Digital efficiency is valuable, but legal robustness is essential. Banks operate under strict supervision, and every document must be capable of standing up in court if necessary. This is exactly where merely being 'digital somehow' differs from being legally compliant and digital.

Every Manual Check, Every Scan and Every Missing Signature Costs Time, Money and Trust. If the evidential value is insufficient, fines or even reversals may follow. Processes that are supposed to be digital become a cost trap.

Banks that establish evidential value correctly from the outset not only reduce audit effort, but also gain greater regulatory confidence and measurable efficiency improvements.

To satisfy supervisors, internal audit and the courts, use the key levers of eIDAS signatures, audit trails, qualified timestamps and an evidence-preserving archiving strategy.

Terminology in 20 Seconds

  • Digital Original: created electronically, with signature + audit trail + timestamp.
  • SES / AES / QES: eIDAS signature levels; QES = equivalent to handwritten signature under eIDAS, subject to the applicable legal context.
  • Audit Trail: Complete logs (who/what/when/with what/why) for internal audit and external review.

Series: From Paper to Performance

What to Expect in This Article:

Core Principles of the Evidential Value of Digital Documents

Digital documents must have evidential value in order to be used in banks in a legally compliant manner. In the German legal context, Sections 371a/b of the German Code of Civil Procedure (ZPO) govern aspects of evidential treatment in civil proceedings, while the eIDAS Regulation (EU 910/2014) provides the EU-wide framework for electronic signatures and trust services:

Integrity

  • The document must be stored unchanged and protected against tampering.
  • Changes must be traceable (e.g. timestamps, hash values).

Authenticity / Signature

  • SES is the 'simple electronic signature'. This includes any electronic indication used by a person to sign, such as click-to-sign, a typed name or a scanned signature.
  • AES, the 'advanced electronic signature', strengthens attribution to the individual and the integrity of the data.
  • Electronic signatures at SES/AES level can cover internal processes or simple approvals.
  • The Qualified Electronic Signature (QES) additionally verifies the signatory's identity and uses a qualified certificate.

Traceability / Audit Trail

  • Complete logging of actions throughout the workflow.
  • Audit-ready records for internal and external reviews.

Timestamps & Evidence Preservation

  • The times of creation, approval and signature must be documented.
  • Essential for legal enforceability and regulatory compliance.

Scans & Evidential Value: A Look at Current Guidance and Decisions

German Federal Archives (Guidance): 'Substitutive scanning' can replace paper, but requires additional measures for the evidential value to approach that of the original. A simple scan remains only a copy.

German BSI TR-RESISCAN (TR-03138): The aim is to achieve evidential value close to that of the original; this does not automatically create the evidential status of an original document.

Legal Assessment: Scanned private documents are generally subject to free judicial assessment of evidence under Section 286 ZPO; without a QES, the evidential rules of Section 371a ZPO do not apply.

Scans Are Suitable for Internal Low-Risk Processes, but Do Not Replace a QES in Legally Significant Banking Transactions.
Further Reading (Practice): PDF ≠ Digital: How Banks Turn PDFs into Structured, Verifiable Data

Distinction: Digital Original vs. Scanned Copy

Not every digital process starts with a genuine digital original. Scanned PDFs are initially only representations of paper documents (without timestamps or an audit trail). For legally robust workflows in banks, it is essential that documents are created digitally from the outset or are provided with a signature and a complete audit trail.

Gescanntes PDF-Papier vs. Digital signiertes Dokument

Document Type Integrity Signature Audit Trail Evidential Value
PDF Scan low none incomplete limited
QES Document very high SES, AES, QES complete full

Legal Basis: Brief & Specific

Section 371a ZPO: Private electronic documents with a QES benefit from the evidential rules applicable to private documents; without a QES, they are generally subject to free judicial assessment of evidence.
Section 371b ZPO: Special rule for scanned public documents (a different framework from private documents).
eIDAS Framework: QES validation under Article 32 eIDAS; the evidential treatment of private electronic documents under German law is governed by Section 371a ZPO.

Anti-Pattern: Evidential Value of Digital Documents

Problem: Documents are scanned and stored as 'digital'.
Cause: Missing signature strategy and no end-to-end audit trail.
Consequence: Limited evidential value, greater retrospective review effort and regulatory risks in audits or legal disputes.

Further Reading (Compliance): Evidential Value of Digital Documents in Banks: Signatures, Audit Trails and Audit Readiness

Compliance Requirements in the Digital Workflow

Digital workflows in banks must meet supervisory requirements. What Does This Mean? Every process step must be fully traceable, audit-ready and auditable.

Every Manual Check, Every Scan and Every Missing Signature Costs Time, Money and Trust. If the evidential value is insufficient, fines or even reversals may follow. Processes that are supposed to be digital become a cost trap.

Wer regulatorische Anforderungen wie MaRisk, BAIT oder DSGVO zuverlässig erfüllen möchte, setzt auf eIDAS-konforme Workflows.

Key Requirements in the German Banking Context Arise From:

  • MaRisk AT 7.2 (Germany): Proper business organisation & internal control system (ICS), with traceability of every action.
  • BAIT (Germany, transitional relevance): Requirements for IT operations and data management, including traceability of changes. BAIT is being phased out as DORA becomes the primary ICT risk framework for institutions within its scope.
  • GDPR Articles 5 & 32: Integrity, confidentiality and availability of personal data.
  • GoBD (Germany): German requirements for audit-ready electronic record-keeping and archiving.
  • German BSI TR-03125 (TR-ESOR): Technical guideline for evidence-preserving long-term storage.

For Banks, This Means: Legal robustness is not an end in itself: it reduces review effort, lowers OPEX (operational expenditure) and protects against regulatory pressure. Every automated evidence record replaces manual checks and creates measurable ROI in compliance operations.

Preserving Evidential Value: What Is Technically Required

Valid on Receipt: QES + timestamp + certificate chain/OCSP.

Valid Over Time: renewed timestamps/hash migration when algorithms or keys become obsolete.

Exportable: reviewable evidence record/audit package.

Applies to: Standardised banking processes with external effect, such as account and securities account openings, loan agreements, powers of attorney or KYC-relevant documents where evidential value and traceability are required by regulation.

Does Not Apply to: Purely internal notes, working documents without decision-making or external effect, and historically scanned legacy files without subsequent signature or evidential-value enhancement.

Preserving Evidential Value in Practice

Even qualified electronically signed documents can lose evidential strength over time if the signature or hash algorithms used are considered obsolete. BSI guidelines (e.g. TR-ESOR) therefore provide for the regular renewal of evidence objects (evidence records) and procedures for long-term signature validation (Long-Term Validation, LTV).

Practical Relevance: Banks are increasingly implementing what are known as archive gates: they check signature status, generate evidence objects and automatically monitor renewal cycles.

Compliance Checklist:

Aspect Required Evidence Regulatory Reference Risk in the Event of Non-Compliance
Signature eIDAS-compliant (SES / AES / QES) eIDAS Art. 25 ff. Loss of evidential strength
Audit Trail Complete logging MaRisk AT 7.2 / BAIT 8 Lack of traceability
Timestamp Qualified in accordance with BSI TR-ESOR BSI TR-03125 Suspicion of manipulation
Archive Audit-ready, GDPR-compliant GoBD / DSGVO Fines, reputational risks

Measurement Framework: Period: 6-12 months Population: account and securities account openings, credit files, KYC-relevant documents KPIs: number of audit findings / retrospective reviews Rework time per case Share of documents protected by QES OPEX per case (compliance & internal audit) Method: before/after comparison by document class Data sources: audit trail logs, archive systems, internal audit reports, ICS documentation Reporting: quarterly (median + outliers)

Mandatory Technical Measures: Validation of incoming signatures and certificates (OCSP/CRL evidence). Automatic renewal of timestamps (hash migration). Archive system with an audit package (evidence objects + validation logs).

The Technical Requirement Pays Off Economically: less rework, shorter audit cycles and lower total costs per case. What was once regarded purely as a compliance burden is now becoming an efficiency lever within the control system.

How Paperfly Safeguards the Evidential Value of Digital Documents

Paperfly ensures that digital documents in banks are processed not only efficiently, but also in a way that preserves their evidential value over the long term. Signatures, timestamps, audit trails and archiving work together in one end-to-end workflow: automated, verifiable and eIDAS-compliant.

Out-of-the-Box Functions:

  • eIDAS-compliant SES, AES and QES signatures by document class
  • Automatic signature, certificate and timestamp validation before archiving
  • Audit-ready storage with an exportable audit package
  • Seamless integration into DMS, core banking and archive systems
-40-60% audit rework through automated evidence management.

Best Practices & Pitfalls

The Solution: Automated, digital end-to-end workflows. They provide eIDAS-compliant signatures (SES/AES/QES), versioning and access control, an automatic audit trail and audit-ready processing.

Typical Errors & Avoidable Risks

  • Simple PDF Scan: No legally robust documentation, limited evidential value
  • Missing Audit Trail: No complete traceability of process steps, compliance risks
  • Versioning Problems: Unclear which document version is valid, errors during updates
  • Manual Review: Time-consuming, error-prone, high resource requirements

Which Signature Level (SES/AES/QES) Is Right?

Not every process requires QES, but some cannot do without it. The following quick picker helps identify the appropriate level in seconds:

  • Does a Written-Form Requirement Apply (Law/Contract)?QES (equivalent to handwritten signature under the applicable legal framework).
  • No Written-Form Requirement, but External Effect for a Customer/Partner?
    • Low to Medium RiskSES (alternatively AES depending on policy/threshold).
    • High Risk / Amounts Above Threshold / PEP / Sanctions ExposureAES/QES.
  • Internal Process Only (no external effect) → SES/AES in accordance with the ICS policy.
  • Uncertainty / Borderline Case → nächsthöhere Stufe wählen (Default-Sicherheit).
Always in Addition (Regardless of Signature Level): Audit trail (who/what/when/with what/why), timestamp, signature/certificate validation before archiving, retrievable storage and defined deletion triggers.

Integration into Existing Processes

For Banks: Digital workflows must integrate seamlessly into existing systems. This enables an end-to-end, auditable process flow without media breaks, from DMS and core banking systems through to CRM and HR solutions.

Seamless Workflow Integration

  • DMS Integration: Signed documents are stored directly in an audit-ready manner. No more manual post-archiving.
  • HR Systems: Contracts, supporting documents or personnel records can be signed and stored automatically while preserving evidential value.
  • CRM & Core Banking Systems: Customer data, applications and approvals flow through a single digital process.
Further Reading (Strategy): Digital Competitiveness in Banks: Capabilities, KPI Set and Roadmap

In the German banking context, combining structured data capture, digital signatures and audit-ready archiving can support requirements under MaRisk and the Internal Control System (ICS). For ICT risk management, DORA is now the primary framework for institutions within its scope, with BAIT remaining relevant only where still applicable during the transition.

Every signature, change and forwarding action is automatically documented in the audit trail; the integrity of the document can be verified at any time using hash values and timestamps.
This creates an end-to-end traceable evidence process that is both eIDAS-compliant and verifiable in line with GoBD.

Step-by-Step Guide to Securing Evidential Value

Your Goal: Make document workflows audit-ready, verifiable and legally reliable.

These 6 Steps Are Required:

  1. Scope & Prioritisation: Identify critical document classes (account/securities account opening, credit files, KYC).
  2. Legal Check: Determine the required signature types (SES/AES/QES) for each document class.
  3. Technical Baseline: Check whether the digital workflow system supports signatures, timestamps and an audit trail.
  4. Automated Validation: Enforce validation rules (mandatory fields, signature status, completeness) before storage.
  5. Audit & Archiving Strategy: Define long-term archiving in line with GoBD/GDPR requirements.
  6. Rollout & Change: Processes, roles, training and monitoring (KPIs).

Automation and AI Potential

Banks Generate Thousands of Documents Every Day. The greater the volume, the more important automated controls and intelligent review mechanisms become.

Modern AI-Based Systems Now Perform Key Tasksthat were previously manual and error-prone, such as checking document authenticity, comparing information with master data or detecting irregularities in the audit trail.

According to the 2023 KYC Trend Report Germany, banks spend an average of up to 28 hours per new-customer onboarding, with manual document checks and follow-up queries accounting for the largest share of time.

Automated validation and workflow intelligence can reduce this duration by 30-50%, while improving data quality at the same time.

Legal Robustness Is the Foundation, but What Matters Is How Quickly and Economically It Is Achieved. Modern eIDAS workflows combine evidential value, efficiency and audit readiness in one step, turning compliance into a competitive advantage.

Conclusion and Outlook

Digitalisation in banks requires a legally robust foundation. Only when integrity, authenticity, traceability and long-term evidence preservation are ensured can a document remain legally reliable in digital form over time.

Now Is the Time to Digitalise Existing Processes Deliberately and to consider evidential value from the outset.

Update 2026 - 2027: eIDAS 2.0 & EUDI Wallet

The eIDAS 2 framework is in force. By 2027, each Member State is expected to offer at least one EUDI Wallet.

For Banks, This Means: Wallet-based identification and signatures replace manual KYC processes, while attribute-based evidence (e.g. residence, corporate role) and integrated signatures accelerate onboarding and contractual journeys. Status: 12/2025

Practical Note: Define policy mapping (SES/AES/QES) now, prepare wallet connectivity for PID/attributes and relying-party processes, and embed long-term evidence preservation in the archive (OCSP/CRL evidence, qualified timestamps, renewal cycles in accordance with BSI TR-03125/TR-ESOR).

Frequently Asked Questions (FAQ)

What Does the Evidential Value of Digital Documents in Banks Mean in Practice?

The evidential value of digital documents describes their legal usability vis-à-vis supervisors, internal audit and the courts. It arises when a document is created digitally from the outset, signed in compliance with eIDAS, timestamped and archived with full traceability through a complete audit trail. Only then can it serve as legally robust evidence.

What Qualifies as a Document with Full Evidential Value?

A document has full evidential value when it is created digitally from the outset or digitised and then signed with an eIDAS-compliant qualified electronic signature (QES). In Germany, Section 371a ZPO governs the evidential treatment of such private electronic documents. Qualified timestamps and a complete audit trail additionally support traceability.

Is a PDF Scan Sufficient as Evidence?

No. Without an electronic signature and audit trail, a PDF scan is merely a digital copy. Evidence of authenticity and integrity is missing, so it is generally subject only to free judicial assessment of evidence. Legally robust banking processes require signed documents with timestamps and a complete audit trail. Source: German Federal Ministry of Justice legal information portal

How Can I Verify the Evidential Value of Digital Documents?

Using Three Criteria:
Signature:
qualified or advanced under eIDAS
Timestamp: records the time of creation
Audit Trail: documents changes and access
Tools such as Paperfly automatically check and log this evidence.

What Advantages Does a Signed Workflow Offer Compared with Paper Processes?

-50% processing time through automated approvals
-30% OPEX (operational expenditure) through eliminating printing, postage and rework. Efficiency, legal robustness and clear ROI benefits.

Can I Integrate Existing DMS or Core Banking Systems?

Yes. Via API interfaces, Paperfly can, for example, be integrated into DMS, CRM or HR systems. Existing processes remain in place while signature and audit functions are added automatically.

How Is Evidential Value Preserved Over the Long Term?

The evidential value of digital documents is preserved over the long term when signatures and timestamps are renewed regularly and validation evidence is stored. In Germany, BSI TR-03125 (TR-ESOR) provides technical guidance on using evidence records, OCSP/CRL evidence and hash and timestamp migrations to support long-term verifiability, even when certificates or algorithms expire. Source: BSI

What Does eIDAS 2/EUDI Bring to Banks?

eIDAS 2.0 and the EUDI Wallet enable state-recognised digital identities and attribute evidence that can be used across banking processes. Wallet-based identification, strong customer authentication (SCA) and integrated signatures significantly shorten onboarding and contractual processes, increase evidential value and reduce manual KYC and review effort. EU-wide rollout is scheduled for 2026/2027. Source: European Commission (Digital Identity)

Back to the Series: From Paper to Performance: End-to-End Digitalisation in Banks (Overview & Introduction)

Mini Glossary: Key Terms on the Evidential Value of Digital Documents

Evidential Value = the legal usability of a document vis-à-vis supervisors, internal audit and the courts; dependent on integrity, authenticity, traceability and long-term evidence preservation.

Digital Original = a document created electronically from the outset, provided with an electronic signature, timestamp and audit trail, and not originating from a scan.

QES (Qualified Electronic Signature) = the highest eIDAS signature level using a qualified certificate. Under the EU-wide eIDAS framework, a QES has the equivalent legal effect of a handwritten signature. In the German legal context, Section 371a ZPO governs the evidential treatment of private electronic documents bearing a QES in civil proceedings.

Audit Trail = complete, audit-ready logging of all process and document actions (who, what, when, with what, why) throughout the entire lifecycle.

Qualified Timestamp = cryptographic evidence of a specific point in time that makes manipulation detectable and is essential for robust evidential use in legal proceedings.

Long-Term Evidence Preservation (LTV) = procedures for preserving evidential value over the long term through evidence records, OCSP/CRL evidence and regular renewal of timestamps and hash algorithms. In the German context, BSI TR-03125 (TR-ESOR) provides relevant technical guidance for this purpose.

Compliance Management = defines signature levels, evidential-value policies and review paths.

Internal Audit = assesses traceability, audit trails and long-term evidence preservation.

IT Governance = is responsible for integrations, archiving strategy and system controls.

Sources:

https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03138/ersetzendes-scannentr-resiscan.html

https://resources.fenergo.com/de/aktuelle-nachrichten/kyc-trend-report-2023-detutschland

https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation

https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR03125/BSI_TR_03125_V1_3.pdf

https://www.gesetze-im-internet.de/zpo/__371a.html