Plan and prepare

When a checksum check reports a mismatch, pause the routine that would overwrite or synchronize that file. A changed value means the bytes differ from the recorded baseline; it does not by itself identify corruption, malicious activity, or an authorized edit. Preserve the report and the current file while you investigate.

Confirm that the comparison used the correct manifest, algorithm, and path. Check for a renamed file, a deliberate new edition, or a tool setting that changed the selection. Record what you find. A simple path mistake should be corrected in the workflow, but the original alert should remain in the maintenance log.

Use a clear process

Compare available copies without modifying them. Identify which versions match a trusted earlier manifest and whether there is a documented reason for a newer version. Work on duplicates for inspection. Do not immediately replace every copy with the first file that opens, because readability alone does not establish which version should be preserved.

If the change was intentional, retain the prior version where appropriate, document the change, and create a baseline for the new edition. If the cause remains unknown, label the item for review and protect the known copies. Use competent technical help when storage failures or a suspected security incident are involved.

Worked example

Suppose one scanned meeting record changes while the rest of the collection matches its baseline. The maintenance log shows that a volunteer rotated the image to make it easier to read, but did so in the preservation folder. Preserve the original copy from an independent backup, retain the rotated version as an access copy if appropriate, and document what occurred. This situation requires a corrected workflow, not an assumption of malicious damage. A different mismatch with no explanatory record should remain unresolved until the available evidence has been reviewed.

Decisions and exceptions

Use an investigation note with the item identifier, alert date, original baseline, current value, available copies, and known recent actions. Record each comparison without editing the files under review. If multiple copies disagree, do not choose a version solely because it has the latest timestamp; timestamps can reflect transfers and other ordinary activity. Look for documented provenance and a trusted earlier verification. When the evidence cannot establish a preferred version, preserve the uncertainty and the available candidates rather than creating a confident but unsupported replacement history.

Check and improve

After a resolution, identify the smallest process change that prevents recurrence. The rotated-image example may need a clearly separated access-copy folder, a read-only preservation area managed through appropriate permissions, and a short instruction for requesting edits. A storage problem may require technical review and a broader check of the affected device. Record who authorized the final action and which copies were updated. Then run the appropriate verification again and confirm the catalog points to the intended version. The final result should explain both the file's state and why the team believes that state is the correct one to preserve.

Solo and community application

Alone, practice with an unimportant copied text file before handling irreplaceable records. In a community archive, require a second person to review a proposed replacement of a preservation master. Keep the decision, evidence, and responsible person's name in the log so a future steward can understand what happened.

Reference guidance

Library of Congress preservation resources explain checksums and records of file changes. The investigation sequence here is a cautious local procedure. After resolving the item, examine whether other files on the same media need checking and fix the process that allowed an authorized change or damaged copy to go unexplained.