Skip to content

Signing

Audit certificate

A signature is only as good as what you can show about how it happened.

Applies to
All signed documents
Attached to
The executed document

What it does

Every executed document carries an audit certificate recording signer IP, intent-to-sign consent, timestamps, SHA-256 fingerprint, retained for 24 months.

The certificate is what turns a signed PDF into something you can rely on later. It travels with the executed copy rather than living in a separate log somebody has to go and find.

What the fingerprint is for

The SHA-256 fingerprint records what was actually signed. If a copy of the document turns up later and anyone questions whether it is the same file, the fingerprint answers it: a single changed byte produces a different hash.

That is the difference between a certificate that says a signature happened and one that ties the signature to a specific document.

What it does not do

Electronic signatures are admissible for most commercial documents in England & Wales; exceptions include deeds, wills, land transfers and lasting powers of attorney. General information, not legal advice.

Questions

Audit certificate, answered

No. Every executed document carries one.

With the executed document, retained rather than held in a separate system.

/features /features/e-signature /glossary/eidas /security