Fire risk assessment: the document the responsible person signs
A fire risk assessment is a legal duty for anyone controlling premises. What it covers, how often to review it, and the findings that get ignored until an inspection.
An information asset register lists the data a business depends on, not the machines it sits on. Auditors and regulators both start there.
An information asset register lists the information a business holds and depends on — customer records, contracts, source code, financial data, HR files — with an owner, a location, a sensitivity classification and a retention period for each. It is not an inventory of laptops and servers; those belong in a different register, and confusing the two produces a list that answers neither question.
Its usefulness comes from being the first thing you reach for in three different situations: an information security assessment, a privacy question about what is held and why, and an incident where the first thing anyone needs to know is what was affected.
The dependency column is what turns a list into a risk tool. It is also the column that reveals the assets nobody had thought about — the spreadsheet that reconciles two systems, the mailbox that holds the only copy of supplier agreements.
ISO 27001 expects an inventory of assets with owners; privacy regimes require a record of processing activities that overlaps heavily with it; and customer security questionnaires ask for it directly. Keeping one register and deriving those views is far cheaper than maintaining three lists that quietly diverge.
Build it at the level of business processes rather than files. A register with four hundred entries will not be maintained; one with thirty, each owned by a named role and reviewed annually, survives contact with a real organisation and answers the same questions. Keep it separate from the fixed asset register: different owners, different review cycles.
Because the register is a table with owners, dates and links to evidence, it belongs somewhere versioned rather than in a shared file. Ettex Records keeps entries with their owners, classifications and review dates, so the state of the register on a given date can be shown — which is what an assessment asks for. What the classifications mean, and which retention applies, remain policy decisions the organisation has to make.
The information register lists data and its owners; the IT register lists hardware and software. Security assessments usually want both, and they answer different questions.
The standard expects assets associated with information to be identified and owned. A register is the normal way to demonstrate that, though the format is not prescribed.
They overlap where personal data is involved. Many organisations maintain one register and generate the processing record from it rather than keeping two.
At least annually, and whenever something material changes — a new system, supplier, data category or retention decision.
A fire risk assessment is a legal duty for anyone controlling premises. What it covers, how often to review it, and the findings that get ignored until an inspection.
An import declaration decides the duty, the VAT and how long the container sits. What the customs authority needs, and which of it has to come from your supplier.
A grievance procedure is judged on how it was run, not on whether the complaint was upheld. The stages, the record, and the mistakes that cost tribunals.