What should a supervisor ask before relying on mobile-extraction evidence?¶
title: What should a supervisor ask before relying on mobile-extraction evidence? subtitle: Test the proposition, source, attribution chain, limitations and proportionality rather than asking only whether the report found a result. slug: what-should-a-supervisor-ask-before-relying-on-mobile-extraction-evidence series: mobile-extraction-and-reader-reports section: evidential-limits-corroboration-and-supervision card_type: manager_tool content_type: core-operational risk_level: high-risk pathway_order: 60 section_order: 10 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 60 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 474 estimated_read_time_seconds: 196 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - supervision - manager questions - decision making - quality sources: - title: 'Forensic Science Regulator: Statutory Code of Practice, Version 2' url: https://www.gov.uk/government/publications/forensic-science-activities-statutory-code-of-practice-version-2 - title: 'Forensic Science Regulator: Interpretation and Communication (FSR-GUI-0004)' url: https://www.gov.uk/government/publications/forensic-science-activities-interpretation-and-communication-fsr-gui-0004 - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/ - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final
What should a supervisor ask before relying on mobile-extraction evidence?¶
Test the proposition, source, attribution chain, limitations and proportionality rather than asking only whether the report found a result.
Script¶
A supervisor does not need to become a mobile-forensics examiner.
They do need to test whether the proposed action matches the strength of the evidence.
Start with the proposition.
What are we relying on the artefact to establish?
That data existed?
That an account was used?
That this handset created the event?
That a person controlled it?
That the person knew about or authored the content?
Those are different conclusions.
Ask what has been preserved.
Do we have the original extraction or reader package?
Can the result be traced to a source file, database or record?
Was it exported with its context and identifiers?
Are we relying on a screenshot or copied text alone?
Then ask about scope.
Which device and acquisition produced the report?
Was it complete, partial or filtered?
Were relevant applications acquired and parsed?
Were cloud, backup, SIM or memory-card sources included?
Could missing data affect the conclusion?
Ask what the artefact shows directly.
Which application and account?
What status, direction, timestamp and source?
Was it active, recovered or classified as deleted?
Is the friendly label supported by the underlying field?
Now test attribution.
What links the account to the handset?
What links the handset to the person at the relevant time?
Could another user, linked device, remote session, compromise or automated process produce the same result?
Has the realistic alternative been tested rather than merely mentioned?
Ask about time.
Which timestamp is being used?
What event does it represent?
Was it stored in UTC or local time?
Was the device clock checked?
Were timezone and daylight-saving conversions documented?
Ask about corroboration.
Which independent system supports the weakest link?
Are several supposed confirmations actually duplicate artefacts from the same database?
Is there contradictory evidence?
Has it been explained?
Ask about validation.
Is the result routine and within the tool’s known purpose?
Or is a single disputed parser interpretation driving a major decision?
Has the digital-forensics unit validated the source where needed?
Ask what remains uncertain.
A good briefing should state the limitation clearly.
The common supervisory mistake is:
“The phone says it, so can we act?”
A better question is:
“What exactly does the source record say, and what inference takes us from that record to this person?”
Another mistake is to demand certainty before any action.
Mobile evidence can support proportionate enquiries even where final attribution remains open.
The action should match the evidential stage.
Further preservation, interview planning or provider enquiries may require less certainty than arrest, charge, dismissal or a decisive adverse finding.
A sound manager asks:
What does it show?
What does it not show?
What alternative survives?
What needs specialist checking?
And is the proposed action proportionate to the remaining uncertainty?
The supervisor’s role is not to repeat the technical findings.
It is to ensure the decision rests on a transparent and tested chain of reasoning.
Key takeaway
The manager should know what the artefact shows directly, which inference is being added and what realistic alternative has been tested.
Manager questions¶
- [ ] What exact proposition are we relying on: artefact, account, handset, location, knowledge, authorship or person?
- [ ] Do we have the original extraction or reader package and a traceable artefact reference?
- [ ] Was the relevant source acquired, parsed and included within the report scope?
- [ ] What does the source record show directly?
- [ ] Which inference takes us from the record to the person?
- [ ] Could another user, linked device, remote session, compromise or automation explain it?
- [ ] Which timestamp is being used, and what event and timezone does it represent?
- [ ] What independent evidence supports the weakest link?
- [ ] Are supposed corroborating artefacts actually duplicates from the same source?
- [ ] Does the parser or source need specialist validation?
- [ ] What remains uncertain, and is the proposed action proportionate to it?
Related questions¶
- What corroboration should I look for before attributing mobile evidence?
- Can a mobile extraction identify the person using the phone?
- When should I return to the digital-forensics unit or specialist?
Source notes¶
- Forensic Science Regulator: Statutory Code of Practice, Version 2
- Forensic Science Regulator: Interpretation and Communication (FSR-GUI-0004)
- SWGDE Best Practices for Mobile Device Forensic Analysis
- NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics