Knowledge HubeDiscovery › Article 003
eDiscovery Certification Council Knowledge Hub

The eDiscovery Process Explained

A practical walkthrough of what happens from the first indication of a dispute through production and presentation, including responsibilities, decisions and common risks.

Article 003eDiscoveryVendor-neutralReviewed August 2026

What happens first?

The eDiscovery process often begins before a claim is filed. A complaint, regulatory enquiry, internal allegation, contract dispute or credible threat of litigation may be enough to require attention. The first practical task is not to collect everything. It is to understand the matter: what happened, which issues may matter, who is involved, what deadlines exist and which information is at risk of disappearing.

Triage and matter scoping

Early scoping brings legal, eDiscovery, IT and business stakeholders together. They identify likely custodians and systems, consider jurisdictions, define preliminary date ranges and decide whether urgent preservation is required. At this point uncertainty is normal. Good teams record assumptions and revisit them as facts emerge.

Identification

The team maps potential sources. A custodian may have email, OneDrive, a laptop, a mobile phone and messages in collaboration tools. Relevant information may also sit in shared systems with no obvious individual owner. The risk is assuming that the familiar source is the only source.

Preservation

Where information may be relevant and at risk of change or deletion, preservation measures are applied. Responsibilities are shared: lawyers define the legal need, IT or platform administrators may implement technical controls, custodians may receive legal hold notices, and eDiscovery specialists track scope and evidence of compliance.

Collection planning

Before collection, the team decides what actually needs to be gathered. Questions include whether a targeted export is sufficient, whether metadata must be retained, whether a device requires forensic acquisition, how cloud content will be obtained, and how the result will be validated. Collection is where legal scope becomes a technical action.

Processing and reduction

Collected data is processed so it can be searched and reviewed. Duplicates, known system files and clearly out-of-scope material may be reduced where appropriate. Search terms, dates, file types and analytics can further narrow the population. Every reduction method creates both efficiency and risk, so testing matters.

Review design

A review protocol translates the legal questions into reviewer decisions. It defines responsiveness, privilege, issue codes, confidentiality, redaction and escalation. Batches, permissions, quality control and reporting are configured. Where TAR or AI-assisted review is used, the team also defines training, validation and stopping criteria.

Review and quality control

Reviewers make decisions, but consistency does not happen automatically. Calibration exercises, second-level review, sampling and disagreement analysis help expose unclear instructions or reviewer drift. Metrics should illuminate quality rather than create a false sense of precision.

Production

Responsive documents are assembled according to the production specification. Families, metadata, natives, images, text, numbering and redactions are checked. A production should be reconciled against the approved population and transferred securely.

Presentation and lessons learned

Evidence may later be used in witness interviews, depositions, hearings or trial. Once the matter closes, mature teams also capture lessons: which sources were difficult, where costs arose, which workflows worked and what should change in the organisation’s readiness programme.

The process is iterative

The EDRM is best understood as a framework, not a one-way conveyor belt. Review may identify a new custodian; collection may expose another system; analysis may widen a date range. Returning to an earlier stage is not failure. Refusing to adapt when the evidence changes is the greater risk.

Practitioner takeaways

  • Start with the purpose of the matter and the questions the evidence must answer.
  • Treat legal, technical and evidential decisions as connected rather than isolated tasks.
  • Use proportionate methods, validate important results and record material decisions.
  • Preserve context and metadata where they affect meaning, authenticity or later analysis.
  • Use technology and AI to support professional judgement, not to disguise weak process.

Related eDiscovery Certification Council Knowledge Hub reading

Authoritative reference points

This is a vendor-neutral professional reference from the eDiscovery Certification Council Knowledge Hub. Jurisdiction-specific legal requirements should be checked against the current applicable rules and authoritative guidance.