Difference between revisions of "Accounting Finance:Document Imaging Management Policy"
| Line 418: | Line 418: | ||
:::3. Management-in-Confidence |
:::3. Management-in-Confidence |
||
:::4. Business |
:::4. Business |
||
| + | |||
| + | ===Image Retention=== |
||
| + | |||
| + | The following retention periods apply in respect of the document categories: |
||
| + | *<u>'''Business.'''</u> '''3 years''' (unless otherwise specified by the DMS Owner following instruction from the uniPHARM Leadership Group) |
||
| + | *<u>'''Legal.'''</u> Under the Income Tax Act, books, records, and their related source documents have to be kept for a minimum of six years from the end of the last tax year to which they relate. The tax year is the fiscal period for corporations. Under the Employment Insurance Act and Canada Pension Plan, the retention period begins at the end of the calendar year to which the records relate. |
||
| + | |||
| + | '''Based on the above, the retention period for documents categorized as ‘legal’ is 7 years.''' |
||
| + | |||
| + | *<u>'''Management-in-Confidence.'''</u> '''3 years''' or as specified on a case by case basis by Management |
||
| + | *<u>'''Personal.'''</u> Under the Personal Information Protection Act, if an organization uses an individual’s information to make a decision that directly affects the individual, the organization must retain that information for at least one year after using it so that the individual has a reasonable opportunity to obtain access to it. |
||
| + | An organization must destroy its documents containing personal information, or remove the means by which the personal information can be associated with particular individuals, as soon as it is reasonable to assume that: |
||
| + | *The purpose for the that personal information was collected is no longer being served by retention |
||
| + | *Retention is no longer necessary for legal or business purposes |
||
| + | Under the Employment Standards Amdt Act (2002) organizations are to retain payroll records for 2 years. |
||
| + | Under the Limitation Act organizations are to retain human resources records for 6 years. |
||
| + | '''Based on the above, the policy is to retain personal information for 7 years beyond the duration of an individual’s employment or association (e.g. a Director) with uniPHARM.''' |
||
| + | |||
| + | It is recognized that there will be overlap between document categories e.g. a legal document may contain personal information. Where such overlap is identified, the following order of precedence applies in respect of retention periods: |
||
| + | :::1. Personal |
||
| + | :::2. Legal |
||
| + | :::3. Management-in-Confidence |
||
| + | :::4. Business |
||
| + | |||
| + | ===Security/Access=== |
||
| + | {| class="wikitable" |
||
| + | |- |
||
| + | | <u>'''Business'''</u> |
||
| + | || |
||
| + | *Accessible by: |
||
| + | ::-All permanent uniPHARM staff |
||
| + | ::-Temporary uniPHARM employees (as required and approved by the DMS Owner) |
||
| + | ::-uniPHARM Shareholders (as required and approved by the DMS Owner) |
||
| + | ::-uniPHARM Customers (as required and approved by the DMS Owner) |
||
| + | ::-Contractors (as required and approved by the DMS Owner) |
||
| + | ::-External auditors (as required) |
||
| + | ::-Government inspectors (as required) |
||
| + | |- |
||
| + | | <u>'''Legal'''</u> |
||
| + | || |
||
| + | *Access restricted to: |
||
| + | ::-Specified members of uniPHARM Management |
||
| + | ::-Specified members of uniPHARM staff |
||
| + | ::-External auditors (as required) |
||
| + | ::-Government inspectors (as required) |
||
| + | |- |
||
| + | | <u>'''Management-in-Confidence'''</u> || Access restricted to specified members of uniPHARM Management |
||
| + | |- |
||
| + | | <u>'''Legal'''</u> |
||
| + | || |
||
| + | *Access restricted to: |
||
| + | ::-Named Human Resources personnel (including Payroll Personnel) |
||
| + | ::-DMS Owner |
||
| + | ::-uniPHARM Management |
||
| + | |} |
||
| + | |||
Revision as of 14:54, 19 January 2018
Using the DIMP
- This Document Management Imaging Policy (DIMP) Manual has been designed primarily for online use. Excessive printing of the manual is discouraged in order to aid version control and minimize costs.
- Virtually all content is self-contained within a subject ‘table’ to make amendment and/or extraction as easy as possible.
- The primary means of document navigation is via the Table of Contents. However, navigation is aided by the use of ‘hyperlinks’. These dynamic links allow users to jump from one subject to a related subject (or punch out to the documents located on the Internet) by simply clicking on the link. A link is displayed by underlined blue text. To return to the original location (i.e. prior to using a hyperlink), a blue return arrow should appear towards the top left hand corner of the screen). A bookmark entitled ‘Return to Table of Contents’ has been included at the commencement of many sections to assist overall navigation. Specific topics of interest (within a sentence of paragraph) have been ‘bookmarked’ and their related subjects hyperlinked to further aid navigation and to link closely related issues.
- All references to actual Federal/Provincial regulations are in bold red text.
- The online version of the DIMP manual is to be maintained as ‘read only’.
- Glossary of Terms has been included clarification purposes.
Introduction
Purpose
The purpose of this document is to detail the management policy and business processes to be applied in respect of documents:
- Scanned and stored in the Gauss Document Management System (DMS)
- Accessed, viewed and retrieved from the DMS
- Destroyed as a result of scanning operations
In addition, this document is intended to demonstrate linkage to the principals required for compliance with Federal/Provincial legislation, including:
- The Personal Information Protection and Electronic Documents Act
- Food and Drugs Act (Good Manufacturing Guideline 2002 Edition)
- Income Tax Act
- Employment Insurance Act
- Employment Standards Amendment Act
- Limitation Act
Background
uniPHARM’s vision is to operate, as far as is practical, in a ‘paperless’ environment. The UNITY Project has provided the means for realising this vision through the installation of the Gauss Document Management System (DMS). This system provides uniPHARM with the capability to capture information from a wide range of paper based or electronic sources, store an electronic image of document, and allow images to be retrieved on an enterprise basis.
The benefits of the DMS are clear in terms of efficiency, space utilization and online access to information. However, in order to ensure that the DMS itself is operated efficiently and to comply with all legal requirements covering document imaging, retention, access and privacy, it is necessary to formalize polices through Standard Operating Procedures (SOPs). This approach is consistent with those already in place in respect of GMP, Project Management and IT Management.
Ownership/Roles/Responsibilities
Background
The Personal Information Protection Act states that an organization is responsible for personal information under its control, including personal information that is not in the custody of the organization. The Act requires an organization to designate one or more individuals to be responsible for ensuring that the organization complies with the regulations.
Role Definition
The primary roles associated with the DMS are defined as follows:
| Role | Definition |
|---|---|
| Owner | Designated individual who is held responsible by the uniPHARM Leadership Group for the efficient management of the DMS and compliance with all relevant legislation |
| Administrator | Designated individual who is held responsible by the Owner for the definition of Document Classes and publication of Batch Classes |
| Operator | Designated individual who is held responsible by the Owner for the efficiency of scanning operations and the quality of scanned images |
| Technical/Security Administrator | Designated individual who is held responsible by the Owner for the efficiency of application support and security administration |
| Delegate | Designated individual held responsible by the Owner for fulfilling the role (as approved by the Owner) of :
|
| User | Any individual who has been approved to:
|
Ownership/Roles/Responsibilities
The following table details the individuals who will be responsible and accountable for the management and delivery of the DMS and the extent of their responsibilities:
| Name | Nancy Ng |
|---|---|
| Role | Owner of the DMS |
| Responsibilities |
|
| Delegate | Christine Del Rosario |
| Name | Christine Del Rosario |
|---|---|
| Role |
|
| Responsibilities' |
|
| Delegate | Nancy Ng |
| Name | Gordie Lee |
|---|---|
| Role |
|
| Responsibilities |
|
| Delegates | Gerald Petznek |
| Name | Chelsea Manasala |
|---|---|
| Role |
|
| Responsibilities |
|
| Delegates | Christine Del Rosario, Nancy Ng |
| Name | Angela Chan |
|---|---|
| Role |
|
| Responsibilities |
|
| Delegates | Nancy Ng |
| Name | Norwin Uy |
|---|---|
| Role |
|
| Responsibilities |
|
| Delegate | Darren Freedman |
Impact of Legislation
Income Tax Act and Employment Insurance Act
| Federal regulations concerning the imaging of tax/employment insurance related documentation require the following: | uniPHARM’s interpretation of and response to these requirements is as follows: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Personal Information Protection & Electronic Documents Act
| To be compliant with Federal regulations, organizations are required to: | uniPHARM’s interpretation of and response to these requirements is as follows: |
|
|
|
|
|
|
|
|
|
|
|
|
|
\\Superserver\FormsGeneral\Document Imaging Management Policy\DIMP_1.1.doc
|
|
|
|
|
|
|
|
|
Food and Drugs Act/GMP Guidelines (2002)
| Federal regulations require that: | uniPHARM’s interpretation of and response to these requirements is contained within the GMP Manual and summarized as follows: |
|
|
| |
| |
|
|
|
|
|
|
Employment Standards Amendments Act
| Provincial regulations require that: | uniPHARM’s interpretation of and response to these requirements is as follows: |
|
|
Limitation Act
| Provincial regulations require that: | uniPHARM’s interpretation of and response to these requirements is as follows: |
|
|
Statement of Responsibility and Authority
I confirm that:
- The (imaging) program will be part of the usual and ordinary activity of uniPHARM’s business.
- The document management policy and practices are considered reasonable to protect the privacy of personal information subject to imaging.
- uniPHARM accepts responsibility for personal information to be processed and retained with the Document Management System
I consider that the Document Imaging Management Policy including Standard Operating Procedures are sufficient to ensure uniPHARM is currently and will remain compliant with current legislation related to the processing, retention, quality, security and availability of documents scanned into the Document Management System.
I consider that responsibilities placed on any one individual are not so extensive as to present any risk to quality.
I hereby grant authority to the individuals listed at Section 3.6 to carry out their assigned responsibilities in accordance with Document Imaging Management Policy regulations. When the primary individual responsible is absent, authority is automatically transferred to the appropriate delegates. In the event that both the primary individual and delegates are absent, authority is automatically transferred to the uniPHARM Leadership Group to recommend and implement a reasonable interim solution.
Acceptance of Responsibility
I hereby accept the authority granted to me at Section 3.5 to carry of the responsibilities defined at Sections 2.1.1 and 2.1.2:
| Signatory | Primary Role | Signature | Date |
|---|---|---|---|
| Nancy Ng | Example | Example | Example |
| Christine Del Rosario | Administrator | Example | Example |
| Chelsea Manansala | Operator | Example | Example |
| Gordie Lee | Operator | Example | Example |
| Angela Chan | Operator (Personal Information) | Example | Example |
| Gerald Petznek | Operator Delegate | Example | Example |
| Norwin Uy | Technical/Security Administrator | Example | Example |
| Darren Freedman | Technical/Security Administrator delegate | Example | Example |
Document Policies
Categorization
The following document categories will apply throughout the DMS:
- Business. This is a non-legal, non-personal document required for business purposes only e.g. query resolution, reference, business intelligence etc. Examples include: waybills, packing slips etc.
- Legal. This is a document the treatment of which is covered by specific legislation (e.g. the Income Tax Act, the Employment Insurance Act) other than the Protection of Personal Information and Electronic Documents Act (see below).
- Management-in-Confidence. This is a document that is for ‘management eyes’ only. Examples include: strategic plans, confidential business notes, correspondence with Directors etc.
- Personal. This is a document that contains personal information covered by the Protection of Personal Information and Electronic Documents Act, the Employment Standards Amendment Act (Payroll Records) and the Limitation Act (Human Resources).
It is recognized that there will be overlap between document categories e.g. a legal document may contain personal information. Where such overlap is identified, the following order of precedence applies:
- 1. Personal
- 2. Legal
- 3. Management-in-Confidence
- 4. Business
Image Retention
The following retention periods apply in respect of the document categories:
- Business. 3 years (unless otherwise specified by the DMS Owner following instruction from the uniPHARM Leadership Group)
- Legal. Under the Income Tax Act, books, records, and their related source documents have to be kept for a minimum of six years from the end of the last tax year to which they relate. The tax year is the fiscal period for corporations. Under the Employment Insurance Act and Canada Pension Plan, the retention period begins at the end of the calendar year to which the records relate.
Based on the above, the retention period for documents categorized as ‘legal’ is 7 years.
- Management-in-Confidence. 3 years or as specified on a case by case basis by Management
- Personal. Under the Personal Information Protection Act, if an organization uses an individual’s information to make a decision that directly affects the individual, the organization must retain that information for at least one year after using it so that the individual has a reasonable opportunity to obtain access to it.
An organization must destroy its documents containing personal information, or remove the means by which the personal information can be associated with particular individuals, as soon as it is reasonable to assume that:
- The purpose for the that personal information was collected is no longer being served by retention
- Retention is no longer necessary for legal or business purposes
Under the Employment Standards Amdt Act (2002) organizations are to retain payroll records for 2 years. Under the Limitation Act organizations are to retain human resources records for 6 years. Based on the above, the policy is to retain personal information for 7 years beyond the duration of an individual’s employment or association (e.g. a Director) with uniPHARM.
It is recognized that there will be overlap between document categories e.g. a legal document may contain personal information. Where such overlap is identified, the following order of precedence applies in respect of retention periods:
- 1. Personal
- 2. Legal
- 3. Management-in-Confidence
- 4. Business
Security/Access
| Business |
|
| Legal |
|
| Management-in-Confidence | Access restricted to specified members of uniPHARM Management |
| Legal |
|