Methodology
A sequence we can repeat inside your tenancy
This is the custom working page for the practice: the order of an application audit, what we need before week one, and what does not belong in the report. It is written for records owners and administrators in Malaysia, not as a generic process poster.
We work from admin centres, sample libraries, and the written schedule you already have — or we say when you do not have one.
1. Scope the stores, not the brand of software
Before fieldwork we ask which repositories hold official records: which SharePoint sites, which vaults, which file shares still receive scans. A “Microsoft shop” can still have three unofficial stores. The engagement letter names the stores. Anything outside them is out of scope unless we agree a change.
2. Inventory
We map libraries, cabinets, content types, label catalogues, and permission roots. Counts matter: objects, versions, unique permission scopes, external users. We do not accept “about two terabytes” as an inventory.
3. Sample the live objects
Policy documents describe intent. We open actual files and list items. We look at metadata completeness, version trails, hold flags, and whether a person in a named role can do what the policy forbids — or cannot do what the policy requires, such as placing a hold.
4. Compare with the duties you named
Typical anchors in our Petaling Jaya work include the PDPA 2010, tax record periods, Companies Act record-keeping, and internal retention schedules. We do not invent a legal opinion. We test whether the application can support the duties you asked us to hold it against.
5. Write findings in the order of harm
Unfindable records, over-exposed records, records that cannot be disposed, and configuration that will fail the next investigation come first. Cosmetic information architecture comes last. Each finding names the store, the evidence, and a remediation that an administrator can attempt.
What we need from you
- A records owner and an application administrator who can grant read access
- The current retention schedule, even if it is a spreadsheet
- Any design papers from go-live, if they still exist
- A list of stores you believe are in production
What this page is not
It is not an implementation plan, a licence recommendation, or a promise that a regulator will accept the report. It is the method we use when you book an application audit or a narrower review.