Accordsign

India compliance

What an Audit Trail Must Contain to Hold Up in an Indian Court

An eSigned contract is only as strong as the evidence behind it. A plain-English guide to what a signature audit trail must record, how Indian evidence law treats electronic records, and the questions to ask your eSignature provider before a dispute — not after.

The Accordsign team 13 July 2026 6 min read
What an audit trail must contain to hold up in an Indian court — document created, sent, viewed, signed and completed, with identity verified, time stamped, IP logged and document hash

A note on what this is. This is general information for Indian businesses, not legal advice. The law is settled on the broad strokes below, but your specific contract, industry, or state may carry additional requirements. When the stakes are high, ask a lawyer.

Here’s an uncomfortable truth about electronic signatures: the signature itself is the easy part. The question that decides a dispute is not “was this signed?” but “can you prove who signed it, when, and that the document hasn’t changed since?”

That proof is the audit trail. Most businesses never look at theirs until the day they need it — which is the one day it’s too late to improve it. This post covers what a serious audit trail records, how Indian law treats it as evidence, and what to check before you trust a platform with contracts you may someday have to enforce.

Two pieces of law do the work here.

The IT Act, 2000 makes electronic signatures legally valid (Section 3A and the Second Schedule cover Aadhaar eSign specifically) and gives electronic records legal recognition. Signed electronically, your contract is as valid as ink — with a short list of Schedule I exceptions (wills, certain property conveyances, and a few others) that our legality guide covers in detail.

The evidence framework — Section 65B of the Evidence Act, carried forward in substance into the Bharatiya Sakshya Adhiniyam, 2023 — governs how electronic records are admitted in court. The practical requirement: an electronic record is typically produced with a certificate attesting to the computer system that produced it and the integrity of the process. What this means for you: the platform that holds your audit trail must be able to produce the record, and the supporting certification, in a form a court will accept. A signature without producible evidence is a claim; with it, it’s proof.

Validity and admissibility are different hurdles. The signature law clears the first. The audit trail clears the second.

What a court-ready audit trail actually records

Think of the audit trail as answering four questions a judge (or an opposing lawyer) will ask.

1. Who signed? Identity evidence, proportional to the signature type:

  • For Aadhaar eSign: the signer authenticated via Aadhaar OTP with a CCA-licensed provider, and the document carries a transaction-level digital signature certificate in the signer’s name. This is the strongest identity evidence in routine Indian commercial use — the authentication chain runs through government identity infrastructure.
  • For standard electronic signatures: the evidence is contextual — the email address the request went to, the device and IP that accessed it, the authentication step (email OTP, login) completed before signing. Weaker than Aadhaar, but for most routine agreements, sufficient — provided it’s recorded.

2. What did they sign? A cryptographic fingerprint (hash) of the document at the moment of signature. This is the tamper-evidence: change one character afterward and the recorded hash no longer matches the document. A trail that doesn’t bind the signature to the exact document contents is decoration.

3. When, in what sequence? Timestamps for the full lifecycle: sent, delivered, viewed, signed — for every party, in order. Sequence matters more than people expect: “the vendor signed after viewing the revised page 4” is exactly the kind of fact disputes turn on.

4. How was it executed? The procedural record: the signing link went to this email, was opened from this IP on this device, authentication was completed by this method, consent to sign electronically was captured. Boring until it’s decisive.

The completed-document package

When signing finishes, what you should hold is not just “a signed PDF” but a package: the final document with all signatures and certificates embedded, plus the audit trail — either embedded as a certificate page or retrievable as a companion record. Check that:

  • The PDF’s signatures validate in a standard reader (open the signature panel — it should show the certificate and confirm the document is unmodified since signing).
  • The audit trail is retrievable per document, on demand, without a support ticket and a week’s wait.
  • The trail survives you leaving the platform. If your provider relationship ends, your evidence must not end with it. Download and archive completed documents with their trails as a matter of routine — your contracts may outlive your subscription.

Questions to ask your provider before you need the answers

  1. Can I download the complete audit trail for any document, myself, today?
  2. Does the trail record viewing and delivery events, or only the signature moment?
  3. Is the document hash recorded at signing, and will the PDF’s signature visibly break if the file is altered?
  4. For Aadhaar eSign: which CCA-licensed ESP performs the authentication, and does each signer receive an individual transaction-level certificate?
  5. If I need a Section 65B-style certification to produce this record in court, can you support that?
  6. How long are trails retained, and what happens to them if I close my account?

A provider that answers these crisply has thought about the day you end up in a dispute. A provider that hasn’t is selling you the easy half of the product.

The habit that costs nothing now and everything later

Once a quarter, pick one completed contract at random. Download it. Open the signature panel. Pull the audit trail. Confirm the whole evidentiary package is intact and in your possession.

Five minutes. The alternative is discovering a gap in your evidence during a dispute — when the contract in question is the one you can least afford to have doubted.

An electronic signature is a legal instrument. The audit trail is what makes it an enforceable one. Choose, and archive, accordingly.

Share this article

About the author

The Accordsign team

We build Accordsign. We write about signing because we think about it a lot.

Try Accordsign free for 14 days.

Three documents on us, no card required.

Start free trial

Newsletter

Get our writing in your inbox.

Once or twice a month. Practical guidance on signing, Indian eSign law, and SMB compliance. No spam, no marketing fluff — unsubscribe in one click.

We use your email only to send the newsletter. See our Privacy Policy.