Certification assesses the facility. Custody follows the asset.
Why a vendor chain full of assessed facilities can still leak, and what has to be true instead.
Two different questions
A content security assessment answers: does this facility have appropriate controls. A custody record answers: where did this asset actually go.
They sound like the same question. They are not, and confusing them is how organisations end up with a fully assessed vendor chain and no ability to investigate a leak.
What assessment can and cannot do
Assessment is genuinely valuable. It raises the floor across a supply chain, it gives buyers a common language, and it forces small vendors to think about controls they would otherwise not have.
Its limits are structural rather than a criticism. It samples a facility at a moment. It cannot speak to the subcontractor engaged after the assessment, the freelancer working from a personal device, or the transfer tool someone reached for because the sanctioned one was slow that afternoon.
The moment it matters
A screener surfaces before its release date. The commercial damage is immediate and the investigation begins.
What the investigation has to work with is whatever records happened to exist. Usually that is email, access logs from several systems that do not correlate, and people memories. The investigation runs for weeks and frequently ends inconclusive, not because nobody tried but because the records were never designed to answer this question.
What has to be true instead
The asset has to carry its own history. Tagged in metadata, with each transfer logged as it happens, across organisational boundaries rather than only inside yours.
That produces something assessment cannot: after a leak you can trace the material back toward a source vendor or contributor in minutes. The conversation with the studio, the distributor and the insurer moves from blame to which control to close.
Making the secure path the fast path
One practical note that matters more than it should. Most custody failures are not defiance, they are friction. When the approved route is slow, people route around it, and the audit trail ends at that moment.
Any custody scheme that is slower than the workaround will be worked around. If the tracked path is also the fastest path, the behaviour resolves itself.
Questions, answered
Are you saying TPN is not worth doing?
Does custody tracking slow production down?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.