Your Business Is Back, But Is Your Information Ready? An H2 Information Health Check

Published

17 August, 2026

The summer slowdown is ending. Teams are returning, projects are picking up pace and attention is turning to the targets that need to be delivered before year-end.

But while your people may be ready for H2, is your information? And how do you know if your business information is ready for H2?

Quick answer: your business information is ready for H2 when it is organised, accessible, secure, appropriately retained and easy for authorised employees to find and use.

A simple information health check can reveal outdated records, access risks, inefficient processes and information gaps before they become bigger problems later in the year.

TL;DR: Your H2 information health check

Ask yourself:

  • Do we know what information we hold?
  • Is it stored in the right place?
  • Can only the right people access it?
  • Are we retaining information for the right amount of time?
  • Can employees quickly find the correct version?
  • Could we recover important information if something went wrong?

If any answer is unclear, it is worth investigating now.

What is an information health check?

An information health check is a structured review of how information is created, stored, accessed, retained and disposed of across an organisation. It helps businesses identify unnecessary data, weak processes, security risks and opportunities to improve the way employees work with both physical and digital information.

Think of it as a mid-year MOT for your information estate.

The objective is not to reorganise every document your organisation owns. It is to identify where information is creating friction or risk and prioritise the improvements that will make the biggest difference during the remainder of the year.

1. Do you know what information your business holds?

Start with visibility.

Business information rarely lives in one neat location. It may be spread across:

    • physical archives and filing cabinets
    • employee desktops and shared drives
    • Microsoft Teams and SharePoint
    • email inboxes
    • cloud platforms
  • legacy databases
  • USB drives and other storage media
  • third-party systems

If nobody has a clear overview of what exists and where it is held, managing information effectively becomes difficult.

The Information Commissioner’s Office (ICO) includes comprehensive data mapping among its accountability measures, helping organisations understand what personal information they hold and where it sits.

Your H2 health check does not necessarily require an organisation-wide audit. Start with departments or information types where the consequences of poor management are highest.

Ask: Could we confidently explain what important information we hold and where to find it?

If not, creating an information inventory or map is a useful starting point.

For businesses beginning a wider transformation project, our guide to moving from paper to performance explores how understanding your existing information landscape can help shape the next steps.

2. Is your information stored in the right places?

Knowing that information exists is only half the battle. Next, consider whether it is stored appropriately.

A contract saved exclusively in someone’s inbox may technically be retrievable, but that does not make the inbox the best place to manage it.

Likewise, frequently accessed documents sitting in boxes in an office storeroom may create unnecessary delays, while inactive physical records taking up valuable workspace could potentially be moved to secure off-site storage.

A healthy information environment uses the right storage method for the information involved.

That could mean:

Active records: Easily accessible to employees who regularly need them.

Inactive records: Securely stored and indexed for retrieval when required.

High-use physical documents: Considered for scanning and digitisation.

Sensitive archives: Protected through appropriate records management and storage.

The aim is not necessarily to make everything digital. It is to create a hybrid information environment where physical and digital records are managed deliberately rather than by default.

3. Can the right people access the right information?

Access that is too restrictive slows people down. Access that is too broad creates unnecessary risk.

The question for H2 is simple: do your current permissions still reflect the way your organisation operates today?

Teams change. Employees move departments. Contractors finish projects. People leave businesses. New systems are introduced.

Permissions that were appropriate in January may no longer be appropriate several months later.

The UK’s National Cyber Security Centre recommends using physical and logical access controls so that only authorised users can access or modify organisational data.

Consider reviewing:

  • access for employees who have changed roles
  • former employee accounts
  • shared folders with large user groups
  • external or contractor permissions
  • access to confidential HR, financial or customer information
  • administrator and privileged accounts

A simple permissions review can help ensure information remains accessible without becoming unnecessarily exposed.

 
 

4. Are you keeping information you no longer need?

One of the easiest information management habits to develop is also one of the most dangerous:

“Keep it, just in case.”

Over time, businesses can accumulate redundant, obsolete and trivial information, commonly referred to as ROT data.

The challenge is bigger than digital clutter. Holding unnecessary information can make searches harder, increase storage demands and complicate governance.

It can also have compliance implications.

Under the UK GDPR storage limitation principle, personal data should not be retained for longer than necessary for the purpose for which it is being processed. The ICO also recommends organisations have documented retention schedules that are regularly reviewed.

As part of your H2 review, ask:

  1. What information has reached the end of its retention period?
  2. What duplicates or outdated versions are being retained?
  3. What records have no clear business, legal or regulatory purpose?
  4. Is disposal taking place consistently and securely?

If the answer is “we don’t know”, a retention and disposal review should move up the priority list.

Our guide to turning ROT into ROI explores how reducing unnecessary information can support more efficient operations.

Where information has reached the end of its lifecycle, secure destruction helps ensure sensitive physical and digital assets are disposed of appropriately.

5. Can employees find the right information quickly?

Information can be perfectly secure and compliant but still cause problems if nobody can find it.

Common warning signs include:

  • employees creating duplicate documents because they cannot find originals
  • multiple versions of the same file circulating
  • inconsistent file naming
  • important approvals taking place through lengthy email chains
  • teams relying on particular employees to locate information
  • manual processes repeatedly slowing work down

Good information management should make the correct information easier to find, trust and act upon.

That might require better indexing and metadata, clearer naming conventions, document management technology or automated workflows.

The goal is to move from simply storing information to making information work for the business.

If repetitive document-heavy processes are causing bottlenecks, explore five ways workflow automation can save time.

6. Could you recover critical information if something went wrong?

Finally, test resilience.

What would happen if an employee accidentally deleted an important folder? A system failed? A cyber incident made files unavailable?

Having a backup is useful. Knowing that the backup can actually be restored is better.

The National Cyber Security Centre advises organisations to back up important data and protect online backups, including through measures such as two-step verification. Its broader guidance also highlights the importance of resilience against destructive actions such as ransomware.

For H2, identify your most business-critical information and ask:

Where is it stored?

Who is responsible for it?

Is it backed up?

When was recovery last tested?

If those questions are difficult to answer, your information resilience may need attention.

Make information one less thing to worry about in H2

There is still plenty of time left in the year to improve how your organisation manages information.

And improvement does not need to begin with a huge digital transformation programme.

Start with one troublesome repository. One retention schedule. One paper-heavy process. One department struggling to locate documents.

At Crown Information Management, we help organisations understand, organise, protect and unlock value from their information throughout its lifecycle. From records management and secure storage to digitisation, workflow automation and secure destruction, the right information strategy can make everyday work simpler while supporting stronger governance and compliance.

Your business is back. Make sure your information is ready to keep up.

Talk to Crown Information Management about an information management approach that supports your priorities for the remainder of H2 and beyond.

Contact Us

FAQs - Information health checks

An information health check reviews how an organisation creates, stores, accesses, retains and disposes of information. It identifies risks, inefficiencies and opportunities to improve records and document management.
Information management should be monitored continuously, with more structured reviews carried out periodically and when significant organisational, regulatory, technology or process changes occur. Retention schedules should also be reviewed regularly, according to ICO guidance.
ROT stands for redundant, obsolete and trivial information. It includes duplicated, outdated or unnecessary data that no longer provides meaningful business value and may create additional storage, retrieval or governance challenges.
Not necessarily. Digitisation should be driven by business requirements. Frequently accessed records, documents needed by distributed teams and information used within digital workflows may be strong candidates, while some inactive records may be more appropriately managed through secure physical storage.
Effective information management helps organisations understand what information they hold, control access, apply appropriate retention periods and dispose of information securely. These practices support accountability and several core UK GDPR data protection principles, including data minimisation, storage limitation and security.

Share this article