eSign.AIeSign.AI

Glossary

Audit Trails and Evidence Packages in eSignature

An audit trail records every action in a signing transaction. An evidence package bundles it for legal use.

eSign.AI Digital Trust Research Team6 min read

What is an audit trail?

An audit trail is a chronological record of every action that occurs during an electronic signature transaction: who sent the document, when it was delivered, who opened it, when they reviewed it, what IP address they used, when they signed, and when the completed document was returned. A well-designed audit trail captures every meaningful event and makes it tamper-evident.

Audit trail vs evidence package

Audit trailEvidence package
What it isLog of events during transactionBundled set of all evidence files
ContainsTimestamps, IPs, user actionsSigned document, audit trail, certificates, timestamps
FormatStructured log (JSON or CSV)PDF with embedded cryptographic evidence
PurposeOperational tracking and complianceLegal proof in court or arbitration

Events captured in a complete audit trail

A thorough audit trail records every significant event from creation to completion.

01

Who created the envelope, when, from what template, with which fields and signature placements.

02

When the email or SMS was sent, when the recipient opened the link, their device, browser, IP address, and approximate geolocation.

03

How long the recipient spent reviewing each page, whether they downloaded or printed the document before signing.

04

What authentication method was used (email OTP, SMS OTP, eKYC, eID), when the signature was applied, the signer certificate details, and the timestamp token.

05

When all signatures were collected, when the completed document was sent to all parties, and the final evidence package generation timestamp.

What goes into an evidence package

An evidence package is the bundle of files you would hand to a court or auditor to prove the signature is valid.

The signed document

The final PDF with embedded PAdES signatures and LTV data. This is the primary evidence — the document itself contains the cryptographic signatures.

Audit trail

A human-readable log of all events with timestamps, IP addresses, and user actions. This contextualises the signature — showing the signer reviewed the document before signing.

Certificate chain

The signer certificate, intermediate CA certificates, and root CA certificate, plus revocation data. Proves the certificate was valid at signing time.

Timestamp token

The RFC 3161 timestamp token from the TSA. Proves the signature existed at a specific time — essential for long-term validation.

Identity verification record

If eKYC was used, a record of the verification method, provider, result, and timestamp. Proves the signer identity was verified.

Audit trail specifications: events, storage, and court admissibility

Concrete specifications for audit trail evaluation.

Standard audit events by provider

Minimum audit events (ISO/IEC 19790): envelope sent, viewed, signed, completed, declined. Extended events: identity verification initiated, identity verified, authentication method, IP address, geolocation, device type, user agent, certificate applied, timestamp applied, document hash, tamper seal. eSign.AI captures all 25+ extended events by default.

Evidence package formats

Standard evidence: PDF audit trail (human-readable). Extended evidence: signed PDF with embedded certificate chain + timestamp token + CRL/OCSP (PAdES B-LT). Advanced evidence: JSON-LD proof with cryptographic hashes linked to blockchain anchor (eSign.AI roadmap 2026). Court filing format: notarised evidence export with affidavits available via QTSP partners.

Storage requirements by jurisdiction

EU eIDAS: retain signing evidence for the duration of the obligation (often 10+ years). China Electronic Signature Law: retain for 5 years minimum. Singapore ETA: no statutory minimum, but MAS guidelines recommend 5-7 years for financial documents. US ESIGN Act: retain per industry regulation (7 years SEC, 30 years FDA).

Audit trail in practice: what to capture, store, and present

Operational guidance for audit trail design and evidence production.

Essential audit events for evidentiary value

A defensible audit trail should capture at minimum: envelope creation (who, when, from what IP), document upload and hash, recipient identification and authentication method, viewing time and duration, signature application with geographic location, signature completion, and document delivery. eSign.AI captures all of these plus device fingerprint, user agent, and certificate chain details — providing the detailed evidence chain needed for cross-border dispute resolution.

Producing evidence for courts and regulators

When producing evidence, the format matters. Courts typically accept: (1) a PDF summary of the audit log (human-readable), (2) the signed PDF with embedded certificate and timestamp (PAdES), and (3) a cryptographic proof file. eSign.AI generates all three automatically. For cross-border disputes, an apostille or notarisation may be required — eSign.AI partners with QTSPs that provide notarised evidence exports for EU proceedings.

Retention periods by jurisdiction and document type

Audit trail retention should match or exceed the document retention period. Common requirements: employment contracts (5-10 years per most APAC labour laws), loan agreements (7 years per MAS/SFC guidelines), patient records (30 years per FDA for medical devices), government filings (permanent). eSign.AI provides configurable retention policies per workspace and document category, with tamper-evident storage.

Common questions

Not always explicitly, but it is very difficult to enforce an electronic signature without one. Most e-signature laws (eIDAS, ESIGN, ETA) require evidence of the signatory consent and intent — an audit trail is the primary evidence of both.

How eSign.AI applies this in practice

eSign.AI generates a comprehensive evidence package for every transaction: signed PDF with embedded signatures, human-readable audit trail, certificate chain, timestamp token, and identity verification record.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.