Skip to content

Topic hub

Evidence Handling Workflows

The lifecycle of an item from collection through presentation, the published guidance that describes each stage, and the duties carried by the people handling it along the way.

About evidence handling workflows

The lifecycle, and what each stage leaves behind

Evidence handling is usually described as a sequence: identification, collection, acquisition, preservation, transfer, examination, and presentation. The names vary between procedures and some collapse two stages into one. What matters more than the vocabulary is that each stage is expected to leave an artefact behind — an entry, a signature, a digest. A stage that produces none is a stage nobody can describe afterwards, and afterwards is when it is asked about.

The guidance most procedures reference

Two publications sit behind most written procedures in this area. ISO/IEC 27037 covers identification, collection, acquisition and preservation, and sets out principles including auditability. NIST SP 800-86 describes a forensic process aimed at incident work. Both are guidance rather than certification schemes: a procedure can reference them, and nobody is assessed against them by writing one. Treating them as a source of structure, rather than as a badge, is the honest use.

Duties travel with the item

Someone is accountable at every point — whoever collected it, whoever stored it, whoever released it, whoever received it. The boundaries between those people are where records come apart: an agency handing to a laboratory, a security team handing to counsel, an examiner handing to an instructing attorney. Recording both halves of every boundary is close to the whole discipline in one sentence, and it is the half-recorded handoff that surfaces later as a gap.

Each stage leaves a signed, chained entry instead of a note somebody has to remember — collection, handoff to counsel, handoff to a vendor, return.

Published guides

Start here

Digital Evidence Handling Procedures: A Practical Overview

Digital evidence handling is a structured lifecycle that begins when data is first identified as evidence and extends through final disposition. Each stage—identification, collection, preservation, examination, analysis, and presentation—requires specific documentation and procedural controls to maintain integrity and establish an unbroken chain of custody.

  • Digital Evidence Standards: NIST SP 800-86 and ISO 27037

    Two frameworks define modern digital-evidence handling: ISO/IEC 27037 for identification, collection, acquisition, and preservation, and NIST SP 800-86 for the forensic process. Here is how they fit together.

  • Transferring Evidence Without Breaking the Chain

    Every transfer must be documented contemporaneously with the receiving party's signature; without it, the record has a gap that invites challenge and, in some cases, exclusion.

  • Evidence Custodian Responsibilities

    An evidence custodian maintains continuous documented possession of evidence from intake through release, accounting for every person who handles it and every transfer. The custodian's central duty is to create and preserve a chain of custody—a contemporaneous record that prevents substitution, tampering, contamination, misplacing, or misidentification of evidence—and to testify, if called, that the evidence remained in substantially the same condition during custody.

  • Litigation Hold vs Chain of Custody: The Difference

    Litigation hold is the duty to preserve information when litigation is foreseeable; chain of custody is the documentation system that records what happened to preserved evidence once it is collected. They overlap in scope but serve distinct purposes, arise at different moments, and violate under different rules.

  • Chain of Custody in Expert Witness Testimony

    An expert witness establishes chain of custody by testifying to the identity and custody of evidence, the persons who handled it, and the intervals between transfers—grounding foundation in documentary evidence and personal observation. Expert testimony on these matters is subject to the same reliability and methodological scrutiny as any other expert opinion under Federal Rule of Evidence 702 and the gatekeeping standards it embodies.

  • Evidence Room Management Best Practices

    Effective evidence room management rests on written procedure, physical segregation, role-based access control, and systematic documentation. These practices help ensure that evidence remains identifiable, locatable, and accounted for throughout its lifecycle—from intake through disposition—and support preservation of the chain of custody.

  • Preserving Evidence During Incident Response

    Evidence preservation during incident response requires collecting the most volatile data first, documenting all major decisions in real time, and planning for custody transfer to investigation before the incident begins. The tension between containing a threat and preserving evidence for investigation is not fully reconcilable—only navigable through advance legal counsel and written decision protocols.

  • Collecting Evidence From Cloud Services

    Collection of cloud-held evidence begins with determining who controls the data—the enterprise custodian or the provider—because that choice governs whether you request an export from the account owner or, for the government only, seek a warrant under 18 U.S.C. § 2703. The method matters deeply: provider export tools are optimized for user convenience, not forensic completeness, so documentation of what was exported and what was deliberately or systemically excluded is essential to the chain of custody.

  • Receiving Evidence From a Client: What to Record on Day One

    When a client delivers evidence to you, document at the moment of receipt: the specific items transferred, the date and time, a description of the item's condition, any markings or alterations, the client's identifying information as the source, and your own name and role. This contemporaneous record creates the foundation of the chain of custody and must capture enough detail that the item could be identified later and its integrity assessed.

  • Chain of Custody in eDiscovery: Collection to Production

    Chain of custody in eDiscovery is maintained through documented transparency about the form and handling of electronically stored information from collection through final production. The producing party remains responsible for custody even when a vendor has possession, and this responsibility is evidenced by contemporaneous records of each step, change in form, and transfer of control.

Also planned for this hub

The full outline this subject is being written to, so you can see what is covered and what is still coming. The 4 titles below are not yet written and are not links.

  • Collecting Evidence From an Employee's Device
  • Writing a Digital Evidence Handling SOP
  • Seizing Computers and Phones as Evidence at a Scene
  • Chain of Custody for Forensic Science Students

Each is listed above as a link once written — subscribe on the guide index to be told when they publish.

Common questions

What are the stages of digital evidence handling?
Identification, collection, acquisition, preservation, transfer, examination, and presentation — though procedures name them differently and some collapse two into one. Common to every version is that each stage changes who is accountable for the item, and each of those changes is what the record has to capture. Digital Evidence Handling Procedures: A Practical Overview →
What should be recorded at each stage?
At minimum: what the item is, in terms that fit exactly one item; who acted, and in what capacity; the time, with a zone; the method or tool used; the condition of the item; and, for digital material, the digest and when it was taken. Anything the record does not say is something a witness has to remember instead. Digital Evidence Handling Procedures: A Practical Overview →
Does the recipient need to acknowledge a transfer?
A handoff recorded by the releasing party alone is half a transfer. The receiving party's acknowledgement is what closes it, and it is the half most often missing from informal handoffs — a folder in shared storage, a drive left on a desk, an emailed export. CustodyTrack seals a transfer only once both parties have signed. Transferring Evidence Without Breaking the Chain →
How does a litigation hold differ from chain of custody?
A hold is a duty not to destroy. A custody record is documentation of what happened to what was kept. Satisfying the first says nothing about the second: a preservation notice does not show who took custody of the collected set, or that the set produced months later is the one that was collected. Litigation Hold vs Chain of Custody: The Difference →

Reading about custody records is not the same as having one.

5 free Authenticated Chain of Custody Forms every month — no card required.