Business records are documents or data that an enterprise routinely generates and retains as part of its normal operations, and that are considered accurate enough to guide managerial decisions. Under the U.S. Federal Rules of Evidence (FRE), business records are an exception to the Hearsay rule and are generally admissible.
Key requirements:
- The record was made in the regular course of business.
- It was kept as part of a routinely conducted activity.
- It is considered reliable enough for the organization to use in decision-making.
Business records can include a wide range of digital and paper documents, such as email, memos, access logs, and intrusion detection system (IDS) reports. Some records may be subject to legal retention requirements, while others may follow internal retention or destruction policies.
The U.S. Department of Justice notes that courts have sometimes admitted computer-generated records under the business records exception even when those records were not actually hearsay, because they resulted from an automated process rather than a human statement.
Examples:
- Contracts and employment agreements
- Invoices and payment records
- Routinely kept access logs
- /var/log/messages
- IDS reports
Source: Network Forensics: Tracking Hackers through Cyberspace, §1.3.6.