Electronic signatures are getting a lot of attention at the moment with people across the world stuck at home due to the coronavirus without any other way to sign documents. This means that more and more documents are being signed electronically than ever before. But, electronic signatures and traditional handwritten signatures are very different. How do you know whether you are signing documents securely using electronic signatures? What are the risks of signing documents electronically and how do you minimize those risks?
This is a particular problem for businesses that haven’t used any kind of electronic signatures before (as far as they know). Electronic signature adoption has been growing steadily over the years and some organisations are on their way towards this kind of digital transformation. Increasing work-from-home trends, now magnified by the forced experiment that lockdowns have brought about, accentuate the focus on electronic signatures. Using electronic signatures instead of handwritten ones is a marked change for most organisations. If addressed properly, the change will improve the security of their signing processes.
Use electronic signatures securely
Many organisations are using whatever electronic signature technologies they can get their hands on without sufficient consideration for security and other practical aspects. Understanding three key concepts will help your organisation to use electronic signatures securely. These are identity, intent and evidential weight.
Identity
When it comes to handwritten signatures, we often rely on identity safeguards such as having witnesses or requiring the signatory to write their name near their signature. These methods can present problems.
Electronic signatures indicate the identity of the signatory in the vast majority of instances of electronic communications. In the electronic world, systems typically identify signatories through unique identifiers sent specifically to them (such as specific URLs or one-time-PINs sent to them by email or text message) or unique credentials (such as usernames and passwords to log into a signing dashboard). In these ways, electronic signatures are often safer than handwritten ones because they use more robust ways of authenticating the identity of the signatory.
Intent
In the world of handwritten signatures, the law recognizes that a ‘mark’ (that may or may not identify the signatory) if intended to act as a signature, is valid. Traditionally, to evidence agreement with words or text contained in a written document, the signatory would apply a signature to the document.
For an electronic signature to validly evidence agreement with or adoption of data in an electronic record, it must be linked to the data intended to be signed. It must tell the story of how the person signing meant to agree to the contents of an electronic message by tying their identity to it through an electronic signature.
It should show that signatory intended the signature to be their signature in a particular context (in some cases it is intended merely as an autograph, in others it might be confirmation that something has been seen or delivered and yet in others it might be confirmation of intent to enter into transactions that have legal consequences).
Evidential weight
Evidential weight is the measure of credible proof that a signature has based on the available facts proving identity and intent.
Typically, if a handwritten signature is disputed the signatory would be called to confirm or deny the signature and possibly the signatories’ intent when applying the signature. Courts might admit evidence from witnesses who saw the signatory apply their signature or handwriting experts that might, in their professional capacity, attest to the fact that they believe the signature in question to be that of the signatory. But, signatories and witnesses die, leave organisations or become otherwise unavailable.
Electronic signatures have greater capacity to positively prove identity and intent by using technologies, such as multi-factor authentication to establish that the signatory is who they claim to be and cryptography to prove that they signed the electronic record by creating a tamper-proof evidentiary artifact. These can confirm the steps that lead up to their signature (such as how the signatories’ identity was authenticated and when and how they chose to apply their signature).
If a digital signature is used, the association of the signatory with the electronic record ensures that the record cannot be amended in any manner after the application of the signature, without detection. This security is superior to paper-based documents that may be changed after signature is applied without the change being evident.
It is important that you choose an electronic signature technology solution that has sufficient evidential weight for your purposes. In assessing evidential weight a court will take into account how the signatory was identified and the reliability of the measures used to prove the integrity of the electronic record (that it was not changed) and the reliability of the association of the signature applied to the electronic record. Weak electronic signatures will be attributed less weight and strong electronic signatures greater weight.
Next steps on how to use electronic signatures securely
Signatures are a critical part of our commercial lives. Knowing about electronic signatures and the security they can provide in our increasingly digital world is a vital business and life skill. We can help you with:
- our Electronic Signature Handbook to empower yourself;
- a free online Electronic Signature Assessment that you can complete yourself; or
- general consulting on Electronic Signature Law.