What Counts?

What Counts?

By TrailBlazer Consulting, LLCBusinessTechnologyEducationHow ToManagement
Download on the App Store

What Counts? episodes

  • Training vs Automation in Information Governance
    Training vs automation in information governance is a risk decision, not a technology preference. In this lightning round, Lee Karas and Maura Dunn explain why training alone rarely holds. At maturity level one, a program works only when individual people make heroic efforts. However, manual filing breaks down fast, because "I'll file that tomorrow" rarely turns into done. For a small company with low regulatory and litigation risk, training is often the right answer since it costs little. By contrast, a global company in a heavily regulated industry cannot afford inconsistent records. Then comes the regulator who called one records response "not good enough" while staff searched fifty years of paper. Finally, a pipeline example shows why weld inspections need a process that captures proof. So before you weigh training vs automation in information governance, start with risk assessment and policy.
    ## Training vs Automation in Information Governance: Episode Chapters
    0:00 Training vs automation in information governance
    0:45 When records programs ran on training
    1:22 People vs process and the maturity model
    2:17 Why manual filing breaks down
    3:11 When training is the right answer
    4:09 When your risk profile calls for automation
    5:37 What happens when a regulator asks for proof
    7:20 The cost of automation vs the cost of risk
    7:45 Pipeline welds and materials traceability
    9:13 Why risk assessment and policy come first
    This episode is brought to you by TrailBlazer Tracker.
    The contract you cannot find is also the contract that auto-renews without you. Tracker reads your PDFs, Word files, and scanned paper, pulls out renewal, cancellation, notice, and payment dates, and puts them on your calendar with lead-time alarms. Every date shows the exact source line it came from, so you can prove where it came from. Track your first document free, forever. Available on the [App Store](https://apps.apple.com/us/app/id6791267818), [Google Play](https://play.google.com/store/apps/details?id=com.trailblazer.rt), and the [Microsoft Store](https://apps.microsoft.com/detail/9pn7wd53t24m?hl=en-US&gl=US). Details at [trailblazer.us.com/tracker](https://trailblazer.us.com/tracker/).
    ## About What Counts
    What Counts is produced by [TrailBlazer Consulting, LLC](https://trailblazer.us.com/) and hosted by Lee Karas and Maura Dunn. Learn more or reach out directly at [[email protected]](mailto:[email protected]). Explore compliance-ready corporate training programs at the [TrailBlazer Learning Academy](https://trailblazerlearningacademy.com/). Read more from Maura at [Maura's Substack](https://mauradunn.substack.com/). Music by Jason Blake. [Full disclaimer](https://trailblazer.us.com/policy-page/).
    11 min
  • Information Governance Policies: The Three That Matter Most
    Why You Need Information Governance Policies
    Why do you need information governance policies? In this lightning round of What Counts, Lee Karas and Maura Dunn explain how policy turns records into dependable evidence. First, Maura shows how a written policy sets expectations for your team and for everyone who relies on you. Next, they tackle a hard question: is a policy you ignore worse than no policy at all? In court, it can lead to an adverse inference. Outside court, food recalls and a bank incentive scandal show the same gap between policy and practice. Then Maura ranks the three information governance policies that matter most. They are the retention schedule, legal hold, and electronic communications. Finally, they discuss why Teams, Slack, texts, and even AI prompts create records that need clear rules.
    Episode Chapters
    00:00 Welcome to the lightning round
    00:53 Consistency, and policy versus process
    01:32 Why records exist: evidence and compliance
    02:39 How information governance policies set expectations
    03:55 Because it says so? How policy protects you
    05:21 Is an ignored policy worse than none?
    06:49 Food recalls and policies nobody followed
    09:49 When a bank's incentives beat its policy
    10:48 Too many policies, and what matters most
    11:00 First policy: the retention schedule
    12:01 Second policy: legal hold
    13:37 Third policy: electronic communications
    16:10 Finally, where AI prompts fit
    17:33 Closing and how to reach us
    This episode is brought to you by TrailBlazer Tracker.
    The contract you cannot find is also the contract that auto-renews without you. Tracker reads your PDFs, Word files, and scanned paper, pulls out renewal, cancellation, notice, and payment dates, and puts them on your calendar with lead-time alarms. Every date shows the exact source line it came from, so you can prove where it came from. Track your first document free, forever. Available on the App Store, Google Play, and the Microsoft Store. Details at trailblazer.us.com/tracker.
    About What Counts
    What Counts is produced by TrailBlazer Consulting, LLC and hosted by Lee Karas and Maura Dunn. Learn more or reach out directly at [email protected]. Explore compliance-ready corporate training programs at the TrailBlazer Learning Academy. Read more from Maura at Maura's Substack. Music by Jason Blake. Full disclaimer.
    19 min
  • Information Governance Risk: Breach vs Access Loss
    Most people hear "information governance risk" and think immediately of a data breach. In this lightning round, Lee Karas and Maura Dunn argue that the breach is only one risk on the list, and often not the one that costs you most. They work through the risk of not being able to reach your own information, using the New England PBS stations whose seventy years of program archives went dark when their cloud provider failed; the risk of ransomware, where nobody wants your data and simply locking you out of it is enough to stop the business; and the risk of the single hard drive or the single box of paper. From there they get practical about scaling risk to the organization: the one-person mechanic shop with three record types that matter (employment, hazardous materials disposal, and financial records supporting the tax return) against the charter school carrying accreditation, curriculum, teacher credentialing, facilities, and student transcripts that graduates ask for fifty years later. They then take on age as its own risk factor, since a company that has kept everything has both a volume problem and an exposure problem: underwriting records written under rules that changed decades ago, or environmental records from an era when the answer was to dump it in the ground. The through line is that a risk assessment is not an academic exercise. It is the input to the retention schedule you build, the repositories you pick, the providers you trust with fiduciary-level responsibility, and whether you are ready to put an AI system on top of any of it.
    Episode chapters
    00:00 Cold open: the lightning round
    00:14 Welcome to What Counts
    00:29 What is information governance risk?
    00:48 The breach answer: financial records and PII
    01:53 A second definition: you cannot find it when you need it
    02:55 The PBS archive that disappeared inside a cloud provider
    03:53 Why inaccessibility goes straight to the bottom line
    04:24 Sizing breach risk: are you actually a target?
    05:34 Ransomware and being locked out of your own data
    06:06 One hard drive, one box: single points of failure
    06:20 The mechanic who keeps everything in paper
    07:53 Three record types a one-person shop still has to manage
    08:42 The charter school: accreditation, curriculum, and student records
    11:27 Company age as a risk factor: volume and obsolete rules
    12:11 Underwriting and environmental records that come back to bite
    14:02 No program, no proof: auditors, regulators, and courts
    15:56 Fiduciary duty and vendor due diligence
    16:37 Deploying AI without an IG program underneath it
    17:40 Turning the assessment into retention and repository decisions
    18:46 Wrap-up
    19:07 Closing credits
    Sponsor block
    This episode is brought to you by TrailBlazer Tracker.
    The contract you cannot find is also the contract that auto-renews without you. Tracker reads your PDFs, Word files, and scanned paper, pulls out renewal, cancellation, notice, and payment dates, and puts them on your calendar with lead-time alarms. Every date shows the exact source line it came from, so you can prove where it came from. Track your first document free, forever. Available on the App Store, Google Play, and the Microsoft Store. Details at trailblazer.us.com/tracker.
    Closing
    What Counts is produced by TrailBlazer Consulting, LLC and hosted by Lee Karas and Maura Dunn. Learn more or reach out directly at [email protected]. Explore compliance-ready corporate training programs at the TrailBlazer Learning Academy. Read more from Maura at Maura's Substack. Music by Jason Blake. Full disclaimer.
    20 min
  • Records vs Non-Records: What Counts as Evidence
    Records vs Non-Records: What Counts as Evidence
    Records vs non-records is the first distinction any information governance program has to get right, and most organizations never make it explicitly. In the opening episode of our lightning round series, Lee Karas and Maura Dunn answer both halves of the question: what is a record, and what is not. A record is any data, in any format, that is recorded or capable of being recorded and that provides evidence of a transaction, a decision, a policy, a process, an obligation, a contract, an agreement, a legal right, or an ownership interest. Format is irrelevant. Structured data, photographs, and recordings qualify; an unrecorded conversation does not, which is why "did you get that in writing" has survived as advice. Maura draws the line at evidence: discarded drafts, background reading, and abandoned research are recorded and are not records, because they are not where the organization landed. Published material you cite belongs to whoever originated it, so your record is the citation, not the source. We close with a Sarbanes-Oxley example that makes the principle concrete: in vendor verification, the record is not the tax identification number you looked up, it is the documented fact that you checked it.
    10 min
  • Records Metadata vs Keyword Search: Making Records Findable
    Records findability starts at the point of creation
    Trustworthy information has four attributes. It must be accurate, reliable, timely, and findable. Last episode covered the first two. This week, Lee Karas and Maura Dunn take on the other two.
    The rule does not change. Capture the record where the work happens. Capture it when it happens. Capture it from the people doing the work. As a result, timeliness and findability follow along.
    Why your file dates cannot be trusted
    Open a shared drive and sort by date. The dates look authoritative. However, they are not.
    Sometimes opening a document changes the date. The created date gives way to the modified date. Meanwhile, that modified date may only mean someone glanced at the file.
    Auto-save makes it worse. Word saves before you rename your copy. Your manual version scheme then breaks quietly. It never runs at all in Microsoft Project or Visio. Even in Excel, it can miss when OneDrive has not finished logging in.
    Timeliness is proof, not a timestamp
    An approval date proves timeliness. So capture it deliberately. A workflow engine already knows who drafted, who commented, who approved, and when. Record that context anyway, because property values alone will not carry it.
    Maura describes a client who did this on paper. Every requirements document carried five or six signature blocks. Each reviewer initialed and dated in ink. Then the team scanned it. An e-signature process gets you the same result today, with less effort.
    Traceability at every step
    Business requirement one becomes functional requirements 1.3, 1.4, and 1.5. That trace increases accuracy. The sign-offs at each step add timeliness.
    Universe search versus precision search
    Library science calls keyword search a universe search. You give it three words. In return, it gives you everything near those words. For example, ask for "training" and you also get "learning."
    The result set grows. The usefulness does not. Instead of the whole company, you now face a couple thousand documents.
    A precision search works differently. First you set the file type. Next you name the business process. Then you name the contract or the facility. Now the found set is small enough to use.
    Metadata is what makes records findable
    Four elements matter most: function, process, record category, and trigger date or event. Those are real data, not keywords. Because of that, you can filter on them and build a collection. In other words, you get a virtual folder without a physical file plan.
    Maura and Lee revisit an old FileNet argument on exactly this point. An IT lead wanted no folders and no file plan. He trusted full-text search to sort out billions of documents. He was partly right, but for the wrong reason.
    Search, access, and retrieval
    Findability has three parts. Search identifies potentially responsive material. Retrieval pulls it back so you can use it. Access decides whether you may open it at all.
    Sometimes users can see that a record exists but cannot read it. Sometimes they cannot see it at all. That choice is yours, so make it on purpose.
    Episode chapters
    00:00 Timeliness and findability: the two attributes we still owe you
    00:58 Why the date on the file lies: created versus modified
    02:12 Auto-save versus manual versioning, and when OneDrive has not logged in yet
    04:35 A tangent worth an episode: password management as a mapping problem
    05:34 Capture at the point of creation, then make capture into storage
    06:39 What the workflow engine already knows, and what you must record by hand
    08:09 Ink initials and signature blocks: traceability from business to functional requirements
    09:44 The universe search: three keywords, a million results, ranked by confidence
    11:51 The precision search: file type, process, and facility narrow it down
    12:58 Process metadata tags every file behind the scenes
    14:27 The FileNet argument: "we will just use search"
    15:24 Function, process, record category, and trigger as real metadata, not keywords
    17:19 Contract records split: construction and non-construction retention
    18:47 Collections as virtual folders, and knowing your repository before you commit
    19:46 Search, access, and retrieval: three parts of one problem
    20:39 Should users know a record exists if they cannot open it?
    Closing
    What Counts is produced by TrailBlazer Consulting, LLC and hosted by Lee Karas and Maura Dunn. Learn more or reach out directly at [email protected]. Explore compliance-ready corporate training programs at the TrailBlazer Learning Academy. Read more from Maura at Maura's Substack. Music by Jason Blake. Full disclaimer.
    22 min
  • Records Capture at the Point of Creation: Provenance and Proof
    Provenance decides whether your data is AI-ready
    Everyone wants to point AI at their content repositories. Maura Dunn's position in Episode 139 is simpler than that. A model can only be as trustworthy as the data feeding it. Provenance settles that question long before anyone builds a pipeline.
    Records capture points settle provenance. These are the moments in a business process where an input becomes a record. Seventeen (17) steps later, the process has changed that input into something new. That is another capture point. Every copy, every hand-off, every transformation makes chain of custody harder to establish.
    Content versus context
    Our back file characterization approach documents the method while we build it. We do not hand a client a disposition report with no reasoning attached.
    Consider a recommendation to destroy sixty (60) of seventy-five (75) files. That report is content. The folder structures, file properties, creation and modification dates, and security group access rights behind it are context.
    Context gives the client something to react to. We can say we hold this level of confidence that these records align with your sales and marketing category. That category carries an end of fiscal year trigger and a five (5) year retention period. The client then makes the risk judgment. Without context, one answer survives a year later: "because Maura said so."
    What the Superfund SITREP got away with
    We built the same principle into our records process mapping work.
    The contrast comes from the US EPA Superfund program. A SITREP moved from field samples and a gas chromatograph printout to a typed memo in a drawer. Eventually it went into a box at the Federal Records Center. That process produced no interim record steps. In a paper world, it did not need to.
    Engineering records capture points into the workflow
    Digital process manipulates information continuously. So the workflow itself has to carry the capture points. Mark the inputs and the interim decision support drafts. Mark the comment responses where public comment periods apply, and the finals.
    Automated workflow and document management version control make those records capture points easier to build than ever. Growing volume makes the discipline harder. Records prove what happened. That proof now doubles as the audit trail for whatever your AI does next.
    14 min
  • Document Version Control: Why AI Picks Your Worst Copy
    Universal search was designed to bring you the universe. So is your AI assistant. Lee and Maura take on the two questions they left hanging last episode: how do you know which version is the last one, and how do you know your data is reliable? AI-ready data turns out to be the same problem, it is not solved by searching harder, and in 2026 it carries a regulatory clock.
    23 min
  • Data Capture Controls: How to Prepare for an Audit
    Corporate data capture risk is a critical vulnerability that can completely disrupt an enterprise during sudden regulatory compliance audits or high-stakes litigation holds. Welcome back to What Counts, the podcast that digs into the messy information governance problems organizations inherit, ignore, and discover too late. In this episode, hosts Lee Karas and Maura Dunn move past theoretical concepts to break down exactly how unstructured file systems multiply your operational liabilities. Manual filing structures inevitably fail under heavy daily workloads, placing the burden entirely on your technology infrastructure to secure critical corporate history.
    27 min
  • Duplicate Records: 3 Rules to Stop Uncontrolled Copies
    Clean dashboards and reliable data don't happen by accident. In this episode of What Counts, Lee Karas and Maura Dunn pick up from the shift from records management to information governance and move into the three action principles that actually get you there: stop making copies, focus on data creation points, and touch once, use many times. They trace how society lost its mindfulness about creating data from Sumerian clay tablets to the printing press to the Federal Records Act and walk through a painfully familiar example of how a single shared link quietly multiplies into four copies. Along the way, they unpack the reliability paradox at the heart of information governance: the more copies you make, the less you can trust your data. It's a candid, practical conversation about why these simple-sounding principles are so hard to follow, and why the tools we use every day keep reinforcing our worst habits.
    New here? Start with the previous episode: Records Management vs. Information Governance.
    Key Takeaways
    The more copies you make, the less reliable your data becomes. People hoard copies because they don't trust they'll find the original later, which only makes the underlying data less trustworthy. It's a paradox, but it holds.
    We've lost our mindfulness about creating data. When information was expensive and hard to produce, more thought went into it. Now anyone can create and disseminate data in seconds, so almost none goes into it.
    Three principles work together: stop making copies, focus on data creation points, and touch once / use many times. They're simple to say, clear to understand, and genuinely hard to do.
    Data creation deserves rules. Who's allowed to create a new contract, location, or counterparty record? Where does it live? Who can change it, and how? Answering these up front prevents downstream chaos.
    Acquisitions are data creation events. When data comes in through an acquisition, you need a crosswalk from old identifiers to new ones or you end up asking, "Where's all the data for Armadillo Ranch?"
    Bad data has real costs: failed audits, unanswerable litigation and e-discovery requests, duplicate survey spend, and revenue you can't collect because you can't prove your rights.
    Your tools may be the problem. Email and collaboration platforms often reinforce copy-making habits or force workarounds, because the value of doing it right isn't obvious in the moment.
    20 min
  • Records Management vs. Information Governance: The Difference
    What's the difference between records management and information governance — and why should anyone running a business care? In this episode of What Counts, Lee Karas and Maura Dunn step back from the weeds of counterparty data to answer a deceptively simple question: what is information governance, and why is it the natural next step? Maura traces the journey from a world where creating a record was hard and expensive — clay tablets, hand-copied scrolls, the Federal Records Act — to today, where producing information takes ten seconds and most of it is noise. Along the way they untangle the vocabulary (governance is strategy and the "why"; management is execution), revisit the records-management principles that still hold true, and show how information governance helps you surface the small slice of information that actually runs your business. They close with practical moves you can make now: stop making copies, send a link instead of an attachment, and standardize and automate your contracts so your best people spend their time where the value and the risk actually live.
    This episode builds on Episode 134, where Lee and Maura broke down how to keep counterparty and vendor data from sprawling across teams and systems before contracts are even signed. Listen to the previous episode here.
    "Governance is more strategic — it incorporates the why. Management is execution."
    Key takeaways
    Governance ≠ management. Governance sets strategy and the "why"; management executes, audits, and proves it.
    Records management isn't dead — its core test still applies: does this provide evidence of a policy, process, decision, action, or transaction?
    Cheap creation is the modern problem. When anyone can publish in ten seconds, the hard part isn't making information — it's finding the small slice that matters.
    Information governance is how you fight the noise so you can surface what runs the business and demonstrates compliance.
    Stop making copies. Replace emailed attachments with links to a single, easy-to-reach, always-current source.
    Unmanaged data is a risk, not just clutter — especially when it contains sensitive or critical-infrastructure information.
    Contracts are where governance pays off: standardize, automate the routine, and reserve human attention for the high-value, high-risk exceptions.
    Overall Episode Length: 0018:28
    Episode chapters
    00:00 — Sponsor: TrailBlazer Insight. Scan your shared drives locally for PII, HIPAA, PCI, and other compliance risks — no cloud, no IT ticket.
    00:20 — Welcome to What Counts. Every organization hides a story in its data; meet your hosts, Lee and Maura.
    00:47 — Recap & the segue. From Episode 134's counterparty-data cleanup (persistent IDs, central systems, choke points) to a bigger question: what is information governance?
    01:33 — Why this, why now. Making your contracts work for you starts with understanding your counterparties — and that leads straight to governance.
    02:00 — The vocabulary problem. The words around this work keep changing (including TrailBlazer's short-lived attempt to coin "information design").
    03:21 — Governance vs. management. Governance is strategic and carries the "why"; management is execution — following, auditing, and proving the process.
    04:07 — Records management roots. Library school, law firms, and federal records centers — and the definition that still anchors the field.
    04:51 — What is a "record"? Information that's recorded (or can be) and provides evidence of decisions, actions, and transactions.
    06:13 — When records were scarce. Cuneiform, scrolls, ink, and recyclable paper that fell apart — and the Federal Records Act, the first time the U.S. allowed records to be destroyed.
    07:44 — Today's flood. Creating information is now the cheapest thing you can do — so the value of any single piece is hard to find, and most has none.
    08:37 — Enter information governance. From information management to data governance to information governance: a philosophy built on records principles, executed in a completely new way, to fight through the noise.
    09:54 — The inbox problem. Open, click, delete — so how do you catch the one email that's actually a record you need to keep?
    10:40 — A real-world miss. Donation receipts lost in a personal inbox overrun with ads — why noise costs you.
    11:39 — Automating the noise away. The weekly report's evolution from paper to email blasts to set-and-forget rules nobody reads.
    12:47 — When unread data becomes a risk. An energy-sector example: construction reports holding critical infrastructure information, piling up and waiting to be breached.
    13:24 — Principle #1: Stop making copies. Don't email attachments — point people to a source. But make it genuinely easy.
    14:00 — Make it easy and more valuable. A weekly link to a live dashboard beats a stale Friday report you read on Monday.
    15:39 — Governance applied to contracts. Standardize terms and exceptions, automate the routine, and free the high-value, high-risk contracts from the noise so senior legal and business minds focus where it counts.
    17:01 — The big shift. From "create the document, then apply retention" to "information that reflects and serves the goals of the business."
    17:33 — Wrap-up & what's next. Where information governance goes from here.
    17:53 — Credits & how to support the show.
    "In our age, creating information is the cheapest thing you can do."
    Frequently asked questions
    What is information governance?
    A strategic approach to creating, organizing, and using information so an organization can cut through the noise and focus on the small share of information that runs the business and demonstrates compliance. It's built on records-management principles but executed very differently.
    What's the difference between records management and information governance?
    Records management focuses on the lifecycle of records — creation, protection, use, and disposition. Information governance is broader and more strategic: it asks why you hold information and how it can serve business goals, not just how to retain and dispose of it.
    What's the difference between management and governance?
    Governance is strategic — it sets direction and incorporates the "why." Management is execution — following the rules, auditing the process, and proving it was followed.
    Who should listen
    General counsel and legal ops, records and information-governance managers, compliance officers, COOs, and contract/CLM owners — especially in mid-market and enterprise energy, healthcare, professional and engineering services, construction, and manufacturing.
    Listen & subscribe
    New episodes of What Counts drop regularly. Subscribe on your favorite podcast app, and if this one was useful, share it with a colleague whose shared drives are full of contracts nobody reads, policies nobody follows, and files nobody can find.
    What Counts is produced by TrailBlazer Consulting, LLC and hosted by Lee Karas and Maura Dunn. Learn more at trailblazer.us.com or email us at [email protected]. Explore compliance-ready training at the TrailBlazer Learning Academy. Read more from Maura at mauradunn.substack.com. Music by Jason Blake. Full disclaimer.
    19 min

About What Counts?

From the publisher's feed

Welcome to What Counts? by TrailBlazer Consulting. The hosts, Maura Dunn and Lee Karas bring over 30 years of experience consulting with public and private organizations across industries including…