Meniu

Ghid DPP Grid

What Is Chain of Custody and Why It Matters in 2026

A chain of custody is a chronological, tamper-evident record of who handled an item, when they handled it, why they handled it, and what happened to it along the way. It proves that the item presented later is the same item collected or recorded at the start, with its identity and condition preserved. You may be hearing the phrase in an audit request, an ESPR briefing, a supplier questionnaire, or a conversation…

De către DPP Grid Editorial revizuit de DPP Grid editorial review publicat 2026-08-16 Actualizat 2026-08-16 15 min

Overview

A chain of custody is a chronological, tamper-evident record of who handled an item, when they handled it, why they handled it, and what happened to it along the way. It proves that the item presented later is the same item collected or recorded at the start, with its identity and condition preserved.

You may be hearing the phrase in an audit request, an ESPR briefing, a supplier questionnaire, or a conversation about Digital Product Passports. Perhaps a returned garment needs verification, a flagged batch needs investigation, or a reseller wants evidence behind a recycled-material claim. The courtroom image is familiar, but the underlying discipline now reaches far beyond forensic evidence.

For product teams, the practical question isn't just, “Who had the item last?” It's, “Can we prove the item's identity and relevant history across every handoff, transformation, storage interval, and approval?” That shift matters as product records become more connected to compliance, authenticity, repair, resale, and sustainability claims.

Table of Contents

The Plain-English Meaning of Chain of Custody

Suppose a customer returns a jacket and says it came from your brand. Your team must determine whether it is genuine, which batch it belongs to, whether it was repaired, and whether the evidence supporting its product record still matches the item. A shipment record alone cannot answer those questions. You need a connected history showing who controlled the jacket, where it went, and what changed.

In plain English, chain of custody is a continuous record of possession and control. It identifies the item, the person or organization responsible for it, the time and reason for each handoff, and its condition during movement. In forensic practice, the record follows evidence from collection through return or disposal, helping establish its integrity and admissibility across transfers (forensic definitions and history of chain of custody).

The word “chain” describes how each event connects to the next. A product leaves a factory, reaches a logistics provider, enters a warehouse, moves to a retailer, and later enters repair or resale. Consistent identification, named control, and condition records keep that history coherent. If one event cannot be connected to the next, confidence in the whole history becomes harder to defend.

!A diagram explaining chain of custody using icons representing who, when, and what actions occurred.

A record is not the same as a form

Rather than a one-time form, chain of custody is an ongoing process control that activates whenever responsibility, location, condition, or access changes. A spreadsheet can store the entries, but operating rules determine whether those entries represent trustworthy custody.

A defensible process answers four questions:

  • What is the item? A persistent identifier separates the item, batch, sample, file, or record from similar objects.
  • Who controlled it? Each custodian has an identifiable role and responsibility.
  • What happened and when? Transfers, storage, inspection, repair, acquisition, or analysis appear in chronological order.
  • Why should anyone trust the record? Seals, access controls, signatures, hashes, approvals, and supporting documents help show that neither the item nor its record was substituted or altered.

ISO 22095, titled Chain of custody, General terminology and models, formalizes terminology and models for this discipline (ISO 22095 context and chain-of-custody overview). For product teams, that provides a shared foundation as chain of custody expands from courtroom evidence to product identity, ESPR-related work, and Digital Product Passports. The selected model still needs to fit the claim and the physical supply chain.

Core Elements That Make a Custody Record Defensible

A defensible record begins with identity. If a sealed evidence bag has no unique identifier, a signature on the transfer log can't establish which bag moved between the crime scene and the laboratory. The same problem appears in commerce when a batch number is reused, a serial number changes during repair, or a document is attached to the wrong product.

For every custody event, capture the identifier, date and time, custodian, purpose, condition, and location or method of control. U.S. forensic and legal practice focuses on the date and time of collection or transfer, the person who handled the item, and the purpose of the transfer. NIST describes chain of custody as a chronological record covering transfer, handling, and storage through return or disposal (NIST definition of chain of custody).

!An infographic showing the four core elements required for a defensible chain of custody record.

The fields that carry the burden

Think of a sealed evidence bag moving from a collection site to a laboratory and then to court. The identifier links the bag to the original collection. The timestamp establishes sequence. The named custodian shows who accepted responsibility. The purpose explains why the transfer occurred, such as laboratory analysis or courtroom presentation.

Condition matters because an item can be present but no longer trustworthy. The record should describe the seal, packaging, visible damage, relevant environmental conditions, or any authorized opening and resealing. Storage and shipping details close the intervals between handoffs. A record that shows a signature at departure and another at arrival, but says nothing about the intervening custody, leaves an avoidable question.

For a product record, the equivalent fields might look like this:

Custody element Product-record application
Unique identifier Item, batch, model, shipment, document, or material identity
Date and time Collection, transfer, inspection, repair, publication, or resale event
Custodian Supplier, carrier, warehouse, retailer, repairer, owner, or reviewer
Purpose Shipment, testing, repair, verification, take-back, or ownership transfer
Condition Seal status, packaging state, repair state, or evidence status
Storage or movement Controlled facility, logistics route, system location, or access record

The record doesn't need to use courtroom language to be useful in a product audit. It does need to make the item's history traceable, chronological, and reviewable. The National Institute of Justice emphasizes that the chain verifies where evidence traveled and who handled it before trial, which is why each custodian must document and preserve the possession history (National Institute of Justice guidance on chain of custody).

Why Gaps Break the Chain and How Tampering Gets Detected

An unbroken chain doesn't mean nothing ever changed. It means every relevant change, transfer, opening, storage period, and responsible party is accounted for. An unexplained gap creates uncertainty because another person can't determine whether the item remained authentic, uncontaminated, correctly identified, and protected during that interval.

That is why an auditor, opposing counsel, or regulator often examines the weakest transition rather than the most carefully documented one. A strong collection record can't repair an unexplained storage period later. A clean delivery receipt can't prove that a package wasn't opened between the warehouse and the carrier.

!A four-step infographic illustrating how gaps in a supply chain lead to broken trust and unverifiable products.

Four failure modes to test

  • Unsigned handoff: Nobody formally accepts responsibility. The gap invites a challenge that the item could have been substituted or mishandled before the next recorded event.
  • Broken seal or altered packaging: The record doesn't explain who opened the item, why it was opened, or how it was secured afterward. That creates room for claims of contamination or tampering.
  • Unrecorded storage interval: The item disappears from the chronology while sitting in a vehicle, facility, cabinet, or system. The missing interval prevents reviewers from testing access and conditions.
  • Contested handler identity: A generic team name or shared account replaces a named person or accountable role. Reviewers can't establish who had control.

These aren't merely administrative defects. They affect the central proposition the chain is meant to support: the item is what the organization says it is, and its relevant condition has been preserved. In a physical setting, seals, locked storage, witnessed handoffs, and signed manifests support that proposition. In a digital setting, access controls, acquisition records, and hash comparisons add a mathematical check.

Practical rule: Treat every unexplained interval as a question someone else will eventually ask. Record the interval before you need to defend it.

A gap doesn't automatically prove misconduct, but it weakens the explanation available to the organization. The prudent response is to design custody controls that make missing events difficult to create and easy to detect.

Physical Evidence and Digital Evidence Side by Side

The logic is the same for a sealed evidence bag and a forensic image of a laptop drive. In both cases, the team must identify the object, document collection, record each transfer, control storage, and explain what was done before presentation.

The physical item has a visible presence, but visibility isn't enough. Investigators still need packaging, seals, custody signatures, storage controls, and condition notes. Digital evidence creates a different problem. A file or disk image can be copied, modified, mounted, or analyzed without visible signs, so the workflow must preserve the original state and demonstrate that later copies correspond to the acquired source.

For digital evidence, the custody record is paired with forensic acquisition, write-blocking, and cryptographic hashing. The standard process is commonly organized around identification, collection, acquisition, and preservation, with documentation of handlers, transfer times, and transfer reasons (digital evidence handling and chain-of-custody principles). A hash comparison checks whether the digital object matches the recorded state at acquisition or verification.

Custody element Physical evidence Digital evidence
Identity Evidence number, description, packaging, and seal Device identifier, image identifier, file description, and acquisition metadata
Collection Officer or examiner records where and how the item was collected Examiner acquires data using a controlled forensic process
Transfer Signed handoff, sealed package, locked storage, or traceable shipment Access log, controlled copy, transfer record, and preserved acquisition details
Integrity Seal condition, packaging, photographs, and condition notes Write-blocking, cryptographic hash, original preservation, and hash verification
Analysis Examiner opens or handles the item under documented authority Examiner works from a forensic image or controlled copy rather than casually altering the source
Presentation Item and custody documentation are produced for review Image, relevant files, hashes, tools, settings, and audit history support reproducibility

The difference isn't that physical evidence is "low tech" and digital evidence is automatically trustworthy. Both require disciplined handling. Digital methods add a way to test whether the recorded object remains mathematically consistent, while physical methods depend more heavily on seals, storage, observation, and documented condition.

Chain of Custody in Product Supply Chains and Sustainability Claims

A product supply chain often has more than one legitimate custody model. The right question isn't “Which model is universally best?” It's “Which model preserves the meaning of the claim we want to make?”

A brand claiming that a specific garment contains material from a specific source may need an identity-preserved approach. A facility handling certified material separately from conventional material may use segregation. A complex manufacturing network may use mass balance, where inputs and outputs are attributed according to defined accounting rules rather than kept physically separate throughout. A book-and-claim model may connect a verified attribute to a product through a certificate or accounting mechanism without claiming that the exact physical molecules traveled through every stage together.

ISEAL's 2026 guidance treats chain of custody as a shared baseline with multiple models, while ISO 22095-2:2026 adds requirements for mass-balance applications (ISEAL guidance on chain-of-custody models and definitions). The important change is conceptual. Chain of custody is no longer limited to proving who held a physical object last. It also governs model selection, attribution, transformation, and claim boundaries.

Match the model to the promise

Consider three claims:

  • Recycled-fiber claim: The team must define how recycled input is identified, transformed, allocated, and supported by records.
  • Conflict-mineral claim: The relevant evidence may involve supplier declarations, facility information, documents, and review decisions across multiple tiers.
  • Organic-cotton claim: The record must preserve the relationship between the claimed attribute and the product or material accounting model used.

A Digital Product Passport makes these relationships visible to different users, but it doesn't make an unsupported claim reliable. The passport should distinguish verified evidence from supplier input, unresolved conflict, preparatory information, and approved public content. Teams evaluating Digital Product Passport implementation should therefore treat the custody model as a governance decision, not just a database field.

This also affects commerce architecture. A brand expanding product identity across storefronts, marketplaces, repair services, and resale may find the broader principles of composable commerce for Shopify brands useful when deciding where product, evidence, and lifecycle events should connect. The architecture should preserve the relationship between the product identity and the claim, even when different systems handle catalog, logistics, ownership, or after-sale activity.

Best Practices for Maintaining an Auditable Chain

Start with the smallest complete workflow, then expand it. A team doesn't need to digitize every operational event before it can improve custody. It needs to identify the points where identity, responsibility, condition, and approval can change.

Identity and chronology

Give each relevant product, batch, document, sample, or digital artifact a persistent identifier. Avoid relying on a description such as “blue jacket” or “supplier certificate.” The identifier should survive a transfer and remain linked when the item enters repair, take-back, or resale.

Record events in chronological, append-only logs. If someone corrects an entry, preserve the original value, the correction reason, the person making the change, and the time of the change. A clean history doesn't mean a history with no corrections. It means reviewers can see what changed and why.

Integrity and authority

Use sealed packaging, locked storage, controlled access, and signed manifests for physical material. For digital material, preserve the acquisition state, use write-blocking where appropriate, calculate hashes, and compare them during verification. These controls address different failure modes, but they serve the same purpose, they make unauthorized alteration harder to hide.

Define who can approve a claim before publication. A supplier may submit a document, an analyst may review it, and a compliance owner may approve the resulting public statement. Those aren't interchangeable actions.

A practical review checklist includes:

  • Identity: Can the team connect every event to one persistent item, batch, or evidence identifier?
  • Chronology: Does each transfer show date, time, handler, purpose, and location or method of control?
  • Integrity: Are seals, access restrictions, hashes, or other tamper-evident measures recorded?
  • Approval: Is the public claim linked to the evidence and approved by an accountable reviewer?
  • Recovery: Can the team explain a missing document, corrected entry, or disputed handoff without rewriting history?

For transport-heavy operations, teams can also compare their process against documented vehicle log best practices, especially where driver identity, route events, delivery confirmation, and maintenance records intersect with custody.

The following video provides a visual introduction to evidence management practices:

Your evidence system should make the approved version easy to find, while keeping the underlying history available for audit. A structured evidence management system can help connect source documents, review decisions, and publication states instead of leaving them scattered across email, shared folders, and supplier portals.

How a Product-Identity Platform Operationalizes Chain of Custody

A Digital Product Passport platform can give chain-of-custody controls a product-facing interface. The passport is what a customer, regulator, reseller, or repair partner sees. Behind it, the system needs to manage identity, evidence, changes, access, review, and publication.

The mapping is straightforward:

  • Persistent identifiers establish the product identity at model, batch, or item level.
  • Evidence-backed fields connect each fact to sources, confidence, conflicts, and approval status.
  • Supplier requests create a controlled path for contributions, documents, materials information, and facility data.
  • Published snapshots preserve the version of the passport that was approved for public use.
  • Lifecycle events extend the record through ownership registration, repair, take-back, trade-in, and resale.

This model prevents a common mistake: treating the public passport as the whole record. A public page may show a concise material claim, but the governed system should retain the evidence behind it, the person who reviewed it, and the publication decision that authorized it.

From handoff to governed product history

A supplier upload isn't automatically a verified fact. It becomes part of a defensible chain when the system records who submitted it, what product or batch it concerns, which evidence supports it, what conflicts exist, and whether an authorized reviewer approved it.

The same principle applies after sale. If an item changes owner or enters a repair program, the event should attach to the same persistent item identity rather than create an unrelated record. That continuity helps a resale partner distinguish a documented lifecycle event from an unsupported claim that a product is genuine or unchanged.

DPP Grid provides these capabilities as a product-identity platform, including persistent product links, evidence governance, supplier contributions, approval states, immutable published snapshots, and lifecycle records for ownership, repair, transfer, and resale. Teams comparing approaches can also review the principles behind integrated proof systems, particularly where product facts need to remain linked to evidence and human decisions.

The result is best understood as a chain-of-custody system with a passport-shaped interface. It doesn't eliminate judgment. It makes the identity, evidence, and approval trail available when judgment needs to be reviewed.

Treating Chain of Custody as a Continuous Trust Discipline

Chain of custody becomes valuable when teams stop treating it as a form completed before an audit. A product's trust history can begin with manufacturing evidence, continue through shipment and sale, and remain relevant during repair, ownership transfer, take-back, and resale.

Three changes sharpen the operating model:

  1. From last possession to complete identity: The question is not only who handled the product last. It is whether every relevant handoff connects to the same product or batch identity.
  2. From paperwork to evidence-linked records: A document matters because it supports a field, decision, or claim. The system should show the source, review status, approval state, and publication history.
  3. From one rigid trail to model selection: The custody approach should match the claim. Physical segregation, identity preservation, mass balance, and book-and-claim each communicate different relationships between inputs and outputs.

The practical work can start this week. Audit the identifiers used by your product, compliance, logistics, repair, and resale teams. Choose the custody model for the claim that creates the greatest verification risk. Then inspect the approval workflow and ask whether a reviewer can reconstruct who submitted each fact, what evidence supported it, and when the public version was authorized.

Trust isn't created by adding more fields. It's created when each important field has a clear identity, source, custodian, decision, and history.

A mature process also distinguishes uncertainty from failure. An unresolved supplier conflict should remain visible as unresolved. A preparatory field shouldn't appear as an approved claim. A corrected record should preserve its prior state. Those distinctions give auditors and commercial partners a more accurate view of what the organization knows and how it knows it.

If you're asking “what is chain of custody” because a product passport, sustainability claim, or resale workflow now depends on it, the answer is practical: build a continuous, evidence-linked history that remains understandable after the item leaves your direct control.


DPP Grid helps product and compliance teams govern Digital Product Passports with persistent identities, evidence-backed fields, human approval states, and lifecycle records for repair, ownership transfer, and resale. Visit DPP Grid to connect product identity with the custody and evidence history your next audit or product claim will require.

This article is operational guidance, not legal advice or certification.