Think about what a handwritten signature actually is. A shape you learned to draw as a teenager, repeated so often it became automatic, and then treated for the rest of your life as proof of who you are.
It was never a good security mechanism. Signatures have been traced, practised and forged for as long as they have existed, and almost nobody who accepts one has any real ability to tell a genuine one from a careful copy. We relied on it because the alternative was worse, and because forgery took effort and nerve.
What has changed is the effort. A convincing imitation of your handwriting, your voice, or your face on a video call no longer takes a skilled forger and weeks of practice. That shift is worth sitting with, because it quietly changes what “signed” ought to mean.
The signature was never the security
Here is the thing that gets missed in most conversations about digital fraud.
The mark on the page has never been the safeguard. The safeguard was always the surrounding process: the fact that you turned up at the bank, that the solicitor looked at your passport, that the person watching you sign had some independent reason to believe you were you.
Strip that context away, and the signature is decoration. This is exactly what happened when everything moved online. Typing your name into a box produces a record that you clicked something. It produces very little evidence about who was sitting at the keyboard.
For most agreements, that is completely fine, and worrying about it is wasted energy. The problem arrives when the stakes rise, or when the person on the other end has never met you and has no way to check.
What actually got harder to trust
The uncomfortable development of recent years is that the checks people instinctively fall back on have weakened.
A photograph of an identity document proves less than it used to. A video call is no longer self-evidently proof that a real person is present. Voice, on its own, has stopped being a reliable signal. None of this means fraud is now easy or common, but it does mean the informal verification most of us relied on, looking at someone and forming a judgement, has lost some of its power.
The response has not been to abandon remote agreements. It has been to move the verification somewhere harder to fake.
Three tiers, and why the top one exists
Under eIDAS, the EU framework governing this area, electronic signatures come in three levels.
A simple electronic signature is the typed name or drawn squiggle. Valid and admissible, but if someone denies signing it, proving otherwise is your problem.
An advanced electronic signature adds real cryptography. It is uniquely linked to the signer, created using data under their sole control, and bound to the document so tampering becomes visible.
A qualified electronic signature, or QES, adds two more conditions: a qualified certificate from a qualified trust service provider, and a qualified signature creation device. Meet those, and Article 25(2) of eIDAS treats the signature as legally equivalent to a handwritten one across every EU member state, without you having to prove anything further.
The reason the top tier exists is not that its cryptography is dramatically better than the tier below. It is that a QES signature cannot be issued to someone whose identity has not been established to a defined standard first.
The check that actually does the work
Before any qualified certificate is issued, the provider has to verify who the applicant is. Properly. Not by sending a confirmation email.
In practice, remote verification of this kind means several things happening at once. Reading the chip embedded in a biometric passport or ID card, which contains cryptographically signed data that is considerably harder to fabricate than a photograph of the same document. Matching a live capture of the person’s face against that verified document image. Running liveness checks to establish that a genuine person is present rather than a still image, a replayed recording or a synthetic video. Examining the document itself for signs of tampering.
Because this mirrors what banks do when opening an account, the shorthand KYC qualified electronic signature has entered common use. Both processes exist to answer one question: is this specific human who they claim to be, established remotely, to a standard that will still stand up years later.
That is where the trust in a qualified signature actually comes from. Not the certificate. Not the timestamp. The identity check underneath, which is why organisations building signing workflows rely on dedicated QES signature providers rather than assembling verification themselves.
How to tell the serious options apart
If you are choosing a signing tool for a business, or evaluating QES software for the first time, a few questions separate the substantial offerings from the rest.
Is the qualified status real and checkable? The EU publishes a Trusted List of qualified trust service providers. Anyone can open it and confirm a claim in about a minute. Some qualified electronic signature providers hold the status directly, others deliver it through a partner. Both are legitimate, but you should know which you are buying.
How is identity actually established? Ask specifically. Document photo upload alone is a weaker method than chip reading plus liveness detection, and the difference matters most in exactly the situations where you were counting on the signature.
Does the verification method work where your signers are? Accepted approaches vary between member states. An implementation that works cleanly in one country can stall in another, and this is where a lot of rollouts quietly fail.
What happens to a signer who has no biometric passport? Every system needs a fallback route. Ask what it is before you find out during a live transaction.
Is there long-term validation? Certificates expire. If you may need to rely on a signature in a decade, the provider needs to have planned for timestamping and archival validation from the beginning.
What is the completion rate like? A legally impeccable process that half your signers abandon is not actually protecting anything. Friction is a real constraint, not a soft one.
If the identity layer is the part you are least sure about, it is worth understanding how identity verification works in its own right before comparing signing tools, since everything above it inherits whatever that layer gets right or wrong.
What this means in practice
Nothing here suggests you should be anxious about clicking a signature box. The overwhelming majority of agreements do not warrant a second thought, and treating every contract as a fraud risk is its own kind of mistake.
What is worth carrying forward is a clearer sense of what a signature does and does not tell you. On its own, it records that someone clicked. It says nothing about who. Whatever confidence you place in it comes from the verification sitting behind it, and that verification is either present or it is not.
When something matters, the useful question is no longer whether the document was signed. It is what anyone actually established about the person who signed it.



