An auditable signature isn’t just "signed", it’s embedded in the file, chains to a recognized trust list, carries the right legal level for its purpose, has a qualified timestamp, and is built to stay checkable for as long as the document needs to survive. Most gaps show up in one of these seven areas.
An embedded PAdES/XAdES/CAdES signature can be checked independently of the platform that created it. A platform-recorded signature can only be confirmed by asking that platform. See the risk of platform-tied signatures.
Check against the EU LOTL for EU-qualified signatures and seals, and against Adobe’s AATL for Acrobat-level trust without an EU qualification. A self-signed or unrecognized certificate proves nothing an auditor can rely on.
Simple, advanced, and qualified electronic signatures carry different legal weight under eIDAS Article 25. Only a qualified signature has automatic EU-wide equivalence to a handwritten one. See is my e-signature legally binding?
A qualified seal carries an Article 35 presumption of integrity and origin, not handwritten equivalence. Confusing the two is a common source of overclaiming. See what is a qualified electronic seal?
A timestamp from a qualified trust service provider establishes when the signature was applied independently of the document’s own metadata, which can be altered. A signing date with no cryptographic timestamp behind it is an assertion, not evidence.
Certificates expire and revocation records don’t last forever. A long-term-validity profile (PAdES-B-LTA) embeds the evidence needed to check the signature long after the certificate itself has lapsed. See future-proofing signed contracts.
The seal covers the exact bytes of the file at signing time. A validator should confirm the document is byte-for-byte unchanged since then, not just that a signature exists somewhere in it.
This isn’t a legal compliance checklist and doesn’t replace advice specific to your regulatory context. It’s the practical, technical version: the questions a validator actually needs to answer to tell you whether a signed document holds up as independent evidence, versus one that depends entirely on trusting whoever created it.