Evidence Collection and Chain of Custody
The protocols forensic accountants follow to collect, preserve, and transfer financial evidence from the scene of discovery to the courtroom, keeping the chain of custody intact at every step.
Last updated:
Chain of custody is the documented, unbroken record of every person who collected, handled, transferred, or stored a piece of evidence from its point of discovery to its presentation in court. In financial investigations, this discipline applies equally to paper documents, forensic images of ERP databases, email archives, and messaging data. Evidence that cannot be shown to be authentic and unaltered is legally fragile regardless of its analytical value. Forensic imaging with write blockers, cryptographic hash verification, and a sequential custody log are the technical and procedural foundations of an admissible evidence chain.
Identifying a fraud pattern in the transaction data is the analytical task. Proving that pattern in court requires something additional: the evidence must be shown to be authentic, unaltered since collection, and delivered to the courtroom through a documented, uninterrupted chain. That chain-of-custody requirement applies as rigorously to a spreadsheet exported from an accounting system as it does to physical exhibits in any other kind of case.
Financial investigations involve an unusual breadth of evidence types: paper documents from filing rooms, electronic records from ERP systems, email archives, instant-message logs, bank statements obtained by subpoena, cloud-hosted accounting data, and increasingly, records from mobile devices and collaboration platforms. Each type has its own collection method, its own preservation requirements, and its own evidentiary standards in different jurisdictions. Collection treated as an afterthought produces results that may be analytically compelling but legally fragile.
This topic covers the full lifecycle of financial evidence: the initial legal hold, document collection protocols for physical and electronic records, imaging financial systems, working with external auditors and regulators, managing third-party data, and the documentation that creates an unbreakable chain from collection to court. The goal is evidence that survives rigorous cross-examination on authenticity and integrity.
By the end of this topic you will be able to:
- Explain what a chain of custody is and describe the consequences of a break in that chain for admissibility.
- Apply forensic imaging techniques, including write blockers and hash verification, to ERP systems and digital storage media.
- Design a legal hold notice that covers data types and systems, not just named custodians, to prevent spoliation.
- Describe the collection requirements and platform-specific tools for email, instant messaging, and cloud-hosted financial data.
- Co-ordinate evidence collection with external auditors and regulators to maintain a consistent evidentiary record.
- Chain of custody
- The documented, unbroken record of every person who collected, handled, transferred, or stored evidence from its collection through its presentation in court. Each link in the chain must be verifiable to demonstrate the evidence is authentic and unaltered.
- Forensic image
- A bit-for-bit copy of a storage device or database, verified by a cryptographic hash. Work proceeds from the image, not the original, so the original remains pristine and its integrity can be demonstrated at any time.
- Hash value
- A fixed-length string generated from a file or dataset by a cryptographic algorithm (typically SHA-256 or MD5). Any change to the underlying data produces a completely different hash, making the hash a tamper-detection mechanism.
- Custodian
- In e-discovery, a person who possesses, controls, or has responsibility for documents or electronic records relevant to an investigation. Identifying custodians is the first step in scoping a document collection.
- Write blocker
- A hardware or software device that prevents any write operations to a storage device during forensic imaging. It ensures the image process does not alter the original data, which is critical for chain-of-custody and authenticity.
- ERP system
- Enterprise Resource Planning software (SAP, Oracle, Microsoft Dynamics, and similar platforms) that manages financial and operational records. ERP databases are often the primary source of transaction-level evidence in forensic accounting matters.
Legal hold: the starting gate
The legal hold was addressed in the context of engagement setup, but its operational implementation is an evidence-collection function. Once counsel issues the hold notice, the forensic accountant works with IT staff to confirm that automated deletion processes are suspended, that backup media is quarantined from routine overwriting cycles, and that a list of custodians and their relevant systems is compiled.
Two common failure points deserve attention. First, the hold notice goes to named individuals but not to the IT team managing the systems those individuals use. The individual stops deleting emails. The server continues its 30-day retention cycle and deletes the same emails from the mailbox. Second, the hold is issued for a named custodian's email, but the investigation later expands to include that custodian's collaboration-tool messages and file-sharing repositories, which were not covered. The hold document should describe data types, not just named people.
Physical document collection
Many financial fraud investigations still involve substantial quantities of paper: original contracts, manually signed approval forms, handwritten notes, physical bank statements, and printed ledger reports. Physical documents require the same rigour as digital ones. They must be collected with a log, segregated by source, preserved in their original state, and stored in a secure location with access controls and a check-in/check-out record.
- Document log: Every document collected should be assigned a unique reference number, recorded in a log with its description, source location, and the identity of the person who collected it and when.
- Segregation: Documents from different sources or relating to different periods or entities should be kept physically separate to prevent cross-contamination of the evidentiary record.
- Original vs copy: Where originals are seized, a certified copy is made for working purposes. The original is stored securely and is produced only when required for inspection or court. The distinction between the working copy and the original is documented in the chain-of-custody log.
- Scanning and Bates numbering: Documents are typically scanned to create a working digital copy. Bates numbering (a sequential unique identifier stamped on each page) is applied during scanning to create an unambiguous reference system across the document set.
Imaging financial systems and ERP databases
The accounting system is usually the most important evidence source in a financial fraud investigation. It contains transaction records, journal entries, approval logs, user-activity audit trails, and in modern systems, timestamps that record exactly when each record was created or modified. Collecting this evidence requires a forensic image of the relevant data, not a management-prepared extract.
A management-prepared export (a CSV file emailed to the forensic accountant by the finance controller) is analytically useful but evidentially weak. The opposing party will argue that the person who prepared the extract could have modified or filtered the data. A forensic image of the database, taken by a qualified digital forensics practitioner with the hash values recorded at acquisition, removes that argument.
ERP systems vary in how their data can be extracted. Some require specialised tooling: SAP, for example, stores data in proprietary table structures (such as BKPF for document headers and BSEG for line items, defined in the ABAP Data Dictionary) that require knowledge of those table structures to extract correctly. Oracle Financials, Microsoft Dynamics, QuickBooks, and Xero each have different export formats and audit-trail architectures. The forensic accountant must understand the specific system's data model well enough to know whether an extract is complete and unmodified.
Email, messaging, and cloud-hosted data
Email archives are a primary evidence source in financial investigations, revealing intent, knowledge, and co-ordination that transaction records alone cannot establish. Collecting email evidence requires image-level collection from mail servers or enterprise archiving platforms (Microsoft Purview, Google Vault), not user-by-user export from the email client, because client-side export can be manipulated and does not capture deleted-but-archived messages.
Instant messaging platforms have become increasingly significant in financial investigations. Slack, Microsoft Teams, WhatsApp, Signal, and Bloomberg Terminal messaging all potentially contain business records. Retention and collection rules for these platforms vary considerably: some have native legal-hold tools (Teams Compliance Center, Slack eDiscovery export), others require third-party collection tools or device imaging. Signal's disappearing-message feature and end-to-end encryption mean collection may need to happen from device images rather than server records.
Working with external auditors and regulators
Most organisations under forensic investigation are also subject to their annual statutory audit. The relationship between the forensic team and the external auditor is often complicated. The external auditor has independent obligations to their professional standards body and ultimately to shareholders or the public interest. The forensic team owes duties to its client, which may differ from what the external auditor needs to report. These tensions need to be managed explicitly.
In regulatory investigations, the forensic accountant may also need to co-ordinate with the regulator's own evidence collection. Regulatory bodies (the SEC in the US, the FCA in the UK, SEBI in India) have statutory powers to compel document production, and their collection processes generate their own evidential record. Working in parallel without communication leads to duplicated effort at best and contradictory evidence at worst.
- Establish a joint document register if practical, so that all parties can see what has been collected, by whom, and when.
- Agree on a single master copy of key documents rather than allowing multiple parties to maintain separate copies with different tracking schemes.
- Clarify with counsel which materials produced to the regulator remain privileged from private litigation and which do not.
- Document every point of contact with external auditors and regulators, including what was produced, to whom, and on what date.
Maintaining the chain of custody through to court
A chain-of-custody log for each piece of evidence should record: the unique reference number, description of the item, date and time of collection, identity of the person who collected it, location from which it was collected, and then a sequential record of every person who subsequently received custody of it, the date of each transfer, and the reason for the transfer.
For digital evidence, the hash value is the core integrity mechanism. The hash of the original image should be computed and recorded at the time of acquisition. Every time the image or a derivative is transferred, the hash of the transferred copy is computed and compared to the source. A match proves the data is identical. Any discrepancy must be explained before the evidence can be used.
Physical storage requirements for digital evidence include media that is write-protected or stored in read-only formats, labelled containers with unique identifiers, secure-room access restricted to named investigators, and climate controls that prevent media degradation. These requirements mirror those used in digital forensics laboratories and are increasingly treated as the standard in financial-investigation matters.
Why should a forensic accountant obtain a forensic image of the ERP database rather than accepting a management-prepared CSV export?
Key Takeaways
- Chain of custody is the documented, unbroken record of every custodian from collection to court; a break in that chain gives opposing parties grounds to challenge authenticity and potentially exclude the evidence.
- Forensic imaging with write blockers and hash verification is the standard for ERP and digital evidence collection; management-prepared extracts are analytically useful but evidentially weak without the same integrity verification.
- Physical documents require their own chain-of-custody discipline: collection logs, Bates numbering, secure storage with access records, and clear distinction between originals and working copies.
- Email, instant-messaging, and cloud-hosted data are increasingly central to financial fraud investigations; each platform has different collection tools and legal requirements, and cross-border data transfers may require formal legal mechanisms.
- Co-ordination with external auditors and regulators, and clear documentation of every contact and production, prevents duplicated effort and conflicting evidence that can undermine the investigation at trial.
What does 'chain of custody' mean in a financial investigation?
How do you image a financial accounting system without disrupting the business?
What is a hash value and why does it matter for digital evidence?
How does a forensic accountant handle documents held by a third party, such as a bank or cloud provider?
What happens if the chain of custody is broken?
Test yourself on Forensic Accounting and Financial Forensics with free, timed mocks.
Practice Forensic Accounting and Financial Forensics questionsSpotted an error in this page? Report a correction or read our editorial standards.