Skip to content
Skip to main content
Payments & Banking Operational Explainer

What payment evidence may exist on a mobile device?

A phone or tablet can connect payment accounts, transactions, authentication and communications in ways a statement alone cannot, but application presence does not prove the device authorised every displayed event.

Evidence spans applications and context

Banking, payment, exchange and wallet data may expose identifiers, beneficiaries, requests, QR codes, addresses, hashes, notifications and alerts. Messages, email, photographs and browser data can show instructions, receipts, recovery and payment links. Credentials, one-time codes and authentication tools may explain access.

Preserve state before exploration

Record whether the device was locked, connected or already authenticated. Live, cached or synchronised data can originate elsewhere, and opening applications may change local and provider records.

Use appropriate forensic preservation and compare artefacts with provider, merchant and blockchain data. Report visibility, access and authorisation separately.

The point to remember

Mobile evidence can link an account and event to an access context, but human authorisation still requires corroboration.

Reference: PAY-196Payments & Banking