The Difference Between Activity and Progress

Why Information Governance Needs More Than Assessments

Over the course of my career, I’ve participated in more records and information governance assessments than I can count. Some were broad enterprise evaluations. Others focused on specific business units, technologies, or compliance concerns. Nearly all of them produced thoughtful observations, practical recommendations, and long lists of things the organization should do next.

Yet one question continued to bother me.

How do we know whether the organization actually became better?

That may sound like an obvious question, but in practice it is surprisingly difficult to answer.

Our profession is very good at documenting activity. We can point to updated retention schedules, revised policies, new governance committees, Microsoft Purview implementations, employee training programs, and countless other initiatives. Those are all worthwhile accomplishments. They represent real work performed by dedicated professionals committed to improving their organizations.

But activity and progress are not the same thing.

Imagine two organizations. Both updated their retention schedules. Both revised their policies. Both implemented new technology. One can demonstrate that its governance program is objectively stronger than it was three years ago. The other simply completed a list of projects. Which organization would you rather be in?

If a chief executive officer were to ask, “Has our information governance program improved over the last three years?” many organizations would respond by listing completed projects. What they often cannot provide is objective evidence that the program itself has become stronger, more mature, or better positioned to manage information risk.

That distinction matters.

One of the strengths of our profession is that we are not lacking for guidance. International standards, industry best practices, regulatory requirements, and professional frameworks provide excellent direction for building effective records and information governance programs. They define what good governance should look like.

What they do not always provide is a practical, repeatable way to answer questions such as:

  • Where are we today?
  • Which improvements should receive priority?
  • How much progress have we actually made?
  • How do we communicate that progress to executive leadership?

Early in my consulting career, another consultant shared a piece of advice that has stayed with me ever since.

“You’re never a prophet in your own land.”

Over time, I found that observation to be remarkably accurate.

In engagement after engagement, the records manager, information governance officer, or compliance professional usually knew exactly where the problems were. They rarely needed another consultant to explain their own organization to them.

What they often needed was something different.

They needed an objective, standards-based way to help leadership see those same priorities with clarity and confidence.

That realization gradually changed how I thought about governance assessments.

Rather than asking whether an organization complied with a particular requirement, I became more interested in measuring the overall maturity of its governance program. Instead of producing a report that would eventually end up on a shelf, I wanted assessments to establish a measurable baseline against which future progress could be evaluated.

In other words, I wanted organizations to be able to answer a simple question a year or two later:

Are we better than we were?

That shift in perspective changes the purpose of an assessment.

An assessment is no longer the end of the engagement.

It becomes the beginning of a continuous improvement process.

Recommendations can be prioritized based on measurable need rather than opinion. Leadership can better understand where investments will have the greatest impact. Future assessments can demonstrate not only that projects were completed, but that governance maturity has measurably improved.

To me, that is where the profession has an opportunity.

As information governance continues to expand into areas such as artificial intelligence, privacy, cybersecurity, cloud computing, and increasingly complex regulatory environments, our ability to demonstrate measurable progress will become even more important. Organizations will continue to ask where to invest, which risks warrant immediate attention, and how to demonstrate value from governance initiatives.

Those questions deserve more than educated opinions.

They deserve objective answers.

Over the past several years, those ideas have evolved into a standards-based assessment methodology that I now use in my consulting practice. The framework itself is less important than the philosophy behind it: governance should be measured in a way that allows organizations to establish a baseline, prioritize improvements, and demonstrate progress over time. Whether an organization develops its own methodology or adopts an existing framework, I believe that principle is becoming increasingly important.

Because governance shouldn’t be measured by effort. It should be measured by progress.

Lean more about our framework:

Contact Us:

Leave a Comment

Your email address will not be published. Required fields are marked *

Verified by ExactMetrics