From Information Governance to Governed Intelligence for Trustworthy AI
This episode explores why strong information governance is essential for trustworthy AI. The discussion covers the importance of knowing what data an organization has, where it is stored, and who is responsible for it. Chris discusses Legal RM’s priorities for 2026, including AI-ready data foundations, accelerated defensible disposal, and deeper integrations across information repositories. The conversation also examines 90-day implementation outcomes, auditability, policy enforcement, cost savings, and governance gaps across systems such as document management platforms, email, file shares, and chat.
Jim: AI isn't some magic wand; it is simply an echo chamber. If you have poor data, you're going to have extremely poor outcomes. Firms are rushing to adopt AI and discovering that data is not governed well. The data is over-retained, it's misclassified, or it's completely under-governed. You can't really do AI well without good information governance first.
That's where we're focused on this governance intelligence. Information governance used to be enough to be thought within law firms. It is front and center in today's world, with a foundation that makes AI trustworthy.
All right, so today is Global Information Governance Day 2026. We have five identical questions: real answers on time to value, defensibility, integrations, and AI governance.
So again, welcome to the InfoGov Hot Seat, the show where information governance flips into governed intelligence and data becomes your AI advantage.
I'm Jim Merrifield, here for this Global Information Governance Day special. I am joined by my co-host for today, Lee. Lee, thanks so much for being here.
Lee: Thanks, Jim. I'm looking forward to the conversation and hearing more from our partners and what teams can actually implement this year.
Jim: Yeah, absolutely. And of course, looking forward to having the conversation with you and the others. So let's bring our friend from the UK.
Hi there. Here's our buddy. What's up, Chris?
Lee: Hey, Chris.
Jim: We're glad that you took time to join us in the hot seat. Of course, Chris, CEO of Legal RM, focusing on—I comply, apply, legal RM. I'm pretty sure I know you're the CEO, but you know what you're doing at Legal RM, and maybe even something personal. I know you travel, so maybe something fun you've been doing.
Chris: Yeah, well, first of all, before I get started with that, I want to say thank you to you, Jim, and Lee, for hosting this event. Also, the backing of the communities and getting together is what we in the information governance world absolutely need.
Information governance used to be enough to be thought within law firms, especially. It is front and center in today's world. And it's largely thanks to people like you, who are spokespersons for this, and the commitment and the backing of the communities.
We see that now with it. We call it an industry, and also with a lot more focus on information governance as firms grow.
So I just want to say that from the get-go.
Really, I'm going to give you an idea of how I got started in IG.
It all started with romance. I moved to Paris after my degree to go and see my girlfriend at the time, and couldn't find a job in an independent law firm looking after their records and their IT.
Who would have known that I'd end up on the supplier side and ended up working for Lateral, Hummingbird, the legal key product suite, which was conflicts, information barriers, and records.
In fact, it was mainly physical records, but there was some integration with iManage, and also with DMS, which was the Hummingbird product.
By the way, I started Legal RM because I saw that firms were drowning in unmanaged records, both physical and electronic, and there was a need to bring together one single platform.
Initially, we weren't doing that. We were providing consultancy to help people get the most out of those older products. Before we realized that there was nothing on the market, we worked with a couple of products—a product called FileTrail, a product called Legal Key—and we did some IRM work even.
Then we saw, well, these aren't good enough for the industry, and so we developed from the ground up our own products, which we launched in 2019.
So yeah, that's a bit of a background on me and how we ended up here.
Jim: Yeah, you've been around ever since, you know, and that's great.
So let me ask you, let's get started here. What do you wish every organization did before they called it an IG program?
Chris: I would say, probably know what you have, where it is, and who's responsible for it. Because with that visibility, everything is just guesswork.
But I also agree with what Nick's comment earlier about not selecting perfection. Don't let perfect be the enemy of the good.
The other thing to say, really—and this is a theme I think we're going to repeat multiple times—is you can't really do AI well without good information governance first, with a foundation that makes AI trustworthy.
So, which is why we've become more mainstream and more important to firms, because we touch on the business rather than on the risk or education aspects.
Jim: I mean, you teed that up so nicely. That's why we're calling this, from here and now, governed intelligence. Governed intelligence. It's IG flipped, right? So, great. You teed that up nicely.
Jim: So, Chris, with all the things going on, what would you say are the top three capabilities you're prioritizing in 2026? I know you're getting a lot of information from your customers and from the industry. What specific customer problems are driving those investments?
Chris: So before I touch on that, I just want to say we employed a Chief AI Officer back in November ourselves, because we wanted to look at both our product suite and adopting AI.
I think certainly other providers have talked about that already, but we see it as central not only to our product suite and where it's going forward, but also in terms of our business.
I think the last speaker mentioned about how AI is pervasive in its place, if it's everywhere. Some firms have connected it with their SharePoint and their OneDrive.
In our business, we have AI connected to our support solution, our CRM, our SharePoint, my emails, Teams—so everything is interconnected. So if I need to know what's going on with a client, I can see it, as long as I have permissions to see it, with no systems. It's very important.
With that said, really, our thing is looking at AI-ready data foundations.
I don't think it's just a solution from us. Aaron touched on it about iManage there: AI classification to better classify, or bring into the iManage world, content within emails under a client-matter structure.
I also think that there's people like NetDocuments with their AI classifier, or auto-classifier, which will go through the whole library or cabinets and pull out additional metadata sources.
But also, I think firms are rushing to adopt AI and discovering that data is not governed well within unstructured data sources. Many of the data's over-retained, it's misclassified, or it's completely under-governed. And that is where it becomes not only a liability to the firm, but also a liability where any AI—
AI isn't some magic wand. It is simply an echo chamber or amplifier of good solutions, but also poor ones. So if you have poor data, you're going to have extremely poor outcomes when it comes to using AI tools, in my view.
We want to invest in making AI-compliant platforms that ensure data is clean, classified, and policy-compliant.
Firms will move to an IG framework rather than an IG team, or an IG tool which might have one or two things. When they procure new tools, they will ensure that it meets the framework for a governance platform I was talking about.
As number one—sorry, I'll go quickly through the other ones.
The next one is accelerated, defensible disposal. The biggest pain point we hear from firms is that they know they're over-retaining. There's a huge amount of information, but if you could boil that down and say, if one partner and one client approve, you get one approval, you can clear down 150,000 documents in 20 boxes, you're going to get more bang for your buck.
So, looking and delivering the absolute obvious, so the business benefit is delivered to the business, to the IG teams, and not buried in some reports. That's the second part where we're looking at really getting rid of that ROT.
The other thing is looking deeper across-platform governance.
We're looking at launching—we're going to come to this a bit further in the conversation—we have integrations with iManage Work, with NetDocuments, and the different flavors of iManage: single-tenancy, on-premise, and cloud.
Although I think nobody's really touched upon—I heard the last speaker say, “It's just APIs, it's just APIs.” No one talks about the weaponization of APIs, the throttling of APIs, or even if the law firm's own access to those APIs is subject to acceptable use.
It's really important that you will do your due diligence to ensure that you have access to do the work you need to do.
Anyway, just to say, iManage, NetDocuments, Office 365, so we have integrations with OneDrive and SharePoint, file shares, whether they be dual AWS, Windows-based, and of course physical records. But we're also going to be deepening our integrations with those repositories.
That's going to also take a two-pronged approach. Our next release is going to have multiple integration points, but we also have the ability to provide ad hoc integrations.
Sometimes there is no business benefit in building a new integration piece. You just need a reminder, and you want a holistic policy engine allowing you to have a governance framework.
Instead of spending a lot of money and time building an integration piece, you may just want a pointer with the necessary metadata understanding to ensure that in 10 years' time, when you want to destroy that content, you're reminded and you know exactly where it is.
Jim: You've got a lot of capabilities there, Chris. So let us ask you: what does a successful 90 days look like in your platform?
Chris: I'm going to almost say the Fifth Amendment to start with, and I'll come and give you an answer.
It depends heavily on the firm—very heavily—and that will be based on the quality of their information and the classification that you're walking into.
If you're going to have to do a cleanup job and a huge amount of mapping, it's going to be a lot slower and you're going to deliver a lot less value within those 90 days.
It's also based on the size of the firm and oftentimes the type of work they do or the number of mergers and combinations that they've done over a period of time.
Because if the data is poor, it's going to be challenging.
My view is, number one, it's going to be visibility within that 90-day period. You want visibility on the information assets across the different repositories that you're connecting to, whether that's a migration of physical records, NetDocs, iManage, SharePoint, and physical records. You want to have that visibility there.
It's the policy application, ensuring that they've got visibility and they understand what their policies are, and they have set the application of those policies.
You can see whether you can identify whether or not it's in our policy engine. It's extremely powerful.
It can be a firm-wide policy. It can be at practice-group level, department or practice-group level. It can be at client level, matter level, sub-matter level, or attorney level. It can be at file type or document type level. It can be at matter type level, or a combination of all of those things.
So it can be granular down to the individual document level, and it can be subject to a number of approvals.
Matching that policy into the visibility of the content, and then looking at the first disposition. So of course, it's a reduction of ROT.
I know in the planning for this, you want to give a concrete kind of outcome, an idea. I'm not going to name the firm, but it's on our website.
One firm in Europe put our system in, and within six months they had saved $100,000 in physical records destruction from the implementation.
But I will caveat that by saying they also changed their off-site storage vendor at the time. So they were able to make those destructions and not pay ridiculous fees or be beholden to the off-site storage vendor, saying we're doing 50 boxes a week or whatever.
The other thing I would say is, for a typical project where we're only doing electronic records, it is the removal of the overage charges that some of the DMS vendors charge, which can be significant in nature.
What is the return on investment? If you're paying $50,000 in overage charges or $150,000, you can bet your bottom dollar that those overage charges are related to redundant, obsolete, or trivial data.
If you get rid of that, you'll be able to remove those overage charges. So it's cost savings.
Jim: Yeah.
Lee: Chris, there are a couple of things that I wanted to extrapolate and follow up on. Visibility, policy enforcement—all of those are obviously key components of any governance initiative.
How do you prove in an audit or dispute that the policies a firm establishes are complied with consistently? What evidence do you produce that details that—in order to report approval trails, exception handling, things like that?
How do you handle the audit process and report back on what those activities were?
Chris: All of the above. Those who have seen our systems know that you can report on every selection. Every action is logged within the system. Retention policies are applied.
We gather and look at who's approved which assets. When I say assets, I mean down to the granular individual information asset—the particular documents or the particular physical record—and there are notes.
So the evidence can be produced: the policy application log, which policy was applied to which asset, when the rule was triggered, whether that was matter closure, last bill dates, creation dates.
If it's at company level, practice-group level, client level, matter level, practice group, whatever, there's so many different options.
Then looking at the approvals, you may have different approvals based on different policies or different areas of law. Again, they can be sequential or they can be all at the same time—who's approved and when, and which vast batch of assets that relates to.
Looking at exception handling: when there's a legal hold, if there's a partner override, or we're pending destruction, but we've got the approval and it's pending for whatever reason because there's one extra level of approval.
We can even produce disposition certificates within the application as well.
The application in itself is the proof because it's completely audited. And I know that one of your questions you were alluding to here was, so how long do you keep this proof?
Whilst we can instruct the deletion of records within iManage, NetDocuments, SharePoint, OneDrive, a file share, or even integrate with the off-site storage vendors to send a request for destruction, those assets will be destroyed, but we will keep the audit of what was there, when, what policy was applied, who approved, and when it was destroyed.
Just a little side note: when we put destruction in, because there's nervousness sometimes when you go into an iManage and NetDocuments environment—nervousness about, “Oh my God, they might destroy everything”—we don't do hard deletions. We do soft deletions, so it goes into a recycling queue, so that you as a firm continue to manage and control what is actually permanently destroyed.
Usually those recycling bins stay in after a 20- to 28-day cycle, so that's kind of important.
Lee: A lot of information.
Jim: Yeah, we need those reports so we can see what actually happened, for numerous reasons. So thanks for sharing that, Chris.
Chris: Can I just say, we also allow you to apply costs associated with cost or savings associated with every action within the application.
Not many of our clients use that, I find, but it's there, and you can go down to the point—I don't know—five below a cent of a dollar. Five zeros after a cent of a dollar.
So you can actually calculate how much your savings are, so IG isn't seen as a cost center but a profit center.
Jim: I like that.
Lee: Chris, we talked a little bit at the outset, when you first joined, about repositories and the various tools your platform covers, such as DMS, email, 360, and file shares.
Where are you seeing any gaps? Can you see, like, chat, for instance? Is that still a gap in systems, or with classifications and things?
Chris: I think that the firms—we haven't seen anything we do—anything, anything, anything.
So we haven't had any gaps in what we do because of where firms are on catch-up to where our product is at.
Most firms are looking at either their DMS first and then their physical records, or physical records and DMS. Then they go into SharePoint. We have some firms where there is a half-and-half split, where they're using a DMS vendor on half of their firm and half using SharePoint.
In that case, we manage both the physical records, the content in their SharePoint, and the content in the DMS. For that individual firm, I'm thinking, although they don't even use physical records, then it uses it for that. But currently, we have addressed the areas where there is proper classification or strong classification.
As I mentioned before, that includes physical records, the content in a structured DMS, structured file shares wherever they're based—OneDrive, SharePoint.
There are connectors we're putting in place where there is not so much a risk profile, but more of a cost benefit. Things like iManage, TitanFile, Box, where there's a true return on investment if you can reduce down the content over here.
I see a need for more and more connectors, or at the same time, restructuring or looking at tools. Tony mentioned that ActiveNav is one tool which looks for dark data within unstructured data sources. There are other tools. I think that is a growth area, where firms will want to look at those massive terabytes of data within unstructured file shares and unstructured emails.
And I think we are part of the solution on that. The areas where there are gaps, in my view today, can be dealt with by using the ad hoc data sources I mentioned within our application.
In the interest of time—I know we've covered a lot of ground, and we're getting close to the top of the hour—but Chris, can I ask you one final takeaway?
In one sentence, what should listeners do in the next 30 days to improve IG outcomes?
I think it's like most of the other people have said, which is really what I said at the beginning: don't let the good be the enemy of perfection, or the enemy of good.
Talks about this a lot: look at picking the most overdue disposition lists, or a particular large client, or whether there's one particular attorney or partner. Get it approved. Get it destroyed, because bad news travels fast, but good news travels fast as well.
Look for champions and celebrate success. People like to be part of success, and if you celebrate it, it will proliferate around the firm and across the firm. It's very important.
Thank you. Yeah, I agree with you. Chris, thanks for joining us today. I mean, this was fun.
Thank you. Thank you, guys. Thank you very much for everything you do.
Yeah, absolutely. Right, Chris. Thanks so much.
Thanks, Chris.
Thank you. Bye-bye.