You have the signed PDF. The evidence is somewhere else
- Technology
- IT consultancy
- Systems integration
- Knutsford
The engagement letter went out on Tuesday, came back signed on Wednesday, and is now a PDF in a folder. If somebody disputed it in eighteen months, what would you put in front of them?
Most firms would produce that PDF. It is the wrong document, or at least the weaker half of the right one.
A signed file shows a name in a signature box and, if you are lucky, a date. What it does not show is any of the things an argument actually turns on: that the person who signed was the person you sent it to, that they were shown this version rather than an earlier one, and that nothing has changed since. All of that sits in a separate record the signing tool kept. Almost nobody has looked at theirs.
There are two records, and you have been filing the wrong one
The names vary by product. Certificate of completion, audit trail, history. What matters is that the provider holds two different things and hands over one of them by default.
The certificate is a summary the provider wrote. Usually a single page: document name, signer names, a few timestamps, a long identifier. It is designed to be stapled to the signed file, and it reads well.
The event log is the list of everything the system recorded. Sent to this address at this time. Opened from this network address. Viewed for this long. Consent to sign electronically accepted at this moment. Signed. Sealed with this hash, so a later edit would show.
The certificate is what you will be given. The log is what you would want.
A certificate of completion is a summary somebody else wrote about your evidence. It is not the evidence.
Go and look at one
- 01Open the most recent document you had signed electronically
- 02Find the certificate, audit trail or history view. It is usually one click from the completed document rather than inside the PDF
- 03Read it properly, once
- 04Write down what is absent: the address it went to, when it was opened, whether the document is sealed against later changes
Ten minutes, and it settles a question you have been assuming the answer to.
The common surprise is not that the record is thin. It is that there were two records all along, the one in your document store is the summary, and the detailed one lives in an account rather than anywhere you control.
The question with real consequences
Can you get the log out, and does it survive you leaving?
The completed PDFs are yours. They downloaded to your machine and they will still open in ten years. The audit trail usually is not in that position. It sits in the provider's system, attached to a subscription, and your access to it is your access to the account. Stop paying and the documents remain. The record of how they came to be signed may not.
Better to know that before changing provider than after. A firm that moves from one signing tool to another and keeps only the completed files has kept the half that proves least, and will not discover it until the day it needs the other half.
We built one, which is how we know which decisions nobody sees
The client portal our sister practice has its clients sign through is ours, part of the platform that runs the practice day to day.
Every element of a signing record is a decision somebody made, and the decisions become invisible the moment the feature works. What counts as an event worth recording. Whether a document that was opened and not signed leaves any trace at all. How long the log is kept after the document is archived, which is a storage cost and therefore a judgement about somebody else's future dispute. Whether an export includes the log or only the file.
Not one of those is a dishonest choice. Every one of them has a version that flatters whoever built the thing, and the version you have is the one nobody thought to ask about. That is the argument for reading your own tool's record rather than assuming a product with a signature box has considered this on your behalf.
This is not the legal question
Whether an electronic signature is valid, whether a particular document can be signed that way at all, whether a deed needs something more: those are questions for a solicitor. We are not one, and you should not take the answer from an article, this one included.
The part we can help with is narrower and gets neglected precisely because it is not the interesting question. Does the evidence exist. Is it in your possession. Could you produce it on a bad day with the account cancelled. A signature that is legally sound and evidentially naked is still a problem.
What is actually worth doing
Less than the length of this article implies.
For most of what a small firm signs, the completed file and the dated email thread that produced it is proportionate. Building a process around it would cost more than the exposure. Leave it alone.
The documents that earn the full treatment are the ones with money, a term or a liability in them. A contract with a notice period. Anything with a payment schedule. Agreement to a scope of work that might later be described as having been something else. For those, download the certificate at the time, and keep it with the document rather than in the tool.
That is the entire habit. Not a system, not a policy. Download the evidence while you still have an account.
It is the same discipline as restoring a backup before you need to. The thing you are relying on is fine right up until the day you ask it for something. And if you are moving between systems anyway, the question of what has to move belongs in the same conversation, because signing history is one of the things that quietly does not.
If you are choosing a signing tool, or leaving one, send us those two questions and we will tell you what the answers are worth.
We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.
If any of this sounds like your business, we will tell you plainly whether we can help.
