The real issue is verifying that the person has a CA at all. You don't want to scan a list for a person's name on every merge.
In JIRA, it's easier for the committer, because only contributors have the correct permissions to submit a patch at all. GitHub currently has no analogue.
My guess would be the sheer volume of commits would be unmanageable unless the process was somehow automated