Records Management for Compliance Officers Training Course
| Course code | SD-KRM-015 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Knowledge & Records Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Compliance officers are often asked to demonstrate that policies, investigations, approvals, contracts, communications and regulated business records are complete, authentic, retrievable and retained for the right period. The difficulty is rarely a lack of documents; it is uncontrolled duplication across shared drives, email, collaboration platforms and business systems, unclear ownership, inconsistent classification and disposal decisions that cannot be defended. This course equips compliance professionals to turn records management into an auditable control rather than an administrative afterthought.
Participants examine the full records lifecycle, from creation and capture through classification, retention, legal hold, retrieval, secure disposal and evidence of destruction. They learn to build a records inventory, apply ISO 15489 principles, translate legal and regulatory obligations into retention rules, define metadata requirements, assess repositories and test whether records controls operate effectively. The course also addresses electronic records, email, Microsoft 365 content, privacy constraints, investigation records and the evidential requirements of audits and enforcement reviews.
Teaching combines instructor-led analysis with practical workshops using realistic compliance scenarios, including a regulatory request, an internal investigation and an over-retention remediation programme. Participants produce a role-relevant records compliance action pack: a records inventory, retention-schedule extract, legal-hold workflow, control-testing checklist and 90-day implementation plan. This gives both the attendee and sponsoring manager a usable set of artefacts for improving governance immediately after the course.
The programme is designed for experienced compliance, risk, governance and information-management professionals who need to own, assess or assure records controls across a business function or enterprise.
Course objectives
By the end of this course, participants will be able to:
- Map a regulated records lifecycle using ISO 15489 concepts from capture through defensible disposal
- Build a records inventory that identifies record series, business owners, systems, sensitivity and regulatory obligations
- Create a retention-schedule extract using legal, operational, tax, privacy and limitation-period requirements
- Define metadata, classification and file-plan rules that improve retrieval and evidence integrity
- Design a legal-hold workflow covering trigger assessment, preservation notices, suspension of disposal and release
- Assess Microsoft 365 and shared-repository records controls against retention, access, audit-trail and disposition requirements
- Test records-management controls using an evidence-based compliance assurance checklist
- Produce a 90-day records compliance remediation plan with priorities, owners, milestones and control measures
Benefits of attending
For you
- Gain a defensible method for answering regulator, auditor and investigation requests for records evidence
- Build credibility as the compliance lead who can convert obligations into operational retention controls
- Learn to challenge weak disposal, over-retention and uncontrolled shared-drive practices with clear criteria
- Develop reusable records inventory, legal-hold and control-testing templates for professional practice
- Prepare for broader responsibilities in information governance, compliance assurance and regulatory risk management
For your organisation
- Reduce exposure to sanctions, adverse audit findings and evidential gaps caused by missing or unmanaged records
- Create clearer ownership for records held across business units, collaboration platforms and line-of-business systems
- Improve response speed and accuracy for regulatory inquiries, litigation, investigations and subject-access requests
- Lower storage, discovery and privacy risk by applying approved retention and defensible-disposal rules
- Provide management with a prioritised remediation plan and measurable records-control improvements
Target competencies
Who should attend
- Compliance Officers — who must demonstrate that regulated records are retained, retrievable and disposed of defensibly
- Compliance Managers — who oversee compliance frameworks and need reliable evidence for audits and regulatory reviews
- Records Managers — who translate retention requirements into classification, disposition and governance controls
- Risk and Internal Control Officers — who assess records-related control gaps across business processes and systems
- Internal Auditors — who test whether retention, legal-hold and records-disposal controls operate effectively
- Data Protection Officers — who must reconcile storage-limitation duties with legal, regulatory and litigation retention needs
Requirements and prerequisites
Participants should have practical experience in compliance, risk, records, legal operations, audit or information governance, and should understand their organisation’s basic policy and control environment. Familiarity with terms such as retention period, personal data, audit trail, access control and legal hold is helpful. Participants should be able to review policy documents and work with spreadsheets; basic Microsoft Excel competence is assumed for the records-inventory exercise. Prior administration experience with Microsoft Purview, SharePoint or another electronic document system is useful but not required. This is not a records-archiving course for complete beginners with no exposure to organisational controls.
Training methodology
The course uses short instructor-led briefings to establish records-management principles, followed by guided analysis of policies, retention rules and control evidence. Participants work in small groups on a simulated regulated organisation with records dispersed across email, SharePoint, shared drives and a case-management system. Workshops cover inventory building, retention decisions, legal-hold notices and assurance testing. Facilitated peer review challenges assumptions and strengthens documentation. On day five, each participant converts course outputs into a practical 90-day application plan for their own compliance environment.
Course outline
Day 1: Records governance and compliance obligations
- Records, documents, data and evidence: operational distinctions
- ISO 15489 principles for authentic, reliable and usable records
- The records lifecycle from creation to disposition
- Compliance obligations mapped to recordkeeping requirements
- Records governance roles, accountability and RACI design
- Risk-based prioritisation of high-value and high-risk record series
- Records-management policy architecture and control statements
Workshop: Participants map a selected business process and produce a lifecycle diagram showing its records, owners, repositories and key compliance risks.
Day 2: Classification, inventories and retention schedules
- Functional classification schemes and file-plan structures
- Records inventory fields: owners, systems, sensitivity and volume
- Metadata schemas for retrieval, disposition and audit evidence
- Retention triggers, event-based rules and fixed-period rules
- Legal, tax, employment, privacy and sectoral retention sources
- Retention-schedule design and approval governance
- Handling duplicates, transitory content and non-record material
Workshop: Using a case organisation, participants build a records-inventory segment and draft retention rules for five record series.
Day 3: Electronic records and defensible preservation
- Electronic records risks in email, chat, shared drives and cloud platforms
- Microsoft 365 retention labels and retention policies
- Microsoft Purview records management and disposition review
- SharePoint document libraries, content types and version history
- Access controls, audit logs and chain-of-custody evidence
- Legal-hold triggers, preservation notices and custodian acknowledgements
- Managing investigation, whistleblowing and regulatory inquiry records
Workshop: Participants design a legal-hold workflow and preservation notice for a simulated misconduct investigation involving Microsoft 365 records.
Day 4: Assurance, audits and disposal controls
- Records-control objectives and testable control activities
- Control design versus operating-effectiveness testing
- Sampling approaches for retention and disposal assurance
- Evidence collection from repositories, logs and disposition approvals
- Assessing gaps in retrieval, access, metadata and audit trails
- Defensible disposition and certificates of destruction
- Audit findings, root-cause analysis and remediation tracking
Workshop: Participants conduct a tabletop controls review, complete an assurance checklist and write two evidence-based findings with corrective actions.
Day 5: Implementation and compliance remediation
- Records-management maturity assessment models
- Prioritising remediation by regulatory exposure and business impact
- Target operating model for records governance
- Stakeholder engagement with legal, IT, privacy and business owners
- Change controls for migration, system replacement and decommissioning
- Key risk indicators and management reporting metrics
- Ninety-day implementation planning and executive briefing
Workshop: Participants assemble and present a 90-day records compliance action plan containing priorities, accountable owners, milestones, metrics and escalation points.
Tools & standards covered
ISO 15489-1:2016 Records Management, Microsoft Purview Records Management, Microsoft SharePoint, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Knowledge & Records Management
Advanced Information Governance and Records Leadership Training Course
Information governance leaders are expected to make records reliable, discoverable and defensible across collaboration platforms, business a…
Banking Records Retention and Information Governance Training Course
Banks hold records that must be retained long enough to satisfy prudential, anti-money-laundering, tax, conduct, audit, litigation and custo…
ISO 30401 Knowledge Management Systems Implementation Training Course
Knowledge is often critical to delivery, safety, customer service and innovation, yet it remains dispersed across personal drives, legacy re…
Knowledge and Records Management Essentials Training Course
Knowledge and records management failures rarely begin with a missing policy. They begin when staff save final documents in personal drives,…