Skip to main content
Category: Access and Security

Tamper Evidence

Also known as: Tamper-Evident, Tamper-Evident Technology
Simply put

Tamper evidence refers to a device, feature, or process designed so that any unauthorized access or interference with a protected item leaves a visible or otherwise detectable sign. The goal is not to prevent tampering outright but to make it apparent that tampering has occurred. Common examples include seals, tapes, and markings that cannot be removed and replaced without leaving a trace.

Formal definition

Tamper evidence describes controls that make unauthorized access to, or alteration of, a protected object readily detectable rather than physically preventing it. It is distinct from tamper resistance or 'tamper proof' measures, which aim to obstruct interference; tamper-evident mechanisms instead provide a reliable indicator that interference has taken place, supporting later inspection and assessment. In recordkeeping contexts, tamper-evident measures may contribute to demonstrating the integrity of a record by helping detect unauthorized modification, though evidence in this packet addresses tamper evidence primarily in physical packaging and product-security settings (for example seals, labels, and tapes) rather than digital record integrity. The distinction between detecting tampering and preventing it should be maintained, and the effectiveness of any tamper-evident control depends on the specific mechanism and its implementation.

Why it matters

For records and information professionals, the integrity of a record, the assurance that it has not been altered in an unauthorized way since its creation or capture, is a foundational property that distinguishes an authoritative record from mere information. Tamper-evident controls contribute to this assurance not by preventing interference outright, but by making any unauthorized access or alteration detectable after the fact. This supports later inspection and assessment, which can matter when the trustworthiness of a record or the container holding it is questioned.

It is important to keep the scope of this concept clear. The evidence available here addresses tamper evidence primarily in physical packaging and product-security settings, seals, labels, and tapes that cannot be removed and replaced without leaving a visible trace, such as the packaging of specialty products including medical equipment. This is distinct from the digital mechanisms sometimes used to detect unauthorized modification of electronic records, which are not addressed in this packet. Professionals should not assume that a control described as tamper-evident in one context provides equivalent assurance in another; the effectiveness of any such measure depends on the specific mechanism and how it is implemented.

Equally important is the distinction between tamper evidence and tamper resistance. A tamper-evident measure reveals that interference has occurred, whereas a tamper-resistant or 'tamper proof' measure aims to obstruct interference in the first place. Conflating the two can lead to misplaced confidence: a seal that shows evidence of tampering does not, on its own, stop a determined actor from accessing protected contents. Understanding this boundary helps organizations select controls appropriate to their actual risk and evidentiary needs.

Who it's relevant to

Records managers and information governance officers
Where the integrity of physical records or their containers matters, tamper-evident measures can help detect unauthorized access and support later assessment of whether a record has been interfered with. These professionals should understand that such measures indicate, rather than prevent, tampering, and that the assurance offered here relates primarily to physical packaging rather than digital record integrity.
Compliance and security personnel
Those responsible for protecting sensitive materials and demonstrating chain-of-custody may use tamper-evident seals, tapes, and labels as one control among others. They should distinguish tamper evidence from tamper resistance and select mechanisms appropriate to the risk, recognizing that effectiveness depends on the specific mechanism and its implementation.
Product and manufacturing quality functions
In production and manufacture of specialty products, such as medical equipment, tamper-evident packaging provides a visible indicator that a package has been accessed. This helps signal potential interference before contents are relied upon, though inspection of the indicator remains necessary for the control to serve its purpose.

Inside Tamper Evidence

Detection Mechanism
The technical or procedural means by which unauthorized alteration of a record becomes apparent, such as cryptographic hashes, digital signatures, checksums, audit trails, or physical seals. Tamper evidence aims to reveal that a change has occurred rather than to prevent the change itself.
Integrity Verification
The process of confirming that a record remains in the state in which it was captured or last authorized, supporting the integrity property that helps distinguish an authoritative record from an altered or uncertain one.
Evidential Value
The contribution tamper evidence makes to a record's reliability and trustworthiness as evidence of activity, by allowing later users to assess whether the record can be relied upon.
Audit Trail and Metadata
Contextual and event information recorded about actions taken on a record, which can help demonstrate whether and when alterations occurred and by whom, depending on how systems are configured and what an organization's policy requires.
Distinction from Tamper Resistance
Tamper evidence exposes that alteration has taken place after the fact, whereas tamper resistance seeks to prevent alteration in the first place. The two are complementary but not interchangeable controls.

Common questions

Answers to the questions practitioners most commonly ask about Tamper Evidence.

Does tamper evidence prevent records from being altered?
No. Tamper evidence is not the same as tamper prevention or tamper resistance. Its purpose is to make unauthorized alteration detectable after the fact, not to stop it from occurring. A record protected by tamper-evident controls can still be modified, but the modification should leave detectable signs. Preventing alteration typically requires additional access controls, storage controls, or write-once mechanisms, which serve a distinct function.
If a record shows no signs of tampering, does that guarantee it is authentic and reliable?
Not necessarily. The absence of detectable tampering supports a record's integrity claim, but integrity is only one of the properties associated with an authoritative record, alongside authenticity, reliability, and usability. Tamper evidence speaks primarily to whether the record has remained unaltered since a given point; it does not by itself establish that the record was reliably created, properly captured, or that its origin is what it purports to be. These properties are typically established through a combination of controls rather than tamper evidence alone.
Where in the records lifecycle should tamper-evident controls be applied?
Tamper-evident controls are often most relevant from the point of capture onward, since integrity claims typically attach to a record once it is fixed as evidence of an activity. Depending on organizational policy and risk assessment, such controls may be maintained through retention, transfer, and any period of permanent preservation. The specific points at which controls are applied, and how they are maintained across custody changes, generally depend on the system, the sensitivity of the records, and applicable requirements.
How can tamper evidence be maintained when records are transferred between systems or custodians?
Maintaining tamper evidence across transfer typically depends on carrying forward verifiable integrity information, such that a receiving system or custodian can confirm the record has not changed since it left the sending environment. This often involves documenting the chain of custody and recording integrity checks at each handover. Because disposition may include transfer rather than destruction, organizations frequently need to consider how integrity assurances survive migration, format changes, and changes in control. The practical approach depends on the systems involved and organizational policy.
What should an organization do when tamper evidence indicates a record may have been altered?
When controls suggest a record may have been altered, organizations typically treat this as an integrity exception to be investigated and documented rather than silently disregarded. Depending on organizational policy, this may involve identifying when and how the discrepancy arose, assessing the impact on the record's evidential value, and determining whether an authoritative version can be restored or must be flagged. Handling such events consistently is often important where records may later be relied upon, and the appropriate response depends on the record's purpose, sensitivity, and any applicable obligations.
How does tamper evidence relate to audit trails and metadata?
Audit trails and metadata often work alongside tamper-evident controls to support integrity claims, but they serve related and distinct functions. Metadata may record the state of a record and the controls applied to it, while an audit trail may capture actions taken on the record over time. For these to reinforce tamper evidence, the audit trail and metadata themselves generally need protection, since integrity information that can be altered without detection offers limited assurance. How these elements are combined typically depends on the recordkeeping system and the assurance level required.

Common misconceptions

Tamper evidence prevents records from being altered.
Tamper evidence is intended to make unauthorized alteration detectable, not to prevent it. Prevention is the aim of tamper-resistance or access controls; the two serve different, complementary functions.
The presence of tamper-evidence mechanisms alone proves a record is authentic and reliable.
Tamper evidence primarily supports the integrity property of a record. Authenticity, reliability, and usability depend on additional factors such as how the record was created, captured, and managed over its lifecycle, and on the surrounding metadata and controls.
Once tamper-evidence controls are applied, a record is protected indefinitely.
The effectiveness of tamper-evidence mechanisms can degrade over time, particularly for digital records where cryptographic methods may weaken and systems change. Ongoing management is typically needed to preserve detectability across the record's retention period.

Best practices

Treat tamper evidence as one component of a broader integrity strategy, combining it with access controls, audit trails, and lifecycle management rather than relying on it in isolation.
Document how tamper-evidence mechanisms operate and how alterations would be detected, so the evidential value of records can be assessed and defended when needed.
Capture and preserve supporting metadata and audit information alongside records, since these often provide the context required to demonstrate integrity over time.
Plan for the long-term viability of digital tamper-evidence methods, reviewing them periodically as technologies and threats evolve across the applicable retention period.
Align tamper-evidence controls with applicable legal, regulatory, and organizational requirements, recognizing that expectations may vary by jurisdiction and sector.
Clearly distinguish authoritative records from copies, drafts, and transitory information when applying tamper-evidence controls, focusing effort where integrity most needs to be demonstrable.