Electronic signature audit trail: how to prove who signed what and when
What is an electronic signature audit trail?
An audit trail is a chronological record of the events associated with a digital process. In the case of electronic signatures, depending on the platform, it may document events such as sending a document, the progress of the workflow, completion of the signature process or its rejection.
Its main purpose is to make it possible to reconstruct at a later stage who was involved in the process, what happened and when.
However, an audit trail should not be confused with the electronic signature itself. The activity log records the workflow, while cryptographic evidence relates directly to the signed document and makes it possible to verify elements such as the signature, certificate, timestamp and integrity of the content.
The two components complement each other, but do not necessarily have the same evidentiary value.
What information should an audit trail contain?
Not all platforms record the same events. Before choosing an electronic signature solution, it is therefore useful to check what information is retained and how easily it can be retrieved.
| Information | Why it matters |
| Participants in the process | Helps reconstruct who was involved |
| Date and time of events | Makes it possible to establish a chronological sequence |
| Signature status | Indicates whether the request has been completed, rejected or is still pending |
| Transaction identifiers | Make it easier to correlate the transaction with other business systems |
| Certificate used | Makes it possible to verify the information associated with the signature |
| Document integrity | Makes it possible to detect any subsequent changes |
For organisations subject to audits or compliance requirements, it is also important to consider the retention, accessibility and exportability of evidence, rather than focusing solely on the number of events recorded.
How can you verify that a document has not been modified?
An electronic signature based on cryptographic mechanisms does not necessarily make it impossible to modify a file. Instead, it makes it possible to detect alterations made after the document was signed.
The content of the document is mathematically linked to the signature. If the signed data changes, subsequent verification can indicate that its integrity is no longer guaranteed. The Swiss Federal Administration also explains that, if a signature is valid, it is possible to verify that the content has not been altered since it was signed. (Bit_admin)
Certificates and timestamps add further elements to the verification chain: the certificate provides information about the signature, while the timestamp makes it possible to establish when the signature was created.
For this reason, it is more accurate to speak of detecting tampering rather than describing documents as technically “unchangeable”.
Why does verification not end when the document is signed?
A document may need to be checked months or years after it was signed. At that point, simply knowing that the workflow was completed may not be enough: it may be necessary to verify whether the signature is technically valid, which certificate was used, whether the file has changed or whether the certificate has been revoked.
Validation tools therefore serve a different purpose from the audit trail.
Another important aspect is signing authority. In a business contract, correctly identifying an individual does not automatically prove that they were authorised to represent the organisation.
One example of this approach in the Swiss market is DeepValidator by DeepCloud. The service validates electronic signatures and seals and, through integration with Swiss Commercial Register data, can check the registered signing authorities for a specific organisation. DeepValidator can also be used to validate signatures from different providers.
Identifying, signing and verifying: three distinct steps
A reliable digital process can therefore be viewed as a chain consisting of three functions:
- Identify the signer
- Sign the document
- Subsequently verify the signature and signing authorities
This distinction also helps when evaluating platforms more comprehensively.
In the DeepCloud ecosystem, for example:
- DeepID is used for digital identification and is integrated into the signing process with DeepSign
- DeepSign manages the electronic signing of documents
- DeepValidator handles the subsequent validation of electronic signatures and seals and, where relevant, registered signing authorities
The value of this model also lies in the fact that all three functions belong to the same ecosystem. More generally, however, when comparing different solutions, the key criterion is to ensure that identity, signature, integrity and validation can be linked in a clear and verifiable way.
A real-world example: GGA Maur digitises collective signatures
The importance of linking identification and signing can be seen in the case of Swiss cooperative GGA Maur. The organisation needed to manage collective signatures even when authorised signatories were working from different locations or remotely. Previously, it used scanned signatures inserted into documents, a method that did not make it possible to verify the signer’s identity unambiguously.
GGA Maur therefore digitised the process using DeepSign in combination with DeepID: DeepID to identify the signer and DeepSign to digitally sign the documents. This allowed GGA Maur to manage signatures remotely while maintaining a documented process and reducing manual steps.
In addition to traceability, the case also demonstrates measurable operational benefits: GGA Maur has reached 500 digitally signed documents and reports savings of CHF 10 per document.
In addition, for organisations with more advanced traceability requirements, on-premises solutions are available. DeepSign On-Prem, for example, securely records actions throughout the process and embeds information about the certificate and, where applicable, the qualified timestamp in the document.
Audit trails and legal validity in Switzerland
In Switzerland, the relevant legal framework is the Federal Act on Electronic Signatures (ZertES).
An audit trail alone does not make a signature equivalent to a handwritten signature. Under Article 14 paragraph 2bis of the Swiss Code of Obligations, this equivalence applies to a qualified electronic signature based on a qualified certificate issued by a recognised provider and accompanied by a qualified timestamp. (Bit_admin)
For many contracts, however, Swiss law applies the principle of freedom of form. The appropriate type of signature therefore depends on the document, the legal requirements and the agreements between the parties.
Conclusion
A reliable signing process does not end when the document is signed. It should make it possible to reconstruct who signed, which document was signed, when the signature took place, whether the content remained intact and, where relevant, whether the signer was authorised to act on behalf of an organisation.
A good audit trail makes it possible to reconstruct the process, but it does not replace the evidence associated with the signature. When evaluating a solution, it is therefore useful to ask a practical question: if this document were challenged or needed to be verified five years from now, what evidence would I have available to prove who signed it, when, what content was signed and under what authority?
Frequently asked questions
Does an audit trail prove that a document has not been modified?
Not on its own. The log reconstructs the events in the process; document integrity is instead verified through the cryptographic mechanisms associated with the signature.
Does an audit trail prove the identity of the signer?
Not necessarily. The audit trail documents the events associated with the signing process, but the level of certainty regarding the signer’s identity depends on the identification method used and the type of electronic signature.
Is it possible to verify which certificate was used?
Yes. For certificate-based digital signatures, information relating to the certificate can be analysed during the validation process.
Does knowing who signed also prove that they were authorised to represent the company?
Not necessarily. Identity and authority to represent an organisation are two separate matters. For Swiss organisations, data from the Commercial Register can help verify registered signing authorities.
What evidence is useful in the event of a dispute?
The signature, certificate, timestamp, integrity verification and process logs can all help reconstruct what happened. Their specific evidentiary value depends on the type of signature and the circumstances of the individual case.