Guidelines Part A

DSS source chapter · ServiceCite reference page

5. Record Management Instructions

Documentary evidence, storage, transfer, retention and destruction of records.

Recorded v1.1 · Effective 21 November 2025Official document (opens in a new tab)

Independent reference copy. Check the official source for current guidance.

Source details, coverage and attribution

Source record

Inclusive Employment Australia Guidelines — Part A: Administrative Requirements

Australian Government Department of Social Services

Open official document (opens in a new tab)
Recorded version
1.1
Effective
21 November 2025
Publication location checked
21 September 2026

Independent web copy · not a Department publication. The recorded check is not a live check for newer Guidelines.

Official Word (opens in a new tab)

Check the official document and the applicable Deed, Work Orders, variations and Provider Portal instructions before acting.

How this copy is checked · changes and limitations
Recorded file
Automated checks compare stored source files with their recorded SHA-256 fingerprints. The fingerprint below identifies the original Word file used to prepare this copy; it does not certify the document's accuracy or currency.
Web preparation
Chapter pages are regenerated from the recorded conversion and checked for unexpected differences, conversion artefacts and broken section targets. This is a reproducibility check, not an independent review of every sentence against today's official document.
What to verify with DSS
Open the official publication to check the available version and compare the passage in its original context. ServiceCite is not endorsed by DSS and does not verify your organisation's private provider instructions.

Recorded publication details

Published
21 November 2025
Effective
21 November 2025
Source retrieved
21 September 2026
Publication location checked
21 September 2026

Attribution and web changes

Source material: © Commonwealth of Australia 2025, Australian Government Department of Social Services, Inclusive Employment Australia Guidelines — Part A: Administrative Requirements, version 1.1. Used under the Creative Commons Attribution 4.0 International licence, subject to the exclusions in the DSS copyright notice.

ServiceCite split the Word document into chapter pages and reformatted it for the web. Word artefacts, source logos, duplicate navigation and internal authoring links were removed; workflow icons were replaced with text labels; and some links were moved for accessibility. ServiceCite headings, summaries, navigation and notices are independently written. This reuse does not imply Australian Government or DSS endorsement.

Document ID
iea-guidelines-part-a
Version ID
iea-guidelines-part-a@1.1
SHA-256
1c38bae7298aedde9ae63598f24b4de2d4699417851ad7a24ced1eff3ff4ba61

Supporting Documents for this Chapter

Supporting Documents (sign-in required)

5.1 Chapter Overview

This Chapter outlines Provider obligations regarding the creation, management, retention, storage, transfer and disposal of Records created or used by Providers under the relevant Deed, and access to those Records by its Personnel and Subcontractors, in accordance with the Records management provisions in the relevant Deed. Providers must create and maintain true, complete and accurate Records in connection with the delivery of its obligations under, and in accordance with the relevant Deed and these Records Management Instructions.

For the relevant Deed, this Chapter of the Guidelines is the Records Management Instructions.

General advice on the management and storage of Records, information and data is available on the National Archives of Australia (NAA) website.

5.2 Records Framework

Under the relevant Deed, ‘Records’ means documents, information and data stored by any means and all copies and extracts of the same. Records include 3 categories:

  • Commonwealth Records are Records provided by the Department to Providers for the purposes of the relevant Deed and includes Records which are copied or derived from Records so provided.

  • Deed Records are all Records:

    • created for the purpose of performing the relevant Deed

    • incorporated in, supplied or required to be supplied along with the Records referred to in the point above, or

    • copied or derived from Records referred to in the above points, and

    • includes all Reports, as defined in the relevant Deed.

  • Provider Records are all Records, except Commonwealth Records, in existence prior to the relevant Deed Commencement Date that are:

    • incorporated in

    • supplied with, or as part of, or

    • required to be supplied with, or as part of, the Deed Records.

To the extent that Records contain Personal Information for the purposes of the Privacy Act 1988 (Cth), Providers must take reasonable steps to ensure that any Personal Information:

  • collected is accurate, up-to-date and complete, and

  • used or disclosed is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete and relevant.

5.2.1 General Records Authority 40

The General Records Authority 40 (GRA 40) sets out the requirements for the transfer of custody of Commonwealth Records to contractors providing Services under outsourcing arrangements, either on behalf of or to the Australian Government. The GRA 40 provides that, notwithstanding custody of Records that temporarily resides with the Provider, ownership of the relevant Records remains with the Australian Government.

Further information on relevant application and conditions of the GRA 40 is provided on the NAA website.

5.3 Management of Records

In accordance with the "digital by default" approach set out in the Australian Government's Building trust in the public record: managing information and data for government and community policy (effective 1 January 2021), Providers must, wherever possible and consistent with the Deed and other applicable legal requirements, create and manage Records in a secure digital format.

Providers must ensure that any digital Record is created, stored and operated in accordance with the Deed requirements (particularly the requirements in relation to Provider IT Systems and other applicable legislative provisions, including the Electronic Transactions Act 1999 (Cth).

Digital Records containing sensitive information as defined in the Privacy Act 1988 (Cth) must be kept securely. The Office of Australian Information Commissioner (OAIC) website provides information on keeping personal identifying information secure.

The Provider must ensure its:

  • Personnel, Subcontractors or Third-Party IT Vendors do not access, copy, disclose or use any:

    • Record containing any information about any employment services program Participant, or

    • Record in the Department's IT Systems containing any information about any individual (including individuals who are not Participants in any employment services program),

unless such access, copying, disclosure or use is for the purpose of:

  • providing Services to a Participant under the relevant Deed, or

  • otherwise complying with the Deed.

Where a provider offers communal computers for use by participants, the provider must ensure there is a procedure to prevent personal information being retained and accessible on the computer.

If a Provider was a Provider under the DES Grant Agreement 2018-2024 and continues to provide Services to Participants under the relevant Deed, the Provider must comply with the relevant Deed in the use and management of Records.

5.3.1 Storage of Documentary Evidence in the Department’s IT Systems

Providers must have true, complete and accurate Documentary Evidence to prove the Provider:

  • is entitled to the Payment

  • has delivered the Services relevant to the claim for Payment, and

  • has done so in accordance with the Deed and these Guidelines.

Key requirements for collecting, retaining and submitting Documentary Evidence include:

  • Providers must retain sufficient Documentary Evidence to provide proof of claims of payment

  • Providers must ensure they comply with their Privacy obligations

  • The Department may contact other relevant people, such as Employers or Participants, to verify the Documentary Evidence provided by the Provider

  • Providers must take all necessary steps to verify the truth, completeness and accuracy of Documentary Evidence, and

  • Any data entered into the Department’s IT Systems must be consistent with the Documentary Evidence held by the Provider.

(Deed reference(s): 24.4, 25, 34)

Documentary Evidence successfully uploaded to the Department’s IT Systems is retained by those IT Systems and the Provider does not need to retain a copy.

Where the Deed or these Guidelines specify that Documentary Evidence is required, Providers must either:

  • upload Documentary Evidence against the claim, or

  • link to previously uploaded Documentary Evidence.

Use of File Notes

Providers must use verifiable Documentary Evidence wherever possible. File Notes may be accepted:

  • to provide context for other verifiable evidence, such as explaining the use of a purchased item, or setting out reasons why a Special Claim was required. File Notes may not be used to substitute for verifiable evidence, such as asserting that an item was purchased, or

  • in exceptional circumstances, to record required details of a Job Placement. In this case the Provider must also upload additional file evidence (not through another File Note) demonstrating to the Department’s satisfaction:

    • verifiable evidence was sought and is not available, and

    • the exceptional circumstances that led to verifiable evidence not being available.

While a Provider must show they attempted to obtain verifiable evidence from the Employer and the Participant, inability to obtain that evidence does not of itself demonstrate to the Department’s satisfaction that there are exceptional circumstances justifying a File Note. As the Department’s satisfaction with File Notes and associated evidence cannot be checked in advance, Providers accept the risk that claims supported by File Notes may be recovered by the Department.

Where Providers manage File Notes through an approved IT System, the system must ensure File Notes have a date, time and user stamp on the entry, and these details are included in extracts or printouts uploaded to the Department’s IT Systems as Documentary Evidence.

Use of Employer or Participant Statements

These Guidelines allow, as Documentary Evidence for Outcome Fees and some related Fees, a “signed and dated written statement or email” from an Employer or Participant containing specified details. In this form of Documentary Evidence, the Employer or Participant is asserting the details in the written statement or email are correct.

A written statement containing required details is acceptable where the Employer or Participant signs and dates the page or pages containing the details.

A statement by email containing required details is acceptable where the email is sent by the Employer or Participant making the statement (including in response to a previous email) and:

  • includes within the body of the email both the required details and a statement from the person (Employer or Participant) that the details are correct

  • attaches a scanned copy of a written statement containing the required details that has been signed and dated by the person (Employer or Participant), or

  • attaches a document containing the required details and includes within the body of the email:

    • matching summary details, including the Employer and Participant names, period covered by the document and total hours and earnings specified in the document, and

    • a statement from the person (Employer or Participant) that the details in the attached document are correct.

Most Documentary Evidence must be collected from either the Participant or their Employer (or other relevant organisation). A Participant can choose to not give permission for their Provider to collect Documentary Evidence – for example, if the Participant does not wish to disclose their disability. In this case, the Inclusive Employment Australia Provider must obtain verifiable evidence from the Participant.

To support best practice:

  • Where Documentary Evidence is a hard copy (paper statement or form), whiteout must not be used, and any alterations or amendments must be signed and dated by the signatory

  • Where Documentary Evidence is an email, the Employer or Participant must be clearly identifiable as the sender in the email address and/or the signature block, and

  • Signature blocks must state the person’s name and, where applicable, the person’s contact phone number, email address, position and organisation. Signature blocks for emails do not need to include an electronic signature.

(Deed reference: 25)

5.3.2 Storage Requirements

The Provider must store all Records in accordance with these Records Management Instructions, the Department’s Security Policies, and where relevant, its Privacy Act 1988 (Cth) and Archives Act obligations.

Providers must store Records securely either on their own premises or off-site using a records storage facility in compliance with legislation covering the management of Commonwealth/Deed Records, including the Privacy Act 1988.

For Records that contain Personal Information for the purposes of the Privacy Act 1988, the Provider must take such steps that are reasonable in the circumstances to protect the information from misuse, interference and loss, and from unauthorised access, modification or disclosure. The guide to securing Personal Information can be found on the OAIC website and provides guidance on the reasonable steps entities are required to take under the Privacy Act 1988 to protect the Personal Information.

Providers must ensure the Department can access Records by retrieving the Record (including, if stored digitally, by retrieving the digital copy and if relevant printing it) and providing it to the Department upon request.

Providers are required to store digital Records in accordance with the Department’s Security Policies, including the Security Policy for External Employment Service Providers and Users available on the Provider Portal.

General advice on the management and storage of Records is available on the NAA website.

Providers must ensure physical Records are protected from:

  • unauthorised addition, alteration, removal or destruction

  • use outside the terms of the relevant Deed

  • for Records containing Personal Information, incidents of privacy, and

  • unauthorised access including inappropriate ‘browsing’ of Records.

Physical Records containing sensitive information, as defined in the Privacy Act 1988, must be kept in lockable cabinets.

5.3.3 Control of Records

Providers must be able to locate and retrieve Records about a Participant if requested. Providers must inform their Account Manager if they become party to legal action in relation to their previous or current delivery of Services, so that arrangements for the appropriate retention of Records can be organised.

Providers must store Records in such a way that all Records relevant to a request under the Freedom of Information Act 1982 (Cth) or under APP 12 of the Privacy Act are able to be located and retrieved efficiently. This includes being able to retrieve email Records and Records created by, or sent to, individuals who have ceased working for Providers.

Records Register

The Provider must maintain an up-to-date register of the Records (digital and physical) held by the Provider and any Third-Party IT Vendor and make this register available to the Department upon request. The register should contain sufficient information to clearly identify the content and location of a Record.

The Records register must be created and managed in a digital format (ideally Microsoft Excel or equivalent or a comma or tab delimited format) that the Department’s IT Systems can read. Providers may wish to identify on the Records register whether Records are:

  • Priority — pertaining to current or pending legal action, complaint, injury or possible claim for compensation

  • Active — current Participants

  • Inactive — former Participants

  • Damaged — e.g. paper Record affected by water

  • Destroyed (whether authorised or accidental) — e.g. paper Record burnt

  • Transferred — Participant and Record transferred to another Provider, and

  • Returned — have been returned to the Department.

5.4 Movement of Records

The Provider must not, and must ensure that its Personnel do not:

  • take, transfer, transmit or disclose any Records relating to the Services, or

  • allow any Records relating to the Services to be taken, transferred, transmitted, accessed or disclosed

outside of Australia without the Department's prior written consent.

Further, the obligation set out above applies in respect of taking, transferring, transmitting, accessing or otherwise disclosing any Records relating to the Services outside of Australia by the Provider:

  • within the Provider's Own Organisation, and

  • to any third Party, including to any Subcontractor.

5.5 Transfer of Records

Providers must only transfer the Records in accordance with these Records Management Instructions or as otherwise directed by the Department.

5.5.1 Transfer between Providers

Records (digital or physical) must only be transferred between Providers in accordance with the relevant Deed and these Records Management Instructions, and where it is required to continue providing Services to Participants. Records must be transferred securely by Providers, as soon as possible or within 28 days of a request to transfer Records. A list of all Records being transferred should be provided to the receiving Provider.

The transfer of Records containing Personal Information and Protected Information must be in accordance with the Privacy Act 1988 and the Social Security (Administration) Act 1999 (Cth).

When a Provider is transferring Records between its Sites, to another Provider, for storage or secure destruction or to the Department, it remains the Provider’s responsibility to ensure the Records are secure during the transfer process.

5.6 Data Migration

Data migration is the process of transferring data from one application or format to another. It may be required when implementing a new application.

Providers must ensure any migration activities include validation of the migrated data quality to ensure that no data is lost and the data continues to be fit for its intended purpose.

When migrating information Providers must ensure:

  • the migration is planned, documented and managed

  • pre and post migration testing proves that authentic, complete, accessible and useable Records can and have been migrated, and

  • source Records are kept for an appropriate length of time after the migration to enable confirmation that the migration has been successful. Determination of the specific retention period must be based on an organisational risk assessment.

Providers must note that the information transferred to the Department will be imported into the Department’s official recordkeeping system and appropriate classification will be applied at the time of import.

5.6.1 Data Security Considerations

Providers are responsible for ensuring Records and any data contained in those Records are secure and appropriately accessed. Providers should ensure:

  • those who access Sensitive or Protected Information have an appropriate security clearance and a need to know that information

  • access (including remote access) to supporting IT systems, networks, infrastructure and applications is controlled

  • information in systems is continuously safeguarded from cyber threats, and

  • administrative privileges such as logon and administrator privileges are restricted.

Providers should refer to the digital Information Assurance / IT Security Compliance guide on the Department of Employment and Workplace Relations' website for more information.

(Deed reference(s): 42.17 - 42.23)

5.6.2 Decommissioning of Systems

When decommissioning any internal systems and migrating Records to a new or updated system, Providers should ensure processes are in place to prevent the loss, destruction or corruption of those Records. If Records have been identified for destruction a Provider must obtain the consent of the Department prior to the destruction, unless:

  • the Record is not a Record created in accordance with the Deed

  • the Record has been successfully uploaded into the Department’s IT Systems in accordance with the Deed, or

  • otherwise specified by the Department in writing.

If in doubt, the Provider should consult with the Department via the Account Manager.

Digital preservation requires a proactive program to identify Records at risk and take necessary action to ensure their ongoing viability. To achieve this, the Providers must consider the lifecycle of the information versus the lifecycle of the system and have plans in place to preserve information as needed. Regular and planned migration helps avoid obsolescence and ensures information continues to be accessible and useable.

5.7 Breaches and Inappropriate Handling of Records

5.7.1 Reporting Requirements

Providers must report to the Department all incidents involving Records, including unauthorised access, damage, destruction, loss or theft. Where the Records contain or possibly contain Personal Information of Participants, Providers must follow the Privacy incident reporting process set out in Chapter 6: Privacy.

5.7.2 Rectification Requirements

For all incidents involving the misuse, interference, loss, unauthorised access, unauthorised use, unauthorised disclosure, damage, destruction, loss or stealing of Records (digital or physical), Providers must:

  • immediately Notify the Department, giving details of the actual, suspected or possible Breach

  • immediately make every effort to recover lost or damaged Records (e.g. retrieving or photocopying Records), including if required, arranging and paying for the services of expert contractors (e.g. disaster recovery or professional drying services)

  • not destroy damaged Records without prior authorisation from the Department

  • inform Participants if any Personal Information has been lost or is at risk of being publicly available

  • where relevant and if necessary, reinterview Participants to recollect information, and

  • review relevant policies and procedures to ensure their adequacy in future.

The Department may make recommendations to the Provider to mitigate the risk of recurrence of the incident.

(Deed reference(s): 46)

5.7.3 Notifiable Data Breaches

If a Provider becomes aware there are reasonable grounds to suspect there may have been an eligible data Breach in relation to any Personal Information held by the Provider in its performance of the Services under the Relevant Deed, the Provider must, as soon as possible and in any event within two calendar days, notify the Department as set out in the Deed.

Please refer to the Chapter 6: Privacy for further information on responding to a Notifiable data Breach.

(Deed reference(s): 45.6 - 45.7)

5.8 Retention of Records

All Records must be retained by the Provider for a period of no less than 7 years after the creation of the Record, unless otherwise specified in the Relevant Deed or these Records Management Instructions or advised by the Department in accordance with the Archives Act.

For certain Records, specific retention periods may be applicable in accordance with Employment Services Records Disposal Authority 2003/00330307, Employment Services Records Authority 2009/00179260 (RA) and the General Records Authority GRA 33 Accredited Training 2012/00579704 (GRA 33).

Records with a longer retention period should be maintained by the Provider until they no longer require them and then be returned to the Department for ongoing management. Records in storage arrangements that are retrieved should be converted to digital format and the physical record destroyed.

Providers have the discretion to retain Records longer than the minimum periods required by law but must not destroy Records prior to the expiration of the relevant retention periods. In addition, the Department may direct some Records to be retained for longer periods, for example, in the case of Records required in any legal action.

Providers must review Records that have reached the minimum retention period before destroying them in accordance with these Records Management Instructions.

If a relevant Record has reached the required minimum retention period but, for example, the Provider has knowledge of a legal action or potential legal action, the Provider must re‑sentence the Record and inform the Account Manager. Sentencing is the process for identifying the minimum retention period for a Record by assessing them against the classes specified in the relevant Records Authority.

At the Completion Date, the Provider must manage all Records in accordance with these Records Management Instructions, the Relevant Deed or as otherwise directed by the Department.

Retention periods are determined with reference to NAA accredited records authorities.

5.9 Destruction of Records

The Provider must:

  • not destroy or otherwise dispose of Records, except in accordance with the Deed, these Records Management Instructions or as otherwise directed by the Department, and

  • provide a list to the Department of any Records that have been destroyed, as directed by the Department.

Records must not be destroyed where the Provider is aware of current or potential legal action or where the Records are subject to a Disposal Freeze or Retention Notice issued by the NAA, even if the minimum retention period has been reached. These Records are priority Records and must be retained in accordance with requirements set out for priority Records in Control of Records section. A Provider must also comply with any Direction from the Department not to destroy Records. Providers must only destroy Records that have reached the minimum retention period and following the review process outlined in Retention of Records section.

Providers must maintain a list of destroyed Records which must be supplied to the Department upon request. This list must also be retained by the Provider in accordance with the applicable retention period or as directed by the Department.

Refer to Retention of Records section for information on retention periods.

5.9.1 Methods of destroying Records

When Providers destroy Records, they must use a method that ensures the information is no longer readable and cannot be retrieved.

Digital Records

It is the Provider’s responsibility to ensure all digital Records are identified and removed from their systems and destroyed. Methods of destroying digital Records include:

  • file shredding

  • degaussing — the process of demagnetising magnetic media to erase recorded data

  • physical Destruction of storage media — such as pulverisation, incineration or shredding, and

  • reformatting — if it can be guaranteed the process cannot be reversed.

To ensure the complete Destruction of a digital Record, all copies should be found and destroyed. This includes removing and destroying copies contained in system backups and off-site storage.

Deletion is not destruction and does not meet the requirements for Destruction of Australian Government Records. When digital Records are deleted, it is only the pointer to the Record (such as the file name and directory path) that is deleted. The actual data objects are gradually overwritten in time by new data. However, until the data is completely overwritten, there remains a possibility that the information can be retrieved.

Physical Records

Providers must ensure physical Records are destroyed using one of the following methods:

  • pulping – transforming used paper into a moist, slightly cohering mass

  • burning – in accordance with relevant environmental protection restrictions, and

  • shredding – using crosscut shredders (using either A or B class shredders).

If Destruction of physical Records is undertaken at an off‑site facility, then a certificate of destruction including details of the Records destroyed and appropriate authorisation must be obtained and retained by the Provider.

5.9.2 General Records Authority 30

Records may be damaged beyond repair because of a disaster, emergency, or other unforeseen circumstance, as defined in GRA 30.

If a Provider considers that a Record or Records have been damaged in line with GRA 30, it must not destroy the Record(s) unless and until the Department provides written authority for the destruction of the Record(s). Providers must notify the Department as soon as possible following the Record(s) being damaged, providing at a minimum:

  • photographic evidence of the damaged Record(s)

  • do any of the damaged Record(s) need to be retained permanently

  • information about the circumstances causing the damage, including whether:

    • the Record(s) in their damaged state pose a health hazard, and

    • any Record(s) were able to be retrieved following the circumstances causing the damage and if so, how this retrieval will be managed.

  • information about the Record(s), including:

    • the number affected, and if approximated, how this number was determined

    • their content

    • their classification, and

    • whether they had been digitised

  • information about how the damaged Record(s) are proposed to be destroyed, and

  • any other information the Provider considers relevant to a request to destroy the Record(s).

5.9.3 General Records Authority 31

Records as defined in the Deed are Commonwealth Records for the purposes of the Archives Act 1988 (Cth).

Subject to certain exclusions and conditions, the NAA provides permission for the destruction of Commonwealth Records created on or after 1 January 1980 under General Records Authority 31 -Destruction of source or original Records after digitisation, conversion or migration (GRA 31) where those Records have been converted from hard copy to digital form.

Providers, as ‘authorised agents’ of the Department, must comply with the requirements of GRA 31.

Providers must retain the original copy of a paper Record for the relevant retention period and return it to the Department in accordance with this Chapter, regardless of whether it has also been converted to digital form, if required to do so under relevant Deed/s, Guidelines or if directed by the Department. Further explanation of the relevant conditions and exclusions for GRA 31 is available on NAA website.