Skip to content

REF / GOVERNANCE

EDMS security and compliance, mapped to the evidence

No product can make an organisation compliant. What a system can do is provide the controls your obligations require, and produce evidence that those controls were in force on the date somebody asks. This page maps each obligation to the control that satisfies it.

REF / CONTROLS

The control surface

Inherited from Microsoft's enterprise platform and configured against your policy. Most of it your security team can verify from Microsoft's own documentation.

Identity

Microsoft Entra ID single sign-on, multi-factor authentication, conditional access by device compliance, location and risk, and legacy authentication blocked.

Access control

Role-based permissions modelled on the organogram, delegated administration by department, and restriction available down to an individual document.

Information protection

Purview sensitivity labels with encryption that travels with the file, data loss prevention over personal and financial identifiers, and dynamic watermarking on view and print.

Audit

Immutable logging of views, edits, downloads, prints, permission changes and deletions, retained on an independent schedule and not editable by administrators.

Records integrity

Declared records cannot be altered or deleted by any user, including global administrators, until retention expires and disposition is reviewed.

Residency

Microsoft cloud region of your choice, a dedicated Azure region, or entirely on premises where law or policy requires data to remain in country.

Availability

Documented recovery point and recovery time objectives, replicated storage, and a restore procedure that is actually run, with the result recorded.

Legal hold

Content frozen in place for litigation, investigation or audit, searchable under hold and exportable as a defensible evidence set.

REF / OBLIGATIONS

Obligation, control, evidence

Written so it can be lifted into a compliance schedule or an audit committee paper. Where a requirement needs a decision from you rather than a setting from us, it says so.

REG-01

Data Protection Act, 2019 (Kenya)

Any organisation processing personal data in Kenya
Requirement How the system satisfies it
Process personal data lawfully and limit access to those who need it Role-based access control through Microsoft Entra ID, restrictable to a single document, with permissions modelled on the organogram and delegated to departmental administrators.
Secure personal data against unauthorised access, loss or damage TLS 1.2 or above in transit and AES-256 at rest, multi-factor authentication, conditional access by device and location, and optional customer-managed keys.
Retain personal data no longer than necessary Retention labels applied automatically by document type, with disposition review and evidenced destruction at end of life.
Identify and protect sensitive categories of personal data Microsoft Purview sensitivity labels and data loss prevention policies that detect national ID numbers, tax PINs, bank details and health information.
Demonstrate compliance and respond to data subject requests Search across the repository scoped to a data subject, an immutable audit trail of every access, and standing compliance reports.
Detect and report personal data breaches Audit alerts on anomalous access and bulk download, with the log detail required for a breach notification.
REG-02

Public Archives and Documentation Service Act (Cap. 19)

Ministries, county governments, state corporations and other public bodies
Requirement How the system satisfies it
Maintain proper control and custody of public records A functional file plan with reference numbering, volumes and folios, and electronic file movement that records custody without the file leaving the system.
Apply approved retention and disposal schedules Retention schedules configured per record class, applied automatically, with event-based triggers such as contract expiry or end of employment.
Obtain authority before destroying public records Disposition review queued to a named records officer, with approval recorded and a destruction certificate produced as evidence.
Transfer records of enduring value to the national archive Archival transfer packaging that preserves file references, metadata and audit history.
REG-03

ISO 15489 — Records management

The international standard for managing records
Requirement How the system satisfies it
Records must be authentic, reliable, complete and usable Record declaration makes content immutable, version history proves completeness, and the audit trail establishes provenance.
Classification against a business classification scheme Function, activity and transaction modelled as content types against your own classification scheme.
Controlled disposition Retention, review and disposal as a managed process with documented authority at each step.
Metadata maintained throughout the record's life Metadata is bound to the record, carried through versions, and preserved on archival transfer.
REG-04

Public Procurement and Asset Disposal Act

Public bodies and organisations subject to public procurement rules
Requirement How the system satisfies it
Retain procurement records for the statutory period Procurement content types carry a retention schedule set to the statutory term, applied at the point of filing.
Produce procurement records on demand for audit Standing reports and security-trimmed search across tender documents, evaluation reports, contracts and disposal records.
REG-05

Donor and grant conditions

NGOs, INGOs and development programmes
Requirement How the system satisfies it
Retain grant records for a defined period after project close Event-based retention that starts its clock at project close, configured per grant and per donor.
Produce procurement and expenditure evidence during audit Evidence indexed against grant, budget line and procurement reference, exportable as a complete audit pack.
REG-06

GDPR and international data protection

Organisations handling EU personal data, and donors who require it
Requirement How the system satisfies it
Lawful basis, purpose limitation and data minimisation Content types carry a defined purpose and retention position, so personal data is not held indefinitely by default or repurposed silently.
Right of access, rectification and erasure Search scoped to a data subject across the repository, with export for a subject access request and controlled deletion where erasure applies and no overriding retention obligation exists.
Records of processing activities The file plan, retention schedule and audit log together evidence what is held, why, for how long and who has accessed it.
Security of processing and breach notification Encryption in transit and at rest, role-based access, DLP over personal identifiers, and audit alerting with the detail a 72-hour notification requires.
International transfers Data residency selected at design stage, with the option of a specific Microsoft cloud region, a dedicated Azure region, or on-premises hosting.
REG-07

ISO 9001 and ISO 45001 document control

Any organisation operating a certified management system
Requirement How the system satisfies it
Documents approved before issue and reviewed on schedule Content approval with publishing control, and scheduled review that routes to the document owner before expiry.
Current versions available at point of use, obsolete versions withdrawn Only the approved current revision is served; superseded revisions are watermarked and retained for the record only.

This mapping describes how the platform supports each obligation. It is not legal advice, and it does not replace your own data protection impact assessment, retention schedule approval or records survey — all three form part of the implementation.

REF / DISPOSAL

What happens at the end of a record's life

The stage most document systems leave undefined, and the first one an auditor will ask you to walk through.

  1. STEP 01

    Retention applied

    A label attaches on filing, based on the record class and any event trigger such as contract expiry.

  2. STEP 02

    Record declared

    The content becomes immutable. No user, including a global administrator, can alter or delete it.

  3. STEP 03

    Retention runs

    The record remains available and searchable throughout, under normal access controls.

  4. STEP 04

    Disposition review

    At expiry it queues to a named records officer rather than deleting itself. Nothing is destroyed automatically.

  5. STEP 05

    Evidenced disposal

    Approved destruction produces a certificate and an audit entry; records of enduring value transfer to the archive instead.

REF / QUESTIONS

Asked most often by security and compliance teams

Does it comply with the Data Protection Act, 2019?

The platform provides the controls the Act requires an organisation to have: access limited by role and logged, encryption in transit and at rest, sensitivity labelling and data loss prevention over personal data, retention limits applied automatically so data is not held longer than necessary, and an audit trail that lets you demonstrate all of it. Compliance is a property of the organisation rather than the software, so implementation includes mapping your retention schedule and access model to your obligations — but the technical controls a Data Commissioner would ask about are in place and evidenced.

Where is our data stored?

Wherever your policy requires. In a Microsoft 365 deployment, data resides in the Microsoft cloud region selected for your tenant. Where regulation or policy requires data to remain in country, the system can be deployed on SharePoint Server in your own data centre, or in a dedicated Azure region. Data residency is decided during the design phase and documented in the solution design, not assumed.

Is our content used to train AI models?

No. The AI capabilities run on Microsoft services within your own tenant boundary, and Microsoft commits that customer content processed by Microsoft 365 Copilot and its content-processing services is not used to train foundation models. Your documents remain subject to your own tenant permissions: the AI can only ever see what the requesting user is already entitled to see.

Can administrators delete records or alter the audit trail?

No. Records declared under a retention label cannot be edited or deleted by any user, including global administrators, until the retention period expires and a reviewed disposition takes place. The audit log is retained on its own independent schedule and is not editable from within the system. This separation is what allows the audit trail to be treated as evidence rather than as a convenience feature.

REF / NEXT STEP

Send us your security questionnaire

We complete vendor security assessments, data protection impact assessments and architecture reviews as part of the sales process rather than after award.