Comments on the EDRM v.2

The Electronic Discovery Reference Model has just released v2.0 for public comment. First stewarded by Tom Gelbmann and George Socha, it has served as the foundational visual reference for discovery practice since 2005. EDRM 2.0 modernizes that framework to reflect two decades of evolution in technology, data volumes, rule changes, regulatory expectations, cross-functional practice and considered court decisions.

David Cohen, CEO of ATJustice and chair of EDRM’s board of project trustees said, “This was a terrific team effort, achieved over a very busy two-year span, and drawing on the input of more than 100 knowledgeable and diverse EDRM members, as each aspect of the model was painstakingly reviewed and discussed – multiple times,”. I joined the committee late in the process (the fall of 22025) and participated in several of what David called “… spirited debates” during that time.

Rian Kennedy, Director of Legal Hold Sales at DISCO and EDRM 2.0 co-project trustee., noted that “While we continually debated going back to the original model, the updates better reflect today’s eDiscovery workflows. The biggest improvements in my mind are making the IGRM the foundation, extending Analysis across the workflow, and better grouping of the phases on the left side.”

I agree with most of that statement with two exceptions.

The changes I agree with are:

• Continuous Analysis. This feature now extends across the bottom of the entire diagram and is a key change. Analysis is ongoing, continuous and often iterative, as new data comes forward and new issues arise. It is an approach I always favored strongly when I wrote my ED Checklist Manifesto in 2020.

(https://ediscovery.aceds.org/hubfs/2020-55_ACEDS%20eDiscovery%20Checklist%20Manifesto.pdf )

• Data Acquisition framework. Continuing with the concept of a unified platform, these combined steps do often act together and grouping them together just makes sense.

One caveat, however, so I guess I don’t totally agree with this new step. Processing should not be included here. It is not part of “data acquisition” even though some software companies automatically process the data upon ingestion. But even then, the processing is done to separate specifications and standards distinct from the step(s) involved in obtaining the data. Most companies who handle ESI have separate departments to do forensic acquisitions and they do not do processing themselves. Some companies don’t do it all and use a separate third party vendor with domain expertise to forensically acquire data. Processing only occurs when the data is provided by that vendor.

• Disposition as a specific phase. Legacy data is an issue that is often overlooked but given the huge increase in data volume, can be a costly line item if not addressed. Ethical issues with handling data at the end of a case are also important and this focus brings that issue to the forefront.

Where I disagree:

It is a minor point on its own but tied to a deeper issue which I discuss further below. The diagram still shows the items after data acquisition In a sequential flow. Much like the Data Acquisition, I would have preferred to see some lines or interface which shows those as continuous or iterative. Again, one of the reasons I did my Checklist Manifesto in a wheel format and will continue that approach in the EDiscovery Checklist Manifest 2.0 (© 2026 GLTC) once EDRM 2.0 is finalized

When EDRM first came out, common complaint I received at lectures was “looks like a map of the NYC subway system”. Why is this important?

As Craig Ball said in his March 2026 post The EDRM Isn’t Broken; It’s Misunderstood:

(https://craigball.net/2026/03/18/the-edrm-isnt-broken-its-misunderstood/)

“The EDRM is a reference model — not a workflow, not a structure, not an operational blueprint.  It maps what needs to be addressed, not how to do it.”

V2.0 goes a long way to correcting the “workflow” interpretation but this point does not. And my last area of disagreement does so even less. V2.0 layers what the EDRM now calls “The Information Governance Foundation” at the bottom of the chart. The Information Governance Reference Model (IGRM) grounds the discovery lifecycle as a foundational layer, reflecting how governance principles shape every downstrea discovery activity.

So first a little history.

The original 2005–2006 EDRM diagram did not have an Information Governance (IG) box. IG was added years later and only became a formal “box” in the 2 014–2015 redesign. George Socha and Tom Gelbmann were explicit that the EDRM was areference model for eDiscovery, not for enterprise information management and IG was considered outside the scope of discovery in 2005–2006. The model intentionally started at “Identification” because that’s where litigation response begins.

Only later did the profession begin to realize that discovery is downstream of governance, mostly in the corporate environment. “Information Governance” became a discipline in 2010–2013, as organizations began adopting IG frameworks (ARMA, ISO 15489, GARP). EDRM responded by exploring how IG related to discovery.

The creation of the IGRM (Information Governance Reference Model in 2011 was a separate model, not part of the EDRM diagram. It mapped stakeholders (Legal, RIM, IT, Business) and their roles in governing information.

The IG box was formally added in the 2014–2015 EDRM refresh and was placed to the left of Identification and framed as an upstream precursor to discovery.

But v2.0 seems to have taken another evolutionary step by explicitly saying: you cannot treat eDiscovery as a standalone workflow anymore. Every step in discovery from preservation to production must be built on top of Information Governance (IG) principles. IG is no longer a side note or a precursor; it is the foundation that shapes, constrains, and enables all downstream discovery activity.

More troublesome, it seems to say that “Governance Principles” determine what discovery can do. The new IGRM v4.1 emphasizes unified policies, stakeholder alignment, and a perpetual policy process cycle, as it expands stakeholder groups to seven (business, IT, security, RIM, legal, risk, privacy) and seems to hold that discovery cannot function unless these groups have already aligned on:

 retention schedules

 access controls

 privacy obligations

 security requirements

 metadata standards

 cloud governance

 AIrelated data policies

I have two main objections to this approach.

First, this concept may work fine for large corporations and the firms that work with them but it doesn’t work so well for other groups. Who, you ask? Well, small and midsized businesses. According to the SBA, small businesses make up about 99.9% of all firms in the US or essentially the entire business landscape. Then we have small and midsized law firms. If we define those firms of being 50 attorneys or less, they are 90% of the market according to surveys by the ABA, Clio, Thomson Reuters and the US Census.

And let’s not forget legal service providers (LSPs) and ALSPs, public service entities, technology vendors and integrators as well as the individuals who may make up class action or MDL suits.

So, the word “principles” implies standardized rules but most people don’t have those. Across the spectrum of business and legal users, governance may be formal, informal, accidental, or a technology default system.

Which reaches my second point. Remember Craig Balls statement I quoted above? “The EDRM is a reference model — not a workflow, not a structure, not an operational blueprint.  It maps what needs to be addressed, not how to do it.”

In IGRM language, principles are conceptual dependencies, not uniform policies. It’s closer to saying:

 discovery depends on retention behavior

 discovery depends on storage behavior

 discovery depends on access control behavior

 discovery depends on deletion behavior

Those behaviors may be:

 formally documented (corporate)

 legally mandated

 completely ad hoc or informal

 even accidental

Furthermore, saying that the IG model is “foundational” additionally strengthens the impression that the EDRM is providing a structural framework, what Craig Ball called “an operational blueprint” , and not the reference model it was intended to be.

So, If we rewrite the mandate in plain language, it may sound something like: Discovery operates within the realities of how information is created, stored, retained, accessed, and disposed—whether those practices are formal, informal, accidental, or technologically imposed. That governance naturally shapes what discovery can preserve, collect, process, review, and produce.

The idea is to remove the implication of standardized IG “principles”. That is, to be sure that EDRM reflects that these are not ISO style governance rules and makes clear that discovery depends on actual behavior, not formal policy. It is more inclusive of all party types and matches how the vast majority of practitioners actually work

Litigation support, forensics, and eDiscovery teams don’t ask ““What are your IG principles?” Rather, they ask, “Where is the data? How long is it kept? Who controls it? What gets deleted? What systems are in play?”

That’s just my 2 cents.

Share this

Signup our newsletter to get update information, news, insight or promotions.