September 30, 2026 · Chain of Custody
Chain of Custody Audit Checklist: What to Review
A chain of custody audit verifies that evidence has been recorded, identified, handled, and transferred without substitution, tampering, contamination, or unexplained gaps. The audit checklist confirms signature and date documentation at each transfer; unique and consistent item identification; condition notation; complete temporal records; and, where applicable, verified integrity values such as hash calculations or forensic seals.
What a Chain of Custody Audit Checks
A chain of custody audit is a systematic review of the recorded history of an evidence item's movement and handling, from collection through storage or submission to a laboratory, court, or other custodian. The purpose is to prevent substitution of, tampering with, mistaking the identity of, damaging, altering, contaminating, misplacing or falsifying the evidence. [2] An audit does not re-examine the physical evidence itself; instead, it examines the documentary and digital record that proves each person who touched the evidence identified themselves, noted the date, documented the condition, and transferred custody to a named successor.
Evidence custody audits operate at two levels. At the operational level—often within a crime laboratory, police evidence room, or investigator's office—supervisors may conduct regular reviews to confirm that handlers are following procedure. At the institutional level, laboratories accredited by the American Society of Crime Laboratory Directors Laboratory Accreditation Board (ASCLD/LAB) or those adhering to standards issued by the American Bar Association, the National Forensic Science Technology Center, the International Organization for Standardization, or the American Society for Testing and Materials generate audit reports and maintain records of their findings. [7] Accredited laboratories and other custodians of evidence establish quality assurance expectations for tracking and auditing evidence in their possession.
Core Elements of an Audit Checklist
A written chain of custody record must include the signature or initials of each individual receiving or transferring evidence, with the corresponding date for each transfer, and a corresponding identifier which specifies each evidentiary item. [1] An audit checklist verifies that these four elements—who, when, what, and sometimes where and why—appear consistently and completely throughout the custody record.
Transfer Documentation: Each person who receives or transfers an item of evidence must make a log entry, sign for its possession, and note the date. [1] As the item passes from person to person—from a collection site to a police station, from an evidence room to a laboratory, from an examiner to a storage vault—a chain of receipts is created. The audit must confirm that there is no point in this sequence where a person handled the evidence but did not document the receipt.
Item Identification: Each evidence item must bear complete identification tags and labels. [1] The audit verifies that each item identifier resolves uniquely—that the label on a container corresponds to one specific item and no other, and that descriptive information (such as item type, source, date of collection, or case number) is consistent across all transfers and custody documents. If the same item is re-labeled or split into sub-samples, the audit must trace the relationship between original and derivative identifiers.
Condition Documentation: Evidence items must be bagged, packaged, or otherwise handled in such a fashion that evidentiary value is not destroyed. [1] Audits should confirm that condition notation—such as whether a package was sealed, photographed, or marked as disturbed—is recorded at each receipt point. If an item shows signs of compromise, the audit must verify that the breach was documented and that appropriate remedial steps were taken.
Temporal Documentation: A chain of custody checklist includes, where applicable, the field location and the geographical location where the item was found or observed, the date and time of collection, and any gaps in the record. [1] The audit must verify that there are no unexplained intervals in which the item's whereabouts or handler are unknown. Under NIST and OSAC standards for initial response at scenes by law enforcement, an item shall be recorded prior to movement as well as who moved the item, why, and to where. [6]
Integrity Values and Digital Records: For items with calculated integrity measures—such as hash values for digital evidence, forensic seals, or bar-code identifiers—the audit verifies that these values are recorded and, if the custody record is electronic, that the computerized data are sufficiently secure, detailed, and accessible for review and can be converted to a hard copy when necessary. [1]
Who Audits Evidence Custody Records
Auditing responsibility flows through several institutional roles and levels.
Laboratory and Custodial Staff: All laboratories that have access to evidence must maintain accurate accountability of the chain of custody. [7] The laboratory bears primary responsibility for auditing its own records and those of items in its care. Best practice requires laboratories to maintain evidence in safe, properly controlled storage facilities and to limit the number of people who come in contact with evidence. [2]
Accreditation Bodies and Standards Organizations: Laboratories accredited by ASCLD/LAB or those adhering to recommendations issued by the American Bar Association, the National Forensic Science Technology Center, the International Organization for Standardization, and the American Society for Testing and Materials are measured for compliance through audits. [7] Failure to comply with chain of custody standards may result in revocation of accreditation or other institutional consequences until deficiencies are remedied.
Law Enforcement Agencies: Police departments and investigative agencies are responsible for auditing the custody records of evidence in their evidence rooms or under their control prior to submission to a laboratory. This responsibility extends to electronic records maintained through evidence management software or digital-evidence platforms.
Quality Assurance Functions: Larger laboratories and law enforcement agencies often employ dedicated quality-assurance staff or designate supervisory personnel to conduct periodic audits and to recommend corrective actions when gaps are identified.
Frequency of Evidence Inventory Reconciliation
A specific universal frequency for evidence audits is not mandated in federal criminal procedure rules for all evidence, apart from rail security-sensitive materials under 49 CFR § 1580.205, which requires reconciliation and documentation within specified intervals and retention for at least 60 calendar days. [4]
However, best practice and accreditation standards require continuous or regularly scheduled physical and documentary audits, commonly conducted quarterly or annually. [5] Critical infrastructure owners and operators should routinely audit chain of custody processes to demonstrate that the authenticity of data collected has been maintained across all stages and to ensure there are no gaps in custody. [5] The frequency of audits may be set by institutional policy, accreditation requirements, or legal mandate depending on the nature of the evidence, the crime, the jurisdiction, and the laboratory's accreditation status.
What Happens When an Audit Identifies a Gap
When an audit discovers that a custody record is incomplete—for example, when a transfer was not signed, dated, or documented—the institution must respond through assessment, documentation, and quality-system review.
Assessment and Documentation: The organization must develop and implement appropriate activities in response to the detected breach. [8] These measures allow the organization to determine the impact and consequences of the gap. For instance, if a chain is broken for 48 hours and the handler is unknown, the assessment might include interviews with relevant staff, a review of laboratory access logs, and a determination of whether the evidence could have been substituted, contaminated, or damaged during that interval.
Evidentiary Consequences: Without proof of an intact chain of custody, the evidence may be excluded from trial or afforded less weight by the trier of fact. [2] Under the Federal Rules of Evidence, evidence is authenticated by testimony that a matter is what it is claimed to be. [9] A broken or incomplete chain of custody can render it impossible for a witness to testify credibly that the item now in court is the same item that was collected at the scene—and, in consequence, the evidence may be deemed inadmissible or unreliable.
Quality System Review and Remediation: The audit report and gap findings are directed to the quality manual and standard operating procedures used by the laboratory. [8] Audit findings provide the basis for changes to policies, training, and monitoring. A gap in one custody record may prompt a laboratory to revise its form design, add mandatory fields, provide additional training to evidence handlers, or implement new check-in and check-out protocols in its evidence room.
Laboratory Compliance Status: Laboratories that fail to remedy chain of custody deficiencies may face suspension of accreditation or other institutional consequences.
An audit is thus not a one-time judgment that evidence is "good" or "bad"; it is a control mechanism that identifies breakdowns in procedure, prompts institutional response, and generates a record that can be presented to a court as evidence of the care (or lack thereof) with which evidence was handled.
Common questions
- What should a chain of custody audit check?
- An audit checklist verifies four core elements: (1) Transfer Documentation—that each person who received or transferred evidence signed and dated the record; (2) Item Identification—that each item bears a unique, consistent identifier across all custody documents; (3) Condition Documentation—that the physical condition of evidence was noted at each receipt point; and (4) Temporal Documentation—that dates, times, locations, and the names of handlers form a complete chain with no unexplained gaps. [1] For digital evidence or items with integrity measures such as hash values or forensic seals, the audit confirms that these values are recorded and, in electronic systems, that data are secure, detailed, accessible, and convertible to hard copy. [1]
- Who audits evidence custody records?
- Auditing responsibility is shared: laboratories accredited by the American Society of Crime Laboratory Directors Laboratory Accreditation Board or those adhering to American Bar Association, National Forensic Science Technology Center, International Organization for Standardization, or American Society for Testing and Materials standards must audit their records and maintain accurate accountability. [7] Police departments and investigative agencies audit evidence in their custody before submission to a laboratory. [2] Larger organizations often employ dedicated quality-assurance staff. Failure to comply with standards may result in revocation of accreditation or other institutional consequences.
- How often should an evidence inventory be reconciled?
- A specific universal frequency is not mandated in federal criminal procedure rules for all evidence, except rail security-sensitive materials, which must be reconciled under 49 CFR § 1580.205 within specified intervals and retained for at least 60 calendar days. [4] Best practice and accreditation standards require continuous or regularly scheduled physical and documentary audits, commonly conducted quarterly or annually. [5] The frequency depends on institutional policy, accreditation requirements, the nature of the evidence, and the jurisdiction.
- What happens when an audit finds a gap?
- The organization must assess and document the impact of the gap and implement corrective activities to determine whether evidence could have been substituted, contaminated, or damaged during the breach. [8] Evidentiary consequences may follow: without proof of an intact chain of custody, evidence may be excluded from trial or afforded less weight by the trier of fact. [2] The audit findings prompt review of the laboratory's quality manual, standard operating procedures, and training, and may result in revision of custody forms, policies, or access protocols. [8] Laboratories that fail to remedy deficiencies may face suspension of accreditation or other institutional consequences.
Sources
- [1] Archived Law 101: Legal Guide for the Forensic Expert — Chain of Custody: The Typical Checklist — National Institute of Justice (NIJ)
- [2] Archived Law 101: Legal Guide for the Forensic Expert — Chain of Custody — National Institute of Justice (NIJ)
- [3] FBI DNA Quality Assurance Audit Document (Rev. #5) — Federal Bureau of Investigation (FBI)
- [4] 49 CFR § 1580.205 — Chain of Custody and Control Requirements — U.S. Code of Federal Regulations (CFR)
- [5] Chain of Custody Best Practices — Critical Infrastructure Systems — Cybersecurity and Infrastructure Security Agency (CISA)
- [6] Standard for Initial Response at Scenes by Law Enforcement (OSAC 2021-N-0016) — National Institute of Standards and Technology (NIST)
- [7] Consulting Accredited Standards for Case File Requirements — National Institute of Justice (NIJ)
- [8] National Commission on Forensic Science — Records, Testing, and Reporting Standards — U.S. Department of Justice
- [9] Rule 901. Authenticating or Identifying Evidence — Federal Rules of Evidence (U.S. Courts)
- [10] State of the Art Biometrics Excellence Roadmap — DNA Evidence Quality Standards — Federal Bureau of Investigation (FBI)
- [11] Federal Rule of Evidence 902 — Evidence That Is Self-Authenticating (including 902(13) and 902(14) and the Advisory Committee Notes) — Legal Information Institute, Cornell Law School
- [12] NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response — National Institute of Standards and Technology
- [13] Electronic Crime Scene Investigation: A Guide for First Responders, 2nd Edition — National Institute of Justice, U.S. Department of Justice
- [14] Forensic Examination of Digital Evidence: A Guide for Law Enforcement — National Institute of Justice, U.S. Department of Justice
- [15] SWGDE Published Documents — Best Practices and Position Papers — Scientific Working Group on Digital Evidence
CustodyTrack creates tamper-evident chain-of-custody records that any third party can verify. See how it works →
For this audience: Chain of Custody for Law Enforcement & Crime Labs