ARMA International's 2025 Information Governance Maturity Index offers a sobering message: establishing an information governance programme is difficult, but sustaining it may be harder. Based on 96 valid survey responses collected in late 2025, the report found that 56.3% of organizations described their overall programme as established at Level 3 or higher, down from 63.0% in 2024. The finding is not a score for Latin America, nor proof that every organization declined. It is a useful warning for the region: technology can advance while the governance required to control information falls behind.
What the index measures
The survey follows version 2.1 of ARMA's Information Governance Implementation Model and examines eight connected domains: steering committee, authorities, support functions, procedural framework, capabilities, information lifecycle, architecture, and infrastructure. Respondents used a five-level scale ranging from sub-standard to transformational. The report groups Levels 3 to 5 as established, meaning the essentials are in place or the organization has progressed beyond them.
That definition matters. An established programme may still operate reactively at Level 3. Passing the threshold does not mean governance is fully integrated into strategy, daily processes, and technology. The index therefore measures more than whether policies exist. It asks whether leadership, accountability, controls, lifecycle practices, and infrastructure work together.
Signal 1: maturity lost ground across every domain
The report's executive summary shows a decline in overall established maturity from 63.0% in 2024 to 56.3% in 2025. It also reports declines across all eight domains. Procedural Framework and Capabilities recorded the largest year-over-year drops, falling 10.7 and 10.3 percentage points respectively. Information Lifecycle declined by 9.1 points.
The central lesson is not that programmes suddenly failed. Annual survey samples change, and a self-assessment cannot diagnose a cause. The stronger conclusion is that maturity does not sustain itself. Policies become outdated, committees lose authority, trained staff leave, systems change, and new cloud or AI uses create information flows that earlier controls did not anticipate.
Signal 2: technology remains ahead of lifecycle governance
Infrastructure was the strongest domain, with 71.0% of respondents reporting established maturity, followed by Capabilities at 68.8%. Information Lifecycle was the weakest at 42.7%. Steering Committee and Procedural Framework also remained comparatively weak, at 53.7% and 53.1% in the report's summary figures.
This is the most important pattern in the report. Organizations are more likely to have platforms, security tools, search, access controls, and technical services than to have consistent rules for information from creation through final disposition. Technology can store and move information, but it cannot decide which record is authoritative, who owns the decision, how long evidence must remain available, or when defensible deletion should occur.
Signal 3: organization size still shapes maturity
The report shows a 16.6 percentage-point gap in overall established maturity: 62.3% for large organizations and 45.7% for small and mid-size organizations. Large organizations also reported higher maturity across all eight domains. The widest gap appeared in Procedural Framework, where the summary comparison shows 65.6% for large organizations and 31.4% for smaller ones.
This does not mean a smaller organization needs an enterprise-scale governance office. It means that a right-sized operating model matters. A small team can define decision rights, maintain a short set of mandatory controls, assign an accountable owner, and focus resources on the processes where information failure would cause the greatest harm.
Signal 4: the local-government result exposes a modernization risk
The state and local government subgroup offers a striking, although small-sample, example. It represented 14.6% of the 96 respondents, or approximately 14 people. Within that subgroup, 50.0% reported established overall maturity, down from 68.8% in 2024. Infrastructure reached 85.7%, while Information Lifecycle stood at 14.3% and Procedural Framework at 21.4%.
These figures should not be generalized to governments in Latin America. The subgroup is small and the survey was not designed as a regional study. Its value is diagnostic: a public institution can modernize networks, cloud services, and applications faster than it defines retention, disposition, accountability, metadata, and evidence requirements. The result is digital capacity without equivalent governance capacity.
Signal 5: the regional opportunity is to close the operating gap
For Mexico, Central America, South America, and other Spanish-speaking markets, the report should be used as a comparison tool, not a regional ranking. Each country has its own archival, transparency, privacy, cybersecurity, and public-administration requirements. Organizations also vary widely in size, mandate, resources, and digital maturity.
The report is still highly relevant because it identifies a common operating gap: governance often remains separate from the systems and processes where information is created and used. Closing that gap requires more than another policy. It requires named decision-makers, cross-functional participation, lifecycle rules embedded in workflows, and evidence that controls are working.
How to use the report responsibly
The index is a point-in-time, self-reported benchmark based on a self-selected sample. Large organizations accounted for 63.5% of respondents, and 84.4% of participants worked in information governance, records management, or information management roles. It is therefore a professional signal, not a census of organizational maturity and not a representative measure of Latin America.
The methodology also changed beginning in 2024 so that each domain uses the number of valid answers to that domain as its denominator. This improves domain-level accuracy, but it means comparisons with earlier reports require care. The direction and the gap between domains are more useful for decision-making than treating every decimal as universally applicable.
A practical agenda for the region
A short maturity assessment can turn the report into an action plan. Organizations can begin with six steps:
- Assess the eight IGIM domains with representatives from operations, records, legal, privacy, security, data, and technology
- Select one or two priority gaps based on organizational risk rather than trying to reach Level 5 everywhere
- Map one critical service or decision from information creation through retention and final disposition
- Give a cross-functional governance group enough authority to resolve ownership, access, and lifecycle questions
- Embed the minimum controls into the platforms and workflows employees already use
- Track a small set of measures and repeat the assessment when systems, laws, risks, or business priorities change
Maturity is a management discipline
The 2025 index does not say that information governance has failed. It says that progress can recede when organizations treat maturity as a completed project. Sustainable governance requires continuous attention to leadership, operating rules, information lifecycles, architecture, and technology as one connected system.
For Latin America, the opportunity is practical: use the benchmark to begin an honest cross-functional conversation, identify the weakest link in one important process, and improve it before the next platform, regulation, or AI initiative increases the cost of inaction. The RIMpro can help translate that first assessment into a right-sized roadmap.
Sources and further reading
This article was adapted and expanded for The RIMpro from the ARMA International Information Governance Maturity Index Report—2025 ↗.
