Digital efficiency is valuable, but legal robustness is essential. Banks operate under strict supervision, and every document must be capable of standing up in court if necessary. This is exactly where merely being 'digital somehow' differs from being legally compliant and digital.
Banks that establish evidential value correctly from the outset not only reduce audit effort, but also gain greater regulatory confidence and measurable efficiency improvements.
To satisfy supervisors, internal audit and the courts, use the key levers of eIDAS signatures, audit trails, qualified timestamps and an evidence-preserving archiving strategy.
Terminology in 20 Seconds
- Digital Original: created electronically, with signature + audit trail + timestamp.
- SES / AES / QES: eIDAS signature levels; QES = equivalent to handwritten signature under eIDAS, subject to the applicable legal context.
- Audit Trail: Complete logs (who/what/when/with what/why) for internal audit and external review.
Series: From Paper to Performance
-
Part 1/5 - From Paper to Performance: Why Banks Need End-to-End Digitalisation
Cost and risk drivers of paper-based processes, plus a roadmap for end-to-end workflows. -
Part 2/5 - PDF ≠ Digital: How Banks Can Finally Use PDFs Intelligently
Why 'saving a PDF' is not a process and how PDFs can become structured, verifiable data. -
Part 3/5 - Evidential Value of Digital Documents: Legally Robust Digital Processes in Banks
Evidential value, audit trails and signatures: what really matters for audit and regulatory robustness. -
Part 4/5 - Digital Competitiveness: How Banks Can Keep Pace in the Digital Market
The capabilities banks now need and the process metrics that make the difference measurable. -
Part 5/5 - Workflow Automation: Step by Step to a Paperless Process
How workflow automation creates robust process infrastructure: faster and compliant
What to Expect in This Article:
- Core Principles of Evidential Value
- Distinction: Digital Original vs. Scanned Copy
- Compliance Requirements in the Digital Workflow
- Preserving Evidential Value in Practice
- Best Practices & Pitfalls
- Which Signature Level (SES/AES/QES) Is Right?
- Integration into Existing Processes
- Step-by-Step Guide to Securing Evidential Value
- Automation and AI Potential
- Conclusion and Outlook
- Frequently Asked Questions (FAQ)
Core Principles of the Evidential Value of Digital Documents
Digital documents must have evidential value in order to be used in banks in a legally compliant manner. In the German legal context, Sections 371a/b of the German Code of Civil Procedure (ZPO) govern aspects of evidential treatment in civil proceedings, while the eIDAS Regulation (EU 910/2014) provides the EU-wide framework for electronic signatures and trust services:
Integrity
- The document must be stored unchanged and protected against tampering.
- Changes must be traceable (e.g. timestamps, hash values).
Authenticity / Signature
- SES is the 'simple electronic signature'. This includes any electronic indication used by a person to sign, such as click-to-sign, a typed name or a scanned signature.
- AES, the 'advanced electronic signature', strengthens attribution to the individual and the integrity of the data.
- Electronic signatures at SES/AES level can cover internal processes or simple approvals.
- The Qualified Electronic Signature (QES) additionally verifies the signatory's identity and uses a qualified certificate.
Traceability / Audit Trail
- Complete logging of actions throughout the workflow.
- Audit-ready records for internal and external reviews.
Timestamps & Evidence Preservation
- The times of creation, approval and signature must be documented.
- Essential for legal enforceability and regulatory compliance.
Scans & Evidential Value: A Look at Current Guidance and Decisions
German Federal Archives (Guidance): 'Substitutive scanning' can replace paper, but requires additional measures for the evidential value to approach that of the original. A simple scan remains only a copy.
German BSI TR-RESISCAN (TR-03138): The aim is to achieve evidential value close to that of the original; this does not automatically create the evidential status of an original document.
Legal Assessment: Scanned private documents are generally subject to free judicial assessment of evidence under Section 286 ZPO; without a QES, the evidential rules of Section 371a ZPO do not apply.
Scans Are Suitable for Internal Low-Risk Processes, but Do Not Replace a QES in Legally Significant Banking Transactions.Further Reading (Practice): PDF ≠ Digital: How Banks Turn PDFs into Structured, Verifiable Data
Distinction: Digital Original vs. Scanned Copy
Not every digital process starts with a genuine digital original. Scanned PDFs are initially only representations of paper documents (without timestamps or an audit trail). For legally robust workflows in banks, it is essential that documents are created digitally from the outset or are provided with a signature and a complete audit trail.
Gescanntes PDF-Papier vs. Digital signiertes Dokument
| Document Type | Integrity | Signature | Audit Trail | Evidential Value |
|---|---|---|---|---|
| PDF Scan | low | none | incomplete | limited |
| QES Document | very high | SES, AES, QES | complete | full |
Legal Basis: Brief & Specific
Section 371a ZPO: Private electronic documents with a QES benefit from the evidential rules applicable to private documents; without a QES, they are generally subject to free judicial assessment of evidence.
Section 371b ZPO: Special rule for scanned public documents (a different framework from private documents).
eIDAS Framework: QES validation under Article 32 eIDAS; the evidential treatment of private electronic documents under German law is governed by Section 371a ZPO.
Anti-Pattern: Evidential Value of Digital Documents
Problem: Documents are scanned and stored as 'digital'.
Cause: Missing signature strategy and no end-to-end audit trail.
Consequence: Limited evidential value, greater retrospective review effort and regulatory risks in audits or legal disputes.
Compliance Requirements in the Digital Workflow
Digital workflows in banks must meet supervisory requirements. What Does This Mean? Every process step must be fully traceable, audit-ready and auditable.
Wer regulatorische Anforderungen wie MaRisk, BAIT oder DSGVO zuverlässig erfüllen möchte, setzt auf eIDAS-konforme Workflows.
Key Requirements in the German Banking Context Arise From:
- MaRisk AT 7.2 (Germany): Proper business organisation & internal control system (ICS), with traceability of every action.
- BAIT (Germany, transitional relevance): Requirements for IT operations and data management, including traceability of changes. BAIT is being phased out as DORA becomes the primary ICT risk framework for institutions within its scope.
- GDPR Articles 5 & 32: Integrity, confidentiality and availability of personal data.
- GoBD (Germany): German requirements for audit-ready electronic record-keeping and archiving.
- German BSI TR-03125 (TR-ESOR): Technical guideline for evidence-preserving long-term storage.
For Banks, This Means: Legal robustness is not an end in itself: it reduces review effort, lowers OPEX (operational expenditure) and protects against regulatory pressure. Every automated evidence record replaces manual checks and creates measurable ROI in compliance operations.

Preserving Evidential Value: What Is Technically Required
Valid on Receipt: QES + timestamp + certificate chain/OCSP.
Valid Over Time: renewed timestamps/hash migration when algorithms or keys become obsolete.
Exportable: reviewable evidence record/audit package.
Applies to: Standardised banking processes with external effect, such as account and securities account openings, loan agreements, powers of attorney or KYC-relevant documents where evidential value and traceability are required by regulation.
Does Not Apply to: Purely internal notes, working documents without decision-making or external effect, and historically scanned legacy files without subsequent signature or evidential-value enhancement.
Preserving Evidential Value in Practice
Even qualified electronically signed documents can lose evidential strength over time if the signature or hash algorithms used are considered obsolete. BSI guidelines (e.g. TR-ESOR) therefore provide for the regular renewal of evidence objects (evidence records) and procedures for long-term signature validation (Long-Term Validation, LTV).
Compliance Checklist:
| Aspect | Required Evidence | Regulatory Reference | Risk in the Event of Non-Compliance |
|---|---|---|---|
| Signature | eIDAS-compliant (SES / AES / QES) | eIDAS Art. 25 ff. | Loss of evidential strength |
| Audit Trail | Complete logging | MaRisk AT 7.2 / BAIT 8 | Lack of traceability |
| Timestamp | Qualified in accordance with BSI TR-ESOR | BSI TR-03125 | Suspicion of manipulation |
| Archive | Audit-ready, GDPR-compliant | GoBD / DSGVO | Fines, reputational risks |
Measurement Framework: Period: 6-12 months Population: account and securities account openings, credit files, KYC-relevant documents KPIs: number of audit findings / retrospective reviews Rework time per case Share of documents protected by QES OPEX per case (compliance & internal audit) Method: before/after comparison by document class Data sources: audit trail logs, archive systems, internal audit reports, ICS documentation Reporting: quarterly (median + outliers)
The Technical Requirement Pays Off Economically: less rework, shorter audit cycles and lower total costs per case. What was once regarded purely as a compliance burden is now becoming an efficiency lever within the control system.
How Paperfly Safeguards the Evidential Value of Digital Documents
Paperfly ensures that digital documents in banks are processed not only efficiently, but also in a way that preserves their evidential value over the long term. Signatures, timestamps, audit trails and archiving work together in one end-to-end workflow: automated, verifiable and eIDAS-compliant.
Out-of-the-Box Functions:
- eIDAS-compliant SES, AES and QES signatures by document class
- Automatic signature, certificate and timestamp validation before archiving
- Audit-ready storage with an exportable audit package
- Seamless integration into DMS, core banking and archive systems
-40-60% audit rework through automated evidence management.
Best Practices & Pitfalls
The Solution: Automated, digital end-to-end workflows. They provide eIDAS-compliant signatures (SES/AES/QES), versioning and access control, an automatic audit trail and audit-ready processing.
Typical Errors & Avoidable Risks
- Simple PDF Scan: No legally robust documentation, limited evidential value
- Missing Audit Trail: No complete traceability of process steps, compliance risks
- Versioning Problems: Unclear which document version is valid, errors during updates
- Manual Review: Time-consuming, error-prone, high resource requirements
Which Signature Level (SES/AES/QES) Is Right?
Not every process requires QES, but some cannot do without it. The following quick picker helps identify the appropriate level in seconds:
- Does a Written-Form Requirement Apply (Law/Contract)? → QES (equivalent to handwritten signature under the applicable legal framework).
- No Written-Form Requirement, but External Effect for a Customer/Partner?
- Low to Medium Risk → SES (alternatively AES depending on policy/threshold).
- High Risk / Amounts Above Threshold / PEP / Sanctions Exposure → AES/QES.
- Internal Process Only (no external effect) → SES/AES in accordance with the ICS policy.
- Uncertainty / Borderline Case → nächsthöhere Stufe wählen (Default-Sicherheit).
Integration into Existing Processes
For Banks: Digital workflows must integrate seamlessly into existing systems. This enables an end-to-end, auditable process flow without media breaks, from DMS and core banking systems through to CRM and HR solutions.
Seamless Workflow Integration
Further Reading (Strategy): Digital Competitiveness in Banks: Capabilities, KPI Set and RoadmapIn the German banking context, combining structured data capture, digital signatures and audit-ready archiving can support requirements under MaRisk and the Internal Control System (ICS). For ICT risk management, DORA is now the primary framework for institutions within its scope, with BAIT remaining relevant only where still applicable during the transition.
This creates an end-to-end traceable evidence process that is both eIDAS-compliant and verifiable in line with GoBD.
Step-by-Step Guide to Securing Evidential Value
Your Goal: Make document workflows audit-ready, verifiable and legally reliable.
These 6 Steps Are Required:
- Scope & Prioritisation: Identify critical document classes (account/securities account opening, credit files, KYC).
- Legal Check: Determine the required signature types (SES/AES/QES) for each document class.
- Technical Baseline: Check whether the digital workflow system supports signatures, timestamps and an audit trail.
- Automated Validation: Enforce validation rules (mandatory fields, signature status, completeness) before storage.
- Audit & Archiving Strategy: Define long-term archiving in line with GoBD/GDPR requirements.
- Rollout & Change: Processes, roles, training and monitoring (KPIs).
Automation and AI Potential
Banks Generate Thousands of Documents Every Day. The greater the volume, the more important automated controls and intelligent review mechanisms become.
According to the 2023 KYC Trend Report Germany, banks spend an average of up to 28 hours per new-customer onboarding, with manual document checks and follow-up queries accounting for the largest share of time.
Automated validation and workflow intelligence can reduce this duration by 30-50%, while improving data quality at the same time.
Legal Robustness Is the Foundation, but What Matters Is How Quickly and Economically It Is Achieved. Modern eIDAS workflows combine evidential value, efficiency and audit readiness in one step, turning compliance into a competitive advantage.
Conclusion and Outlook
Digitalisation in banks requires a legally robust foundation. Only when integrity, authenticity, traceability and long-term evidence preservation are ensured can a document remain legally reliable in digital form over time.
Update 2026 - 2027: eIDAS 2.0 & EUDI Wallet
The eIDAS 2 framework is in force. By 2027, each Member State is expected to offer at least one EUDI Wallet.
For Banks, This Means: Wallet-based identification and signatures replace manual KYC processes, while attribute-based evidence (e.g. residence, corporate role) and integrated signatures accelerate onboarding and contractual journeys. Status: 12/2025
Frequently Asked Questions (FAQ)
What Does the Evidential Value of Digital Documents in Banks Mean in Practice?
The evidential value of digital documents describes their legal usability vis-à-vis supervisors, internal audit and the courts. It arises when a document is created digitally from the outset, signed in compliance with eIDAS, timestamped and archived with full traceability through a complete audit trail. Only then can it serve as legally robust evidence.
What Qualifies as a Document with Full Evidential Value?
A document has full evidential value when it is created digitally from the outset or digitised and then signed with an eIDAS-compliant qualified electronic signature (QES). In Germany, Section 371a ZPO governs the evidential treatment of such private electronic documents. Qualified timestamps and a complete audit trail additionally support traceability.
Is a PDF Scan Sufficient as Evidence?
No. Without an electronic signature and audit trail, a PDF scan is merely a digital copy. Evidence of authenticity and integrity is missing, so it is generally subject only to free judicial assessment of evidence. Legally robust banking processes require signed documents with timestamps and a complete audit trail. Source: German Federal Ministry of Justice legal information portal
How Can I Verify the Evidential Value of Digital Documents?
Using Three Criteria:
Signature: qualified or advanced under eIDAS
Timestamp: records the time of creation
Audit Trail: documents changes and access
Tools such as Paperfly automatically check and log this evidence.
What Advantages Does a Signed Workflow Offer Compared with Paper Processes?
-50% processing time through automated approvals
-30% OPEX (operational expenditure) through eliminating printing, postage and rework. Efficiency, legal robustness and clear ROI benefits.
Can I Integrate Existing DMS or Core Banking Systems?
Yes. Via API interfaces, Paperfly can, for example, be integrated into DMS, CRM or HR systems. Existing processes remain in place while signature and audit functions are added automatically.
How Is Evidential Value Preserved Over the Long Term?
The evidential value of digital documents is preserved over the long term when signatures and timestamps are renewed regularly and validation evidence is stored. In Germany, BSI TR-03125 (TR-ESOR) provides technical guidance on using evidence records, OCSP/CRL evidence and hash and timestamp migrations to support long-term verifiability, even when certificates or algorithms expire. Source: BSI
What Does eIDAS 2/EUDI Bring to Banks?
eIDAS 2.0 and the EUDI Wallet enable state-recognised digital identities and attribute evidence that can be used across banking processes. Wallet-based identification, strong customer authentication (SCA) and integrated signatures significantly shorten onboarding and contractual processes, increase evidential value and reduce manual KYC and review effort. EU-wide rollout is scheduled for 2026/2027. Source: European Commission (Digital Identity)
Back to the Series: From Paper to Performance: End-to-End Digitalisation in Banks (Overview & Introduction)Mini Glossary: Key Terms on the Evidential Value of Digital Documents
Evidential Value = the legal usability of a document vis-à-vis supervisors, internal audit and the courts; dependent on integrity, authenticity, traceability and long-term evidence preservation.
Digital Original = a document created electronically from the outset, provided with an electronic signature, timestamp and audit trail, and not originating from a scan.
QES (Qualified Electronic Signature) = the highest eIDAS signature level using a qualified certificate. Under the EU-wide eIDAS framework, a QES has the equivalent legal effect of a handwritten signature. In the German legal context, Section 371a ZPO governs the evidential treatment of private electronic documents bearing a QES in civil proceedings.
Audit Trail = complete, audit-ready logging of all process and document actions (who, what, when, with what, why) throughout the entire lifecycle.
Qualified Timestamp = cryptographic evidence of a specific point in time that makes manipulation detectable and is essential for robust evidential use in legal proceedings.
Long-Term Evidence Preservation (LTV) = procedures for preserving evidential value over the long term through evidence records, OCSP/CRL evidence and regular renewal of timestamps and hash algorithms. In the German context, BSI TR-03125 (TR-ESOR) provides relevant technical guidance for this purpose.
Compliance Management = defines signature levels, evidential-value policies and review paths.
Internal Audit = assesses traceability, audit trails and long-term evidence preservation.
IT Governance = is responsible for integrations, archiving strategy and system controls.
Sources:
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03138/ersetzendes-scannentr-resiscan.htmlhttps://resources.fenergo.com/de/aktuelle-nachrichten/kyc-trend-report-2023-detutschland
https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation
https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR03125/BSI_TR_03125_V1_3.pdf
https://www.gesetze-im-internet.de/zpo/__371a.html
