What Exactly Is an Audit Trail for Electronic Signatures?

An audit trail is evidence, not a legal requirement, and it only helps if you keep it and someone can explain how the signing worked.

Ayush Garg
Ayush Garg, co-founder of SignWith
Updated Verified October 202618 min read
Short answer

An audit trail for electronic signatures is the record that shows who signed a document, when and how: each signer's email, timestamps for when it was sent, opened and signed, IP addresses, the browser and device, any identity check, and a fingerprint (hash) showing the file has not changed since. Vendors often call it a Certificate of Completion.

Header image for What Exactly Is an Audit Trail for Electronic Signatures?
On this page

A California employer once held a signed arbitration agreement and still lost, because nobody could explain how the employee's e-signature got onto it (Ruiz v. Moss Bros.).

An e-signature audit trail is the record that does that explaining: who was sent the document, when they opened and signed it, from which IP address and browser, and a hash that shows the file has not changed since.

This page walks through a real two-page certificate line by line, what the ESIGN Act and UETA actually say, and five court cases where the record decided the outcome. Legal facts were verified October 2026 against the primary sources linked in each section.

What does an e-signature audit trail record?

An e-signature audit trail records who the signer was, what happened and when, where it happened from, what the signer entered, and whether the file has changed since. Most vendors print it as a PDF next to the signed document.

The table uses the fields on SignWith's Certificate of Completion, with the placeholder values from the example in our help center article on the certificate. No real person's email or IP address appears on this page.

Field on the certificateExample value (placeholder)What it shows in a dispute
Document name and pagesFreelance-Services-Agreement.pdf, 1 pageWhich file was signed
CompletedSeptember 27, 2026 16:45 CESTWhen the last party finished, with the time zone
Participant[email protected]Which inbox the signing link was sent to
Email OTP verificationVerifiedThe signer typed a one-time code sent to that inbox (shown only when the sender turned email verification on)
IP address203.0.113.24The network the signer used, not a street address
BrowserChrome 151 on LinuxThe kind of device and browser used
Completed fieldsA drawn signature, initials "AC", a date, a text field, a checkboxWhat the signer actually entered
Event historyEmail sent, Form viewed, Submission started, Submission completed, each with a time and IPThe order in which things happened
Document integrityOriginal and result SHA256 values in base64url, with a "Generated at" timeWhether the file you hold is the file that was signed
Page 1 of an example Certificate of Completion showing the document name, completion time, the placeholder participant alex@example.com with IP 203.0.113.24 and Chrome 151 on Linux, and the completed signature, initials, date, text, checkbox and number fields
Figure 1: Page 1 of an example SignWith certificate from a test signing on 27 September 2026. Placeholder signer and documentation IP address.

Page 2 holds the event history and the two document fingerprints. Each event has a time, a party label such as "Client" and an IP address; the "Email sent" line has no IP because the server sends that email, not the signer.

Page 2 of an example Certificate of Completion with an event history of Email sent, Email link clicked, Form viewed, Submission started and Submission completed, and a Document integrity section with original and result SHA256 values
Figure 2: Page 2 of the same example certificate: event history and document integrity. Placeholder data.

What changes when the signer verifies their email

When the sender switches on email verification for a send, each participant gets the line "Email OTP verification: Verified", and the event history gains two events: "Verification email sent" and "Email verified with one-time code". The table below is the event history from a two-party test signing on 27 September 2026, with the IP addresses replaced by documentation placeholders.

Time (UTC, 27 Sep 2026)EventPartyIP address (placeholder)
16:23Email sentFirst PartyNot recorded
16:24Verification email sentFirst Party203.0.113.10
16:24Email verified with one-time codeFirst Party203.0.113.10
16:24Form viewedFirst Party203.0.113.10
16:24Submission startedFirst Party203.0.113.10
16:24Submission completedFirst Party203.0.113.10
16:24Email sentSecond PartyNot recorded
16:25Verification email sentSecond Party198.51.100.20
16:25Email verified with one-time codeSecond Party198.51.100.20
16:25Form viewedSecond Party198.51.100.20
16:25Submission startedSecond Party198.51.100.20
16:25Submission completedSecond Party198.51.100.20

In the certificate from the signing without email verification (Figure 2), "Email link clicked" sits where the two verification events are here.

There is no separate consent line in the history. The signer agrees by clicking the AGREE AND SIGN DOCUMENT button at the end of the document, and that click is what the history records as "Submission completed".

The dark blue AGREE AND SIGN DOCUMENT button a signer clicks to agree and complete signing
Figure 3: The button the signer clicks to agree and sign. The click completes the submission.
Audit trail

What the certificate records at each step of a signing

  1. 1
    Email sent
    • Time
    • Party
    • No IP: the server sends it
  2. 2
    Verification email sent (email verification on)
    • Time
    • IP address
  3. 3
    Email verified with one-time code
    • Time
    • IP address
  4. 4
    Form viewed, Submission started
    • Time
    • IP address
  5. 5
    Submission completed (the AGREE AND SIGN DOCUMENT click)
    • Time
    • IP address
    • Browser and OS
    • Field values and signature image
  6. 6
    Certificate generated
    • Original SHA256
    • Result SHA256
    • Generated at time
Certificate of CompletionA document with a seal, representing the Certificate of Completion
Certificate of Completion
Timestamps, IP addresses, device and browser details and email events, sealed with a SHA-256 hash.
Event names as printed on two real test certificates from 27 September 2026. Without email verification, Email link clicked replaces the two verification events.Source: Certificate of Completion help article. Checked Oct 2026

Does US law require an audit trail for electronic signatures?

No. Neither the ESIGN Act nor UETA uses the words "audit trail" (both texts searched, verified October 2026). The law says a signature cannot be refused just for being electronic, and that you may show who signed "in any manner". An audit trail is the usual way to show it.

What the texts actually say:

  • ESIGN Act, 15 U.S.C. 7001(a)(1): a signature, contract or other record "may not be denied legal effect, validity, or enforceability solely because it is in electronic form" (Cornell LII).
  • What counts as an e-signature, 7006(5): "an electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record" (govinfo).
  • UETA section 9(a): a signature "is attributable to a person if it was the act of the person. The act of the person may be shown in any manner, including a showing of the efficacy of any security procedure applied" (UETA official text). States adopt it under their own section numbers.
  • Keeping the record, ESIGN 7001(d) and (e): a retained record must accurately reflect the contract and remain accessible "in a form that is capable of being accurately reproduced for later reference". Where a law requires a contract in writing, legal effect may be denied if the record cannot be retained and reproduced by all parties.
  • Consumer consent, 7001(c): only when a law requires information to be given to a consumer in writing does ESIGN require the consumer's consent to receive it electronically. That is why some vendors log a separate consent event.

Several vendor pages say ESIGN and UETA "require" an audit trail. They do not. An audit trail is also not the same thing as a certificate-based digital signature; our guide to digital vs electronic signatures explains the difference.

How do courts use an audit trail?

Courts treat the audit trail as evidence that a specific person signed, but only after someone explains how the record was made. When a signer denies signing, the side relying on the contract carries the burden of proof, which our answer on whether electronic signatures hold up in court explains step by step.

Under Federal Rule of Evidence 901, you "must produce evidence sufficient to support a finding that the item is what the proponent claims it is", for example "evidence describing a process or system and showing that it produces an accurate result" (verified October 2026).

Court cases

Five cases where the signing record decided the outcome

  1. Dec 23, 2014Ruiz v. Moss Bros. Auto Group: employer lostNo one explained how the signature and its date and time came to be on the agreement.Cal. Court of Appeal opinion
  2. Feb 9, 2016Moton v. Maplebear (Instacart): company wonThe court relied on a time-stamped audit trail using IP addresses, as summarized by Fenwick & West.Fenwick & West summary
  3. Apr 3, 2018IO Moonwalkers v. Banc of America Merchant Services: company boundSigning records showed the contracts were viewed and signed from the company email account minutes apart.N.C. Court of Appeals opinion
  4. Nov 19, 2019Fabian v. Renovate America: company lostA "DocuSigned by" signature alone was not enough without an explanation of the process.Cal. Court of Appeal opinion
  5. May 28, 2021Aerotek v. Boyd: employer wonA time-stamped record tied to each candidate's unique identifier outweighed simple denials.Supreme Court of Texas opinion
Checked Oct 2026
CaseCourt and dateOutcomeWhat the record did or did not show
Ruiz v. Moss Bros. Auto GroupCal. Court of Appeal, December 23, 2014Employer lost the motion to compel arbitrationThe declarant "did not explain how Ruiz's printed electronic signature, or the date and time printed next to the signature, came to be placed on the 2011 agreement"
Moton v. Maplebear (Instacart)S.D.N.Y., February 9, 2016Company wonThe court relied on a time-stamped audit trail tracking, with IP addresses, when each signer received, viewed and signed (Fenwick & West summary)
IO Moonwalkers v. Banc of America Merchant ServicesN.C. Court of Appeals, April 3, 2018Moonwalkers bound by the contractsRecords from DocuSign showed "someone with access to the Moonwalkers email account viewed the emails and corresponding contracts sent by DocuSign, and then electronically signed the contracts several minutes later"
Fabian v. Renovate AmericaCal. Court of Appeal, November 19, 2019Company lost the motion to compel arbitrationThe declarant made no "reference to DocuSign or the process used to obtain and verify Fabian's 'docusigned' electronic initials and signature"
Aerotek v. BoydSupreme Court of Texas, May 28, 2021Employer won, arbitration compelledThe hiring system stored "a new electronic record that includes the candidate's unique identifier, the type of document, and a timestamp showing the date and time the document was signed"; "The Employees' simple denials are no evidence otherwise."

Case texts from the linked opinions, verified October 2026. Aerotek involved an in-house hiring system, not an e-signature vendor, but the point is the same: a time-stamped record tied to a unique login.

How do DocuSign, Dropbox Sign and Adobe audit trails compare?

DocuSign and Dropbox Sign both record events with timestamps, IP addresses and a way to check the document, but they name and package the record differently. The table shows only what each vendor's own pages say (verified October 2026).

ToolWhat the record is calledWhat the vendor says it recordsThe catch
DocuSignCertificate of CompletionEnvelope ID, number of document pages, number of signatures and initials, signer details, IP address, signature image and key event timestamps, per a DocuSign employee on the DocuSign CommunityNone found in the documentation read
Dropbox SignAudit trailTimestamped events "from the moment the document is submitted for signature to when it is completely signed and secured, such as IP address", plus "a hash of the PDF document" (Dropbox Help)"Self signed documents, documents signed using the 'Just Me' signing option, don't include an audit trail"
Adobe Acrobat SignAudit trailAdobe defines it as "a digital log that archives when and where a document was signed and by whom" (Adobe)Adobe's help pages on its audit report could not be opened for this page, so check in your account whether signer IP addresses are captured

Whatever the tool, open one completed certificate before you rely on it and check four lines: the signer's email, the event times, the IP addresses and the document fingerprint.

What can an audit trail not prove?

An audit trail ties a signature to an email inbox, a device and a network address. It does not prove who was sitting at the keyboard. Its limits:

  • Inbox access is not identity. A one-time code proves someone could read that inbox. In IO Moonwalkers the record showed "someone with access to the Moonwalkers email account", which was enough there, but a shared inbox weakens it.
  • An IP address is approximate. It shows the network used, which can be an office, a VPN or a mobile carrier, not a street address.
  • In-person signing relies on the sender. When a signer signs on the sender's device, the certificate identifies them by the email the sender typed.
  • Some documents have no trail. Dropbox Sign's self-signed "Just Me" documents carry none.
  • A record nobody explains can fail. Ruiz and Fabian lost with signed documents in hand.

What keeps an audit trail useful in a dispute, in four steps:

  1. Download the signed document and the certificate when signing finishes.
  2. Store both with the contract, in the same folder.
  3. Note how signing worked: email verification on or off, remote or in person.
  4. Be ready to describe the process, which is the kind of evidence FRE 901(b)(9) describes.
Before any dispute

Keep an audit trail you can actually use

  1. Step 1Download both PDFsThe signed document and the certificate
  2. Step 2Store them togetherIn the same folder as the contract
  3. Step 3Note how it was signedEmail verification on or off, remote or in person
  4. Step 4Be ready to explain itDescribe the process step by step (FRE 901(b)(9))
Source: Federal Rule of Evidence 901. Checked Oct 2026

Regulated fields add their own record-keeping rules on top; our e-signature guide for financial services covers the ones that apply there.

What does SignWith's audit trail record?

Every completed document comes with a Certificate of Completion that records timestamps, IP addresses, device and browser details and email events, sealed with a SHA-256 hash.

On SignWith the certificate opens from the AUDIT LOG button on a completed document as a two-page PDF, and every party, including the sender, gets the signed document and the certificate by email when signing finishes. The help center walkthrough shows where to find it.

Email verification is a switch the sender turns on for each send, and the code check then shows on the certificate as described above. See how email verification works. Signed documents stay in your account; keep your own copy of both PDFs with the contract anyway.

This 51-second video from our channel walks through the certificate and where to find it.

Ayush Garg (SignWith) · 51 sWatch on YouTube

SignWith fits people and small teams who want a simple way to get a document signed, with no subscription and no hidden fees: you buy credits, and a credit is used only when a document is signed. Pick an alternative when:

  • Your buyer runs a vendor security review or needs identity checks beyond an email code. An enterprise vendor such as DocuSign sells ID verification; confirm what it covers with their sales team.
  • You need templates, bulk send or team accounts today. Those are coming soon on SignWith, not live.
SignWith's email OTP verification, consent record, signing record and audit trail are designed to support the requirements of the ESIGN Act and UETA.
FAQ

Frequently asked questions

Is an audit trail the same as a Certificate of Completion?

Mostly, yes. Certificate of Completion is the name DocuSign and SignWith give the audit record, Dropbox Sign calls it an audit trail, and Adobe uses audit trail in its guides. All of them record who was sent the document, what happened and when.

Is an electronic signature valid without an audit trail?

Yes, the law does not require one by name. The ESIGN Act says a signature cannot be denied effect just for being electronic, and UETA says who signed 'may be shown in any manner' (verified October 2026). Without an audit trail you need other evidence that the person signed, and that is harder to produce.

Can an e-signature audit trail show that a document was changed?

It can show whether the file you hold matches the one recorded at signing. Certificates print a hash, a fingerprint of the file; if even one character of the file changed, the fingerprint would not match. That is why you should keep the certificate with the exact signed PDF.

Does an audit trail record the signer's consent?

Not always as its own line. On the certificate shown above, the signer agrees by clicking AGREE AND SIGN DOCUMENT, and the history records that click as 'Submission completed'. A separate consent event matters mainly for consumer disclosures, where ESIGN 7001(c) requires consent to receive them electronically.

How long should I keep an e-signature audit trail?

Keep it as long as you keep the contract. ESIGN treats an electronic record as retained only if it stays accessible and can be accurately reproduced for the period the law requires for that record. Download the certificate when signing finishes and store it with the signed document, see getting the signed document.

Does an IP address in the audit trail prove where someone signed?

No. An IP address identifies the network the signer used, such as an office, a mobile carrier or a VPN. It supports the rest of the record but is not a street address.

Primary sources

Ayush Garg

Written by

Ayush Garg

Co-founder, SignWith

Ayush is the co-founder of SignWith, the pay-per-document e-signature tool for businesses that just want documents signed without the intensity of a full platform. He worked as a freelancer, then a consultant, then a fractional head of growth, signing contracts with his clients. He has 6+ years of experience running SaaS and service businesses and writes about e-signatures, document workflows, and lean software.

Sign documents without another subscription.

Upload, sign and send in minutes. When you need more than the free documents, buy credits once, and a credit is used only when a document is signed.

3
Free documents every month
$0.58
Per document on Business
1,000+
Businesses signing