May 26, 2026 · Updated August 25, 2026 · Fundamentals
What Is Chain of Custody? A Complete Guide
Chain of custody is the chronological, documented record of everyone who has handled an item of evidence from collection to trial. It answers who, what, when, where, and why for every step—and establishes both authenticity and integrity.
What is chain of custody?
Chain of custody is a recorded means of verifying where evidence has traveled and who handled it before trial [1]. More formally, it is a process that tracks the movement of evidence through its collection, safeguarding, and analysis lifecycle by documenting each person who handled the evidence, the date and time it was collected or transferred, and the purpose for the transfer [8]. It is a chronological, documented record that answers five questions for every step: who had the item, what they did with it, when they had it, where it was stored, and why it moved.
Courts care about chain of custody because it serves two distinct purposes at once. First, it establishes that the evidence offered at trial is the same item that was collected—no substitution, no mix-up, no mistaken identity. Second, it provides grounds for concluding that the evidence has not been altered, contaminated, damaged, or falsified along the way. Under the Federal Rules of Evidence, authentication of evidence—showing it is what it purports to be—is a foundational requirement before a judge may allow it to be presented to a jury [1]. Chain of custody is one of the primary mechanisms for meeting that foundation.
Without a complete and documented chain, the opposing party has grounds to question the evidence's reliability. A judge may exclude it, or a jury may discount it. The stakes are high because the integrity of the entire case may turn on whether critical evidence can be trusted.
Why an unbroken chain matters
Evidence is only persuasive if it is authentic. A break in the chain—an unexplained gap in time, a missing signature, an item that changed hands without a record—gives the opposing party an opening to argue that the evidence cannot be trusted. The challenge does not always claim that evidence was actually tampered with; it simply points to the gap and allows doubt to do the work.
The legal standard reflects this reality. Courts do not require that the prosecution exclude every possibility of tampering. Instead, the government must show by direct or circumstantial evidence a reasonable probability that the evidence is authentic [19]. Gaps in the chain of custody go to the weight and credibility of the evidence rather than its admissibility [19]. But this distinction cuts both ways: while a gap does not automatically bar evidence from trial, it does invite the jury to discount it—and defense counsel will exploit that invitation.
The remedy is straightforward but rigorous: document every transfer, every storage location, and every examination, contemporaneously and in a form that cannot be quietly edited later. Contemporaneous documentation—made at the time the event occurs, not days or weeks afterward—carries far greater weight than a reconstructed record.
The core elements of a chain-of-custody record
A defensible chain-of-custody record must include specific information at each stage of evidence handling. The National Institute of Justice identifies these core elements [4]:
- Unique identifier: A number, code, or label that distinguishes this item from all others in the case and remains constant throughout the evidence's lifecycle
- Item description: A clear, detailed account of what the item is, including physical characteristics (size, color, distinguishing marks) and, when the item is found at a scene, its location and position
- Identity of the person who collected the item: Full name, title, badge number, or other identifier
- Date and time of collection: Recorded with sufficient precision that the record is unambiguous
- Location where the item was found: The scene address, building number, room number, or other geographic reference specific enough to be reconstructed
- Condition at collection: A baseline account of the item's state when seized (sealed, intact, damaged, etc.), so later condition changes can be tracked and explained
- Each subsequent transfer: For every person who took custody of the item, the record must show who released it, who received it, when, and for what purpose
- Storage and access control: Where the item was held between transfers, what security measures were in place, and whether access was restricted
- Signature or electronic transfer documentation: Each person assuming custody must sign a document or confirm receipt through a secure electronic process [4]
The specificity matters. A record that states "evidence collected" is weaker than one that includes specific details such as the collector's full name and badge number, the precise location (such as "north bedroom windowsill"), the exact time of collection, and the container used (such as a sealed evidence bag with a unique identifier and number). The more detail contemporaneously recorded, the harder it is to challenge later.
Physical and digital evidence: Different custodial demands
For physical evidence—a weapon, a biological sample, a seized device—the chain is primarily about custody and storage: sealed containers, evidence lockers, locked cabinets, restricted access, and signatures on transfer forms.
For digital evidence—files, disk images, logs, mobile phone extractions, and electronic records—custody of the physical medium is necessary but not sufficient. Digital data presents a unique challenge: it can be copied, accessed, and modified without leaving obvious traces on the original. A person can read a digital file thousands of times without changing it. They can also alter it without leaving fingerprints.
Because of this, the chain-of-custody record for digital evidence must prove not only custody but also integrity—that the specific bytes examined are identical to the bytes collected, byte for byte. This is why forensic practice pairs the custody log with a cryptographic hash of the acquired data. A hash is a mathematical fingerprint of the data: if even one bit changes, the hash changes completely and unmistakably. By recording the hash value at collection and comparing it to later hash calculations, anyone can verify that the data has not been altered [11].
The Scientific Working Group on Digital Evidence (SWGDE) provides detailed guidance on what digital chain-of-custody documentation must include [11]:
- Collection notes with details of the software employed
- Forensic acquisition logs and reports
- Screenshots of key investigative steps
- Downloaded data size and number of files
- Hash values (typically MD5, SHA-1, or SHA-256) calculated at acquisition
- File names and directory structures
- Analysis reports, with notation of any tools used and any changes made during examination
Each of these elements serves a purpose: the logs and screenshots create a contemporaneous record of what was done and when; the hash values prove the data was not altered; the file metadata and directory structures help establish that the material examined is indeed what was originally collected.
From paper forms to tamper-evident records
Traditional chain-of-custody forms are paper documents passed along with the evidence. They work, but they share an inherent vulnerability: a paper log can be backdated, rewritten, or lost in transit, and nothing about the document itself proves it has not been altered. Investigators and evidence custodians sign the form in good faith, but a signature on a piece of paper is not proof that the document was not edited after the signature was applied.
Modern practice increasingly favors records that are tamper-evident by construction—where each entry is cryptographically linked to the entries before it, so that altering any earlier entry would break the hash chain and become immediately detectable by anyone who verifies the record's integrity. This is the principle underlying secure digital custody systems: each new entry incorporates a hash of the previous entry, creating a chain of mathematical dependencies where any alteration would be immediately detectable. If someone changes a date, a name, or a transfer reason in entry #3, the hash of entry #4 will no longer match when recalculated.
Critically, this makes alteration detectable. Anyone can verify the record's integrity without needing to trust the person who created it or relying on passwords or access controls. The mathematics speak for themselves.
Responsible custodians and continuous accountability
Best practice in chain-of-custody documentation requires that each person who touches an item of evidence document that fact—either in writing or through secure electronic confirmation [4]. Each person who handles the item should make a log entry and electronically confirm or sign a receipt showing that they handled the evidence. As the item passes from person to person—from first responder to investigator to evidence custodian to laboratory analyst to prosecutor—a chain of receipts is created [1]. Gaps in this chain—missing signatures, undocumented transfers, unclear custody periods—are the primary points of vulnerability.
In practice, this means establishing a culture of accountability at every step. The first responder who collects evidence bears responsibility for initial documentation and proper packaging. The evidence custodian bears responsibility for secure storage and logging every person who accesses the evidence. The forensic analyst bears responsibility for documenting examination and maintaining digital integrity. The prosecutor bears responsibility for verifying the chain before trial and disclosing it to defense counsel.
No single person bears the entire responsibility, but each person in the chain bears responsibility for their own step. The chain is only as strong as its weakest link.
The standard for evidence condition and admissibility
Before physical objects may be admitted into evidence, the proponent must establish that they are in "substantially the same condition as when the crime was committed" [19]. This does not mean the evidence must be pristine or unchanged—fingerprint evidence or DNA evidence may be degraded, and that does not automatically render it inadmissible. But the condition at trial must be the condition that was documented at collection, subject only to changes that are explained and expected given the item's nature and storage.
A broken padlock cannot be offered as if it were intact. A bloodstain cannot be claimed to be fresh if the chain of custody shows it sat in an unrefrigerated evidence locker for six months. The chain of custody establishes what happened to the item between collection and trial; if the condition has changed, the chain of custody must account for it.
The bottom line
Chain of custody is not a formality—it is the foundation that makes evidence credible and helps establish a basis for admissibility. It rests on a simple principle: if you cannot account for where an item of evidence has been and who has had access to it, you cannot ask a court to trust it. Whether the item is a physical exhibit or a disk image, the goal is the same: a complete, contemporaneous record that answers who, what, when, where, and why for every step of the item's life. That record must be made at the time the events occur, not reconstructed afterward. And in the case of digital evidence, it must be supported by hash values and forensic documentation that prove the data's integrity. The record is the evidence's biography. Without it, the evidence's story cannot be told.
Common questions
- What is a chain of custody?
- Chain of custody is a recorded process that tracks the movement of evidence through its collection, safeguarding, and analysis by documenting each person who handled the evidence, the date and time of each transfer, and the purpose for the transfer [8]. It is a chronological, documented record that establishes both that the evidence offered at trial is the same item that was collected and that it has not been altered, contaminated, or falsified along the way [1]. To authenticate evidence under Federal Rule of Evidence 901, the proponent must establish that the evidence is what it purports to be. Chain of custody is one method for establishing this foundation, though evidence can be authenticated through other means such as eyewitness testimony or documents.
- What information must a chain of custody record contain?
- A defensible chain-of-custody record must include a unique identifier for the item, a description of what the item is, the date and time of collection, the location where the item was found, the identity of the person who collected it, the condition of the item when collected, and the signature or electronic confirmation of every person who subsequently assumed custody [4]. For each transfer, the record must document who released the item, who received it, when the transfer occurred, and for what purpose. For digital evidence, the record must additionally include forensic acquisition logs, hash values, file counts, software used, and detailed notes on any examination or analysis performed [11].
- What happens if the chain of custody is broken?
- A break in the chain—such as an unexplained gap in time, a missing signature, or an undocumented transfer—does not automatically exclude evidence from trial. However, gaps in the chain of custody go to the weight and credibility of the evidence rather than its admissibility, and courts apply the standard that the prosecution must show a reasonable probability that the evidence is authentic [19]. In practice, a broken chain invites the opposing party to argue that the evidence cannot be trusted, and it gives the jury grounds to discount or disbelieve the evidence even if it is allowed into trial.
- Who is responsible for maintaining the chain of custody?
- Each person who handles an item of evidence bears responsibility for documenting their custody of it by signing a receipt or confirming the transfer through secure electronic means [4]. The first responder who collects evidence must establish the initial chain and ensure proper packaging. The evidence custodian must maintain secure storage and log every access. The forensic analyst must document examination and maintain digital integrity. The prosecutor must verify the complete chain before trial. No single person bears the entire responsibility, but the chain is maintained through the cumulative accountability of every person who touches the evidence.
Sources
- [1] Federal Rules of Evidence Rule 901 - Authenticating or Identifying Evidence — Cornell Law School / Legal Information Institute
- [2] Federal Rules of Evidence Rule 902 - Evidence That Is Self-Authenticating — Cornell Law School / Legal Information Institute
- [3] Advisory Committee Notes - Rule 901 Authentication — U.S. Government Publishing Office
- [4] Chain of Custody Record Requirements — National Institute of Justice
- [5] Chain of Custody Typical Checklist — National Institute of Justice
- [6] Chain of Custody - Law 101 Legal Guide for the Forensic Expert — National Institute of Justice
- [7] Collecting DNA Evidence at Property Crime Scenes - Chain of Custody — National Institute of Justice
- [8] Chain of Custody - NIST Glossary — NIST - Cybersecurity and Infrastructure Security Agency
- [9] Digital Evidence Preservation - NIST Interagency Report 8387 — National Institute of Standards and Technology
- [10] What Every First Responding Officer Should Know About DNA Evidence - Chain of Custody — National Institute of Justice
- [11] Best Practices for Digital Evidence Collection — Scientific Working Group on Digital Evidence
- [12] Best Practices for Remote Collection of Digital Evidence from an Endpoint — Scientific Working Group on Digital Evidence
- [13] Digital Evidence - FBI Law Enforcement Bulletin — Federal Bureau of Investigation
- [14] Video Evidence Primer for Prosecutors — Office of Justice Programs
- [15] Admissibility in Federal Court of Electronic Copies of Personnel Records — U.S. Department of Justice
- [16] Forensic Science: Chain of Custody — Office of Justice Programs
- [17] Digital Evidence and the U.S. Criminal Justice System — National Institute of Justice
- [18] Crime Scene Investigation 2013 - A Guide For Law Enforcement — Office of Justice Programs
- [19] Core Criminal Law Subjects: Evidence: Authentication — U.S. Court of Appeals for the Armed Forces
- [20] Third Circuit Jury Instructions - Final Instructions: Consideration of Particular Kinds of Evidence — U.S. Court of Appeals for the Third Circuit
- [21] NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response — National Institute of Standards and Technology
- [22] Electronic Crime Scene Investigation: A Guide for First Responders, 2nd Edition — National Institute of Justice, U.S. Department of Justice
- [23] Forensic Examination of Digital Evidence: A Guide for Law Enforcement — National Institute of Justice, U.S. Department of Justice
- [24] SWGDE Published Documents — Best Practices and Position Papers — Scientific Working Group on Digital Evidence
CustodyTrack creates tamper-evident chain-of-custody records that any third party can verify. See how it works →
For this audience: Chain of Custody for Corporate Legal, IT & eDiscovery