What happens first?
Triage and matter scoping
Early scoping brings legal, eDiscovery, IT and business stakeholders together. They identify likely custodians and systems, consider jurisdictions, define preliminary date ranges and decide whether urgent preservation is required. At this point uncertainty is normal. Good teams record assumptions and revisit them as facts emerge.
Identification
The team maps potential sources. A custodian may have email, OneDrive, a laptop, a mobile phone and messages in collaboration tools. Relevant information may also sit in shared systems with no obvious individual owner. The risk is assuming that the familiar source is the only source.
Preservation
Where information may be relevant and at risk of change or deletion, preservation measures are applied. Responsibilities are shared: lawyers define the legal need, IT or platform administrators may implement technical controls, custodians may receive legal hold notices, and eDiscovery specialists track scope and evidence of compliance.
Collection planning
Before collection, the team decides what actually needs to be gathered. Questions include whether a targeted export is sufficient, whether metadata must be retained, whether a device requires forensic acquisition, how cloud content will be obtained, and how the result will be validated. Collection is where legal scope becomes a technical action.
Processing and reduction
Collected data is processed so it can be searched and reviewed. Duplicates, known system files and clearly out-of-scope material may be reduced where appropriate. Search terms, dates, file types and analytics can further narrow the population. Every reduction method creates both efficiency and risk, so testing matters.
Review design
A review protocol translates the legal questions into reviewer decisions. It defines responsiveness, privilege, issue codes, confidentiality, redaction and escalation. Batches, permissions, quality control and reporting are configured. Where TAR or AI-assisted review is used, the team also defines training, validation and stopping criteria.
Review and quality control
Reviewers make decisions, but consistency does not happen automatically. Calibration exercises, second-level review, sampling and disagreement analysis help expose unclear instructions or reviewer drift. Metrics should illuminate quality rather than create a false sense of precision.
Production
Responsive documents are assembled according to the production specification. Families, metadata, natives, images, text, numbering and redactions are checked. A production should be reconciled against the approved population and transferred securely.
Presentation and lessons learned
Evidence may later be used in witness interviews, depositions, hearings or trial. Once the matter closes, mature teams also capture lessons: which sources were difficult, where costs arose, which workflows worked and what should change in the organisation’s readiness programme.
The process is iterative
The EDRM is best understood as a framework, not a one-way conveyor belt. Review may identify a new custodian; collection may expose another system; analysis may widen a date range. Returning to an earlier stage is not failure. Refusing to adapt when the evidence changes is the greater risk.
Practitioner takeaways
- Start with the purpose of the matter and the questions the evidence must answer.
- Treat legal, technical and evidential decisions as connected rather than isolated tasks.
- Use proportionate methods, validate important results and record material decisions.
- Preserve context and metadata where they affect meaning, authenticity or later analysis.
- Use technology and AI to support professional judgement, not to disguise weak process.
Related eDiscovery Certification Council Knowledge Hub reading
Authoritative reference points
This is a vendor-neutral professional reference from the eDiscovery Certification Council Knowledge Hub. Jurisdiction-specific legal requirements should be checked against the current applicable rules and authoritative guidance.