Service

Document management application audit

Most organisations already run a document management application. The question is whether that application matches the retention rules, access promises, and filing habits people actually use. We audit the live system, not a slide deck.

Typical duration: Three to six weeks, depending on repositories and sites

Rows of labelled archive boxes on metal shelving

We begin with a scoped inventory: libraries, cabinets, workspaces, and the connectors that feed them. SharePoint tenancies, M-Files vaults, OpenText libraries, Laserfiche repositories, Google shared drives, and in-house file servers are all in scope when they hold official records.

From there we sample real objects. We look at naming, metadata completeness, version trails, hold flags, disposal jobs, and the gap between written policy and what the application will actually allow a user to do on a Thursday afternoon.

The written product is an audit report with findings ranked by harm: records that cannot be found, records that cannot be disposed, records that are visible to the wrong people, and configuration that will fail a regulator or an internal investigation.

What we examine

  • Repository map and ownership of each store
  • Metadata schemas and mandatory fields in practice
  • Retention labels, holds, and disposal jobs
  • Permission models, guest access, and inherited rights
  • Search, audit logs, and export paths
  • Backup, restore tests, and orphaned content

What you receive

A bound findings report, a ranked remediation list, and a walkthrough with the records owner and the application administrator.

Ask for a scope on this work