| Assessment | Readiness baseline and findings report | Current-state evidence, maturity observations, gaps, risks, dependencies, and limitations | Legal, risk, compliance, technology |
| Inventory | Discoverable information-source register | Repositories, owners, custodians, formats, retention, residency, access, preservation, and collection notes | Legal operations, records, IT |
| Controls | Legal-hold and preservation control design | Triggers, notices, system actions, monitoring, escalation, release, evidence, and exceptions | Legal, records, system owners |
| Procedures | Collection-readiness playbooks | Authorisation, extraction, metadata, chain of custody, quality checks, transfer, and provider handoff | IT, security, discovery providers |
| Operating model | RACI and governance model | Accountabilities, decision rights, forums, escalation, reporting, and review cadence | Executives and control owners |
| Roadmap | Risk-prioritised remediation backlog | Actions, owners, sequence, dependencies, acceptance criteria, cost drivers, and decision gates | Programme and service leaders |
| Assurance | Testing and exercise pack | Scenarios, test scripts, evidence requirements, observations, corrective actions, and retest criteria | Internal audit, risk, legal operations |