Skip to content

Evidence request lists

ISO/IEC 27050 - Electronic Discovery (Parts 1-4)

Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Part 1 Overview

27050-1.1
eDiscovery Scope and Terminology

Define the scope and terminology for electronic discovery activities within the organisation, aligned with ISO/IEC 27050-1.

Artefacts an auditor will ask for
  • eDiscovery scope statement
  • glossary aligned with the standard
  • stakeholder map for ESI custodians
Where this commonly fails
  • scope limited to email and file shares ignoring chat and SaaS
  • inconsistent terminology between legal and IT
27050-1.2
ESI Lifecycle Overview

Document the electronically stored information lifecycle from identification through presentation, mapping each stage to organisational responsibilities.

Artefacts an auditor will ask for
  • ESI lifecycle diagram
  • RACI matrix per lifecycle stage
  • policy referencing each stage
Where this commonly fails
  • lifecycle ends at production without disposition stage
  • no owner for cross-functional stages

Part 1: Overview and Concepts (ISO/IEC 27050-1:2019)

27050-1.4
Terms and definitions

Key electronic discovery terminology including ESI, custodian, and preservation

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
27050-1.5
Overview of electronic discovery

General overview of the electronic discovery process and its importance in legal proceedings

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
27050-1.6
Electronic discovery process elements

Description of identification, preservation, collection, processing, review, analysis, and production of ESI

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
27050-1.7
Electronically stored information

Common ESI types, common sources, and characteristics of electronically stored information

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak

Part 2 Governance

27050-2.1
eDiscovery Governance Framework

Establish a governance framework for eDiscovery covering accountability, policy and integration with legal, compliance and IT functions.

Artefacts an auditor will ask for
  • eDiscovery governance policy
  • steering committee terms of reference
  • integration map with legal, compliance and IT
Where this commonly fails
  • eDiscovery treated as one-off project not ongoing capability
  • legal owns policy without IT operational input
27050-2.2
Roles and Responsibilities

Define eDiscovery roles including legal counsel, eDiscovery project manager, IT, records management, custodians and external counsel.

Artefacts an auditor will ask for
  • RACI for eDiscovery roles
  • role descriptions with required competencies
  • training records for designated roles
Where this commonly fails
  • custodian role undefined leading to inconsistent collections
  • no project manager assigned for complex matters
27050-2.3
Risk Management for eDiscovery

Identify, assess and treat risks specific to eDiscovery including spoliation, privilege waiver, data privacy and chain of custody.

Artefacts an auditor will ask for
  • eDiscovery risk register
  • privilege protection procedures
  • cross-border data transfer assessments
Where this commonly fails
  • risk register copy of generic IT risks without eDiscovery specifics
  • no privilege review workflow

Part 2: Guidance for Governance and Management (ISO/IEC 27050-2:2018)

27050-2.4
Policies and Procedures

Maintain documented policies and procedures for legal holds, preservation, collection, processing, review and production of ESI.

Artefacts an auditor will ask for
  • legal hold policy
  • preservation procedures
  • review and production playbooks
Where this commonly fails
  • policies exist on paper but no operational playbooks
  • no version control or review cycle
27050-2.5
Policy and compliance

Setting electronic discovery policy and achieving compliance with external and internal requirements

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
27050-2.6
Risk ownership and management

Identifying risks related to electronic discovery and establishing ownership and accountability

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
27050-2.7
Records management integration

Integrating electronic discovery governance with organizational records management practices

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak

Part 3 Procedures

27050-3.1
Identification of ESI

Identify potentially relevant ESI sources, custodians and locations at the start of a matter using documented procedures.

Artefacts an auditor will ask for
  • data source inventory
  • custodian interview templates
  • identification reports per matter
Where this commonly fails
  • data source inventory not maintained
  • custodian interviews skipped under time pressure
27050-3.2
Preservation of ESI

Preserve identified ESI through legal holds, suspension of routine deletion and protection of metadata and chain of custody.

Artefacts an auditor will ask for
  • legal hold notices with acknowledgements
  • hold release records
  • evidence that deletion routines were suspended for held data
Where this commonly fails
  • legal hold notices never acknowledged by custodians
  • deletion routines continued on held data
27050-3.3
Collection of ESI

Collect ESI using forensically defensible methods that preserve metadata and chain of custody, documented in collection logs.

Artefacts an auditor will ask for
  • collection plan per matter
  • tool validation records
  • hash values and chain of custody logs
Where this commonly fails
  • collections performed via drag and drop losing metadata
  • no chain of custody documentation
27050-3.4
Processing of ESI

Process collected ESI to extract text, normalise formats, deduplicate and prepare for review while maintaining defensibility.

Artefacts an auditor will ask for
  • processing specifications
  • deduplication and near-deduplication logs
  • exception reports for items requiring manual handling
Where this commonly fails
  • processing exceptions discarded silently
  • no documentation of processing settings used
27050-3.5
Review and Analysis

Review processed ESI for relevance, privilege and confidentiality using defensible workflows including technology-assisted review where appropriate.

Artefacts an auditor will ask for
  • review protocol
  • reviewer training records
  • TAR validation statistics where used
Where this commonly fails
  • TAR used without validation metrics
  • privileged documents missed due to insufficient reviewer training
27050-3.6
Production of ESI

Produce reviewed ESI in agreed formats with appropriate redactions, load files and production logs.

Artefacts an auditor will ask for
  • production specifications agreed with requesting party
  • redaction logs
  • production manifests with hash verification
Where this commonly fails
  • redactions applied as image overlay without removing underlying text
  • no verification that production matches manifest
27050-3.7
Presentation of ESI

Prepare and present ESI in proceedings with appropriate authentication, demonstratives and witness preparation.

Artefacts an auditor will ask for
  • authentication declarations from collection custodians
  • demonstrative exhibits
  • witness preparation logs
Where this commonly fails
  • authentication relies on memory of collectors no longer with the organisation
  • no contingency for technical failures in proceedings

Part 3: Code of Practice (ISO/IEC 27050-3:2020)

27050-3.8
Review, analysis, and production

Requirements for reviewing, analyzing, and producing ESI in response to discovery obligations

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
27050-3.9
ESI lifecycle management

Requirements spanning the lifecycle of ESI from initial creation through final disposition

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak

Part 4 ICT Readiness

27050-4.1
ICT Readiness Assessment for eDiscovery

Assess organisational ICT readiness to support eDiscovery activities efficiently and defensibly.

Artefacts an auditor will ask for
  • ICT readiness assessment report
  • gap analysis against ISO/IEC 27050-4
  • remediation roadmap
Where this commonly fails
  • readiness assessed only against current systems ignoring new SaaS adoption
  • remediation roadmap without funding
27050-4.2
Data Map and Inventory

Maintain an enterprise data map covering all repositories that may contain potentially responsive ESI.

Artefacts an auditor will ask for
  • enterprise data map covering on-premises, cloud, mobile and SaaS
  • update cadence and ownership
  • integration with information asset register
Where this commonly fails
  • data map excludes collaboration and chat platforms
  • no refresh cadence after SaaS additions
27050-4.3
Retention and Disposition

Implement retention schedules and disposition controls that align with eDiscovery obligations, including legal hold suspension.

Artefacts an auditor will ask for
  • records retention schedule
  • auto-deletion rules with legal hold integration
  • disposition logs
Where this commonly fails
  • auto-deletion not paused by legal holds
  • retention schedule out of step with regulatory requirements
27050-4.4
Tools and Technology

Select, validate and maintain tools used for eDiscovery activities including preservation, collection, processing and review platforms.

Artefacts an auditor will ask for
  • tool inventory with vendor and version
  • validation and testing records
  • tool change management evidence
Where this commonly fails
  • tools used without validation evidence
  • updates applied without re-validation
27050-4.5
Cloud and SaaS Considerations

Address eDiscovery challenges introduced by cloud and SaaS including data location, provider cooperation and export limitations.

Artefacts an auditor will ask for
  • cloud provider eDiscovery capability assessments
  • contractual eDiscovery support clauses
  • export testing for each major SaaS platform
Where this commonly fails
  • no eDiscovery clause in cloud contracts
  • export capabilities never tested until first matter

Part 4: Technical Readiness (ISO/IEC 27050-4:2021)

27050-4.6
Proactive measures

Proactive measures that organizations can implement to enable effective and appropriate electronic discovery

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
27050-4.7
Technical infrastructure

Guidance on technical infrastructure requirements for collection, processing, and review tools

Artefacts an auditor will ask for
  • eDiscovery policy
  • ESI inventory
  • Legal hold procedure
  • Production workflow
Where this commonly fails
  • No legal hold workflow
  • ESI inventory stale
  • Production inconsistent
  • Records integration weak
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.