Becoming Compliant – The Return Outweighs the Investment
According to The Intranet Journal there are over 8,500 state and federal regulations that concern records management. You are probably most familiar with Sarbanes-Oxley, ISO, HIPAA, Safe Harbor, and the Securities Exchange Act. There are also the unique compliance guidelines required by your industry, such as the FDA’s 21 CFR Part 11 regulations for the life sciences industry. Regardless of your market – medical, insurance, financial, government, life sciences – no one has been spared.
What impact does regulation have on your ECM (enterprise content management) and ERM (enterprise records management) technology strategy? The bad news: It tends to drive unexpected investments in unplanned and unfamiliar technology. The good news: It typically results in significant productivity and efficiency improvements that return more than the initial investment.
Regulations influence your technology decision at every level from requirements gathering to implementation. They drive the strategy as well dictate information management, workflow, and archiving. Regulations are especially stringent on how companies maintain paper and electronic information. Storage and dissemination of that information receives the most attention because of privacy issues, the ability to record an audit trail, and accountability.
There are many ECM and ERM systems available to manage and secure your information. However companies often overlook two critical considerations when evaluating and implementing these systems:
- How and who can retrieve and view the information? And what can they do with it?
Consider the following scenario: Your company invests in a sophisticated solution to maintain, track, and secure your data. You provide access to your users, who retrieve information from the repository and open the files in the creator application (e.g. Microsoft Word, Adobe, Excel, etc.). Although safeguards have been built into the repository preventing users from saving to their desktop, there may be a loophole. Sometimes users can copy, paste, and save the information into another document on their computer. The viewing method you select can negatively affect your compliance efforts because of often overlooked loopholes such as this.
- How does the viewing component impact your productivity?
Think about the repetitive steps involved when receiving documents for review. If it’s in Word you first open Microsoft Word. It it’s a PDF you open Adobe. Consider how many times a day creator applications are launched to review files. Calculate the time it takes for the programs to load and then retrieve the files. Now multiply those seconds or minutes by the total number of users retrieving information from your repository. That is a lot of time and money wasted waiting! And if your organization is viewing large files or the users are in multiple locations it can put a strain on network bandwidth as well.
You should understand your viewing preferences as well as the compliance-driven requirements you must incorporate before evaluating solutions. Consider these necessities in addition to the repository requirements to ensure that you implement the most efficient solution for your needs.
The following are some considerations when defining your viewing preferences and compliance requirements:
- Does the viewing application adhere to the security levels inherent in the ECM/ERM system? (e.g. Should all users have the same rights to copy, paste, save, and/or print information?)
- Can users manipulate pages and create new documents in the viewer?
- Should users be allowed to redact the original file, which permanently alters the content? Or do you need to preserve the original file?
- Does the viewing application provide real redaction on the fly?
- Do you want to restrict the ability to open the file in the creator application?
- Do you want files to be stored in cache so that no information resides on the user’s desktop?
- Can the document viewer support all of the necessary formats?
- Can your viewing application provide on-the-fly viewing, delivering only the pages you want, on demand when you need them? Or does it make you wait for the entire document to download before you can begin navigating to the relevant page(s)?
Defining a complete storage and document viewing strategy, then implementing the most efficient technology ensures accuracy and accountability as well as increases productivity. If yours is a public company, it also provides executive management with the confidence that internal processes adhere to SEC and IRS regulations.
State and federal regulations impact all American companies and foreign companies doing business in America. The onus is on each organization to stay up-to-date on—and in compliance with—the latest regulations. Here are a few links and articles that may be of interest to help you better understand regulation and compliance issues.
Organizations
- AIIM – Focus on Compliance
- X9 - Accredited Standards Committee
- ARMA – Regulatory Issues
- EMC – Compliance Solutions
General Compliance Information
- SearchDataManagement.com – What CIOs should know about records
- E-Discovery Rules Double-Edged Sword for CIOs
- The Compliance Imperative: Managing Record Retention in a Rapidly Changing Regulatory Environment
- The Intranet Journal
- The Library of Congress
Sarbanes-Oxley Information
- SEC – Sarbanes-Oxley Public Law (PDF)
- SEC – Spotlight on Sarbanes-Oxley
- TechRepublic – Document Retention: The IT manager’s changing role
- Sarbanes-Oxley Compliance Journal – Preservation Perils: Updating your Corporation’s Document Retention Policy for the Digital Age
- The American Institute of Certified Public Accountants
HIPAA
Snowbound Software Articles
Read additional articles from Snowbound regarding Document Imaging
- Web-Imaging—A Crucial Component In Your Document Management Solution
- Finding the Sweet Spot in Document Imaging — Image Quality and Its Effect on Productivity
- High-Speed Viewing, Annotation, and Conversion for Document Management Systems
Contact Snowbound to learn how we can enhance your ECM or ERM system to remain compliant and drastically increase your productivity.
