Two years after signing, a client says they never signed the contract. You have the PDF with their signature; their lawyer asks who put it there, and when. The electronic signature audit trail is how you answer: a chronological record of everything that happened to the document while it was being signed. Here is what a good one records, why it matters in a dispute, how to make it tamper-evident and what to ask your provider.
What an audit trail records
An audit trail, also called an evidence file or a certificate of completion, is the log a signing platform keeps for each document. It typically records:
- when the document was created and sent, and to which email address or phone number;
- when each signer opened the link, with their IP address and browser or device;
- when a one-time code was requested, where it was sent and when it was entered correctly;
- any identity check performed, and its outcome;
- when each signature was applied and the document completed, with a fingerprint (hash) of the final file.
The signed PDF shows what was signed. The audit trail shows who, when, how and from where. In a dispute you need both.
Does every provider keep one?
The ones we checked do, under different names. DocuSign's data residency page calls the audit trail of a transaction the Certificate of Completion, which records the details of the signing event. Youtrust (formerly Yousign) lists "Audit trail in PDF" in its plan comparison and describes an evidence file attesting to the signature, which includes the time stamp. Both were checked on 2 October 2026. What differs is what the record contains, how well it is protected and whether you can take it with you.
Why it matters when a signature is disputed
eIDAS guarantees that an electronic signature cannot be denied legal effect or refused as evidence just because it is electronic (Article 25(1)), but it leaves its weight to national law (recital 49). For a simple electronic signature, the audit trail is often the main evidence of who signed. Two national examples:
- Italy. For a document with a simple electronic signature, the court freely assesses whether it meets a written form requirement and what it proves, in the light of its security, integrity and unalterability (Article 20(1-bis) of the Digital Administration Code). Those are the questions an audit trail answers.
- Germany. Outside the presumption for qualified signatures (§ 371a of the Code of Civil Procedure, ZPO), the court decides by its free conviction, taking account of the whole proceedings and of any evidence taken (§ 286 ZPO).
For an advanced electronic signature, the audit trail is also part of how you show that the requirements of Article 26 were met: that the signature is uniquely linked to the signer, capable of identifying them and created under their sole control. A consistent record turns "I never signed" into a question of facts: for example, a phone number registered to the client, a one-time code verified at 14:32, the signature at 14:34 and an IP address consistent with their office. Our guide to whether electronic signatures are legally binding covers the rules in more Member States.
The weak point: who keeps the record?
The next objection is predictable: the log was produced by the other side's provider, so it could have been edited. A serious audit trail must be tamper-evident, not just detailed. The common techniques:
- Hash chain. Each event includes the SHA-256 fingerprint of the previous one, so altering one entry breaks the chain from that point on.
- Qualified time stamp. It binds data to a moment and enjoys a presumption of the accuracy of its date and time and of the integrity of the data it is bound to (Article 41(2) eIDAS).
- Qualified electronic seal. Applied to the document, it enjoys a presumption of the integrity of the data and of the correctness of its origin (Article 35(2)).
- External anchoring. The fingerprint is recorded on a system the provider does not control, such as a public blockchain: a complement to the legal evidence, not a substitute for it.
What to ask your provider
- Can you export the audit trail as a readable document, or does it live only inside the platform?
- Are the events chained cryptographically, or is it a log that can be rewritten?
- Can a third party verify the record without trusting the provider?
- Does it record the identity check, if you use one, and the contact details the code was sent to?
- Does the record stay with you if you close your account?
How long to keep it
Keep the audit trail together with the signed PDF for as long as the contract could be disputed, which depends on the limitation periods of the law that governs it: without the audit trail, a PDF signed with a simple signature has little to show who signed it. The record also contains personal data, such as names, contact details and IP addresses, so include it in your retention policy.
How it works on DOCUJET
Every DOCUJET plan records who signed, when and from where. At the end of every signed PDF is its certificate: who signed, with which contact detail, on what day and at what time, and the SHA-256 fingerprint of the original document. The full record of every step, IP address included, is in the audit dossier you download from the document, and the audit trail uses a SHA-256 hash chain. From the Starter plan upwards the document also receives a qualified electronic seal and a qualified time stamp from Namirial. Every document's fingerprint is anchored on the Bitcoin blockchain, and anyone can check it on our verification page without the file leaving their browser. Our guide on how to verify a digital signature in a PDF covers the other checks, and the security page explains how we protect documents.
Sources: Regulation (EU) No 910/2014 (eIDAS), Articles 25, 26, 35, 41 and recital 49; Digital Administration Code, Article 20 (Italy); ZPO § 286, § 371a; DocuSign, data residency; Youtrust, application pricing.
Ready to try it?Open a free account: 3 documents a month, forever, with a complete audit trail.Start for free →
