Senior Information Risk Owner (SIRO) is a senior executive role within public sector organisations, this isn’t a statutory requirement, but many organisations choose to follow this best practice. Often this role is replicated, or the responsibilities are identified and allocated to individuals in other sectors e.g. private sector.
They are responsible for ensuring that information risks are properly identified, assessed, and managed at a strategic level. The SIRO oversees the organisation’s approach to information governance, including the protection and appropriate use of information assets. This includes ensuring compliance with relevant legislation, such as data protection laws, and supporting the development of robust policies for managing records and information.
The SIRO’s responsibilities often overlap with records management because both functions are concerned with safeguarding information, maintaining compliance, and promoting best practices for handling organisational records. While the Records Manager focuses on the operational aspects—such as classification, storage, retention, and disposal—the SIRO provides strategic oversight, supports risk management, and ensures that records management is aligned with the organisation’s wider objectives for information security and governance. The SIRO works closely with Records Managers, Information Asset Owners, and Data Protection Officers to ensure a coherent approach to managing information risks across the organisation.
The Records Manager is tasked with implementing the organisation’s records management policies and procedures. They maintain the records management system, provide guidance to staff, and ensure that records are properly classified, stored, and disposed of in accordance with legal and organisational requirements.
The Archivist is responsible for preserving, organising, and managing records and documents of long-term value to an organisation. Archivists ensure that historical and vital records are accessible, properly stored, and protected against loss or deterioration.
In some smaller organisations the roles of records manager and archivist may be combined or where organisations have limited resources or use volunteers.
Departmental Managers are responsible for ensuring their teams comply with the records management policies. They monitor record-keeping practices within their departments, encourage best practice, and report any issues or breaches to the Records Manager or Data Controller.
They might also be given a specific role of:
Information Asset Owner which is a key role within a public body, responsible for overseeing specific sets of information assets such as databases, files, or systems. They ensure that these assets are managed securely and in compliance with organisational and legal requirements.
Information Asset Owners assess risks related to their assets, authorise access, and support the implementation of appropriate security measures. Additionally, they collaborate with Records Managers and Information Governance Officers to guarantee that information is properly classified, retained, and disposed of according to established policies.
Information Governance Officer provides expert advice on records management and data protection. They support the Records Manager and Data Controller in ensuring the organisation’s compliance with statutory regulations and help to resolve complex issues related to the handling of records.
Information Security Officer: The Information Security Officer plays a central role in safeguarding an organisation’s information assets, spanning physical, personnel, and digital realms. This position involves developing and implementing robust policies and procedures to prevent unauthorised access, loss, or misuse of records. Responsibilities include conducting risk assessments across physical storage and digital systems, ensuring staff are well-trained in security awareness, and maintaining compliance with relevant regulations such as the UK GDPR and Data Protection Act 2018. The Information Security Officer also oversees secure handling and storage of sensitive documents, manages access controls for personnel, and ensures that both paper and electronic records are protected against threats, thereby supporting the organisation’s wider records management framework.
Cyber Security Officer: The Cyber Security Officer specialises in defending the organisation’s digital infrastructure against cyber threats. This role focuses on monitoring network security, responding swiftly to incidents such as data breaches, and ensuring the secure transmission and storage of electronic records. The Cyber Security Officer is responsible for identifying vulnerabilities in the organisation’s IT systems, implementing technical safeguards, and coordinating with other records management and information governance professionals to guarantee that digital records are kept confidential, accurate, and available. Their expertise is vital for maintaining the integrity of digital records and protecting them from evolving cyber risks within a modern organisational context.
All Employees who create, handle, or manage records have a duty to follow organisational policies and procedures. They must ensure records are accurate, securely stored, and disposed of appropriately, reporting any concerns or incidents relating to records management to their line manager.
Related Roles
Data Protection Officer (DPO): The Data Protection Officer is responsible for overseeing an organisation’s compliance with data protection laws, such as the UK GDPR and the Data Protection Act 2018. The DPO advises on and monitors data protection obligations, conducts impact assessments, and acts as the primary contact for data subjects and regulatory authorities. In relation to records management, the DPO ensures that personal data within records is handled lawfully, transparently, and securely, and that retention and disposal practices adhere to statutory requirements. The DPO works closely with Records Managers and Information Governance Officers to support the proper classification, retention, and safeguarding of records, helping to embed privacy by design and data protection principles throughout the records management lifecycle.
A Caldicott Guardian is a senior individual within NHS organisations and local authorities in England and Wales, responsible for safeguarding the confidentiality of patient and service user information and enabling appropriate information sharing. The role originates from the 1997 Caldicott Report, which set out principles for protecting patient data and ensuring it is only used when necessary and in ways that respect privacy.
Caldicott Guardians are required in NHS bodies, social care organisations, and other settings where confidential health and social care information is handled. Their appointment is mandatory for all NHS organisations, including hospitals, trusts, and clinical commissioning groups, as well as local authorities that provide social care services in England and Wales. The Caldicott Guardian acts as the ‘conscience’ of the organisation, overseeing the use and sharing of confidential information and ensuring decisions are made in line with the Caldicott Principles.
While the Records Manager focuses on the lifecycle of all organisational records—ensuring they are created, stored, retained, and disposed of appropriately—the Caldicott Guardian’s remit is specifically to oversee the use and sharing of confidential health and care information. The two roles work closely together to ensure that information governance policies and procedures protect patient data, comply with legal requirements, and support effective records management practices across the organisation.