Legal hold problems rarely start with one dramatic failure. More often, risk builds through smaller process gaps: a custodian list that goes stale, a reminder that goes out late, a preservation issue that isn’t surfaced, or a release that isn’t clearly documented. Individually, those gaps may seem manageable. Together, they can make it harder to demonstrate the reasonable, consistent preservation process Legal intended to follow.
In a recent Onit webinar on closing the gaps in legal hold processes, the throughline was straightforward: legal holds are rarely managed in one place. Most organizations run some mix of specialized technology and manual process across identifying custodians, tracking HR changes, monitoring preservation status, and reporting. Each handoff between those pieces is a place where something can slip.
A Useful Frame: The Information Governance Reference Model
Before getting into where things break down, it’s worth grounding the discussion in a framework that already exists for this. EDRM, the organization behind the Electronic Discovery Reference Model, maintains an Information Governance Reference Model that lays out a cross-functional approach to managing information, including stakeholder alignment, retention decisions, and the ongoing processes that connect them. It’s a useful reminder that legal holds don’t exist in isolation. They sit inside a broader information governance structure that touches Legal, IT, HR, and Records Management alike.
With that frame in mind, here’s where the hold lifecycle itself tends to break down.
Where the Process Breaks Down, Stage by Stage
Identifying custodians. This is the first place data goes stale. People change roles, leave the company, or pick up new responsibilities, and a manual process often doesn’t catch it. Without a way to track this in real time, the custodian list on day one of a hold can already be wrong by day thirty.
Issuing notice. Instructions vary depending on who is writing them and when. Without a defined template covering purpose, scope, suspension of routine deletion, and confidentiality, notices can end up inconsistent across groups handling similar matters.
Acknowledgment tracking. Once a notice goes out, Legal needs visibility into whether custodians have received and acknowledged it. In a manual process, those acknowledgments often land in an inbox with no structure behind them. In larger matters where a hold notice might go to hundreds of people, identifying exactly who among them hasn’t responded becomes a real burden, not a minor annoyance.
Follow-up and escalation. Reminder timing tends to be inconsistent without something automated managing it. Instead of a defined cadence, follow-up often depends on someone remembering to check for non-responses, which is exactly the kind of gap that shows up later if a hold gets challenged.
Preservation. A hold ultimately has to translate into reasonable steps to preserve potentially relevant information. But preservation activity can sit outside the day-to-day hold workflow, leaving Legal and IT to reconcile status across systems. When preservation requests, status, failures, and follow-up aren’t visible alongside the hold itself, identifying exceptions becomes harder.
Release and reporting. Releasing a custodian from a hold, and documenting that release, is easy to do inconsistently. Reconstructing who is or isn’t currently subject to a hold, at best, means pulling data from multiple systems. At worst, it’s a fully manual exercise every time someone asks.
What a Stronger Process Looks Like
A few foundations show up consistently in a process that holds up under scrutiny:
- Connection to matter context. The matter explains why a hold exists; the hold addresses what happens next. When hold activity, including notices, acknowledgments, escalations, and releases, stays tied to the matter record, Legal gets a complete view without reconciling separate systems.
- Clear custodian accountability. Knowing what each custodian is required to do, whether they’ve acknowledged it, and whether they’re actually following through, rather than assuming a notice sent equals a notice actioned.
- Consistency in notices, reminders, and escalations. The same level of detail and the same cadence applied every time, not dependent on who happens to be running a particular matter.
- Real visibility into status. Surfacing what’s complete, overdue, or needs attention through alerts, rather than requiring someone to run a report to find out something already went wrong.
The point of technology in this process is to support it, not replace judgment. Automating notice delivery, acknowledgment tracking, and status alerts doesn’t remove Legal’s role in deciding scope or handling exceptions. It removes the administrative burden that makes those small gaps likely to happen in the first place.








