Skip to content

Electronic signature audit trail: how to prove who signed what and when

Share on

An electronic signature audit trail makes the process traceable. However, assessing its reliability also requires considering identity, certificates, timestamps and document integrity
image

What is an electronic signature audit trail?

An audit trail is a chronological record of the events associated with a digital process. In the case of electronic signatures, depending on the platform, it may document events such as sending a document, the progress of the workflow, completion of the signature process or its rejection.

Its main purpose is to make it possible to reconstruct at a later stage who was involved in the process, what happened and when.

However, an audit trail should not be confused with the electronic signature itself. The activity log records the workflow, while cryptographic evidence relates directly to the signed document and makes it possible to verify elements such as the signature, certificate, timestamp and integrity of the content.

The two components complement each other, but do not necessarily have the same evidentiary value.

What information should an audit trail contain?

Not all platforms record the same events. Before choosing an electronic signature solution, it is therefore useful to check what information is retained and how easily it can be retrieved.

InformationWhy it matters
Participants in the processHelps reconstruct who was involved
Date and time of eventsMakes it possible to establish a chronological sequence
Signature statusIndicates whether the request has been completed, rejected or is still pending
Transaction identifiersMake it easier to correlate the transaction with other business systems
Certificate usedMakes it possible to verify the information associated with the signature
Document integrityMakes it possible to detect any subsequent changes

For organisations subject to audits or compliance requirements, it is also important to consider the retention, accessibility and exportability of evidence, rather than focusing solely on the number of events recorded.

How can you verify that a document has not been modified?

An electronic signature based on cryptographic mechanisms does not necessarily make it impossible to modify a file. Instead, it makes it possible to detect alterations made after the document was signed.

The content of the document is mathematically linked to the signature. If the signed data changes, subsequent verification can indicate that its integrity is no longer guaranteed. The Swiss Federal Administration also explains that, if a signature is valid, it is possible to verify that the content has not been altered since it was signed. (Bit_admin)

Certificates and timestamps add further elements to the verification chain: the certificate provides information about the signature, while the timestamp makes it possible to establish when the signature was created.

For this reason, it is more accurate to speak of detecting tampering rather than describing documents as technically “unchangeable”.

Why does verification not end when the document is signed?

A document may need to be checked months or years after it was signed. At that point, simply knowing that the workflow was completed may not be enough: it may be necessary to verify whether the signature is technically valid, which certificate was used, whether the file has changed or whether the certificate has been revoked.

Validation tools therefore serve a different purpose from the audit trail.

Another important aspect is signing authority. In a business contract, correctly identifying an individual does not automatically prove that they were authorised to represent the organisation.

One example of this approach in the Swiss market is DeepValidator by DeepCloud. The service validates electronic signatures and seals and, through integration with Swiss Commercial Register data, can check the registered signing authorities for a specific organisation. DeepValidator can also be used to validate signatures from different providers.

Identifying, signing and verifying: three distinct steps

A reliable digital process can therefore be viewed as a chain consisting of three functions:

  • Identify the signer
  • Sign the document
  • Subsequently verify the signature and signing authorities

This distinction also helps when evaluating platforms more comprehensively.

In the DeepCloud ecosystem, for example:

  • DeepID is used for digital identification and is integrated into the signing process with DeepSign
  • DeepSign manages the electronic signing of documents
  • DeepValidator handles the subsequent validation of electronic signatures and seals and, where relevant, registered signing authorities

The value of this model also lies in the fact that all three functions belong to the same ecosystem. More generally, however, when comparing different solutions, the key criterion is to ensure that identity, signature, integrity and validation can be linked in a clear and verifiable way.

A real-world example: GGA Maur digitises collective signatures

The importance of linking identification and signing can be seen in the case of Swiss cooperative GGA Maur. The organisation needed to manage collective signatures even when authorised signatories were working from different locations or remotely. Previously, it used scanned signatures inserted into documents, a method that did not make it possible to verify the signer’s identity unambiguously.

GGA Maur therefore digitised the process using DeepSign in combination with DeepID: DeepID to identify the signer and DeepSign to digitally sign the documents. This allowed GGA Maur to manage signatures remotely while maintaining a documented process and reducing manual steps.

In addition to traceability, the case also demonstrates measurable operational benefits: GGA Maur has reached 500 digitally signed documents and reports savings of CHF 10 per document.

In addition, for organisations with more advanced traceability requirements, on-premises solutions are available. DeepSign On-Prem, for example, securely records actions throughout the process and embeds information about the certificate and, where applicable, the qualified timestamp in the document.

Audit trails and legal validity in Switzerland

In Switzerland, the relevant legal framework is the Federal Act on Electronic Signatures (ZertES).

An audit trail alone does not make a signature equivalent to a handwritten signature. Under Article 14 paragraph 2bis of the Swiss Code of Obligations, this equivalence applies to a qualified electronic signature based on a qualified certificate issued by a recognised provider and accompanied by a qualified timestamp. (Bit_admin)

For many contracts, however, Swiss law applies the principle of freedom of form. The appropriate type of signature therefore depends on the document, the legal requirements and the agreements between the parties.

Conclusion

A reliable signing process does not end when the document is signed. It should make it possible to reconstruct who signed, which document was signed, when the signature took place, whether the content remained intact and, where relevant, whether the signer was authorised to act on behalf of an organisation.

A good audit trail makes it possible to reconstruct the process, but it does not replace the evidence associated with the signature. When evaluating a solution, it is therefore useful to ask a practical question: if this document were challenged or needed to be verified five years from now, what evidence would I have available to prove who signed it, when, what content was signed and under what authority?

Frequently asked questions

Does an audit trail prove that a document has not been modified?

Does an audit trail prove the identity of the signer?

Is it possible to verify which certificate was used?

Does knowing who signed also prove that they were authorised to represent the company?

What evidence is useful in the event of a dispute?

Still signing by hand?
Try DeepSign now.

Start for free