Knowledge HubeDiscovery › Article 002
eDiscovery Certification Council Knowledge Hub

The Complete Guide to eDiscovery

The flagship end-to-end guide to the eDiscovery lifecycle, from information governance and identification through preservation, collection, processing, review, analysis, production and presentation.

Article 002eDiscoveryVendor-neutralReviewed August 2026

The short answer

eDiscovery is the disciplined management of electronically stored information (ESI) when that information may matter to litigation, investigations, regulatory enquiries or other legal processes. A mature eDiscovery workflow is not simply a sequence of software operations. It is a chain of legal, technical and evidential decisions designed to find what matters, preserve it appropriately, control cost and explain what was done.

Why an end-to-end view matters

Problems in eDiscovery rarely stay within one stage. Poor information governance can make identification harder. Weak identification can lead to incomplete preservation. Over-collection can inflate processing and review costs. Inadequate review instructions can compromise production. Each stage should be planned with the stages before and after it in mind.

1. Information governance

The strongest eDiscovery programmes begin before a dispute exists. Organisations that understand their systems, retention rules, ownership, data flows and disposal practices can respond faster when a matter arises. Keeping everything forever is not readiness; it can increase cost, privacy exposure and discovery risk.

2. Identification

Identification asks where potentially relevant information is likely to exist. Custodians are important, but modern matters also involve non-custodial sources: shared mailboxes, Teams channels, Slack workspaces, databases, cloud repositories, mobile devices, line-of-business applications and archives. Interviews, questionnaires, system inventories and data maps help turn a legal issue into a workable source map.

3. Preservation

Preservation protects potentially relevant information from inappropriate alteration or destruction. Legal holds are one mechanism, not the whole of preservation. Technical measures may include suspending deletion, applying in-place holds, preserving cloud content, exporting data or acquiring forensic copies.

4. Collection

Collection moves information from its source into a controlled workflow. A defensible collection is appropriately scoped, repeatable where possible, documented and validated. The most intrusive method is not automatically the best.

5. Processing

Processing converts heterogeneous source data into a population that can be searched, analysed and reviewed. Typical operations include text and metadata extraction, container expansion, file identification, deduplication, DeNISTing, OCR, date filtering and exception handling.

6. Review

Review applies legal and investigative judgement to documents. Reviewers may code for responsiveness, relevance, privilege, confidentiality, issues and redaction. Modern review often combines people with analytics such as email threading, near-duplicate detection, clustering and TAR.

7. Analysis

Analysis looks across the evidence for patterns and meaning. Timelines, communication networks, concepts, recurring names and unusual activity can help investigators understand a matter before every document has been read.

8. Production and presentation

Production is the controlled delivery of responsive information in an agreed or required format. Natives, images, extracted text, metadata, load files, numbering and redactions may all form part of the specification. Presentation follows when evidence is used in interviews, hearings, depositions or trial.

Proportionality and defensibility

A defensible workflow does not mean doing everything that technology makes possible. It means making reasonable, proportionate and documented choices. Teams should be able to explain scope, custodians, sources, date ranges, search methods, exclusions, validation and quality controls.

Where AI fits

AI now operates across multiple stages: source mapping, classification, review prioritisation, summarisation, chronology building and quality control. Its value depends on the task, the data and the controls around it. Human oversight, validation, confidentiality and traceability remain central.

A practical operating principle

Start with the legal and factual questions, translate them into data questions, select proportionate methods, validate the results and document material decisions. That principle survives changes in software, data sources and terminology.

Practitioner takeaways

  • Start with the purpose of the matter and the questions the evidence must answer.
  • Treat legal, technical and evidential decisions as connected rather than isolated tasks.
  • Use proportionate methods, validate important results and record material decisions.
  • Preserve context and metadata where they affect meaning, authenticity or later analysis.
  • Use technology and AI to support professional judgement, not to disguise weak process.

Related eDiscovery Certification Council Knowledge Hub reading

Authoritative reference points

This is a vendor-neutral professional reference from the eDiscovery Certification Council Knowledge Hub. Jurisdiction-specific legal requirements should be checked against the current applicable rules and authoritative guidance.