| Current-state assessment | Policies, schedules, systems, ownership, controls, evidence, risks, and gaps | Findings report and heat map | Assess | Evidence access and interviews | Records / Compliance |
| Information and repository inventory | Record classes, data categories, systems, locations, owners, lifecycle state, and dependencies | Structured register | Assess | System and business knowledge | Data / IT / Business |
| Obligation and decision map | Relevant requirements, interpretations, assumptions, approvals, and review points | Traceability matrix | Design | Authorised legal validation | Legal / Compliance |
| Retention schedule | Categories, triggers, periods, exceptions, legal holds, and disposal outcomes | Approved schedule | Design | Business and legal approval | Records |
| Lifecycle control framework | Control objectives, activities, owners, evidence, frequency, and escalation | Control catalogue and RACI | Design | Control-owner agreement | Risk / Records |
| Technology requirements | Metadata, rules, workflow, hold, disposal, logging, reporting, and integration requirements | Requirements and acceptance criteria | Enable | Platform architecture and constraints | IT / Product owner |
| Implementation and remediation plan | Workstreams, dependencies, priorities, waves, risks, resources, and governance | Roadmap and backlog | Implement | Budget and delivery capacity | Programme sponsor |
| Assurance and reporting pack | Tests, results, exceptions, KPIs, issue tracking, and governance reporting | Evidence pack and dashboard | Operate | Operational data and sign-off | Compliance / Internal control |