Legal Cyber Academy
All insights

Chain-of-Custody Gaps Go to Weight, With Three Exceptions

By the Legal Cyber Academy editorial team ·

A missing signature on a custody form almost never keeps digital evidence out. Courts treat custody gaps as matters of weight for the jury, because authentication asks only whether a reasonable juror could find the item is what it is claimed to be. Three situations break that rule: evidence that is fungible and alterable rather than readily identifiable, a gap that is actually evidence of alteration, and the case where no foundation was laid at all.

This article is educational. It is not legal advice, and it is not a substitute for reading the rules and your own jurisdiction's case law.

Why do custody gaps usually go to weight?

Because of where the question sits in the rules. Authentication under Rule 901(a) requires evidence sufficient to support a finding that the item is what its proponent claims. It is a conditional-relevance determination under Rule 104(b): the judge decides whether a reasonable juror could so find, and the jury decides whether it does. A chain-of-custody defect that leaves that threshold satisfied is argument, not exclusion.

The clearest statement of the two-track structure in a digital case is United States v. Durham. Phone-recorded videos were properly admitted on the testimony of the person who made them, and no chain-of-custody analysis was required, because the recordings were unique, readily identifiable and relatively resistant to change. The court then stated the other track explicitly: where evidence is not readily identifiable and is susceptible to alteration, a more stringent foundation is required — a chain of custody complete enough to make exchange, contamination or tampering improbable.

That is the whole doctrine in two sentences, and it is worth reading carefully, because the operative question is not "how good is the paperwork" but "which category is this item in".

People v. Goldsmith supplies the complementary point on the judicial attitude to digital alterability. Automated traffic-enforcement photographs and video were adequately authenticated by an investigating officer's testimony and were not hearsay; testimony from a technician with expertise in the operation and maintenance of the system's computers was not a prerequisite; and the court declined to require a greater authentication showing for digital images merely because digital images can in theory be altered. Perceived errors in a particular computer's operation go to the weight of the evidence rather than its admissibility unless specifically challenged.

The words "unless specifically challenged" are the crack in the wall, and the rest of this article is about what fits through it.

Which side of the Durham line is a forensic image on?

This is where lawyers and examiners most often talk past each other, and the answer is: it depends on what the exhibit is.

A hash-verified image is closer to readily identifiable than to fungible. The verification hash is a mathematical assertion that this copy corresponds to the source at acquisition. If the acquisition hash was recorded and the verification hash matches, the item is identifiable in a way a bag of white powder is not, and the custody record has less work to do.

A physical device, or data whose acquisition hash was never recorded, is on the fungible side. There is nothing intrinsic to the item establishing that it is unchanged, so the foundation has to come from the custody record — which is exactly the more stringent showing Durham describes.

A screenshot or a photograph of a screen is the hardest case, because it carries no verifiable relationship to anything. It is a representation of a display at a moment, produced by a person, with no intrinsic integrity property at all. The authentication case law bears this out: the exclusions in Griffin v. State, Commonwealth v. Mangel and United States v. Vayner all concern printouts and screen captures, and Rossbach v. Montefiore Medical Center concerned a photograph of text messages that forensic analysis showed could not have been produced on the device said to have received them.

The forensic sentence that joins this to the legal test: hash verification does not make evidence admissible, but it moves an item from the category that needs a complete custody chain into the category that can be authenticated by a witness who can say what it is. That is why ISO/IEC 27037, the SWGDE best practices for digital evidence collection and the SWGDE acquisition best practices treat hash recording at the point of acquisition as a documentation obligation rather than an optional verification step. A hash computed later, from an image whose acquisition value was never captured, proves the image has not changed since you computed it and nothing about the device.

Does the copy need the original?

Under the original-writing rules, generally no. Rule 1003 permits a duplicate to be admitted to the same extent as the original unless a genuine question is raised about the original's authenticity, or the circumstances make it unfair to admit the duplicate. Forensic practice is built on that provision: examinations are performed on working copies precisely so that the source is not disturbed.

United States v. Durham also shows the discovery-side corollary, and it is the practical answer to a device-production demand: the court upheld the handling of the defendant's requests to inspect the phone where the government produced a mirror image rather than the device, and the defence examined that image through its own forensic expert.

Lorraine v. Markel American Insurance Co. is the opinion that puts the whole sequence in order — relevance, authenticity under Rules 901 and 902, hearsay, the original-writing rules, and Rule 403 — and it is the one to hand a court that is treating authentication as the only hurdle. Its own facts are the cautionary tale: neither party's electronic exhibits could be considered because none was authenticated, emails having simply been attached to the motions rather than supported by affidavit or any other foundation.

When does a custody problem actually exclude the evidence?

Three situations, and it is worth being precise about why each is different.

One: the item is fungible and alterable, and the chain does not make tampering improbable. This is the Durham second track applied. In digital practice the recurring fact patterns are a device handled by multiple people with no log, a collection performed without write protection and without a recorded acquisition hash, and an extraction whose tool output cannot be tied to the device it came from. The exclusion in these cases is not a punishment for poor paperwork; it is a finding that nothing establishes what the exhibit is.

Two: the gap is not a gap but affirmative evidence of alteration. Here custody stops being a housekeeping question and becomes an authenticity question, and the consequences escalate past exclusion.

  • Cat3, LLC v. Black Lineage, Inc. treated the production of altered versions of emails, where the authentic versions no longer existed in native form, as a loss of information within Rule 37(e), found intent to deprive, precluded the plaintiffs from relying on their version, and ordered them to pay the fees and costs of establishing the spoliation. The forensic finding that carried it was that the altered addresses could not have arisen from any automatic or inadvertent computer process.
  • Rossbach v. Montefiore Medical Center went further: dismissal of the action was affirmed where the proffered evidence was shown to be internally impossible on the device claimed. Only the portion of the judgment sanctioning counsel was vacated, on the ground that the district court applied the wrong legal standard to the attorney.
  • Genger v. TR Investors, LLC shows the adjacent route where the integrity of the source is attacked rather than the exhibit: deletion of files and wiping of unallocated free space supported contempt of a status quo order and a substantial fee and expert-cost award.

Three: no foundation was offered at all. This is not a chain-of-custody failure and should not be argued as one. It is the Lorraine failure — the exhibit was attached, not authenticated — and the answer is a witness or a Rule 902 certification, not a better custody log.

How do you attack a custody record effectively?

Generalised complaints about gaps lose. Specific, verifiable defects that bear on whether the exhibit is what it is claimed to be win, or at least earn a hearing. The productive lines:

  1. No acquisition hash. Ask what value was recorded at collection, by what tool, and where the log is. If the answer is that the hash was computed later from the image, the integrity claim is circular.
  2. Hash mismatch, or a hash over the wrong scope. A hash over a logical container is not a hash over the source medium.
  3. No write protection. Hardware write blocker, software blocking, or nothing — and what mounted the device before imaging.
  4. Extraction type mislabelled. A logical extraction described as a physical image is a substantive misdescription of what the exhibit contains and what is absent from it.
  5. Tool version and validation. Whether the tool and version used were tested for the function relied on. The NIST Computer Forensics Tool Testing programme and the SWGDE minimum requirements for testing tools are the reference points, and Federated Testing is where an examiner can show their own validation.
  6. Time. Device clock offset, time zone, and whether displayed timestamps were normalised — the most common source of genuinely wrong conclusions in an otherwise sound examination.
  7. Unaccounted custody intervals that coincide with something. A gap matters when something could have happened in it. A gap over a weekend in a locked evidence room usually does not.

The reciprocal point for the proponent: every one of those is answerable in advance by contemporaneous documentation, and none is answerable afterwards by recollection.

Does the certification route change the custody analysis?

It formalises it. Rule 902(14) allows data copied from a device, storage medium or file to be self-authenticated where the copy is authenticated by a process of digital identification and a qualified person so certifies — hash verification, in practice — with the notice and certification requirements borrowed from Rule 902(11). The reference entry for Rules 902(13) and 902(14) sets out the provisions.

What that route does is convert the custody showing into a document that must be served in advance and made available for inspection. What it does not do is settle anything beyond the integrity of the copy: it does not establish who authored the content, and it does not survive a genuine challenge to the process. On the constitutional question, United States v. Brinson held that admitting a Rule 902(11) authenticating certificate did not violate the Confrontation Clause because the certificate was not testimonial — prepared to authenticate records rather than to prove a fact at trial — with the operative distinction being between authenticating a record and asserting a substantive fact about the defendant.

One honest caveat on the state of the law. The digital chain-of-custody case law is thinner and more fact-bound than practitioners assume; much of what circulates as rule is really the practice of particular districts and the requirements of laboratory accreditation regimes such as ISO/IEC 17025 rather than evidentiary doctrine. Where your jurisdiction has not spoken, argue from the Durham two-track framework and the standards, and do not present a lab requirement as an admissibility rule.

For the working sequence in one place, ISO/IEC 27042 on analysis and interpretation and the SWGDE guidance for personnel presenting digital evidence in legal proceedings are the two most useful references. Counsel preparing to cross-examine on these points will find the Digital Forensics for Lawyers track covers the acquisition mechanics the questions depend on.

Go deeper — courses on this

Keep reading

Get the next one by email

Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.