A custody log is a chronological record of every person who has held a specific asset, with the date, condition, and an acknowledgement captured at each handover.
A custody log is a chronological record of who has held a specific asset, with each change of hands captured as it happens - names, dates, condition, and a signature or scan at every handover. This page uses the term in its equipment and property sense: laptops, tools, instruments, keys, and evidence, not the parenting journals that share the phrase. Read top to bottom, a custody log tells one item’s whole working history: issued to Lena in March, transferred to the night shift in May, back to the tool crib in June, out again the same week. Its strict, evidence-grade relative is the chain of custody; the custody log is the everyday record that proves the chain held.
What you will learn
- What a custody log records
- Custody log template: the fields to include
- Custody log example
- Custody log vs chain of custody, hand receipt and sign-out sheet
- Who is on the log: owner, custodian, holder
- Why a who-had-what-when history matters
- Where custody logs are used
- Custody at handover: onboarding, offboarding and transfers
- Custody at end of life
- Keeping a custody log current
- How custody logs fail
- How long to keep custody records
- Paper, spreadsheet, or system
- Starting a custody log this week
- FAQ
- Tools that make this easier
What a custody log records
Each entry is a handover, and a complete one answers five questions:
- Which item - the asset ID, so the log survives the existence of two identical instruments.
- From whom, to whom - both sides of the handover, because “returned” is meaningless without knowing who accepted the return.
- When - date, and time where handovers are frequent.
- In what condition - including existing damage, noted by the receiver. This is the entry’s insurance value.
- Why - the job, site, or project, which later lets you reconstruct where the item physically was.
The log is per asset, not per person: one item, one timeline. A per-person view (“everything Lena holds”) is useful too, but it is derived from the asset timelines, not a substitute for them. That per-asset shape is what separates a custody log from an equipment sign-out sheet, which is organised around a pool of shared kit rather than around one thing.
Custody log template: the fields to include
Most people searching for a custody log template want a column list they can put into a form, a sheet, or a system today. This is the set that holds up under questioning:
| Field | What it is for | Mandatory? |
|---|---|---|
| Entry number | Gives every handover a stable reference, so corrections and disputes can point at a specific line | Yes |
| Date and time | Places the handover in the timeline; time matters wherever an item changes hands more than once a day | Yes |
| Asset ID / asset tag | Identifies the exact unit, not the model. See asset tag | Yes |
| Description and serial number | Backs up the ID with something the manufacturer also recognises. See serial number | Yes |
| Released by | The person or store giving the item up - half of the handover people forget | Yes |
| Received by | The person taking charge from this moment on | Yes |
| Condition at handover | The state the receiver accepts, existing damage included. See condition report | Yes |
| Acknowledgement | Signature, initials, or a logged scan by the receiver - what turns a claim into an agreement | Yes |
| Accessories included | Chargers, batteries, cases, blades, keys. Partial returns are the most common real dispute | Recommended |
| Purpose or destination | Job, site, project, or client, so the item’s physical whereabouts can be reconstructed later | Recommended |
| Due or expected return date | Makes the item chaseable instead of merely absent. See overdue asset | Recommended |
| Notes | Anything that will not fit the fields: agreed exceptions, damage photos, ticket references | Optional |
Two of these are worth naming twice. Condition and accessories are the fields most often left blank and the two that end up mattering when something goes wrong. A log that records who took the laptop but not that it left with a dock and two adapters cannot settle what came back, and a log with no condition line makes the person who reports a crack look like the person who caused it.
Custody log example
One asset, five entries. The item is a laser level with the asset ID LL-004.
| # | Date | Asset | Released by | Received by | Condition | Accessories | Purpose |
|---|---|---|---|---|---|---|---|
| 1 | 04 Mar, 07:10 | LL-004 | Tool crib (M. Reid) | L. Andersson | Good, lens clean | Case, tripod, 2 batteries | Site 12, first-fix |
| 2 | 11 Mar, 16:40 | LL-004 | L. Andersson | J. Okafor | Good, scuff on housing | Case, tripod, 2 batteries | Direct crew-to-crew transfer, Site 12 |
| 3 | 19 Mar, 17:55 | LL-004 | J. Okafor | Tool crib (M. Reid) | Damaged - lens cracked | Case, tripod, 1 battery | Return from site |
| 4 | 20 Mar, 09:15 | LL-004 | Tool crib (M. Reid) | Precision Instruments Ltd | Damaged, as logged 19 Mar | Unit only | Warranty repair |
| 5 | 02 Apr, 11:00 | LL-004 | Precision Instruments Ltd | Tool crib (M. Reid) | Repaired and recalibrated | Unit only, cert attached | Return to service |
Read it back and each row answers a question someone will eventually ask. Entry 2 is why “who had it when the lens cracked” is answerable at all: it names both sides of a transfer that happened in a car park, not at a counter. Entry 3 is the only place the damage is fixed in time, and the missing second battery is recorded there rather than discovered three weeks later. Entries 4 and 5 keep the timeline unbroken while the item was off site, which is what makes the warranty claim straightforward and the calibration certificate traceable. Delete any one row and the log stops being a history and becomes a set of assertions.
Custody log vs chain of custody, hand receipt and sign-out sheet
These four terms get used as synonyms and are not. The most common error is treating chain of custody and custody log as the same thing: the chain is the process and the standard, the log is the record that evidences it.
| Record | What it is | Scope | Who signs | What a gap costs |
|---|---|---|---|---|
| Chain of custody | A process and legal standard requiring unbroken, documented possession | An item from collection to disposal or presentation | Every person in the sequence, both releasing and receiving | Evidence may be inadmissible or worthless |
| Custody log | The running record of every holder of one asset | One asset, its whole life | Releasing and receiving party at each handover | Accountability breaks; disputes become unresolvable |
| Hand receipt | A single signed handover event, descended from the military DA Form 2062 and its sub-hand receipts | One issue to one person, at one moment | The receiver, countersigned by the issuer | No proof that person accepted the item |
| Equipment sign-out sheet | A shared borrow list for a pool of kit | A pool or a store, not a single item | Whoever borrows, often initials only | No per-item history; the pool is short and nobody knows since when |
A stack of hand receipts in date order is effectively a custody log. A sign-out sheet becomes one only if it is reorganised per asset. And a custody log becomes a chain of custody when it is held to evidentiary discipline: sealed packaging, both signatures every time, no unexplained interval, and a documented handling protocol. In police and security work the same record is usually called a property custody log or evidence log, and it sits alongside a property-room access log; the vocabulary differs, the mechanics do not. For the operational pattern that generates these entries day to day, see check-in / check-out.
Who is on the log: owner, custodian, holder
Compliance frameworks that deal with asset inventories - ISO 27001 Annex A among them - keep insisting on a distinction that most spreadsheets collapse:
- The asset owner is accountable for the asset across its life: its classification, its acceptable use, its eventual disposal. The owner does not have to be holding the thing, and frequently never touches it.
- The asset custodian is whoever has day-to-day charge of it: the tool crib manager, the department lead, the IT team running a laptop pool.
- The holder is whoever signed for it right now, which may be a custodian, a technician on a site, or a contractor.
The asset register is where ownership lives, because ownership changes rarely. The custody log is where custody lives, because custody changes constantly. Keeping them in separate records is not duplication; it is the only way to answer “who decided this laptop could leave the country” and “who has it this week” as two different questions. The rule that ties them together is the one asset accountability is built on: delegating custody never delegates accountability. Handing an instrument to a subcontractor moves the holder line on the log and moves nothing at all on the register. For how this plays out under a formal control framework, see ISO 27001 asset management.
Why a who-had-what-when history matters
Shared equipment generates the same disputes everywhere. The laser level comes back with a cracked lens and three people plausibly had it that week. Half the tool batteries have vanished and nobody remembers which van they rode out in. An auditor asks who held a client’s loaned unit in February. A warranty claim needs to show the machine was with trained staff. In every case the answer is either in the log or in nobody’s memory - and memory reliably loses.
The compliance framing is blunter, and worth internalising because it is how auditors actually reason: a custody event that was never recorded is, for audit purposes, an event that did not happen. It does not matter that everyone remembers the handover. If the record does not carry it, the asset’s history has a hole in it, and a history with a hole cannot be relied on anywhere else either.
The log also changes behaviour upstream, which is the return most people underestimate. Equipment that is signed for comes back sooner and in better condition than equipment that simply circulates, because the last name on the record is visible to everyone and nobody enjoys being it.
Where custody logs are used
IT and offboarding. Laptops, phones, monitors, access cards and security keys are issued at hire and must come back at exit. The custody record is what proves a leaver’s laptop was returned, on what date, in what state, and who accepted it - a question that arrives months later from finance or from a security review. IT departments often call the same artefact an IT equipment custody form.
Tool cribs, construction and field service. Kit moves between vans, crews and sites, usually without passing a desk. Power tools, test instruments and access equipment change hands in car parks, which is exactly why the entry has to be possible where the handover happens. In construction the log doubles as the answer to “which site is that on”, not just “who has it”.
Laboratories and clinical settings. Samples, reagents and calibrated instruments sit closest to true chain-of-custody discipline: the log carries condition, storage state and calibration status, and the interval between entries is itself meaningful. Medical laboratories frequently run both records, an equipment custody log and a sample chain of custody, with different standards applied to each.
Schools, libraries and lending pools. High volume, modest unit value, very many hands. Libraries have run per-item custody histories longer than anyone, and the lesson from them is that the entry must take seconds, or the volume defeats it.
Police and security property rooms. This is the property custody log proper: seized and found property, evidence bags with tamper-evident seals, and a separate access log for the room itself. Here the custody record is evidence in its own right, and police departments hold it to the evidentiary standard rather than the operational one.
Custody at handover: onboarding, offboarding and transfers
Three moments do most of the work.
Issue at onboarding. A new starter receives a kit - machine, peripherals, phone, card. What the record must prove is that the items were received, itemised, and accepted in a stated condition. This is the point at which the accessories field earns its place, because onboarding kits are the ones most likely to come back partial.
Transfer between people or departments. An asset transfer is two facts, not one: released by X, received by Y. Systems and sheets that record only “now assigned to Y” lose the releasing half, and with it the ability to say when X stopped being answerable. Direct transfers are also the handovers most likely to happen away from any counter, so they are the ones most likely to go unrecorded.
Return at exit. The asset return is the entry that closes the loop, and a log that records issues but not returns shows every item as permanently out - which is worse than no log, because it looks authoritative and is wrong. Proof of return is the single most requested output of a custody log in commercial settings; the practical mechanics of getting kit back are covered in employee offboarding and hardware recovery.
A useful discipline for all three: the entry is made by the receiver, not the releaser. The person taking responsibility is the person with an incentive to state the condition accurately.
Custody at end of life
The last entry on a custody log is the one auditors ask about first, and it is the one most logs do not have. Disposal, resale, donation and recycling are all custody transfers: the item passes from the organisation to a vendor, a buyer, or a charity, and that handover deserves the same two-sided record as any other.
For data-bearing devices the stakes rise. The custody record has to line up with proof of erasure or destruction, so that the timeline reads: last internal holder, handover to the ITAD vendor on a stated date, then a certificate of destruction referencing the same serial numbers. When those three do not reconcile, you cannot demonstrate that the data left with the device under control, only that the device left.
An asset whose log simply stops is treated as unaccounted for, regardless of what actually happened to it. That is why asset decommissioning and asset disposal should both write to the custody timeline rather than only changing a status field somewhere else. “Retired” is a state; “released to vendor on 14 May, received by name, certificate reference” is a record.
Keeping a custody log current
- Log at the handover, not at the end of the week. Backfilled entries are guesses wearing the clothes of records.
- Record both directions. Returns and transfers matter as much as issues; a log of issues only shows everything as permanently out.
- Never edit history. Corrections go in as new entries that reference the entry being corrected, state what was wrong, and name who corrected it. A log that can be quietly rewritten convinces no one.
- Decide in advance who may correct an entry. Usually the custodian of the record rather than the person the correction favours - a small piece of segregation of duties that costs nothing to set up.
- Make the entry cheaper than skipping it. If logging a handover takes longer than the handover, the log loses.
- Spot check on a cadence. A quarterly asset verification on a sample of items tells you whether the log describes reality or only describes intentions.
How custody logs fail
The defects repeat across every organisation, and each produces a recognisable symptom:
- Undocumented transfers. An item moves crew to crew without an entry. Symptom: the log names a holder who has not seen the item for a month.
- Backfilled entries. Someone reconstructs the week on Friday afternoon. Symptom: suspiciously round times, and dates that conflict with other records.
- Missing acknowledgement. The issuer writes the entry alone. Symptom: the record is a claim rather than an agreement, and the named holder disputes it.
- Vague descriptions. “Drill” instead of an asset ID. Symptom: two identical units share one history and neither can be traced.
- One-directional logging. Issues recorded, returns not. Symptom: an overdue list that everyone has learned to ignore.
- Scattered custody. Approvals in email, a whiteboard in the store, a shared spreadsheet on someone’s drive. Symptom: no single timeline exists, so assembling one takes a morning and is still contested.
- Edited history. Entries changed in place. Symptom: the log is no longer usable as an audit trail, because nobody can say what it said last month.
Left long enough, these produce ghost assets: items the records still carry and nobody can actually find. The spreadsheet-specific version of most of these failures is unpacked in why Excel fails for asset tracking.
How long to keep custody records
There is no single legal answer, but there is a defensible default. Keep completed custody records at least through the next audit cycle, and as a floor at least a year. Keep an individual asset’s full history until its disposal is documented, not until its last return - the disposal entry is the one that closes the timeline, and deleting the earlier entries leaves it dangling. Where warranty, insurance, or sector compliance obligations reach further back, they set the period rather than your convenience does. Audit readiness mostly means being able to produce this history without a scramble.
The other half is data protection, and it applies to almost every organisation running one of these. Custody entries name employees and record their movements and their handling of company property, which makes them personal data. That has three practical consequences: collect only the fields accountability genuinely needs, limit who can read a full custody history rather than exposing it to everyone, and define a retention period in a data retention policy instead of keeping every entry indefinitely by default. “We keep it forever because storage is cheap” is not a retention policy, and it is the answer that causes trouble in a review.
Paper, spreadsheet, or system
All three work. They differ on five questions, and the honest comparison is worth making before choosing:
| Question | Paper log | Spreadsheet | Asset system |
|---|---|---|---|
| Does the entry happen at the moment of handover? | Yes, if the book is where the handover is | Rarely - usually typed up later | Yes, if the entry can be made on a phone at the point of handover |
| Can history be quietly rewritten? | Hard to alter, easy to lose | Yes, and without a trace | No, if the system keeps an append-only audit history |
| Can you see everything one person holds? | Only by reading every page | Yes, with filtering | Yes |
| Can you see every holder one item has had? | Yes, if the book is per item | Awkward - sheets are usually per pool or per week | Yes, per asset by design |
| Does it survive the person who maintained it? | The book does; the conventions do not | Rarely | Yes |
Paper has genuine strengths: it needs no connectivity, it collects a physical signature, and nobody has to be trained. It is a reasonable choice for a single store with one counter. Spreadsheets are free and perfectly adequate for one small pool of items, but they are organised around rows and dates rather than around assets, so the per-item timeline has to be assembled by hand every time somebody asks for it - and any cell can be changed without leaving evidence. A system earns its place mainly on the last two rows of that table: a permanent per-asset history, and independence from whoever used to keep the log.
Starting a custody log this week
- Choose the item set. Anything shared, portable, and worth replacing. Do not start with everything; start with the category that already causes arguments.
- Give every item a unique ID and a label. A per-asset ID is what makes a per-asset timeline possible. Physical labels - a printed QR code or an asset tag - stop the ID being a thing people have to remember.
- Define the handover moment. Name the exact event that requires an entry: leaving the crib, changing hands on site, going into a van, coming back. Ambiguity here is where most gaps originate.
- Put the entry where the handover is. If the record lives at a desk and the handover happens at a gate, the record loses. This is the single decision that determines whether the log survives month two.
- Agree the mandatory fields. Use the template table above, and resist adding columns nobody will fill.
- Decide who may correct an entry, and how. Corrections as new referencing entries, made by a named record custodian.
- Set a review cadence and run a first spot check. A short cycle count on ten items in week two will tell you more about the log’s health than a policy document will.
Then apply the one-minute test: pick any shared item and name, with dates, its last three holders. If the log cannot do that, it is a list of good intentions. For a broader walk-through of standing up equipment tracking from nothing, see how to keep track of company tools.
FAQ
What is the difference between a custody log and a chain of custody?
Chain of custody is the process and the standard; the custody log is the record that evidences it. A chain of custody describes the requirement that possession is documented without a break, from the moment an item is collected until it is disposed of or presented; the log is the physical or digital artefact that proves the requirement was met. In forensic, laboratory, and evidence-room work the standard is legal admissibility, and a single gap can make the item worthless. For equipment, the standard is operational accountability, and a gap is a problem to be closed rather than a disqualification. Most workplaces run a custody log and borrow only as much of the chain’s rigour as their risk demands.
What should each entry in a custody log include?
The asset’s ID, who released it, who received it, the date and time, the condition at handover, the accessories included, and ideally why - the job, project, or site it went to. A signature, initials, or a logged scan turns the entry from a claim into an acknowledgement. Condition and accessories are the two fields most often skipped and most often needed: without them, damage found later belongs to whoever is unlucky enough to report it, and a missing charger becomes an argument rather than a record.
What fields should a custody log template have?
Mandatory: entry number, date and time, asset ID, item description with serial number, released by, received by, condition at handover, and an acknowledgement. Strongly recommended: accessories included, purpose or destination, and an expected return date. Optional: notes, and a reference to the ticket or approval behind the movement. Keep the fields to what accountability actually needs - every extra column is one more reason a busy person skips the entry entirely.
How long should you keep custody records?
As a working rule, keep completed custody records at least through the next audit cycle and generally no less than a year, and keep an individual asset’s full history until its disposal is documented rather than until it comes back. Warranty, insurance, and sector compliance obligations often reach further back, so check those before deleting anything. Because custody entries name employees, they are personal data: limit who can read a full history, collect only the fields accountability requires, and set a defined retention period instead of keeping everything forever.
What should you do if there is a gap in a custody log?
Close it honestly rather than tidily. Record a new dated entry that states what is known and what is not - the last confirmed holder, the date the item was next seen, and who reconstructed the entry - and mark it as a reconstruction rather than a contemporaneous record. Never backdate or overwrite history, because a log that can be quietly rewritten stops being evidence of anything. Then fix the cause: most gaps come from a handover that happened somewhere the log was not, so move the entry point to where the handover actually occurs.
Do small teams need a custody log?
As soon as equipment is shared, yes - the trigger is shared use, not headcount. A five-person crew passing one laser level around generates exactly the disputes a log prevents: who had it when the lens cracked, where it was left on Friday, whether it ever came back from the last job. For one person and their own kit, an asset list without custody history is usually enough.
Tools that make this easier
A custody log survives on how cheap the entry is at the moment of handover. AMPthilly keeps one register for physical equipment, digital records and consumables, and records checkouts and returns against a named employee, client, department or location - capturing who, when, the condition, and any notes, with due dates, direct transfers between owners, and bulk checkout for onboarding kits. Printable QR labels are scanned with a normal phone camera and open the asset’s profile in the browser with no app to install, so the entry can be made in a car park rather than back at a desk. The audit history logs checkouts, returns, transfers, ownership and status changes, field edits, attached documents, tickets and approvals into one filterable timeline you can export to CSV, and the four roles - Admin, Manager, Employee, Client - govern who can see a full history. Onboarding and offboarding templates cover the issue-and-return sweep, including one-step transfer of a leaver’s gear to a replacement with the history intact. The free plan covers 3 users, 25 assets and 75 MB with no card required, and includes SSO, MFA and full audit history. Built in the EU and GDPR-aligned.
The takeaway
A custody log is per asset and chronological: one item, one timeline, every holder in order. Each entry is a two-sided handover - released by someone, received by someone - with condition and accessories attached, made at the moment it happens and never edited afterwards. It is worth exactly what it can prove when an auditor, an insurer, or a colleague asks, which is why the chain of custody is the standard and the log is the evidence. The practical bar has not changed: pick any shared item and name its last three holders, with dates, in under a minute.
Related terms
- Chain of Custody - the unbroken, evidence-grade standard the log provides evidence for
- Equipment Loan Agreement - the terms a holder accepts when custody transfers
- Equipment Reservation - booking custody of an item ahead of time
- Tool Crib - the controlled store where custody usually begins and ends
- Kitting - bundling items so custody transfers as one set instead of piece by piece