Summary. Electronic signatures have been legally valid for twenty-five years, so validity is not the compliance question. Attribution is: proving that a particular person made the mark, years later, after the platform was replaced. This checklist builds a program around that reality. It tiers documents by risk and assigns a signing method to each, sets the credential and authentication controls that make attribution provable, specifies what the audit trail must capture and where it is retained, handles the consumer consent process most companies implement incorrectly, and enumerates the categories that must still be on paper.


What this checklist is for. Designing, deploying, or auditing an electronic signature program. For the legal framework, see Electronic Signatures and Records Under ESIGN and UETA.


Phase 1 — Classify documents by risk

  • Low risk — internal approvals, routine acknowledgments, low-value orders. Click-to-accept with a system log is adequate.
  • Medium risk — commercial contracts, NDAs, employment documents, vendor terms. A commercial platform with unique authentication, an audit trail, tamper evidence, and a completion certificate.
  • High risk — significant transactions, arbitration agreements, guaranties, releases, and anything likely to be litigated. Add identity verification and multi-factor authentication, and deliver an executed copy with confirmation.
  • Excluded or high-formality — see Phase 4. Paper, or a compliant remote notarization or electronic wills process where the state permits it.
  • Publish the classification map and enforce it technically so an excluded document cannot be routed through the workflow.

Phase 2 — Attribution controls

  • Issue unique credentials to each signer, with a forced password change on first use.
  • Prohibit shared logins. An administrator signing "to help" destroys attribution for every document signed that way.
  • Implement multi-factor authentication, or at minimum a second identifying factor such as a one-time code to a personal email or mobile number on file.
  • For high-risk documents, add identity verification — government identification capture or knowledge-based authentication.
  • Make the signing act unmistakably a signing act: a discrete button labeled "Sign," presented after the document, with an on-screen statement that clicking constitutes a signature creating a binding agreement.
  • Present the complete document before the signature block, not behind a link.
  • Include a confirmation screen displaying what the signer entered, with an opportunity to correct — which eliminates the avoidance right for errors in automated transactions under UETA § 10.
  • Deliver an executed copy to the signer and record the delivery.

Phase 3 — The audit trail

  • Capture, for every signature: the signer's identifier, timestamps for viewed, opened, signed, and completed, the IP address, the device and browser fingerprint, the sequence of documents presented, and a hash of the signed document.
  • Apply a tamper-evident seal at completion.
  • Generate and retain a completion certificate.
  • Export the audit trail and certificate with the executed document, and store both outside the vendor's platform. A signed PDF without its audit trail is much weaker evidence.
  • Retain the version of the document that was displayed, not merely the current template, so you can show what this signer saw.
  • Confirm the vendor will provide a Rule 902(13) certification on request, and identify a qualified certifying witness in advance.

Phase 4 — Documents that may not be signed electronically

  • Wills, codicils, and testamentary trusts — unless the state has enacted an electronic wills statute, and then only under its procedures.
  • Adoption, divorce, and other family law matters.
  • Negotiable instruments and documents of title under UCC Articles 3, 4, 5, and 7 — note that Articles 2 and 2A are covered, and that Article 9 uses "authenticate," which includes electronic signing.
  • Notices of default, acceleration, repossession, foreclosure, eviction, or the right to cure on a primary residence.
  • Notices of cancellation or termination of utility services.
  • Notices of cancellation or termination of health or life insurance benefits.
  • Product recall notices and notices of material failure affecting health or safety.
  • Documents accompanying the transport of hazardous materials.
  • Court filings and orders, governed by court rules — and note that a declaration under 28 U.S.C. § 1746 requires the declarant's own signature, not counsel's filing signature.
  • Maintain this list in the document management system, enforced by configuration.

Phase 5 — Consumer transactions

Where a statute requires that information be provided to a consumer in writing, ESIGN § 7001(c) imposes a specific process.

  • Disclose the right to receive the record on paper and the right to withdraw consent, with conditions, consequences, and fees.
  • State whether consent applies to this transaction only or to categories of records in the relationship.
  • State the procedures to withdraw consent and to update contact information.
  • State how to obtain a paper copy and any fee.
  • Provide the hardware and software requirements statement.
  • Obtain consent in a manner that reasonably demonstrates the consumer can access the format that will be used — present a sample in that format and require confirmation, not merely a checkbox on a web page.
  • Obtain renewed consent if requirements change in a way that creates a material risk the consumer cannot access records.
  • Retain evidence of the disclosures given and the consent obtained, by version and date.

Phase 6 — Notarization and witnessing

  • Determine whether the document requires notarization or witnesses under the governing law.
  • Where notarization is required, confirm whether the state permits remote online notarization, and confirm the notary is commissioned and endorsed for it.
  • Confirm the RON process includes identity proofing and credential analysis, an audio-video recording retained for the statutory period, tamper-evident technology, and an electronic journal.
  • For real estate, confirm the title insurer's requirements and the county recorder's acceptance of electronic recording — both are frequently more restrictive than the statute.
  • Where witnesses are required, confirm whether remote witnessing is permitted in that state.
  • Confirm out-of-state recognition if the notary and the signer are in different jurisdictions.

Phase 7 — Retention and evidence

  • Retain records in a form that accurately reflects the information and remains accessible and capable of accurate reproduction.
  • Use an archival format such as PDF/A rather than a proprietary format tied to a discontinued application.
  • Maintain integrity controls demonstrating the record has not changed.
  • Index records so they can be retrieved by signer, date, and document type on demand.
  • Set retention to the limitations period plus a margin, and longer where a regulation requires it.
  • Implement legal hold capability that suspends destruction.
  • Plan vendor transitions: migrate historical records with their metadata and audit trails, or export them in a self-contained form, before terminating a platform. This is the most common evidentiary failure in the field.
  • For regulated contexts, confirm compliance with sector rules such as 21 C.F.R. Part 11.

Phase 8 — Signature authority

  • Map who may bind the company for which document types and at what dollar thresholds, in writing.
  • Configure the platform so only authorized senders can initiate requests and only designated signers appear for each document type.
  • Require counter-signature above defined thresholds.
  • Give notice of authority limits to significant counterparties in the master agreement, converting an apparent-authority problem into an actual-notice problem.
  • Audit quarterly: pull a report of everything signed, by whom, and confirm each was within authority.
  • Train the people who send documents, who are usually not lawyers.

Common mistakes

  1. Shared credentials, which destroy attribution.
  2. The audit trail not retained outside the vendor's platform.
  3. A vendor migration that kept the PDFs and lost the provenance.
  4. Consumer consent by checkbox, with no reasonable demonstration of access to the delivery format.
  5. An electronically signed will or trust amendment in a state that does not permit it.
  6. A promissory note signed electronically and later sold, discovered not to be a transferable record.
  7. Terms behind a link rather than displayed, weakening both assent and the logical-association element.
  8. No copy delivered to the signer.
  9. A signature applied by someone with platform access but no authority.
  10. A "wet signature required" clause in the parties' own agreement, ignored by operations.

Primary authority

  • ESIGN, 15 U.S.C. §§ 7001–7031, particularly § 7001(a), (c), (d), and (g); § 7003 (exclusions); § 7021 (transferable records); § 7004 (agency requirements).
  • UETA §§ 2, 5, 7, 9 (attribution), 10 (errors), 11 (notarization), 12 (retention), and 16 (transferable records), as adopted.
  • Evidence: Fed. R. Evid. 901(b)(9) and 902(13) and (14).
  • Cases: Ruiz v. Moss Bros. Auto Group, Inc., 232 Cal. App. 4th 836 (2014).
  • E-SIGN: 15 U.S.C. § 7001(a) (validity), § 7001(b) (no requirement to use), § 7001(c) (consumer consent and the reasonable demonstration requirement), § 7001(d) (record retention and accuracy), § 7001(e) (accurate reproduction), § 7002 (state law preemption), § 7003 (exclusions: wills and trusts, family law, UCC other than Articles 2 and 2A, court documents, and notices of termination, foreclosure, and health insurance cancellation), § 7006 (definitions).
  • UETA (1999): § 5 (agreement to conduct business electronically), § 7 (legal effect), § 8 (provision of information), § 9 (attribution and effect), § 10 (change or error), § 11 (notarization), § 12 (retention), § 14 (automated transactions), § 15 (time of sending and receipt), § 16 (transferable records). New York instead enacts N.Y. State Tech. Law §§ 301–309.
  • Negotiable and transferable records: UCC § 9-105 (control of electronic chattel paper), § 3-104 (negotiable instruments), § 7-106 (control of electronic documents of title).
  • Regulated records: 21 C.F.R. Part 11, including § 11.10 (controls for closed systems), § 11.50 (signature manifestations), § 11.100 (general requirements); 45 C.F.R. § 164.312(e) (HIPAA transmission security).
  • Evidence: Fed. R. Evid. 901(b)(9), § 902(13), § 902(14), § 803(6), § 1001(d) and § 1003 (duplicates).

Related

This checklist is educational and not legal advice. State adoptions of UETA vary, remote notarization and electronic wills statutes differ, and sector-specific regulations impose additional requirements. Consult qualified counsel before deploying an electronic signature program or relying on an electronically executed document in an excluded category.