Low Friction Information Governance with Microsoft

Information is at the core of every informed business action or decision. To provide value and avoid unnecessary risk, such as a lawsuit, to an organization, information must be captured, shared, accessed, stored and disposed of following a governed lifecycle to avoid misinformation, inefficiencies and breach of legal or regulatory requirements.

The following challenges are common among organizations attempting to ensure compliance within classic frameworks and tools:

  • Inefficient systems, originally put in place to manage physical records, as opposed to digital systems
  • Lack of employee adherence to tagging and organizing documents as required across the organization (e.g., managing documents, their versions, in the appropriate places, from draft initiation to publishing)
  • Inconsistent oversight and application of compliance needs, including the retention of data in different information and document file repositories
  • Staff expectations on how to conduct information management tasks, and leaders’ expectations on how to best ensure their team’s adherence
  • System resources required to procure, build, manage and maintain repositories, including a records center and archiving systems.

Electronic content management systems such as Microsoft SharePoint have transformed the capability and capacity of organizations to meet these requirements without relying on manual processes which are both time consuming and prone to information mismanagement.

SharePoint Online provides organizations the benefit of leveraging an in-place records management system. Rather than relying on human decisions or limited automation of when and where to retain content, SharePoint Online provides out-of-the-box features for seamless retention, without requiring user intervention or restriction.

Documents and items in SharePoint Online can be applied to a policy which will ensure retention regardless of deletion or being overwritten, allowing for content to be discoverable by authorized individuals (e.g., approved eDiscovery investigators) for the defined period (e.g., seven years). Retention policies also allow for automatic deletion of documents after a specific duration, which is critical when handling sensitive information such as personal information (PI) or personal health information (PHI).

Automation Reduces Friction

Retention automation reduces risk by ensuring policies are adhered to, but also providing the ability to delete information once it should no longer be stored, for example, once a document no longer has business value.

For more advanced needs, Microsoft 365 provides more advanced capabilities without additional third-party systems or forcing staff to interact with different tools and interfaces. These features include but are not limited to:

  • Application of compliance capabilities to multiple applications, including:
    • Automated retention of all emails, documents, and chat messages within the M365 tenant
    • In-application tagging for sensitivity to automate applications of permissions (e.g., allow only internal sharing) and document standards (e.g., watermark stating a document is confidential)
    • Monitoring and alerting of sensitive information types (e.g., passport numbers included in an email) in email and chat communications as well as documents
    • Tracking user and administrator actions and activities in Microsoft 365 for up to 10 years using the Advanced Audit Log
  • Providing a minimum or maximum retention at the document level with a few user clicks
  • Automatically setting the retention based on the storage location (e.g., Board of Directors collaboration area) or type of information within the document (e.g., monitor for financial data)
  • Ensuring documents identified as confidential do not leave the organization’s cloud environment by restricting the ability to download and copy to unmanaged devices and external accounts (e.g., cannot email outside of the company)
  • Providing eDiscovery specialists the ability to search across the organization, directly, without the need to request IT resources (and introduce potential conflicts of interest) to search and export results from multiple data sources.

Microsoft 365 provides a series of compliance tools for the core productivity and communication applications used by enterprise organizations as their day-to-day tools.

Most importantly, they optimize these capabilities by enabling automated methods for application, execution, and oversight (using reports, dashboards, and alerts). By reducing friction with staff for compliance, in terms of end user effort as well as education and training, organizations can reduce their compliance risk while improving employee productivity.

Ensuring Compliance

Managing compliance is an ongoing process which is benefitted by continuous improvement due to an ever-changing environment, both from within the organization, and from outside regulatory and legal authorities.

  • Review all legal and policy-based compliance needs
  • Identify existing information repositories and how they interact with business information through its lifecycle
  • Ensure available software is configured and capturing organizational requirements
  • Identify opportunities to optimize adherence and minimize outstanding risk (e.g., build a roadmap)
  • Implement a governance strategy to manage and maintain the organization’s compliance needs and capabilities as they evolve over time.

To learn more about our Microsoft capabilities, contact us.


Sev Derghazarian

Sev Derghazarian

Software Services

Subscribe to Topics

Learn how a worldwide leader in providing cleaner, softer water successfully effected a major global finance and IT transformation in 2020 http://ow.ly/nORb50EmU5t #ClientStory #ITtransformation #financialtranformation

We're on @FortuneMagazine's 100 Best Companies list for the 7th time! Thank you to our employees who say @Protiviti offered them a consistently great workplace experience & support during Covid. We appreciate your confidence in us – and we have confidence in you! #100BestCos

What can be gained from upgrading to SAP HANA 2.0? Our 2-part series explores the factors organizations should consider before making the decision to upgrade http://ow.ly/ofrL50EcsyV #SAPblog #SAPHANA

Understand the key principles, requirements & parallels between data privacy & ethics: join our experts on April 27 as they discuss the privacy & ethics implications of emerging technologies. From our #TechInsights series, more at http://ow.ly/DldP50E5H3x #PROTech #PROwebinar

"Enterprise technologists must determine which protocol will be best for their organizations based on the unique circumstances of their planned IoT deployments," said Protiviti managing director Scott Laliberte. Read more: http://ow.ly/35uA50EhJSj

Load More...