16MTECH

Information Governance

Clearer information handling, privacy, access, retention, and responsible AI use.

Information governance helps a business understand what information it holds, why it has it, where it is stored, who can use it, and what should happen to it over time.

Most SMEs hold more business, customer, staff, financial, and operational information than they realise. It may be spread across email, shared drives, devices, cloud services, backups, websites, and new AI tools.

16MTECH helps businesses make this environment easier to understand and manage. The work is practical: identify important information, clarify responsibilities, reduce unnecessary access, improve handling, and prepare sensible governance processes.

A useful starting view

  • What information do we hold?
  • Where is it stored?
  • Who can access it?
  • How sensitive is it?
  • When should it be retained or removed?
  • Could an AI tool receive it?

Practical information governance

Information inventory

Identify important information types, systems, owners, locations, and flows without trying to document every file individually.

Classification and handling

Define practical levels for public, internal, confidential, or sensitive information and the handling each level needs.

Access control

Clarify who should access important information, how access is approved, and what happens when roles change.

Retention and lifecycle

Consider how long information remains useful or necessary, where copies exist, and how disposal can be managed.

Privacy and protection

Connect information practices with privacy considerations, security controls, cloud services, sharing, backups, and incidents.

Responsibilities and guidance

Create plain-language roles, policies, checklists, and decision points that staff can actually follow.

AI governance

Before business information goes into an AI tool, ask better questions.

Information

  • What data will the tool receive?
  • Does it contain customer, staff, confidential, or commercially sensitive material?
  • Is all of that information necessary for the task?

Provider and settings

  • Where may information be processed or retained?
  • Could inputs be used to improve a model?
  • What account, sharing, and deletion controls are available?

People and decisions

  • Who may use the tool and for what work?
  • How will important outputs be checked?
  • Who owns the decision if an output is wrong?

Responsible AI is not a single policy document. It requires proportionate decisions about approved use, data handling, human review, accountability, and ongoing change.

A manageable governance process

  1. Scope the information environmentChoose the business process, information types, systems, or AI use cases that matter most.
  2. Map current practiceUnderstand collection, storage, access, sharing, protection, retention, and disposal.
  3. Identify gaps and decisionsFind unclear ownership, excessive access, unnecessary copies, weak guidance, and unmanaged technology use.
  4. Build practical controlsAgree responsibilities, classification, access, retention, approved use, review points, and staff guidance.
  5. Review and improveUpdate processes as systems, people, risks, and AI capabilities change.

Governance support, not legal advice

16MTECH can help identify privacy and compliance considerations, improve information management, and prepare a business for informed discussions with legal or specialist advisers. The service does not provide legal advice or guarantee compliance.

Connect governance with cybersecurity and networking →

Information governance questions

Is information governance only for large organisations?

No. Smaller businesses often benefit from a lighter, more practical approach because important knowledge and access may depend on a few people or loosely connected systems.

Is data governance the same as information governance?

The terms overlap. Data governance often focuses on data quality, ownership, standards, and use. Information governance takes a wider view that can include documents, email, records, privacy, security, retention, and accountability.

Do we need an AI policy?

A policy can help, but it should be supported by approved-use decisions, staff guidance, data-handling rules, provider review, human oversight, and a way to respond as tools change.

Need a clearer view of business information or AI risk?

Start with the systems, information types, or proposed AI use that is creating uncertainty.