Records Management for Compliance Officers Training Course

5 days Knowledge & Records Management Certificate on completion
Course codeSD-KRM-015
Duration5 days
LevelIntermediate to Advanced
CategoryKnowledge & Records Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Compliance officers are often asked to demonstrate that policies, investigations, approvals, contracts, communications and regulated business records are complete, authentic, retrievable and retained for the right period. The difficulty is rarely a lack of documents; it is uncontrolled duplication across shared drives, email, collaboration platforms and business systems, unclear ownership, inconsistent classification and disposal decisions that cannot be defended. This course equips compliance professionals to turn records management into an auditable control rather than an administrative afterthought.

Participants examine the full records lifecycle, from creation and capture through classification, retention, legal hold, retrieval, secure disposal and evidence of destruction. They learn to build a records inventory, apply ISO 15489 principles, translate legal and regulatory obligations into retention rules, define metadata requirements, assess repositories and test whether records controls operate effectively. The course also addresses electronic records, email, Microsoft 365 content, privacy constraints, investigation records and the evidential requirements of audits and enforcement reviews.

Teaching combines instructor-led analysis with practical workshops using realistic compliance scenarios, including a regulatory request, an internal investigation and an over-retention remediation programme. Participants produce a role-relevant records compliance action pack: a records inventory, retention-schedule extract, legal-hold workflow, control-testing checklist and 90-day implementation plan. This gives both the attendee and sponsoring manager a usable set of artefacts for improving governance immediately after the course.

The programme is designed for experienced compliance, risk, governance and information-management professionals who need to own, assess or assure records controls across a business function or enterprise.

Course objectives

By the end of this course, participants will be able to:

  • Map a regulated records lifecycle using ISO 15489 concepts from capture through defensible disposal
  • Build a records inventory that identifies record series, business owners, systems, sensitivity and regulatory obligations
  • Create a retention-schedule extract using legal, operational, tax, privacy and limitation-period requirements
  • Define metadata, classification and file-plan rules that improve retrieval and evidence integrity
  • Design a legal-hold workflow covering trigger assessment, preservation notices, suspension of disposal and release
  • Assess Microsoft 365 and shared-repository records controls against retention, access, audit-trail and disposition requirements
  • Test records-management controls using an evidence-based compliance assurance checklist
  • Produce a 90-day records compliance remediation plan with priorities, owners, milestones and control measures

Benefits of attending

For you

  • Gain a defensible method for answering regulator, auditor and investigation requests for records evidence
  • Build credibility as the compliance lead who can convert obligations into operational retention controls
  • Learn to challenge weak disposal, over-retention and uncontrolled shared-drive practices with clear criteria
  • Develop reusable records inventory, legal-hold and control-testing templates for professional practice
  • Prepare for broader responsibilities in information governance, compliance assurance and regulatory risk management

For your organisation

  • Reduce exposure to sanctions, adverse audit findings and evidential gaps caused by missing or unmanaged records
  • Create clearer ownership for records held across business units, collaboration platforms and line-of-business systems
  • Improve response speed and accuracy for regulatory inquiries, litigation, investigations and subject-access requests
  • Lower storage, discovery and privacy risk by applying approved retention and defensible-disposal rules
  • Provide management with a prioritised remediation plan and measurable records-control improvements

Target competencies

Records lifecycle governanceRetention schedule designLegal hold managementMetadata classificationControl effectiveness testingDefensible disposition

Who should attend

  • Compliance Officers — who must demonstrate that regulated records are retained, retrievable and disposed of defensibly
  • Compliance Managers — who oversee compliance frameworks and need reliable evidence for audits and regulatory reviews
  • Records Managers — who translate retention requirements into classification, disposition and governance controls
  • Risk and Internal Control Officers — who assess records-related control gaps across business processes and systems
  • Internal Auditors — who test whether retention, legal-hold and records-disposal controls operate effectively
  • Data Protection Officers — who must reconcile storage-limitation duties with legal, regulatory and litigation retention needs

Requirements and prerequisites

Participants should have practical experience in compliance, risk, records, legal operations, audit or information governance, and should understand their organisation’s basic policy and control environment. Familiarity with terms such as retention period, personal data, audit trail, access control and legal hold is helpful. Participants should be able to review policy documents and work with spreadsheets; basic Microsoft Excel competence is assumed for the records-inventory exercise. Prior administration experience with Microsoft Purview, SharePoint or another electronic document system is useful but not required. This is not a records-archiving course for complete beginners with no exposure to organisational controls.

Training methodology

The course uses short instructor-led briefings to establish records-management principles, followed by guided analysis of policies, retention rules and control evidence. Participants work in small groups on a simulated regulated organisation with records dispersed across email, SharePoint, shared drives and a case-management system. Workshops cover inventory building, retention decisions, legal-hold notices and assurance testing. Facilitated peer review challenges assumptions and strengthens documentation. On day five, each participant converts course outputs into a practical 90-day application plan for their own compliance environment.

Course outline

Day 1: Records governance and compliance obligations

  • Records, documents, data and evidence: operational distinctions
  • ISO 15489 principles for authentic, reliable and usable records
  • The records lifecycle from creation to disposition
  • Compliance obligations mapped to recordkeeping requirements
  • Records governance roles, accountability and RACI design
  • Risk-based prioritisation of high-value and high-risk record series
  • Records-management policy architecture and control statements

Workshop: Participants map a selected business process and produce a lifecycle diagram showing its records, owners, repositories and key compliance risks.

Day 2: Classification, inventories and retention schedules

  • Functional classification schemes and file-plan structures
  • Records inventory fields: owners, systems, sensitivity and volume
  • Metadata schemas for retrieval, disposition and audit evidence
  • Retention triggers, event-based rules and fixed-period rules
  • Legal, tax, employment, privacy and sectoral retention sources
  • Retention-schedule design and approval governance
  • Handling duplicates, transitory content and non-record material

Workshop: Using a case organisation, participants build a records-inventory segment and draft retention rules for five record series.

Day 3: Electronic records and defensible preservation

  • Electronic records risks in email, chat, shared drives and cloud platforms
  • Microsoft 365 retention labels and retention policies
  • Microsoft Purview records management and disposition review
  • SharePoint document libraries, content types and version history
  • Access controls, audit logs and chain-of-custody evidence
  • Legal-hold triggers, preservation notices and custodian acknowledgements
  • Managing investigation, whistleblowing and regulatory inquiry records

Workshop: Participants design a legal-hold workflow and preservation notice for a simulated misconduct investigation involving Microsoft 365 records.

Day 4: Assurance, audits and disposal controls

  • Records-control objectives and testable control activities
  • Control design versus operating-effectiveness testing
  • Sampling approaches for retention and disposal assurance
  • Evidence collection from repositories, logs and disposition approvals
  • Assessing gaps in retrieval, access, metadata and audit trails
  • Defensible disposition and certificates of destruction
  • Audit findings, root-cause analysis and remediation tracking

Workshop: Participants conduct a tabletop controls review, complete an assurance checklist and write two evidence-based findings with corrective actions.

Day 5: Implementation and compliance remediation

  • Records-management maturity assessment models
  • Prioritising remediation by regulatory exposure and business impact
  • Target operating model for records governance
  • Stakeholder engagement with legal, IT, privacy and business owners
  • Change controls for migration, system replacement and decommissioning
  • Key risk indicators and management reporting metrics
  • Ninety-day implementation planning and executive briefing

Workshop: Participants assemble and present a 90-day records compliance action plan containing priorities, accountable owners, milestones, metrics and escalation points.

Tools & standards covered

ISO 15489-1:2016 Records Management, Microsoft Purview Records Management, Microsoft SharePoint, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should have working exposure to compliance controls, governance, audit, records, privacy or legal operations. The course assumes you can interpret internal policies and use spreadsheets, but it does not require prior system-administration experience.

A laptop is recommended for the inventory, retention-schedule and action-planning workshops. You do not need access to live organisational systems, and no confidential records should be brought into the classroom or live online sessions.

Yes. It is particularly useful where records managers need to explain retention and disposition controls in compliance and assurance terms, while compliance officers need to understand how those controls work in practice.

This course focuses on records as evidence across their lifecycle: classification, retention, legal hold, retrieval, audit trails and defensible disposal. Privacy is addressed where it affects retention and storage limitation, but the course does not concentrate on the wider GDPR or privacy-programme curriculum.

You can use the records inventory, retention-rule logic, legal-hold workflow and assurance checklist to assess one priority process or repository. The final 90-day plan provides a structured route for assigning owners, addressing control gaps and reporting progress to management.

You will leave with completed or adaptable templates for a records inventory, retention-schedule extract, legal-hold workflow, control-testing checklist and remediation plan. These are designed for adaptation to your organisation's policies, systems and regulated record categories.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Knowledge & Records Management

5 Days Certificate

Advanced Information Governance and Records Leadership Training Course

Information governance leaders are expected to make records reliable, discoverable and defensible across collaboration platforms, business a…

5 Days Certificate

Banking Records Retention and Information Governance Training Course

Banks hold records that must be retained long enough to satisfy prudential, anti-money-laundering, tax, conduct, audit, litigation and custo…

5 Days Certificate

ISO 30401 Knowledge Management Systems Implementation Training Course

Knowledge is often critical to delivery, safety, customer service and innovation, yet it remains dispersed across personal drives, legacy re…

5 Days Certificate

Knowledge and Records Management Essentials Training Course

Knowledge and records management failures rarely begin with a missing policy. They begin when staff save final documents in personal drives,…