1. Definition
The Record-Keeping control type refers to the systematic creation, storage, protection, and use of safeguarding records — including intake files, training completions, behavior breaches, incident reports, audits, budgets, stakeholder consultations, and leadership reports.
Record-keeping is not just about compliance. In SAM, records are the evidence base that demonstrates a living system: what was decided, why it was decided, how it was implemented, and what was learned. Without reliable records, an organization cannot prove accountability, detect patterns, or show return on its safeguarding investments.
Examples of Record-Keeping Controls
- Centralized safeguarding records system with clear access controls.
- Standardized forms for incidents, breaches, intake, audits, and reviews.
- Version control for safeguarding policies and training materials.
- Secure digital storage with retention and destruction protocols.
- Clear chain of custody for sensitive records (e.g., abuse allegations).
- Integration of records across controls (e.g., behavior breach → incident response → training update).
2. Purpose of Record-Keeping Controls
The purpose of record-keeping is to:
- Provide proof of safeguarding actions, decisions, and learning.
- Enable pattern detection across incidents, behaviors, or audit findings.
- Support accountability to leadership, regulators, funders, and families.
- Establish defensibility for the organization and staff by showing that reasonable, risk-informed steps were taken at the right time
- Protect staff and organizations from unfounded allegations through documented evidence.
- Ensure lessons are captured and transferred into continuous improvement.
It reduces uncertainties such as:
- How can we show what was done, when, and by whom?
- How do we know if risks are recurring or escalating?
- How do we prove safeguarding is being managed, not just promised?
- How do we defend our decisions and actions if they are challenged?
3. What Makes Record-Keeping Fit-for-Purpose?
A. Strategic Fit (Alignment with Swans)
- Records provide evidence that safeguarding is real and mission-critical.
- Transparency in records reinforces trust with stakeholders.
- Enables ROI analysis by linking investment in controls to reduced incidents or risks.
B. Operational Fit (Seven Operational Criteria)
| Criterion | Applied to Record-Keeping |
|---|---|
| Operational Safety & Security | Records stored securely; confidentiality protected. |
| Behavioral Alignment | Breach and incident records reinforce codes of conduct. |
| Supervision & Oversight | Records are reviewed by managers and safeguarding leads. |
| Information & Communication | Records provide clarity about actions, outcomes, and responsibilities. |
| Resources & Capacity | Record-keeping demonstrates that safeguarding is integral to program delivery. |
| Alignment with Objectives | Record-keeping demonstrates safeguarding is integral to program delivery. |
| Cultural & Contextual Fit | Records are accessible and appropriate across cultural and legal contexts. |
C. Lived Experience Fit (Seven Universal Criteria)
| Criterion | Applied to Record-Keeping |
|---|---|
| Clarity | Staff know what to record, how, and why. |
| Ownership | Record-keeping treated as safeguarding, not bureaucracy. |
| Confidence | People believe records are handled fairly and securely. |
| Fit | Processes align with day-to-day safeguarding practice. |
| Alignment | Records connect across controls (intake, training, incidents). |
| Consistency | The system evolves with new risks, technology, or legal standards. |
| Adaptiveness | System evolves with new risks, tech, or legal standards. |
4. Cross-Team Responsibilities
| Stage | Teams Involved | SAM Risk Considerations |
|---|---|---|
| Setting standards | Safeguarding, Legal, Compliance | Define what must be recorded, by whom, and how long it’s kept. |
| Collecting data | HR, Programs, Supervisors, Staff | Ensure intake, training, behavior, and event records are complete. |
| Securing storage | IT, Facilities | Protect records (digital + physical) with strong security. |
| Reviewing records | Supervisors, Safeguarding | Detect patterns, escalate risks, track compliance. |
| Reporting insights | Jigsaw Team, Leadership | Use records to learn, inform budget, change management, and audits. |
| Retention/destruction | Compliance, Legal | Follow laws, protect confidentiality, avoid unnecessary exposure. |
5. Common Strengths and Gaps
Strengths
- Many organizations already have incident forms or HR files.
- Some use digital systems for training and vetting.
Gaps
- Records scattered across departments → no integrated view.
- Inconsistent quality or completeness.
- Staff are unsure what to record or are fearful of consequences.
- Weak security of sensitive records.
- Lessons captured but not applied to improvement.
6. Signals of a Strong Record-Keeping Control Set
- Records are centralized, consistent, and secure.
- Staff describe record-keeping as meaningful and useful, not just admin.
- Managers regularly review records to identify patterns.
- Records link across controls (e.g., training gaps identified from behavior breaches).
- External stakeholders see clear evidence of safeguarding action and learning.
7. Opportunities for Improvement
- Move from fragmented files to a central safeguarding records system.
- Provide role-specific guidance: “What you must record, and why it matters.”
- Train staff to view record-keeping as a safeguard, not a bureaucratic burden.
- Link record-keeping to both short-term monitoring (implementation) and long-term reviewing (appropriateness).
- Record map to show what is collected, by whom, and where it is stored.
8. How Record-Keeping Is Tracked in Jigsaw
- Record audits test completeness, security, and consistency.
- Short-term monitoring: spot checks of new records for accuracy and completeness.
- Long-term reviewing: annual assessment of whether records remain relevant, secure, and useful for safeguarding.
Bottom line: In Jigsaw, record-keeping is not paperwork — it is a control in itself. It provides the evidence base for accountability, learning, and ROI. Just as importantly, it provides defensibility: the ability to show regulators, funders, insurers, and courts that the organization acted responsibly and transparently. Without strong records, an organization cannot defend itself, even when it has acted well.
