Will Your Digital Records Hold Up as Evidence? What Canada's Electronic Records Standard Requires

CAN/CGSB-72.34, Electronic Records as Documentary Evidence, is the National Standard of Canada for making digital records trustworthy enough to hold up in court, and the practices it calls for are the same ones that make your records reliable every day. If you're digitizing paper, running a digital mailroom, or modernizing records, it's the benchmark worth building on from the start.
Most organizations that scan, capture, or otherwise digitize their records are thinking about efficiency: faster retrieval, less storage, a cleaner digital mailroom. Fewer are thinking about the question that tends to surface later, during litigation, an audit, or a regulatory inquiry: if you had to prove that digital record in court, would it hold up?
What is CAN/CGSB-72.34?
CAN/CGSB-72.34, Electronic Records as Documentary Evidence, is a National Standard of Canada first published in 2005 and reissued in its latest edition in June 2024. I served as a voting member, in the producer category, on the CGSB committee that developed this revision, so I've spent a fair amount of time thinking about how the standard turns legal admissibility requirements into decisions a records manager or IT lead can actually act on.
It lays out how to build and run records systems so that the electronic records they produce (emails, scanned documents, digital forms, audio-visual files) can be shown to be reliable, accurate, and authentic.
The 2005 edition didn't appear from nowhere. It traces back to earlier Canadian work on electronic evidence, notably CAN/CGSB-72.11-93, Microfilm and Electronic Images as Documentary Evidence, and each revision since has kept pace with the technology it governs:
- CAN/CGSB-72.11-93: the earlier heritage, covering rules for microfilm and electronic images as documentary evidence.
- CAN/CGSB-72.34-2005: the first edition of 72.34, aligned to the electronic-evidence amendments to the Canada Evidence Act.
- CAN/CGSB-72.34-2017: refined the definitions and practices for proving the authenticity and integrity of electronic record systems.
- CAN/CGSB-72.34-2024: the current edition, adding risk coverage for mobile devices, social media, and AI and automated decision systems.
"The practices that make a record defensible in litigation are largely the same ones that make it trustworthy day to day."
Why it matters beyond the courtroom
The Canada Evidence Act and its provincial and territorial counterparts invite courts to consider "any standard, procedure, usage or practice" when weighing whether an electronic document is admissible. CAN/CGSB-72.34 gives organizations something concrete to point to.
That's useful well beyond the courtroom. The practices that make a record defensible in litigation are largely the same ones that make it trustworthy day to day: consistent metadata, a documented chain of custody, retention and disposition schedules you can defend, and an audit trail that shows what happened to a record and when. The standard says plainly that these are best practices independent of legal considerations. Organizations benefit from following them whether or not a record ever becomes evidence.
What the standard actually requires
At a practical level, the standard turns "trustworthy" into specific, buildable requirements:
- Metadata capture: capture consistent metadata at the point of creation or scanning, not after the fact.
- Classification and indexing: records are categorized and indexed so they can be found and understood in context.
- Chain of custody: a documented record of who handled a record and when, from capture to disposition.
- Retention and disposition: defensible schedules governing how long records are kept and how they're destroyed.
- Quality checks: verification that a digitized record faithfully represents its source, without alteration.
- Conversion and migration: records stay intact and readable as formats and systems change over the years.
- IT system management: backup and recovery, encryption and secure signatures, and audit trails detailed enough to demonstrate system integrity if a record is challenged.
- Risk assessment: current-edition guidance now covers mobile devices, social media, and AI and automated decision systems.
What it means for digitization and digital mailroom projects
For organizations converting paper archives or incoming mail into digital records, the standard gets specific fast. It addresses digitization directly, along with metadata capture, classification and indexing, and the quality checks needed to confirm a digitized record faithfully represents its source. It also covers conversion and migration over time, which matters for any digital mailroom program built to run for years rather than months.
The IT system management guidance reflects how much records environments have shifted since the previous edition. It now calls for risk assessments that cover mobile devices, social media, and automated decision systems, and it sets clear expectations for backup and recovery, encryption and secure signatures, and audit trails detailed enough to demonstrate system integrity if a record is ever challenged. You don't need to be anticipating a lawsuit for any of this to matter.
A standard in transition
One thing worth flagging: Public Services and Procurement Canada wound down the Canadian General Standards Board, with its standards-development and conformity services ceasing as of April 1, 2026. Responsibility for the future of CGSB standards, including this one, is moving to the federal departments whose mandates cover each standard's subject area, with PSPC supporting the transition. The standard itself stays valid and in force, and existing standards remain available. What's changing is who stewards it. We'll keep an eye on how that plays out and update clients as it becomes clearer.
Where Nimble fits in
Whether or not you ever cite this standard by name, its principles hold up well for any digitization or digital mailroom initiative: capture records with the right metadata from the start, document your processes, and build in the audit trail and retention discipline that let you stand behind a digital record years after it was created.
That's the same discipline we bring to digitization and records management engagements at Nimble, informed directly by having helped write the national standard that defines what "trustworthy" means for an electronic record in Canada. If you're planning a digital mailroom or a scanning and digitization project and want it built on solid footing, let's talk about how to get it right from day one.
Frequently asked questions
Is CAN/CGSB-72.34 mandatory?
No, it's a voluntary National Standard of Canada. But because the Canada Evidence Act invites courts to consider "any standard, procedure, usage or practice" when weighing whether an electronic document is admissible, following it gives you something concrete to point to if a record is ever challenged.
Does the CGSB wind-down mean the standard no longer applies?
No. CGSB's standards-development and conformity services ceased as of April 1, 2026, but the standard stays valid and in force. Stewardship is moving to federal departments, and existing standards remain available.
Does it apply to scanned paper records, or only born-digital ones?
Both. It addresses digitization directly (metadata capture, classification, and the quality checks that confirm a scanned record faithfully represents its source), alongside born-digital records like email, forms, and audio-visual files.
About the author
Daryl Stott, President, Nimble Information Strategies Inc.
Daryl has spent more than 30 years in document imaging, data capture, and digitization, working with organizations across the private and public sectors. He is a founding board member of AIIM Canada and served as a voting member on the CGSB committee that developed this standard. He's now President of Nimble, and still likes nothing better than talking with clients about how to implement intelligent document processes.
