ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Part 1 Overview
Define the scope and terminology for electronic discovery activities within the organisation, aligned with ISO/IEC 27050-1.
- eDiscovery scope statement
- glossary aligned with the standard
- stakeholder map for ESI custodians
- scope limited to email and file shares ignoring chat and SaaS
- inconsistent terminology between legal and IT
Document the electronically stored information lifecycle from identification through presentation, mapping each stage to organisational responsibilities.
- ESI lifecycle diagram
- RACI matrix per lifecycle stage
- policy referencing each stage
- lifecycle ends at production without disposition stage
- no owner for cross-functional stages
Part 1: Overview and Concepts (ISO/IEC 27050-1:2019)
Key electronic discovery terminology including ESI, custodian, and preservation
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
General overview of the electronic discovery process and its importance in legal proceedings
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Description of identification, preservation, collection, processing, review, analysis, and production of ESI
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Common ESI types, common sources, and characteristics of electronically stored information
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Part 2 Governance
Establish a governance framework for eDiscovery covering accountability, policy and integration with legal, compliance and IT functions.
- eDiscovery governance policy
- steering committee terms of reference
- integration map with legal, compliance and IT
- eDiscovery treated as one-off project not ongoing capability
- legal owns policy without IT operational input
Define eDiscovery roles including legal counsel, eDiscovery project manager, IT, records management, custodians and external counsel.
- RACI for eDiscovery roles
- role descriptions with required competencies
- training records for designated roles
- custodian role undefined leading to inconsistent collections
- no project manager assigned for complex matters
Identify, assess and treat risks specific to eDiscovery including spoliation, privilege waiver, data privacy and chain of custody.
- eDiscovery risk register
- privilege protection procedures
- cross-border data transfer assessments
- risk register copy of generic IT risks without eDiscovery specifics
- no privilege review workflow
Part 2: Guidance for Governance and Management (ISO/IEC 27050-2:2018)
Maintain documented policies and procedures for legal holds, preservation, collection, processing, review and production of ESI.
- legal hold policy
- preservation procedures
- review and production playbooks
- policies exist on paper but no operational playbooks
- no version control or review cycle
Setting electronic discovery policy and achieving compliance with external and internal requirements
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Identifying risks related to electronic discovery and establishing ownership and accountability
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Integrating electronic discovery governance with organizational records management practices
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Part 3 Procedures
Identify potentially relevant ESI sources, custodians and locations at the start of a matter using documented procedures.
- data source inventory
- custodian interview templates
- identification reports per matter
- data source inventory not maintained
- custodian interviews skipped under time pressure
Preserve identified ESI through legal holds, suspension of routine deletion and protection of metadata and chain of custody.
- legal hold notices with acknowledgements
- hold release records
- evidence that deletion routines were suspended for held data
- legal hold notices never acknowledged by custodians
- deletion routines continued on held data
Collect ESI using forensically defensible methods that preserve metadata and chain of custody, documented in collection logs.
- collection plan per matter
- tool validation records
- hash values and chain of custody logs
- collections performed via drag and drop losing metadata
- no chain of custody documentation
Process collected ESI to extract text, normalise formats, deduplicate and prepare for review while maintaining defensibility.
- processing specifications
- deduplication and near-deduplication logs
- exception reports for items requiring manual handling
- processing exceptions discarded silently
- no documentation of processing settings used
Review processed ESI for relevance, privilege and confidentiality using defensible workflows including technology-assisted review where appropriate.
- review protocol
- reviewer training records
- TAR validation statistics where used
- TAR used without validation metrics
- privileged documents missed due to insufficient reviewer training
Produce reviewed ESI in agreed formats with appropriate redactions, load files and production logs.
- production specifications agreed with requesting party
- redaction logs
- production manifests with hash verification
- redactions applied as image overlay without removing underlying text
- no verification that production matches manifest
Prepare and present ESI in proceedings with appropriate authentication, demonstratives and witness preparation.
- authentication declarations from collection custodians
- demonstrative exhibits
- witness preparation logs
- authentication relies on memory of collectors no longer with the organisation
- no contingency for technical failures in proceedings
Part 3: Code of Practice (ISO/IEC 27050-3:2020)
Requirements for reviewing, analyzing, and producing ESI in response to discovery obligations
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Requirements spanning the lifecycle of ESI from initial creation through final disposition
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Part 4 ICT Readiness
Assess organisational ICT readiness to support eDiscovery activities efficiently and defensibly.
- ICT readiness assessment report
- gap analysis against ISO/IEC 27050-4
- remediation roadmap
- readiness assessed only against current systems ignoring new SaaS adoption
- remediation roadmap without funding
Maintain an enterprise data map covering all repositories that may contain potentially responsive ESI.
- enterprise data map covering on-premises, cloud, mobile and SaaS
- update cadence and ownership
- integration with information asset register
- data map excludes collaboration and chat platforms
- no refresh cadence after SaaS additions
Implement retention schedules and disposition controls that align with eDiscovery obligations, including legal hold suspension.
- records retention schedule
- auto-deletion rules with legal hold integration
- disposition logs
- auto-deletion not paused by legal holds
- retention schedule out of step with regulatory requirements
Select, validate and maintain tools used for eDiscovery activities including preservation, collection, processing and review platforms.
- tool inventory with vendor and version
- validation and testing records
- tool change management evidence
- tools used without validation evidence
- updates applied without re-validation
Address eDiscovery challenges introduced by cloud and SaaS including data location, provider cooperation and export limitations.
- cloud provider eDiscovery capability assessments
- contractual eDiscovery support clauses
- export testing for each major SaaS platform
- no eDiscovery clause in cloud contracts
- export capabilities never tested until first matter
Part 4: Technical Readiness (ISO/IEC 27050-4:2021)
Proactive measures that organizations can implement to enable effective and appropriate electronic discovery
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Guidance on technical infrastructure requirements for collection, processing, and review tools
- eDiscovery policy
- ESI inventory
- Legal hold procedure
- Production workflow
- No legal hold workflow
- ESI inventory stale
- Production inconsistent
- Records integration weak
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.