June 23, 2026 · Best Practices
Chain of Custody Best Practices That Withstand Judicial Scrutiny
Challenges to evidence rarely allege tampering; they point to gaps. The way to prevail is to leave no gap to point at. Seven concrete practices—grounded in federal evidence law, published standards, and appellate experience—eliminate the intervals courts scrutinize.
What Best Practices Accomplish
Most challenges to evidence do not allege that someone actually tampered with it. They point to a gap — an interval no one can account for, a transfer with no record, a device with no integrity value — and argue that the evidence therefore cannot be trusted. The way to defeat that argument is to leave no gap to point at. Federal evidence law requires proof that an item "is what the proponent claims it to be," a showing accomplished through testimony accounting for custody [1]. Published forensic guidance converges on a handful of practices that accomplish this across physical and digital evidence alike.
The Seven Core Practices
1. Document contemporaneously
Record custody events as they happen, not from memory afterward. A contemporaneous record carries far more weight than a reconstruction, and it avoids the inconsistencies that cross-examination exploits. The distinction is not merely one of preference. When testimony rests on later recollection, opposing counsel can elicit gaps, uncertainties, and competing versions. A written note made at the moment of transfer — dated, timed, and naming both parties — becomes difficult to impeach without affirmative evidence of falsification.
Contemporaneous documentation supports authentication under FRE 901 [1]. The moment custody changes hands is the moment to record it. This does not require elaborate documentation; it requires immediate documentation. NIJ guidance directs that "each person who touches an item of evidence should sign for its possession" [4], and that documentation should occur at the time of the transfer, not afterward [5].
In digital investigations, this becomes especially critical. An acquisition timestamp that is written in real time—captured by the forensic tool itself—carries far more evidentiary weight than a custodian's later statement about when an image was created. NIST SP 800-86 emphasizes that acquisition should be logged contemporaneously, including the date, time, tool used, and hash value [8]. If the log entry is made after the fact from notes or memory, any discrepancy becomes a vulnerability.
2. Minimize handoffs, and record every one
Every transfer is a potential break. Keep the number of people who handle an item small, and make every handoff a two-party event with both people identified, timestamped, and the purpose noted. An item should never move without a record.
The logic is straightforward: if evidence passes through five hands, the opposing party can cross-examine all five. If it passes through two, there is less testimony to challenge. Practical custody practice reflects this. Evidence should move from collection directly to storage, or from storage directly to analysis, with as few intermediate steps as possible. A chain involving collection → temporary holding → transit → archive → analysis → examination → report creation → trial is not uncommon, but each step is an opportunity for opposing counsel to ask, "Who exactly handled it? For how long? In what conditions? In whose presence?"
NIJ guidance makes clear that reliable methods for transfer must "accurately track items" and that documentation must identify the date, time, purpose of custody change, and the signatures of both the releasing and receiving person [5]. The form should require both signatures, creating a two-party acknowledgment. If evidence is shipped, the method must be trackable—not a manila envelope placed in a mail slot, but a recorded, signed transfer to a shipping service with a tracking number, verified on receipt. Electronic transfer of digital evidence requires similar discipline: who moved the file from one system to another? When? Verified by what method?
3. Work from copies, never originals
For digital evidence, NIST SP 800-86 is explicit: examine copies, preserve originals. Create a forensic image, verify it against the source by hash, and do all analysis on the copy. The original stays sealed. This practice serves dual purposes. First, it protects the original from accidental or incidental change. Second, and equally important, it creates an independent record of integrity. If analysis has been conducted on a copy certified against the original, no cross-examination can suggest that the analysis process itself altered the evidence.
In practice, this means that the original source device, storage media, or file should be imaged or duplicated at the moment of acquisition, before any analysis begins. The forensic examiner's work product comes from the copy; the original is preserved, logged, and stored. This is not an optional step; it is foundational to digital evidence handling. The alternative—analyzing the original directly—creates an impossible inferential burden at trial. The examiner must testify that the device or file was unchanged during the examination process, a claim that can be challenged without independent verification [9].
For practitioners, this means establishing a clear protocol: acquisition creates an image; the image is hashed and compared to the source; all subsequent examination is documented as work on the copy; and the original is never accessed again until trial, if at all.
4. Capture integrity values at acquisition
Compute a cryptographic hash (SHA-256 is the modern default) at the moment of acquisition and record it. This single step is what later lets you prove — not just assert — that the evidence is unchanged, and it supports authentication under FRE 901 [1].
A cryptographic hash is a mathematical function that produces a unique, fixed-length value for any digital object. If a single bit of the object changes, the hash value changes entirely. If the hash value at acquisition matches the hash value at trial, the object is provably unchanged. The importance of this step cannot be overstated. Without it, the examiner's testimony about integrity rests entirely on his or her credibility and procedure. With it, integrity is independent of credibility; it is mathematically verifiable.
NIST SP 800-86 directs that "hash values should be computed and recorded at the time of acquisition" [8]. These values should be documented on the custody form, in the examination report, and in any chain of custody log. For digital evidence, the hash is to integrity what a sealing timestamp is to physical evidence—it creates an objective record that permits verification.
In practice, modern forensic tools generate hashes automatically. The examiner's responsibility is to verify the reported hash and record it in the custody record contemporaneously. If the evidence is later transferred, the receiving party should independently verify the hash against the provided value. Any discrepancy is grounds for a break in chain; any match is confirmation that the evidence has not been altered.
5. Control and log access to storage
Evidence should live in access-controlled storage — physical lockers or access-controlled systems — with access logged. "It was in the office" is not custody; a locked, logged location is.
This practice is foundational. Evidence in an unlocked drawer, a shared filing cabinet, or an unsecured storage room is evidence without custody. The opposing party can reasonably argue that anyone with access to the space could have altered, substituted, or contaminated the item. NIST-IR-7928 directs that evidence "should be maintained in locked storage" and that access should be documented [3]. NIJ guidance echoes this: evidence should be kept in a "locked evidence room, cage, cabinet, or locker" [5].
For digital evidence stored on drives or servers, the principle is the same. The storage location should be access-controlled — password-protected, encrypted, or both — and access logs should be maintained. This means using evidence management systems that log who accessed what, when, and from what location. A hard drive left on an examiner's desk is a risk; the same drive in an access-controlled evidence locker with an access log is defensible.
6. Preserve the record in tamper-evident form
The custody record is itself evidence. If it can be quietly edited or back-dated, its value drops. Prefer records that are tamper-evident by construction, where altering an earlier entry is detectable.
This principle extends the integrity requirement from the evidence itself to the documentation of custody. A custody form that can be edited with a pen stroke, photocopied with alterations invisible to the naked eye, or retroactively modified on a computer creates an obvious vulnerability. Cross-examination will point out that the record is fallible; that it could have been altered; that there is no way to detect if it was.
Tamper-evident custody records are constructed to make alteration visible. A paper form with carbon copies (so that alteration of the original leaves a detectable discrepancy) is one approach. A digital record that uses cryptographic hashing—where any change to an earlier entry changes a subsequent cryptographic value, making the alteration detectable—is another. The record should be designed so that any alteration is verifiable as having occurred.
For practitioners, this means choosing custody documentation systems with this principle in mind. A form that has been printed, signed, and sealed is more difficult to alter than an editable spreadsheet. A digital system that prevents editing and logs all changes is more defensible than a system where any custodian can overwrite prior entries.
7. Make the record independently verifiable
The strongest records do not require the fact-finder to trust the custodian — they can be checked. A record whose integrity anyone can verify, without special access, is far harder to impeach than one that rests on a custodian's word.
This practice inverts the burden. Rather than the fact-finder accepting the custodian's testimony that "nothing was altered," the fact-finder can verify independently that the record shows no signs of alteration. This is possible through cryptographic verification: a hash-sealed record can be checked by anyone using the provided hash value. These methods do not require faith; they require only mathematics.
The Federal Rules of Evidence recognize this. FRE 901 permits a party to "describe a process or system and establish that it produces an accurate result" [1]. A custody documentation system that produces mathematically verifiable records — records whose integrity can be checked through cryptographic means — supports this standard. It transforms custody from a narrative that depends on credibility into a record that depends on cryptography.
How These Practices Connect to Authentication Under FRE 901
Federal Rule of Evidence 901(a) requires that "to satisfy the requirement of authenticating or identifying an item of evidence, the proponent must produce evidence sufficient to support a finding that the item is what the proponent claims it to be" [1]. For physical evidence, this is historically accomplished through custodial testimony — the chain of custody. For digital evidence, the same requirement applies, but the methods of proof are more precise. A cryptographic hash at acquisition, verification of the copy against the original, contemporaneous logging, and a tamper-evident custody record collectively satisfy this requirement.
The effect is that the seven practices above do not merely comply with good practice; they operationalize authentication. They transform what would otherwise be a narrative question—"Do you believe this custodian?"—into an objective question that can be independently verified.
Common Gaps and How These Practices Close Them
In appellate litigation, challenges to chain of custody typically exploit one of three gaps: temporal gaps (unexplained intervals), custodial gaps (transfers with no record or no signature), and integrity gaps (no method to verify that the evidence is unchanged). The seven practices directly address each.
Temporal gaps disappear when custody is documented contemporaneously. A record that shows a transfer at 2:47 p.m. on March 15, with both parties named and the purpose noted, eliminates the argument that the evidence sat unattended for an unknown period.
Custodial gaps close when every handoff is a two-party, signed, dated event. An item that moves from collection to examiner to analyst to trial, with each transition documented and acknowledged, leaves no interval for opposing counsel to question.
Integrity gaps are filled by the hash. An original digital item that was imaged at acquisition, hashed contemporaneously, and verified on receipt eliminates the inference that the evidence could have been altered. If the hash at trial matches the hash at acquisition, the item is provably unchanged. If it does not match, a break has been identified.
Implementation and Documentation
These practices are not theoretical. They are operationalized through custody documentation forms, evidence management systems, and institutional protocols. A chain of custody form should capture each of the seven practices: contemporaneous notation of the date and time; identification of both parties to each transfer; the method of transfer and the purpose; for digital evidence, the source device, the acquisition method, and the hash value; identification of the storage location; and notation of any access events. The form itself should be in tamper-evident form — printed and sealed, not editable — and should be independently verifiable, at minimum through cryptographic means.
For organizations, this means establishing a custody protocol before evidence arrives. The protocol should specify who may collect evidence, how it must be documented, where it must be stored, who may access it and under what conditions, and how it must be transferred. Examiners and custodians should be trained on the protocol. Forms and systems should enforce compliance.
Documentation Systems That Support These Principles
Modern evidence management systems can be designed to operationalize these seven practices. Such a system would ideally incorporate the following features:
- Custody events recorded contemporaneously, with built-in timestamps that cannot be backdated
- Two-party acknowledgment requirements for all transfers, with both parties identified
- Automatic capture of acquisition method, tool, source device, and hash values for digital evidence
- Access-controlled storage with automatic logging of all access events
- Tamper-evident record design that makes any alteration detectable through cryptographic verification
- Independent verifiability of record integrity without special access or privileged system credentials
These features are grounded in the practices and standards described above.
---
General information, not legal advice. Follow the rules and procedures of your jurisdiction.
Common questions
- What are chain of custody best practices?
- Seven core practices eliminate the gaps that make evidence vulnerable to challenge: (1) document custody events contemporaneously, not from memory; (2) minimize handoffs and record every transfer with two-party signatures; (3) work from forensic copies of digital evidence, preserving originals; (4) compute and record a cryptographic hash at acquisition to prove evidence has not changed; (5) store evidence in locked, access-controlled locations with logged access; (6) make custody records tamper-evident so alterations are detectable; and (7) use documentation systems that are independently verifiable [3][4][5]. These practices are grounded in Federal Rule of Evidence 901 and published guidance from NIST and NIJ [1][8].
- Which practices matter most when a record is challenged?
- When a custody record is attacked, three things are scrutinized: whether there are unexplained intervals in custody (met by contemporaneous documentation), whether transfers were witnessed and documented (met by two-party signatures on every handoff), and whether the evidence is provably unchanged (met by cryptographic hashing at acquisition and tamper-evident custody records). A cryptographic hash is particularly decisive for digital evidence, because it permits independent verification that evidence has not been altered, converting integrity from a credibility question into a mathematical one [8].
- What guidance do agencies publish on custody handling?
- NIST SP 800-86 directs that digital evidence be imaged before analysis, that hash values be computed and recorded at acquisition, and that analysis be performed on copies rather than originals [8]. NIST-IR-7928 requires that evidence be maintained in locked storage and that chain of custody records be accurate and complete [3]. NIJ guidance specifies that each person who handles evidence must sign for it contemporaneously, that transfers must identify the date, time, purpose, and releasing and receiving person, and that documentation occur at the time of transfer, not afterward [4][5]. Agencies publishing chain of custody standards typically converge on these elements [3][5].
Sources
- [1] Rule 901. Authenticating or Identifying Evidence - Federal Rules of Evidence — Legal Information Institute (Cornell Law)
- [2] Rule 901. Authenticating or Identifying Evidence — U.S. Government Publishing Office
- [3] Handbook on Biological Evidence Preservation — National Institute of Standards and Technology
- [4] Law 101: Legal Guide for the Forensic Expert - Chain of Custody — National Institute of Justice
- [5] Law 101: Legal Guide for the Forensic Expert - Maintaining a Chain of Custody — National Institute of Justice
- [6] Law 101: Legal Guide for the Forensic Expert - Chain of Custody: The Typical Checklist — National Institute of Justice
- [7] ADVISORY COMMITTEE ON EVIDENCE RULES April 19, 2024 — U.S. Courts - Judicial Conference
- [8] NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response — National Institute of Standards and Technology
- [9] Electronic Crime Scene Investigation: A Guide for First Responders, 2nd Edition — National Institute of Justice, U.S. Department of Justice
- [10] Forensic Examination of Digital Evidence: A Guide for Law Enforcement — National Institute of Justice, U.S. Department of Justice
- [11] SWGDE Published Documents — Best Practices and Position Papers — Scientific Working Group on Digital Evidence
CustodyTrack creates tamper-evident chain-of-custody records that any third party can verify. See how it works →