---
title: What Does EDRM 2.0 Actually Change? A Litigator's Read of the New Model
description: EDRM 2.0 released September 1, 2026. A practicing litigator's read of what actually changed, what it means for in-house counsel and eDiscovery vendors, and the public-comment debate that shaped it.
---

[Proteus Blog | eDiscovery & Managed Review](https://blog.proteusdiscovery.com)

# [What Does EDRM 2.0 Actually Change? A Litigator's Read of the New Model](https://blog.proteusdiscovery.com/what-does-edrm-2-0-actually-change-a-litigator-s-read-of-the-new-model)

 Written by [Ray Biederman](https://blog.proteusdiscovery.com/author/ray-biederman) | Sep 25, 2026, 3:10:29 PM

*By **Ray Biederman**, Co-Founder, Proteus Discovery Group | Founding Partner, Mattingly Burke Cohen & Biederman | Adjunct Lecturer, Indiana University*

## Why I'm writing this

On September 1, 2026, EDRM released the first substantive rewrite of the Electronic Discovery Reference Model since 2005. If you spent the last two decades in eDiscovery, EDRM was your map. If you're new to the practice, EDRM 2.0 is now the map, and the terrain it describes is different in ways that matter for how you scope matters, hold data, choose vendors, and defend your process.

Most of the writing on EDRM 2.0 so far has come from platform vendors and industry organizations. Those pieces do a solid job explaining what changed. What they don't do is tell you what to change in your own practice, because the vendors who wrote them sell software, not judgment. I teach eDiscovery, information governance, and health information protection at Indiana University. I've testified as an expert witness on document production. I still practice commercial litigation at MBCB. So this piece is a litigator's read: what the new model actually changes, what it doesn't, and where in-house teams should look first.

## What EDRM 2.0 actually changed

Four changes matter. Everything else in the release notes is a rearrangement.

### 1. Analysis is now continuous, a band across every phase

In the original EDRM, "Analysis" was a discrete step that sat between Processing and Review. In practice, no one has done it that way in years. Everyone runs analytics during collection to test search terms, during review to categorize by concept, during production to spot privilege, and after production to defend the scope in a meet-and-confer.

EDRM 2.0 finally puts a blue band across the entire lifecycle labeled "Analysis." The description is that analysis is the "connective tissue" among iterative phases. Translation: legal judgment, data science, and AI are involved from the first custodian interview through disposition, and they never stop.

What this means for how you run matters: if you or your vendor still describe analysis as a phase that starts after processing ends, your process is dated. The proportionality argument you make in a meet-and-confer is easier when you can show the court that you tested the scope with analytics before you started collecting, not after.

### 2. Information governance moved from the side to underneath

In the old model, the Information Governance Reference Model (IGRM) sat off to one side. Practitioners either mentioned it in passing or ignored it. The result was predictable: preservation obligations attached to systems no one had governed, retention policies contradicted legal hold notices, and the "keep everything forever" default became the operating norm at most organizations.

EDRM 2.0 makes information governance foundational. It's the layer everything else sits on. Preservation, collection, processing, and review all operate against a governance model that defines what's kept, where it lives, who owns it, and how long it survives.

What this means for in-house counsel: the question "do we have a data map?" is no longer optional. If your organization can't say, on demand, what data lives where and how long it's retained, EDRM 2.0 doesn't just call it a gap. It calls it the foundation you're missing.

The IGRM placement drew opposing criticism during the public comment period, which is worth knowing if you're deciding what to make of it. One commenter argued the new placement claims too much for governance, because plenty of relevant data in real organizations is not governed at all. Another argued the opposite, that moving IGRM to a foundational layer buries it, and practitioners will lose sight of governance as the base of everything. The trustees held the placement and added a caveat that matters for how you use the model: the placement "communicates a conceptual relationship between the models rather than an assessment of the maturity or effectiveness of any particular organization's Information Governance program." Translation: your organization is not being scored by the diagram. But it is being asked whether governance is the layer everything else rests on.

### 3. Identification, Preservation, and Collection are one framework now

The old three-step sequence. Identify, then Preserve, then Collect, described a workflow that assumed you could see all the data before you touched it. Anyone who has done a Slack collection knows this hasn't been true for a decade.

EDRM 2.0 replaces the sequence with a "unified Data Acquisition" framework. The three activities still exist, but they're recognized as interdependent and iterative. You identify while you preserve, you preserve while you collect, you go back and identify more once you see what you've collected.

What this means: your legal hold protocol needs to account for the fact that identification isn't a one-time event. New systems get discovered mid-matter. Custodians remember accounts they forgot to mention. A Data Acquisition framework acknowledges this. A three-step waterfall doesn't.

Worth knowing the debate here, because it will show up in vendor pitches. Some public comments argued that Processing runs on different tools, shrinks the data it touches, and demands a different skill set, so grouping it with Identification, Preservation, and Collection blurs a distinction that matters. The trustees kept the grouping but added a clarification worth quoting to any vendor who tries to misuse the umbrella: "Data Acquisition is used as an umbrella grouping in the model. It is not intended to redefine Processing as Collection or to suggest that the activities are technically identical." In other words, the umbrella describes the relationship, not the work. A vendor who collapses Processing into Collection is misreading the umbrella.

### 4. Disposition is now an explicit phase

The old model implicitly ended at Presentation, as if data ceased to exist once it was produced. EDRM 2.0 adds a Disposition phase at the end, making explicit what defensible practice already required: what happens to the data 60, 90, or 180 days after the case closes matters, for cost, for privacy, and for exposure on the next matter.

What this means: if your discovery process doesn't specify when hosting stops, when the data is purged, and how you verify it, you're paying for storage on matters that settled years ago and carrying risk on data that should have been disposed of.

## Whether the map needed redrawing at all

The debate about EDRM 2.0 started months before the public comment window opened, and it's worth reading, because it's the debate you'll actually have with clients and colleagues.

Craig Ball, who serves as EDRM's general counsel but wrote in his personal capacity in March 2026, argued the model was never broken because it was never a workflow. "Think of it as a compass, not a GPS turn-by-turn," Ball wrote. "It orients you. It doesn't drive for you, and it ain't broke."

Doug Austin, writing on eDiscovery Today a week later, accepted the premise and rejected the conclusion. Perception had already won, he argued. Software companies were marketing on which half of the diagram they covered. Arrows had taught an industry to read a reference model as an assembly line. "It looks too much like a workflow now for most people to see it as anything else," Austin wrote.

The final model speaks to both arguments with a line of guidance printed alongside the diagram: "Although the diagram flows generally left to right, the EDRM is a conceptual view of the eDiscovery process, not a literal or linear workflow. Practitioners may perform the steps in a different order, repeat them, or circle back to earlier phases as their understanding of the data improves."

That's Ball's position, published as EDRM's own reading instruction, attached to the redesign Austin said was the only thing that would change how the diagram gets read. Both were right, in a way. And the working practitioner's takeaway is the same either way: whatever your vendor's platform diagrams look like, discovery is iterative. If a proposal or a workflow assumes strict left-to-right progression, that's the vendor's misreading of the model, not the model's misreading of the work.

## What EDRM 2.0 doesn't fix

The model is a map. It doesn't drive the car. Three things EDRM 2.0 leaves for practitioners to solve on their own:

**It doesn't tell you who owns which phase in your organization.** In-house counsel, outside counsel, and eDiscovery vendors all touch every phase. EDRM 2.0 describes what the phases are; it doesn't say whose neck is on the line when preservation fails. That's a governance question your organization has to answer.

**It doesn't tell you how to hold AI-assisted decisions defensible.** The model acknowledges AI runs throughout the lifecycle. It does not tell you what documentation, validation, or human-in-the-loop protocols you need to defend an AI-assisted privilege review or a TAR-driven production. That's on you and your vendor, and judges are getting educated fast.

**It doesn't tell you what any of this costs.** EDRM has never been a cost model. It's a process model. If you want to know what a defensible collection, review, and production actually costs at your organization, you need a different tool. Which brings us to the next section.

## Where in-house teams should look first

If you read EDRM 2.0 and want to know how ready your own organization is under the new model, the fastest path is an honest self-assessment. Not a vendor audit, the vendor has an incentive. A self-assessment your team can run in an afternoon.

I built one. It's called the [Discovery Readiness Scorecard](https://proteusdiscovery.com/discovery-readiness-scorecard). Eighteen questions, four sections, scored separately so you can see which section is your weakest, because exposure concentrates in the weakest section. It does not average out.

 

The four sections mirror what EDRM 2.0 actually asks of you:

1. **Preservation & Legal Hold.** Does your legal hold reach the systems your workforce actually uses in 2026 (chat, mobile, ephemeral messaging, collaboration tools)? This is the section where sanctions live, and it's the section in-house counsel own personally.
2. **Your Data Map.** Do you know what you have, where it lives, who owns it, and how long it's retained, before a matter opens? Nobody has a perfect data map. The point of the section is knowing what you don't know.
3. **Vendor & Cost Control.** Who chooses your eDiscovery vendor? Who signs the SOW? Who monitors spend before it hits your invoice? In most companies, the GC signs the check, rarely picks the vendor, and almost never controls scope.
4. **Defensibility.** Can you document the process for every matter, in a form that survives cross-examination? This is where in-house teams lose the most credibility with the bench.

The scorecard takes about four minutes. You'll get your score, your band, and a section breakdown that tells you where to spend the next quarter's attention. It's free and nothing is stored server-side, the answers stay in your browser.

## Frequently asked questions

### What is EDRM 2.0?

EDRM 2.0 is the September 1, 2026 update to the Electronic Discovery Reference Model, the framework that has served as the industry's map for managing electronically stored information (ESI) throughout the litigation lifecycle since 2005. It was developed by approximately 150 practitioners across the global EDRM community and is the first substantive rewrite of the model since it incorporated the Information Governance Reference Model.

### What changed in EDRM 2.0 versus the previous EDRM model?

Four substantive changes: Analysis is now a continuous band across every phase rather than a discrete step; Information Governance moved from a side panel to a foundational layer underneath the entire model; Identification, Preservation, and Collection were unified into a single "Data Acquisition" framework rather than a three-step sequence; and a Disposition phase was added at the end to make explicit what happens to data after a matter closes.

### Does EDRM 2.0 require organizations to change how they do eDiscovery?

The model isn't a rule. It's a reference. It doesn't require anything. But it does describe how the practice actually works in 2026, and organizations that are still operating against the 2005-era model are almost certainly missing preservation obligations, over-collecting, under-analyzing, and hosting data long after they should have disposed of it. EDRM 2.0 is a benchmark, how you compare against it is a business decision.

### What does EDRM 2.0 mean for in-house counsel?

Three things. First, information governance is no longer optional, you need a data map, or at least an honest inventory of what you don't know. Second, preservation is your job, not your outside counsel's, and your legal hold process needs to reach modern collaboration and messaging systems. Third, disposition is now part of the model, which means you should know when the hosting stops on every matter your organization has had in the last five years.

### What does EDRM 2.0 mean for eDiscovery vendors?

Vendors whose services are still organized around the old three-step "identify, preserve, collect" sequence are operating against a dated framework. The unified Data Acquisition framework in EDRM 2.0 assumes an iterative, analytics-driven process. Vendors who can defend their AI and analytics use across every phase, with documentation and validation, will have an easier time defending their work under the new model.

### Who created EDRM 2.0?

EDRM 2.0 was developed by approximately 150 multidisciplinary practitioners from the global EDRM community, including in-house counsel, law firms, service providers, technologists, academics, and members of the judiciary. Project trustees included Rian Kennedy, Stephanie Clerkin, Brett Burney, and Shannon Lex Bales, chaired by David R. Cohen. Mary Mack is CEO and Chief Legal Technologist of EDRM. The public comment version was released for review June 30, 2026, and the final model was published September 1, 2026.

### Is the EDRM 2.0 model free to use?

Yes. The EDRM 2.0 diagram is licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). It can be used commercially and adapted, provided you attribute EDRM.net and indicate whether the diagram has been modified.

### How does EDRM 2.0 relate to information governance and IGRM?

EDRM 2.0 builds on the Information Governance Reference Model (IGRM) version 4.1, released by EDRM in June 2026. Together, the updated IGRM and EDRM 2.0 provide an integrated reference for how organizations manage information from creation through final disposition, with discovery activities grounded by the broader governance lifecycle rather than treated as a separate discipline.

### Did the public comment period change anything in EDRM 2.0?

Yes, but modestly, and the "no change" responses are the more revealing part of the record. EDRM grouped submissions into eight sections. One produced two visual adjustments: the relevance triangle now levels off after Production rather than continuing to climb, and the Analysis band ends at Disposition rather than running past. The other seven sections received written responses explaining why the trustees made no change, ranging from a proposal to pull Processing out of the Data Acquisition grouping, to a proposal to restore the original 2005 design. The procedural rule the trustees invoked more than once: earlier votes by the roughly 100-person project team were given greater weight than individual public comments, though the substance of each comment was still considered. Reading the trustees' responses together is worth the twenty minutes, because it shows what a consensus body compromises on and what it doesn't.

## A closing framework

If you read EDRM 2.0 and want a way to think about what it means for your organization, use these three questions:

**Do we have a data map that reflects how our workforce actually operates in 2026?**  
If not, that's where governance work starts.

**Does our legal hold process reach the systems people actually use, chat, mobile, ephemeral messaging?**  
If not, preservation is the exposure to close first.

**Can we document, for any matter, when hosting stopped and when the data was disposed of?**  
If not, you're paying for storage and carrying risk on matters that closed years ago.

The Discovery Readiness Scorecard turns those three questions into eighteen specific ones. It takes four minutes. If your score surprises you, in either direction, send me the number and I'll tell you whether it's a problem or just a Tuesday.

[Take the Discovery Readiness Scorecard →](https://proteusdiscovery.com/discovery-readiness-scorecard)

Ray Biederman is Co-Founder and CEO of Proteus Discovery Group, a litigator-led eDiscovery firm headquartered in Indianapolis. He is also a founding partner at Mattingly Burke Cohen & Biederman LLP, where he leads commercial litigation, and an adjunct lecturer at Indiana University teaching eDiscovery, information governance, and health information protection. He has testified as an expert witness on document production and is recognized as a SuperLawyer and Best Lawyer in eDiscovery and commercial litigation.

If your Discovery Readiness Scorecard surprises you, reach out at [ray.biederman@proteusdiscovery.com](mailto:ray.biederman@proteusdiscovery.com). I read them all.

[View full post](https://blog.proteusdiscovery.com/what-does-edrm-2-0-actually-change-a-litigator-s-read-of-the-new-model)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Ray Biederman"
  },
  "dateModified" : "2026-09-25T15:10:29.198Z",
  "datePublished" : "2026-09-25T15:10:29Z",
  "headline" : "What Does EDRM 2.0 Actually Change? A Litigator's Read of the New Model",
  "image" : {
    "@type" : "ImageObject",
    "height" : 60,
    "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
    "width" : 60
  },
  "mainEntityOfPage" : "https://blog.proteusdiscovery.com/what-does-edrm-2-0-actually-change-a-litigator-s-read-of-the-new-model",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Proteus Blog"
  }
}
```