one owner, not by buying one system, and not by building the perfect framework – but by getting a dozen partial owners and interested parties to agree on a shared game, with agreed objectives, roles, responsibilities and accountabilities, and measures of success, and then committing to improving the game a little at a time.
One game, whatever you call it
It’s about recognizing that people from different professional and experience backgrounds come at this space with different perspectives. Data, Information, Records. Those perspectives are equally valid, but they must be married, not in opposition.
It's about helping teams recognize that their area of expertise does not give them ownership of a whole discrete thing, but that they each bring their experience which are important pieces of the puzzle, that together and only together, contribute to the bigger whole – which we can refer to as Information Management.
To us it’s the distinction between soccer and football. It really doesn’t matter what you call it - the same issues must be addressed; classification, retention, ownership, stewardship, custodianship, version control, quality are pressing issues in the structured and unstructured domains.
It’s also about recognizing that the game has changed; that the shift from paper to digital has happened and that IM frameworks need to be updated to reflect new realities and practicalities of the digital world.
Agree the scope, then the rules
So, if IM is a team game and it’s about how all the players work together.
Then an IM strategy is about creating the rules of the game – keeping to our football analogy – the playing surface, the vocabulary, the players and officials, their roles and responsibilities, the permitted and non-permitted plays, the way we referee and address non-compliance.
It sets out the games that are going be played and the way we keep score to track how we are performing. It also establishes the ways that we govern the rules – how we might change them if we need to.
Do the risk management work up front
We think it's about pulling the risk management work forward.
What data / information is this system going to hold? Who owns the data? Who should be able to see it? Who must not see it? What's the retention? What happens to it when we turn the system off? How do we extract the data after the contract?
Ensuring that ownership, retention, legal holds, privacy, security, audit, and continuity topics are properly addressed up front on any project can help you avoid sovereignty, ownership, IM, security and privacy issues down the line.
A Privacy Impact Assessment for instance, done at the right point – when you're choosing the solution, not after you’ve bought the product – is one aspect of due diligence that forces exactly the questions that good IM depends on.
Borrow before build
Of course, IM strategy is also about defining a consistent information lifecycle, classification and metadata schemes that can apply across your whole information AND data landscape, it’s about drawing from good practices already established in your organization, perhaps in the GIS domain, not duplicating things that don’t need to be duplicated.
It’s about moving forward the things that have become blockers for your organization – that everyone knows and see’s but doesn’t feel like they have the agency to solve.
In this space it’s not about reinventing the wheel. In many ways, stealing is the best way to advance quickly. Universities, provincial governments have all tackled the issues of classification, metadata, and policy - and you can steal and quickly adapt to become 10% better very quickly. Just plan to come back and revisit.
Find the equilibrium
Then there's the operating model and being honest that not everything can be centralized and not everything can be decentralized. There are some things that should be done once, centrally, and other things that need to be done many times. Agree what those are, distribute what should be distributed, and accept that maintaining the balance is not a one-time decision – it is an equilibrium to be actively managed across both the information management and the data domains.
Then it’s about user experience – providing the right advice and guidance and ways of working to make it easy for staff to do the right thing (often without knowing they are).
And someone has to own the strategy itself. Not the data or information – that stays with the departments that create and use it – but the framework itself.
As we’ve noted earlier, the Clerk often has a strong claim while IT has the reach into the systems. However, it is our view that accountability sits a level up, with the CAO or the Corporate Services Lead, and that the Clerk and IT must actively partner, engaging broadly, with other parties to cascade change, responsibilities and accountabilities throughout the organization and to run it collaboratively day to day.
What you get
None of this is sexy or groundbreaking work, nor is it building frameworks for its own sake.
Done well, you will notice it in mundane ways. Roles and responsibilities will be clearer. Tensions between teams will reduce. Staff will find the current version of a document without having to ask a colleague which one it is. FOI requests will get answered in days rather than weeks, because the record is where the schedule says it should be. Data can becomes more discoverable. Nobody builds the fourth copy of the same dataset. Retention happens, so the things that should be gone are gone – and risks are reduced.
It also means you can answer the AI question confidently. That AI will not spit out and answer from a confidential source. When someone asks "who can see what, and why", you have an answer you'd be comfortable giving Council – because classification, permissions and ownership got purposefully decided rather than by accident.
Organizations that sort this out will be able to leverage new tools with confidence. The rest will either slow adoption or may find out about their access problems the hard way – ending up with a complaint, on the front page of the paper or with a judicial inquiry.
Ultimately, we think success in the modern digital era depends on a far more collaborative approach to information management than most organizations have today. Tying the pieces together, agreeing how they work, and managing the balance over time – that's what an information management strategy ought to deliver.
If any of the challenges that we talk about sounds like your organization, the good news is that the first step is a small one. We usually start with a short discovery – who holds which piece today, where the friction really is, and which blockers everyone already knows about but nobody owns. That gives you something you can act on in short order, instead of a five-year plan that's going to sit on the shelf because it can’t be resourced.
We would be happy to walk through what that looks like.