Records quietly underpin trust, accountability, and compliance across your business. When they are lost, altered, or inaccessible, the damage is rarely technical—it is organisational, legal, and financial. Over my 30 years in governance, risk, and compliance, I have seen far too many businesses treat records as static files sitting in forgotten cloud buckets or dusty archive boxes, only to face severe penalties, lost court battles, or failed ISO certification audits when they couldn’t prove a decision, transaction, or compliance step. Annex A 5.33 is about governance and integrity throughout the entire record lifecycle.
ISO 27001:2022 includes Annex A 5.33 to ensure your organisation protects records from loss, damage, unauthorised access, falsification, and destruction, while keeping them usable, reliable, and legally defensible for as long as required. This control replaces former 2013 requirements (18.1.3) and aligns record management directly with data retention schedules, cryptographic integrity checks, access controls, and secure destruction protocols.
Quick Summary: What ISO 27001 Annex A 5.33 Requires
At a practical level, Annex A 5.33 is about preserving the authenticity, integrity, and availability of business evidence. It does not dictate a single records management software suite; it expects structured, risk-proportionate governance. Here is what you need to do in plain English:
- Identify & Categorise Organisational Records: Map all record types—financial, legal, HR, operational, and IT audit logs—defining their business and regulatory value.
- Protect Integrity & Authenticity: Enforce controls (like WORM storage, digital signatures, and access restrictions) to stop unauthorised alteration or falsification.
- Establish Formal Retention Schedules: Define explicit retention timeframes based on statutory, regulatory, contractual, and operational requirements.
- Ensure Usability & Readability Over Time: Protect electronic records against technological obsolescence, file format decay, and media degradation.
- Enforce Secure Disposal: Destroy or crypto-shred records permanently once retention periods expire, maintaining auditable certificates of destruction (Annex A 7.14).
- Maintain Chain of Custody for Evidential Records: Log all access, transfers, and modifications for high-value legal and security records (Annex A 8.15).
Why Neglecting Record Protection Is a Critical Hazard
When records are poorly protected, your organisation loses its legal memory. If an auditor, regulator, or court demands proof of compliance, a missing, altered, or unverified record leaves your business completely indefensible.
Ignoring record protection controls exposes your business to severe hazards:
- Inadmissible Legal & Evidential Records: Courts rejecting critical business records or security logs during disputes because integrity and chain-of-custody could not be proven.
- Regulatory Fines for Premature Destruction: Destroying financial, tax, or health records before statutory retention limits expire, triggering severe legal penalties.
- Excessive Risk & Liability from Indefinite Retention: Hoarding legacy data indefinitely “just in case,” inflating storage costs and exposing obsolete customer PII to data breaches (Annex A 5.34).
- Format Obsolescence & Inaccessibility: Storing critical records in proprietary or legacy formats that can no longer be opened or read by modern IT systems.
My 8 Step Plan to Implement Annex A 5.33 Fast
You do not need an over-engineered archive department to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready record protection framework.
1. Develop a Comprehensive Record Identification Matrix
Catalog all records generated and held across your business operations (Annex A 8.9):
- Financial & Accounting: Tax filings, invoices, payroll ledgers, audit reports (statutory retention: typically 6–7 years).
- Legal & Corporate: Articles of incorporation, board minutes, contracts, IP filings, NDAs (statutory retention: permanent or contract length + 6 years).
- Personnel & HR: Employment contracts, screening logs (Annex A 6.1), exit sign-offs, pension records.
- Information Security & IT: SIEM event logs (Annex A 8.15), backup restoration logs (Annex A 8.13), vulnerability scans, access approval forms.
2. Publish a Documented Record Retention & Disposal Policy
Establish clear rules governing how long every record category must be retained before secure destruction:
- Cross-reference legal, regulatory (e.g., GDPR, Companies Act), and contractual requirements to set statutory retention caps.
- Define explicit trigger events for retention periods (e.g., “7 years from end of financial year” or “6 years post-contract termination”).
- Incorporate “Legal Hold” procedures to suspend automated deletion instantly if litigation or an investigation arises.
3. Enforce Technical Controls Against Record Falsification
Protect record integrity and authenticity so evidence holds up under legal and audit scrutiny:
- Store critical audit logs and system records in Write-Once-Read-Many (WORM) storage or immutable cloud buckets (e.g., AWS S3 Object Lock).
- Apply digital signatures and cryptographic hashing (e.g., SHA-256) to verify that electronic files have not been altered since creation.
- Restrict edit and delete permissions strictly using least-privilege Role-Based Access Control (RBAC) (Annex A 8.3).
4. Prevent Storage Degradation and Format Obsolescence
Ensure electronic and physical records remain readable and usable throughout their retention lifecycle:
- Store electronic records in open, long-term archival formats (e.g., PDF/A, CSV) rather than proprietary or short-lived application formats.
- Perform routine media integrity checks and migrate archives off aging physical storage (tapes, optical discs) to secure cloud repositories.
- Store physical paper records in fire-resistant, climate-controlled environments protected against environmental threats (Annex A 7.5).
5. Restrict Access and Maintain Chain of Custody
Records often contain sensitive commercial data or customer PII. Limit access and maintain audit trails:
- Enforce strict access controls so only authorized roles can view or export sensitive record repositories.
- Enable detailed access logging on document management portals to track who accessed, downloaded, or transferred records (Annex A 8.15).
- Maintain a formal chain of custody log for high-value legal evidence or physical media transfers.
6. Automate Secure Record Disposal Protocols
Disposing of expired records safely is just as critical as retaining active ones:
- Configure automated lifecycle purge policies inside cloud storage systems to flag or delete expired records automatically.
- Use certified physical shredding vendors (DIN 66399 Level P-4 or higher) for physical paper and media destruction (Annex A 7.10).
- Execute cryptographic erasure (crypto-shredding) for cloud-hosted records, destroying underlying encryption keys securely (Annex A 8.24).
7. Synchronize Record Protection with Backup & DR Plans
Ensure essential business records are fully backed up and recoverable during disasters (Annex A 8.13):
- Include record repositories in daily automated backup routines and verify off-site replication.
- Test record retrieval speed and file integrity during routine disaster recovery restoration exercises.
- Store secondary record copies in geographically distinct locations to guard against site-wide disasters (Annex A 7.5).
8. Conduct Routine Record Management Audits
Verify that your record protection practices match your written policy commitments over time:
- Perform annual spot-check audits sampling active and archived record stores to confirm retention and access compliance.
- Verify that expired records have been purged cleanly according to policy without orphaned files remaining on unmonitored shares.
- Provide signed Certificates of Destruction and retention schedules as audit evidence during ISO 27001 surveillance audits.
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same record protection mistakes. Here are the main traps and how to solve them:
- Problem: Storing Electronic Records in Mutable Folders Where Anyone Can Edit or Delete Them
Ninja Solution: Move critical records to read-only, access-controlled repositories or immutable cloud buckets with versioning enabled. - Problem: Keeping Every Document and Email Indefinitely “Just in Case”
Ninja Solution: Enforce automated lifecycle retention rules that purge expired files, reducing storage costs and PII breach exposure. - Problem: Destroying Expired Records Without Keeping Audit Proof of Disposal
Ninja Solution: Obtain and archive formal Certificates of Destruction for all physical and digital media disposal activities. - Problem: Storing Legacy Records in Obsolete Proprietary File Formats That Can No Longer Be Opened
Ninja Solution: Standardize long-term record archives on standardized open formats like PDF/A and CSV during ingestion.
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 5.33 is about preserving the trust, authenticity, and usability of your organisational evidence. Storage alone does not protect records; active lifecycle governance ensures your data remains readable, secure, and legally defensible when you need it most.
By mapping record categories, publishing retention schedules, enforcing immutable integrity controls, guarding against format obsolescence, restricting access, automating secure disposal, and conducting routine audits, you build true evidence resilience, satisfy regulatory mandates, and pass your ISO 27001 audit with complete confidence.
