Property and Evidence|The Gilded Margin
Digital evidence is changing.
But for Property & Evidence professionals, the bigger issue may be what happens when digital evidence is also a record.
For years, when someone said “evidence,” it was relatively easy to picture what they meant: a firearm, a piece of clothing, a computer, a cellphone, a biological sample, or another physical item that could be collected, packaged, booked, stored, transferred, examined, retained, and eventually disposed of.
Digital evidence has never fit perfectly into that model. Now, it is getting harder to pretend that it does.
The National Institute of Standards and Technology (NIST) currently lists six Scientific Working Group on Digital Evidence (SWGDE) documents that are open for public comment through August 30, 2026. The subjects are Timing Advance Records, body-worn camera systems, audio files, mobile-device forensic analysis, data integrity within digital forensics, and quality-management systems for digital and multimedia evidence units (National Institute of Standards and Technology [NIST], 2026). (NIST)
On the surface, that looks like a forensic-science development story.
For Property & Evidence, I think it is something bigger.
It is a records-management problem coming straight toward the evidence room.
The reason is that digital evidence and records increasingly overlap in ways that make preservation, retention, custody, and disposition much harder to define.
A body-worn-camera recording can be a routine government record one minute and evidence in a criminal investigation the next. A cellular-provider record can become important evidence even though the agency never physically possesses it. A forensic extraction can become part of the evidentiary history of an investigation while also documenting the work performed by a forensic examiner.
The file itself may not change.
Its status does.
And that raises a question agencies need to answer before a case forces them to:
When evidence is also a record, which retention clock wins—and who is responsible for knowing that the clock has changed?
That is the issue I think deserves the most attention.
What NIST Is Actually Showing Us
The six SWGDE documents currently open for comment are technical, but the underlying issues are surprisingly easy to understand.
They are essentially asking six very practical questions:
- What information are we dealing with?
- Where did it come from?
- How do we know it is reliable?
- How should it be collected and handled?
- How do we preserve it?
- And can someone still understand and use it years from now?
The six documents cover very different types of digital evidence, which is part of what makes the current standards activity so interesting.
They include:
- Best Practices for Interpreting Timing Advance Records
- Considerations for Body Worn Camera Systems
- Technical Overview of Audio Files
- Best Practices for Mobile Device Forensic Analysis
- Best Practices Regarding Data Integrity Within Digital Forensics
- Quality Management System for Digital and Multimedia Evidence Units
NIST identifies all six as SWGDE documents released for public comment, with a deadline of August 30, 2026. (NIST)
These are not six versions of the same problem.
They show how many different places digital evidence now comes from.
And that is where the Property & Evidence problem begins.
Timing Advance Records: What Was the Phone Doing Near a Cell Tower?
Timing Advance Records come from cellular networks.
In simple terms, a cellular network needs to know how long it takes a signal from a device to reach the cell site so that communications can be properly synchronized. Timing Advance information can then be used to infer an approximate distance between the device and the serving cell site.
That does not mean investigators can look at the information and say, “The phone was standing at this exact address.”
It is not GPS.
It is an estimate that can help establish an approximate area in which the device may have been operating.
SWGDE explains that Timing Advance is a measure of delay that can be used to infer approximate distance for geolocation purposes. It also cautions that the information is affected by provider-specific systems and proprietary algorithms, meaning practitioners have to understand the limitations of the data rather than treating it as an exact location record (Scientific Working Group on Digital Evidence [SWGDE], 2025). (SWGDE – SWGDE)
Why should Property & Evidence care?
Because the phone and the information about the phone may be in two completely different places.
The phone might be sitting in your evidence room.
The cellular records are held by the wireless provider.
And the provider may not retain those records indefinitely.
That creates a preservation problem that traditional evidence procedures do not necessarily solve.
An agency can properly collect and preserve the phone while failing to preserve network information that could later become important to the investigation.
In other words:
The evidence may exist somewhere else while the evidence room is doing everything right with the physical device.
That is a significant shift.
With physical evidence, preservation generally starts when somebody takes possession of the item.
With digital evidence, preservation may need to start when somebody realizes that information exists somewhere else.
Body-Worn Camera Systems: The Camera Is Not the Evidence
Body-worn cameras may be the easiest example for the public to understand.
An officer wears a camera.
The officer records an incident.
The recording is uploaded.
The recording becomes evidence.
But there is considerably more happening inside that process.
A body-worn-camera system can generate video, audio, timestamps, metadata, user information, upload information, system records, and other information associated with the recording.
The camera itself is equipment.
The recording is evidence.
Those two things can have completely different lifecycles.
An officer may use the same camera every day. A recording from one particular incident may need to remain available for years.
The current SWGDE draft specifically addressing body-worn-camera systems is important because it recognizes that the system creating the evidence is itself part of the digital-evidence conversation (NIST, 2026). (NIST)
But there is another problem that matters even more to Property & Evidence.
A recording may begin life as an ordinary agency record.
Then its status changes.
An officer’s camera records an arrest. Nothing appears unusual at the time. The recording sits in the system under the normal retention schedule.
Two months later, the person arrested files a complaint.
Or the arrest becomes part of a criminal prosecution.
Or a use-of-force investigation begins.
Or litigation is threatened.
The recording has not changed.
Its status has changed.
That is where the retention problem starts.
Who was responsible for recognizing that change?
The officer?
The supervisor?
The investigator?
The records custodian?
The body-camera administrator?
The evidence unit?
The legal department?
That is a much more important question than simply asking whether the agency has a body-camera retention policy.
Audio Files: A Recording Is More Than What You Hear
Audio evidence can look simple.
You have a recording.
You press play.
You hear the conversation.
But the file itself can contain technical information that matters to a forensic examination.
How was the recording created?
What format is it?
Was it compressed?
Was it converted?
Was it edited?
Was another copy created?
What happened to the original?
The current SWGDE draft concerning audio files reflects the need for forensic guidance around digital audio rather than treating every recording as simply a file that can be played and copied (NIST, 2026). (NIST)
This matters because investigators routinely create derivatives.
Someone may convert a file into a format that is easier to play.
Someone may clip a relevant portion.
Someone may enhance the audio.
Someone may create a transcript.
Someone may make a copy for a prosecutor or court.
Those things can all be useful.
But the derivative is not automatically the original.
That means one recording can become several different digital objects, each potentially having a different purpose and potentially requiring different treatment.
For Property & Evidence, that raises a basic question:
Which one are we retaining?
And then:
Who decided that was sufficient?
Mobile Device Forensic Analysis: Your Phone Contains More Than Your Text Messages
Mobile-device evidence is probably the category most people recognize.
It is also one of the categories most easily misunderstood.
People hear “cellphone evidence” and think about text messages, photographs, and call history.
A modern cellphone can contain far more than that.
It may contain application data, location information, browser history, search history, databases, device information, deleted or partially deleted artifacts, authentication information, photographs, videos, and information synchronized from other systems.
Some information associated with the phone may not even be stored on the phone.
It may be in a cloud account.
It may exist with an application provider.
It may be stored somewhere else entirely.
SWGDE’s mobile-device guidance has recognized for years that forensic tools do not necessarily recover or interpret every artifact available on every device. Operating systems, applications, security features, databases, and forensic tools all affect what can be recovered and understood. The current NIST list shows that SWGDE is now proposing a new version of its mobile-device forensic-analysis best practices. (NIST)
For Property & Evidence, this creates an important retention question.
“We extracted the phone” does not necessarily mean “we preserved everything on the phone.”
Technology changes.
Operating systems change.
Applications change.
Forensic software changes.
What can be recovered from a device today may not be the same as what could be recovered from that device several years ago.
That does not mean agencies should simply keep every extraction forever. It does mean agencies need to make deliberate decisions about what must be retained, why it must be retained, and how the physical device relates to the forensic derivative.
If the phone is retained for ten years but the extraction is destroyed after five, what happens if the case is reopened in year eight?
Maybe the phone can be examined again.
Maybe it cannot produce the same results.
Maybe the original extraction is needed to understand what the examiner saw at the time.
Maybe the forensic software has changed.
Maybe the examiner is no longer available.
Those are evidence-management questions, not just forensic questions.
Data Integrity: Can We Prove the Data Is What We Say It Is?
The phrase “data integrity” sounds technical, but the basic question is straightforward:
Can we trust what we are looking at?
Digital information is easy to copy.
It is also easy to transfer, convert, process, alter, or accidentally overwrite.
If an examiner receives a file, how can the examiner demonstrate that the file analyzed is the file originally acquired?
If someone makes a copy, how can they establish what happened?
If a video is exported from a system, how does the agency explain its relationship to the original?
If a forensic extraction is processed through software, how can the agency demonstrate that the process produced reliable results?
That is the basic problem data-integrity standards are trying to address.
SWGDE guidance emphasizes that integrity begins during acquisition and that digital evidence should be acquired and handled in a way that provides confidence that the data represents the information that was originally obtained. For third-party productions, SWGDE recommends documenting the source and using cryptographic hashes to establish a baseline for the acquired data. (SWGDE – SWGDE)
Why does Property & Evidence care?
Because chain of custody for digital evidence is more than asking:
“Who had it?”
It also asks:
“What happened to it while they had it?”
A physical item can sit in a locker and remain physically recognizable.
Digital information can be copied, transformed, exported, uploaded, downloaded, processed, and stored in multiple locations without anyone physically touching the original device.
That makes documentation extremely important.
Quality Management: Are We Doing This the Same Way Every Time?
The quality-management document may be the least exciting title on the list.
It may also be one of the most important.
In plain English, a quality-management system is a structured way of making sure important work is performed consistently and can withstand scrutiny.
For digital and multimedia evidence, that can involve procedures, training, documentation, equipment, software, validation, quality control, personnel competency, audits, and corrective action.
The question is essentially:
Do we have a reliable system for handling digital evidence, or are we relying on individual employees knowing what to do?
That distinction matters.
If an examiner leaves the agency, can another qualified examiner understand what was done?
If a case is reopened years later, can someone locate the original evidence?
If a forensic tool changes, can the agency identify which version was used?
If an error is discovered, is there a process for documenting and addressing it?
Quality management eventually becomes evidence management.
A digital-forensics unit can perform excellent examinations, but if the resulting evidence cannot be located, explained, authenticated, or preserved later, the agency still has a problem.
The Common Thread Is Preservation
At first, these six documents appear to have very little in common.
A cellular-network record does not look anything like a body-camera video.
A cellphone extraction does not look anything like an audio file.
A quality-management system is not even an evidence item.
But they are connected by the same problem:
Digital information has to be identified, collected, understood, preserved, trusted, and available later.
That last part matters.
Later.
Not just tomorrow.
Not just while the investigator is assigned to the case.
Not just while the prosecutor has the file.
Digital evidence may need to be understood years after it was created.
SWGDE’s guidance on archiving digital and multimedia evidence specifically recognizes that forensic evidence and examination results may be needed for review or testimony years after a case is completed. It recommends that organizations determine what must be preserved, for how long, and who is responsible for maintaining the archive. (SWGDE – SWGDE)
That is where the Property & Evidence function becomes increasingly important.
The Real Problem: When Evidence Is Also a Record
This is the part I think deserves more attention than it gets.
Not every record is evidence.
Not every piece of evidence is necessarily a record in the same sense.
But some information can be both.
And when that happens, the agency can suddenly have more than one reason to preserve the same information.
Take a body-camera recording.
It may begin as an agency record.
Then it becomes evidence in a criminal case.
Now imagine that the agency’s records schedule says the recording would ordinarily be deleted after a certain period, but the criminal case requires longer preservation.
Or imagine a lawsuit creates another preservation obligation.
Or a prosecutor needs the material for discovery.
Which requirement controls?
The answer depends on the circumstances, applicable law, agency policy, and the specific type of record or evidence involved. There is not one universal retention rule that automatically resolves every situation.
But that is exactly the problem.
Someone has to recognize that the status changed.
And someone has to make sure the system holding the information knows that the status changed.
One File Can Have More Than One Retention Clock
This may be the most important concept for Property & Evidence professionals to start discussing.
A digital file can have multiple potential retention timelines.
There may be a routine system-retention period.
There may be a records-retention period.
There may be an evidence-retention requirement.
There may be a litigation hold.
There may be a discovery obligation.
There may be a forensic-archive requirement.
There may also be an outside provider’s retention policy.
Those clocks may start at different times.
The body-camera system may start its clock when the recording is created.
The evidence clock may begin when the recording is identified as evidence.
A legal hold may begin later.
A case may be reopened years after the original incident.
The information may therefore have a changing preservation status even though the underlying file has not changed.
That is the problem.
The file is static.
The obligations surrounding it are not.
The Keeper Problem
The other major issue is figuring out who is actually responsible.
Property & Evidence may have custody of the physical phone.
Digital Forensics may have the extraction.
The investigator may have exported files.
Records may have the body-camera recording.
IT may administer the server.
The prosecutor may have a discovery copy.
The cellular provider may have the network information.
The cloud provider may have the original account data.
Who is the keeper?
There may not be one keeper.
There may be several custodians responsible for different manifestations of the same underlying information.
That distinction is important.
Custody is not always the same thing as control.
Control is not always the same thing as responsibility for preservation.
And ownership is not necessarily the same thing as any of them.
SWGDE’s archiving guidance makes a similar point operationally: organizations need to clearly designate responsibility for managing digital-evidence archives, including who is responsible for adding, retrieving, maintaining, and eventually removing information. (SWGDE – SWGDE)
That is exactly the type of responsibility that becomes increasingly important as digital evidence spreads across systems.
The Evidence May Have a Preservation Clock Before It Reaches the Evidence Room
This is perhaps the biggest departure from traditional evidence management.
An investigator may discover that relevant evidence exists with a cellular carrier.
A victim may identify a doorbell-camera recording.
An officer may realize that a body-camera recording is relevant.
A detective may learn that information is stored in a cloud account.
A prosecutor may identify material that needs to be preserved.
The physical evidence may still be sitting somewhere else.
The evidence room has not received anything.
But the preservation issue has already begun.
SWGDE’s cloud-service-provider guidance is a good example. It specifically discusses preservation when there is a risk of destruction or loss and identifies preservation requests or appropriate litigation holds as mechanisms that may be used to preserve provider-held data. (SWGDE – SWGDE)
That means the preservation clock can begin before booking.
And that changes how agencies need to think about responsibility.
One Investigation Can Have Several Different Clocks
Consider a stalking investigation.
The case involves a cellphone, social-media messages, body-camera footage, a doorbell camera, cellular records, and a forensic extraction.
The phone has one retention process.
The body-camera system has another.
The doorbell camera may overwrite footage automatically.
The social-media platform may have its own policies.
The cellular provider controls its records.
The forensic unit has its own examination and archive procedures.
The investigative report is an agency record.
The prosecutor may have discovery responsibilities.
All of those pieces can contribute to the same case.
But there is no guarantee that they share the same retention period.
This is why saying “the case evidence is retained for X years” may not be enough.
Which evidence?
The phone?
The extraction?
The original video?
The exported video?
The provider’s records?
The forensic notes?
The metadata?
The audit logs?
The answer matters.
The Derivative Problem
Digital evidence also creates something that physical evidence rarely does at the same scale: derivatives.
One original file can generate multiple copies.
A body-camera video can become an exported copy, a redacted copy, a court copy, a discovery copy, and a training copy.
A cellphone can produce a forensic extraction, screenshots, exported photographs, reports, timelines, and other analytical products.
A cloud account can produce downloaded files, reports, logs, and screen captures.
Which one is the evidence?
Sometimes there is more than one answer.
The original may be the primary source.
A forensic extraction may be a preserved representation of the source.
A screenshot may document what an investigator observed.
A report may explain what the examiner found.
A redacted copy may be appropriate for disclosure.
Each serves a purpose.
But the existence of a derivative does not automatically make the original unnecessary.
SWGDE guidance on digital evidence acquisition recommends preserving the original production, documenting its source, and creating appropriate working and archive copies. (SWGDE – SWGDE)
That is an important distinction for evidence-management policy.
What Happens When the Case Changes?
This is where I think agencies need to spend more time.
A digital file can start as a routine record.
Then a complaint is filed.
Then it becomes investigative evidence.
Then the case is prosecuted.
Then litigation occurs.
Then the case is closed.
Then, years later, it is reopened.
The evidence has moved through several statuses.
Who was responsible for updating those statuses?
Who made sure the retention period changed?
Who made sure an automated deletion system did not remove the file?
Who knows whether the forensic extraction still exists?
Who knows whether the original provider data still exists?
Who knows whether a derivative copy is the only remaining copy?
Those are not theoretical questions.
They are the practical questions that arise when evidence exists across multiple systems.
Property & Evidence Needs a Seat at the Table
Property & Evidence does not need to become Digital Forensics.
It does not need to manage every cloud account, body-camera platform, or cellular record.
But it needs to understand the digital evidence lifecycle well enough to know where its responsibilities begin and end.
The traditional questions still matter:
Where is it?
Who received it?
Who has custody?
How was it packaged?
Where is it stored?
When can it be released?
When can it be destroyed?
Digital evidence adds another layer:
Where is the original information?
Where are the derivatives?
Who controls the system?
Who controls the account?
What happens when the status changes?
Which retention schedule applies?
Who communicates that change?
Who has authority to authorize disposition?
What happens if another department or outside provider controls the information?
Those questions should be answered in policy before an agency finds itself trying to answer them in court.
What Agencies Should Be Looking At Now
This standards activity would be a good reason for agencies to review their policies—not just their digital-forensics policies, but their overall evidence and records processes.
They should be asking whether their policies clearly distinguish between a physical device and the digital evidence generated by that device.
They should be asking who is responsible for identifying when a routine recording becomes evidence.
They should be asking whether investigators know when provider-held information may need to be preserved.
They should be asking how forensic extractions are retained and who controls them after the examination is complete.
They should be asking whether digital derivatives are traceable back to the original.
They should be asking how automated deletion systems interact with evidence holds.
And, perhaps most importantly, they should be asking whether Property & Evidence, Records, IT, Digital Forensics, Investigations, Legal, and prosecutors all understand who is responsible for what.
Because the worst-case scenario is not necessarily that everyone ignored the evidence.
It may be that everyone assumed someone else was responsible for preserving it.
Why This Matters Beyond the Evidence Room
This is also where digital evidence becomes a public-safety issue.
People generally think of digital evidence as screenshots and text messages.
That is only one small part of it.
A stalking investigation could involve phone records, location information, social-media activity, body-camera recordings, doorbell-camera footage, vehicle information, cloud accounts, application data, and other digital records.
A child-safety investigation could involve phones, tablets, gaming systems, social platforms, cloud accounts, photographs, messages, and location information.
A theft investigation could involve vehicle systems, surveillance cameras, access-control systems, cellular information, and digital payment records.
A domestic-violence investigation could involve messages, recordings, smart-home devices, social-media activity, and location-related information.
The important public lesson is not that everyone needs to become a forensic examiner.
It is that digital evidence can exist in places people do not realize are creating or storing it.
And when something serious happens, preservation may matter before anyone has physically collected anything.
The Bigger Professional Shift
The six SWGDE documents currently open for comment are significant individually.
But together, they show something larger.
Digital evidence is no longer one category of evidence.
It is an ecosystem.
Timing Advance Records come from cellular networks.
Body-camera evidence comes from recording systems.
Audio evidence comes from numerous devices and platforms.
Mobile evidence comes from increasingly complicated devices and applications.
Data-integrity standards address whether information can be trusted.
Quality-management standards address whether the people and systems handling that information can demonstrate consistent, defensible practices.
And all of those things eventually come back to one fundamental evidence question:
Can we find it, understand it, trust it, and produce it when we need it?
That is where Property & Evidence becomes part of the conversation.
Conclusion
The most important thing happening in digital evidence right now may not be the technology.
It may be the growing overlap between evidence management and records management.
A body-camera recording can begin as a routine government record and later become criminal evidence.
A cellular-provider record can become evidence without ever entering police custody.
A cloud file can be controlled by a private company while being relevant to a criminal investigation.
A forensic extraction can become part of the evidentiary history of a case.
An audio recording can have an original file, an exported copy, a redacted copy, and a courtroom version.
A cellphone can remain physical evidence while the digital information extracted from it exists somewhere else entirely.
And all of those things can have different custodians, different systems, and potentially different retention requirements.
That brings the conversation back to the question I think Property & Evidence professionals should be asking now:
When evidence is also a record, which retention clock wins—and who is responsible for knowing that the clock has changed?
There is no universal answer that can be applied to every piece of digital information. The applicable law, records schedule, case status, evidence policy, legal holds, discovery obligations, and type of information all matter.
But there does need to be an answer inside the agency about who recognizes the change and who is responsible for acting on it.
Because the biggest risk may not be intentionally destroying evidence.
It may be allowing a system to automatically delete something because, as far as that system knew, it was still just a routine record.
The evidence room of the future may not look much different physically.
There will still be lockers.
There will still be evidence numbers.
There will still be phones, computers, cameras, firearms, clothing, biological evidence, and other physical property.
But increasingly, the evidence associated with those items will exist somewhere else.
It may be in a server.
A cloud account.
A cellular provider’s system.
A body-camera platform.
A forensic archive.
A vehicle.
A database.
An application.
Or a combination of all of them.
The challenge for Property & Evidence is not to own every piece.
It is to understand the lifecycle well enough to know what exists, where it exists, who is responsible for it, when its status and changes, and which preservation clock is running.
That is the professional trend worth watching.
Because the question is no longer simply:
“Where is the evidence?”
It is:
“Who is keeping it, why are they keeping it, how long do they have to keep it, and who is responsible for knowing when that answer changes?”
Digital evidence is changing. Evidence rooms have to change with it.
References
National Institute of Standards and Technology. (2026, August 10). Standards open for comment. U.S. Department of Commerce. (NIST)
Scientific Working Group on Digital Evidence. (2020). Best practices for archiving digital and multimedia evidence. SWGDE. (SWGDE – SWGDE)
Scientific Working Group on Digital Evidence. (2024). Best practices for digital evidence acquisition, preservation, and analysis from cloud service providers (SWGDE 23-F-004-1.1). SWGDE. (SWGDE – SWGDE)
Scientific Working Group on Digital Evidence. (2025). Technical notes on the use of Timing Advance Records (SWGDE 25-F-002-1.0). SWGDE. (SWGDE – SWGDE)
Scientific Working Group on Digital Evidence. (2025). Best practices for digital evidence collection. SWGDE. (SWGDE – SWGDE)

Leave a comment