Back to the blog

Information Governance Policies: The Three That Matter Most

Sep 21, 2026

Information Governance Policies: The Three That Matter Most

This blog post accompanies the TrailBlazer Learning Academy podcast episode "Information Governance Policies: The Three That Matter Most" with hosts Maura Dunn and Lee Karas. Listen to the episode or play it on our podcast page.

Why Written Policies Matter

Information governance policies turn everyday business records into dependable evidence. A written policy sets formal expectations for your internal team, executive leadership, auditors, and external regulatory bodies. Without clear written policies, operational consistency breaks down, and day-to-day practices lose their authority in legal proceedings.

A critical question tackled in this episode is whether an ignored policy is worse than having no policy at all. In court, maintaining a written policy that employees systematically ignore can lead to an adverse inference ruling, where a judge presumes missing or mishandled evidence would have proven harmful to your organization. Outside the courtroom, recent corporate scandals, ranging from unheeded food safety protocols during recalls to high-pressure banking environments that ignored internal compliance standards, demonstrate the immense operational and financial risk of maintaining a gap between policy and practice.

The 3 Policies That Matter Most

Organizations frequently accumulate dozens of dense, overlapping compliance documents that confuse staff and prove impossible to enforce. In this episode, Maura Dunn identifies the 3 foundational information governance policies that every enterprise must prioritize:

  • Retention Schedule: The legal baseline defining what records your organization creates, how long each record class must be kept, and when routine disposition must occur.

  • Legal Hold Policy: The mechanism that immediately suspends routine disposal when litigation, regulatory inquiries, or internal audits arise, protecting the organization from spoliation claims.

  • Electronic Communications Policy: Rules governing official communication channels, data management, and retention expectations across traditional email, mobile text messages, collaboration platforms like Microsoft Teams and Slack, and modern inputs like AI prompts and outputs.

What to Do Next

To establish a defensible and realistic policy framework, records and information governance practitioners should take the following steps:

  • Evaluate policy adherence: Review existing workflows to ensure operational practice matches what your documentation requires. If a policy cannot be followed, update the process or amend the rule.

  • Address modern communication channels: Confirm that your electronic communications policy explicitly addresses ephemeral messaging, chat platforms, and AI tool usage.

  • Eliminate redundant documentation: Focus resources on maintaining and enforcing the core 3 policies before drafting niche standards.

To evaluate your program maturity or start drafting baseline documentation, explore IG Navigator and download practical tools from our template library.