System of Record
A system of record is the information storage and management system that an organization designates as the authoritative source for a particular set of data, such as customer, employee, product, or supplier information. When the same data appears in multiple systems, the system of record is the one treated as correct and definitive. In a related but narrower legal sense, a 'system of records' can refer to a group of records under the control of a government agency that is retrievable by a personal identifier.
A system of record (SOR), also called a source system of record (SSoR), is a data management designation identifying the authoritative information storage and management system for specific data elements or entities (for example, customers, employees, products, or suppliers) within an organization. It establishes the definitive value for those elements where the same data may be duplicated or replicated across multiple downstream systems, and it thereby supports data integrity, lineage, and reconciliation objectives. This governance and data-management usage should be distinguished from the term 'system of records' as used in U.S. federal privacy contexts, where, per the NIST glossary, it denotes a group of records under the control of a federal agency containing a personal identifier by which records are retrieved; the two terms are related in name but differ in scope and legal meaning. This entry addresses the concept at a definitional level and does not cover specific implementation architectures, tooling, or jurisdiction-specific recordkeeping obligations.
Why it matters
Designating a system of record matters because most organizations hold the same data, customer details, employee records, product information, or supplier data, across many systems, and without a single authoritative source those copies inevitably diverge. When two systems report different values for the same entity, the system of record designation resolves the conflict by establishing which value is treated as correct and definitive. This underpins data integrity, supports reconciliation between systems, and enables data lineage to be traced back to an authoritative origin.
For governance and compliance functions, a clearly identified system of record is often a prerequisite for reliable reporting and for demonstrating that decisions and disclosures rest on trustworthy data. Where controls depend on data, access certifications, financial reconciliations, or regulatory submissions, ambiguity about which system is authoritative can undermine the assurance those controls are intended to provide.
Care is needed to distinguish the data-management concept from the term 'system of records' used in U.S. federal privacy contexts. Under the NIST glossary, a 'system of records' denotes a group of records under the control of a federal agency that is retrievable by a personal identifier. The two terms are related in name but differ in scope and legal meaning, and conflating them can create confusion when privacy obligations and data-governance designations are discussed together.
Who it's relevant to
Inside SOR
Common questions
Answers to the questions practitioners most commonly ask about SOR.
