An audit trail proves a document was signed by the right person, at the right time, without modification. Learn what UK e-signature audit trails should contain, their legal importance, and how VedaSign's audit trail works.
UK Compliance Guide

Audit Trails

Electronic Signature Audit Trails — What They Are and Why They Matter

An audit trail is the chain of evidence that proves who signed a document, when, and that it hasn't been altered since.

What Is an Electronic Signature Audit Trail?

An electronic signature audit trail is a detailed log of every action taken during the document signing process. It records evidence of the signer's identity, the method used to sign, the exact time and date of signing, and the document's integrity — providing proof that the document has not been altered after it was signed. In legal disputes or regulatory investigations, the audit trail is the primary evidence that a signature was made by the claimed person, with their knowledge and consent, and that the document has not been tampered with.

What a UK-Standard Audit Trail Should Contain

For a UK electronic signature to be admissible and legally defensible, its audit trail should capture the following information at minimum:

  • Signer's full name and email address
  • IP address of the device used to sign
  • Date and time of signing (with timezone)
  • Browser and device information (user agent)
  • Document hash before and after signing — to prove no modification occurred
  • Unique document ID and transaction reference
  • Method of signing (drawn, typed, clicked)
  • Email delivery timestamp — confirming the signer received the document
  • View timestamp — confirming the signer opened and viewed the document before signing

Audit Trails and UK Legal Proceedings

In English law, electronic evidence is admissible under the Civil Evidence Act 1995. For an electronic signature to be given full weight as evidence, the party relying on it must be able to demonstrate that the signature was made by the claimed signatory and that the document has not been altered since signing. The Law Commission's 2019 report on electronic execution of documents confirmed that courts will look at the totality of evidence — including audit trails — when assessing the validity and weight of an electronic signature.

Tamper-Evidence and Document Integrity

VedaSign uses cryptographic hashing to create a unique fingerprint of every document at the time of signing. If the document is modified after signing — even a single character change — the hash will no longer match, immediately revealing the tampering. The signed PDF contains an embedded certificate of completion including the audit log, meaning the evidence travels with the document.

Audit Trail Retention and GDPR

Audit trail records contain personal data and must be retained in accordance with UK GDPR's storage limitation principle. Best practice is to align audit trail retention with the retention period of the underlying document — typically 6 years for commercial contracts under the Limitation Act 1980.

  • Retain audit trails for the same period as the underlying document
  • Include audit trail retention in your data retention schedule
  • Ensure your DPA with your e-signature provider covers audit trail data
  • Export and archive completed documents with embedded audit trails

£15/month

UK-hosted · GDPR compliant · Unlimited users

No per-user fees. No document caps. No hidden charges.

Start Your 14-Day Free Trial

Frequently Asked Questions

What is included in VedaSign's audit trail?

VedaSign's audit trail includes the signer's name, email address, IP address, timestamp, browser information, document hash, delivery confirmation, and view confirmation — all embedded in the completed signed PDF.

Is an electronic signature without an audit trail legally valid?

An electronic signature without an audit trail may still be technically valid, but it is much harder to defend in a dispute. An audit trail provides the evidential chain needed to prove who signed, when, and that the document was not altered afterwards.

Can a VedaSign audit trail be used as evidence in court?

Yes. VedaSign's audit trail is designed to meet the evidential requirements for electronic documents under the Civil Evidence Act 1995. The audit log is embedded in the signed PDF, making it portable and independently verifiable.

How long should I keep electronic signature audit trails?

For most commercial contracts, 6 years from the date the contract ends — aligned with the Limitation Act 1980 limitation period. Regulated industries may have longer requirements set by their regulator.

Does VedaSign use tamper-evident technology?

Yes. VedaSign applies cryptographic hashing to every signed document. Any post-signature modification will break the hash, making tampering immediately detectable.

We use essential cookies to keep VedaSign running securely, and analytics cookies to help us improve the site. You can choose which to accept. Cookie Policy