- Services ServicesServices --
-
- Digital Solutions
- Document Scanning and Indexing
- Digital Contract Management
- Digital Invoice Processing
- Digital Mailroom
- Employee Management System (HRDMS)
- Visitor Management System (VIZIO)
- Enterprise Content Management (ECM)
- Information Consulting
- Employee Onboarding
- Central Know Your Customer Automation (CKYC)
- Digital Signatures
- Fixed Asset Management
-
- Case Studies
- Insight
- Customer Centre
The mid-year pause is over. Teams are refocusing, projects are gathering pace and attention is turning to the targets that need to be delivered before year-end.
But while your people may be ready for the second half of the year, is your information? And how do you know if your business information is ready for H2?
Quick answer: your business information is ready for H2 when it is organised, accessible, secure, appropriately retained and easy for authorised employees to find and use.
A simple information health check can reveal outdated records, access risks, inefficient processes and information gaps before they create bigger operational or compliance problems.
TL;DR: Your H2 information health check
Ask yourself:
- Do we know what information we hold?
- Is it stored in the right place?
- Can only the right people access it?
- Are we retaining information for the right amount of time?
- Can employees quickly find the correct version?
- Could we recover important information if something went wrong?
If any answer is unclear, it is worth investigating now.
What is an information health check?
An information health check is a structured review of how information is created, stored, accessed, retained and disposed of across an organisation. It helps businesses identify unnecessary data, weak processes, security risks and opportunities to improve the way employees work with both physical and digital information.
Think of it as a mid-year check-up for your information estate.
The objective is not to reorganise every document your organisation owns. It is to identify where information is creating friction or risk and prioritise the improvements that can make the biggest difference during the remainder of the year.
1. Do you know what information your business holds?
Start with visibility.
Business information rarely lives in one neat location. It may be spread across:
- physical archives and filing cabinets
- employee desktops and shared drives
- Microsoft Teams or SharePoint
- email inboxes
- cloud platforms
- legacy databases
- USB drives and other storage media
- third-party systems
If nobody has a clear overview of what exists and where it is held, managing that information securely and efficiently becomes difficult.
This is particularly important when personal information is involved. South Africa’s Protection of Personal Information Act (POPIA) establishes requirements for the lawful processing and protection of personal information, making visibility over what information an organisation processes an important part of effective information governance.
Your H2 health check does not necessarily require an organisation-wide audit. Start with departments, systems or information types where poor information management would have the greatest impact.
Ask: Could we confidently explain what important information we hold, why we hold it and where to find it?
If not, creating an information inventory or map is a useful starting point.
2. Is your information stored in the right places?
Knowing that information exists is only half the battle. Next, consider whether it is stored appropriately.
A contract saved exclusively in someone’s inbox may technically be retrievable, but that does not make the inbox the best place to manage it.
Likewise, frequently accessed documents sitting in boxes in an office storeroom may create unnecessary delays, while inactive physical records taking up valuable workspace could potentially be moved to secure off-site storage.
A healthy information environment uses the right storage method for the information involved.
That could mean:
Active records: Easily accessible to authorised employees who regularly need them.
Inactive records: Securely stored, indexed and retrievable when required.
High-use physical documents: Considered for scanning and digitisation.
Sensitive archives: Protected through appropriate records management and secure storage.
Crown Information Management South Africa provides both physical records management and document scanning and indexing services, allowing organisations to take a hybrid approach rather than assuming every record needs to be managed in the same way.
The aim is not necessarily to make everything digital. It is to create an information environment where physical and digital records are managed deliberately rather than by default.
3. Can the right people access the right information?
Access that is too restrictive slows people down. Access that is too broad creates unnecessary risk.
The question for H2 is simple: do your current permissions still reflect the way your organisation operates today?
Teams change. Employees move departments. Contractors finish projects. People leave businesses. New platforms and systems are introduced.
Permissions that were appropriate at the beginning of the year may no longer be appropriate several months later.
Under section 19 of POPIA, responsible parties are required to take appropriate, reasonable technical and organisational measures to protect the integrity and confidentiality of personal information and prevent loss, damage, unauthorised destruction or unlawful access. The Information Regulator also highlights the need to identify foreseeable risks, maintain safeguards and regularly verify that those safeguards are working.
Consider reviewing:
- access for employees who have changed roles
- accounts belonging to former employees
- shared folders with large user groups
- external or contractor permissions
- access to confidential HR, financial or customer information
- administrator and privileged accounts
A permissions review can help ensure information remains accessible to the people who need it without becoming unnecessarily exposed.
4. Are you keeping information you no longer need?
One of the easiest information management habits to develop is also one of the most problematic:
“Keep it, just in case.”
Over time, businesses can accumulate redundant, obsolete and trivial information, commonly referred to as ROT data.
The challenge goes beyond digital clutter. Holding unnecessary information can make searches harder, increase storage requirements and complicate information governance.
It may also create compliance risks.
POPIA states that records of personal information should generally not be retained for longer than necessary to achieve the purpose for which the information was collected or processed, subject to specified exceptions.
As part of your H2 review, ask:
- What information has reached the end of its required retention period?
- What duplicate or outdated versions are being retained?
- What records have no clear business, legal or regulatory purpose?
- Are retention policies actually being followed?
- Is information being disposed of consistently and securely?
If the answer is “we don’t know”, a retention and disposal review should move up the priority list.
Where information has legitimately reached the end of its lifecycle, secure destruction can help businesses ensure sensitive information on paper, devices and other media is disposed of appropriately.
5. Can employees find the right information quickly?
Information can be secure and compliant but still cause problems if nobody can find it.
Common warning signs include:
- employees creating duplicate documents because they cannot find the original
- multiple versions of the same file circulating
- inconsistent file naming
- important approvals taking place through lengthy email chains
- teams relying on individual employees to locate information
- manual processes repeatedly slowing work down
- employees spending unnecessary time searching across different systems
Good information management should make the correct information easier to find, trust and act upon.
That might require better indexing and metadata, clearer naming conventions, document management technology or automated workflows.
The goal is to move from simply storing information to making information work for the business.
For organisations where repetitive document-heavy processes are creating bottlenecks, technologies such as digital document management and workflow automation can help centralise information and reduce manual administration.
Crown Information Management South Africa’s digital solutions cover the document lifecycle from capture and management through to automation, retention and disposal.
6. Could you recover critical information if something went wrong?
Finally, test resilience.
What would happen if an employee accidentally deleted an important folder? A key system became unavailable? A device failed? A cyber incident temporarily prevented employees from accessing files?
Having backups and recovery procedures is important. Knowing that they actually work is even better.
Start by identifying your most business-critical information and asking:
Where is it stored?
Who is responsible for it?
Is it protected?
Is there another copy?
How quickly could we recover it?
This also links back to POPIA. Organisations processing personal information must put reasonable measures in place to identify foreseeable internal and external risks and safeguard information against loss, damage and unauthorised access.
If your recovery procedures have not been reviewed or tested recently, H2 provides a useful opportunity to address the gap before the year-end rush.
Make information one less thing to worry about in H2
There is still plenty of time left in the year to improve how your organisation manages information.
And improvement does not need to begin with a huge digital transformation programme.
Start with one troublesome repository. One retention schedule. One paper-heavy process. One department struggling to locate documents.
Good information management can also support a wider compliance framework. In South Africa, that can include obligations under POPIA, the Promotion of Access to Information Act (PAIA) and sector-specific records requirements, depending on the organisation and information involved.
At Crown Information Management South Africa, we help organisations understand, organise, protect and unlock value from their information throughout its lifecycle. From records management and secure storage to digitisation, digital solutions and secure destruction, the right information strategy can make everyday work simpler while supporting stronger governance and compliance.
Your business is back. Make sure your information is ready to keep up.
Talk to Crown Information Management about an information management approach that supports your priorities for the remainder of H2 and beyond.
Contact UsFAQs - information health checks
An information health check reviews how an organisation creates, stores, accesses, retains and disposes of information. It identifies risks, inefficiencies and opportunities to improve records and document management.
The Protection of Personal Information Act, or POPIA, is South Africa's primary data protection legislation. It establishes conditions for the lawful processing of personal information and requirements for protecting that information, making effective information management an important part of an organisation's compliance approach.
There is no single review schedule that will suit every organisation. Businesses should monitor information management continuously and conduct more structured reviews when systems, teams, regulations or business processes change. Mid-year and year-end reviews can provide useful opportunities to identify emerging risks and priorities.
ROT stands for redundant, obsolete and trivial information. It includes duplicated, outdated or unnecessary data that no longer provides meaningful business value and may create additional storage, retrieval or governance challenges.
Not necessarily. Digitisation should be driven by business requirements. Frequently accessed records, documents required by distributed teams and information used in digital workflows may be strong candidates, while some inactive records may be more appropriately managed through secure physical storage. Crown Information Management South Africa supports both approaches.
Effective information management helps organisations understand what personal information they process, control access to it, apply appropriate retention periods and dispose of it securely. These practices can support compliance with POPIA's requirements around responsible processing, retention and security safeguards.