Some lawyer friends I have (here in Australia) have told me that electronic signatures (of the kind like DocuSign and Adobe Sign that have you “adopt” a digital signature and click a “Sign” button) should only be used in situations where the other party’s actions soon after signing will confirm their intention to be bound by the document.
For example, if there is a sales contract and the buyer proceeds to pay the money, then that payment shows intent to follow the purchase agreement.
Or, if someone sends an email after signing saying “All done. I look forward to working with you.” — that has the same effect.
To use it for something where the other party will be doing nothing for a long time (like a guarantor on a loan or lease) or acting unpredictably (like a house tenant) would be very risky. The other party could easily use the defence of “I didn’t click the button… I didn’t even know about the contract.” even if they did know and did click the button.
So why use a digital signing system? Efficiency!
It’s quicker and easier. You can get dozens done with the same time & effort it takes to arrange a single wet signature. It’s multilingual. It’s automated. It’s fancy!
Having any signature, whether wet or digital, shows that your side is following proper process. The signing of a document is an important moment, and the specific date & time often has real commercial, accounting or legal ramifications. Even if you could easily show to a court that the other party has “agreed” without signing (e.g. via email, text, phone, etc) and is acting in accordance, it’s better to just avoid the court in the first place.
To summarise:
Wet signatures are best. The other party would be crazy to challenge them.
Digital signatures are better than just an email saying “I agree.” The other party would have to be brave to challenge one.
An email saying “I agree” is better than a handshake.
(Again, I’m not a lawyer! I would love to hear a lawyer’s opinion. Though, please do so anonymously — I don’t want anyone getting in trouble!)
People can always claim they didn't sign something, ink or digital. The reason that DocuSign is a multi billion $$ company is that they have a bunch of audit trail features which make it pretty darn clear the person did in fact sign it.
There's some truth to what they're saying, but is it any different than a handwritten signature? "I didn't sign that. That's not my signature."
In both cases, from a legal perspective, the issue is the same: I've got to prove to a judge or jury, by a preponderance of the evidence, you did sign or click. I can either bring in paid whore handwritting analyst to testify that in their professional opinion, it is your signature (and hope he doesn't get excluded for being a quack), or I can subpoena docusign to produce whatever evidence they have that the person actually clicked. In the end, the judge or jury will either believe them or not.
If this is a billion dollar life or death deal, my free legal advice is, in either situation, get as much verification as you can at the time of the signing. Both will be easier to prove if you have things like a copy of their driver's license, or even better, video of the person clicking/signing.
In the EU, often a personal key on a tamperproof personal device is used. In many EU countries these are readily available to citizens and the resulting signatures carry the signer's name, a unique personal ID code, and have the same legal effect as a handwritten signature. This is called a "qualified electronic signature". Qualified trust service providers verify the identities of people and provision the hardware to them.
The EU system is great in that when creating or verifying signatures, you don't necessarily need a service provider at all — the software is free. Of course a good system can help managing signature invitations, the documents, archival, reminders, etc. But it's not needed for security; in fact the most secure way would be to not give your documents to a third party at all.
Alternatively, the e-signing providers private key can be used to create a seal on behalf of the person signing. It's then up to the security of the e-signing provider, how they validate the signer's identity, etc, to decide how trustworthy such a signature is.
One subtle problem in this setup is the trust list. Abode effectively has their own trust bit sovereign rights, while EU has it's own trust list (which doesn't always match with a list of qualified providers as per EU-conforming states). Then US federal government has it's own trust list.
So it's the usual PKI problem.
In the end you can't modify (actually you can, because PDF, but it's a different problem) the data without breaking crypto signature, but identity that is proven by this operation is not government-endorsed. Everybody is mostly fine with a status quo.
For us, the biggest question that comes up for our customers is the variety of signature specimen we intend to work with and how it will be applied to the final documents (the ones the bank would take to court):
1. No signature captured at all.
2. Signature captured using adoption of a machine-generated specimen.
3. Signature captured using touch, mouse or stylus.
4. Signature captured using a paper specimen & CCD.
5. Actual wet signature on paper with in-person presence required.
Option 1 seems to be the most popular with the latest wave of online banking products. Option 3 is the happy path for our in-branch product, but we have some cases fall into the Option 5 bucket as well - typically only when all signers cannot be present simultaneously for non-consumer accounts.Depending on the liability associated with the customer/account combo, the required quality of the signature specimen could vary. Some of our customers will allow for basic consumer accounts to be opened with minimal backing documentation because the limits on those products are relatively low (and relative volume is VERY high). For business customers & accounts, we are in a completely different universe. You take that stuff a lot slower. Businesses are typically much more understanding when you say you can't give them an active account right now.
The most important foundation to all of this is Know Your Customer (KYC). That entire process is designed to ensure that whoever you are pulling into the core system is exactly who they say they are, so that all subsequent business with that individual can be correctly attributed to the appropriate natural person. Once you have a 'hardened' customer information file, you can start to do scary business because you are now reasonably-confident you could win in court.