This post focuses specifically on criminal investigations and disaster victim identification, since different forensic applications can fall under different legal frameworks. Closing a scientific gap and putting a tool into real casework are two different things. Here’s what has to happen in between.
Research finding, not operational approval
A method that performs well in one laboratory is a research finding. Different institutions must carry out several separate processes before it becomes an authorised operational tool, each answering a different question.
Proving the science actually works
Validation isn’t one test. It typically includes selecting and confirming the relevant markers, measuring accuracy and error rates, and testing degraded or mixed samples. It also means checking performance across different sample types, and validating the software or model used to interpret results. Crucially, it also means checking whether the method performs equally well across different populations and sample sources, not just on average. A method with good overall accuracy can still create unequal outcomes if its errors are concentrated in particular groups. Independent laboratories then need to reproduce the results under real operating conditions, not just repeat the original study.
How forensic laboratory workflows prove a lab can use it properly
This is a separate question from whether the method works. Laboratory accreditation, commonly through the ISO/IEC 17025 standard, assesses whether a laboratory is competent to carry out a defined scope of testing under an effective quality system. ISO publishes the standard. A national accreditation body then evaluates the laboratory against it, for a specific set of methods, not automatically for every technique the lab might use in future.
Establishing a lawful, proportionate purpose
In the EU, when a competent authority processes personal data for criminal investigations, the Law Enforcement Directive (2016/680) applies. It requires that any measure affecting someone’s rights be necessary and proportionate to its purpose. Proportionality doesn’t mean “a new method is barred whenever an older one exists.” It means weighing whether the tool’s expected value justifies its effect on someone’s rights, and whether a less intrusive option could achieve a similarly reliable result. Genetic and biometric data that can uniquely identify someone sit in specially protected categories under the Directive. It permits their use only where strictly necessary, with appropriate safeguards.
“Processing” here means the entire life of the data: collecting a sample, analysing it, storing a result, sharing it, and eventually deleting it. All of these steps, not just the lab test, fall under the same legal requirements.
Protecting the people behind the data
Concrete safeguards matter more than the word “safeguards” itself. In practice, that includes restricting a method to a clearly defined purpose, recording who accessed and used a result, deleting data once it’s no longer needed, and requiring a data-protection impact assessment before deployment. Purpose limitation, in plain terms: if a lab analyses a sample to help one investigation, no one should reuse the resulting data later for an unrelated purpose without a separate legal basis.
If a criminal case uses a result, the defence needs a meaningful way to examine and challenge the method itself: the validation data, the error rates, and how investigators reached the result, not just the final output.
Authorising and monitoring deployment
Here’s a simplified version of the path from research to practice:
- Researchers demonstrate initial performance
- Independent labs reproduce it
- The intended use, ethical and legal basis are defined
- Data-protection and rights risks are assessed
- The implementing laboratory validates the method locally
- An accreditation body assesses that lab’s scope
- A competent public authority authorises a specific use
- Courts or other bodies determine, case by case, what weight the result carries as evidence
None of these steps is optional, and the research team performs none of them itself.
This doesn’t stop once a tool is deployed. Ongoing monitoring, such as tracking real-world error rates, re-validating after a software update, and investigating complaints, is part of responsible use, not a one-time formality before launch.
Where ForMAT stands
Some forensic institutes and operational laboratories participate in the ForMAT research consortium. That participation is part of the project’s research and development work. It doesn’t mean any authority has authorised a ForMAT toolset for routine operational use or relied on it in a real decision. Whether, and how, any of this research might eventually be authorised depends on the validation, accreditation, ethical, legal, and oversight steps described above, carried out by the relevant independent bodies, not by the project itself. A scientifically promising early result doesn’t guarantee that the relevant bodies will ultimately validate, authorise, or admit the method as evidence.
A concrete example
A blood trace at a crime scene produces no database match. Before investigators could use any new methylation-based method, the authority would need to confirm the law permits it for this type of case and that using it is necessary and proportionate. The laboratory would need a validated procedure and would report any result with its uncertainty, not a precise figure. Investigators could use a broad estimate as one factor in reviewing leads. They shouldn’t treat it as an identification, and they shouldn’t exclude everyone outside the estimated range on that basis alone. Investigators should record every step, from analysis to access to retention, and keep it open to independent review.
Curious about the science behind this? Our posts on the investigative gap forensic labs face and common myths about forensic DNA cover that side of the story. For the EU’s framework governing data protection in criminal investigations, see Directive (EU) 2016/680; for the laboratory accreditation standard referenced above, see ISO/IEC 17025.
Frequently asked questions
What does “processing” mean in this context?
It covers the entire life of a piece of data: collecting a sample, analysing it, storing the result, sharing it, using it in a decision, and eventually deleting it. It’s not just the lab test itself.
What’s the difference between validation and accreditation?
Validation asks whether a method works reliably. Accreditation asks whether a specific laboratory is competent to run tests, including that method, within an effective quality system. A lab can be accredited generally while a particular new method still needs to be added to its accredited scope.
What does “legal admissibility” mean?
Whether a court is permitted to receive and consider a result as evidence at all. Being admitted doesn’t mean a court accepts the result as decisive. Courts still weigh how much to rely on it.
Does this apply to everything ForMAT is researching?
This post focuses on criminal investigations and disaster victim identification. Other potential application areas may involve different legal frameworks and different safeguards, and would need their own dedicated assessment.